"your computer is infected"

Résolu
Bonjour,

une croix blanche sur fond rouge dans la barre de taches + un "delself" sur le bureau.
Je vous fournis le rapport SmitFraudix en démarrage mode sans échec :

OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode sans echec

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

C:\Program Files\akl\ supprimé

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» 404Fix

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

AntiXPVSTFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» RK

»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{167D02C3-8434-413B-B8BA-6935C6FCA742}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{167D02C3-8434-413B-B8BA-6935C6FCA742}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{167D02C3-8434-413B-B8BA-6935C6FCA742}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""

»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

Nettoyage terminé.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Fin

Merci pour votre aide !!
Configuration: Windows XP
Internet Explorer 6.0

35 réponses

Résumé de la discussion

Une infection sur Windows XP est décrite, avec une icône delself sur le bureau et une croix blanche dans la barre des tâches après l'exécution de SmitFraudFix en mode sans échec. Plusieurs outils et procédures ont été proposés, notamment OTMoveIt, nettoyage du registre, suppression des outils suspects et vérifications avec Malwarebytes pour éliminer les composants malveillants. Des réponses indiquent que l'icône et les outils peuvent être supprimés ou désinstallés et que des nettoyages et des points de restauration sont envisagés. En outre, un retour signale que delself.bat a été déplacé avec succès et que l'icône du bureau a disparu, montrant une progression nécessitant une vérification continue.

Bobot (l’IA à votre service)
  1. demarre win en mode echec puis demarer , executer et tape regedit
    cherche la clée :
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    puis donne moi la valeur
    si elle n'est pas normale , tu a un virus ,sinon pour aller plus vite va sur le site de msn france , clique messenger et tu a un scan gratuit dans la rubrique antivirus
    1
    1. Tout d'abord, merci beaucoup Verni29 !

      Je colle donc les 2 rapports :

      1)
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:41:40, on 12/10/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\ArchestrA\aaLogger.exe
      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Fichiers communs\ArchestrA\NTServApp.exe
      C:\WINDOWS\ICSVRNT.EXE
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
      C:\Program Files\Fichiers communs\ArchestrA\slssvc.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Apoint2K\Apoint.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\necmfk\necmfk.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
      C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
      C:\Program Files\Apoint2K\HidFind.exe
      C:\Program Files\Apoint2K\Apntex.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\WINDOWS\vVX1000.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\NCLAUNCH.EXe
      C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\MonHJK.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll (file missing)
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
      O4 - HKLM\..\Run: [NECMFK] C:\Program Files\necmfk\necmfk.exe
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
      O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
      O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O4 - Global Startup: Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g.lnk = ?
      O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
      O16 - DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} (3DVista Viewer Control) - http://www.3dvista.com/downloads/viewer3dv.cab
      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: avgrsstx.dll
      O23 - Service: ArchestrA Logger (aaLogger) - Invensys Systems, Inc. - C:\Program Files\Fichiers communs\ArchestrA\aaLogger.exe
      O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: FS Service Control - Wonderware Corporation - C:\Program Files\Fichiers communs\ArchestrA\NTServApp.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: InterCom Server (InterCom) - CNS International - C:\WINDOWS\ICSVRNT.EXE
      O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
      O23 - Service: Wonderware SuiteLink (slssvc) - Invensys Systems, Inc. - C:\Program Files\Fichiers communs\ArchestrA\slssvc.exe
      O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      O23 - Service: Wonderware NetDDE Helper (WWNetDDE) - Invensys Systems, Inc. - C:\Program Files\Fichiers communs\ArchestrA\wwnetdde.exe
      1
      1. Voici le log :

