XP en vrac

Salut,

J ai des petits soucis:
Tout a commencé avec un message de avast (oui... je sais... c'est pas le top) : j avais un virus BV:AutoRun-T [Wrm] dans le c:\autorun.inf.

Après quelques recherches... je me débrouille et pense avoir achevé la bestiole.
Mais lors du redémarage pour avoir le mode sans échec... pas de mode sans échec. Je passe en mode démarrage normal qui plante sur le logo de bienvenue de la page d'ouverture de XP.
Je retente un sans échec simple.... rien... bloquage avec au passage un message comme quoi il ne trouve pas "sptd.sys".
Et la je vous parle du mode sans echec avec prise en charge réseau qui fonctionne par je ne sais quel miracle.

Je remarque des choses qui ne me semble pas normales : j ai un autorun.inf sur mon C:/ et sur une carte SD implanté dans un lecteur du PC... étrange car cette carte SD est une carte photo. Il est accompagne d'un dossier RECYCLED avec un .com dedans... il répond au doux nom de "S-2-4-17-100014810-100009468-100021540-5450.com"

Contenu du fichier autorun.inf:
[autorun]
;zkdqlvuhdymchdcfcdsctgswcqkrgccusfmxskwvfmcvdjjffxdfbykejrsim
shellexecute="RECYCLER\S-2-4-17-100014810-100009468-100021540-5450.com c:\"
;zjuuknhwcaffgldfulefjzpsgmewxrcfnuqnrhjjewerz
shell\Open\command="RECYCLER\S-2-4-17-100014810-100009468-100021540-5450.com c:\"
;egqgztehhhklnherxdjckyxcwezhunlfuktgumuuvpsqutbehcmglqvbxrz
shell=Open

le truc étrange, c'est que mode normal, il ne voulait pas se laisser détruire et renaissait qq secondes apres destruction poubelle (et effaçage poubelle).

Voila.... je suis dans la merde... et j'ai un oral professionnel dans une semaine avec des recherches a mener sur le web. Bref HELPPPP :/

Pour ceux qui voudraeint m'aider voila le fichier hijackthis.log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:27:57, on 29/03/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://gamespace.daemon-tools.cc/fra/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [CleanSetup] cmd /C rmdir /S /Q "C:\Documents and Settings\Utilisateur\Local Settings\Temp\nro.tmp\"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: WLANUtility.lnk = C:\Program Files\IEEE 802.11b WLAN Utility\WLANUtil.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c985373d23476c) (gupdate1c985373d23476c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero MediaHome 4 Service (NeroMediaHomeService.4) - Nero AG - C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe

--
End of file - 5468 bytes

MERCI INFINIMENT.
Configuration: Windows XP
Firefox 3.0.8

23 réponses

Résumé de la discussion

Une infection informatique est signalée par l'apparition d'un fichier autorun.inf et d'un dossier RECYCLED sur la carte SD, signalant BV:AutoRun-T [Wrm] et des redémarrages problématiques. Le système rencontre des blocages du mode sans échec et des redirections via autorun.inf, avec des éléments persistants qui se réinstallent après tentative de destruction. Le fichier HijackThis montre de nombreuses entrées de démarrage, des services et des extras qui signalent une compromission, et les réponses suggèrent des outils de nettoyage comme Toolbar-S&D et OTMoveIt3. D'autres indices évoquent l'examen d'éventuels vecteurs externes et imposent de démarrer en mode sécurisé tout en vidant les artefacts, sans conclure sur le statut final de l'issue.

Bobot (l’IA à votre service)
  1. Bon on commence par la redirection de page

    1/Télécharge ToolBar S&D ( de Eric_71/Team IDN ) sur ton bureau :
    https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

    ( Tuto : https://sites.google.com/site/toolbarsd/aideenimages )

    !! Déconnecte toi et ferme toutes tes applications en cours le temps de la manipe !!

    * Double-clique sur ToolBar SD.exe pour lancer l'outil et laisse toi guider ...
    --> Tapes ( option " recherche " ) puis tape sur [Entrée].

    Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse

    ( le rapport est en outre sauvegardé ici -> C:\TB.txt )

    2/
    Relance Toolbar-S&D en double-cliquant sur le raccourci
    .
    Ø Tape sur "2" puis valide en appuyant sur "Entrée".

    ! Ne ferme pas la fenêtre lors de la suppression !

    Un rapport sera généré, poste son contenu ici.

    NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
    Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
    Tape explorer puis valide.
    1. Merci pour le coup de main !

      Premier rapport de SD

      -----------\\ ToolBar S&D 1.2.8 XP/Vista

      Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
      X86-based PC ( Uniprocessor Free : Processeur Intel Pentium II )
      BIOS : Default System BIOS
      USER : Utilisateur ( Administrator )
      BOOT : Fail-safe with network boot
      Antivirus : avast! antivirus 4.8.1201 [VPS 090329-0] 4.8.1201 (Activated)
      A:\ (USB)
      C:\ (Local Disk) - NTFS - Total:74 Go (Free:48 Go)
      D:\ (CD or DVD)
      E:\ (CD or DVD)
      F:\ (USB)
      G:\ (USB) - FAT - Total:243 Mo (Free:0 Go)
      H:\ (Local Disk) - NTFS - Total:116 Go (Free:78 Go)
      I:\ (USB)
      J:\ (USB)
      K:\ (Local Disk) - NTFS - Total:116 Go (Free:102 Go)

      "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
      Option : [1] ( 30/03/2009| 0:00 )

      -----------\\ Recherche de Fichiers / Dossiers ...

      C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
      C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\CONTENT\searchsettingsplugin.js
      C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\CONTENT\searchsettingsplugin.xul
      C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\LOCALE\EN-US\searchsettingsplugin.dtd
      C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\LOCALE\EN-US\searchsettingsplugin.properties
      C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\COMPONENTS\SearchSettingsFF.dll
      C:\DOCUME~1\UTILIS~1\APPLIC~1\Search Settings
      C:\DOCUME~1\UTILIS~1\APPLIC~1\Search Settings\kb127
      C:\DOCUME~1\UTILIS~1\APPLIC~1\Search Settings\kb127\res
      C:\DOCUME~1\UTILIS~1\APPLIC~1\Search Settings\kb127\temp
      C:\Program Files\Search Settings
      C:\Program Files\Search Settings\kb127
      C:\Program Files\Search Settings\SearchSettings.exe
      C:\Program Files\Search Settings\kb127\res
      C:\Program Files\Search Settings\kb127\SearchSettingsRes409.dll
      C:\Program Files\Search Settings\kb127\temp

      -----------\\ [..\Internet Explorer\Main]

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
      "Start Page"="https://gamespace.daemon-tools.cc/fra/home"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
      "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
      "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
      "Search Bar"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"

      --------------------\\ Recherche d'autres infections

      Aucune autre infection trouvée !

      1 - "C:\ToolBar SD\TB_1.txt" - 30/03/2009| 0:00 - Option : [1]

      Second Rapport

      -----------\\ ToolBar S&D 1.2.8 XP/Vista

      Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
      X86-based PC ( Uniprocessor Free : Processeur Intel Pentium II )
      BIOS : Default System BIOS
      USER : Utilisateur ( Administrator )
      BOOT : Fail-safe with network boot
      Antivirus : avast! antivirus 4.8.1201 [VPS 090329-0] 4.8.1201 (Activated)
      A:\ (USB)
      C:\ (Local Disk) - NTFS - Total:74 Go (Free:48 Go)
      D:\ (CD or DVD)
      E:\ (CD or DVD)
      F:\ (USB)
      G:\ (USB) - FAT - Total:243 Mo (Free:0 Go)
      H:\ (Local Disk) - NTFS - Total:116 Go (Free:78 Go)
      I:\ (USB)
      J:\ (USB)
      K:\ (Local Disk) - NTFS - Total:116 Go (Free:102 Go)

      "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
      Option : [2] ( 30/03/2009| 0:02 )

      -----------\\ SUPPRESSION

      Supprime! - C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
      Supprime! - C:\DOCUME~1\UTILIS~1\APPLIC~1\Search Settings\kb127
      Supprime! - C:\Program Files\Search Settings\kb127
      Supprime! - C:\Program Files\Search Settings\SearchSettings.exe
      Supprime! - C:\DOCUME~1\UTILIS~1\APPLIC~1\Search Settings
      Supprime! - C:\Program Files\Search Settings

      -----------\\ Recherche de Fichiers / Dossiers ...

      -----------\\ [..\Internet Explorer\Main]

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
      "Start Page"="https://gamespace.daemon-tools.cc/fra/home"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
      "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
      "Start Page"="https://www.msn.com/fr-fr/"
      "Search Bar"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"

      --------------------\\ Recherche d'autres infections

      Aucune autre infection trouvée !

      1 - "C:\ToolBar SD\TB_1.txt" - 30/03/2009| 0:00 - Option : [1]
      2 - "C:\ToolBar SD\TB_2.txt" - 30/03/2009| 0:03 - Option : [2]

      Pour la suite... demain soir car j'ai une journée de folie demain : levé 6h... et retour maison vers 20h... et le tout en non stop :/

      ps; pour le reste... en mode sans échec avec réseau ou je tente en "normal" si ça marche...
  2. Ensuite l'autorun

    1/
    Telecharge maintenant FindyKill sur ton bureau :

    http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

    --> Lance l installation avec les parametres par default

    --> Au menu principal,choisi l option 1 (Recherche)

    --> Post le rapport FindyKill.txt

    Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

    2/
    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

    --> Fais clic droit sur le raccourci FindyKill sur ton bureau

    --> Au menu principal,choisi l option 2 (Suppression)

    /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

    /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

    -------> ensuite post le rapport FindyKill.txt

    Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
    1. allez... j ai encore un peu de temps... et ça me ronge

      rapport1 de findy :
      ############################## [ FindyKill V4.721 ]

      # User : Utilisateur (Administrateurs) # MAXDATA-831FA97
      # Update on 29/03/09 by Chiquitine29
      # Start at: 00:13:28 | 30/03/2009
      # Website : http://pagesperso-orange.fr/FindyKill.Ad.Remover/

      # Processeur Intel Pentium II
      # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
      # Internet Explorer 7.0.5730.11
      # Windows Firewall Status : Disabled
      # AV : avast! antivirus 4.8.1201 [VPS 090329-0] 4.8.1201 [ Enabled | Updated ]

      # A:\ # Lecteur de disquettes 3 ½ pouces
      # C:\ # Disque fixe local # 74,53 Go (48,83 Go free) # NTFS
      # D:\ # Disque CD-ROM
      # E:\ # Disque CD-ROM
      # F:\ # Disque amovible
      # G:\ # Disque amovible # 243,98 Mo (73,52 Mo free) [EOS_DIGITAL] # FAT
      # H:\ # Disque fixe local # 116,44 Go (78,35 Go free) [Nouveau nom] # NTFS
      # I:\ # Disque amovible
      # J:\ # Disque amovible
      # K:\ # Disque fixe local # 116,45 Go (102,84 Go free) # NTFS

      ############################## [ Processus actifs ]

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\NOTEPAD.EXE
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      ################## [ Fichiers / Dossiers infectieux C:\ ]

      ################## [ C:\WINDOWS & C:\WINDOWS\Prefetch ]

      ################## [ C:\WINDOWS\system32 ]

      ################## [ C:\WINDOWS\system32\drivers ]

      ################## [ C:\.. Application Data ... ]

      ################## [ C:\Users...\Temp Files... ]

      Found ! - C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\Patcher\Patcher2608\RTPatch\patch.exe
      Found ! - C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\Patcher\Patcher2624\RTPatch\patch.exe
      Found ! - C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\Patcher\Patcher4032\RTPatch\patch.exe
      Found ! - C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\Patcher\Patcher4040\RTPatch\patch.exe

      ################## [ Registre / Clés infectieuses ]

      ################## [ Recherche dans supports amovibles]

      # Contenu de l'autorun : C:\autorun.inf

      [autorun]
      ;zkdqlvuhdymchdcfcdsctgswcqkrgccusfmxskwvfmcvdjjffxdfbykejrsim
      shellexecute="RECYCLER\S-2-4-17-100014810-100009468-100021540-5450.com c:\"
      ;zjuuknhwcaffgldfulefjzpsgmewxrcfnuqnrhjjewerz
      shell\Open\command="RECYCLER\S-2-4-17-100014810-100009468-100021540-5450.com c:\"
      ;egqgztehhhklnherxdjckyxcwezhunlfuktgumuuvpsqutbehcmglqvbxrz
      shell=Open
      # Présence des fichiers :

      Found ! [29/03/2009 22:17][-rahs----] - C:\autorun.inf

      ################## [ Registre / Mountpoint2 ]

      # -> Not found !

      ################## [ ! Fin du rapport # FindyKill V4.721 ! ]

      Ensuite je lance le mode 2... et je poste la suite .
  3. Ensuite,on descend en profondeur de l'infection

    Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    -> http://images.malwareremoval.com/random/RSIT.exe

    ! Déconnecte toi et ferme toutes tes applications en cours !

    Double-clique sur " RSIT.exe " pour le lancer .

    -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    * Devant l'option "List files/folders created ..." , tu choisis : 2 months

    * clique ensuite sur " Continue " pour lancer l'analyse ...

    -> laisse faire le scan et ne touche pas au PC ...

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

    Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante
    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

    ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
    1. Bsr
      https://download.cnet.com/malwarebytes-anti-malware/windows.html?part=dl-10804572&subj=dl&tag=button
      installe , màj et scan complet
      post le rapport
      1. Ben tu peux faire la 2eme etape de findy kill pour virer l'autorun.Le reste demain
        1. Bon.... c'est un epu ce que je craignais :

          Je lance le mode 2 de findy, il reboot... et plantage au redémarrage "normal" sur ma fenêtre "bienvenu" de XP.

          Y aurai t il un bug sur XP lui même?

          Je vais faire dormir mon neurone . Merci a tous et a demain. Bonne nuit.
      2. Regardes demain s'il a édité un rapport.Sinon refais la procédure 2 et postes le rapport demain.Bonne soirée
        1. Y a du nouveau...
          après une seconde relance ce jour de findykill, je retombe sur un écran "bienvenu" de xp, figé.
          Blazé, je décide d'aller manger.
          A mon retour, je me retrouve avec mon fond d ecran, un findykill près au travail mais un message étrange:
          "exception Processing Message
          c0000013 parameters
          75afbf9c 4 75afbf9c" le tout dans une fenêtre du genre "pas de C:" et qui me demande réessayer, annuler, ignorer.

          Je réessaye... marche pas, je fais ignorer.... ça passe pas.... je recommence et paf.... la fenêtre diparait et findykill est au travail.

