Virus non supprimables

Résolu
Bonjour,
Voilà j'ai Bitdefender et je viens d'effectuer une analyse approfondie. A la fin il y a marqué qu'il y a 6 fichiers infectés mais je ne peux effectuer aucune action sur ces fichiers.
Voici ce qu'il y a marqué:
Nom de l'objet Nom de la menace État final
[System]=]HKEY_USERS\S-1-5-21-1831035316-3038454185-1936441505-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\kkieg=]C:\USERS\UTILISATEUR\APPDATA\LOCAL\KKIEG.EXE Gen:Adware.Heur.pq0@j8ojbcji Aucune action possible
[System]=]C:\Users\utilisateur\AppData\Local\kkieg.exe [2904] (disk) Gen:Adware.Heur.pq0@j8ojbcji Aucune action possible
C:\Users\utilisateur\AppData\Local\kkieg.exe Gen:Adware.Heur.pq0@j8ojbcji Échec du déplacement en quarantaine
C:\Users\utilisateur\AppData\Local\kkieg.exe Gen:Adware.Heur.pq0@j8ojbcji Aucune action possible
C:\Users\utilisateur\AppData\Local\kkieg.exe Gen:Adware.Heur.pq0@j8ojbcji Aucune action possible
[System]=]C:\Users\utilisateur\AppData\Local\kkieg.exe [2904] (memory dump)

Ce sont les fichiers que je ne peux pas supprimer et ils sont .exe (c'est pas anodin).
Pourriez-vous m'aider ? Merci d'avance.
Configuration: Windows Vista Internet Explorer 7.0

34 réponses

Résumé de la discussion

Le sujet concerne une détection par Bitdefender de six fichiers infectés (Gen:Adware.Heur.pq0@j8ojbcji) non supprimables ni mis en quarantaine sur Windows Vista, nécessitant une aide pour l'élimination. Plusieurs réponses évoquent la poursuite du nettoyage avec des outils additionnels et des droits administrateur, en préconisant l'exécution en tant qu'administrateur et le recours à RSIT et à des rapports détaillés. Des échanges suggèrent aussi de laisser l'outil terminer le processus, de générer des rapports RSIT ou USBFix et de vérifier les éléments persistants comme les fichiers autorun.inf et les entrées Run. D'autres échanges précisent que des éléments persistants peuvent être présents sur des supports amovibles et que l'analyse des rapports USBFix aide à identifier les zones à nettoyer en profondeur.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonsoir,

    Pas Malwarebytes maintenant !!

    ▶ Télécharge Random's System Information Tool (RSIT).

    ▶ Un tutoriel sera à ta disposition sur mon site web pour l'installer et l'utiliser correctement.

    ▶ Double clique sur RSIT.exe pour lancer l'outil.

    ▶ Clique sur 'Continue' à l'écran Disclaimer.

    ▶ Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

    ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports.

    ( C:\RSIT\log.txt et C:\RSIT\info.txt )

    CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller

    Comment héberger les rapports trop longs de RSIT ??
    1. Contributeur
      Pas de soucis Geoffrey , je te laisses faire :)

      J'ai été certes un peu trop vite ....
  2. Contributeur sécurité
    Il est préférable de voir un rapport de diagnostic avant de faire exécuter Malwarebytes ;)
    1. J'exécute et il y a marqué: "listing event logs". Est-ce que ça prend du temps ?
      1. Contributeur sécurité
        cela peut durer quelques minutes... Laisse-le terminer sans rien toucher ;)
        1. Non c'est bon.
          Voici les rapports:
          info.txt logfile of random's system information tool 1.06 2009-10-18 21:59:35