        Logfile of random's system information tool 1.04 (written by random/random)
        Run by prisci at 2008-10-12 14:21:17
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 3 GB (10%) free of 34 GB
        Total RAM: 447 MB (34% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 14:22:00, on 12/10/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Fichiers communs\ArchestrA\aaLogger.exe
        C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Fichiers communs\ArchestrA\NTServApp.exe
        C:\WINDOWS\ICSVRNT.EXE
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
        C:\Program Files\Microsoft LifeCam\MSCamS32.exe
        C:\Program Files\Fichiers communs\ArchestrA\slssvc.exe
        C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
        C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
        C:\WINDOWS\System32\svchost.exe
        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
        C:\PROGRA~1\AVG\AVG8\avgemc.exe
        C:\Program Files\Apoint2K\Apoint.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\necmfk\necmfk.exe
        C:\WINDOWS\AGRSMMSG.exe
        C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
        C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
        C:\Program Files\Apoint2K\HidFind.exe
        C:\Program Files\Apoint2K\Apntex.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        C:\WINDOWS\vVX1000.exe
        C:\PROGRA~1\AVG\AVG8\avgtray.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\NCLAUNCH.EXe
        C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
        C:\Documents and Settings\prisci\Bureau\RSIT.exe
        C:\Program Files\Trend Micro\HijackThis\prisci.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll (file missing)
        O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
        O4 - HKLM\..\Run: [NECMFK] C:\Program Files\necmfk\necmfk.exe
        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
        O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
        O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O4 - Global Startup: Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g.lnk = ?
        O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
        O16 - DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} (3DVista Viewer Control) - http://www.3dvista.com/downloads/viewer3dv.cab
        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
        O20 - AppInit_DLLs: avgrsstx.dll
        O23 - Service: ArchestrA Logger (aaLogger) - Invensys Systems, Inc. - C:\Program Files\Fichiers communs\ArchestrA\aaLogger.exe
        O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
        O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
        O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: FS Service Control - Wonderware Corporation - C:\Program Files\Fichiers communs\ArchestrA\NTServApp.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: InterCom Server (InterCom) - CNS International - C:\WINDOWS\ICSVRNT.EXE
        O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
        O23 - Service: Wonderware SuiteLink (slssvc) - Invensys Systems, Inc. - C:\Program Files\Fichiers communs\ArchestrA\slssvc.exe
        O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe
        O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
        O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
        O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
        O23 - Service: Wonderware NetDDE Helper (WWNetDDE) - Invensys Systems, Inc. - C:\Program Files\Fichiers communs\ArchestrA\wwnetdde.exe
        1
        1. -Voici le rapport OTMoveIt:

          C:\Delself illimination.txt moved successfully.
          C:\Program Files\guhaqdc moved successfully.
          C:\Documents and Settings\All Users\Application Data\ncbadczw moved successfully.
          < [HKEY_CURRENT_USER\software\microsoft\windows\currentversion­\explorer\mountpoints2\{d9fb4fe0-855f-11dc-b71e-00038a000015­}] >
          File/Folder [HKEY_CURRENT_USER\software\microsoft\windows\currentversion­\explorer\mountpoints2\{d9fb4fe0-855f-11dc-b71e-00038a000015­}] not found.

          OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10132008_125841

          -Pour ce qui est de RavAntivirus, il m'indiquait dès son lancement que l'ordinateur était sain. Je l'ai laissé tourner quelques heures, mais à priori tout était OK.

          -Pour FlashDisinfector, pas de rapport.

          -Cependant, j'ai toujours l'icone "delself.bat" sur le bureau (ce n'est pas un message mais bel et bien une icone avec un engrenage jaune dans un encadré fond blanc, et bleu dans la partie superieure)

          Encore merci Verni 29 !!
          1
          1. Ca a fonctionné :"C:\Documents and Settings\prisci\Bureau\delself.bat moved successfully."

            Et je n'ai plus l'icone sur le bureau !
            1
            1. Contributeur sécurité
              1) Double-clique sur OTMoveIt.exe pour le lancer.
              Copie la liste qui se trouve en citation ci-dessous et colle-la dans le cadre de gauche de OTMoveIt sous Paste List of Files/Folders to move.

              H:\A graver\Metallica - Death Magnetic\06-metallica-cyande.mp3
              H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_41A45_JDCF.rar
              H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_51A55_UFCG.rar
              H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_56A60_FRVG.rar
              H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_61A65_UFCE.rar
              H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_66A70_UVBN.rar
              H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_71A75_UHDJ.rar
              H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_76A80_UJCF.rar
              H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_81A90_JCFG.rar
              H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_91A100_UJCV.rar
              H:\Film\Humour\Kaamelott\Livre 1\Vus\Kaamelott_1A5_GFRT.rar
              H:\Film\Humour\Kaamelott\Livre 1\Vus\Kaamelott_5A10_GHDE.rar
              H:\Film\Humour\Kaamelott\Livre 2\Kaamelott_51A60_GVCB.rar

              clique sur MoveIt! pour lancer la suppression.
              Le résultat apparaitra dans le cadre "Results".
              Clique sur Exit pour fermer.

              Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
              Il est possible que ton ordinateur redémarre pour supprimer les fichiers.

              2) Garde IE6, si tu le désires, mais la dernière version de IE est plus sécurisée.

              3) OUvre OTMoveIT et clique sur cleanUp.
              Ceci devrait faire la même chose que ToolsCleaner ( enlevre les outils utilisés ).

              A+
              Il
              1
              1. 1) Voici le rapport :

                H:\A graver\Metallica - Death Magnetic\06-metallica-cyande.mp3 moved successfully.
                H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_41A45_JDCF.rar moved successfully.
                H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_51A55_UFCG.rar moved successfully.
                H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_56A60_FRVG.rar moved successfully.
                H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_61A65_UFCE.rar moved successfully.
                H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_66A70_UVBN.rar moved successfully.
                H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_71A75_UHDJ.rar moved successfully.
                H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_76A80_UJCF.rar moved successfully.
                H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_81A90_JCFG.rar moved successfully.
                H:\Film\Humour\Kaamelott\Livre 1\Kaamelott_91A100_UJCV.rar moved successfully.
                H:\Film\Humour\Kaamelott\Livre 1\Vus\Kaamelott_1A5_GFRT.rar moved successfully.
                H:\Film\Humour\Kaamelott\Livre 1\Vus\Kaamelott_5A10_GHDE.rar moved successfully.
                H:\Film\Humour\Kaamelott\Livre 2\Kaamelott_51A60_GVCB.rar moved successfully.

                OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10152008_192343
                1
                1. Contributeur sécurité
                  Essaie avec OTMOveIT ( CleanUp ) et dis moi si effectivement, il a supprimé les outils qu'on a utilisé.

                  A+
                  1
                  1. 1) J'ai essayé Clean up de OTMove it, il a supprimé certains outils, je ne saurais te dire quoi, il n'a pas fait de rapport et s'est désinstallé lui-même. J'ai donc toujours Rav, disinfector, Rsit, Malwarebytes,...sur mon bureau.

                    2) J'ai utilisé CCleaner (Nettoyeur et Registre)

                    J'allais m'attaquer au point de restauration, je dois attendre ou je peux le faire dès maintenant?

                    A+
                    1
                    1. Contributeur sécurité
                      Désinstalle les autres outils :
                      RAV, Flash Désinfector et RSIT sont des fichiersr que tu supprimes manuellement.

                      Malwarebytes, garde le et passe le de temps en temps pour vérifier que ton PC est propre.

                      Après, tu peux faire la suite.

                      A+
                      1
                      1. Salut

                        Ca y est, tout est desinstallé et point de restauration créé !
                        Au passage, j'ai souvent un message dans la barre de taches qui m'indique que "ma mémoire virtuelle est insuffisante"...Comment puis-je y remedier ?

                        Un grand merci pour ton aide en tout cas, me voilà debarassé d'un tas de véroles, et ce, grâce à toi.
                        Tu m'as vraiment bien guidé !

                        A+
                        1
                        1. Contributeur sécurité
                          Si tu as ce message, c'est qu'il y a un réglage à faire pour augmenter cette mémoire virtuelle.

                          Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.
                          http://images.malwareremoval.com/random/RSIT.exe

                          Double clique sur RSIT.exe pour lancer l'outil.
                          Clique sur ' continue ' à l'écran Disclaimer.
                          Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
                          Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports
                          ( log.txt & info.txt )

                          A+
                          1
                          1. Contributeur sécurité
                            Bonjour, needYou

                            On continue.

                            1) poste moi un nouveau rapport Hijackthis.

                            2)
                            Pour cette manipulation, je te conseille de noter ou d'imprimer ce texte car la désinfection va se faire en mode sans échec et tu n'auras pas accès à Internet pour visualiser les consignes.
                            Autre astuce : Copie/colle le texte dans un fichier .txt que tu enregistres sur ton bureau. Tu le retrouveras alors sur ton bureau et en mode sans échec.

                            Tu télécharges MalwareBytes.
                            http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                            Tu l'installes. Choisis les options par défaut.
                            A la fin de l’installation, il te sera demandé de mettre à jour MalwareBytes et de l’exécuter .
                            Ne choisis que la mise à jour. Le logiciel sera lancé en mode sans échec.

                            Tu relances l'ordinateur en mode sans échec ( tapote la touche F8 après redémarrage ).
                            Tu choisis ton compte utilisateur.