          Voila son rapport 2

          ############################## [ FindyKill V4.721 ]

          # User : Utilisateur (Administrateurs) # MAXDATA-831FA97
          # Update on 29/03/09 by Chiquitine29
          # Start at: 20:40:04 | 30/03/2009
          # Website : http://pagesperso-orange.fr/FindyKill.Ad.Remover/

          # Processeur Intel Pentium II
          # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
          # Internet Explorer 7.0.5730.11
          # Windows Firewall Status : Disabled
          # AV : avast! antivirus 4.8.1201 [VPS 090330-0] 4.8.1201 [ Enabled | Updated ]

          # A:\ # Lecteur de disquettes 3 ½ pouces
          # C:\ # Disque fixe local # 74,53 Go (48,83 Go free) # NTFS
          # D:\ # Disque CD-ROM
          # E:\ # Disque CD-ROM
          # F:\ # Disque amovible
          # G:\ # Disque amovible # 243,98 Mo (73,52 Mo free) [EOS_DIGITAL] # FAT
          # I:\ # Disque amovible
          # J:\ # Disque amovible

          ############################## [ Active Processes ]

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          ################## [ Infected Files / Folders C:\ ]

          ################## [ C:\WINDOWS & C:\WINDOWS\prefetch ]

          ################## [ C:\WINDOWS\System32 ]

          ################## [ C:\WINDOWS\System32\drivers ]

          ################## [ C:\.. Application Data ... ]

          ################## [ C:\Documents and Settings\Utilisateur\.....\Temp Files... ]

          Deleted ! - C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\eToroSetup.exe
          Deleted ! - C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\setup.exe
          Deleted ! - C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\Patcher\Patcher2608\RTPatch\patch.exe
          Deleted ! - C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\Patcher\Patcher2624\RTPatch\patch.exe
          Deleted ! - C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\Patcher\Patcher4032\RTPatch\patch.exe
          Deleted ! - C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\Patcher\Patcher4040\RTPatch\patch.exe

          ################## [ Registry / Infected keys ]

          ################## [ Cleaning Removable drives ]

          # Deleting Files :

          Deleted ! - C:\autorun.inf

          ################## [ Registry / Mountpoint2 ]

          # -> Not found !

          ################## [ States / Restarting of services ]

          # Services : [ Auto=2 / Request=3 / Disable=4 ]

          # Ndisuio -> # Type of startup =3
          # Ip6Fw -> # Type of startup =2
          # SharedAccess -> # Type of startup =2
          # wuauserv -> # Type of startup =2
          # wscsvc -> # Type of startup =2

          ################## [ Searching Other Infections ]

          # -> Nothing found.

          ################## [ ! End of Report # FindyKill V4.721 ! ]
      3. Ensuite on vire le surplus de tracking cookies

        Télécharge Superantispyware (SAS)

        Choisis "enregistrer" et enregistre-le sur ton bureau.

        Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

        Créé une icône sur le bureau.

        Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

        - Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
        - Sous Configuration and Preferences, clique sur le bouton "Preferences"
        - Clique sur l'onglet "Scanning Control "
        - Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

        Close browsers before scanning
        Scan for tracking cookies
        Terminate memory threats before quarantining
        - Laisse les autres lignes décochées.

        - Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

        - Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

        Dans la colonne de gauche, coche C:\Fixed Drive.

        Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

        Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

        A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

        Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

        Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

        Pour recopier les informations sur le forum, fais ceci :

        - après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
        - Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
        - Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

        - Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

        - Copie son contenu dans ta réponse.

        Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
        1. ok.... je vais faire ça de suite.

          Avant j 'ai passé mon PC sous RSIT

          info.txt

          info.txt logfile of random's system information tool 1.06 2009-03-30 22:02:45

          ======Uninstall list======

          -->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
          -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
          -->C:\Program Files\MAGIX\Speed2_burnR_mxcdr\unwise.exe
          -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          ACDSee Photo Editor 2008-->MsiExec.exe /I{A6142247-58B1-40C7-B8E0-965C1A8026A5}
          ACDSee Pro 2.5-->MsiExec.exe /I{2D95950E-6D76-43E7-94A5-D9DBA2FD29E4}
          Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
          Adobe Bridge 1.0-->MsiExec.exe /I{B74D4E10-1033-0000-0000-000000000001}
          Adobe Color Common Settings-->C:\Program Files\Fichiers communs\Adobe\Installers\6c8e2cb4fd241c55406016127a6ab2e\Setup.exe
          Adobe Color Common Settings-->MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}
          Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
          Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Help Center 1.0-->MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
          Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
          Adobe Photoshop CS2-->msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
          Adobe Photoshop CS3-->MsiExec.exe /I{BF794769-8875-4E01-B7BE-E00104604F4A}
          Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
          Adobe Setup-->MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}
          Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
          Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
          Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
          AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
          Blender (remove only)-->"C:\Program Files\Blender Foundation\Blender\uninstall.exe"
          Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
          Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB914440)-->"C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB935448)-->"C:\WINDOWS\$NtUninstallKB935448$\spuninst\spuninst.exe"
          Correctif Windows XP - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
          Correctif Windows XP - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
          Correctif Windows XP - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
          Correctif Windows XP - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
          Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
          Correctif Windows XP - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
          Correctif Windows XP - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
          Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
          CuteFTP 5.0 XP-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{18DF995F-2ACC-47E4-A33B-A703F4D39E92}\Setup.exe" -l0x40c /l040C UNINSTALL
          DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
          DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
          DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
          DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
          DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
          eMule-->"C:\Program Files\eMule\Uninstall.exe"
          FileZilla Client 3.1.2-->C:\Program Files\FileZilla FTP Client\uninstall.exe
          FindyKill-->C:\FindyKill\Uninstal.exe
          Firebird SQL Server - MAGIX Edition-->C:\Program Files\MAGIX\Common\Database\unwise.exe
          Freeplayer-->C:\Program Files\Freeplayer\Uninstall.exe
          Google Earth Plugin-->MsiExec.exe /I{F43C7DE1-CB20-11DD-8D77-005056806466}
          Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
          High Definition Audio - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
          HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
          Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
          Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
          Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
          IEEE 802.11b WLAN Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9EC7F942-836F-4D62-ADBD-9C65ADB66220}\Setup.exe" -l0x9
          Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
          iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
          iWizz-->C:\Program Files\iWizz\uninstall.exe
          Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
          Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
          LightZone 3.6.1-->C:\Program Files\LightZone 3\uninstall.exe
          MAGIX 3D Maker (embeded)-->C:\Program Files\MAGIX\Common\3D_Maker_embeded\unwise.exe
          MAGIX Screenshare 4.3.6.1987 (F)-->C:\Program Files\MAGIX\PCVisit\unwise.exe
          MAGIX Vidéo deluxe 15 Plus Version à télécharger 8.0.2.5 (F)-->C:\Program Files\MAGIX\Video_deluxe_15_Plus_Version_a_telecharger\unwise.exe
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
          Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
          Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
          Microsoft .NET Framework 3.0 French Language Pack-->MsiExec.exe /X{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}
          Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
          Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
          Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
          Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
          Microsoft Office PowerPoint Viewer 2003-->MsiExec.exe /X{90AF040C-6000-11D3-8CFE-0150048383C9}
          Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
          Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Mise à jour de sécurité pour Lecteur Windows Media (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 9 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB896424)-->"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB899589)-->"C:\WINDOWS\$NtUninstallKB899589$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB911567)-->"C:\WINDOWS\$NtUninstallKB911567$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB912919)-->"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB917422)-->"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920214)-->"C:\WINDOWS\$NtUninstallKB920214$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB921398)-->"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB921883)-->"C:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB922616)-->"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB924191)-->"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB937894)-->"C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB904942)-->"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB920342)-->"C:\WINDOWS\$NtUninstallKB920342$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB925720)-->"C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB925876)-->"C:\WINDOWS\$NtUninstallKB925876$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB936357)-->"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
          Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
          Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 French Language Pack\setup.exe
          Monopoly Deluxe-->"C:\Program Files\Zylom Games\Monopoly Deluxe\GameInstlr.exe" --uninstall UnInstall.log
          Mozilla Firefox (3.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
          Neat Image v5 Demo (with plug-in)-->"C:\Program Files\Neat Image\unins000.exe"
          Nero MediaHome 4-->C:\Program Files\Fichiers communs\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="9M06-01C3-PZT6-AK05-37L3-2TU5-3U76-8XPX"
          Nero Suite-->C:\Program Files\Fichiers communs\Ahead\Uninstall\Setup.exe /uninstall
          Package de base Microsoft de service de chiffrement pour cartes à puce-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
          PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
          PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
          PhotoTools 1.0 Professional Edition-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B01DD5B7-9862-43D7-BCA3-7882A17E4328}\setup.exe" -l0x9 -uninst -removeonly
          Portrait Professional Max 6.3-->"C:\Program Files\Portrait Professional Max 6\unins000.exe"
          QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
          R.C. Cars-->MsiExec.exe /X{FDACD776-2B0F-427F-95BD-FAF664D75308}
          Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
          Ri4m v5.0.1d-->C:\Program Files\Ripp-it_AM\Ri4m_Uninstal.exe
          Ripp-It Codec Pack v 4.2.6-->C:\Program Files\Ripp-It Codec Pack\uninst.exe
          Search Settings 1.2-->MsiExec.exe /X{D0C73318-7B4A-4D16-A0C4-3B83F075EA88}
          SUPER © Version 2009.bld.35 (Jan 5, 2009)-->C:\PROGRA~1\SUPER\Setup.exe /remove /q0
          Tunatic-->"C:\WINDOWS\lsb_un20.exe" /C=UC /N=Tunatic
          Turbo Photo 6.2-->"C:\Program Files\Turbo Photo\unins000.exe"
          VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
          VirtuaGirl HD-->C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\VirtuaGirl HD\uninstall.lnk
          Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
          Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
          Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
          Windows Media Format SDK Hotfix - KB891122-->"C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
          Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
          Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
          Windows Presentation Foundation Language Pack (FRA)-->MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
          Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
          Windows Workflow Foundation FR Language Pack-->MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}
          Xara3D6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{64C96428-3A75-4AAE-A538-C450EF68175F}\setup.exe" -l0x9
          XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
          Xvid 1.1.2 final uninstall-->"C:\Program Files\Xvid\unins000.exe"

          =====HijackThis Backups=====

          O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll [2009-03-29]

          ======Hosts File======

          127.0.0.1 activate.adobe.com

          ======Security center information======

          AV: avast! antivirus 4.8.1201 [VPS 090330-0]

          ======System event log======

          Computer Name: MAXDATA-831FA97
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service NLA (Network Location Awareness).

          Record Number: 14094
          Source Name: Service Control Manager
          Time Written: 20090210133649.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: MAXDATA-831FA97
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service Service de transfert intelligent en arrière-plan.

          Record Number: 14093
          Source Name: Service Control Manager
          Time Written: 20090210133649.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: MAXDATA-831FA97
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service avast! Web Scanner.

          Record Number: 14092
          Source Name: Service Control Manager
          Time Written: 20090210133649.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: MAXDATA-831FA97
          Event Code: 7036
          Message: Le service avast! Mail Scanner est entré dans l'état : en cours d'exécution.

          Record Number: 14091
          Source Name: Service Control Manager
          Time Written: 20090210133649.000000+060
          Event Type: Informations
          User:

          Computer Name: MAXDATA-831FA97
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service avast! Mail Scanner.

          Record Number: 14090
          Source Name: Service Control Manager
          Time Written: 20090210133649.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          =====Application event log=====

          Computer Name: MAXDATA-831FA97
          Event Code: 1517
          Message: Windows a sauvegardé le Registre utilisateur MAXDATA-831FA97\Utilisateur alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.

          Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

          Record Number: 1533
          Source Name: Userenv
          Time Written: 20090315215901.000000+060
          Event Type: Avertissement
          User: AUTORITE NT\SYSTEM

          Computer Name: MAXDATA-831FA97
          Event Code: 11707
          Message: Product: R.C. Cars -- Installation operation completed successfully.

          Record Number: 1532
          Source Name: MsiInstaller
          Time Written: 20090315120426.000000+060
          Event Type: Informations
          User: MAXDATA-831FA97\Utilisateur

          Computer Name: MAXDATA-831FA97
          Event Code: 0
          Message:
          Record Number: 1531
          Source Name: gupdate1c985373d23476c
          Time Written: 20090315094117.000000+060
          Event Type: Informations
          User:

          Computer Name: MAXDATA-831FA97
          Event Code: 1800
          Message: Le service Centre de sécurité Windows a démarré.

          Record Number: 1530
          Source Name: SecurityCenter
          Time Written: 20090315094104.000000+060
          Event Type: Informations
          User:

          Computer Name: MAXDATA-831FA97
          Event Code: 1
          Message:
          Record Number: 1529
          Source Name: Bonjour Service
          Time Written: 20090315094048.000000+060
          Event Type: Informations
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Fichiers communs\Adobe\AGL;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Fichiers communs\DivX Shared\
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 22 Stepping 1, GenuineIntel
          "PROCESSOR_REVISION"=1601
          "NUMBER_OF_PROCESSORS"=1
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
          "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

          -----------------EOF-----------------
        2. @yarnet son copain le log.txt

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Utilisateur at 2009-03-30 22:02:41
          Microsoft Windows XP Professionnel Service Pack 2
          System drive C: has 49 GB (65%) free of 76 GB
          Total RAM: 503 MB (42% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 22:02:44, on 30/03/2009
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16608)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\WINDOWS\explorer.exe
          C:\Documents and Settings\Utilisateur\Bureau\RSIT.exe
          C:\Program Files\Trend Micro\HijackThis\Utilisateur.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - Default URLSearchHook is missing
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-21-730956478-3185035934-520569064-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'NeroMediaHomeUser.4')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: WLANUtility.lnk = C:\Program Files\IEEE 802.11b WLAN Utility\WLANUtil.exe
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: Google Update Service (gupdate1c985373d23476c) (gupdate1c985373d23476c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: Nero MediaHome 4 Service (NeroMediaHomeService.4) - Nero AG - C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
      4. Postes le rapport Superantispyware,tu as encore de belles infections
        1. Et hop le rapport a 5h47 de SAS. Je l'ai laissé mettre en 40aine

          SUPERAntiSpyware Scan Log
          https://www.superantispyware.com/

          Generated 03/30/2009 at 11:24 PM

          Application Version : 4.26.1000

          Core Rules Database Version : 3820
          Trace Rules Database Version: 1774

          Scan type : Complete Scan
          Total Scan Time : 01:03:30

          Memory items scanned : 447
          Memory threats detected : 0
          Registry items scanned : 4452
          Registry threats detected : 1
          File items scanned : 83845
          File threats detected : 6

          Unclassified.Unknown Origin
          HKU\S-1-5-21-730956478-3185035934-520569064-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}

          Adware.Tracking Cookie
          C:\Documents and Settings\Utilisateur\Cookies\utilisateur@doubleclick[2].txt
          C:\Documents and Settings\Utilisateur\Cookies\utilisateur@adultfriendfinder[2].txt
          C:\Documents and Settings\Utilisateur\Cookies\utilisateur@adbrite[2].txt
          C:\Documents and Settings\Utilisateur\Cookies\utilisateur@xiti[1].txt
          C:\Documents and Settings\Utilisateur\Cookies\utilisateur@smartadserver[1].txt

          Trojan.Unknown Origin
          C:\WINDOWS\SYSTEM32\VGHD.SCR
      5. Relances hijack this,puis "do a scan only",puis coches les lignes ci dessous et fix

        R3 - Default URLSearchHook is missing
        O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll

        Ensuite:

        ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

        ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :

        http://oldtimer.geekstogo.com/OTMoveIt3.exe

        ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

        ---> Copie (Ctrl+C) le texte suivant ci-dessous :

        :processes
        explorer.exe

        :files
        c:\program files\search settings\kb127\searchsettings.dll

        :reg
        [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]

        :commands
        [purity]
        [emptytemp]
        [start explorer]
        [reboot]

        ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

        ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

        Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
        Accepte en cliquant sur YES.

        ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
        Le nom du rapport correspond au moment de sa création : date_heure.log
        1. ========== PROCESSES ==========
          Process explorer.exe killed successfully.
          ========== FILES ==========
          File/Folder c:\program files\search settings\kb127\searchsettings.dll not found.
          ========== REGISTRY ==========
          Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\\ not found.
          Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\\ not found.
          ========== COMMANDS ==========
          File delete failed. C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\etilqs_sqFMGZHJHnGm2LZZYRde scheduled to be deleted on reboot.
          File delete failed. C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\~DF7441.tmp scheduled to be deleted on reboot.
          User's Temp folder emptied.
          User's Temporary Internet Files folder emptied.
          User's Internet Explorer cache folder emptied.
          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
          Local Service Temp folder emptied.
          Local Service Temporary Internet Files folder emptied.
          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5c8.dat scheduled to be deleted on reboot.
          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_68c.dat scheduled to be deleted on reboot.
          Windows Temp folder emptied.
          Java cache emptied.
          File delete failed. C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\XUL.mfl scheduled to be deleted on reboot.
          FireFox cache emptied.
          Temp folders emptied.
          Explorer started successfully

          OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03312009_055349

          Files moved on Reboot...
          File C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\etilqs_sqFMGZHJHnGm2LZZYRde not found!
          C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\~DF7441.tmp moved successfully.
          File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
          File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be moved on reboot.
          File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
          File C:\WINDOWS\temp\Perflib_Perfdata_5c8.dat not found!
          File C:\WINDOWS\temp\Perflib_Perfdata_68c.dat not found!
          C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_001_ moved successfully.
          C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_002_ moved successfully.
          C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_003_ moved successfully.
          C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_MAP_ moved successfully.
          C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\urlclassifier3.sqlite moved successfully.
          C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\XUL.mfl moved successfully.
      6. Ensuite:

        1/Télécharge ToolBar S&D ( de Eric_71/Team IDN ) sur ton bureau :
        https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

        ( Tuto : https://sites.google.com/site/toolbarsd/aideenimages )

        !! Déconnecte toi et ferme toutes tes applications en cours le temps de la manipe !!

        * Double-clique sur ToolBar SD.exe pour lancer l'outil et laisse toi guider ...
        --> Tapes ( option " recherche " ) puis tape sur [Entrée].

        Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse

        ( le rapport est en outre sauvegardé ici -> C:\TB.txt )

        2/
        Relance Toolbar-S&D en double-cliquant sur le raccourci
        .
        Ø Tape sur "2" puis valide en appuyant sur "Entrée".

        ! Ne ferme pas la fenêtre lors de la suppression !

        Un rapport sera généré, poste son contenu ici.

        NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
        Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
        Tape explorer puis valide.

        Ensuite refais procedure 1 et 2 findy kill,il y a encore un autorun a virer

        3/
        Telecharge maintenant FindyKill sur ton bureau :

        http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

        --> Lance l installation avec les parametres par default

        --> Au menu principal,choisi l option 1 (Recherche)

        --> Post le rapport FindyKill.txt

        Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

        4/
        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

        --> Fais clic droit sur le raccourci FindyKill sur ton bureau

        --> Au menu principal,choisi l option 2 (Suppression)

        /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

        /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

        -------> ensuite post le rapport FindyKill.txt

        Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
        1. annalyse 1 TB

          -----------\\ ToolBar S&D 1.2.8 XP/Vista

          Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
          X86-based PC ( Uniprocessor Free : Processeur Intel Pentium II )
          BIOS : Default System BIOS
          USER : Utilisateur ( Not Administrator ! )
          BOOT : Normal boot
          Antivirus : avast! antivirus 4.8.1201 [VPS 090330-0] 4.8.1201 (Activated)
          A:\ (USB)
          C:\ (Local Disk) - NTFS - Total:74 Go (Free:49 Go)
          D:\ (CD or DVD)
          E:\ (CD or DVD)
          F:\ (USB)
          G:\ (USB) - FAT - Total:243 Mo (Free:0 Go)
          I:\ (USB)
          J:\ (USB)

          "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
          Option : [1] ( 31/03/2009| 6:04 )

          -----------\\ Recherche de Fichiers / Dossiers ...

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Start Page"="https://gamespace.daemon-tools.cc/fra/home"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Start Page"="https://www.msn.com/fr-fr/"
          "Search Bar"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"

          --------------------\\ Recherche d'autres infections

          Aucune autre infection trouvée !

          1 - "C:\ToolBar SD\TB_1.txt" - 30/03/2009| 0:00 - Option : [1]
          2 - "C:\ToolBar SD\TB_2.txt" - 30/03/2009| 0:03 - Option : [2]
          3 - "C:\ToolBar SD\TB_3.txt" - 31/03/2009| 6:05 - Option : [1]
        2. @yarnanalyse 2 TB

          -----------\\ ToolBar S&D 1.2.8 XP/Vista

          Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
          X86-based PC ( Uniprocessor Free : Processeur Intel Pentium II )
          BIOS : Default System BIOS
          USER : Utilisateur ( Not Administrator ! )
          BOOT : Normal boot
          Antivirus : avast! antivirus 4.8.1201 [VPS 090330-0] 4.8.1201 (Activated)
          A:\ (USB)
          C:\ (Local Disk) - NTFS - Total:74 Go (Free:49 Go)
          D:\ (CD or DVD)
          E:\ (CD or DVD)
          F:\ (USB)
          G:\ (USB) - FAT - Total:243 Mo (Free:0 Go)
          I:\ (USB)
          J:\ (USB)

          "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
          Option : [2] ( 31/03/2009| 6:06 )

          -----------\\ Recherche de Fichiers / Dossiers ...

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Start Page"="https://gamespace.daemon-tools.cc/fra/home"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Start Page"="https://www.msn.com/fr-fr/"
          "Search Bar"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"

          --------------------\\ Recherche d'autres infections

          Aucune autre infection trouvée !

          1 - "C:\ToolBar SD\TB_1.txt" - 30/03/2009| 0:00 - Option : [1]
          2 - "C:\ToolBar SD\TB_2.txt" - 30/03/2009| 0:03 - Option : [2]
          3 - "C:\ToolBar SD\TB_3.txt" - 31/03/2009| 6:05 - Option : [1]
          4 - "C:\ToolBar SD\TB_4.txt" - 31/03/2009| 6:06 - Option : [2]
        3. @yarnanalyse 1 findy

          ############################## [ FindyKill V4.721 ]

          # User : Utilisateur (Administrateurs) # MAXDATA-831FA97
          # Update on 29/03/09 by Chiquitine29
          # Start at: 06:30:42 | 31/03/2009
          # Website : http://pagesperso-orange.fr/FindyKill.Ad.Remover/

          # Processeur Intel Pentium II
          # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
          # Internet Explorer 7.0.5730.11
          # Windows Firewall Status : Disabled
          # AV : avast! antivirus 4.8.1201 [VPS 090330-0] 4.8.1201 [ Enabled | Updated ]

          # A:\ # Lecteur de disquettes 3 ½ pouces
          # C:\ # Disque fixe local # 74,53 Go (49,26 Go free) # NTFS
          # D:\ # Disque CD-ROM
          # E:\ # Disque CD-ROM
          # F:\ # Disque amovible
          # G:\ # Disque amovible # 243,98 Mo (73,52 Mo free) [EOS_DIGITAL] # FAT
          # I:\ # Disque amovible
          # J:\ # Disque amovible

          ############################## [ Processus actifs ]

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          C:\Program Files\IEEE 802.11b WLAN Utility\WLANUtil.exe
          C:\Program Files\Java\jre6\bin\jucheck.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          ################## [ Fichiers / Dossiers infectieux C:\ ]

          ################## [ C:\WINDOWS & C:\WINDOWS\Prefetch ]

          ################## [ C:\WINDOWS\system32 ]

          ################## [ C:\WINDOWS\system32\drivers ]

          ################## [ C:\.. Application Data ... ]

          ################## [ C:\Users...\Temp Files... ]

          ################## [ Registre / Clés infectieuses ]

          ################## [ Recherche dans supports amovibles]

          # Présence des fichiers :

          ################## [ Registre / Mountpoint2 ]

          # -> Not found !

          ################## [ ! Fin du rapport # FindyKill V4.721 ! ]
        4. Analyse 2 de findykill

          ############################## [ FindyKill V4.721 ]

          # User : Utilisateur (Administrateurs) # MAXDATA-831FA97
          # Update on 29/03/09 by Chiquitine29
          # Start at: 06:37:35 | 31/03/2009
          # Website : http://pagesperso-orange.fr/FindyKill.Ad.Remover/

          # Processeur Intel Pentium II
          # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
          # Internet Explorer 7.0.5730.11
          # Windows Firewall Status : Disabled
          # AV : avast! antivirus 4.8.1201 [VPS 090330-0] 4.8.1201 [ Enabled | Updated ]

          # A:\ # Lecteur de disquettes 3 ½ pouces
          # C:\ # Disque fixe local # 74,53 Go (49,25 Go free) # NTFS
          # D:\ # Disque CD-ROM
          # E:\ # Disque CD-ROM
          # F:\ # Disque amovible
          # G:\ # Disque amovible # 243,98 Mo (73,52 Mo free) [EOS_DIGITAL] # FAT
          # I:\ # Disque amovible
          # J:\ # Disque amovible

          ############################## [ Active Processes ]

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          C:\Program Files\IEEE 802.11b WLAN Utility\WLANUtil.exe
          C:\Program Files\Java\jre6\bin\jucheck.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          ################## [ Infected Files / Folders C:\ ]

          ################## [ C:\WINDOWS & C:\WINDOWS\prefetch ]

          Deleted ! - C:\WINDOWS\prefetch\WINUPGRO.EXE-17681AA8.pf

          ################## [ C:\WINDOWS\System32 ]

          ################## [ C:\WINDOWS\System32\drivers ]

          ################## [ C:\.. Application Data ... ]

          ################## [ C:\Documents and Settings\Utilisateur\.....\Temp Files... ]

          ################## [ Registry / Infected keys ]

          ################## [ Cleaning Removable drives ]

          # Deleting Files :

          ################## [ Registry / Mountpoint2 ]

          # -> Not found !

          ################## [ States / Restarting of services ]

          # Services : [ Auto=2 / Request=3 / Disable=4 ]

          # Ndisuio -> # Type of startup =3
          # Ip6Fw -> # Type of startup =2
          # SharedAccess -> # Type of startup =2
          # wuauserv -> # Type of startup =2
          # wscsvc -> # Type of startup =2

          ################## [ Searching Other Infections ]

          # -> Nothing found.

          ################## [ ! End of Report # FindyKill V4.721 ! ]
      7. Télécharge Superantispyware (SAS)

        Choisis "enregistrer" et enregistre-le sur ton bureau.

        Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

        Créé une icône sur le bureau.

        Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

        - Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
        - Sous Configuration and Preferences, clique sur le bouton "Preferences"
        - Clique sur l'onglet "Scanning Control "
        - Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

        Close browsers before scanning
        Scan for tracking cookies
        Terminate memory threats before quarantining
        - Laisse les autres lignes décochées.

        - Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

        - Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

        Dans la colonne de gauche, coche C:\Fixed Drive.

        Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

        Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

        A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

        Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

        Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

        Pour recopier les informations sur le forum, fais ceci :

        - après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
        - Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
        - Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

        - Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

        - Copie son contenu dans ta réponse.

        Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
        1. voila le rapport

          SUPERAntiSpyware Scan Log
          https://www.superantispyware.com/

          Generated 03/30/2009 at 11:24 PM

          Application Version : 4.26.1000

          Core Rules Database Version : 3820
          Trace Rules Database Version: 1774

          Scan type : Complete Scan
          Total Scan Time : 01:03:30

          Memory items scanned : 447
          Memory threats detected : 0
          Registry items scanned : 4452
          Registry threats detected : 1
          File items scanned : 83845
          File threats detected : 6

          Unclassified.Unknown Origin
          HKU\S-1-5-21-730956478-3185035934-520569064-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}

          Adware.Tracking Cookie
          C:\Documents and Settings\Utilisateur\Cookies\utilisateur@doubleclick[2].txt
          C:\Documents and Settings\Utilisateur\Cookies\utilisateur@adultfriendfinder[2].txt
          C:\Documents and Settings\Utilisateur\Cookies\utilisateur@adbrite[2].txt
          C:\Documents and Settings\Utilisateur\Cookies\utilisateur@xiti[1].txt
          C:\Documents and Settings\Utilisateur\Cookies\utilisateur@smartadserver[1].txt

          Trojan.Unknown Origin
          C:\WINDOWS\SYSTEM32\VGHD.SCR

          c'est toujours pas clean mais mon PC 'tourne" en mode normal. Il a toutefois un peu ma réactivité lorsque j'ai descendu une bouteille de vodka sans avoir dormi pendant 4 jours pendant une conférence sur "la prépondérance de l'efficience dans une société contractuellement libérale" ...
      8. Mdr,belle image.Je te donne une procedure.Je reprendrais ensuite la desinfection ce we car je pars a l 'etranger jusqu'a samedi.

        Télécharge SDFix sur ton bureau :
        ici http://downloads.andymanchesta.com/RemovalTools/SDFix.exe.
        ou ici http://download.bleepingcomputer.com/andymanchesta/SDFix.exe­
        ou ici http://sdfix.net/SDFix.exe

        --> Double-clique sur SDFix.exe et choisis "Install" .

        ( tuto ici : https://www.malekal.com/slenfbot-still-an-other-irc-bot/ )

        Puis une fois l'installe faite ,

        Impératif : Démarrer en mode sans echec .

        /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

        Comment aller en Mode sans échec :
        1) Redémarre ton ordi .
        2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
        3) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
        4) Choisis la première option : Sans Échec , et valide en tapant sur [Entrée] .
        5) Choisis ton compte habituel ( et pas Administrateur ).
        attention : pas de connexion possible en mode sans échec , donc copie ou imprime bien la manipe pour éviter les erreurs ...

        Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double-clique sur RunThis.bat pour lancer l'outil .
        -->Tapes Y pour lancer le script ...
        Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire , donc :
        presses une touche pour redémarrer quand il te le sera demandé .

        Le PC va mettre du temps avant de démarrer ( c'est normale ), après le chargement du Bureau presses une touche lorsque "Finished" s'affiche .

        Le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier
        C:\SDFix sous le nom "Report.txt".

        Ensuite repostes un Rsit tout neuf (supprimes les anciens rapports avant de relancer le scan).Je regarderais ca en rentrant.

        Je vais demander sinon a un confrere deviruseur de te donner un coup de main,car ton pc en a besoin

        ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

        Bonne fin de soirée
        1. Merci pour tout et profites de ton voyage!

          Déja je peux bosser et avancer dans mon projet. A ce titre, je te suis infiniment reconnaissant !

          [b]SDFix: Version 1.240 [/b]
          Run by Utilisateur on 01/04/2009 at 15:02

          Microsoft Windows XP [version 5.1.2600]
          Running From: C:\SDFix

          [b]Checking Services [/b]:

          Restoring Default Security Values
          Restoring Default Hosts File

          Rebooting

          [b]Checking Files [/b]:

          No Trojan Files Found

          Removing Temp Files

          [b]ADS Check [/b]:

          [b]Final Check [/b]:

          catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2009-04-01 15:13:51
          Windows 5.1.2600 Service Pack 2 NTFS

          scanning hidden processes ...

          scanning hidden services & system hive ...

          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gaopdxserv.sys]
          "start"=dword:00000001
          "type"=dword:00000001
          "imagepath"=str(2):"\systemroot\system32\drivers\gaopdxrdyevkaybomydgeqpxggxujcxxxsabkw.sys"
          "group"="file system"

          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gaopdxserv.sys\modules]
          "gaopdxserv"="\\?\globalroot\systemroot\system32\drivers\gaopdxrdyevkaybomydgeqpxggxujcxxxsabkw.sys"
          "gaopdxl"="\\?\globalroot\systemroot\system32\gaopdxupqeoaktprbkqddovjfntbiqjikhbfrl.dll"
          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
          "p0"="C:\Program Files\DAEMON Tools Lite\"
          "h0"=dword:00000000
          "khjeh"=hex:72,7b,cd,47,c9,f6,b5,f4,9d,11,d4,9a,bb,9b,ae,3a,40,db,41,8d,ca,..

          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
          "a0"=hex:20,01,00,00,6b,6a,d2,70,20,9c,70,7c,6f,ee,44,ef,6d,fd,4c,82,bd,..
          "khjeh"=hex:40,f2,1c,4a,0f,c7,20,32,70,55,3c,27,1d,32,19,b2,d3,63,7a,cf,19,..

          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
          "khjeh"=hex:1f,33,d1,6f,bd,dd,fd,d2,cc,f1,c7,80,cd,8a,d9,6e,a5,69,f4,3b,29,..
          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\gaopdxserv.sys]
          "start"=dword:00000001
          "type"=dword:00000001
          "imagepath"=str(2):"\systemroot\system32\drivers\gaopdxrdyevkaybomydgeqpxggxujcxxxsabkw.sys"
          "group"="file system"
          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
          "p0"="C:\Program Files\DAEMON Tools Lite\"
          "h0"=dword:00000000
          "khjeh"=hex:72,7b,cd,47,c9,f6,b5,f4,9d,11,d4,9a,bb,9b,ae,3a,40,db,41,8d,ca,..

          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
          "a0"=hex:20,01,00,00,6b,6a,d2,70,20,9c,70,7c,6f,ee,44,ef,6d,fd,4c,82,bd,..
          "khjeh"=hex:40,f2,1c,4a,0f,c7,20,32,70,55,3c,27,1d,32,19,b2,d3,63,7a,cf,19,..

          [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
          "khjeh"=hex:1f,33,d1,6f,bd,dd,fd,d2,cc,f1,c7,80,cd,8a,d9,6e,a5,69,f4,3b,29,..
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys]
          "start"=dword:00000001
          "type"=dword:00000001
          "imagepath"=str(2):"\systemroot\system32\drivers\gaopdxrdyevkaybomydgeqpxggxujcxxxsabkw.sys"
          "group"="file system"
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
          "s1"=dword:2df9c43f
          "s2"=dword:110480d0
          "h0"=dword:00000001

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
          "p0"="C:\Program Files\DAEMON Tools Lite\"
          "h0"=dword:00000000
          "khjeh"=hex:72,7b,cd,47,c9,f6,b5,f4,9d,11,d4,9a,bb,9b,ae,3a,40,db,41,8d,ca,..

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
          "a0"=hex:20,01,00,00,6b,6a,d2,70,20,9c,70,7c,6f,ee,44,ef,6d,fd,4c,82,bd,..
          "khjeh"=hex:40,f2,1c,4a,0f,c7,20,32,70,55,3c,27,1d,32,19,b2,d3,63,7a,cf,19,..

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
          "khjeh"=hex:1f,33,d1,6f,bd,dd,fd,d2,cc,f1,c7,80,cd,8a,d9,6e,a5,69,f4,3b,29,..

          scanning hidden registry entries ...

          scanning hidden files ...

          scan completed successfully
          hidden processes: 0
          hidden services: 0
          hidden files: 0

          [b]Remaining Services [/b]:

          Authorized Application Key Export:

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
          "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
          "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
          "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
          "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
          "C:\\Windows\\system32\\javaw.exe"="C:\\Windows\\system32\\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
          "C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"="C:\\Program Files\\Freeplayer\\vlc\\vlc.exe:*:Enabled:VLC media player"
          "C:\\Windows\\system32\\dpvsetup.exe"="C:\\Windows\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
          "C:\\Windows\\system32\\rundll32.exe"="C:\\Windows\\system32\\rundll32.exe:*:Enabled:Ex‚cuter une DLL en tant qu'application"
          "C:\\Program Files\\Nero\\Nero MediaHome 4\\NMMediaServerService.exe"="C:\\Program Files\\Nero\\Nero MediaHome 4\\NMMediaServerService.exe:*:Enabled:Nero MediaHome 4"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

          [b]Remaining Files [/b]:

          [b]Files with Hidden Attributes [/b]:

          Sun 26 Jun 2005 616,448 ..SHR --- "C:\Program Files\SUPER\cygwin1.dll"
          Tue 21 Jun 2005 45,568 ..SHR --- "C:\Program Files\SUPER\cygz.dll"
          Fri 9 Jan 2009 90,624 ..SHR --- "C:\Program Files\SUPER\Setup.exe"
          Mon 20 Oct 2008 16,447 A.SHR --- "C:\Program Files\SUPER\_Setup.dll"
          Wed 3 May 2006 163,328 ..SHR --- "C:\Windows\system32\flvDX.dll"
          Wed 21 Feb 2007 31,232 ..SHR --- "C:\Windows\system32\msfDX.dll"
          Sun 16 Mar 2008 216,064 ..SHR --- "C:\Windows\system32\nbDX.dll"
          Fri 23 May 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
          Mon 8 Dec 2008 74 A..H. --- "C:\Program Files\GlobalSCAPE\CuteFTPFR\cuteftp.sys"
          Tue 4 Jun 2002 84,992 ...HR --- "C:\Program Files\SUPER\mencoder\14_43260.dll"
          Tue 4 Jun 2002 44,032 ...HR --- "C:\Program Files\SUPER\mencoder\28_83260.dll"
          Tue 10 Dec 2002 73,766 ...HR --- "C:\Program Files\SUPER\mencoder\atrc3260.dll"
          Tue 10 Dec 2002 65,575 ...HR --- "C:\Program Files\SUPER\mencoder\cook3260.dll"
          Sun 9 Jun 2002 36,864 ...HR --- "C:\Program Files\SUPER\mencoder\ddnt3260.dll"
          Tue 4 Jun 2002 20,480 ...HR --- "C:\Program Files\SUPER\mencoder\dnet3260.dll"
          Tue 10 Dec 2002 102,437 ...HR --- "C:\Program Files\SUPER\mencoder\drv13260.dll"
          Tue 10 Dec 2002 176,165 ...HR --- "C:\Program Files\SUPER\mencoder\drv23260.dll"
          Tue 10 Dec 2002 208,935 ...HR --- "C:\Program Files\SUPER\mencoder\drv33260.dll"
          Tue 10 Dec 2002 217,127 ...HR --- "C:\Program Files\SUPER\mencoder\drv43260.dll"
          Sun 9 Jun 2002 40,448 ...HR --- "C:\Program Files\SUPER\mencoder\dspr3260.dll"
          Sun 4 Nov 2001 225,280 ...HR --- "C:\Program Files\SUPER\mencoder\ivvideo.dll"
          Tue 10 Apr 2001 225,280 ...HR --- "C:\Program Files\SUPER\mencoder\qtmlClient.dll"
          Fri 20 Feb 2004 232,960 ...HR --- "C:\Program Files\SUPER\mencoder\raac.dll"
          Sun 9 Jun 2002 525,824 ...HR --- "C:\Program Files\SUPER\mencoder\rnco3260.dll"
          Tue 10 Dec 2002 245,805 ...HR --- "C:\Program Files\SUPER\mencoder\rnlt3260.dll"
          Tue 10 Dec 2002 45,093 ...HR --- "C:\Program Files\SUPER\mencoder\rv103260.dll"
          Tue 10 Dec 2002 98,341 ...HR --- "C:\Program Files\SUPER\mencoder\rv203260.dll"
          Tue 10 Dec 2002 94,247 ...HR --- "C:\Program Files\SUPER\mencoder\rv303260.dll"
          Tue 10 Dec 2002 90,151 ...HR --- "C:\Program Files\SUPER\mencoder\rv403260.dll"
          Tue 10 Dec 2002 102,439 ...HR --- "C:\Program Files\SUPER\mencoder\sipr3260.dll"
          Sun 9 Jun 2002 49,152 ...HR --- "C:\Program Files\SUPER\mencoder\tokr3260.dll"
          Thu 20 Mar 2008 5,632 ..SHR --- "C:\Program Files\SUPER\spk\1stRun.exe"
          Tue 26 Feb 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"

          [b]Finished![/b]
        2. le rsit LOG

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Utilisateur at 2009-04-01 15:29:01
          Microsoft Windows XP Professionnel Service Pack 2
          System drive C: has 50 GB (65%) free of 76 GB
          Total RAM: 503 MB (19% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 15:29:10, on 01/04/2009
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16608)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          C:\Program Files\IEEE 802.11b WLAN Utility\WLANUtil.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Java\jre6\bin\jucheck.exe
          C:\Documents and Settings\Utilisateur\Bureau\RSIT.exe
          C:\Program Files\Trend Micro\HijackThis\Utilisateur.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://gamespace.daemon-tools.cc/fra/home
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - Default URLSearchHook is missing
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-21-730956478-3185035934-520569064-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'NeroMediaHomeUser.4')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: WLANUtility.lnk = C:\Program Files\IEEE 802.11b WLAN Utility\WLANUtil.exe
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
          O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: Google Update Service (gupdate1c985373d23476c) (gupdate1c985373d23476c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: Nero MediaHome 4 Service (NeroMediaHomeService.4) - Nero AG - C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
        3. le rsit INFO

          info.txt logfile of random's system information tool 1.06 2009-04-01 15:29:13

          ======Uninstall list======

          -->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
          -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
          -->C:\Program Files\MAGIX\Speed2_burnR_mxcdr\unwise.exe
          -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          ACDSee Photo Editor 2008-->MsiExec.exe /I{A6142247-58B1-40C7-B8E0-965C1A8026A5}
          ACDSee Pro 2.5-->MsiExec.exe /I{2D95950E-6D76-43E7-94A5-D9DBA2FD29E4}
          Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
          Adobe Bridge 1.0-->MsiExec.exe /I{B74D4E10-1033-0000-0000-000000000001}
          Adobe Color Common Settings-->C:\Program Files\Fichiers communs\Adobe\Installers\6c8e2cb4fd241c55406016127a6ab2e\Setup.exe
          Adobe Color Common Settings-->MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}
          Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
          Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Help Center 1.0-->MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
          Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
          Adobe Photoshop CS2-->msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
          Adobe Photoshop CS3-->MsiExec.exe /I{BF794769-8875-4E01-B7BE-E00104604F4A}
          Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
          Adobe Setup-->MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}
          Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
          Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
          Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
          AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
          Blender (remove only)-->"C:\Program Files\Blender Foundation\Blender\uninstall.exe"
          Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
          Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB914440)-->"C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB935448)-->"C:\WINDOWS\$NtUninstallKB935448$\spuninst\spuninst.exe"
          Correctif Windows XP - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
          Correctif Windows XP - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
          Correctif Windows XP - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
          Correctif Windows XP - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
          Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
          Correctif Windows XP - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
          Correctif Windows XP - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
          Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
          CuteFTP 5.0 XP-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{18DF995F-2ACC-47E4-A33B-A703F4D39E92}\Setup.exe" -l0x40c /l040C UNINSTALL
          DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
          DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
          DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
          DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
          DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
          FileZilla Client 3.1.2-->C:\Program Files\FileZilla FTP Client\uninstall.exe
          FindyKill-->C:\FindyKill\Uninstal.exe
          Firebird SQL Server - MAGIX Edition-->C:\Program Files\MAGIX\Common\Database\unwise.exe
          Freeplayer-->C:\Program Files\Freeplayer\Uninstall.exe
          Google Earth Plugin-->MsiExec.exe /I{9491C880-1C35-11DE-97B2-005056806466}
          Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
          High Definition Audio - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
          HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
          Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
          Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
          Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
          IEEE 802.11b WLAN Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9EC7F942-836F-4D62-ADBD-9C65ADB66220}\Setup.exe" -l0x9
          Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
          iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
          iWizz-->C:\Program Files\iWizz\uninstall.exe
          Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
          Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
          LightZone 3.6.1-->C:\Program Files\LightZone 3\uninstall.exe
          MAGIX 3D Maker (embeded)-->C:\Program Files\MAGIX\Common\3D_Maker_embeded\unwise.exe
          MAGIX Screenshare 4.3.6.1987 (F)-->C:\Program Files\MAGIX\PCVisit\unwise.exe
          MAGIX Vidéo deluxe 15 Plus Version à télécharger 8.0.2.5 (F)-->C:\Program Files\MAGIX\Video_deluxe_15_Plus_Version_a_telecharger\unwise.exe
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
          Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
          Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
          Microsoft .NET Framework 3.0 French Language Pack-->MsiExec.exe /X{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}
          Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
          Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
          Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
          Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
          Microsoft Office PowerPoint Viewer 2003-->MsiExec.exe /X{90AF040C-6000-11D3-8CFE-0150048383C9}
          Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
          Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Mise à jour de sécurité pour Lecteur Windows Media (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 9 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB896424)-->"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB899589)-->"C:\WINDOWS\$NtUninstallKB899589$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB911567)-->"C:\WINDOWS\$NtUninstallKB911567$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB912919)-->"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB917422)-->"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920214)-->"C:\WINDOWS\$NtUninstallKB920214$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB921398)-->"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB921883)-->"C:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB922616)-->"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB924191)-->"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB937894)-->"C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB904942)-->"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB920342)-->"C:\WINDOWS\$NtUninstallKB920342$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB925720)-->"C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB925876)-->"C:\WINDOWS\$NtUninstallKB925876$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB936357)-->"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
          Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
          Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 French Language Pack\setup.exe
          Monopoly Deluxe-->"C:\Program Files\Zylom Games\Monopoly Deluxe\GameInstlr.exe" --uninstall UnInstall.log
          Mozilla Firefox (3.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
          Neat Image v5 Demo (with plug-in)-->"C:\Program Files\Neat Image\unins000.exe"
          Nero MediaHome 4-->C:\Program Files\Fichiers communs\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="9M06-01C3-PZT6-AK05-37L3-2TU5-3U76-8XPX"
          Nero Suite-->C:\Program Files\Fichiers communs\Ahead\Uninstall\Setup.exe /uninstall
          Package de base Microsoft de service de chiffrement pour cartes à puce-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
          PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
          PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
          PhotoTools 1.0 Professional Edition-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B01DD5B7-9862-43D7-BCA3-7882A17E4328}\setup.exe" -l0x9 -uninst -removeonly
          Portrait Professional Max 6.3-->"C:\Program Files\Portrait Professional Max 6\unins000.exe"
          QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
          R.C. Cars-->MsiExec.exe /X{FDACD776-2B0F-427F-95BD-FAF664D75308}
          Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
          Ri4m v5.0.1d-->C:\Program Files\Ripp-it_AM\Ri4m_Uninstal.exe
          Ripp-It Codec Pack v 4.2.6-->C:\Program Files\Ripp-It Codec Pack\uninst.exe
          Search Settings 1.2-->MsiExec.exe /X{D0C73318-7B4A-4D16-A0C4-3B83F075EA88}
          SUPER © Version 2009.bld.35 (Jan 5, 2009)-->C:\PROGRA~1\SUPER\Setup.exe /remove /q0
          SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
          Tunatic-->"C:\WINDOWS\lsb_un20.exe" /C=UC /N=Tunatic
          Turbo Photo 6.2-->"C:\Program Files\Turbo Photo\unins000.exe"
          VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
          VirtuaGirl HD-->C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\VirtuaGirl HD\uninstall.lnk
          Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
          Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
          Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
          Windows Media Format SDK Hotfix - KB891122-->"C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
          Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
          Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
          Windows Presentation Foundation Language Pack (FRA)-->MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
          Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
          Windows Workflow Foundation FR Language Pack-->MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}
          Xara3D6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{64C96428-3A75-4AAE-A538-C450EF68175F}\setup.exe" -l0x9
          XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
          Xvid 1.1.2 final uninstall-->"C:\Program Files\Xvid\unins000.exe"