          ======Uninstall list======

          -->"C:\Program Files\Creative Installation Information\CD_RIPPER_UNICODE_2\Setup.exe" /remove /l0x040c
          -->"C:\Program Files\Creative Installation Information\CREATIVE_SYNC_MANAGER_U\Setup.exe" /remove /l0x040c
          -->"C:\Program Files\Creative Installation Information\CREATIVE_VIDEO_CONVERTER\Setup.exe" /remove /l0x040c
          -->"C:\Program Files\Creative Installation Information\ZEN_MTP_MEDIA_EXPLORER\Setup.exe" /remove /l0x040c
          -->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
          -->"C:\Program Files\HP Games\Blasterball 2 Revolution\Uninstall.exe"
          -->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
          -->"C:\Program Files\HP Games\Bricks of Egypt\Uninstall.exe"
          -->"C:\Program Files\HP Games\Chicken Invaders 3 - Revenge of the Yolk\Uninstall.exe"
          -->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
          -->"C:\Program Files\HP Games\Crystal Maze\Uninstall.exe"
          -->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
          -->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
          -->"C:\Program Files\HP Games\FATE\Uninstall.exe"
          -->"C:\Program Files\HP Games\Fish Tycoon\Uninstall.exe"
          -->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
          -->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
          -->"C:\Program Files\HP Games\Jewel Quest\Uninstall.exe"
          -->"C:\Program Files\HP Games\Magic Academy\Uninstall.exe"
          -->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
          -->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
          -->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
          -->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
          -->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
          -->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
          -->"C:\Program Files\HP Games\Polar Golfer Pineapple Cup\Uninstall.exe"
          -->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
          -->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
          -->"C:\Program Files\HP Games\Shooting Stars Pool\Uninstall.exe"
          -->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
          -->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
          -->"C:\Program Files\HP Games\Super Granny\Uninstall.exe"
          -->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
          -->"C:\Program Files\HP Games\Virtual Villagers - A New Home\Uninstall.exe"
          -->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
          -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
          32 Bit HP CIO Components Installer-->MsiExec.exe /I{09BDEEF0-5590-457D-89A9-5DB2742F9BBF}
          Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
          Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Reader 8.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81000000003}
          Adobe Shockwave Player-->MsiExec.exe /X{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}
          AIM 6-->C:\Program Files\AIM6\uninst.exe
          ALTools Update-->"C:\Program Files\ESTsoft\ALUpdate\unins000.exe"
          ALZip-->"C:\Program Files\ESTsoft\ALZip\unins000.exe"
          AOL Toolbar 5.0-->"C:\Program Files\AOL\AOL Toolbar 5.0\uninstall.exe"
          Apple Application Support-->MsiExec.exe /I{0C34B801-6AEC-4667-B053-03A67E2D0415}
          Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
          Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
          AVIConverter 5.1.0-->C:\Program Files\AVIConverter\uninst.exe
          BitDefender Total Security 2009-->MsiExec.exe /X{8ACF317C-CA66-4363-AEBF-A073B124AA1A}
          Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch-->C:\Program Files\InstallShield Installation Information\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\setup.exe -runfromtemp -l0x0409
          Call of Duty(R) 4 - Modern Warfare(TM)-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x040c
          C'est pas Sorcier 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{620528FA-A345-40AA-B74C-376934350D9B}\setup.exe" -l0x40c -removeonly
          Creative System Information-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c /remove
          Creative ZEN-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D24DDB61-8868-46CF-BC36-BECC1674F0C1}\SETUP.EXE" -l0x40c /remove
          CyberLink YouCam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
          DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
          DVD Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
          Enquête à Versailles - Avec Vauban-->"C:\Program Files\nemopolis\Vauban\Vauban_Uninstall.exe"
          ESU for Microsoft Vista-->MsiExec.exe /I{AD3FDC40-BCF4-476D-A2D6-C4B154DD9DF5}
          Favorit-->c:\users\utilisateur\appdata\local\sqswmaw.bat
          GIMP 2.6.6-->"C:\Program Files\GIMP-2.0\setup\unins000.exe"
          Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe" /uninstall
          Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
          Hauppauge MCE XP/Vista Software Encoder (2.0.25149)-->C:\PROGRA~1\WinTV\UNSftMCE.EXE C:\PROGRA~1\WinTV\softMCE.LOG
          Hewlett-Packard Active Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
          Hewlett-Packard Asset Agent for Health Check-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
          HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
          HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD0E2B92-3814-46F0-893B-4612EA010C7E}\setup.exe" -l0x9 -removeonly
          HP Customer Participation Program 10.0-->C:\Program Files\Hewlett-Packard\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
          HP Doc Viewer-->MsiExec.exe /I{082702D5-5DD8-4600-BCE5-48B15174687F}
          HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9885A11E-60E4-417C-B58B-8B31B21C0B8A}\setup.exe" -l0x9 -removeonly
          HP Help and Support-->MsiExec.exe /I{28EDCE9C-3304-4331-8AB3-F3EBE94C35B4}
          HP Imaging Device Functions 10.0-->C:\Program Files\Hewlett-Packard\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
          HP Photosmart All-In-One Driver Software 10.0 Rel .2-->C:\Program Files\Hewlett-Packard\Digital Imaging\{20B30DC1-E423-4939-B51D-05C58B0F9BBB}\setup\hpzscr01.exe -datfile hposcr21.dat -onestop
          HP Photosmart Essential 2.5-->C:\Program Files\Hewlett-Packard\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
          HP Quick Launch Buttons 6.30 E1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x040c uninst
          HP QuickPlay 3.6-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
          HP QuickTouch 1.00 C4-->MsiExec.exe /I{7DC4A410-9986-4329-9E5D-687B2C42CA39}
          HP Smart Web Printing-->C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
          HP Solution Center 10.0-->C:\Program Files\Hewlett-Packard\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
          HP Total Care Advisor-->MsiExec.exe /X{b02df929-29a7-4fd2-9a70-81a644b635f7}
          HP Update-->MsiExec.exe /X{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}
          HP User Guides 0088-->MsiExec.exe /I{8347A7A5-4AB8-433F-82AA-496B0D189A9B}
          HP Wireless Assistant-->MsiExec.exe /I{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}
          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
          Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
          Intel® Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
          Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
          LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" -uninstall
          Les Sims™ Histoires de vie-->MsiExec.exe /I{2284D904-C138-4B58-93EC-5C362AB5130A}
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Microsoft .NET Framework 1.1 Hotfix (KB929729)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M929729\M929729Uninstall.msp"
          Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
          Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
          Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
          Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
          Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
          Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
          Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
          Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
          Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
          Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
          Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
          Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
          Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
          Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
          Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
          Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
          Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
          Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
          Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
          Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
          Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
          Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
          Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
          Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
          Motorola SM56 Data Fax Modem-->rundll32.exe sm56co6a.dll,SM56UnInstaller
          MSCU for Microsoft Vista-->MsiExec.exe /I{E87F5651-CE15-493F-AE99-3B670E25A54E}
          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          muvee autoProducer 6.1-->C:\Program Files\InstallShield Installation Information\{250E9609-E830-43EB-B379-DAB7546A2422}\muveesetup.exe -removeonly -runfromtemp
          My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
          NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
          OCR Software by I.R.I.S. 10.0-->C:\Program Files\Hewlett-Packard\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
          Orange - Logiciels Internet-->C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
          PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
          QuickPlay SlingPlayer 0.4.4-->"C:\Program Files\HP\QuickPlay\unins000.exe"
          QuickTime-->MsiExec.exe /I{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}
          Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
          Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
          RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x40c anything
          Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
          Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
          Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
          Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
          Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
          Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
          Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
          Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
          Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
          Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
          Shop for HP Supplies-->C:\Program Files\Hewlett-Packard\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
          Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
          Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
          Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
          VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
          Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
          VLC media player 1.0.2-->C:\Program Files\VideoLAN\VLC\uninstall.exe
          Vuze-->C:\Program Files\Vuze\uninstall.exe
          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
          Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
          Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
          Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
          Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
          Xfire (remove only)-->"C:\Program Files\Xfire\uninst.exe"