                            Pour lancer MalwareBytes, double-clique sur le raccourci du bureau.

                            Dans l’onglet Recherche, sélectionne Exécuter un examen complet.
                            Clique sur recherche. Tu ne sélectionnes que les disques durs de l’ordinateur.
                            Clique sur lancer l’examen.

                            A la fin de la recherche, Comme il est demandé, clique sur afficher les résultats de la recherche.
                            Choisis alors Supprimer la selection pour nettoyer les infections.
                            Tu postes le rapport dans ton prochain message.

                            Si tu ne le retrouves pas, ouvre MalwareBytes et regarde dans l’onglet Rapport/logs. Il y est.
                            Clique dessus et choisir ouvrir.

                            le scan dure en moyenne 50 mn.

                            A+
                            -1
                            1. 1) Voici déjà mon rapport Hijackthis :

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 14:22:27, on 11/10/2008
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\System32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Fichiers communs\ArchestrA\aaLogger.exe
                              C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                              C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\Program Files\Fichiers communs\ArchestrA\NTServApp.exe
                              C:\WINDOWS\ICSVRNT.EXE
                              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                              C:\Program Files\Microsoft LifeCam\MSCamS32.exe
                              C:\Program Files\Fichiers communs\ArchestrA\slssvc.exe
                              C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                              C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                              C:\PROGRA~1\AVG\AVG8\avgemc.exe
                              C:\Documents and Settings\All Users\Application Data\ncbadczw\fitkneja.exe
                              C:\Program Files\Apoint2K\Apoint.exe
                              C:\Program Files\necmfk\necmfk.exe
                              C:\WINDOWS\AGRSMMSG.exe
                              C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                              C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              C:\WINDOWS\vVX1000.exe
                              C:\PROGRA~1\AVG\AVG8\avgtray.exe
                              C:\WINDOWS\system32\brastk.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\WINDOWS\NCLAUNCH.EXe
                              C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\WINDOWS\system32\fexkbqje.exe
                              C:\Program Files\Apoint2K\HidFind.exe
                              C:\Program Files\Apoint2K\Apntex.exe
                              C:\WINDOWS\system32\NOTEPAD.EXE
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\WINDOWS\system32\notepad.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                              O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll (file missing)
                              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                              O4 - HKLM\..\Run: [NECMFK] C:\Program Files\necmfk\necmfk.exe
                              O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                              O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                              O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                              O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                              O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
                              O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                              O4 - HKLM\..\Run: [brastk] C:\WINDOWS\system32\brastk.exe
                              O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
                              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [comui] C:\WINDOWS\system32\fexkbqje.exe
                              O4 - HKCU\..\Run: [brastk] C:\WINDOWS\system32\brastk.exe
                              O4 - HKLM\..\Policies\Explorer\Run: [9oFGMvO02k] C:\Documents and Settings\All Users\Application Data\ncbadczw\fitkneja.exe
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                              O4 - Global Startup: Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g.lnk = ?
                              O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                              O16 - DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} (3DVista Viewer Control) - http://www.3dvista.com/downloads/viewer3dv.cab
                              O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
                              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                              O20 - AppInit_DLLs: avgrsstx.dll
                              O21 - SSODL: ShProc - {618685D1-4E5A-F8ED-18F2-01B95CF4F502} - C:\Program Files\guhaqdc\ShProc.dll (file missing)
                              O23 - Service: ArchestrA Logger (aaLogger) - Invensys Systems, Inc. - C:\Program Files\Fichiers communs\ArchestrA\aaLogger.exe
                              O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                              O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
                              O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                              O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                              O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                              O23 - Service: FS Service Control - Wonderware Corporation - C:\Program Files\Fichiers communs\ArchestrA\NTServApp.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: InterCom Server (InterCom) - CNS International - C:\WINDOWS\ICSVRNT.EXE
                              O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                              O23 - Service: Wonderware SuiteLink (slssvc) - Invensys Systems, Inc. - C:\Program Files\Fichiers communs\ArchestrA\slssvc.exe
                              O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe
                              O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                              O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                              O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                              O23 - Service: Wonderware NetDDE Helper (WWNetDDE) - Invensys Systems, Inc. - C:\Program Files\Fichiers communs\ArchestrA\wwnetdde.exe
                              -1
                              1. 2) Et voici le rapport MalwareBytes :