          =====HijackThis Backups=====

          O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll [2009-03-29]
          R3 - Default URLSearchHook is missing [2009-03-31]

          ======Hosts File======

          127.0.0.1 localhost

          ======Security center information======

          AV: avast! antivirus 4.8.1201 [VPS 090331-0]

          ======System event log======

          Computer Name: MAXDATA-831FA97
          Event Code: 7036
          Message: Le service Service de découvertes SSDP est entré dans l'état : en cours d'exécution.

          Record Number: 14418
          Source Name: Service Control Manager
          Time Written: 20090217081224.000000+060
          Event Type: Informations
          User:

          Computer Name: MAXDATA-831FA97
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service avast! Mail Scanner.

          Record Number: 14417
          Source Name: Service Control Manager
          Time Written: 20090217081224.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: MAXDATA-831FA97
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service Service de découvertes SSDP.

          Record Number: 14416
          Source Name: Service Control Manager
          Time Written: 20090217081224.000000+060
          Event Type: Informations
          User: MAXDATA-831FA97\Utilisateur

          Computer Name: MAXDATA-831FA97
          Event Code: 7036
          Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.

          Record Number: 14415
          Source Name: Service Control Manager
          Time Written: 20090217081224.000000+060
          Event Type: Informations
          User:

          Computer Name: MAXDATA-831FA97
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service Service COM de gravage de CD IMAPI.

          Record Number: 14414
          Source Name: Service Control Manager
          Time Written: 20090217081224.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          =====Application event log=====

          Computer Name: MAXDATA-831FA97
          Event Code: 0
          Message:
          Record Number: 1566
          Source Name: gupdate1c985373d23476c
          Time Written: 20090320175135.000000+060
          Event Type: Informations
          User:

          Computer Name: MAXDATA-831FA97
          Event Code: 1800
          Message: Le service Centre de sécurité Windows a démarré.

          Record Number: 1565
          Source Name: SecurityCenter
          Time Written: 20090320175126.000000+060
          Event Type: Informations
          User:

          Computer Name: MAXDATA-831FA97
          Event Code: 1
          Message:
          Record Number: 1564
          Source Name: Bonjour Service
          Time Written: 20090320175106.000000+060
          Event Type: Informations
          User:

          Computer Name: MAXDATA-831FA97
          Event Code: 0
          Message:
          Record Number: 1563
          Source Name: gupdate1c985373d23476c
          Time Written: 20090320175105.000000+060
          Event Type: Informations
          User:

          Computer Name: MAXDATA-831FA97
          Event Code: 0
          Message:
          Record Number: 1562
          Source Name: gupdate1c985373d23476c
          Time Written: 20090320081512.000000+060
          Event Type: Informations
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Fichiers communs\Adobe\AGL;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Fichiers communs\DivX Shared\
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 22 Stepping 1, GenuineIntel
          "PROCESSOR_REVISION"=1601
          "NUMBER_OF_PROCESSORS"=1
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
          "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

          -----------------EOF-----------------
      9. Hi
        "Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
        X86-based PC ( Uniprocessor Free : Processeur Intel Pentium II )"

        "Il a toutefois un peu ma réactivité lorsque j'ai descendu une bouteille de vodka..."

        n'as tu jamais eu un doute si ton processeur était capable de "gèrer" Xp pro? (pas celui sorti en 2003, celui de 2009)
        1. 1/ Bon il y a toujours la daemon toolbar,fais la procedure suivante

          C:\Program Files\DAEMON Tools Lite, et la on trouve le fichier "uninst" pour le désinstaller.

          La toolbar daemon est considée comme adware car elle integre dans le logiciel un programme qui t'envoies des pub (sans que tu demandes rien).

          2/ Ensuite relances hijack this,puis"do a scan only" et coches la ligne ci dessous (si elle est encore presente)

          R3 - Default URLSearchHook is missing

          Ensuite:

          3/---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

          ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :

          http://oldtimer.geekstogo.com/OTMoveIt3.exe

          ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

          ---> Copie (Ctrl+C) le texte suivant ci-dessous :

          :processes
          explorer.exe

          :files
          c:\program files\search settings\kb127\searchsettings.dll

          :reg
          [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
          [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]

          :commands
          [purity]
          [emptytemp]
          [start explorer]
          [reboot]

          ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

          ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

          Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
          Accepte en cliquant sur YES.

          ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
          Le nom du rapport correspond au moment de sa création : date_heure.log

          Ensuite

          Passes en mode sans echec

          Comment aller en Mode sans échec
          1) Redémarres ton ordi
          2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
          3) Tu verras un écran avec options de démarrage apparaître
          4) Choisis la première option : Sans Échec, et valide avec "Entrée"
          5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
          (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

          4/Refais toolbar sd 1 et 2 et postes moi les rapports (j'aimerais bien qu'on en vienne a bout de cette toolbar).
          1. salut, et merci pour ta fidèlité face a ma galère.

            rapport OT

            ========== PROCESSES ==========
            Process explorer.exe killed successfully.
            ========== FILES ==========
            File/Folder c:\program files\search settings\kb127\searchsettings.dll not found.
            ========== REGISTRY ==========
            Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\\ not found.
            Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\\ not found.
            ========== COMMANDS ==========
            File delete failed. C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\hsperfdata_Utilisateur\2656 scheduled to be deleted on reboot.
            File delete failed. C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\hsperfdata_Utilisateur\832 scheduled to be deleted on reboot.
            File delete failed. C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\etilqs_3PXigacTTnhRh6b1Yva3 scheduled to be deleted on reboot.
            File delete failed. C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\~DFA8FE.tmp scheduled to be deleted on reboot.
            User's Temp folder emptied.
            User's Temporary Internet Files folder emptied.
            User's Internet Explorer cache folder emptied.
            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
            Local Service Temp folder emptied.
            Local Service Temporary Internet Files folder emptied.
            File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5c8.dat scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_67c.dat scheduled to be deleted on reboot.
            Windows Temp folder emptied.
            Java cache emptied.
            File delete failed. C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\XUL.mfl scheduled to be deleted on reboot.
            FireFox cache emptied.
            Temp folders emptied.
            Explorer started successfully

            OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 04042009_232031

            Files moved on Reboot...
            File C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\hsperfdata_Utilisateur\2656 not found!
            File C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\hsperfdata_Utilisateur\832 not found!
            File C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\etilqs_3PXigacTTnhRh6b1Yva3 not found!
            C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\~DFA8FE.tmp moved successfully.
            File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
            File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be moved on reboot.
            File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
            File C:\WINDOWS\temp\Perflib_Perfdata_5c8.dat not found!
            C:\WINDOWS\temp\Perflib_Perfdata_67c.dat moved successfully.
            C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_001_ moved successfully.
            C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_002_ moved successfully.
            C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_003_ moved successfully.
            C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\Cache\_CACHE_MAP_ moved successfully.
            C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\urlclassifier3.sqlite moved successfully.
            C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\j9lhfd1z.default\XUL.mfl moved successfully.
          2. rapport TB en mode 1

            -----------\\ ToolBar S&D 1.2.8 XP/Vista

            Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
            X86-based PC ( Uniprocessor Free : Processeur Intel Pentium II )
            BIOS : Default System BIOS
            USER : Utilisateur ( Administrator )
            BOOT : Fail-safe with network boot
            Antivirus : avast! antivirus 4.8.1201 [VPS 090404-0] 4.8.1201 (Activated)
            A:\ (USB)
            C:\ (Local Disk) - NTFS - Total:74 Go (Free:48 Go)
            D:\ (CD or DVD)
            F:\ (USB)
            G:\ (USB) - FAT - Total:243 Mo (Free:0 Go)
            I:\ (USB)
            J:\ (USB)

            "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
            Option : [1] ( 04/04/2009|23:49 )

            -----------\\ Recherche de Fichiers / Dossiers ...

            -----------\\ [..\Internet Explorer\Main]

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
            "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Start Page"="https://gamespace.daemon-tools.cc/fra/home"

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
            "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
            "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Start Page"="https://www.msn.com/fr-fr/"
            "Search Bar"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"

            --------------------\\ Recherche d'autres infections

            Aucune autre infection trouvée !

            1 - "C:\ToolBar SD\TB_1.txt" - 30/03/2009| 0:00 - Option : [1]
            2 - "C:\ToolBar SD\TB_2.txt" - 30/03/2009| 0:03 - Option : [2]
            3 - "C:\ToolBar SD\TB_3.txt" - 31/03/2009| 6:05 - Option : [1]
            4 - "C:\ToolBar SD\TB_4.txt" - 31/03/2009| 6:06 - Option : [2]
            5 - "C:\ToolBar SD\TB_5.txt" - 04/04/2009|23:49 - Option : [1]
          3. Et le rapport TB en mode 2... merci encore et bravo pour l'expertise. C'est un peu du chinois pour moi tout ça.

            -----------\\ ToolBar S&D 1.2.8 XP/Vista

            Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
            X86-based PC ( Uniprocessor Free : Processeur Intel Pentium II )
            BIOS : Default System BIOS
            USER : Utilisateur ( Administrator )
            BOOT : Fail-safe with network boot
            Antivirus : avast! antivirus 4.8.1201 [VPS 090404-0] 4.8.1201 (Activated)
            A:\ (USB)
            C:\ (Local Disk) - NTFS - Total:74 Go (Free:48 Go)
            D:\ (CD or DVD)
            F:\ (USB)
            G:\ (USB) - FAT - Total:243 Mo (Free:0 Go)
            I:\ (USB)
            J:\ (USB)

            "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
            Option : [2] ( 04/04/2009|23:50 )

            -----------\\ Recherche de Fichiers / Dossiers ...

            -----------\\ [..\Internet Explorer\Main]

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
            "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Start Page"="https://gamespace.daemon-tools.cc/fra/home"

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
            "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
            "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Start Page"="https://www.msn.com/fr-fr/"
            "Search Bar"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"

            --------------------\\ Recherche d'autres infections

            Aucune autre infection trouvée !

            1 - "C:\ToolBar SD\TB_1.txt" - 30/03/2009| 0:00 - Option : [1]
            2 - "C:\ToolBar SD\TB_2.txt" - 30/03/2009| 0:03 - Option : [2]
            3 - "C:\ToolBar SD\TB_3.txt" - 31/03/2009| 6:05 - Option : [1]
            4 - "C:\ToolBar SD\TB_4.txt" - 31/03/2009| 6:06 - Option : [2]
            5 - "C:\ToolBar SD\TB_5.txt" - 04/04/2009|23:49 - Option : [1]
            6 - "C:\ToolBar SD\TB_6.txt" - 04/04/2009|23:50 - Option : [2]
        2. As tu trouvé des traces de la daemon toolbar?
          1. je ne sais pas comment voir si ça traine encore sur mon PC.

            Sinon avec hijackthis, j ai toujours:

            R3 - Default URLSearchHook is missing

            malgré la tentative de fix
        3. Tu suis ce chemin pour la toolbar daemon

          C:\Program Files\DAEMON Tools Lite, et la on trouve le fichier "uninst" pour le désinstaller.

