Votre question

Rootkit

Tags :
  • Rootkit
  • Sécurité
Dernière réponse : dans Sécurité et virus
22 Février 2009 18:30:02

bonjour,
mon ordi est infecté par un rootkit et je n'arrive pas à m'en débarassé. j'ai eset comme anti virus et j'ai essayé ad aware,sophos ainsi que avg anti rootkit, rien n'y fait .Puis je suivre les différentes procédures postées sur le forum ?
merci

Autres pages sur : rootkit

a b 8 Sécurité
22 Février 2009 20:40:38

Bonjour,

Pourquoi penser à un rootkit ?
23 Février 2009 06:29:50

Angeldark a dit :
Bonjour,

Pourquoi penser à un rootkit ?

bonjour,
parce que c'est ce qui est marqué dans la zone quarantaine d'eset et j'ai essayé de le supprimer mais il revient toujours.
voilà ce qui est écrit dans eset Win32/Rootkit.Podnuha.NBPtrojan.
Donc j'en ai conclu que c'était un rootkit. voilà.
merci de ta réponse
Contenus similaires
a b 8 Sécurité
23 Février 2009 13:29:38

Il reste en quarantaine ou pas ? Tu as l'emplacement ?

Télécharge Random's System Information Tool (RSIT) (de random/random) et sauvegarde-le sur le Bureau.

  • Double-clique sur RSIT.exe afin de lancer RSIT.
  • Clique Continue  à l'écran Disclaimer.
  • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
  • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt  (qui sera affiché)
    ainsi que de info.txt  (qui sera réduit dans la Barre des Tâches)
  • NB : Les rapports sont sauvegardés dans le dossier C:\rsit  
  • Veille bien à me poster l'intégralité des rapports, vérifie qu'ils soient complets une fois que tu les as postés.

    &

    Télécharge Rooter.exe (d’ Eric 71) sur ton Bureau.

  • Double-clique dessus, une fenêtre va s'ouvrir, il te faudra patienter.
  • Poste le rapport qui s'ouvre.

    Note : Il se trouve ici : %SystemDrive%\Rooter.txt (%SystemDrive% étant la partition où est installée Windows; C:\ en général)
    24 Février 2009 06:42:15

    bonjour,
    quand je le supprime de la quarantaine, il disparaît pour réapparaitre je joins les 2 rapports :

    log;text:
    immLogfile of random's system information tool 1.05 (written by random/random)
    Run by Compaq_Propriétaire at 2009-02-24 06:32:40
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 15 GB (10%) free of 148 GB
    Total RAM: 1023 MB (48% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 06:32:55, on 24/02/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\brsvc01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
    C:\Program Files\ESET\ESET Smart Security\ekrn.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\IoctlSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\ESET\ESET Smart Security\egui.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Windows Live Toolbar\msn_sl.exe
    C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\V5Q1GA4A\RSIT[1].exe
    C:\Program Files\trend micro\Compaq_Propriétaire.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    R3 - URLSearchHook: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    F2 - REG:system.ini: Shell=
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    O2 - BHO: (no name) - {7BD4A40D-8DFC-4F9F-B288-011490D5FCD1} - C:\WINDOWS\system32\BrWebIn.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: mysidesearch search enhancer - {880F9C04-CB4A-9117-18A0-5C899363CB13} - C:\WINDOWS\system32\rkcrwjakfzrhtml.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: snappyads - {f18970dd-8f96-7e99-c7c1-56a16232a2c3} - (no file)
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
    O3 - Toolbar: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [System] explorer.exe
    O4 - HKCU\..\Run: [oeyek] "c:\documents and settings\compaq_propriétaire\local settings\application data\oeyek.exe" oeyek
    O4 - HKCU\..\Run: [nodenable] C:\Program Files\eset\nodenable.exe
    O4 - HKCU\..\RunServices: [System] explorer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
    O4 - Global Startup: Contrôleur d’état.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?d32c1a7c185643c7bce11ae098e15e13
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d32c1a7c185643c7bce11ae098e15e13
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
    O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld...
    O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.fr/Genoogle/Components/ActiveX/Se...
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0....
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
    O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
    O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SsBeSvc.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe

    --
    End of file - 13458 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]
    PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-02-20 1882136]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7BD4A40D-8DFC-4F9F-B288-011490D5FCD1}]
    C:\WINDOWS\system32\BrWebIn.dll [2002-10-31 96256]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{880F9C04-CB4A-9117-18A0-5C899363CB13}]
    mysidesearch search enhancer - C:\WINDOWS\system32\rkcrwjakfzrhtml.dll [2009-02-20 611328]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-09-16 737776]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
    Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f18970dd-8f96-7e99-c7c1-56a16232a2c3}]
    snappyads

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2007-10-01 2436160]
    {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - GamesBar - C:\Program Files\GamesBar\oberontb.dll [2007-06-19 380928]
    {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-02-20 1882136]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2004-07-01 4112384]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-11-04 413696]
    "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]
    "AppleSyncNotifier"=C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-02-06 177472]
    "LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2004-10-08 221184]
    "LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2005-01-18 458752]
    "LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2005-01-18 217088]
    "NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2008-05-28 570664]
    "egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-10-24 1451264]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe [2008-01-22 152872]
    "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-10-07 68856]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
    "Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [2008-07-10 397312]
    "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-08-08 490952]
    "LDM"=C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe [2008-12-21 20480]
    "LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe [2005-01-18 196608]
    "System"=C:\WINDOWS\explorer.exe [2008-04-14 1037824]
    "oeyek"=c:\documents and settings\compaq_propriétaire\local settings\application data\oeyek.exe oeyek []
    "nodenable"=C:\Program Files\eset\nodenable.exe [2008-09-22 326829]

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    Contrôleur d’état.lnk - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

    C:\Documents and Settings\Compaq_Propriétaire\Menu Démarrer\Programmes\Démarrage
    OpenOffice.org 2.2.lnk - C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
    C:\WINDOWS\system32\igfxsrvc.dll [2004-08-03 344064]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=FF000000
    "NoDriveAutoRun"=4294967295
    "ForceClassicControlPanel"=1

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL France"
    "C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\GHIJ8HMN\installer-38284-845-Open-Office-complet-en-francais-French[1].exe"="C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\GHIJ8HMN\installer-38284-845-Open-Office-complet-en-francais-French[1].exe:*:Enabled:installer-38284-845-Open-Office-complet-en-francais-French[1]"
    "C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
    "C:\Program Files\Zapu\Zapu\wDivi.exe"="C:\Program Files\Zapu\Zapu\wDivi.exe:*:D isabled:Zapu Control"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe"="C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home"
    "C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe"="C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.0"
    "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
    "C:\Program Files\HomePlayer\HomePlayer.exe"="C:\Program Files\HomePlayer\HomePlayer.exe:*:Enabled:HomePlayer"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\Program Files\River Past\Audio Converter Pro\AudioConverter.exe"="C:\Program Files\River Past\Audio Converter Pro\AudioConverter.exe:*:Enabled:River Past Audio Converter Pro"
    "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
    "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
    "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

    ======List of files/folders created in the last 1 months======

    2009-02-24 06:32:40 ----D---- C:\rsit
    2009-02-24 06:32:40 ----D---- C:\Program Files\trend micro
    2009-02-22 15:27:59 ----D---- C:\Program Files\Lavasoft
    2009-02-22 15:27:58 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2009-02-22 15:27:20 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
    2009-02-22 11:42:14 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\ImgBurn
    2009-02-22 11:41:42 ----D---- C:\Program Files\ImgBurn
    2009-02-22 11:03:53 ----D---- C:\Program Files\GRISOFT
    2009-02-20 19:04:30 ----A---- C:\WINDOWS\system32\rkcrwjakfzrhtml.dll
    2009-02-19 17:07:08 ----D---- C:\Program Files\Sophos
    2009-02-17 20:33:28 ----D---- C:\UT2004Demo
    2009-02-12 09:27:33 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
    2009-02-12 03:51:07 ----A---- C:\WINDOWS\system32\SETC83.tmp
    2009-02-12 03:51:06 ----A---- C:\WINDOWS\system32\SETC7F.tmp
    2009-02-12 03:51:06 ----A---- C:\WINDOWS\system32\SETC7E.tmp
    2009-02-12 03:51:05 ----A---- C:\WINDOWS\system32\SETC74.tmp
    2009-02-12 03:51:03 ----A---- C:\WINDOWS\system32\SETC8F.tmp
    2009-02-12 03:51:03 ----A---- C:\WINDOWS\system32\SETC77.tmp
    2009-02-12 03:51:02 ----A---- C:\WINDOWS\system32\SETC76.tmp
    2009-02-12 03:51:01 ----A---- C:\WINDOWS\system32\SETC87.tmp
    2009-02-12 03:51:00 ----A---- C:\WINDOWS\system32\SETC8C.tmp
    2009-02-12 03:50:57 ----A---- C:\WINDOWS\system32\SETC85.tmp
    2009-02-11 21:46:57 ----HD---- C:\LG3G
    2009-02-11 21:46:48 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\LG Electronics
    2009-02-11 21:44:53 ----D---- C:\Program Files\LG Electronics
    2009-02-11 21:43:32 ----D---- C:\Program Files\LG PC Suite 2
    2009-02-08 11:30:01 ----A---- C:\WINDOWS\system32\BrWebIn.dll
    2009-02-08 11:29:55 ----A---- C:\WINDOWS\system32\rkcrwjakfzrhtml.dll-uninst.exe
    2009-02-08 11:29:28 ----A---- C:\WINDOWS\system32\4570a8a5-6b89-18d4-e741-858565033b7d.exe
    2009-02-06 23:24:28 ----A---- C:\WINDOWS\system32\_rkcrwjakfzrhtml.dll
    2009-01-29 19:18:50 ----D---- C:\Program Files\PHPNukeFR
    2009-01-29 19:18:50 ----D---- C:\Program Files\Conduit

    ======List of files/folders modified in the last 1 months======

    2009-02-24 06:32:41 ----D---- C:\WINDOWS\Temp
    2009-02-24 06:32:40 ----RD---- C:\Program Files
    2009-02-24 06:32:38 ----D---- C:\WINDOWS\Prefetch
    2009-02-23 17:20:20 ----AD---- C:\WINDOWS
    2009-02-22 18:36:48 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\OpenOffice.org2
    2009-02-22 18:33:57 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-02-22 17:42:27 ----AD---- C:\WINDOWS\system32
    2009-02-22 15:30:10 ----SHD---- C:\WINDOWS\Installer
    2009-02-22 15:30:04 ----D---- C:\Config.Msi
    2009-02-22 15:27:59 ----D---- C:\WINDOWS\system32\drivers
    2009-02-22 15:27:20 ----D---- C:\Program Files\Fichiers communs
    2009-02-22 14:48:50 ----A---- C:\WINDOWS\Ulead32.ini
    2009-02-22 10:53:21 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-02-20 13:03:28 ----D---- C:\Temp
    2009-02-19 20:54:15 ----A---- C:\WINDOWS\NeroDigital.ini
    2009-02-19 15:58:00 ----D---- C:\WINDOWS\Debug
    2009-02-19 12:40:48 ----A---- C:\WINDOWS\win.ini
    2009-02-18 15:19:02 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\LimeWire
    2009-02-18 12:47:53 ----SD---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Microsoft
    2009-02-18 10:05:59 ----D---- C:\Program Files\MSECache
    2009-02-16 21:33:37 ----D---- C:\Program Files\eMule
    2009-02-16 19:02:37 ----D---- C:\Program Files\MessengerSkinner
    2009-02-16 19:01:31 ----D---- C:\Program Files\Jewel Quest
    2009-02-16 18:12:31 ----D---- C:\Program Files\ESET
    2009-02-16 18:08:47 ----HD---- C:\WINDOWS\inf
    2009-02-14 17:03:56 ----D---- C:\Documents and Settings\All Users\Application Data\Bluetooth
    2009-02-13 03:01:25 ----D---- C:\WINDOWS\system32\CatRoot
    2009-02-12 09:27:32 ----HD---- C:\WINDOWS\$hf_mig$
    2009-02-12 09:27:20 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2009-02-12 09:27:15 ----D---- C:\Program Files\Internet Explorer
    2009-02-11 21:46:42 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-02-11 21:44:53 ----HD---- C:\Program Files\InstallShield Installation Information
    2009-02-11 11:05:48 ----D---- C:\Program Files\World of Warcraft
    2009-02-11 09:52:43 ----D---- C:\Program Files\Avanquest update
    2009-02-11 09:03:08 ----SHD---- C:\System Volume Information
    2009-02-11 09:03:08 ----D---- C:\WINDOWS\system32\Restore
    2009-02-10 19:28:16 ----A---- C:\WINDOWS\pex.INI
    2009-02-09 17:17:54 ----A---- C:\AILog.txt
    2009-02-04 00:21:12 ----A---- C:\WINDOWS\system32\MRT.exe
    2009-02-01 11:32:21 ----D---- C:\Nostale(FR)
    2009-01-31 13:21:29 ----D---- C:\WINDOWS\Minidump
    2009-01-29 19:25:52 ----D---- C:\Program Files\Microsoft Games
    2009-01-27 08:01:34 ----A---- C:\WINDOWS\DUMP57b5.tmp
    2009-01-27 05:41:04 ----A---- C:\WINDOWS\DUMP5544.tmp
    2009-01-27 03:20:35 ----A---- C:\WINDOWS\DUMP54b7.tmp
    2009-01-27 02:36:00 ----A---- C:\WINDOWS\DUMP52d3.tmp
    2009-01-27 02:34:22 ----A---- C:\WINDOWS\DUMP5217.tmp
    2009-01-27 02:33:01 ----A---- C:\WINDOWS\DUMP5350.tmp
    2009-01-27 02:31:41 ----A---- C:\WINDOWS\DUMP5330.tmp
    2009-01-27 02:30:25 ----A---- C:\WINDOWS\DUMP52e2.tmp
    2009-01-27 02:29:08 ----A---- C:\WINDOWS\DUMP5296.tmp
    2009-01-27 02:27:44 ----A---- C:\WINDOWS\DUMP53ec.tmp
    2009-01-27 02:26:29 ----A---- C:\WINDOWS\DUMP5229.tmp
    2009-01-27 02:24:34 ----A---- C:\WINDOWS\DUMP5257.tmp
    2009-01-27 02:23:16 ----A---- C:\WINDOWS\DUMP52b4.tmp
    2009-01-27 02:21:53 ----A---- C:\WINDOWS\DUMP5340.tmp
    2009-01-27 02:20:36 ----A---- C:\WINDOWS\DUMP5295.tmp
    2009-01-27 02:19:20 ----A---- C:\WINDOWS\DUMP5294.tmp
    2009-01-27 02:18:02 ----A---- C:\WINDOWS\DUMP5321.tmp
    2009-01-27 02:16:24 ----A---- C:\WINDOWS\DUMP53dd.tmp
    2009-01-26 23:58:41 ----A---- C:\WINDOWS\DUMP5256.tmp
    2009-01-26 23:57:24 ----A---- C:\WINDOWS\DUMP5248.tmp
    2009-01-26 23:56:07 ----A---- C:\WINDOWS\DUMP53dc.tmp
    2009-01-26 23:54:43 ----A---- C:\WINDOWS\DUMP5287.tmp
    2009-01-26 23:53:27 ----A---- C:\WINDOWS\DUMP52c4.tmp
    2009-01-26 23:52:07 ----A---- C:\WINDOWS\DUMP52b3.tmp
    2009-01-26 23:50:47 ----A---- C:\WINDOWS\DUMP52f2.tmp
    2009-01-26 23:49:26 ----A---- C:\WINDOWS\DUMP5236.tmp
    2009-01-26 23:48:09 ----A---- C:\WINDOWS\DUMP51c9.tmp
    2009-01-26 23:46:54 ----A---- C:\WINDOWS\DUMP52a6.tmp
    2009-01-26 23:45:30 ----A---- C:\WINDOWS\DUMP53cd.tmp
    2009-01-26 23:44:14 ----A---- C:\WINDOWS\DUMP51da.tmp
    2009-01-26 23:42:57 ----A---- C:\WINDOWS\DUMP52a5.tmp
    2009-01-26 23:41:41 ----A---- C:\WINDOWS\DUMP516b.tmp
    2009-01-26 23:40:24 ----A---- C:\WINDOWS\DUMP5247.tmp
    2009-01-26 23:39:04 ----A---- C:\WINDOWS\DUMP5277.tmp
    2009-01-26 23:37:45 ----A---- C:\WINDOWS\DUMP5246.tmp
    2009-01-26 23:36:26 ----A---- C:\WINDOWS\DUMP5276.tmp
    2009-01-26 23:34:48 ----A---- C:\WINDOWS\DUMP5275.tmp
    2009-01-26 23:33:32 ----A---- C:\WINDOWS\DUMP51d9.tmp
    2009-01-26 23:32:16 ----A---- C:\WINDOWS\DUMP5228.tmp
    2009-01-26 23:30:59 ----A---- C:\WINDOWS\DUMP51b9.tmp
    2009-01-26 23:29:43 ----A---- C:\WINDOWS\DUMP53ad.tmp
    2009-01-26 23:28:05 ----A---- C:\WINDOWS\DUMP52a4.tmp
    2009-01-26 23:26:45 ----A---- C:\WINDOWS\DUMP51e8.tmp
    2009-01-26 23:25:21 ----A---- C:\WINDOWS\DUMP5265.tmp
    2009-01-26 23:24:06 ----A---- C:\WINDOWS\DUMP5303.tmp
    2009-01-26 23:22:29 ----A---- C:\WINDOWS\DUMP5286.tmp
    2009-01-26 23:20:53 ----A---- C:\WINDOWS\DUMP5208.tmp
    2009-01-26 23:19:19 ----A---- C:\WINDOWS\DUMP5227.tmp
    2009-01-26 23:17:42 ----A---- C:\WINDOWS\DUMP5302.tmp
    2009-01-26 23:16:20 ----A---- C:\WINDOWS\DUMP52c3.tmp
    2009-01-26 23:14:57 ----A---- C:\WINDOWS\DUMP5285.tmp
    2009-01-26 20:48:38 ----D---- C:\Program Files\KeyChain Photo Manager
    2009-01-25 13:32:44 ----D---- C:\WINDOWS\network diagnostic