          ======Security center information======

          AV: BitDefender Antivirus
          FW: BitDefender Firewall
          AS: BitDefender Antispyware
          AS: Windows Defender

          ======System event log======

          Computer Name: PC-de-utilisate
          Event Code: 3004
          Message: L’agent de protection en temps réel Windows Defender a détecté des modifications. Microsoft vous recommande d’analyser les logiciels responsables de ces modifications, à la recherche de risques potentiels. Vous pouvez vous servir des informations relatives au fonctionnement de ces programmes pour autoriser ou non leur exécution, ou pour les supprimer de l’ordinateur. N’autorisez les modifications que si vous faites confiance au programme ou à l’éditeur de logiciel. Windows Defender ne peut pas annuler les modifications que vous autorisez.
          Pour plus d’informations, consultez les données suivantes :
          Non applicable
          ID d’analyse : {6D904094-230F-4D06-834A-B1E263792700}
          Utilisateur : PC-de-utilisate\utilisateur
          Nom : Unknown
          ID :
          ID de gravité :
          ID de catégorie :
          Chemin d’accès trouvé : iemain:HKCU@S-1-5-21-1831035316-3038454185-1936441505-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page
          Type d’alerte : Logiciel non classifié
          Type de détection :
          Record Number: 157771
          Source Name: Microsoft-Windows-Windows Defender
          Time Written: 20091018184322.000000-000
          Event Type: Avertissement
          User:

          Computer Name: PC-de-utilisate
          Event Code: 4
          Message: Le spouleur d’impression n’a pas pu rouvrir une connexion d’imprimante existante car il n’a pas pu lire les informations de configuration dans la clé de Registre S-1-5-18\Printers\Connections. Le spouleur d’impression n’a pas pu ouvrir la clé de Registre. Ceci peut se produire si la clé de Registre est endommagée ou absente, ou si le Registre est momentanément indisponible.
          Record Number: 157775
          Source Name: Microsoft-Windows-SpoolerWin32SPL
          Time Written: 20091018185400.000000-000
          Event Type: Avertissement
          User:

          Computer Name: PC-de-utilisate
          Event Code: 4
          Message: Le spouleur d’impression n’a pas pu rouvrir une connexion d’imprimante existante car il n’a pas pu lire les informations de configuration dans la clé de Registre S-1-5-18\Printers\Connections. Le spouleur d’impression n’a pas pu ouvrir la clé de Registre. Ceci peut se produire si la clé de Registre est endommagée ou absente, ou si le Registre est momentanément indisponible.
          Record Number: 157776
          Source Name: Microsoft-Windows-SpoolerWin32SPL
          Time Written: 20091018185400.000000-000
          Event Type: Avertissement
          User:

          Computer Name: PC-de-utilisate
          Event Code: 4
          Message: Le spouleur d’impression n’a pas pu rouvrir une connexion d’imprimante existante car il n’a pas pu lire les informations de configuration dans la clé de Registre S-1-5-18\Printers\Connections. Le spouleur d’impression n’a pas pu ouvrir la clé de Registre. Ceci peut se produire si la clé de Registre est endommagée ou absente, ou si le Registre est momentanément indisponible.
          Record Number: 157780
          Source Name: Microsoft-Windows-SpoolerWin32SPL
          Time Written: 20091018195404.000000-000
          Event Type: Avertissement
          User:

          Computer Name: PC-de-utilisate
          Event Code: 4
          Message: Le spouleur d’impression n’a pas pu rouvrir une connexion d’imprimante existante car il n’a pas pu lire les informations de configuration dans la clé de Registre S-1-5-18\Printers\Connections. Le spouleur d’impression n’a pas pu ouvrir la clé de Registre. Ceci peut se produire si la clé de Registre est endommagée ou absente, ou si le Registre est momentanément indisponible.
          Record Number: 157781
          Source Name: Microsoft-Windows-SpoolerWin32SPL
          Time Written: 20091018195404.000000-000
          Event Type: Avertissement
          User:

          =====Application event log=====

          Computer Name: PC-de-utilisate
          Event Code: 1530
          Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

          DÉTAIL -
          2 user registry handles leaked from \Registry\User\S-1-5-21-1831035316-3038454185-1936441505-1000:
          Process 1948 (\Device\HarddiskVolume1\WINDOWS\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-1831035316-3038454185-1936441505-1000\Software\Policies
          Process 1948 (\Device\HarddiskVolume1\WINDOWS\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-1831035316-3038454185-1936441505-1000\Software

          Record Number: 46486
          Source Name: Microsoft-Windows-User Profiles Service
          Time Written: 20091018171723.000000-000
          Event Type: Avertissement
          User: AUTORITE NT\SYSTEM

          Computer Name: PC-de-utilisate
          Event Code: 5007
          Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
          Record Number: 46514
          Source Name: WerSvc
          Time Written: 20091018175542.000000-000
          Event Type: Erreur
          User:

          Computer Name: PC-de-utilisate
          Event Code: 1002
          Message: Le programme Explorer.EXE version 6.0.6000.16771 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans l’application Rapports et solutions aux problèmes du Panneau de configuration. ID de processus : d80 Heure de début : 01ca501bcb5b49ce Heure de fin : 47
          Record Number: 46518
          Source Name: Application Hang
          Time Written: 20091018195250.000000-000
          Event Type: Erreur
          User:

          Computer Name: PC-de-utilisate
          Event Code: 1002
          Message: Le programme explorer.exe version 6.0.6000.16771 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans l’application Rapports et solutions aux problèmes du Panneau de configuration. ID de processus : f54 Heure de début : 01ca502c92d7c22e Heure de fin : 31
          Record Number: 46521
          Source Name: Application Hang
          Time Written: 20091018195320.000000-000
          Event Type: Erreur
          User:

          Computer Name: PC-de-utilisate
          Event Code: 1002
          Message: Le programme explorer.exe version 6.0.6000.16771 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans l’application Rapports et solutions aux problèmes du Panneau de configuration. ID de processus : 162c Heure de début : 01ca502ca4cea2ae Heure de fin : 47
          Record Number: 46523
          Source Name: Application Hang
          Time Written: 20091018195412.000000-000
          Event Type: Erreur
          User:

          =====Security event log=====

          Computer Name: PC-de-utilisate
          Event Code: 4624
          Message: L’ouverture de session d’un compte s’est correctement déroulée.

          Sujet :
          ID de sécurité : S-1-5-18
          Nom du compte : PC-DE-UTILISATE$
          Domaine du compte : WORKGROUP
          ID d’ouverture de session : 0x3e7

          Type d’ouverture de session : 5

          Nouvelle ouverture de session :
          ID de sécurité : S-1-5-18
          Nom du compte : SYSTEM
          Domaine du compte : AUTORITE NT
          ID d’ouverture de session : 0x3e7
          GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

          Informations sur le processus :
          ID du processus : 0x2bc
          Nom du processus : C:\WINDOWS\System32\services.exe

          Informations sur le réseau :
          Nom de la station de travail :
          Adresse du réseau source : -
          Port source : -

          Informations détaillées sur l’authentification :
          Processus d’ouverture de session : Advapi
          Package d’authentification : Negotiate
          Services en transit : -
          Nom du package (NTLM uniquement) : -
          Longueur de la clé : 0

          Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

          Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

          Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

          Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

          Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

          Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
          - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
          - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
          - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
          - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
          Record Number: 23345
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090702153315.863270-000
          Event Type: Succès de l'audit
          User:

          Computer Name: PC-de-utilisate
          Event Code: 4672
          Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

          Sujet :
          ID de sécurité : S-1-5-18
          Nom du compte : SYSTEM
          Domaine du compte : AUTORITE NT
          ID d’ouverture de session : 0x3e7

          Privilèges : SeAssignPrimaryTokenPrivilege
          SeTcbPrivilege
          SeSecurityPrivilege
          SeTakeOwnershipPrivilege
          SeLoadDriverPrivilege
          SeBackupPrivilege
          SeRestorePrivilege
          SeDebugPrivilege
          SeAuditPrivilege
          SeSystemEnvironmentPrivilege
          SeImpersonatePrivilege
          Record Number: 23346
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090702153315.863270-000
          Event Type: Succès de l'audit
          User:

          Computer Name: PC-de-utilisate
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume1\WINDOWS\System32\drivers\PnkBstrK.sys
          Record Number: 23347
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090702153851.090270-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-de-utilisate
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume1\WINDOWS\System32\drivers\PnkBstrK.sys
          Record Number: 23348
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090702153935.860270-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-de-utilisate
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume1\WINDOWS\System32\drivers\PnkBstrK.sys
          Record Number: 23349
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090702154746.577270-000
          Event Type: Échec de l'audit
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\CyberLink\Power2Go;C:\Program Files\QuickTime\QTSystem;C:\Program Files\ESTsoft\ALZip;C:\Program Files\QuickTime\QTSystem\
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
          "PROCESSOR_ARCHITECTURE"=x86
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "USERNAME"=SYSTEM
          "windir"=%SystemRoot%
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 6, GenuineIntel
          "PROCESSOR_REVISION"=1706
          "NUMBER_OF_PROCESSORS"=2
          "PLATFORM"=MCD
          "PCBRAND"=Pavilion
          "OnlineServices"=Services en ligne
          "USERPART"=F:
          "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip
          "QTJAVA"=C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip

          -----------------EOF-----------------
          Logfile of random's system information tool 1.06 (written by random/random)
          Run by utilisateur at 2009-10-18 21:59:22
          Microsoft® Windows Vista™ Édition Familiale Premium
          System drive C: has 61 GB (43%) free of 141 GB
          Total RAM: 3070 MB (45% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 21:59:33, on 18/10/2009
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16890)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\WINDOWS\System32\rundll32.exe
          C:\Program Files\Synaptics\SynTP\SynTPStart.exe
          C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
          C:\WINDOWS\RtHDVCpl.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
          C:\Program Files\Hp\QuickPlay\QPService.exe
          C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
          C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
          C:\WINDOWS\System32\rundll32.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
          C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
          C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
          C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
          C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
          C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
          C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
          C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
          C:\Users\utilisateur\AppData\Local\kkieg.exe
          C:\WINDOWS\ehome\ehtray.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
          C:\Users\utilisateur\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Windows\system32\wuauclt.exe
          C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
          C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
          C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
          C:\Program Files\BitDefender\BitDefender 2009\uiscan.exe
          C:\Program Files\OrangeHSS\systray\systrayapp.exe
          C:\Program Files\Internet Explorer\IEUser.exe
          C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
          C:\Windows\explorer.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          c:\program files\aol\aol toolbar 5.0\AolTbServer.exe
          C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
          C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Users\utilisateur\Desktop\RSIT.exe
          C:\Program Files\trend micro\utilisateur.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail?kw=
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
          O1 - Hosts: ::1 localhost
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
          O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
          O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
          O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
          O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
          O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
          O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
          O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
          O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
          O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
          O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
          O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
          O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe
          O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
          O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
          O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
          O4 - HKCU\..\Run: [kkieg] "c:\users\utilisateur\appdata\local\kkieg.exe" kkieg
          O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\utilisateur\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
          O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
          O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
          O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
          O13 - Gopher Prefix:
          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
          O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
          O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
          O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
          O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
          1. Contributeur sécurité
            Pourrais-tu me renvoyer le rapport log.txt stp ?? Il est incomplet...

            D'où la nécessité de les héberger ;)
            1. Ok le voici:
              Logfile of random's system information tool 1.06 (written by random/random)
              Run by utilisateur at 2009-10-18 21:59:22
              Microsoft® Windows Vista™ Édition Familiale Premium
              System drive C: has 61 GB (43%) free of 141 GB
              Total RAM: 3070 MB (45% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 21:59:33, on 18/10/2009
              Platform: Windows Vista (WinNT 6.00.1904)
              MSIE: Internet Explorer v7.00 (7.00.6000.16890)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\Dwm.exe
              C:\Windows\system32\taskeng.exe
              C:\WINDOWS\System32\rundll32.exe
              C:\Program Files\Synaptics\SynTP\SynTPStart.exe
              C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
              C:\WINDOWS\RtHDVCpl.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
              C:\Program Files\Hp\QuickPlay\QPService.exe
              C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
              C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
              C:\WINDOWS\System32\rundll32.exe
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
              C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
              C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
              C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
              C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
              C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
              C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
              C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
              C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
              C:\Users\utilisateur\AppData\Local\kkieg.exe
              C:\WINDOWS\ehome\ehtray.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
              C:\Users\utilisateur\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Windows\system32\wuauclt.exe
              C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
              C:\Program Files\BitDefender\BitDefender 2009\uiscan.exe
              C:\Program Files\OrangeHSS\systray\systrayapp.exe
              C:\Program Files\Internet Explorer\IEUser.exe
              C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
              C:\Windows\explorer.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              c:\program files\aol\aol toolbar 5.0\AolTbServer.exe
              C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
              C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
              C:\Windows\system32\SearchFilterHost.exe
              C:\Users\utilisateur\Desktop\RSIT.exe
              C:\Program Files\trend micro\utilisateur.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail?kw=
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
              O1 - Hosts: ::1 localhost
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
              O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
              O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
              O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
              O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
              O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
              O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
              O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
              O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
              O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
              O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
              O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
              O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
              O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
              O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
              O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
              O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe
              O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
              O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
              O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
              O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
              O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
              O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
              O4 - HKCU\..\Run: [kkieg] "c:\users\utilisateur\appdata\local\kkieg.exe" kkieg
              O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\utilisateur\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
              O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
              O8 - Extra context menu item: &Recherche AOL Toolbar - c:\program files\aol\aol toolbar 5.0\resources\fr-fr\local\search.html
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
              O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
              O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
              O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
              O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
              O13 - Gopher Prefix:
              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
              O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
              O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
              O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
              O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
              O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
              O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
              O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
              1. Contributeur sécurité
                Ok... C'est bien ce que je pensais... Infection Navipromo.