          Y'a quelque chose qui te reinstalle cette verrole.Repostes moi un Rsit tout neuf (supprimes les anciens rapports avant de relancer le scan)
          1. salut,

            c'est reparti :)

            info.txt

            info.txt logfile of random's system information tool 1.06 2009-04-07 23:47:15

            ======Uninstall list======

            -->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
            -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
            -->C:\Program Files\MAGIX\Speed2_burnR_mxcdr\unwise.exe
            -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            ACDSee Pro 2.5-->MsiExec.exe /I{2D95950E-6D76-43E7-94A5-D9DBA2FD29E4}
            Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
            Adobe Bridge 1.0-->MsiExec.exe /I{B74D4E10-1033-0000-0000-000000000001}
            Adobe Color Common Settings-->C:\Program Files\Fichiers communs\Adobe\Installers\6c8e2cb4fd241c55406016127a6ab2e\Setup.exe
            Adobe Color Common Settings-->MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}
            Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
            Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Help Center 1.0-->MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
            Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
            Adobe Photoshop CS2-->msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
            Adobe Photoshop CS3-->MsiExec.exe /I{BF794769-8875-4E01-B7BE-E00104604F4A}
            Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
            Adobe Setup-->MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}
            Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
            Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
            Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
            Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
            avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
            AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
            Blender (remove only)-->"C:\Program Files\Blender Foundation\Blender\uninstall.exe"
            CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
            Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB914440)-->"C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB935448)-->"C:\WINDOWS\$NtUninstallKB935448$\spuninst\spuninst.exe"
            Correctif Windows XP - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
            Correctif Windows XP - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
            Correctif Windows XP - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
            Correctif Windows XP - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
            Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
            Correctif Windows XP - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
            Correctif Windows XP - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
            Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
            CuteFTP 5.0 XP-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{18DF995F-2ACC-47E4-A33B-A703F4D39E92}\Setup.exe" -l0x40c /l040C UNINSTALL
            DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
            DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
            DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
            DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
            DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
            FileZilla Client 3.1.2-->C:\Program Files\FileZilla FTP Client\uninstall.exe
            FindyKill-->C:\FindyKill\Uninstal.exe
            Google Earth Plugin-->MsiExec.exe /I{9491C880-1C35-11DE-97B2-005056806466}
            Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
            High Definition Audio - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
            HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
            Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
            Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
            Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
            IEEE 802.11b WLAN Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9EC7F942-836F-4D62-ADBD-9C65ADB66220}\Setup.exe" -l0x9
            Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
            iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
            Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
            Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
            Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
            LightZone 3.6.1-->C:\Program Files\LightZone 3\uninstall.exe
            Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
            Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
            Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
            Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
            Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
            Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
            Microsoft .NET Framework 3.0 French Language Pack-->MsiExec.exe /X{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}
            Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
            Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
            Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
            Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
            Microsoft Office PowerPoint Viewer 2003-->MsiExec.exe /X{90AF040C-6000-11D3-8CFE-0150048383C9}
            Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
            Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            Mise à jour de sécurité pour Lecteur Windows Media (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 9 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB896424)-->"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB899589)-->"C:\WINDOWS\$NtUninstallKB899589$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB911567)-->"C:\WINDOWS\$NtUninstallKB911567$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB912919)-->"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB917422)-->"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB920214)-->"C:\WINDOWS\$NtUninstallKB920214$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB921398)-->"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB921883)-->"C:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB922616)-->"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB924191)-->"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB937894)-->"C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB904942)-->"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB920342)-->"C:\WINDOWS\$NtUninstallKB920342$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB925720)-->"C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB925876)-->"C:\WINDOWS\$NtUninstallKB925876$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB936357)-->"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
            Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
            Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 French Language Pack\setup.exe
            Mozilla Firefox (3.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
            Neat Image v5 Demo (with plug-in)-->"C:\Program Files\Neat Image\unins000.exe"
            Nero Suite-->C:\Program Files\Fichiers communs\Ahead\Uninstall\Setup.exe /uninstall
            OpenOffice.org 3.0 Language Pack (French)-->MsiExec.exe /I{2A0DB319-6365-4876-B7D8-994A79AA1329}
            OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
            Package de base Microsoft de service de chiffrement pour cartes à puce-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
            PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
            PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
            PhotoTools 1.0 Professional Edition-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B01DD5B7-9862-43D7-BCA3-7882A17E4328}\setup.exe" -l0x9 -uninst -removeonly
            QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
            Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
            Ripp-It Codec Pack v 4.2.6-->C:\Program Files\Ripp-It Codec Pack\uninst.exe
            SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
            Synergie Maintenance-->"C:\DIAXENS\Synergie Maintenance\unins000.exe"
            Tunatic-->"C:\WINDOWS\lsb_un20.exe" /C=UC /N=Tunatic
            Turbo Photo 6.2-->"C:\Program Files\Turbo Photo\unins000.exe"
            VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
            Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
            Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
            Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
            Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
            Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
            Windows Media Format SDK Hotfix - KB891122-->"C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
            Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
            Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
            Windows Presentation Foundation Language Pack (FRA)-->MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
            Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
            Windows Workflow Foundation FR Language Pack-->MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}
            XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
            Xvid 1.1.2 final uninstall-->"C:\Program Files\Xvid\unins000.exe"

            =====HijackThis Backups=====

            O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll [2009-03-29]
            R3 - Default URLSearchHook is missing [2009-03-31]
            R3 - Default URLSearchHook is missing [2009-04-04]
            R3 - Default URLSearchHook is missing [2009-04-05]

            ======Hosts File======

            127.0.0.1 localhost

            ======Security center information======

            AV: avast! antivirus 4.8.1201 [VPS 090407-0]

            ======System event log======

            Computer Name: MAXDATA-831FA97
            Event Code: 7036
            Message: Le service Carte de performance WMI est entré dans l'état : en cours d'exécution.

            Record Number: 14824
            Source Name: Service Control Manager
            Time Written: 20090224220716.000000+060
            Event Type: Informations
            User:

            Computer Name: MAXDATA-831FA97
            Event Code: 7035
            Message: Un contrôle Démarrer a correctement été envoyé au service Carte de performance WMI.

            Record Number: 14823
            Source Name: Service Control Manager
            Time Written: 20090224220716.000000+060
            Event Type: Informations
            User: AUTORITE NT\SYSTEM

            Computer Name: MAXDATA-831FA97
            Event Code: 7036
            Message: Le service Service de la passerelle de la couche Application est entré dans l'état : en cours d'exécution.

            Record Number: 14822
            Source Name: Service Control Manager
            Time Written: 20090224220715.000000+060
            Event Type: Informations
            User:

            Computer Name: MAXDATA-831FA97
            Event Code: 7035
            Message: Un contrôle Démarrer a correctement été envoyé au service Service de la passerelle de la couche Application.

            Record Number: 14821
            Source Name: Service Control Manager
            Time Written: 20090224220715.000000+060
            Event Type: Informations
            User: AUTORITE NT\SYSTEM

            Computer Name: MAXDATA-831FA97
            Event Code: 7036
            Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.

            Record Number: 14820
            Source Name: Service Control Manager
            Time Written: 20090224220711.000000+060
            Event Type: Informations
            User:

            =====Application event log=====

            Computer Name: MAXDATA-831FA97
            Event Code: 1001
            Message: Les compteurs de performances pour le service WmiApRpl (WmiApRpl) ont été supprimés.
            Les données d'enregistrement contiennent les nouvelles valeurs du dernier compteur système
            et les dernières entrées du registre d'aide.

            Record Number: 1712
            Source Name: LoadPerf
            Time Written: 20090330204311.000000+120
            Event Type: Informations
            User:

            Computer Name: MAXDATA-831FA97
            Event Code: 1800
            Message: Le service Centre de sécurité Windows a démarré.

            Record Number: 1711
            Source Name: SecurityCenter
            Time Written: 20090330204204.000000+120
            Event Type: Informations
            User:

            Computer Name: MAXDATA-831FA97
            Event Code: 0
            Message:
            Record Number: 1710
            Source Name: gupdate1c985373d23476c
            Time Written: 20090330204204.000000+120
            Event Type: Informations
            User:

            Computer Name: MAXDATA-831FA97
            Event Code: 0
            Message:
            Record Number: 1709
            Source Name: NeroMediaHomeService.4
            Time Written: 20090330204150.000000+120
            Event Type: Informations
            User:

            Computer Name: MAXDATA-831FA97
            Event Code: 1
            Message:
            Record Number: 1708
            Source Name: Bonjour Service
            Time Written: 20090330204134.000000+120
            Event Type: Informations
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Fichiers communs\Adobe\AGL;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Fichiers communs\DivX Shared\
            "windir"=%SystemRoot%
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "PROCESSOR_ARCHITECTURE"=x86
            "PROCESSOR_LEVEL"=6
            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 22 Stepping 1, GenuineIntel
            "PROCESSOR_REVISION"=1601
            "NUMBER_OF_PROCESSORS"=1
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
            "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

            -----------------EOF-----------------
          2. Et le log.txt

            Logfile of random's system information tool 1.06 (written by random/random)
            Run by Utilisateur at 2009-04-07 23:47:11
            Microsoft Windows XP Professionnel Service Pack 2
            System drive C: has 49 GB (65%) free of 76 GB
            Total RAM: 503 MB (36% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 23:47:13, on 07/04/2009
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16608)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\Explorer.EXE
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Google\Update\GoogleUpdate.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            C:\Program Files\IEEE 802.11b WLAN Utility\WLANUtil.exe
            C:\Program Files\OpenOffice.org 3\program\soffice.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\OpenOffice.org 3\program\soffice.bin
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
            C:\Program Files\Java\jre6\bin\jucheck.exe
            C:\Documents and Settings\Utilisateur\Bureau\RSIT.exe
            C:\Program Files\Trend Micro\HijackThis\Utilisateur.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://gamespace.daemon-tools.cc/fra/home
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
            O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
            O4 - Global Startup: WLANUtility.lnk = C:\Program Files\IEEE 802.11b WLAN Utility\WLANUtil.exe
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
            O23 - Service: Google Update Service (gupdate1c985373d23476c) (gupdate1c985373d23476c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
            O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        4. Clique sur le menu Demarrer /Panneau de configuration/Options des dossiers/ puis dans l'onglet Affichage
          - Coche Afficher les fichiers et dossiers cachés
          - Décoche Masquer les extensions des fichiers dont le type est connu
          - Décoche Masquer les fichiers protégés du système d'exploitation (recommandé)
          clique sur Appliquer, puis OK.

          N'oublie pas de recacher à nouveau les fichiers cachés et protégés du système d'exploitation en fin de désinfection, c'est important

          Fais analyser le(s) fichier(s) suivants sur Virustotal :

          C:\WINDOWS\mgxoschk.ini
          C:\WINDOWS\system32\TTIC32.dll
          C:\WINDOWS\system32\STRING32.dll

          http://www.virustotal.com/flash/index_en.html

          * Clique sur Parcourir en haut, choisis Poste de travail et cherche ce fichier : Chemin\Fichier
          * Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
          * Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
          * Lorsque l'analyse est terminée ("Situation actuelle: terminé"), clique sur Formaté
          * Une nouvelle fenêtre de ton navigateur va apparaître
          * Clique alors sur les deux fleches
          * Fais un clic droit sur la page, et choisis Sélectionner tout, puis copier
          * Enfin colle le résultat dans ta prochaine réponse.

          * Fais la même chose avec ces fichiers : Chemin\Fichier

          Note : Pour analyser un autre fichier, clique en bas sur Autre fichier.
          1. wow... impressionnant ce site

            Bon, j'ai fais les manips (y compris la remise en cache... qui ne l'étaient pas)

            et les rapports

            Fichier mgxoschk.ini reçu le 2009.04.08 23:38:41 (CET)
            Antivirus Version Dernière mise à jour Résultat
            a-squared 4.0.0.101 2009.04.08 -
            AhnLab-V3 5.0.0.2 2009.04.08 -
            AntiVir 7.9.0.138 2009.04.08 -
            Antiy-AVL 2.0.3.1 2009.04.08 -
            Authentium 5.1.2.4 2009.04.08 -
            Avast 4.8.1335.0 2009.04.08 -
            AVG 8.5.0.285 2009.04.08 -
            BitDefender 7.2 2009.04.08 -
            CAT-QuickHeal 10.00 2009.04.08 -
            ClamAV 0.94.1 2009.04.08 -
            Comodo 1105 2009.04.08 -
            DrWeb 4.44.0.09170 2009.04.08 -
            eSafe 7.0.17.0 2009.04.07 -
            eTrust-Vet 31.6.6446 2009.04.08 -
            F-Prot 4.4.4.56 2009.04.08 -
            F-Secure 8.0.14470.0 2009.04.08 -
            Fortinet 3.117.0.0 2009.04.08 -
            GData 19 2009.04.08 -
            Ikarus T3.1.1.49.0 2009.04.08 -
            K7AntiVirus 7.10.697 2009.04.08 -
            Kaspersky 7.0.0.125 2009.04.08 -
            McAfee 5578 2009.04.08 -
            McAfee+Artemis 5578 2009.04.08 -
            McAfee-GW-Edition 6.7.6 2009.04.08 -
            Microsoft 1.4502 2009.04.08 -
            NOD32 3995 2009.04.08 -
            Norman 6.00.06 2009.04.08 -
            nProtect 2009.1.8.0 2009.04.08 -
            Panda 10.0.0.14 2009.04.08 -
            PCTools 4.4.2.0 2009.04.08 -
            Prevx1 V2 2009.04.08 -
            Rising 21.24.22.00 2009.04.08 -
            Sophos 4.40.0 2009.04.08 -
            Sunbelt 3.2.1858.2 2009.04.08 -
            Symantec 1.4.4.12 2009.04.08 -
            TheHacker 6.3.4.0.303 2009.04.08 -
            TrendMicro 8.700.0.1004 2009.04.08 -
            VBA32 3.12.10.2 2009.04.08 -
            ViRobot 2009.4.7.1684 2009.04.08 -
            VirusBuster 4.6.5.0 2009.04.08 -
            Information additionnelle
            File size: 7023 bytes
            MD5...: d5967d586b7e7c722df85f276f410785
            SHA1..: 6a56cf47ead4b84bf47c74d616ce3e11e01fa643
            SHA256: e89702347a5bc655e123a3998f951604b834569126640a819ffb57a76ed2c1af
            SHA512: 7de4d64bd0d7967e72f0d365fdc9d55c5fc474fb4988b09b30d4324384d7f4a9<br>158968f5a343930e8b30b8ccfb9bfa93062a5af171f3533420481bbac726cfde
            ssdeep: 192:/1G2ITXH5PuluvuKX2bB/cDNDYepMHMfiCffbsm8:d4NuluvuLVyNDHMHARY<br>B<br>
            PEiD..: -
            TrID..: File type identification<br>Generic INI configuration (100.0%)
            PEInfo: -
            RDS...: NSRL Reference Data Set<br>-