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AmdK7;Pilote de processeur AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41856]
    R1 AvgArCln;Avg Anti-Rootkit Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgArCln.sys [2007-01-18 3968]
    R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-10-24 53256]
    R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-10-24 54280]
    R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys []
    R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
    R1 SiSkp;SiSkp; C:\WINDOWS\system32\DRIVERS\srvkp.sys [2004-07-17 12160]
    R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2008-09-12 5632]
    R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-09-06 20747]
    R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-10-24 39944]
    R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-10-24 73224]
    R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-12-12 391424]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-06-15 626220]
    R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
    R3 BrScnUsb;Brother USB Still Image driver; C:\WINDOWS\System32\Drivers\BrScnUsb.sys [2004-10-15 15295]
    R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-10-24 31240]
    R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2003-11-12 41984]
    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
    R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    R3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2003-09-10 21060]
    R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2005-01-31 22016]
    R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
    R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-07-01 2459840]
    R3 Pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 10368]
    R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
    R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S3 a1u3mhpe;a1u3mhpe; C:\WINDOWS\system32\drivers\a1u3mhpe.sys []
    S3 ASPI;Advanced SCSI Programming Interface Driver; \??\C:\WINDOWS\System32\DRIVERS\ASPI32.sys []
    S3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys []
    S3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys []
    S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys []
    S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys []
    S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
    S3 C-Dilla;C-Dilla; \??\C:\WINDOWS\system32\drivers\CDANT.SYS []
    S3 EL90XBC;Pilote de la carte EtherLink XL 90XB/C 3Com; C:\WINDOWS\system32\DRIVERS\el90xbc5.sys [2001-08-18 66591]
    S3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-08-03 730653]
    S3 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
    S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\4DA0.tmp []
    S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
    S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
    S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
    S3 nocashio;nocashio; C:\WINDOWS\system32\drivers\nocashio.sys [2007-12-28 4096]
    S3 PID_0928;Logitech QuickCam Express(PID_0928); C:\WINDOWS\system32\DRIVERS\LV561AV.SYS [2005-01-31 211712]
    S3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2002-07-29 23808]
    S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
    S3 RT73;Belkin USB Network Adapter; C:\WINDOWS\system32\DRIVERS\rt73.sys [2005-08-02 232192]
    S3 s616bus;Sony Ericsson Device 616 driver (WDM); C:\WINDOWS\system32\DRIVERS\s616bus.sys [2007-04-03 83208]
    S3 s616mdfl;Sony Ericsson Device 616 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s616mdfl.sys [2007-04-03 15112]
    S3 s616mdm;Sony Ericsson Device 616 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s616mdm.sys [2007-04-03 108680]
    S3 s616mgmt;Sony Ericsson Device 616 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s616mgmt.sys [2007-04-03 100360]
    S3 s616nd5;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (NDIS); C:\WINDOWS\system32\DRIVERS\s616nd5.sys [2007-04-03 23176]
    S3 s616obex;Sony Ericsson Device 616 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s616obex.sys [2007-04-03 98568]
    S3 s616unic;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (WDM); C:\WINDOWS\system32\DRIVERS\s616unic.sys [2007-04-03 99080]
    S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\WINDOWS\system32\DRIVERS\s916bus.sys [2007-11-02 83496]
    S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s916mdfl.sys [2007-11-02 15016]
    S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s916mdm.sys [2007-11-02 109992]
    S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s916mgmt.sys [2007-11-02 103976]
    S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s916obex.sys [2007-11-02 100008]
    S3 SiS315;SiS315; C:\WINDOWS\system32\DRIVERS\sisgrp.sys [2004-07-19 218112]
    S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
    S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2005-12-22 80272]
    S3 sscdmdfl;SAMSUNG CDMA Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2005-12-22 10864]
    S3 sscdmdm;SAMSUNG CDMA Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2005-12-22 137884]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
    S3 USB_RNDIS;Thomson ST Remote NDIS Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
    S3 usbbus;LGE Mobile Composite USB Device; C:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2007-07-11 12416]
    S3 UsbDiag;LGE Mobile USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys [2007-07-11 19840]
    S3 USBIO;USBIO Driver (usbio.sys); C:\WINDOWS\System32\Drivers\usbio.sys [2001-05-07 19805]
    S3 USBModem;LGE Mobile USB Modem; C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2007-07-11 21632]
    S3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
    S3 UsbSagCom;Mobile Device Full USB Driver; C:\WINDOWS\system32\DRIVERS\UsbSagCom.sys [2007-06-29 51712]
    S3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys []
    S3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys []
    S3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2004-05-05 142976]
    S3 w200bus;Sony Ericsson W200 driver (WDM); C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 61504]
    S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 9328]
    S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 97056]
    S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 88560]
    S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 86368]
    S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
    S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
    S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-14 5504]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2009-02-22 611664]
    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
    R2 Belkin Wireless USB Network Adapter Service;Belkin Wireless USB Network Adapter; C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe [2004-03-29 49152]
    R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
    R2 Brother XP spl Service;BrSplService; C:\WINDOWS\system32\brsvc01a.exe [2002-04-11 57344]
    R2 C-DillaSrv;C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2001-09-10 32256]
    R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2004-07-01 114755]
    R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
    R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
    R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
    R3 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe [2008-01-22 275752]
    R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
    S2 .EsetTrialReset;Eset Trial Reset; C:\WINDOWS\system32\regedt32.exe [2004-08-04 3584]
    S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
    S3 Boonty Games;Boonty Games; C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2008-08-19 69120]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
    S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-10-24 19200]
    S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268800]
    S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-10-01 138168]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
    S3 MSCSPTISRV;MSCSPTISRV; C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe [2006-12-14 45056]
    S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2008-04-08 800040]
    S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe [2006-12-14 57344]
    S3 SonicStage Back-End Service;SonicStage Back-End Service; C:\Program Files\Fichiers communs\Sony Shared\AVLib\SsBeSvc.exe [2007-02-05 112184]
    S3 SPTISRV;Sony SPTI Service; C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe [2006-12-14 69632]
    S3 SSScsiSV;SonicStage SCSI Service; C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe [2007-02-05 75320]
    S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
    S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
    S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]

    -----------------EOF-----------------
    édiatémént.
    et info.text
    info.txt logfile of random's system information tool 1.05 2009-02-24 06:33:00

    ======Uninstall list======

    -->C:\Program Files\InstallShield Installation Information\{B36361DC-FB9B-4AD0-B868-56164C37D5BB}\setup.exe -runfromtemp -l0x040c/UNINSTALL -removeonly
    -->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
    -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
    -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
    -->C:\WINDOWS\UNRecode.exe /UNINSTALL
    -->Dummy
    -->MsiExec.exe /I{8A42F680-2DD6-11D4-9A8C-0040F6982C20}
    -->MsiExec.exe /I{A2529672-574A-4A99-86A5-C1770A0E31FE}
    -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\Setup.exe"
    -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\Setup.exe"
    -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\Setup.exe"
    -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E06E4F4E-72D6-4497-BFFD-BCB43077C2F4}\setup.exe" -l0x40c -uninst
    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    6MP DigiCam Owner's Manual-->C:\Program Files\InstallShield Installation Information\{CD4A7627-1EF1-4EBA-BAFF-B69C0C05710E}\setup.exe -u
    Action Replay Code Manager-->"C:\Program Files\Datel\Action Replay Code Manager\unins000.exe"
    Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
    Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Reader 8.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
    Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
    Adobe® Photoshop® Album Edition Découverte 3.2-->MsiExec.exe /I{A654A805-41D9-40C7-AA46-4AF04F044D61}
    Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
    Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
    Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
    Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
    Avanquest update-->C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe -runfromtemp -l0x0009 -removeonly
    AVG Anti-Rootkit Free-->C:\Program Files\GRISOFT\AVG Anti-Rootkit Free\Uninstall.exe
    AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
    Barre d'outils Outlook de Windows Live (Windows Live Toolbar)-->MsiExec.exe /X{6E15BEDF-7EB5-4010-998E-B430DB4EFE45}
    Belkin 54g USB Network Adapter-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Belkin\Belkin Wireless Network Utility\setup.exe" -l0x9
    Big Fish Games Client-->C:\Program Files\bfgclient\Uninstall.exe
    Bloqueur de fenêtres pop-up (Windows Live Toolbar)-->MsiExec.exe /X{A425C250-A0E1-4D78-B1C1-A5CBC7385E7C}
    Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
    Brother MFL-Pro Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BB9AC6BF-71B6-42A4-9689-C17D9F44E79A}\Setup.exe" -l0x40c Brunin03.dllBrunin03.dll
    CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
    CDex extraction audio-->"C:\Program Files\CDex_150\uninstall.exe"
    Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
    Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
    Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
    Connexion Facile à Internet-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{8105684D-8CA6-440D-8F58-7E5FD67A499D} /l1036
    Contextual Tool Snappyads-->C:\WINDOWS\system32\4570a8a5-6b89-18d4-e741-858565033b7d.exe
    Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
    Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
    Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
    dBpoweramp Music Converter-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
    dBpoweramp Windows Media Audio 10 Codec-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.dat
    Démo d'Unreal Tournament 2004-->C:\UT2004Demo\System\Setup.exe uninstall "UT2004-Demo"
    Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{EFFCB0F1-CFEC-48D4-B793-EBFCAE852976}
    Disc2Phone-->MsiExec.exe /I{FFAB5ABB-8AAB-42E2-847F-1743E51E01E9}
    DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
    DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
    DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
    DVDCoach Express 1.0.0-->"C:\Program Files\Kibisoft\DVDCoach Express\unins000.exe"
    EasyCleaner-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F5346614-B7C4-4E94-826A-E2363155233D}\setup.exe" -l0x9 -removeonly
    eMule-->"C:\Program Files\eMule\Uninstall.exe"
    Enjoy 6e-->C:\WINDOWS\Enjoy 6e Uninstaller.exe
    ESET Smart Security-->MsiExec.exe /I{4CEBE5E6-D1FD-4BDF-8C9C-29A9A3CC2B7C}
    Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{0CA6047C-D28B-4295-834A-07C52BA20C2D}
    Fashion Craze-->"C:\Program Files\Gamenext\Fashion Craze\Uninstall.exe" "C:\Program Files\Gamenext\Fashion Craze\install.log"
    Favorit-->"c:\documents and settings\compaq_propriétaire\local settings\application data\oeyek.exe" -uninstall
    Football Generation-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{623446F8-D2D4-4942-9CA2-9D71ED8B24E9}\setup.exe" -l0x40c
    Freeplayer-->C:\Program Files\Freeplayer\Uninstall.exe
    GamesBar 1.1.0.5-->C:\Program Files\GamesBar\uninst.exe
    Gimp pour Windows 2.2.10-->"C:\Program Files\Gimp\uninstall.exe"
    Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
    Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
    Help and Support Additions-->C:\PROGRA~1\HELPAN~1\UNWISE.EXE C:\PROGRA~1\HELPAN~1\INSTALL.LOG
    High Definition Audio Driver Package - KB835221-->C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
    HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
    HomePlayer 1.5.6b-->C:\Program Files\HomePlayer\uninst.exe
    Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
    ImgBurn-->"C:\Program Files\ImgBurn\uninstall.exe"
    InterActual Player-->C:\Program Files\InterActual\InterActual Player\inuninst.exe
    InterVideo WinDVD Creator 2-->"C:\Program Files\InstallShield Installation Information\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}\setup.exe" REMOVEALL
    InterVideo WinDVD Player-->"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
    iriver plus 3 (remove only)-->"C:\Program Files\iriver\iriver plus 3\uninstall.exe"
    iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
    Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
    Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
    Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
    Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
    Jewel Quest Mysteries Curse of the Emerald Tear (supprimer seulement)-->"C:\Program Files\iWin.com Games\Jewel Quest Mysteries Curse of the Emerald Tear\Uninstall.exe"
    KBD-->C:\HP\KBD\KBD.EXE uninstalled
    KeyChain Photo Manager-->MsiExec.exe /I{25CC3073-0F00-46A3-8433-8F437AD90EAF}
    KnC-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{71C554B9-79B7-4B5A-8AF0-C6E5CBE108CC}\setup.exe" -l0x40c -removeonly
    Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
    LG PC Suite-->C:\Program Files\InstallShield Installation Information\{993960EE-CA4D-443F-8F88-E24260DD5FD2}\setup.exe -runfromtemp -l0x040c -removeonly
    LG USB Modem driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C3ABE126-2BB2-4246-BFE1-6797679B3579}\setup.exe" -l0x40c LG -removeonly
    LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
    Logiciel QuickCam de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x40c
    Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x40c UNINSTALL
    Logitech Print Service-->C:\PROGRA~1\Logitech\PRINTS~1\UNWISE.EXE C:\PROGRA~1\Logitech\PRINTS~1\INSTALL.LOG
    Luxor 3 fr-->"C:\Program Files\BoontyGames\Luxor 3\unins000.exe"
    Marsu-Fix-->C:\WINDOWS\Marsu-Fix Uninstaller.exe
    Memory Stick Formatter-->C:\Program Files\InstallShield Installation Information\{27337663-2619-11D4-99DC-0000F49094C7}\setup.exe -runfromtemp -l0x040c/UNINSTALL -removeonly
    Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
    MicroBillard-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\MicroBillard\ST6UNST.LOG"
    Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
    Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
    Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
    Microsoft Age of Empires II-->"C:\Program Files\Microsoft Games\Age of Empires II\UNINSTAL.EXE" /runtemp /uninstall
    Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
    Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
    Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
    Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
    Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
    Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Mise à jour de sécurité pour le Codeur Windows Media (KB954156)-->"C:\WINDOWS\$NtUninstallKB954156_WM9L$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
    MobileMe Control Panel-->MsiExec.exe /I{A14C24F6-615B-415E-84B0-610FDAD19B68}
    Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
    Movie Collection 5.4.9.0-->"C:\Program Files\Movie Collection\unins000.exe"
    Movie Converter (remove only)-->"C:\Program Files\iriver\Movie Converter\uninstall.exe"
    MP3 Player Utilities 3.13-->MsiExec.exe /I{2D5B83B8-98A0-4F9C-AE1D-BED98AE17467}
    MP3 Player Utilities 3.79-->MsiExec.exe /I{7784A172-61F1-445E-8368-601607E0DD22}
    MP3 Player Utilities 4.21-->MsiExec.exe /I{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}
    MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
    MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
    MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
    Navigation par onglets (Windows Live Toolbar)-->MsiExec.exe /X{E916E61F-DE9D-4EAF-91E1-CEB50016326A}
    Nero 7 Ultra Edition-->MsiExec.exe /X{F90D6825-8F1F-4E3A-9E42-A9C8A9DD1036}
    neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
    NewsLeecher v3.8 Final-->"C:\Program Files\NewsLeecher\unins000.exe"
    Nostale Online FR (Remove)-->"C:\Nostale(FR)\unins000.exe"
    NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
    OneCare Advisor (Windows Live Toolbar)-->MsiExec.exe /X{6D7F8D4B-D1A4-402A-973E-31E90940E585}
    OpenMG Limited Patch 4.7-07-14-05-01-->C:\Program Files\Fichiers communs\Sony Shared\OpenMG\HotFixes\HotFix4.7-07-14-05-01\HotFixSetup\setup.exe /u
    OpenMG Secure Module 4.7.00-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1150\INTEL3~1\IDriver.exe /M{CCD663AE-610D-4BDF-AAB0-E914B044527D} UNINSTALL
    OpenOffice.org 2.2-->MsiExec.exe /I{419805D6-75A0-4981-BC8F-9FF97EC6B03A}
    PaperPort-->MsiExec.exe /I{A17EABB6-D0C6-44E5-820C-72DC7F495064}
    PC-Doctor pour Windows-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\Setup.exe"
    PHPNukeFR Toolbar-->C:\PROGRA~1\PHPNUK~1\UNWISE.EXE /U C:\PROGRA~1\PHPNUK~1\INSTALL.LOG
    Play89-->C:\Program Files\Play89\Play89.exe /uninstall
    Pochette Express 2-->C:\Program Files\Pochette Express 2\uninstall.exe
    Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
    PS2-->C:\WINDOWS\system32\ps2.exe uninstall
    PSP Video 9 1.74-->C:\Program Files\pspvideo9\uninst.exe
    Python 2.2 combined Win32 extensions-->C:\Python22\Lib\SITE-P~1\UNWISE~1.EXE C:\Python22\Lib\SITE-P~1\w32inst.log
    Python 2.2.1-->C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
    QuickPar 0.9-->C:\Program Files\QuickPar\uninst.exe
    QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
    RamBoost XP 4.0.6-->"C:\Program Files\RamBoost XP\unins000.exe"
    River Past Audio Converter Pro-->"C:\WINDOWS\Audio Converter Pro Uninstaller.exe"
    Safari-->MsiExec.exe /I{582D2A53-F426-4C5E-A2E6-43C1AB36B907}
    SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
    SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
    Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
    SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
    SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
    Samsung PC Studio 3-->"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -runfromtemp -l0x040c -removeonly
    Satsuki Decoder Pack-->C:\Program Files\Satsuki Decoder Pack\Uninstall.exe
    Search Assistant Mysidesearch-->C:\WINDOWS\system32\rkcrwjakfzrhtml.dll-uninst.exe
    Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    Security Update pour Microsoft .NET Framework 2.0 (KB928365)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
    Setup ANGE DAO FAO-->MsiExec.exe /I{57C4249B-69A3-4814-95BD-9A05100528B5}
    SiS VGA Utilities-->Rundll32 SiSInst.dll,Uninstall VGA,R
    SonicStage 4.3-->RunDll32 C:\PROGRA~1\FICH
    a b 8 Sécurité
    24 Février 2009 21:01:41