                                Malwarebytes' Anti-Malware 1.28
                                Version de la base de données: 1253
                                Windows 5.1.2600 Service Pack 3

                                11/10/2008 21:26:09
                                mbam-log-2008-10-11 (21-26-09).txt

                                Type de recherche: Examen complet (C:\|)
                                Eléments examinés: 164182
                                Temps écoulé: 2 hour(s), 48 minute(s), 20 second(s)

                                Processus mémoire infecté(s): 0
                                Module(s) mémoire infecté(s): 0
                                Clé(s) du Registre infectée(s): 32
                                Valeur(s) du Registre infectée(s): 5
                                Elément(s) de données du Registre infecté(s): 0
                                Dossier(s) infecté(s): 3
                                Fichier(s) infecté(s): 65

                                Processus mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Module(s) mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Clé(s) du Registre infectée(s):
                                HKEY_CLASSES_ROOT\CLSID\{618685D1-4E5A-F8ED-18F2-01B95CF4F502} (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
                                HKEY_CLASSES_ROOT\CLSID\{0656a137-b161-cadd-9777-e37a75727e78} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CLASSES_ROOT\CLSID\{0b682cc1-fb40-4006-a5dd-99edd3c9095d} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CLASSES_ROOT\CLSID\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CLASSES_ROOT\CLSID\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CLASSES_ROOT\CLSID\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CLASSES_ROOT\CLSID\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CLASSES_ROOT\CLSID\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CLASSES_ROOT\CLSID\{54645654-2225-4455-44a1-9f4543d34545} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CLASSES_ROOT\CLSID\{5c7f15e1-f31a-44fd-aa1a-2ec63aaffd3a} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\dpcproxy (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\HOL5_VXIEWER.FULL.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Classes\hol5_vxiewer.full.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Classes\applications\accessdiver.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\fwbd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\HolLol (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mslagent (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Invictus (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Golden Palace Casino PT (Trojan.DNSChanger) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Golden Palace Casino NEW (Trojan.DNSChanger) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\iTunesMusic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\rdriv (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\wkey (Malware.Trace) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully.

                                Valeur(s) du Registre infectée(s):
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\shproc (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\brastk (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\brastk (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\9ofgmvo02k (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SystemCheck2 (Trojan.Agent) -> Quarantined and deleted successfully.

                                Elément(s) de données du Registre infecté(s):
                                (Aucun élément nuisible détecté)

                                Dossier(s) infecté(s):
                                C:\WINDOWS\mslagent (Adware.EGDAccess) -> Quarantined and deleted successfully.
                                C:\Program Files\Inet Delivery (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.

                                Fichier(s) infecté(s):
                                C:\Program Files\guhaqdc\ShProc.dll (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\brastk.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
                                C:\Documents and Settings\All Users\Application Data\ncbadczw\fitkneja.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
                                C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP795\A0099881.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\mslagent\2_mslagent.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
                                C:\WINDOWS\mslagent\mslagent.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
                                C:\WINDOWS\mslagent\uninstall.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
                                C:\Program Files\Inet Delivery\inetdl.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\Program Files\Inet Delivery\intdel.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\WINDOWS\a.bat (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\WINDOWS\base64.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\WINDOWS\FVProtect.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\WINDOWS\userconfig9x.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\WINDOWS\winsystem.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\WINDOWS\zip1.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\WINDOWS\zip2.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\WINDOWS\zip3.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\WINDOWS\zipped.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                C:\WINDOWS\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\iTunesMusic.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\akttzn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\anticipator.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\awtoolb.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\bsva-egihsg52.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\dpcproxy.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\emesx.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\h@tkeysh@@k.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\hoproxy.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\hxiwlgpm.dat (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\hxiwlgpm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\medup012.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\medup020.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\msgp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\msnbho.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\msvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\mtr2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\mwin32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\netode.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\newsd32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\ps1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\psof1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\psoft1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\regc64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\regm64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\Rundl1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\sncntr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\ssurf022.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\ssvchost.com (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\ssvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\sysreq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\taack.dat (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\taack.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\temp#01.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\thun.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\thun32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\VBIEWER.OCX (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\vcatchpi.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\winlogonpc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\winsystem.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\WINWGPX.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\vbsys2.dll (Trojan.Clicker) -> Quarantined and deleted successfully.
                                -1
                                1. Contributeur sécurité
                                  1) Vas dans le répertoire d'installation d'Hijackthis.