                Ton PC est infecté par l'ad-aware Navipromo/Magic Control qui affiche des publicités intempestives.
                Il s'installe via certains programmes, dont ceux-ci :

                ● Funky Emoticons
                ● go-astro
                ● GoRecord
                ● HotTVPlayer / HotTVPlayer & Paris Hilton
                ● Live-Player
                ● MailSkinner
                ● Messenger Skinner
                ● Instant Access
                ● InternetGameBox
                ● Officiale Emule (Version d'Emule modifiée)
                ● Original Solitaire
                ● SuperSexPlayer
                ● Speed Downloading
                ● Sudoplanet
                ● Webmediaplayer

                /!\ Fais attention de ne pas faire la même erreur, donc évite ces programmes /!\

                ▶ Télécharge sur le bureau Navilog1

                *Si ton antivirus s'affole , le désactiver
                sous vista : Clic-droit sur le raccourci Navilog1 présent sur le bureau et choisis "Exécuter en tant qu'administrateur
                sous XP : double-clic dessus pour l'installer et le lancer

                ▶ taper F
                ▶ Appuyer sur une touche jusqu' arriver aux options
                ▶ Choisir Recherche/désinfection automatique ( = taper 1 )

                ▶un rapport : fixnavi.txt dans ==> C:

                ▶le copier et le coller dans la réponse
                1. Contributeur sécurité
                  Les antivirus ne peuvent pas supprimer cette infection...
                  1. Voici le rapport:
                    Fix Navipromo version 4.0.3 commencé le 18/10/2009 22:19:30,13

                    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                    !!! Postez ce rapport sur le forum pour le faire analyser !!!

                    Outil exécuté depuis C:\Program Files\navilog1

                    Mise à jour le 18.10.2009 à 10h00 par IL-MAFIOSO

                    Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
                    X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz )
                    BIOS : Ver 1.00PARTTBL
                    USER : utilisateur ( Administrator )
                    BOOT : Normal boot

                    Antivirus : BitDefender Antivirus 12.0 (Activated)
                    Firewall : BitDefender Firewall 12.0 (Activated)

                    C:\ (Local Disk) - NTFS - Total:137 Go (Free:59 Go)
                    D:\ (Local Disk) - NTFS - Total:149 Go (Free:148 Go)
                    E:\ (Local Disk) - NTFS - Total:11 Go (Free:2 Go)
                    F:\ (CD or DVD)

                    Recherche executée en mode normal

                    Nettoyage exécuté au redémarrage de l'ordinateur

                    C:\Users\utilisateur\AppData\Local\kkieg.dat supprimé !
                    C:\Users\utilisateur\AppData\Local\kkieg_nav.dat supprimé !
                    C:\Users\utilisateur\AppData\Local\kkieg_navps.dat supprimé !
                    C:\Users\utilisateur\AppData\Local\kkieg.bat supprimé !
                    C:\Users\utilisateur\AppData\Local\sqswmaw.bat supprimé !

                    Nettoyage contenu C:\Windows\Temp effectué !
                    Nettoyage contenu C:\Users\UTILIS~1\AppData\Local\Temp effectué !

                    *** Sauvegarde du Registre vers dossier Safebackup ***

                    sauvegarde du Registre réalisée avec succès !

                    *** Nettoyage Registre ***

                    Nettoyage Registre Ok

                    *** Scan terminé 18/10/2009 22:27:19,24 ***

                    Est-ce bon ?
                    1. Contributeur sécurité
                      Ok maintenant :

                      ▶ Rends-toi à cette adresse afin de télécharger UsbFix (créé par Chiquitine29 & C_XX) :

                      ▶ https://www.androidworld.fr/

                      ▶ Clique sur TÉLÉCHARGER et enregistre-le sur ton bureau.