    Re,

    Télécharge Navilog (de Il-Mafioso)

  • Enregistre-le sur ton Bureau.
  • Installe-le en double cliquant sur navilog.exe.
  • Une fois l'installation terminée, l'utilitaire s'exécutera automatiquement.
    (Si ce n'est pas le cas, double clique sur le raccourci présent sur le Bureau)
  • Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.
    ! N'utilise pas l'option 2, 3 et 4 sans notre accord !
  • Patiente jusqu'à l'apparition de ce message :
    *** Analyse Termine le ..... ***
  • Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste le rapport ici.
  • Poste le rapport généré.

    Le rapport se trouve ici : C:\fixnavi.txt
    24 Février 2009 22:46:55

    Bonsoir,
    voilà le rapport

    Search Navipromo version 3.7.4 commencé le 24/02/2009 à 22:43:00,31

    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
    !!! Postez ce rapport sur le forum pour le faire analyser !!!
    !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

    Outil exécuté depuis C:\Program Files\navilog1

    Mise à jour le 16.02.2009 à 18h00 par IL-MAFIOSO

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 3000+ )
    BIOS : Rev. 3.11
    USER : Compaq_Propriétaire ( Administrator )
    BOOT : Normal boot

    Antivirus : ESET Smart Security 3.0 3.0 (Activated)
    Firewall : ESET Personal firewall 3.0.684.0 (Activated)

    A:\ (USB)
    C:\ (Local Disk) - NTFS - Total:144 Go (Free:14 Go)
    D:\ (Local Disk) - FAT32 - Total:4 Go (Free:1 Go)
    E:\ (CD or DVD)
    F:\ (CD or DVD)
    G:\ (CD or DVD)
    H:\ (CD or DVD)
    I:\ (USB)


    Recherche executé en mode normal

    *** Recherche Programmes installés ***

    Favorit

    *** Recherche dossiers dans "C:\WINDOWS" ***


    *** Recherche dossiers dans "C:\Program Files" ***

    ...\MessengerSkinner trouvé !

    *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

    ...\MessengerSkinner trouvé !

    *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


    *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***


    *** Recherche dossiers dans "C:\Documents and Settings\Compaq_Propriétaire\applic~1" ***

    ...\MessengerSkinner trouvé !

    *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***


    *** Recherche dossiers dans "C:\DOCUME~1\cindy\applic~1" ***

    ...\MessengerSkinner trouvé !

    *** Recherche dossiers dans "C:\Documents and Settings\Compaq_Propriétaire\locals~1\applic~1" ***


    *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***


    *** Recherche dossiers dans "C:\DOCUME~1\cindy\locals~1\applic~1" ***


    *** Recherche dossiers dans "C:\Documents and Settings\Compaq_Propriétaire\menudm~1\progra~1" ***


    *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***


    *** Recherche dossiers dans "C:\DOCUME~1\cindy\menudm~1\progra~1" ***


    *** Recherche avec GenericNaviSearch ***
    !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
    !!! A vérifier impérativement avant toute suppression manuelle !!!

    * Recherche dans "C:\WINDOWS\system32" *

    * Recherche dans "C:\Documents and Settings\Compaq_Propriétaire\locals~1\applic~1" *

    * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

    * Recherche dans "C:\DOCUME~1\cindy\locals~1\applic~1" *



    *** Recherche fichiers ***



    *** Recherche clés spécifiques dans le Registre ***
    !! Les clés trouvées ne sont pas forcément infectées !!

    HKEY_CURRENT_USER\Software\Lanconfig

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "oeyek"="\"c:\\documents and settings\\compaq_propri‚taire\\local settings\\application data\\oeyek.exe\" oeyek"


    *** Module de Recherche complémentaire ***
    (Recherche fichiers spécifiques)

    1)Recherche nouveaux fichiers Instant Access :


    2)Recherche Heuristique :

    * Dans "C:\WINDOWS\system32" :


    * Dans "C:\Documents and Settings\Compaq_Propriétaire\locals~1\applic~1" :

    oeyek.dat trouvé !
    oeyek_nav.dat trouvé !
    oeyek_navps.dat trouvé !

    * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :


    * Dans "C:\DOCUME~1\cindy\locals~1\applic~1" :

    okyqo.dat trouvé !
    okyqo_nav.dat trouvé !
    okyqo_navps.dat trouvé !

    3)Recherche Certificats :

    Certificat Egroup trouvé !
    Certificat Electronic-Group trouvé !
    Certificat Montorgueil absent !
    Certificat OOO-Favorit trouvé !
    Certificat Sunny-Day-Design-Ltd absent !

    4)Recherche autres dossiers et fichiers connus :



    *** Analyse terminée le 24/02/2009 à 22:43:54,07 ***
    merci
    a b 8 Sécurité
    25 Février 2009 13:19:30

    Re,

  • Double clique sur le raccourci de Navilog.
  • Choisis l'option 2 puis valide. (Entrée)
  • Laisse toi guider.
  • Ton ordinateur va redémarrer, sinon fais le manuellement.
  • Ton bureau va disparaître.
  • Après un certain temps, le Bloc-notes va s'ouvrir.
  • Sauvegarde le rapport.
  • Referme le Bloc-notes. Ton bureau va maintenant réapparaître.

    Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
    Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "Nouvelle tâche (exécuter)"
    Tapes explorer et valide. Cela te fera apparaitre ton bureau


    Démarrer -> panneau de configuration -> options internet
    Clique sur l'onglet "Contenu" puis onglet "Certificats" et si tu trouves ceci, en particulier dans "éditeurs approuvés" :

    VIP

    Si tu les trouves, fais ceci :
    * Sélectionne chacun de ces certificats et clique sur exporter. Enregistre le/les sur ton bureau.
    * Supprime ensuite ceux présents dans l'onglet "certificats" des options de ton naviguateur.

    Ensuite pour chacun des certificats présents sur ton bureau :
    * Va sur le site Web :
    http://www.bleepingcomputer.com/submit-malware.php?chan...
    * Copie/colle ceci dans la case 'Link to Topic' :
    le nom du certificat (Montorgueil ,......)
    * Copie/colle ceci dans la case 'Browse to the File' :
    Le certificat correspondant que tu avais exportés vers ton bureau

    Si c'est fait, supprime enfin le certificat présent sur ton bureau.

    Les programmes suivants installent cette infection :

    * Go-astro
    * GoRecord
    * HotTVPlayer
    * Live Player
    * MailSkinner
    * Messenger Skinner
    * Instant Access
    * InternetGameBox
    * sudoplanet
    * Webmediaplayer : sauf celui provenant du site suivant > http://www.azertysite.new.fr/
    * Sur le site www.games-desktop.com (Ne pas aller dessus!)

  • Poste le rapport sauvegardé auparavant (C:\cleannavi.txt) ainsi qu'un nouveau rapport Hijackthis.
    25 Février 2009 15:49:02

    merci pour tes réponses, je le fais tout de suite, par contre, je ne trouve pas le rapport C:\cleannavi.txt
    à +
    25 Février 2009 16:03:31

    c'est normal que je ne le trouvait pas puisqu'il n'y était pas encore.je n'ai pas trouvé les certificats.je joins les 2 rapports

    Logfile of random's system information tool 1.05 (written by random/random)
    Run by Compaq_Propriétaire at 2009-02-25 15:59:56
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 19 GB (13%) free of 148 GB
    Total RAM: 1023 MB (51% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:00:04, on 25/02/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\brsvc01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
    C:\Program Files\ESET\ESET Smart Security\ekrn.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\IoctlSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\ESET\ESET Smart Security\egui.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Windows Live Toolbar\msn_sl.exe
    C:\Documents and Settings\Compaq_Propriétaire\Bureau\RSIT.exe
    C:\Program Files\trend micro\Compaq_Propriétaire.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    R3 - URLSearchHook: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    F2 - REG:system.ini: Shell=
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    O2 - BHO: (no name) - {7BD4A40D-8DFC-4F9F-B288-011490D5FCD1} - C:\WINDOWS\system32\BrWebIn.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: mysidesearch search enhancer - {880F9C04-CB4A-9117-18A0-5C899363CB13} - C:\WINDOWS\system32\rkcrwjakfzrhtml.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: snappyads - {f18970dd-8f96-7e99-c7c1-56a16232a2c3} - (no file)
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
    O3 - Toolbar: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [System] explorer.exe
    O4 - HKCU\..\Run: [nodenable] C:\Program Files\eset\nodenable.exe
    O4 - HKCU\..\RunServices: [System] explorer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
    O4 - Global Startup: Contrôleur d’état.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?d32c1a7c185643c7bce11ae098e15e13
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d32c1a7c185643c7bce11ae098e15e13
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
    O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld...
    O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.fr/Genoogle/Components/ActiveX/Se...
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0....
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
    O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
    O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SsBeSvc.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe

    --
    End of file - 13096 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]
    PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-02-20 1882136]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7BD4A40D-8DFC-4F9F-B288-011490D5FCD1}]
    C:\WINDOWS\system32\BrWebIn.dll [2002-10-31 96256]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{880F9C04-CB4A-9117-18A0-5C899363CB13}]
    mysidesearch search enhancer - C:\WINDOWS\system32\rkcrwjakfzrhtml.dll [2009-02-20 611328]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-09-16 737776]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
    Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f18970dd-8f96-7e99-c7c1-56a16232a2c3}]
    snappyads

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2007-10-01 2436160]
    {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - GamesBar - C:\Program Files\GamesBar\oberontb.dll [2007-06-19 380928]
    {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-02-20 1882136]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2004-07-01 4112384]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-11-04 413696]
    "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]
    "AppleSyncNotifier"=C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-02-06 177472]
    "LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2004-10-08 221184]
    "LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2005-01-18 458752]
    "LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2005-01-18 217088]
    "NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2008-05-28 570664]
    "egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-10-24 1451264]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe [2008-01-22 152872]
    "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-10-07 68856]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
    "Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [2008-07-10 397312]
    "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-08-08 490952]
    "LDM"=C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe [2008-12-21 20480]
    "LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe [2005-01-18 196608]
    "System"=C:\WINDOWS\explorer.exe [2008-04-14 1037824]
    "nodenable"=C:\Program Files\eset\nodenable.exe [2008-09-22 326829]

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    Contrôleur d’état.lnk - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

    C:\Documents and Settings\Compaq_Propriétaire\Menu Démarrer\Programmes\Démarrage
    OpenOffice.org 2.2.lnk - C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
    C:\WINDOWS\system32\igfxsrvc.dll [2004-08-03 344064]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=FF000000
    "NoDriveAutoRun"=4294967295
    "ForceClassicControlPanel"=1

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=
    "HonorAutoRunSetting"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL France"
    "C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\GHIJ8HMN\installer-38284-845-Open-Office-complet-en-francais-French[1].exe"="C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\GHIJ8HMN\installer-38284-845-Open-Office-complet-en-francais-French[1].exe:*:Enabled:installer-38284-845-Open-Office-complet-en-francais-French[1]"
    "C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
    "C:\Program Files\Zapu\Zapu\wDivi.exe"="C:\Program Files\Zapu\Zapu\wDivi.exe:*:D isabled:Zapu Control"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe"="C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home"
    "C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe"="C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.0"
    "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
    "C:\Program Files\HomePlayer\HomePlayer.exe"="C:\Program Files\HomePlayer\HomePlayer.exe:*:Enabled:HomePlayer"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\Program Files\River Past\Audio Converter Pro\AudioConverter.exe"="C:\Program Files\River Past\Audio Converter Pro\AudioConverter.exe:*:Enabled:River Past Audio Converter Pro"
    "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
    "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
    "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{46e8706c-57ff-11dc-ac2c-806d6172696f}]
    shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480