                                  C:\Program Files\Trend Micro\HijackThis\

                                  Renomme Hijackthis.exe en monHJK.exe ( click droit --> renommer )
                                  Double clique après sur cet executable et choisis l'option Do a system scan and save a logfile.
                                  Tu postes alors le rapport Hijackthis.

                                  2) Télécharge navilog d'il mafioso.
                                  http://il.mafioso.pagesperso-orange.fr/Navifix/Navilog1.exe
                                  Tu l’installes.
                                  Double-clique sur le raccourci qui a été crée sur le bureau.
                                  Choisis l'option 1.

                                  Une fois l’analyse terminée, un rapport va s’ouvrir dans le bloc-notes.
                                  Tu copies et colles le texte de ce rapport dans ton prochain message.

                                  A+
                                  -1
                                  1. Contributeur sécurité
                                    As-tu encore des problèmes avec ton PC ?

                                    Une dernière vérification :

                                    Tu vas sur le site de Kaspersky:
                                    https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

                                    Clique sur Demarrer Online-scanner ( en bas de page à droite ) pour commencer l'analyse.
                                    Il te sera demandé d'installer un logiciel de Kaspersky, accepte.

                                    A la fin de cette analyse, clique sur enregistrer le rapport.
                                    Poste le contenu de ce rapport dans ton prochain message.

                                    A+
                                    -1
                                    1. Je n'ai plus la croix dans la barre de tâches mais j'ai toujours le "delself" qui traîne sur le bureau.

                                      Petit soucis avec Kaspersky :
                                      "Échec du chargement du contrôle ActiveX Kaspersky On-line Scanner!

                                      Vous devez jouir des privilèges d'administrateur sur ce poste ;
                                      en outre, il faut configurer le niveau de sécurité IE sur Moyen."

                                      Que dois-je faire ?
                                      -1
                                      1. Contributeur sécurité
                                        Tu feras un scan plus tard.
                                        Il faut déjà qu'on supprime ce virus delself.

                                        Télécharges Random's System Information Tool (RSIT) de random/random et enregistre le sur ton Bureau.
                                        http://images.malwareremoval.com/random/RSIT.exe

                                        Déconnecte toi et fermes toutes tes applications en cours.

                                        Double-clique sur " RSIT.exe " pour le lancer .
                                        dans la fenêtre qui va s’ouvrir choisis 3 months pour l'option "List files/folders created ..." ,
                                        cliques ensuite sur " Continue " pour lancer l'analyse ...

                                        Si la dernière version de HijackThis n'est pas trouvée sur ton PC, RSIT la téléchargera et te demandera d'accepter la licence.

                                        Attends jusqu’à la fin de l’analyse.
                                        deux rapports vont être generés.

                                        Poste le contenu de " log.txt ", ainsi que de " info.txt " ( dans la barre des tâches), pour analyse et attends la suite ...

                                        Si tu ne les trouves pas,les rapports sont sauvegardés dans le dossier C:\rsit.

                                        A+
                                        -1
                                        1. Et l'info :