            Antivirus Version Dernière mise à jour Résultat
            a-squared 4.0.0.101 2009.04.08 -
            AhnLab-V3 5.0.0.2 2009.04.08 -
            AntiVir 7.9.0.138 2009.04.08 -
            Antiy-AVL 2.0.3.1 2009.04.08 -
            Authentium 5.1.2.4 2009.04.08 -
            Avast 4.8.1335.0 2009.04.08 -
            AVG 8.5.0.285 2009.04.08 -
            BitDefender 7.2 2009.04.08 -
            CAT-QuickHeal 10.00 2009.04.08 -
            ClamAV 0.94.1 2009.04.08 -
            Comodo 1105 2009.04.08 -
            DrWeb 4.44.0.09170 2009.04.08 -
            eSafe 7.0.17.0 2009.04.07 -
            eTrust-Vet 31.6.6446 2009.04.08 -
            F-Prot 4.4.4.56 2009.04.08 -
            F-Secure 8.0.14470.0 2009.04.08 -
            Fortinet 3.117.0.0 2009.04.08 -
            GData 19 2009.04.08 -
            Ikarus T3.1.1.49.0 2009.04.08 -
            K7AntiVirus 7.10.697 2009.04.08 -
            Kaspersky 7.0.0.125 2009.04.08 -
            McAfee 5578 2009.04.08 -
            McAfee+Artemis 5578 2009.04.08 -
            McAfee-GW-Edition 6.7.6 2009.04.08 -
            Microsoft 1.4502 2009.04.08 -
            NOD32 3995 2009.04.08 -
            Norman 6.00.06 2009.04.08 -
            nProtect 2009.1.8.0 2009.04.08 -
            Panda 10.0.0.14 2009.04.08 -
            PCTools 4.4.2.0 2009.04.08 -
            Prevx1 V2 2009.04.08 -
            Rising 21.24.22.00 2009.04.08 -
            Sophos 4.40.0 2009.04.08 -
            Sunbelt 3.2.1858.2 2009.04.08 -
            Symantec 1.4.4.12 2009.04.08 -
            TheHacker 6.3.4.0.303 2009.04.08 -
            TrendMicro 8.700.0.1004 2009.04.08 -
            VBA32 3.12.10.2 2009.04.08 -
            ViRobot 2009.4.7.1684 2009.04.08 -
            VirusBuster 4.6.5.0 2009.04.08 -

            Information additionnelle
            File size: 7023 bytes
            MD5...: d5967d586b7e7c722df85f276f410785
            SHA1..: 6a56cf47ead4b84bf47c74d616ce3e11e01fa643
            SHA256: e89702347a5bc655e123a3998f951604b834569126640a819ffb57a76ed2c1af
            SHA512: 7de4d64bd0d7967e72f0d365fdc9d55c5fc474fb4988b09b30d4324384d7f4a9<br>158968f5a343930e8b30b8ccfb9bfa93062a5af171f3533420481bbac726cfde
            ssdeep: 192:/1G2ITXH5PuluvuKX2bB/cDNDYepMHMfiCffbsm8:d4NuluvuLVyNDHMHARY<br>B<br>
            PEiD..: -
            TrID..: File type identification<br>Generic INI configuration (100.0%)
            PEInfo: -
            RDS...: NSRL Reference Data Set<br>-

            Fichier TTIC32.dll reçu le 2009.04.08 23:43:37 (CET)
            Antivirus Version Dernière mise à jour Résultat
            a-squared 4.0.0.101 2009.04.08 -
            AhnLab-V3 5.0.0.2 2009.04.08 -
            AntiVir 7.9.0.138 2009.04.08 -
            Antiy-AVL 2.0.3.1 2009.04.08 -
            Authentium 5.1.2.4 2009.04.08 -
            Avast 4.8.1335.0 2009.04.08 -
            AVG 8.5.0.285 2009.04.08 -
            BitDefender 7.2 2009.04.08 -
            CAT-QuickHeal 10.00 2009.04.08 -
            ClamAV 0.94.1 2009.04.08 -
            Comodo 1105 2009.04.08 -
            DrWeb 4.44.0.09170 2009.04.08 -
            eSafe 7.0.17.0 2009.04.07 -
            eTrust-Vet 31.6.6446 2009.04.08 -
            F-Prot 4.4.4.56 2009.04.08 -
            F-Secure 8.0.14470.0 2009.04.08 -
            Fortinet 3.117.0.0 2009.04.08 -
            GData 19 2009.04.08 -
            Ikarus T3.1.1.49.0 2009.04.08 -
            K7AntiVirus 7.10.697 2009.04.08 -
            Kaspersky 7.0.0.125 2009.04.08 -
            McAfee 5578 2009.04.08 -
            McAfee+Artemis 5578 2009.04.08 -
            McAfee-GW-Edition 6.7.6 2009.04.08 -
            Microsoft 1.4502 2009.04.08 -
            NOD32 3995 2009.04.08 -
            Norman 6.00.06 2009.04.08 -
            nProtect 2009.1.8.0 2009.04.08 -
            Panda 10.0.0.14 2009.04.08 -
            PCTools 4.4.2.0 2009.04.08 -
            Prevx1 V2 2009.04.08 -
            Rising 21.24.22.00 2009.04.08 -
            Sophos 4.40.0 2009.04.08 -
            Sunbelt 3.2.1858.2 2009.04.08 -
            Symantec 1.4.4.12 2009.04.08 -
            TheHacker 6.3.4.0.303 2009.04.08 -
            TrendMicro 8.700.0.1004 2009.04.08 -
            VBA32 3.12.10.2 2009.04.08 -
            ViRobot 2009.4.7.1684 2009.04.08 -
            VirusBuster 4.6.5.0 2009.04.08 -
            Information additionnelle
            File size: 24576 bytes
            MD5...: ab024efed92d5a91ddcc9577fd5a3a9c
            SHA1..: 81b4f535ad92e2a2dbfbaebcfbac4f631dd341d9
            SHA256: 489c1e4b7a34b735ca203ccde332ce64001c54e02f91d0a342529f0c52e03475
            SHA512: ea0aef6dfe3aa0dc0f573fd5bd156ad3acccc4fa8b7ef6d4093eb78aef634ca2<br>521fef7b0041ded1a642c27a2985fa7d407dce2647f3d9f9fc0fd49cf924871a
            ssdeep: 48:SA3CQAENAPHVpgSO60f8dLzOxVZR9+dt2MQ2drHwHsZiNy+HsOIwT8iw8fPh4<br>YaU:V3CxVp50f8dnOxRKVnrHwH6iNy+Mc5S<br>
            PEiD..: Armadillo v1.xx - v2.xx
            TrID..: File type identification<br>Win32 Dynamic Link Library (generic) (65.4%)<br>Generic Win/DOS Executable (17.2%)<br>DOS Executable Generic (17.2%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
            PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x14b7<br>timedatestamp.....: 0x3e71a1c5 (Fri Mar 14 09:32:53 2003)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x55a 0x1000 2.64 00344efae6ef05d2fcd8ea9ae5d5038c<br>.rdata 0x2000 0x458 0x1000 1.83 899f75ac53603d5a772c4911b76ae116<br>.data 0x3000 0x24 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110<br>.rsrc 0x4000 0x388 0x1000 0.93 a1b8afc8e105424c7f4979b496b92cd7<br>.reloc 0x5000 0xb6 0x1000 0.28 4db97e8d0c1042cdb4cd050494b945cc<br><br>( 4 imports ) <br>> KERNEL32.dll: LocalFree, LocalAlloc, LocalHandle, DisableThreadLibraryCalls<br>> String32.dll: __1Path@@QAE@XZ, __0String@@QAE@PBD@Z, __0String@@QAE@XZ, __1String@@QAE@XZ<br>> TTI32.dll: __0TTITree@@QAE@XZ, _GetNextTTI@TTITree@@QAGPBVTTI@@XZ, _InitTTIGet@TTITree@@QAGXABVPath@@@Z, __1TTITree@@QAE@XZ, _RegisterTTI@TTITree@@QAGXABVPath@@W4TTOpcode@@PBVString@@2@Z, _GetNextTTIPN@TTITree@@QAGHAAVPath@@AAPBVTTI@@@Z, _InitTTIPNGet@TTITree@@QAGXXZ<br>> MSVCRT.dll: _adjust_fdiv, malloc, _initterm, free, __3@YAXPAX@Z, __2@YAPAXI@Z<br><br>( 8 exports ) <br>_TticDestGetNext@16, _TticDestInitGet@8, _TticFreeTree@4, _TticGetNext@20, _TticGetTree@4, _TticInitGet@4, _TticNewTree@0, _TticRegister@20<br>
            RDS...: NSRL Reference Data Set<br>-

            Antivirus Version Dernière mise à jour Résultat
            a-squared 4.0.0.101 2009.04.08 -
            AhnLab-V3 5.0.0.2 2009.04.08 -
            AntiVir 7.9.0.138 2009.04.08 -
            Antiy-AVL 2.0.3.1 2009.04.08 -
            Authentium 5.1.2.4 2009.04.08 -
            Avast 4.8.1335.0 2009.04.08 -
            AVG 8.5.0.285 2009.04.08 -
            BitDefender 7.2 2009.04.08 -
            CAT-QuickHeal 10.00 2009.04.08 -
            ClamAV 0.94.1 2009.04.08 -
            Comodo 1105 2009.04.08 -
            DrWeb 4.44.0.09170 2009.04.08 -
            eSafe 7.0.17.0 2009.04.07 -
            eTrust-Vet 31.6.6446 2009.04.08 -
            F-Prot 4.4.4.56 2009.04.08 -
            F-Secure 8.0.14470.0 2009.04.08 -
            Fortinet 3.117.0.0 2009.04.08 -
            GData 19 2009.04.08 -
            Ikarus T3.1.1.49.0 2009.04.08 -
            K7AntiVirus 7.10.697 2009.04.08 -
            Kaspersky 7.0.0.125 2009.04.08 -
            McAfee 5578 2009.04.08 -
            McAfee+Artemis 5578 2009.04.08 -
            McAfee-GW-Edition 6.7.6 2009.04.08 -
            Microsoft 1.4502 2009.04.08 -
            NOD32 3995 2009.04.08 -
            Norman 6.00.06 2009.04.08 -
            nProtect 2009.1.8.0 2009.04.08 -
            Panda 10.0.0.14 2009.04.08 -
            PCTools 4.4.2.0 2009.04.08 -
            Prevx1 V2 2009.04.08 -
            Rising 21.24.22.00 2009.04.08 -
            Sophos 4.40.0 2009.04.08 -
            Sunbelt 3.2.1858.2 2009.04.08 -
            Symantec 1.4.4.12 2009.04.08 -
            TheHacker 6.3.4.0.303 2009.04.08 -
            TrendMicro 8.700.0.1004 2009.04.08 -
            VBA32 3.12.10.2 2009.04.08 -
            ViRobot 2009.4.7.1684 2009.04.08 -
            VirusBuster 4.6.5.0 2009.04.08 -

            Information additionnelle
            File size: 24576 bytes
            MD5...: ab024efed92d5a91ddcc9577fd5a3a9c
            SHA1..: 81b4f535ad92e2a2dbfbaebcfbac4f631dd341d9
            SHA256: 489c1e4b7a34b735ca203ccde332ce64001c54e02f91d0a342529f0c52e03475
            SHA512: ea0aef6dfe3aa0dc0f573fd5bd156ad3acccc4fa8b7ef6d4093eb78aef634ca2<br>521fef7b0041ded1a642c27a2985fa7d407dce2647f3d9f9fc0fd49cf924871a
            ssdeep: 48:SA3CQAENAPHVpgSO60f8dLzOxVZR9+dt2MQ2drHwHsZiNy+HsOIwT8iw8fPh4<br>YaU:V3CxVp50f8dnOxRKVnrHwH6iNy+Mc5S<br>
            PEiD..: Armadillo v1.xx - v2.xx
            TrID..: File type identification<br>Win32 Dynamic Link Library (generic) (65.4%)<br>Generic Win/DOS Executable (17.2%)<br>DOS Executable Generic (17.2%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
            PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x14b7<br>timedatestamp.....: 0x3e71a1c5 (Fri Mar 14 09:32:53 2003)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x55a 0x1000 2.64 00344efae6ef05d2fcd8ea9ae5d5038c<br>.rdata 0x2000 0x458 0x1000 1.83 899f75ac53603d5a772c4911b76ae116<br>.data 0x3000 0x24 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110<br>.rsrc 0x4000 0x388 0x1000 0.93 a1b8afc8e105424c7f4979b496b92cd7<br>.reloc 0x5000 0xb6 0x1000 0.28 4db97e8d0c1042cdb4cd050494b945cc<br><br>( 4 imports ) <br>> KERNEL32.dll: LocalFree, LocalAlloc, LocalHandle, DisableThreadLibraryCalls<br>> String32.dll: __1Path@@QAE@XZ, __0String@@QAE@PBD@Z, __0String@@QAE@XZ, __1String@@QAE@XZ<br>> TTI32.dll: __0TTITree@@QAE@XZ, _GetNextTTI@TTITree@@QAGPBVTTI@@XZ, _InitTTIGet@TTITree@@QAGXABVPath@@@Z, __1TTITree@@QAE@XZ, _RegisterTTI@TTITree@@QAGXABVPath@@W4TTOpcode@@PBVString@@2@Z, _GetNextTTIPN@TTITree@@QAGHAAVPath@@AAPBVTTI@@@Z, _InitTTIPNGet@TTITree@@QAGXXZ<br>> MSVCRT.dll: _adjust_fdiv, malloc, _initterm, free, __3@YAXPAX@Z, __2@YAPAXI@Z<br><br>( 8 exports ) <br>_TticDestGetNext@16, _TticDestInitGet@8, _TticFreeTree@4, _TticGetNext@20, _TticGetTree@4, _TticInitGet@4, _TticNewTree@0, _TticRegister@20<br>
            RDS...: NSRL Reference Data Set<br>-