    ======List of files/folders created in the last 1 months======

    2009-02-25 15:49:51 ----A---- C:\cleannavi.txt
    2009-02-25 03:00:51 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
    2009-02-24 22:43:00 ----A---- C:\fixnavi.txt
    2009-02-24 22:41:13 ----D---- C:\Program Files\Navilog1
    2009-02-24 06:40:06 ----A---- C:\Rooter.txt
    2009-02-24 06:38:58 ----D---- C:\Rooter$
    2009-02-24 06:32:40 ----D---- C:\rsit
    2009-02-24 06:32:40 ----D---- C:\Program Files\trend micro
    2009-02-22 15:27:59 ----D---- C:\Program Files\Lavasoft
    2009-02-22 15:27:58 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2009-02-22 15:27:20 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
    2009-02-22 11:42:14 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\ImgBurn
    2009-02-22 11:41:42 ----D---- C:\Program Files\ImgBurn
    2009-02-22 11:03:53 ----D---- C:\Program Files\GRISOFT
    2009-02-20 19:04:30 ----A---- C:\WINDOWS\system32\rkcrwjakfzrhtml.dll
    2009-02-19 17:07:08 ----D---- C:\Program Files\Sophos
    2009-02-17 20:33:28 ----D---- C:\UT2004Demo
    2009-02-12 09:27:33 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
    2009-02-12 03:51:07 ----A---- C:\WINDOWS\system32\SETC83.tmp
    2009-02-12 03:51:06 ----A---- C:\WINDOWS\system32\SETC7F.tmp
    2009-02-12 03:51:06 ----A---- C:\WINDOWS\system32\SETC7E.tmp
    2009-02-12 03:51:05 ----A---- C:\WINDOWS\system32\SETC74.tmp
    2009-02-12 03:51:03 ----A---- C:\WINDOWS\system32\SETC8F.tmp
    2009-02-12 03:51:03 ----A---- C:\WINDOWS\system32\SETC77.tmp
    2009-02-12 03:51:02 ----A---- C:\WINDOWS\system32\SETC76.tmp
    2009-02-12 03:51:01 ----A---- C:\WINDOWS\system32\SETC87.tmp
    2009-02-12 03:51:00 ----A---- C:\WINDOWS\system32\SETC8C.tmp
    2009-02-12 03:50:57 ----A---- C:\WINDOWS\system32\SETC85.tmp
    2009-02-11 21:46:57 ----HD---- C:\LG3G
    2009-02-11 21:46:48 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\LG Electronics
    2009-02-11 21:44:53 ----D---- C:\Program Files\LG Electronics
    2009-02-11 21:43:32 ----D---- C:\Program Files\LG PC Suite 2
    2009-02-08 11:30:01 ----A---- C:\WINDOWS\system32\BrWebIn.dll
    2009-02-08 11:29:55 ----A---- C:\WINDOWS\system32\rkcrwjakfzrhtml.dll-uninst.exe
    2009-02-08 11:29:28 ----A---- C:\WINDOWS\system32\4570a8a5-6b89-18d4-e741-858565033b7d.exe
    2009-02-06 23:24:28 ----A---- C:\WINDOWS\system32\_rkcrwjakfzrhtml.dll
    2009-01-29 19:18:50 ----D---- C:\Program Files\PHPNukeFR
    2009-01-29 19:18:50 ----D---- C:\Program Files\Conduit

    ======List of files/folders modified in the last 1 months======

    2009-02-25 16:00:03 ----D---- C:\WINDOWS\Prefetch
    2009-02-25 15:59:23 ----D---- C:\WINDOWS\Temp
    2009-02-25 15:54:36 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\OpenOffice.org2
    2009-02-25 15:53:45 ----AD---- C:\WINDOWS\system32
    2009-02-25 15:52:41 ----RD---- C:\Program Files
    2009-02-25 15:51:01 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-02-25 15:40:13 ----A---- C:\WINDOWS\Ulead32.ini
    2009-02-25 15:13:07 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\LimeWire
    2009-02-25 10:38:04 ----A---- C:\WINDOWS\NeroDigital.ini
    2009-02-25 10:23:21 ----AD---- C:\WINDOWS
    2009-02-25 03:01:00 ----HD---- C:\WINDOWS\inf
    2009-02-25 03:00:55 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2009-02-24 20:24:39 ----HD---- C:\WINDOWS\$hf_mig$
    2009-02-24 20:24:28 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-02-22 15:30:10 ----SHD---- C:\WINDOWS\Installer
    2009-02-22 15:30:04 ----D---- C:\Config.Msi
    2009-02-22 15:27:59 ----D---- C:\WINDOWS\system32\drivers
    2009-02-22 15:27:20 ----D---- C:\Program Files\Fichiers communs
    2009-02-20 13:03:28 ----D---- C:\Temp
    2009-02-19 15:58:00 ----D---- C:\WINDOWS\Debug
    2009-02-19 12:40:48 ----A---- C:\WINDOWS\win.ini
    2009-02-18 12:47:53 ----SD---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Microsoft
    2009-02-18 10:05:59 ----D---- C:\Program Files\MSECache
    2009-02-16 21:33:37 ----D---- C:\Program Files\eMule
    2009-02-16 19:01:31 ----D---- C:\Program Files\Jewel Quest
    2009-02-16 18:12:31 ----D---- C:\Program Files\ESET
    2009-02-14 17:03:56 ----D---- C:\Documents and Settings\All Users\Application Data\Bluetooth
    2009-02-13 03:01:25 ----D---- C:\WINDOWS\system32\CatRoot
    2009-02-12 09:27:15 ----D---- C:\Program Files\Internet Explorer
    2009-02-11 21:46:42 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-02-11 21:44:53 ----HD---- C:\Program Files\InstallShield Installation Information
    2009-02-11 11:05:48 ----D---- C:\Program Files\World of Warcraft
    2009-02-11 09:52:43 ----D---- C:\Program Files\Avanquest update
    2009-02-11 09:03:08 ----SHD---- C:\System Volume Information
    2009-02-11 09:03:08 ----D---- C:\WINDOWS\system32\Restore
    2009-02-10 19:28:16 ----A---- C:\WINDOWS\pex.INI
    2009-02-09 17:17:54 ----A---- C:\AILog.txt
    2009-02-04 00:21:12 ----A---- C:\WINDOWS\system32\MRT.exe
    2009-02-01 11:32:21 ----D---- C:\Nostale(FR)
    2009-01-31 13:21:29 ----D---- C:\WINDOWS\Minidump
    2009-01-29 19:25:52 ----D---- C:\Program Files\Microsoft Games
    2009-01-27 08:01:34 ----A---- C:\WINDOWS\DUMP57b5.tmp
    2009-01-27 05:41:04 ----A---- C:\WINDOWS\DUMP5544.tmp
    2009-01-27 03:20:35 ----A---- C:\WINDOWS\DUMP54b7.tmp
    2009-01-27 02:36:00 ----A---- C:\WINDOWS\DUMP52d3.tmp
    2009-01-27 02:34:22 ----A---- C:\WINDOWS\DUMP5217.tmp
    2009-01-27 02:33:01 ----A---- C:\WINDOWS\DUMP5350.tmp
    2009-01-27 02:31:41 ----A---- C:\WINDOWS\DUMP5330.tmp
    2009-01-27 02:30:25 ----A---- C:\WINDOWS\DUMP52e2.tmp
    2009-01-27 02:29:08 ----A---- C:\WINDOWS\DUMP5296.tmp
    2009-01-27 02:27:44 ----A---- C:\WINDOWS\DUMP53ec.tmp
    2009-01-27 02:26:29 ----A---- C:\WINDOWS\DUMP5229.tmp
    2009-01-27 02:24:34 ----A---- C:\WINDOWS\DUMP5257.tmp
    2009-01-27 02:23:16 ----A---- C:\WINDOWS\DUMP52b4.tmp
    2009-01-27 02:21:53 ----A---- C:\WINDOWS\DUMP5340.tmp
    2009-01-27 02:20:36 ----A---- C:\WINDOWS\DUMP5295.tmp
    2009-01-27 02:19:20 ----A---- C:\WINDOWS\DUMP5294.tmp
    2009-01-27 02:18:02 ----A---- C:\WINDOWS\DUMP5321.tmp
    2009-01-27 02:16:24 ----A---- C:\WINDOWS\DUMP53dd.tmp
    2009-01-26 23:58:41 ----A---- C:\WINDOWS\DUMP5256.tmp
    2009-01-26 23:57:24 ----A---- C:\WINDOWS\DUMP5248.tmp
    2009-01-26 23:56:07 ----A---- C:\WINDOWS\DUMP53dc.tmp
    2009-01-26 23:54:43 ----A---- C:\WINDOWS\DUMP5287.tmp
    2009-01-26 23:53:27 ----A---- C:\WINDOWS\DUMP52c4.tmp
    2009-01-26 23:52:07 ----A---- C:\WINDOWS\DUMP52b3.tmp
    2009-01-26 23:50:47 ----A---- C:\WINDOWS\DUMP52f2.tmp
    2009-01-26 23:49:26 ----A---- C:\WINDOWS\DUMP5236.tmp
    2009-01-26 23:48:09 ----A---- C:\WINDOWS\DUMP51c9.tmp
    2009-01-26 23:46:54 ----A---- C:\WINDOWS\DUMP52a6.tmp
    2009-01-26 23:45:30 ----A---- C:\WINDOWS\DUMP53cd.tmp
    2009-01-26 23:44:14 ----A---- C:\WINDOWS\DUMP51da.tmp
    2009-01-26 23:42:57 ----A---- C:\WINDOWS\DUMP52a5.tmp
    2009-01-26 23:41:41 ----A---- C:\WINDOWS\DUMP516b.tmp
    2009-01-26 23:40:24 ----A---- C:\WINDOWS\DUMP5247.tmp
    2009-01-26 23:39:04 ----A---- C:\WINDOWS\DUMP5277.tmp
    2009-01-26 23:37:45 ----A---- C:\WINDOWS\DUMP5246.tmp
    2009-01-26 23:36:26 ----A---- C:\WINDOWS\DUMP5276.tmp
    2009-01-26 23:34:48 ----A---- C:\WINDOWS\DUMP5275.tmp
    2009-01-26 23:33:32 ----A---- C:\WINDOWS\DUMP51d9.tmp
    2009-01-26 23:32:16 ----A---- C:\WINDOWS\DUMP5228.tmp
    2009-01-26 23:30:59 ----A---- C:\WINDOWS\DUMP51b9.tmp
    2009-01-26 23:29:43 ----A---- C:\WINDOWS\DUMP53ad.tmp
    2009-01-26 23:28:05 ----A---- C:\WINDOWS\DUMP52a4.tmp
    2009-01-26 23:26:45 ----A---- C:\WINDOWS\DUMP51e8.tmp
    2009-01-26 23:25:21 ----A---- C:\WINDOWS\DUMP5265.tmp
    2009-01-26 23:24:06 ----A---- C:\WINDOWS\DUMP5303.tmp
    2009-01-26 23:22:29 ----A---- C:\WINDOWS\DUMP5286.tmp
    2009-01-26 23:20:53 ----A---- C:\WINDOWS\DUMP5208.tmp
    2009-01-26 23:19:19 ----A---- C:\WINDOWS\DUMP5227.tmp
    2009-01-26 23:17:42 ----A---- C:\WINDOWS\DUMP5302.tmp
    2009-01-26 23:16:20 ----A---- C:\WINDOWS\DUMP52c3.tmp
    2009-01-26 23:14:57 ----A---- C:\WINDOWS\DUMP5285.tmp
    2009-01-26 20:48:38 ----D---- C:\Program Files\KeyChain Photo Manager

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AmdK7;Pilote de processeur AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41856]
    R1 AvgArCln;Avg Anti-Rootkit Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgArCln.sys [2007-01-18 3968]
    R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-10-24 53256]
    R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-10-24 54280]
    R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys []
    R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
    R1 SiSkp;SiSkp; C:\WINDOWS\system32\DRIVERS\srvkp.sys [2004-07-17 12160]
    R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2008-09-12 5632]
    R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-09-06 20747]
    R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-10-24 39944]
    R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-10-24 73224]
    R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-12-12 391424]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-06-15 626220]
    R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
    R3 BrScnUsb;Brother USB Still Image driver; C:\WINDOWS\System32\Drivers\BrScnUsb.sys [2004-10-15 15295]
    R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-10-24 31240]
    R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2003-11-12 41984]
    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
    R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    R3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2003-09-10 21060]
    R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2005-01-31 22016]
    R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
    R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-07-01 2459840]
    R3 Pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 10368]
    R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
    R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S3 ASPI;Advanced SCSI Programming Interface Driver; \??\C:\WINDOWS\System32\DRIVERS\ASPI32.sys []
    S3 azpd8xb3;azpd8xb3; C:\WINDOWS\system32\drivers\azpd8xb3.sys []
    S3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys []
    S3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys []
    S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys []
    S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys []
    S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
    S3 C-Dilla;C-Dilla; \??\C:\WINDOWS\system32\drivers\CDANT.SYS []
    S3 EL90XBC;Pilote de la carte EtherLink XL 90XB/C 3Com; C:\WINDOWS\system32\DRIVERS\el90xbc5.sys [2001-08-18 66591]
    S3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-08-03 730653]
    S3 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
    S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\4DA0.tmp []
    S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
    S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
    S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
    S3 nocashio;nocashio; C:\WINDOWS\system32\drivers\nocashio.sys [2007-12-28 4096]
    S3 PID_0928;Logitech QuickCam Express(PID_0928); C:\WINDOWS\system32\DRIVERS\LV561AV.SYS [2005-01-31 211712]
    S3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2002-07-29 23808]
    S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
    S3 RT73;Belkin USB Network Adapter; C:\WINDOWS\system32\DRIVERS\rt73.sys [2005-08-02 232192]
    S3 s616bus;Sony Ericsson Device 616 driver (WDM); C:\WINDOWS\system32\DRIVERS\s616bus.sys [2007-04-03 83208]
    S3 s616mdfl;Sony Ericsson Device 616 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s616mdfl.sys [2007-04-03 15112]
    S3 s616mdm;Sony Ericsson Device 616 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s616mdm.sys [2007-04-03 108680]
    S3 s616mgmt;Sony Ericsson Device 616 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s616mgmt.sys [2007-04-03 100360]
    S3 s616nd5;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (NDIS); C:\WINDOWS\system32\DRIVERS\s616nd5.sys [2007-04-03 23176]
    S3 s616obex;Sony Ericsson Device 616 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s616obex.sys [2007-04-03 98568]
    S3 s616unic;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (WDM); C:\WINDOWS\system32\DRIVERS\s616unic.sys [2007-04-03 99080]
    S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\WINDOWS\system32\DRIVERS\s916bus.sys [2007-11-02 83496]
    S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s916mdfl.sys [2007-11-02 15016]
    S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s916mdm.sys [2007-11-02 109992]
    S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s916mgmt.sys [2007-11-02 103976]
    S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s916obex.sys [2007-11-02 100008]
    S3 SiS315;SiS315; C:\WINDOWS\system32\DRIVERS\sisgrp.sys [2004-07-19 218112]
    S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
    S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2005-12-22 80272]
    S3 sscdmdfl;SAMSUNG CDMA Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2005-12-22 10864]
    S3 sscdmdm;SAMSUNG CDMA Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2005-12-22 137884]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
    S3 USB_RNDIS;Thomson ST Remote NDIS Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
    S3 usbbus;LGE Mobile Composite USB Device; C:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2007-07-11 12416]
    S3 UsbDiag;LGE Mobile USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys [2007-07-11 19840]
    S3 USBIO;USBIO Driver (usbio.sys); C:\WINDOWS\System32\Drivers\usbio.sys [2001-05-07 19805]
    S3 USBModem;LGE Mobile USB Modem; C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2007-07-11 21632]
    S3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
    S3 UsbSagCom;Mobile Device Full USB Driver; C:\WINDOWS\system32\DRIVERS\UsbSagCom.sys [2007-06-29 51712]
    S3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys []
    S3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys []
    S3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2004-05-05 142976]
    S3 w200bus;Sony Ericsson W200 driver (WDM); C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 61504]
    S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 9328]
    S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 97056]
    S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 88560]
    S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 86368]
    S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
    S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
    S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-14 5504]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2009-02-22 611664]
    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
    R2 Belkin Wireless USB Network Adapter Service;Belkin Wireless USB Network Adapter; C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe [2004-03-29 49152]
    R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
    R2 Brother XP spl Service;BrSplService; C:\WINDOWS\system32\brsvc01a.exe [2002-04-11 57344]
    R2 C-DillaSrv;C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2001-09-10 32256]
    R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2004-07-01 114755]
    R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
    R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
    R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
    R3 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe [2008-01-22 275752]
    S2 .EsetTrialReset;Eset Trial Reset; C:\WINDOWS\system32\regedt32.exe [2004-08-04 3584]
    S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
    S3 Boonty Games;Boonty Games; C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2008-08-19 69120]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
    S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-10-24 19200]
    S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268800]
    S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-10-01 138168]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
    S3 MSCSPTISRV;MSCSPTISRV; C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe [2006-12-14 45056]
    S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2008-04-08 800040]
    S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe [2006-12-14 57344]
    S3 SonicStage Back-End Service;SonicStage Back-End Service; C:\Program Files\Fichiers communs\Sony Shared\AVLib\SsBeSvc.exe [2007-02-05 112184]
    S3 SPTISRV;Sony SPTI Service; C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe [2006-12-14 69632]
    S3 SSScsiSV;SonicStage SCSI Service; C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe [2007-02-05 75320]
    S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
    S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
    S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
    S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]