                      ▶ tutoriel recherche

                      ▶ Double-clique sur UsbFix présent sur ton bureau, l'installation se fera automatiquement

                      ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                      ▶ Choisi l'option 1 (recherche)

                      ▶ Laisse travailler l'outil

                      ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra

                      * Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

                      * Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

                      * Note : "SniffC.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                      1. Le voilà:

                        ############################## | UsbFix V6.042 |

                        User : utilisateur (Administrateurs) # PC-DE-UTILISATE
                        Update on 15/10/2009 by Chiquitine29, C_XX & Chimay8
                        Start at: 22:37:01 | 18/10/2009
                        Website : http://pagesperso-orange.fr/NosTools/index.html

                        Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz
                        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-bit) #
                        Internet Explorer 7.0.6000.16890
                        Windows Firewall Status : Disabled
                        AV : BitDefender Antivirus 12.0 [ Enabled | Updated ]
                        FW : BitDefender Firewall[ Enabled ]12.0

                        C:\ -> Disque fixe local # 137,25 Go (59,72 Go free) [OS] # NTFS
                        D:\ -> Disque fixe local # 149,05 Go (148,96 Go free) [DATA] # NTFS
                        E:\ -> Disque fixe local # 11,8 Go (2,14 Go free) [HP_RECOVERY] # NTFS
                        F:\ -> Disque CD-ROM
                        G:\ -> Disque amovible # 7,45 Go (163,56 Mo free) [PIATTE] # FAT32

                        ############################## | Processus actifs |

                        C:\Windows\System32\smss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                        C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\Explorer.EXE
                        C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\PnkBstrA.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
                        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\SearchIndexer.exe
                        C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
                        C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\conime.exe
                        c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                        C:\Windows\notepad.exe
                        C:\Windows\system32\wuauclt.exe
                        C:\WINDOWS\System32\rundll32.exe
                        C:\WINDOWS\System32\rundll32.exe
                        C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                        C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                        C:\WINDOWS\RtHDVCpl.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                        C:\Program Files\Hp\QuickPlay\QPService.exe
                        C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                        C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
                        C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                        C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                        C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                        C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
                        C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                        C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
                        C:\Windows\servicing\TrustedInstaller.exe
                        C:\WINDOWS\ehome\ehtray.exe
                        C:\Program Files\Windows Media Player\wmpnscfg.exe
                        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                        C:\Users\utilisateur\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                        C:\Program Files\OrangeHSS\Launcher\Launcher.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                        C:\Program Files\Windows Media Player\wmpnetwk.exe
                        C:\Program Files\Internet Explorer\ieuser.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                        C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
                        c:\program files\aol\aol toolbar 5.0\AolTbServer.exe
                        C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
                        C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
                        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
                        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
                        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
                        C:\Program Files\OrangeHSS\systray\systrayapp.exe
                        C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
                        C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
                        C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
                        C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
                        C:\Windows\system32\WUDFHost.exe
                        C:\Windows\system32\WUDFHost.exe
                        C:\Windows\system32\SearchProtocolHost.exe
                        C:\Windows\system32\SearchFilterHost.exe
                        C:\Windows\system32\wbem\wmiprvse.exe

                        ################## | Fichiers # Dossiers infectieux |

                        E:\desktop.ini

                        ################## | Registre # Clés Run infectieuses |

                        ################## | Registre # Mountpoints2 |

                        ################## | ! Fin du rapport # UsbFix V6.042 ! |
                        1. Contributeur sécurité
                          ▶ tutoriel nettoyage

                          ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

                          ▶ Double clic sur le raccourci UsbFix présent sur ton bureau

                          ▶ choisi l'option 2 ( Suppression )

                          ▶ Ton bureau disparaîtra et le pc redémarrera .

                          ▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

                          ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .

                          ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                          ▶ /!\ UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.androidworld.fr/

                          ▶ Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.

                          ▶ Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

                          ▶ Merci d'avance pour ta contribution !!
                          1. Là je n'ai pas le temps. Je ferais cela demain sans problème. Merci beaucoup de ton aide et du temps que tu as passé pour moi.
                            Bonne soirée.
                            1. Contributeur sécurité
                              Ok pas de soucis ;-)

                              Bonne fin de soirée, à demain
                              • 1
                              • 2