                                          info.txt logfile of random's system information tool 1.04 2008-10-12 14:22:08

                                          ======Uninstall list======

                                          -->"C:\Program Files\Fichiers communs\aolshare\Coach\AolCInUn.exe" -lang="fr-fr"
                                          -->agrsmdel
                                          -->C:\PROGRA~1\FICHIE~1\AOL\ACS\AcsUninstall.exe /c
                                          -->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{09B44E78-A988-4BC0-962F-63ECD3333708} /l1036
                                          -->C:\Progra~1\Necmfk\remmfutl.exe /del
                                          -->C:\Program Files\Fichiers communs\AOL\Screensaver\uninst_ygpss.exe
                                          -->C:\Program Files\Fichiers communs\aolshare\Aolunins_fr.exe
                                          -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                                          -->C:\Program Files\Learn2.com\StRunner\stuninst.exe
                                          -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
                                          -->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
                                          -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
                                          -->C:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
                                          -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
                                          -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
                                          -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
                                          -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
                                          -->C:\WINDOWS\UNRecode.exe /UNINSTALL
                                          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
                                          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.EXE" -uninstall
                                          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\SETUP.EXE" -uninstall
                                          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\SETUP.EXE"
                                          -->rundll32 C:\WINDOWS\System32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
                                          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                                          µTorrent 1.6.1 (Build 490)-->C:\Program Files\µtorrent 1.6.1 buid 490\µtorrent\Uninstal.exe
                                          Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
                                          Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
                                          Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
                                          Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
                                          Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
                                          Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
                                          Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
                                          Adobe Color Common Settings-->C:\Program Files\Fichiers communs\Adobe\Installers\6c8e2cb4fd241c55406016127a6ab2e\Setup.exe
                                          Adobe Color Common Settings-->MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}
                                          Adobe Color EU Extra Settings-->MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
                                          Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
                                          Adobe Color NA Recommended Settings-->MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
                                          Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
                                          Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
                                          Adobe ExtendScript Toolkit 2-->C:\Program Files\Fichiers communs\Adobe\Installers\3e054d2218e7aa282c2369d939e58ff\Setup.exe
                                          Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}
                                          Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
                                          Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                                          Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
                                          Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
                                          Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
                                          Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
                                          Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\719d6f144d0c086a0dfa7ff76bb9ac1\Setup.exe
                                          Adobe Photoshop CS3-->MsiExec.exe /I{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}
                                          Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002}
                                          Adobe Setup-->MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}
                                          Adobe Setup-->MsiExec.exe /I{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}
                                          Adobe Setup-->MsiExec.exe /I{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}
                                          Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~2\Install.log
                                          Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
                                          Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
                                          Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
                                          Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
                                          Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
                                          Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
                                          Alice Auto-diagnostic-->C:\Program Files\TechCity Solutions\AliceSAV\uninstall.exe
                                          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                                          Assistant Publication de sites Web Microsoft 1.53-->RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wpie3x86.inf,WebPostUninstall
                                          Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
                                          AVG Free 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
                                          AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
                                          CDex extraction audio-->"C:\Program Files\CDex_150\uninstall.exe"
                                          Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                                          Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                                          COSMOSWorks 2006 sp0-->MsiExec.exe /I{30371D3F-86DC-41BC-8950-3E7BB5D66B89}
                                          DesignPro SE-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{105E1A5B-A749-4825-A8A1-AFD16615DC6C}
                                          DivXG400-->"C:\WINDOWS\IPUI_DivXG400.exe" /U /D
                                          DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
                                          DWGeditor-->MsiExec.exe /X{AC7190A0-EEA1-423C-A531-FCEB4E0EBBB1}
                                          eDrawings 2006-->MsiExec.exe /I{8C47092F-B249-43CB-A780-40274329043D}
                                          eMule-->"C:\Program Files\eMule\Uninstall.exe"
                                          GdiplusUpgrade-->MsiExec.exe /I{5421155F-B033-49DB-9B33-8F80F233D4D5}
                                          Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
                                          HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                                          Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                                          HP Image Zone 3.5-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
                                          HP PSC & OfficeJet 3.5-->"C:\Program Files\HP\Digital Imaging\{0FABD3D7-3036-4e78-B29D-58957ADB0A12}\setup\hpzscr01.exe" -datfile hposcr03.dat
                                          HP Software Update-->MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
                                          Kit de Connexion Alice ADSL-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3A0221AD-D30B-4320-8F9B-1D0F0E6C6843}\setup.exe" -l0x40c ControlPanel
                                          Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                                          Livebox-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC7DDAAE-7F2B-4270-9BFD-5A130B667E9E}\Setup.exe" -l0x40c
                                          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                                          Memories Disc Creator 2.0-->MsiExec.exe /X{2E132061-C78A-48D4-A899-1D13B9D189FA}
                                          Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                                          Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                                          Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                                          Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                                          Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                                          Microsoft LifeCam-->MsiExec.exe /X{968D41C3-25BB-4632-A6DF-2E1C8F0143A4}
                                          Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
                                          Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                                          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                                          Microsoft Visual Studio 6.0 Édition Entreprise (Français)-->"C:\Program Files\Microsoft Visual Studio\Common\Setup\1036\Setup.exe"
                                          Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
                                          Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
                                          Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
                                          Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                                          MSDN Library pour Visual Studio 6.0a (Français)-->"C:\Program Files\Microsoft Visual Studio\MSDN98\98VSa\1036\Setup\Setup.exe"
                                          MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                                          MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                                          Navilog1 3.6.6-->"C:\Program Files\Navilog1\unins000.exe"
                                          Nero 7 Premium-->MsiExec.exe /I{4781569D-5404-1F26-4B2B-6DF444441031}
                                          Optio E10 Digital Camera Driver-->C:\PROGRA~1\OPTIOE~1\UNWISE.EXE C:\PROGRA~1\OPTIOE~1\INSTALL.LOG
                                          overland-->MsiExec.exe /I{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}
                                          Packard Bell InfoCentre-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{07A1C2E1-76DD-11D6-9922-009027E9C183}\setup.exe"
                                          PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
                                          PDFCreator-->"C:\Program Files\PDFCreator\unins000.exe"
                                          PDMWorks Clients 2006 sp0-->MsiExec.exe /I{A0E5B0BB-123A-40FC-868C-8C958AC9BDDD}
                                          PL7 Pro V4.3-->C:\WINDOWS\PL7SYS\UNINSTAL\SETUP PL7PRO/PL7 Pro/43/F
                                          QuickTime-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{4E5E22C2-1386-47AE-8EDE-32DDCDCD6653} /l1036
                                          RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                                          Sagem - Utilitaire réseau pour Clé USB Wi-Fi 802.11g-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0E691604-B328-4B4A-8F17-C9D6395075C5}\Setup.exe" -l0x40c
                                          SAGEM Wi-Fi 11g USB adapter-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB2D74EA-777C-4C58-AE8A-AAF15BB3B9E0}\Setup.exe" -l0x40c
                                          SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
                                          SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
                                          Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
                                          SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
                                          SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
                                          Samsung PC Studio 3 USB Driver Installer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -l0x40c -removeonly
                                          Samsung PC Studio 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x40c -removeonly
                                          Sentinel System Driver-->C:\WINDOWS\SYSTEM32\RNBOSENT\SETUPX86.EXE /U /q
                                          SolidWorks 2006 SP0-->MsiExec.exe /I{5CCD87D7-B345-4211-9F2E-021F1B623E02}
                                          Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
                                          Tetris-->"C:\Program Files\Tetris\unins000.exe"
                                          UNITELWAY WDM Driver-->C:\WINDOWS\IsUninst.exe -fC:\XWAYDRV\UNITELWAYW2KDriverUninst.isu
                                          Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
                                          Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
                                          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                                          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                                          Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                                          Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                                          Wonderware InTouch-->MsiExec.exe /I{5D282B1A-42F3-4E4A-9B6F-6C6450E3A839}
                                          XWAY Driver Manager-->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\System32\XWAYMgrUninst.isu
                                          ZoneAlarm-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