    -----------------EOF-----------------
    Clean Navipromo version 3.7.4 commencé le 25/02/2009 à 15:49:51,20

    Outil exécuté depuis C:\Program Files\navilog1

    Mise à jour le 16.02.2009 à 18h00 par IL-MAFIOSO

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 3000+ )
    BIOS : Rev. 3.11
    USER : Compaq_Propriétaire ( Administrator )
    BOOT : Normal boot

    Antivirus : ESET Smart Security 3.0 3.0 (Activated)
    Firewall : ESET Personal firewall 3.0.684.0 (Activated)

    A:\ (USB)
    C:\ (Local Disk) - NTFS - Total:144 Go (Free:18 Go)
    D:\ (Local Disk) - FAT32 - Total:4 Go (Free:1 Go)
    E:\ (CD or DVD)
    F:\ (CD or DVD)
    G:\ (CD or DVD)
    H:\ (CD or DVD)
    I:\ (USB)


    Mode suppression automatique
    avec prise en charge résultats Catchme et GNS


    Nettoyage exécuté au redémarrage de l'ordinateur


    *** fsbl1.txt non trouvé ***
    (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)


    *** Suppression avec sauvegardes résultats GenericNaviSearch ***

    * Suppression dans "C:\WINDOWS\System32" *


    * Suppression dans "C:\Documents and Settings\Compaq_Propriétaire\locals~1\applic~1" *


    * Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

    * Suppression dans "C:\DOCUME~1\cindy\locals~1\applic~1" *


    *** Suppression dossiers dans "C:\WINDOWS" ***


    *** Suppression dossiers dans "C:\Program Files" ***

    ...\MessengerSkinner ...suppression...
    ...\MessengerSkinner supprimé !


    *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

    ...\MessengerSkinner ...suppression...
    ...\MessengerSkinner supprimé !


    *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


    *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***


    *** Suppression dossiers dans "C:\Documents and Settings\Compaq_Propriétaire\applic~1" ***

    ...\MessengerSkinner ...suppression...
    ...\MessengerSkinner supprimé !


    *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***


    *** Suppression dossiers dans "C:\DOCUME~1\cindy\applic~1" ***

    ...\MessengerSkinner ...suppression...
    ...\MessengerSkinner supprimé !


    *** Suppression dossiers dans "C:\Documents and Settings\Compaq_Propriétaire\locals~1\applic~1" ***


    *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***


    *** Suppression dossiers dans "C:\DOCUME~1\cindy\locals~1\applic~1" ***


    *** Suppression dossiers dans "C:\Documents and Settings\Compaq_Propriétaire\menudm~1\progra~1" ***


    *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***


    *** Suppression dossiers dans "C:\DOCUME~1\cindy\menudm~1\progra~1" ***



    *** Suppression fichiers ***


    *** Suppression fichiers temporaires ***

    Nettoyage contenu C:\WINDOWS\Temp effectué !
    Nettoyage contenu C:\Documents and Settings\Compaq_Propri‚taire\locals~1\Temp effectué !

    *** Traitement Recherche complémentaire ***
    (Recherche fichiers spécifiques)

    1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

    2)Recherche, création sauvegardes et suppression Heuristique :


    * Dans "C:\WINDOWS\system32" *



    * Dans "C:\Documents and Settings\Compaq_Propriétaire\locals~1\applic~1" *


    oeyek.dat trouvé !
    Copie oeyek.dat réalisée avec succès !
    oeyek.dat supprimé !

    oeyek_nav.dat trouvé !
    Copie oeyek_nav.dat réalisée avec succès !
    oeyek_nav.dat supprimé !

    oeyek_navps.dat trouvé !
    Copie oeyek_navps.dat réalisée avec succès !
    oeyek_navps.dat supprimé !


    * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *



    * Dans "C:\DOCUME~1\cindy\locals~1\applic~1" *


    okyqo.dat trouvé !
    Copie okyqo.dat réalisée avec succès !
    okyqo.dat supprimé !

    okyqo_nav.dat trouvé !
    Copie okyqo_nav.dat réalisée avec succès !
    okyqo_nav.dat supprimé !

    okyqo_navps.dat trouvé !
    Copie okyqo_navps.dat réalisée avec succès !
    okyqo_navps.dat supprimé !


    *** Sauvegarde du Registre vers dossier Safebackup ***

    sauvegarde du Registre réalisée avec succès !

    *** Nettoyage Registre ***

    Nettoyage Registre Ok


    *** Certificats ***

    Certificat Egroup supprimé !
    Certificat Electronic-Group supprimé !
    Certificat Montorgueil absent !
    Certificat OOO-Favorit supprimé !
    Certificat Sunny-Day-Design-Ltdt absent !

    *** Recherche autres dossiers et fichiers connus ***



    *** Nettoyage terminé le 25/02/2009 à 15:53:44,73 ***

    a b 8 Sécurité
    26 Février 2009 19:51:53

    Re,

    Télécharge OTMoveIt3 (de OldTimer). Sauvegarde-le sur ton Bureau.
    Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :

    :processes
    explorer.exe

    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{880F9C04-CB4A-9117-18A0-5C899363CB13}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{6F282B65-56BF-4BD1-A8B2-A4449A05863D}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{6F282B65-56BF-4BD1-A8B2-A4449A05863D}"=-

    :files
    C:\Program Files\GamesBar
    C:\WINDOWS\system32\rkcrwjakfzrhtml.dll
    C:\WINDOWS\system32\rkcrwjakfzrhtml.dll-uninst.exe
    C:\WINDOWS\system32\4570a8a5-6b89-18d4-e741-858565033b7d.exe
    C:\WINDOWS\system32\_rkcrwjakfzrhtml.dll
    C:\Program Files\Conduit

    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]


    Double clique sur OTMoveIt3.exe afin de le lancer.
    Colle (ou Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
    Clique maintenant sur le bouton [#ff0000]MoveIt![/#f] puis ferme OTMoveIt3.

    [#ff0000]Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
    Accepte en cliquant sur YES.[/#f]

    Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
    Le nom du rapport correspond au moment de sa création : date_heure.log
    26 Février 2009 22:03:45

    merci beaucoup pour ton aide je te joins le rapport
    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== REGISTRY ==========
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{880F9C04-CB4A-9117-18A0-5C899363CB13}\\ deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{6F282B65-56BF-4BD1-A8B2-A4449A05863D} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}\ deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{6F282B65-56BF-4BD1-A8B2-A4449A05863D} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}\ not found.
    ========== FILES ==========
    C:\Program Files\GamesBar moved successfully.
    C:\WINDOWS\system32\rkcrwjakfzrhtml.dll unregistered successfully.
    C:\WINDOWS\system32\rkcrwjakfzrhtml.dll moved successfully.
    C:\WINDOWS\system32\rkcrwjakfzrhtml.dll-uninst.exe moved successfully.
    C:\WINDOWS\system32\4570a8a5-6b89-18d4-e741-858565033b7d.exe moved successfully.
    C:\WINDOWS\system32\_rkcrwjakfzrhtml.dll unregistered successfully.
    C:\WINDOWS\system32\_rkcrwjakfzrhtml.dll moved successfully.
    C:\Program Files\Conduit\Community Alerts moved successfully.
    C:\Program Files\Conduit moved successfully.
    ========== COMMANDS ==========
    File delete failed. C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\dhyfnsge.dat scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IadHide4.dll scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFEC9D.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFECAA.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFF37D.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFF38A.tmp scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
    Local Service Temp folder emptied.
    Local Service Temporary Internet Files folder emptied.
    Windows Temp folder emptied.
    Java cache emptied.
    FireFox cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02262009_214024

    Files moved on Reboot...
    File C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\dhyfnsge.dat not found!
    DllUnregisterServer procedure not found in C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IadHide4.dll
    C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IadHide4.dll NOT unregistered.
    C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\IadHide4.dll moved successfully.
    File C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFEC9D.tmp not found!
    File C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFECAA.tmp not found!
    File C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFF37D.tmp not found!
    File C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~DFF38A.tmp not found!
    File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
    File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be moved on reboot.
    File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
    a b 8 Sécurité
    26 Février 2009 22:31:24

    Refais un scan RSIT :) 
    27 Février 2009 06:41:40

    scan rsit

    Logfile of random's system information tool 1.05 (written by random/random)
    Run by Compaq_Propriétaire at 2009-02-27 06:38:26
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 17 GB (11%) free of 148 GB
    Total RAM: 1023 MB (50% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 06:38:33, on 27/02/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\brsvc01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
    C:\Program Files\ESET\ESET Smart Security\ekrn.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\IoctlSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\ESET\ESET Smart Security\egui.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
    C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
    C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Windows Live Toolbar\msn_sl.exe
    C:\Documents and Settings\Compaq_Propriétaire\Bureau\RSIT.exe
    C:\Program Files\trend micro\Compaq_Propriétaire.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    R3 - URLSearchHook: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    F2 - REG:system.ini: Shell=
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    O2 - BHO: (no name) - {7BD4A40D-8DFC-4F9F-B288-011490D5FCD1} - C:\WINDOWS\system32\BrWebIn.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: snappyads - {f18970dd-8f96-7e99-c7c1-56a16232a2c3} - (no file)
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [System] explorer.exe
    O4 - HKCU\..\Run: [nodenable] C:\Program Files\eset\nodenable.exe
    O4 - HKCU\..\RunServices: [System] explorer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
    O4 - Global Startup: Contrôleur d’état.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?d32c1a7c185643c7bce11ae098e15e13
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d32c1a7c185643c7bce11ae098e15e13
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld...
    O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.fr/Genoogle/Components/ActiveX/Se...
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0....
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
    O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
    O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SsBeSvc.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe

    --
    End of file - 12919 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]
    PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-02-20 1882136]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7BD4A40D-8DFC-4F9F-B288-011490D5FCD1}]
    C:\WINDOWS\system32\BrWebIn.dll [2002-10-31 96256]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-09-16 737776]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
    Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f18970dd-8f96-7e99-c7c1-56a16232a2c3}]
    snappyads

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2007-10-01 2436160]
    {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-02-20 1882136]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2004-07-01 4112384]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-11-04 413696]
    "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]
    "AppleSyncNotifier"=C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-02-06 177472]
    "LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2004-10-08 221184]
    "LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2005-01-18 458752]
    "LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2005-01-18 217088]
    "NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2008-05-28 570664]
    "egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-10-24 1451264]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe [2008-01-22 152872]
    "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-10-07 68856]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
    "Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [2008-07-10 397312]
    "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-08-08 490952]
    "LDM"=C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe [2008-12-21 20480]
    "LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe [2005-01-18 196608]
    "System"=C:\WINDOWS\explorer.exe [2008-04-14 1037824]
    "nodenable"=C:\Program Files\eset\nodenable.exe [2008-09-22 326829]

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    Contrôleur d’état.lnk - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

    C:\Documents and Settings\Compaq_Propriétaire\Menu Démarrer\Programmes\Démarrage
    OpenOffice.org 2.2.lnk - C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
    C:\WINDOWS\system32\igfxsrvc.dll [2004-08-03 344064]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=FF000000
    "NoDriveAutoRun"=4294967295
    "ForceClassicControlPanel"=1

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=
    "HonorAutoRunSetting"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL France"
    "C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\GHIJ8HMN\installer-38284-845-Open-Office-complet-en-francais-French[1].exe"="C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\GHIJ8HMN\installer-38284-845-Open-Office-complet-en-francais-French[1].exe:*:Enabled:installer-38284-845-Open-Office-complet-en-francais-French[1]"
    "C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
    "C:\Program Files\Zapu\Zapu\wDivi.exe"="C:\Program Files\Zapu\Zapu\wDivi.exe:*:D isabled:Zapu Control"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe"="C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home"
    "C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe"="C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.0"
    "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
    "C:\Program Files\HomePlayer\HomePlayer.exe"="C:\Program Files\HomePlayer\HomePlayer.exe:*:Enabled:HomePlayer"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\Program Files\River Past\Audio Converter Pro\AudioConverter.exe"="C:\Program Files\River Past\Audio Converter Pro\AudioConverter.exe:*:Enabled:River Past Audio Converter Pro"
    "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
    "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
    "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{46e8706c-57ff-11dc-ac2c-806d6172696f}]
    shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480


    ======List of files/folders created in the last 1 months======

    2009-02-26 21:39:37 ----D---- C:\_OTMoveIt
    2009-02-25 15:49:51 ----A---- C:\cleannavi.txt
    2009-02-25 03:00:51 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
    2009-02-24 22:43:00 ----A---- C:\fixnavi.txt
    2009-02-24 22:41:13 ----D---- C:\Program Files\Navilog1
    2009-02-24 06:40:06 ----A---- C:\Rooter.txt
    2009-02-24 06:38:58 ----D---- C:\Rooter$
    2009-02-24 06:32:40 ----D---- C:\rsit
    2009-02-24 06:32:40 ----D---- C:\Program Files\trend micro
    2009-02-22 15:27:59 ----D---- C:\Program Files\Lavasoft
    2009-02-22 15:27:58 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2009-02-22 15:27:20 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
    2009-02-22 11:42:14 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\ImgBurn
    2009-02-22 11:41:42 ----D---- C:\Program Files\ImgBurn
    2009-02-22 11:03:53 ----D---- C:\Program Files\GRISOFT
    2009-02-19 17:07:08 ----D---- C:\Program Files\Sophos
    2009-02-17 20:33:28 ----D---- C:\UT2004Demo
    2009-02-12 09:27:33 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
    2009-02-12 03:51:07 ----A---- C:\WINDOWS\system32\SETC83.tmp
    2009-02-12 03:51:06 ----A---- C:\WINDOWS\system32\SETC7F.tmp
    2009-02-12 03:51:06 ----A---- C:\WINDOWS\system32\SETC7E.tmp
    2009-02-12 03:51:05 ----A---- C:\WINDOWS\system32\SETC74.tmp
    2009-02-12 03:51:03 ----A---- C:\WINDOWS\system32\SETC8F.tmp
    2009-02-12 03:51:03 ----A---- C:\WINDOWS\system32\SETC77.tmp
    2009-02-12 03:51:02 ----A---- C:\WINDOWS\system32\SETC76.tmp
    2009-02-12 03:51:01 ----A---- C:\WINDOWS\system32\SETC87.tmp
    2009-02-12 03:51:00 ----A---- C:\WINDOWS\system32\SETC8C.tmp
    2009-02-12 03:50:57 ----A---- C:\WINDOWS\system32\SETC85.tmp
    2009-02-11 21:46:57 ----HD---- C:\LG3G
    2009-02-11 21:46:48 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\LG Electronics
    2009-02-11 21:44:53 ----D---- C:\Program Files\LG Electronics
    2009-02-11 21:43:32 ----D---- C:\Program Files\LG PC Suite 2
    2009-02-08 11:30:01 ----A---- C:\WINDOWS\system32\BrWebIn.dll
    2009-01-29 19:18:50 ----D---- C:\Program Files\PHPNukeFR