            Fichier STRING32.dll reçu le 2009.04.08 23:47:11 (CET)
            Antivirus Version Dernière mise à jour Résultat
            a-squared 4.0.0.101 2009.04.08 -
            AhnLab-V3 5.0.0.2 2009.04.08 -
            AntiVir 7.9.0.138 2009.04.08 -
            Antiy-AVL 2.0.3.1 2009.04.08 -
            Authentium 5.1.2.4 2009.04.08 -
            Avast 4.8.1335.0 2009.04.08 -
            AVG 8.5.0.285 2009.04.08 -
            BitDefender 7.2 2009.04.08 -
            CAT-QuickHeal 10.00 2009.04.08 -
            ClamAV 0.94.1 2009.04.08 -
            Comodo 1105 2009.04.08 -
            DrWeb 4.44.0.09170 2009.04.08 -
            eSafe 7.0.17.0 2009.04.07 -
            eTrust-Vet 31.6.6446 2009.04.08 -
            F-Prot 4.4.4.56 2009.04.08 -
            F-Secure 8.0.14470.0 2009.04.08 -
            Fortinet 3.117.0.0 2009.04.08 -
            GData 19 2009.04.08 -
            Ikarus T3.1.1.49.0 2009.04.08 -
            K7AntiVirus 7.10.697 2009.04.08 -
            Kaspersky 7.0.0.125 2009.04.08 -
            McAfee 5578 2009.04.08 -
            McAfee+Artemis 5578 2009.04.08 -
            McAfee-GW-Edition 6.7.6 2009.04.08 -
            Microsoft 1.4502 2009.04.08 -
            NOD32 3995 2009.04.08 -
            Norman 6.00.06 2009.04.08 -
            nProtect 2009.1.8.0 2009.04.08 -
            Panda 10.0.0.14 2009.04.08 -
            PCTools 4.4.2.0 2009.04.08 -
            Prevx1 V2 2009.04.08 -
            Rising 21.24.22.00 2009.04.08 -
            Sophos 4.40.0 2009.04.08 -
            Sunbelt 3.2.1858.2 2009.04.08 -
            Symantec 1.4.4.12 2009.04.08 -
            TheHacker 6.3.4.0.303 2009.04.08 -
            TrendMicro 8.700.0.1004 2009.04.08 -
            VBA32 3.12.10.2 2009.04.08 -
            ViRobot 2009.4.7.1684 2009.04.08 -
            VirusBuster 4.6.5.0 2009.04.08 -
            Information additionnelle
            File size: 38176 bytes
            MD5...: 5d7d97df6aa504cc3c7dd92021b58d33
            SHA1..: ddcda377b43f20d52a28e05b05beb1bdf61fdcc5
            SHA256: eee7535d9fb0adf9b964fb8d9346fe98419d76dcd8dd06883ce9b0a65437fe89
            SHA512: 430e47af83bc969204f5e41c7765cb4fe22b722884399598c934cc39afec0514<br>19c1459f3fccd78f9cd802f769bdd89dafab73b1789c8dfe8bb257da3e6c80a8
            ssdeep: 384:dlSMEOas6ZqM4dcHjhJ7QJVP9r/fxBZ2aK0VQYJLWFVbuxG:dlt7AZqM4dcH<br>1xQPFr/fxBZ2w1LIbuxG<br>
            PEiD..: Armadillo v1.xx - v2.xx
            TrID..: File type identification<br>Win64 Executable Generic (88.0%)<br>Win32 Dynamic Link Library (generic) (7.8%)<br>Generic Win/DOS Executable (2.0%)<br>DOS Executable Generic (2.0%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
            PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x2fca<br>timedatestamp.....: 0x47346fa2 (Fri Nov 09 14:33:06 2007)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x206e 0x3000 5.02 7427789abe85dde9cdb1350b3ab8d812<br>.rdata 0x4000 0x9ec 0x1000 3.80 378a5dcd49199f98d205be02b6d94dc1<br>.data 0x5000 0x3ac 0x1000 0.24 2bf492c2d7ce461b1eca67652183b119<br>.rsrc 0x6000 0x378 0x1000 0.92 45c618c50e8ad561037a20b3c54f8dbb<br>.reloc 0x7000 0x12a 0x1000 0.59 fa2cac724d8c5a151a8554a782acdf4e<br><br>( 3 imports ) <br>> KERNEL32.dll: MultiByteToWideChar, WideCharToMultiByte, DisableThreadLibraryCalls<br>> USER32.dll: CharUpperBuffA, CharToOemBuffA, OemToCharBuffA<br>> MSVCRT.dll: _adjust_fdiv, _initterm, wcscmp, malloc, free, wcslen, wcscpy<br><br>( 59 exports ) <br>__0Path@@AAE@ABV0@ABVString@@@Z, __0Path@@AAE@ABV0@PBD@Z, __0Path@@QAE@ABV0@@Z, __0PathW@@AAE@ABV0@ABVStringW@@@Z, __0PathW@@AAE@ABV0@PBG@Z, __0PathW@@QAE@ABV0@@Z, __0String@@AAE@ABV0@PBD@Z, __0String@@QAE@PBD@Z, __0String@@QAE@XZ, __0StringW@@AAE@ABV0@PBG@Z, __0StringW@@QAE@PBG@Z, __0StringW@@QAE@XZ, __0WinCaption@@QAE@PBD0@Z, __0WinCaptionW@@QAE@PBG0@Z, __1Path@@QAE@XZ, __1PathW@@QAE@XZ, __1String@@QAE@XZ, __1StringW@@QAE@XZ, __4Path@@QAEAAV0@ABV0@@Z, __4Path@@QAEAAV0@ABVString@@@Z, __4Path@@QAEAAV0@PBD@Z, __4PathW@@QAEAAV0@ABV0@@Z, __4PathW@@QAEAAV0@ABVStringW@@@Z, __4PathW@@QAEAAV0@PBG@Z, __4String@@QAEAAV0@ABV0@@Z, __4StringW@@QAEAAV0@ABV0@@Z, _GetDrive@Path@@QBE_BDXZ, _GetDrive@PathW@@QBE_BGXZ, _GetPathEnd@Path@@QBEPBDXZ, _GetPathEnd@PathW@@QBEPBGXZ, _GetPathFirst@Path@@QBEPBDXZ, _GetPathFirst@PathW@@QBEPBGXZ, _GetPathFirstEle@Path@@QBEPBVString@@XZ, _GetPathFirstEle@PathW@@QBEPBVStringW@@XZ, _GetPathHead@Path@@QBEPBDXZ, _GetPathHead@PathW@@QBEPBGXZ, _GetPathPath@Path@@QBEPBV1@XZ, _GetPathPath@PathW@@QBEPBV1@XZ, _GetPathRest@Path@@QBEPBDXZ, _GetPathRest@PathW@@QBEPBGXZ, _GetPathUnc@Path@@QBEPBVString@@XZ, _GetPathUnc@PathW@@QBEPBVStringW@@XZ, _StringCompare@String@@ABEHPBD@Z, _StringCompare@StringW@@ABEHPBG@Z, _Truncate@Path@@QBE_AVString@@I@Z, _Truncate@PathW@@QBE_AVStringW@@I@Z, ANSICompare, ANSIUpper, ConvertMbToUtf16, ConvertUtf16ToMb, ConvertUtf16ToUtf8, ConvertUtf8ToUtf16, IsUtf16HighSurrogate, IsUtf16LowSurrogate, IsUtf8BOM, OemCompare, OemUpper, PhpStrCmpA, PhpStrCmpW<br>
            RDS...: NSRL Reference Data Set<br>-

            Antivirus Version Dernière mise à jour Résultat
            a-squared 4.0.0.101 2009.04.08 -
            AhnLab-V3 5.0.0.2 2009.04.08 -
            AntiVir 7.9.0.138 2009.04.08 -
            Antiy-AVL 2.0.3.1 2009.04.08 -
            Authentium 5.1.2.4 2009.04.08 -
            Avast 4.8.1335.0 2009.04.08 -
            AVG 8.5.0.285 2009.04.08 -
            BitDefender 7.2 2009.04.08 -
            CAT-QuickHeal 10.00 2009.04.08 -
            ClamAV 0.94.1 2009.04.08 -
            Comodo 1105 2009.04.08 -
            DrWeb 4.44.0.09170 2009.04.08 -
            eSafe 7.0.17.0 2009.04.07 -
            eTrust-Vet 31.6.6446 2009.04.08 -
            F-Prot 4.4.4.56 2009.04.08 -
            F-Secure 8.0.14470.0 2009.04.08 -
            Fortinet 3.117.0.0 2009.04.08 -
            GData 19 2009.04.08 -
            Ikarus T3.1.1.49.0 2009.04.08 -
            K7AntiVirus 7.10.697 2009.04.08 -
            Kaspersky 7.0.0.125 2009.04.08 -
            McAfee 5578 2009.04.08 -
            McAfee+Artemis 5578 2009.04.08 -
            McAfee-GW-Edition 6.7.6 2009.04.08 -
            Microsoft 1.4502 2009.04.08 -
            NOD32 3995 2009.04.08 -
            Norman 6.00.06 2009.04.08 -
            nProtect 2009.1.8.0 2009.04.08 -
            Panda 10.0.0.14 2009.04.08 -
            PCTools 4.4.2.0 2009.04.08 -
            Prevx1 V2 2009.04.08 -
            Rising 21.24.22.00 2009.04.08 -
            Sophos 4.40.0 2009.04.08 -
            Sunbelt 3.2.1858.2 2009.04.08 -
            Symantec 1.4.4.12 2009.04.08 -
            TheHacker 6.3.4.0.303 2009.04.08 -
            TrendMicro 8.700.0.1004 2009.04.08 -
            VBA32 3.12.10.2 2009.04.08 -
            ViRobot 2009.4.7.1684 2009.04.08 -
            VirusBuster 4.6.5.0 2009.04.08 -

            Information additionnelle
            File size: 38176 bytes
            MD5...: 5d7d97df6aa504cc3c7dd92021b58d33
            SHA1..: ddcda377b43f20d52a28e05b05beb1bdf61fdcc5
            SHA256: eee7535d9fb0adf9b964fb8d9346fe98419d76dcd8dd06883ce9b0a65437fe89
            SHA512: 430e47af83bc969204f5e41c7765cb4fe22b722884399598c934cc39afec0514<br>19c1459f3fccd78f9cd802f769bdd89dafab73b1789c8dfe8bb257da3e6c80a8
            ssdeep: 384:dlSMEOas6ZqM4dcHjhJ7QJVP9r/fxBZ2aK0VQYJLWFVbuxG:dlt7AZqM4dcH<br>1xQPFr/fxBZ2w1LIbuxG<br>
            PEiD..: Armadillo v1.xx - v2.xx
            TrID..: File type identification<br>Win64 Executable Generic (88.0%)<br>Win32 Dynamic Link Library (generic) (7.8%)<br>Generic Win/DOS Executable (2.0%)<br>DOS Executable Generic (2.0%)<br>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
            PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x2fca<br>timedatestamp.....: 0x47346fa2 (Fri Nov 09 14:33:06 2007)<br>machinetype.......: 0x14c (I386)<br><br>( 5 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x206e 0x3000 5.02 7427789abe85dde9cdb1350b3ab8d812<br>.rdata 0x4000 0x9ec 0x1000 3.80 378a5dcd49199f98d205be02b6d94dc1<br>.data 0x5000 0x3ac 0x1000 0.24 2bf492c2d7ce461b1eca67652183b119<br>.rsrc 0x6000 0x378 0x1000 0.92 45c618c50e8ad561037a20b3c54f8dbb<br>.reloc 0x7000 0x12a 0x1000 0.59 fa2cac724d8c5a151a8554a782acdf4e<br><br>( 3 imports ) <br>> KERNEL32.dll: MultiByteToWideChar, WideCharToMultiByte, DisableThreadLibraryCalls<br>> USER32.dll: CharUpperBuffA, CharToOemBuffA, OemToCharBuffA<br>> MSVCRT.dll: _adjust_fdiv, _initterm, wcscmp, malloc, free, wcslen, wcscpy<br><br>( 59 exports ) <br>__0Path@@AAE@ABV0@ABVString@@@Z, __0Path@@AAE@ABV0@PBD@Z, __0Path@@QAE@ABV0@@Z, __0PathW@@AAE@ABV0@ABVStringW@@@Z, __0PathW@@AAE@ABV0@PBG@Z, __0PathW@@QAE@ABV0@@Z, __0String@@AAE@ABV0@PBD@Z, __0String@@QAE@PBD@Z, __0String@@QAE@XZ, __0StringW@@AAE@ABV0@PBG@Z, __0StringW@@QAE@PBG@Z, __0StringW@@QAE@XZ, __0WinCaption@@QAE@PBD0@Z, __0WinCaptionW@@QAE@PBG0@Z, __1Path@@QAE@XZ, __1PathW@@QAE@XZ, __1String@@QAE@XZ, __1StringW@@QAE@XZ, __4Path@@QAEAAV0@ABV0@@Z, __4Path@@QAEAAV0@ABVString@@@Z, __4Path@@QAEAAV0@PBD@Z, __4PathW@@QAEAAV0@ABV0@@Z, __4PathW@@QAEAAV0@ABVStringW@@@Z, __4PathW@@QAEAAV0@PBG@Z, __4String@@QAEAAV0@ABV0@@Z, __4StringW@@QAEAAV0@ABV0@@Z, _GetDrive@Path@@QBE_BDXZ, _GetDrive@PathW@@QBE_BGXZ, _GetPathEnd@Path@@QBEPBDXZ, _GetPathEnd@PathW@@QBEPBGXZ, _GetPathFirst@Path@@QBEPBDXZ, _GetPathFirst@PathW@@QBEPBGXZ, _GetPathFirstEle@Path@@QBEPBVString@@XZ, _GetPathFirstEle@PathW@@QBEPBVStringW@@XZ, _GetPathHead@Path@@QBEPBDXZ, _GetPathHead@PathW@@QBEPBGXZ, _GetPathPath@Path@@QBEPBV1@XZ, _GetPathPath@PathW@@QBEPBV1@XZ, _GetPathRest@Path@@QBEPBDXZ, _GetPathRest@PathW@@QBEPBGXZ, _GetPathUnc@Path@@QBEPBVString@@XZ, _GetPathUnc@PathW@@QBEPBVStringW@@XZ, _StringCompare@String@@ABEHPBD@Z, _StringCompare@StringW@@ABEHPBG@Z, _Truncate@Path@@QBE_AVString@@I@Z, _Truncate@PathW@@QBE_AVStringW@@I@Z, ANSICompare, ANSIUpper, ConvertMbToUtf16, ConvertUtf16ToMb, ConvertUtf16ToUtf8, ConvertUtf8ToUtf16, IsUtf16HighSurrogate, IsUtf16LowSurrogate, IsUtf8BOM, OemCompare, OemUpper, PhpStrCmpA, PhpStrCmpW<br>
            RDS...: NSRL Reference Data Set<br>-
        5. ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

          ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :

          http://oldtimer.geekstogo.com/OTMoveIt3.exe

          ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

          ---> Copie (Ctrl+C) le texte suivant ci-dessous :

          :processes
          explorer.exe

          :files
          c:\program files\search settings

          :reg
          [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
          [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]

          :commands
          [purity]
          [emptytemp]
          [start explorer]
          [reboot]

          ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

          ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

          Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
          Accepte en cliquant sur YES.

          ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
          Le nom du rapport correspond au moment de sa création : date_heure.log
          1. ========== PROCESSES ==========
            Process explorer.exe killed successfully.
            ========== FILES ==========
            File/Folder c:\program files\search settings not found.
            ========== REGISTRY ==========
            Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\\ not found.
            Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\\ not found.
            ========== COMMANDS ==========
            File delete failed. C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\~DF4B4A.tmp scheduled to be deleted on reboot.
            User's Temp folder emptied.
            User's Temporary Internet Files folder emptied.
            User's Internet Explorer cache folder emptied.
            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
            Local Service Temp folder emptied.
            Local Service Temporary Internet Files folder emptied.
            File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_168.dat scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_634.dat scheduled to be deleted on reboot.
            Windows Temp folder emptied.
            Java cache emptied.
            FireFox cache emptied.
            Temp folders emptied.
            Explorer started successfully

            OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 04092009_191851

            Files moved on Reboot...
            C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\~DF4B4A.tmp moved successfully.
            File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
            File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be moved on reboot.
            File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
            File C:\WINDOWS\temp\Perflib_Perfdata_168.dat not found!
            File C:\WINDOWS\temp\Perflib_Perfdata_634.dat not found!
            • 1
            • 2