                                          ======Security center information======

                                          AV: AVG Anti-Virus Free
                                          FW: ZoneAlarm Firewall (disabled)

                                          ======Environment variables======

                                          "ComSpec"=%SystemRoot%\system32\cmd.exe
                                          "Path"=C:\Program Files\Fichiers communs\ArchestrA\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\PROGRA~1\FICHIE~1\TVNAVI~1;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Samsung\Samsung PC Studio 3\
                                          "windir"=%SystemRoot%
                                          "OS"=Windows_NT
                                          "PROCESSOR_ARCHITECTURE"=x86
                                          "PROCESSOR_LEVEL"=6
                                          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 9 Stepping 5, GenuineIntel
                                          "PROCESSOR_REVISION"=0905
                                          "NUMBER_OF_PROCESSORS"=1
                                          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                                          "TEMP"=%SystemRoot%\TEMP
                                          "TMP"=%SystemRoot%\TEMP
                                          "CLASSPATH"=C:\Program Files\QuickTime\QTSystem\QTJava.zip
                                          "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip
                                          "VERSION"=3.0.5.001
                                          "SESSIONID"=1155771871670htx60608eaa46:10d328b60cb:-8a8
                                          "COLLECTIONID"=COL8143
                                          "ITEMID"=dj-22741-15
                                          "UPDATEDIR"=C:\DOCUME~1\prisci\LOCALS~1\Temp\rad53E74.tmp
                                          "TOOLPATH"=/C:\Program%20Files\HP\HP%20Software%20Update\install.htm
                                          "HMSERVER"=https://wwss1proa.cce.hp.com/wuss/servlet/WUSSServlet
                                          "SWUTVER"=1.0.22.20030804
                                          "OSVER"=winXPH
                                          "LANG"=1036
                                          "TIMEOUT"=0
                                          "FP_NO_HOST_CHECK"=NO
                                          "tvdumpflags"=8

                                          -----------------EOF-----------------
                                          -1
                                          • 1
                                          • 2