    ======List of files/folders modified in the last 1 months======

    2009-02-27 06:38:34 ----D---- C:\WINDOWS\Temp
    2009-02-26 21:52:08 ----D---- C:\WINDOWS\Prefetch
    2009-02-26 21:45:39 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\OpenOffice.org2
    2009-02-26 21:41:39 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-02-26 21:40:32 ----RD---- C:\Program Files
    2009-02-26 21:40:32 ----AD---- C:\WINDOWS\system32
    2009-02-25 20:04:29 ----A---- C:\WINDOWS\NeroDigital.ini
    2009-02-25 15:40:13 ----A---- C:\WINDOWS\Ulead32.ini
    2009-02-25 15:13:07 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\LimeWire
    2009-02-25 10:23:21 ----AD---- C:\WINDOWS
    2009-02-25 03:01:00 ----HD---- C:\WINDOWS\inf
    2009-02-25 03:00:55 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2009-02-24 20:24:39 ----HD---- C:\WINDOWS\$hf_mig$
    2009-02-24 20:24:28 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-02-22 15:30:10 ----SHD---- C:\WINDOWS\Installer
    2009-02-22 15:30:04 ----D---- C:\Config.Msi
    2009-02-22 15:27:59 ----D---- C:\WINDOWS\system32\drivers
    2009-02-22 15:27:20 ----D---- C:\Program Files\Fichiers communs
    2009-02-20 13:03:28 ----D---- C:\Temp
    2009-02-19 15:58:00 ----D---- C:\WINDOWS\Debug
    2009-02-19 12:40:48 ----A---- C:\WINDOWS\win.ini
    2009-02-18 12:47:53 ----SD---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Microsoft
    2009-02-18 10:05:59 ----D---- C:\Program Files\MSECache
    2009-02-16 21:33:37 ----D---- C:\Program Files\eMule
    2009-02-16 19:01:31 ----D---- C:\Program Files\Jewel Quest
    2009-02-16 18:12:31 ----D---- C:\Program Files\ESET
    2009-02-14 17:03:56 ----D---- C:\Documents and Settings\All Users\Application Data\Bluetooth
    2009-02-13 03:01:25 ----D---- C:\WINDOWS\system32\CatRoot
    2009-02-12 09:27:15 ----D---- C:\Program Files\Internet Explorer
    2009-02-11 21:46:42 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-02-11 21:44:53 ----HD---- C:\Program Files\InstallShield Installation Information
    2009-02-11 11:05:48 ----D---- C:\Program Files\World of Warcraft
    2009-02-11 09:52:43 ----D---- C:\Program Files\Avanquest update
    2009-02-11 09:03:08 ----SHD---- C:\System Volume Information
    2009-02-11 09:03:08 ----D---- C:\WINDOWS\system32\Restore
    2009-02-10 19:28:16 ----A---- C:\WINDOWS\pex.INI
    2009-02-09 17:17:54 ----A---- C:\AILog.txt
    2009-02-04 00:21:12 ----A---- C:\WINDOWS\system32\MRT.exe
    2009-02-01 11:32:21 ----D---- C:\Nostale(FR)
    2009-01-31 13:21:29 ----D---- C:\WINDOWS\Minidump
    2009-01-29 19:25:52 ----D---- C:\Program Files\Microsoft Games

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AmdK7;Pilote de processeur AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41856]
    R1 AvgArCln;Avg Anti-Rootkit Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgArCln.sys [2007-01-18 3968]
    R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-10-24 53256]
    R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-10-24 54280]
    R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys []
    R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
    R1 SiSkp;SiSkp; C:\WINDOWS\system32\DRIVERS\srvkp.sys [2004-07-17 12160]
    R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2008-09-12 5632]
    R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-09-06 20747]
    R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-10-24 39944]
    R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-10-24 73224]
    R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-12-12 391424]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-06-15 626220]
    R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
    R3 BrScnUsb;Brother USB Still Image driver; C:\WINDOWS\System32\Drivers\BrScnUsb.sys [2004-10-15 15295]
    R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-10-24 31240]
    R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2003-11-12 41984]
    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
    R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    R3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2003-09-10 21060]
    R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2005-01-31 22016]
    R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
    R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-07-01 2459840]
    R3 Pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 10368]
    R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
    R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S3 afe13rsa;afe13rsa; C:\WINDOWS\system32\drivers\afe13rsa.sys []
    S3 ASPI;Advanced SCSI Programming Interface Driver; \??\C:\WINDOWS\System32\DRIVERS\ASPI32.sys []
    S3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys []
    S3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys []
    S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys []
    S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys []
    S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
    S3 C-Dilla;C-Dilla; \??\C:\WINDOWS\system32\drivers\CDANT.SYS []
    S3 EL90XBC;Pilote de la carte EtherLink XL 90XB/C 3Com; C:\WINDOWS\system32\DRIVERS\el90xbc5.sys [2001-08-18 66591]
    S3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-08-03 730653]
    S3 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
    S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\4DA0.tmp []
    S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
    S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
    S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
    S3 nocashio;nocashio; C:\WINDOWS\system32\drivers\nocashio.sys [2007-12-28 4096]
    S3 PID_0928;Logitech QuickCam Express(PID_0928); C:\WINDOWS\system32\DRIVERS\LV561AV.SYS [2005-01-31 211712]
    S3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2002-07-29 23808]
    S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
    S3 RT73;Belkin USB Network Adapter; C:\WINDOWS\system32\DRIVERS\rt73.sys [2005-08-02 232192]
    S3 s616bus;Sony Ericsson Device 616 driver (WDM); C:\WINDOWS\system32\DRIVERS\s616bus.sys [2007-04-03 83208]
    S3 s616mdfl;Sony Ericsson Device 616 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s616mdfl.sys [2007-04-03 15112]
    S3 s616mdm;Sony Ericsson Device 616 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s616mdm.sys [2007-04-03 108680]
    S3 s616mgmt;Sony Ericsson Device 616 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s616mgmt.sys [2007-04-03 100360]
    S3 s616nd5;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (NDIS); C:\WINDOWS\system32\DRIVERS\s616nd5.sys [2007-04-03 23176]
    S3 s616obex;Sony Ericsson Device 616 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s616obex.sys [2007-04-03 98568]
    S3 s616unic;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (WDM); C:\WINDOWS\system32\DRIVERS\s616unic.sys [2007-04-03 99080]
    S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\WINDOWS\system32\DRIVERS\s916bus.sys [2007-11-02 83496]
    S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s916mdfl.sys [2007-11-02 15016]
    S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s916mdm.sys [2007-11-02 109992]
    S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s916mgmt.sys [2007-11-02 103976]
    S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s916obex.sys [2007-11-02 100008]
    S3 SiS315;SiS315; C:\WINDOWS\system32\DRIVERS\sisgrp.sys [2004-07-19 218112]
    S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
    S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2005-12-22 80272]
    S3 sscdmdfl;SAMSUNG CDMA Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2005-12-22 10864]
    S3 sscdmdm;SAMSUNG CDMA Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2005-12-22 137884]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
    S3 USB_RNDIS;Thomson ST Remote NDIS Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
    S3 usbbus;LGE Mobile Composite USB Device; C:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2007-07-11 12416]
    S3 UsbDiag;LGE Mobile USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys [2007-07-11 19840]
    S3 USBIO;USBIO Driver (usbio.sys); C:\WINDOWS\System32\Drivers\usbio.sys [2001-05-07 19805]
    S3 USBModem;LGE Mobile USB Modem; C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2007-07-11 21632]
    S3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
    S3 UsbSagCom;Mobile Device Full USB Driver; C:\WINDOWS\system32\DRIVERS\UsbSagCom.sys [2007-06-29 51712]
    S3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys []
    S3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys []
    S3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2004-05-05 142976]
    S3 w200bus;Sony Ericsson W200 driver (WDM); C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 61504]
    S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 9328]
    S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 97056]
    S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 88560]
    S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 86368]
    S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
    S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
    S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-14 5504]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2009-02-22 611664]
    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
    R2 Belkin Wireless USB Network Adapter Service;Belkin Wireless USB Network Adapter; C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe [2004-03-29 49152]
    R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
    R2 Brother XP spl Service;BrSplService; C:\WINDOWS\system32\brsvc01a.exe [2002-04-11 57344]
    R2 C-DillaSrv;C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2001-09-10 32256]
    R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2004-07-01 114755]
    R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
    R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
    R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
    R3 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe [2008-01-22 275752]
    S2 .EsetTrialReset;Eset Trial Reset; C:\WINDOWS\system32\regedt32.exe [2004-08-04 3584]
    S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
    S3 Boonty Games;Boonty Games; C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2008-08-19 69120]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
    S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-10-24 19200]
    S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268800]
    S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-10-01 138168]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
    S3 MSCSPTISRV;MSCSPTISRV; C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe [2006-12-14 45056]
    S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2008-04-08 800040]
    S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe [2006-12-14 57344]
    S3 SonicStage Back-End Service;SonicStage Back-End Service; C:\Program Files\Fichiers communs\Sony Shared\AVLib\SsBeSvc.exe [2007-02-05 112184]
    S3 SPTISRV;Sony SPTI Service; C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe [2006-12-14 69632]
    S3 SSScsiSV;SonicStage SCSI Service; C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe [2007-02-05 75320]
    S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
    S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
    S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
    S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]

    -----------------EOF-----------------
    a b 8 Sécurité
    27 Février 2009 18:42:47

    Re,

    Il y a des restes.

    Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :

    :processes
    explorer.exe

    :services
    Boonty Games

    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "System"=-
    "nodenable"=-

    :files
    C:\Program Files\Fichiers communs\BOONTY Shared
    C:\Program Files\eset\nodenable.exe

    :commands
    [start explorer]
    [reboot]


    Double clique sur OTMoveIt3.exe afin de le lancer.
    Colle (ou Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
    Clique maintenant sur le bouton [#ff0000]MoveIt![/#f] puis ferme OTMoveIt3.

    [#ff0000]Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
    Accepte en cliquant sur YES.[/#f]

    Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
    Le nom du rapport correspond au moment de sa création : date_heure.log
    27 Février 2009 20:34:28

    je t'envoie le rapport
    Process explorer.exe killed successfully.
    ========== SERVICES/DRIVERS ==========
    Service Boonty Games stopped successfully.
    Service Boonty Games deleted successfully.
    ========== REGISTRY ==========
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\System deleted successfully.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\nodenable deleted successfully.
    ========== FILES ==========
    C:\Program Files\Fichiers communs\BOONTY Shared\Service moved successfully.
    C:\Program Files\Fichiers communs\BOONTY Shared moved successfully.
    C:\Program Files\eset\nodenable.exe moved successfully.
    ========== COMMANDS ==========
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02272009_192528
    encore merci
    a b 8 Sécurité
    28 Février 2009 11:12:08

    Refais un scan RSIT, le dernier normalement :) 
    28 Février 2009 12:48:22

    Logfile of random's system information tool 1.05 (written by random/random)
    Run by Compaq_Propriétaire at 2009-02-28 12:46:23
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 16 GB (11%) free of 148 GB
    Total RAM: 1023 MB (51% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:46:30, on 28/02/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\brsvc01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
    C:\Program Files\ESET\ESET Smart Security\ekrn.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\IoctlSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\ESET\ESET Smart Security\egui.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
    C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Brother\ControlCenter2\brctrcen.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Documents and Settings\Compaq_Propriétaire\Bureau\RSIT.exe
    C:\Program Files\trend micro\Compaq_Propriétaire.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&loca...
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&lo...
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    R3 - URLSearchHook: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    F2 - REG:system.ini: Shell=
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    O2 - BHO: (no name) - {7BD4A40D-8DFC-4F9F-B288-011490D5FCD1} - C:\WINDOWS\system32\BrWebIn.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: snappyads - {f18970dd-8f96-7e99-c7c1-56a16232a2c3} - (no file)
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\RunServices: [System] explorer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
    O4 - Global Startup: Contrôleur d’état.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?d32c1a7c185643c7bce11ae098e15e13
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d32c1a7c185643c7bce11ae098e15e13
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld...
    O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.fr/Genoogle/Components/ActiveX/Se...
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0....
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
    O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
    O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SsBeSvc.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe

    --
    End of file - 12720 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]
    PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-02-20 1882136]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7BD4A40D-8DFC-4F9F-B288-011490D5FCD1}]
    C:\WINDOWS\system32\BrWebIn.dll [2002-10-31 96256]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-09-16 737776]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
    Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f18970dd-8f96-7e99-c7c1-56a16232a2c3}]
    snappyads

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2007-10-01 2436160]
    {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-02-20 1882136]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2004-07-01 4112384]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-11-04 413696]
    "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]
    "AppleSyncNotifier"=C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-02-06 177472]
    "LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2004-10-08 221184]
    "LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2005-01-18 458752]
    "LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2005-01-18 217088]
    "NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2008-05-28 570664]
    "egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-10-24 1451264]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe [2008-01-22 152872]
    "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-10-07 68856]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
    "Sony Ericsson PC Suite"=C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe [2008-07-10 397312]
    "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-08-08 490952]
    "LDM"=C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe [2008-12-21 20480]
    "LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe [2005-01-18 196608]

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    Contrôleur d’état.lnk - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

    C:\Documents and Settings\Compaq_Propriétaire\Menu Démarrer\Programmes\Démarrage
    OpenOffice.org 2.2.lnk - C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
    C:\WINDOWS\system32\igfxsrvc.dll [2004-08-03 344064]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=FF000000
    "NoDriveAutoRun"=4294967295
    "ForceClassicControlPanel"=1

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=
    "HonorAutoRunSetting"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL France"
    "C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\GHIJ8HMN\installer-38284-845-Open-Office-complet-en-francais-French[1].exe"="C:\Documents and Settings\Compaq_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\GHIJ8HMN\installer-38284-845-Open-Office-complet-en-francais-French[1].exe:*:Enabled:installer-38284-845-Open-Office-complet-en-francais-French[1]"
    "C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
    "C:\Program Files\Zapu\Zapu\wDivi.exe"="C:\Program Files\Zapu\Zapu\wDivi.exe:*:D isabled:Zapu Control"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe"="C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home"
    "C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe"="C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.0"
    "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
    "C:\Program Files\HomePlayer\HomePlayer.exe"="C:\Program Files\HomePlayer\HomePlayer.exe:*:Enabled:HomePlayer"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\Program Files\River Past\Audio Converter Pro\AudioConverter.exe"="C:\Program Files\River Past\Audio Converter Pro\AudioConverter.exe:*:Enabled:River Past Audio Converter Pro"
    "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
    "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
    "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{46e8706c-57ff-11dc-ac2c-806d6172696f}]
    shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480


    ======List of files/folders created in the last 1 months======

    2009-02-26 21:39:37 ----D---- C:\_OTMoveIt
    2009-02-25 15:49:51 ----A---- C:\cleannavi.txt
    2009-02-25 03:00:51 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
    2009-02-24 22:43:00 ----A---- C:\fixnavi.txt
    2009-02-24 22:41:13 ----D---- C:\Program Files\Navilog1
    2009-02-24 06:40:06 ----A---- C:\Rooter.txt
    2009-02-24 06:38:58 ----D---- C:\Rooter$
    2009-02-24 06:32:40 ----D---- C:\rsit
    2009-02-24 06:32:40 ----D---- C:\Program Files\trend micro
    2009-02-22 15:27:59 ----D---- C:\Program Files\Lavasoft
    2009-02-22 15:27:58 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2009-02-22 15:27:20 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
    2009-02-22 11:42:14 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\ImgBurn
    2009-02-22 11:41:42 ----D---- C:\Program Files\ImgBurn
    2009-02-22 11:03:53 ----D---- C:\Program Files\GRISOFT
    2009-02-19 17:07:08 ----D---- C:\Program Files\Sophos
    2009-02-17 20:33:28 ----D---- C:\UT2004Demo
    2009-02-12 09:27:33 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
    2009-02-12 03:51:07 ----A---- C:\WINDOWS\system32\SETC83.tmp
    2009-02-12 03:51:06 ----A---- C:\WINDOWS\system32\SETC7F.tmp
    2009-02-12 03:51:06 ----A---- C:\WINDOWS\system32\SETC7E.tmp
    2009-02-12 03:51:05 ----A---- C:\WINDOWS\system32\SETC74.tmp
    2009-02-12 03:51:03 ----A---- C:\WINDOWS\system32\SETC8F.tmp
    2009-02-12 03:51:03 ----A---- C:\WINDOWS\system32\SETC77.tmp
    2009-02-12 03:51:02 ----A---- C:\WINDOWS\system32\SETC76.tmp
    2009-02-12 03:51:01 ----A---- C:\WINDOWS\system32\SETC87.tmp
    2009-02-12 03:51:00 ----A---- C:\WINDOWS\system32\SETC8C.tmp
    2009-02-12 03:50:57 ----A---- C:\WINDOWS\system32\SETC85.tmp
    2009-02-11 21:46:57 ----HD---- C:\LG3G
    2009-02-11 21:46:48 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\LG Electronics
    2009-02-11 21:44:53 ----D---- C:\Program Files\LG Electronics
    2009-02-11 21:43:32 ----D---- C:\Program Files\LG PC Suite 2
    2009-02-08 11:30:01 ----A---- C:\WINDOWS\system32\BrWebIn.dll
    2009-01-29 19:18:50 ----D---- C:\Program Files\PHPNukeFR

    ======List of files/folders modified in the last 1 months======

    2009-02-28 12:35:10 ----D---- C:\WINDOWS\Temp
    2009-02-28 12:17:35 ----D---- C:\WINDOWS\Prefetch
    2009-02-28 09:31:39 ----D---- C:\Program Files\WinRAR
    2009-02-27 22:20:40 ----A---- C:\WINDOWS\Ulead32.ini
    2009-02-27 21:25:06 ----A---- C:\WINDOWS\NeroDigital.ini
    2009-02-27 20:53:10 ----HD---- C:\WINDOWS\inf
    2009-02-27 20:41:19 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-02-27 20:29:44 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\OpenOffice.org2
    2009-02-27 19:25:50 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-02-27 19:25:29 ----D---- C:\Program Files\Fichiers communs
    2009-02-27 19:25:29 ----D---- C:\Program Files\ESET
    2009-02-27 18:10:30 ----D---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\LimeWire
    2009-02-26 21:40:32 ----RD---- C:\Program Files
    2009-02-26 21:40:32 ----AD---- C:\WINDOWS\system32
    2009-02-25 10:23:21 ----AD---- C:\WINDOWS
    2009-02-25 03:00:55 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2009-02-24 20:24:39 ----HD---- C:\WINDOWS\$hf_mig$
    2009-02-22 15:30:10 ----SHD---- C:\WINDOWS\Installer
    2009-02-22 15:30:04 ----D---- C:\Config.Msi
    2009-02-22 15:27:59 ----D---- C:\WINDOWS\system32\drivers
    2009-02-20 13:03:28 ----D---- C:\Temp
    2009-02-19 15:58:00 ----D---- C:\WINDOWS\Debug
    2009-02-19 12:40:48 ----A---- C:\WINDOWS\win.ini
    2009-02-18 12:47:53 ----SD---- C:\Documents and Settings\Compaq_Propriétaire\Application Data\Microsoft
    2009-02-18 10:05:59 ----D---- C:\Program Files\MSECache
    2009-02-16 21:33:37 ----D---- C:\Program Files\eMule
    2009-02-16 19:01:31 ----D---- C:\Program Files\Jewel Quest
    2009-02-14 17:03:56 ----D---- C:\Documents and Settings\All Users\Application Data\Bluetooth
    2009-02-13 03:01:25 ----D---- C:\WINDOWS\system32\CatRoot
    2009-02-12 09:27:15 ----D---- C:\Program Files\Internet Explorer
    2009-02-11 21:46:42 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-02-11 21:44:53 ----HD---- C:\Program Files\InstallShield Installation Information
    2009-02-11 11:05:48 ----D---- C:\Program Files\World of Warcraft
    2009-02-11 09:52:43 ----D---- C:\Program Files\Avanquest update
    2009-02-11 09:03:08 ----SHD---- C:\System Volume Information
    2009-02-11 09:03:08 ----D---- C:\WINDOWS\system32\Restore
    2009-02-10 19:28:16 ----A---- C:\WINDOWS\pex.INI
    2009-02-09 17:17:54 ----A---- C:\AILog.txt
    2009-02-04 00:21:12 ----A---- C:\WINDOWS\system32\MRT.exe
    2009-02-01 11:32:21 ----D---- C:\Nostale(FR)
    2009-01-31 13:21:29 ----D---- C:\WINDOWS\Minidump
    2009-01-29 19:25:52 ----D---- C:\Program Files\Microsoft Games

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AmdK7;Pilote de processeur AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41856]
    R1 AvgArCln;Avg Anti-Rootkit Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgArCln.sys [2007-01-18 3968]
    R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-10-24 53256]
    R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-10-24 54280]
    R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys []
    R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
    R1 SiSkp;SiSkp; C:\WINDOWS\system32\DRIVERS\srvkp.sys [2004-07-17 12160]
    R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2008-09-12 5632]
    R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-09-06 20747]
    R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-10-24 39944]
    R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-10-24 73224]
    R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-12-12 391424]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-06-15 626220]
    R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
    R3 BrScnUsb;Brother USB Still Image driver; C:\WINDOWS\System32\Drivers\BrScnUsb.sys [2004-10-15 15295]
    R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-10-24 31240]
    R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2003-11-12 41984]
    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
    R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    R3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2003-09-10 21060]
    R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2005-01-31 22016]
    R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
    R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-07-01 2459840]
    R3 Pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 10368]
    R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
    R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S3 a1gci1mz;a1gci1mz; C:\WINDOWS\system32\drivers\a1gci1mz.sys []
    S3 ASPI;Advanced SCSI Programming Interface Driver; \??\C:\WINDOWS\System32\DRIVERS\ASPI32.sys []
    S3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys []
    S3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys []
    S3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys []
    S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys []
    S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
    S3 C-Dilla;C-Dilla; \??\C:\WINDOWS\system32\drivers\CDANT.SYS []
    S3 EL90XBC;Pilote de la carte EtherLink XL 90XB/C 3Com; C:\WINDOWS\system32\DRIVERS\el90xbc5.sys [2001-08-18 66591]
    S3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-08-03 730653]
    S3 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
    S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\4DA0.tmp []
    S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
    S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
    S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
    S3 nocashio;nocashio; C:\WINDOWS\system32\drivers\nocashio.sys [2007-12-28 4096]
    S3 PID_0928;Logitech QuickCam Express(PID_0928); C:\WINDOWS\system32\DRIVERS\LV561AV.SYS [2005-01-31 211712]
    S3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2002-07-29 23808]
    S3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
    S3 RT73;Belkin USB Network Adapter; C:\WINDOWS\system32\DRIVERS\rt73.sys [2005-08-02 232192]
    S3 s616bus;Sony Ericsson Device 616 driver (WDM); C:\WINDOWS\system32\DRIVERS\s616bus.sys [2007-04-03 83208]
    S3 s616mdfl;Sony Ericsson Device 616 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s616mdfl.sys [2007-04-03 15112]
    S3 s616mdm;Sony Ericsson Device 616 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s616mdm.sys [2007-04-03 108680]
    S3 s616mgmt;Sony Ericsson Device 616 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s616mgmt.sys [2007-04-03 100360]
    S3 s616nd5;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (NDIS); C:\WINDOWS\system32\DRIVERS\s616nd5.sys [2007-04-03 23176]
    S3 s616obex;Sony Ericsson Device 616 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s616obex.sys [2007-04-03 98568]
    S3 s616unic;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (WDM); C:\WINDOWS\system32\DRIVERS\s616unic.sys [2007-04-03 99080]
    S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\WINDOWS\system32\DRIVERS\s916bus.sys [2007-11-02 83496]
    S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s916mdfl.sys [2007-11-02 15016]
    S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s916mdm.sys [2007-11-02 109992]
    S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s916mgmt.sys [2007-11-02 103976]
    S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s916obex.sys [2007-11-02 100008]
    S3 SiS315;SiS315; C:\WINDOWS\system32\DRIVERS\sisgrp.sys [2004-07-19 218112]
    S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
    S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2005-12-22 80272]
    S3 sscdmdfl;SAMSUNG CDMA Modem Filter; C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2005-12-22 10864]
    S3 sscdmdm;SAMSUNG CDMA Modem Drivers; C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2005-12-22 137884]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
    S3 USB_RNDIS;Thomson ST Remote NDIS Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
    S3 usbbus;LGE Mobile Composite USB Device; C:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2007-07-11 12416]
    S3 UsbDiag;LGE Mobile USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys [2007-07-11 19840]
    S3 USBIO;USBIO Driver (usbio.sys); C:\WINDOWS\System32\Drivers\usbio.sys [2001-05-07 19805]
    S3 USBModem;LGE Mobile USB Modem; C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2007-07-11 21632]
    S3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
    S3 UsbSagCom;Mobile Device Full USB Driver; C:\WINDOWS\system32\DRIVERS\UsbSagCom.sys [2007-06-29 51712]
    S3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys []
    S3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys []
    S3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2004-05-05 142976]
    S3 w200bus;Sony Ericsson W200 driver (WDM); C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 61504]
    S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 9328]
    S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 97056]
    S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 88560]
    S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 86368]
    S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
    S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
    S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-14 5504]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2009-02-22 611664]
    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
    R2 Belkin Wireless USB Network Adapter Service;Belkin Wireless USB Network Adapter; C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe [2004-03-29 49152]
    R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
    R2 Brother XP spl Service;BrSplService; C:\WINDOWS\system32\brsvc01a.exe [2002-04-11 57344]
    R2 C-DillaSrv;C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2001-09-10 32256]
    R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2004-07-01 114755]
    R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920]
    R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
    R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
    R3 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe [2008-01-22 275752]
    R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
    S2 .EsetTrialReset;Eset Trial Reset; C:\WINDOWS\system32\regedt32.exe [2004-08-04 3584]
    S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
    S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-10-24 19200]
    S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268800]
    S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-10-01 138168]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
    S3 MSCSPTISRV;MSCSPTISRV; C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe [2006-12-14 45056]
    S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2008-04-08 800040]
    S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe [2006-12-14 57344]
    S3 SonicStage Back-End Service;SonicStage Back-End Service; C:\Program Files\Fichiers communs\Sony Shared\AVLib\SsBeSvc.exe [2007-02-05 112184]
    S3 SPTISRV;Sony SPTI Service; C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe [2006-12-14 69632]
    S3 SSScsiSV;SonicStage SCSI Service; C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe [2007-02-05 75320]
    S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
    S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
    S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]

    -----------------EOF-----------------
    voili voilou! un gros gros merci :) 
    a b 8 Sécurité
    28 Février 2009 15:27:45

    Encore des soucis ?
    28 Février 2009 17:18:03

    il est toujours là. :fou: 
    a b 8 Sécurité
    28 Février 2009 17:20:06

    Tu m'as toujours pas donner l'emplacement...
    28 Février 2009 17:25:59

    milles escuses, je croyais l'avoir fait
    je crois que c'est C:\WINDOWS\system32\BrWebIn.dll
    il y a aussi écrit
    Win32/rootkit.podhuna.NBPtrojan
    encore milles escuses je croyais avoir donné ces renseignements
    a b 8 Sécurité
    28 Février 2009 17:42:15

    Tu as essayé de supprimer manuellement le fichier ?
    28 Février 2009 18:23:01

    en fait j'y ai pensé mais j'ai eu peur, car je ne suis pas calée en informatique et l'endroit je pensais qu'il y avait un risque mais si tu me dis que je peux alors je le fais.
    a b 8 Sécurité
    28 Février 2009 18:24:32

    Oui, fais-le ;) 
    28 Février 2009 18:32:14

    j'ai essayé mais j'ai un message
    accès refusé vérifiez que le disque n'est pas plain ou protégé en écriture et que le fichier n'est utilisé actuellement. Dois je essayer en mode sans echec?
    a b 8 Sécurité
    28 Février 2009 19:48:43

    Même en mode sans échec ?
    28 Février 2009 19:53:17

    C'était une question. Je vais essayer tout de suite
    28 Février 2009 20:06:03

    même en mode sans échec j'ai le message!!!!!je ne sais pas ce que j'ai attr&ppé sur mon ordi mais c'est dur dur!!!!
    a b 8 Sécurité
    28 Février 2009 20:13:37

    Refais un script OTMI alors :

    :processes
    explorer.exe

    :files
    C:\WINDOWS\system32\BrWebIn.dll

    :commands
    [start explorer]
    [reboot]
    28 Février 2009 20:26:44

    il s'accroche méchamment!!!! :fou: 
    28 Février 2009 20:28:13

    escuse moi j'ai oublié de poster le rapport
    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== FILES ==========
    LoadLibrary failed for C:\WINDOWS\system32\BrWebIn.dll
    C:\WINDOWS\system32\BrWebIn.dll NOT unregistered.
    File move failed. C:\WINDOWS\system32\BrWebIn.dll scheduled to be moved on reboot.
    ========== COMMANDS ==========
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02282009_201528

    Files moved on Reboot...
    LoadLibrary failed for C:\WINDOWS\system32\BrWebIn.dll
    C:\WINDOWS\system32\BrWebIn.dll NOT unregistered.
    File move failed. C:\WINDOWS\system32\BrWebIn.dll scheduled to be moved on reboot.
    a b 8 Sécurité
    28 Février 2009 21:09:48

    Toujours là ?
    28 Février 2009 21:12:08

    toujours là le vilain!!!!!!
    a b 8 Sécurité
    28 Février 2009 21:15:54

    Re,

    Télécharge Catchme (Przemyslaw Gmerek) sur ton Bureau.

  • Double clique sur catchme.exe (le .exe n'est pas forcément visible) afin de le lancer.
  • Lorsque la recherche sera terminée, poste le rapport catchme.log dans ta prochaine réponse. (Ce rapport est sur ton bureau.)
    28 Février 2009 21:22:19

    je ne comprends pas tout mais j'ai l'impression que le rootkit n'apparaît pas


    catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
    http://www.gmer.net

    scanning hidden processes ...

    scanning hidden services ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0
    a b 8 Sécurité
    28 Février 2009 21:43:56

    Tu peux analyser ce fichier sur VirusTotal et me poster le rapport ?
    28 Février 2009 21:46:50

    0 bytes size received / Se ha recibido un archivo vacio
    a b 8 Sécurité
    28 Février 2009 21:50:03

    Space comme fichier :x

    Télécharge ComboFix (de sUBs) sur ton Bureau.

  • Désactive temporairement toute protection résidente ! (Antivirus, antispywares..)
  • Double clique sur ComboFix.exe.
  • Accepte la licence en cliquant sur Oui.
  • Le programme va te demander si tu souhaites installer la Console de Récupération. C'est une précaution, au cas où l'ordinateur tomberait en panne. Je te conseille donc de l'installer, ça ne coûte rien, et ça pourrait potentiellement servir !
  • Lorsque l'opération sera terminée, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.

    Le rapport se trouve ici : %SystemDrive%\ComboFix.txt (%systemdrive% étant la partition où est installée Windows; C:\ en général)

    Aide : Comment utiliser ComboFix.
    28 Février 2009 22:21:49

    voilà le rapport, par contre ça ne s'est pas passé tout à fait comme dans l'aide, combofix a fait redémarré mon ordi avant le rapport et de ce fait mes protections se sont réactivitées, j'espère que cela n'erronera pas le rapport



    ComboFix 09-02-28.01 - Compaq_Propriétaire 2009-02-28 22:05:20.1 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1023.551 [GMT 1:00]
    Lancé depuis: c:\documents and settings\Compaq_Propriétaire\Bureau\ComboFix.exe
    AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
    FW: ESET Personal firewall *disabled*
    * Un nouveau point de restauration a été créé
    .
    ADS - system32: deleted 1134383 bytes in 1 streams.
    ADS - WINDOWS: deleted 24 bytes in 1 streams.

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
    c:\documents and settings\Compaq_Propriétaire\Cookies\gogovoj._sy
    c:\documents and settings\Compaq_Propriétaire\Cookies\osorugecy.sys
    c:\documents and settings\LocalService\Application Data\sysproc64
    c:\documents and settings\LocalService\Application Data\sysproc64\sysproc32.sys
    c:\documents and settings\NetworkService\Application Data\sysproc64
    c:\documents and settings\NetworkService\Application Data\sysproc64\sysproc32.sys
    c:\program files\XPSecurityCenter
    c:\program files\XPSecurityCenter\comp.dat
    c:\program files\XPSecurityCenter\data\daily.cvd
    c:\program files\XPSecurityCenter\htmlayout.dll
    c:\program files\XPSecurityCenter\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
    c:\program files\XPSecurityCenter\Microsoft.VC80.CRT\msvcm80.dll
    c:\program files\XPSecurityCenter\Microsoft.VC80.CRT\msvcp80.dll
    c:\program files\XPSecurityCenter\Microsoft.VC80.CRT\msvcr80.dll
    c:\program files\XPSecurityCenter\pthreadVC2.dll
    c:\program files\XPSecurityCenter\un.ico
    c:\program files\XPSecurityCenter\unzip32.dll
    c:\windows\system32\DelSelf.bat
    c:\windows\system32\sysproc64
    c:\windows\system32\sysproc64\00017068.uf
    c:\windows\system32\sysproc64\sysproc32.sys
    c:\windows\system32\sysproc64\sysproc86.sys
    c:\windows\system32\zip32.dll
    D:\Autorun.inf

    .
    ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_ISODRIVE
    -------\Service_ISODrive


    ((((((((((((((((((((((((((((( Fichiers créés du 2009-01-28 au 2009-02-28 ))))))))))))))))))))))))))))))))))))
    .

    2009-02-26 21:39 . 2009-02-26 21:39 <REP> d-------- C:\_OTMoveIt
    2009-02-24 22:41 . 2009-02-25 15:53 <REP> d-------- c:\program files\Navilog1
    2009-02-24 06:38 . 2009-02-24 06:40 <REP> d-------- C:\Rooter$
    2009-02-24 06:32 . 2009-02-24 06:33 <REP> d-------- C:\rsit
    2009-02-24 06:32 . 2009-02-28 12:46 <REP> d-------- c:\program files\trend micro
    2009-02-22 15:27 . 2009-02-22 15:27 <REP> d-------- c:\program files\Lavasoft
    2009-02-22 15:27 . 2009-02-22 15:27 <REP> d-------- c:\program files\Fichiers communs\Wise Installation Wizard
    2009-02-22 15:27 . 2009-02-22 15:30 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
    2009-02-22 12:54 . 2009-02-22 13:18 4,699,979,776 --a------ C:\Image.iso
    2009-02-22 11:42 . 2009-02-22 11:58 <REP> d-------- c:\documents and settings\Compaq_Propriétaire\Application Data\ImgBurn
    2009-02-22 11:41 . 2009-02-22 11:41 <REP> d-------- c:\program files\ImgBurn
    2009-02-22 11:03 . 2007-01-18 13:00 3,968 --a------ c:\windows\system32\drivers\AvgArCln.sys
    2009-02-19 17:07 . 2009-02-19 17:07 <REP> d-------- c:\program files\Sophos
    2009-02-17 20:33 . 2009-02-28 20:30 <REP> d-------- C:\UT2004Demo
    2009-02-12 03:51 . 2008-12-20 23:47 1,160,192 --a------ c:\windows\system32\SETC76.tmp
    2009-02-12 03:51 . 2008-12-20 23:47 826,368 --a------ c:\windows\system32\SETC74.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 459,264 --a------ c:\windows\system32\SETC7F.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 383,488 --a------ c:\windows\system32\SETC87.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 267,776 --a------ c:\windows\system32\SETC83.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 124,928 --a------ c:\windows\system32\SETC8F.tmp
    2009-02-12 03:51 . 2008-12-20 23:47 105,984 --a------ c:\windows\system32\SETC77.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 63,488 --a------ c:\windows\system32\SETC8C.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 52,224 --a------ c:\windows\system32\SETC7E.tmp
    2009-02-12 03:50 . 2008-12-20 23:46 6,066,688 --a------ c:\windows\system32\SETC85.tmp
    2009-02-11 21:46 . 2009-02-11 21:51 <REP> d--h----- C:\LG3G
    2009-02-11 21:46 . 2009-02-11 21:46 <REP> d-------- c:\documents and settings\Compaq_Propriétaire\Application Data\LG Electronics
    2009-02-11 21:44 . 2009-02-11 21:44 <REP> d-------- c:\program files\LG Electronics
    2009-02-11 21:44 . 2007-07-11 10:45 21,632 --a------ c:\windows\system32\drivers\lgusbmodem.sys
    2009-02-11 21:44 . 2007-07-11 15:51 19,840 --a------ c:\windows\system32\drivers\lgusbdiag.sys
    2009-02-11 21:44 . 2007-07-11 10:40 12,416 --a------ c:\windows\system32\drivers\lgusbbus.sys
    2009-02-11 21:43 . 2009-02-11 21:44 <REP> d-------- c:\program files\LG PC Suite 2
    2009-02-08 11:30 . 2002-10-31 00:09 96,256 --a------ c:\windows\system32\BrWebIn.dll

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-02-28 21:11 --------- d-----w c:\documents and settings\Compaq_Propriétaire\Application Data\OpenOffice.org2
    2009-02-28 17:54 --------- d-----w c:\documents and settings\Compaq_Propriétaire\Application Data\LimeWire
    2009-02-27 18:25 --------- d-----w c:\program files\ESET
    2009-02-18 09:05 --------- d-----w c:\program files\MSECache
    2009-02-16 20:33 --------- d-----w c:\program files\eMule
    2009-02-16 18:01 --------- d-----w c:\program files\Jewel Quest
    2009-02-14 16:03 --------- d-----w c:\documents and settings\All Users\Application Data\Bluetooth
    2009-02-11 20:44 --------- d--h--w c:\program files\InstallShield Installation Information
    2009-02-11 10:05 --------- d-----w c:\program files\World of Warcraft
    2009-02-11 08:52 --------- d-----w c:\program files\Avanquest update
    2009-01-29 18:25 --------- d-----w c:\program files\Microsoft Games
    2009-01-27 07:01 98,304 ----a-w c:\windows\DUMP57b5.tmp
    2009-01-27 04:41 98,304 ----a-w c:\windows\DUMP5544.tmp
    2009-01-27 02:20 98,304 ----a-w c:\windows\DUMP54b7.tmp
    2009-01-27 01:36 98,304 ----a-w c:\windows\DUMP52d3.tmp
    2009-01-27 01:34 98,304 ----a-w c:\windows\DUMP5217.tmp
    2009-01-27 01:33 98,304 ----a-w c:\windows\DUMP5350.tmp
    2009-01-27 01:31 98,304 ----a-w c:\windows\DUMP5330.tmp
    2009-01-27 01:30 98,304 ----a-w c:\windows\DUMP52e2.tmp
    2009-01-27 01:29 98,304 ----a-w c:\windows\DUMP5296.tmp
    2009-01-27 01:27 98,304 ----a-w c:\windows\DUMP53ec.tmp
    2009-01-27 01:26 98,304 ----a-w c:\windows\DUMP5229.tmp
    2009-01-27 01:24 98,304 ----a-w c:\windows\DUMP5257.tmp
    2009-01-27 01:23 98,304 ----a-w c:\windows\DUMP52b4.tmp
    2009-01-27 01:21 98,304 ----a-w c:\windows\DUMP5340.tmp
    2009-01-27 01:20 98,304 ----a-w c:\windows\DUMP5295.tmp
    2009-01-27 01:19 98,304 ----a-w c:\windows\DUMP5294.tmp
    2009-01-27 01:18 98,304 ----a-w c:\windows\DUMP5321.tmp
    2009-01-27 01:16 98,304 ----a-w c:\windows\DUMP53dd.tmp
    2009-01-26 22:58 98,304 ----a-w c:\windows\DUMP5256.tmp
    2009-01-26 22:57 98,304 ----a-w c:\windows\DUMP5248.tmp
    2009-01-26 22:56 98,304 ----a-w c:\windows\DUMP53dc.tmp
    2009-01-26 22:54 98,304 ----a-w c:\windows\DUMP5287.tmp
    2009-01-26 22:53 98,304 ----a-w c:\windows\DUMP52c4.tmp
    2009-01-26 22:52 98,304 ----a-w c:\windows\DUMP52b3.tmp
    2009-01-26 22:50 98,304 ----a-w c:\windows\DUMP52f2.tmp
    2009-01-26 22:49 98,304 ----a-w c:\windows\DUMP5236.tmp
    2009-01-26 22:48 98,304 ----a-w c:\windows\DUMP51c9.tmp
    2009-01-26 22:46 98,304 ----a-w c:\windows\DUMP52a6.tmp
    2009-01-26 22:45 98,304 ----a-w c:\windows\DUMP53cd.tmp
    2009-01-26 22:44 98,304 ----a-w c:\windows\DUMP51da.tmp
    2009-01-26 22:42 98,304 ----a-w c:\windows\DUMP52a5.tmp
    2009-01-26 22:41 98,304 ----a-w c:\windows\DUMP516b.tmp
    2009-01-26 22:40 98,304 ----a-w c:\windows\DUMP5247.tmp
    2009-01-26 22:39 98,304 ----a-w c:\windows\DUMP5277.tmp
    2009-01-26 22:37 98,304 ----a-w c:\windows\DUMP5246.tmp
    2009-01-26 22:36 98,304 ----a-w c:\windows\DUMP5276.tmp
    2009-01-26 22:34 98,304 ----a-w c:\windows\DUMP5275.tmp
    2009-01-26 22:33 98,304 ----a-w c:\windows\DUMP51d9.tmp
    2009-01-26 22:32 98,304 ----a-w c:\windows\DUMP5228.tmp
    2009-01-26 22:30 98,304 ----a-w c:\windows\DUMP51b9.tmp
    2009-01-26 22:29 98,304 ----a-w c:\windows\DUMP53ad.tmp
    2009-01-26 22:28 98,304 ----a-w c:\windows\DUMP52a4.tmp
    2009-01-26 22:26 98,304 ----a-w c:\windows\DUMP51e8.tmp
    2009-01-26 22:25 98,304 ----a-w c:\windows\DUMP5265.tmp
    2009-01-26 22:24 98,304 ----a-w c:\windows\DUMP5303.tmp
    2009-01-26 22:22 98,304 ----a-w c:\windows\DUMP5286.tmp
    2009-01-26 22:20 98,304 ----a-w c:\windows\DUMP5208.tmp
    2009-01-26 22:19 98,304 ----a-w c:\windows\DUMP5227.tmp
    2009-01-26 22:17 98,304 ----a-w c:\windows\DUMP5302.tmp
    2009-01-26 22:16 98,304 ----a-w c:\windows\DUMP52c3.tmp
    2009-01-26 22:14 98,304 ----a-w c:\windows\DUMP5285.tmp
    2009-01-26 19:48 --------- d-----w c:\program files\KeyChain Photo Manager
    2009-01-18 16:20 --------- d-----w c:\program files\CDex_150
    2009-01-16 07:03 --------- d-----w c:\documents and settings\Compaq_Propriétaire\Application Data\kibisoft
    2009-01-16 06:03 --------- d-----w c:\program files\Kibisoft
    2009-01-15 21:03 --------- d-----w c:\program files\Pochette Express 2
    2009-01-11 20:26 0 ---ha-w c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
    2009-01-11 20:25 --------- d-----w c:\program files\MP3 Player Utilities 4.21
    2009-01-07 18:47 --------- d-----w c:\program files\AGI
    2008-12-31 09:57 --------- d-----w c:\program files\Fichiers communs\Ahead
    2008-12-31 09:54 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
    2008-12-21 16:33 81,920 ------r c:\windows\bwUnin-6.1.4.68-8876480L.exe
    2008-12-06 23:02 49,206 ----a-w c:\program files\KeyChain Photo ManagerTmpBitmap.bmp
    2008-11-06 16:55 270 ----a-w c:\documents and settings\Compaq_Propriétaire\Application Data\avp.bat
    2008-11-06 16:54 1,697,280 ----a-w c:\documents and settings\Compaq_Propriétaire\Application Data\winexpl.exe
    2008-09-11 05:55 19,603 ----a-w c:\program files\Fichiers communs\qyky._sy
    2008-09-11 05:55 17,687 ----a-w c:\program files\Fichiers communs\gamyc._sy
    2008-09-11 05:55 16,444 ----a-w c:\program files\Fichiers communs\copure._dl
    2008-09-11 05:55 14,358 ----a-w c:\documents and settings\All Users\Application Data\riqazy.bat
    2008-09-11 05:55 13,785 ----a-w c:\program files\Fichiers communs\ahihado.db
    2008-09-11 05:55 13,499 ----a-w c:\program files\Fichiers communs\zone.com
    2008-08-19 14:50 0 ----a-w c:\program files\temp01
    2008-09-22 15:44 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008092220080923\index.dat
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BD4A40D-8DFC-4F9F-B288-011490D5FCD1}]
    2002-10-31 00:09 96256 --a------ c:\windows\system32\BrWebIn.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-07 68856]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-10 397312]
    "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
    "LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-12-21 20480]
    "LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-01-18 196608]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
    "System"="explorer.exe" [2008-04-14 c:\windows\explorer.exe]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-01 4112384]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
    "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-02-06 177472]
    "LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
    "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-01-18 458752]
    "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-01-18 217088]
    "NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
    "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-10-24 1451264]

    c:\documents and settings\cindy\Menu D‚marrer\Programmes\D‚marrage\
    OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 393216]

    c:\documents and settings\Compaq_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
    OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 393216]

    c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    Contr“leur d'‚tat.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2007-09-02 802816]
    Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-12-21 450560]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "ForceClassicControlPanel"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\eMule\\emule.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
    "c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\HomePlayer\\HomePlayer.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "c:\\Program Files\\River Past\\Audio Converter Pro\\AudioConverter.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

    R0 gdjnipcx;gdjnipcx;c:\windows\system32\drivers\gdjnipcx.sys [2007-09-01 23424]
    R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
    S2 .EsetTrialReset;Eset Trial Reset;c:\windows\system32\regedt32.exe [2007-09-01 3584]
    S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2008-02-24 16512]
    S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\4DA0.tmp --> c:\windows\system32\4DA0.tmp [?]
    S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\drivers\s916bus.sys [2008-07-14 83496]
    S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\system32\drivers\s916mdfl.sys [2008-07-14 15016]
    S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\system32\drivers\s916mdm.sys [2008-07-14 109992]
    S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s916mgmt.sys [2008-07-14 103976]
    S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface;c:\windows\system32\drivers\s916obex.sys [2008-07-14 100008]
    S3 UsbSagCom;Mobile Device Full USB Driver;c:\windows\system32\drivers\UsbSagCom.sys [2007-06-29 51712]
    S3 w200bus;Sony Ericsson W200 driver (WDM);c:\windows\system32\drivers\w200bus.sys [2008-01-05 61504]
    S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;c:\windows\system32\drivers\w200mdfl.sys [2008-01-05 9328]
    S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;c:\windows\system32\drivers\w200mdm.sys [2008-01-05 97056]
    S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w200mgmt.sys [2008-01-05 88560]
    S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;c:\windows\system32\drivers\w200obex.sys [2008-01-05 86368]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
    \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
    .
    Contenu du dossier 'Tâches planifiées'

    2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

    2009-02-28 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
    - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    BHO-{f18970dd-8f96-7e99-c7c1-56a16232a2c3} - (no file)


    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.fr/
    uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=presario&pf=desktop
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.google.com
    mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=presario&pf=desktop
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = *.local;localhost
    IE: c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d32c1a7c185643c7bce11ae098e15e13
    IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?d32c1a7c185643c7bce11ae098e15e13
    IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d32c1a7c185643c7bce11ae098e15e13
    DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} - hxxp://www.myheritage.fr/Genoogle/Components/ActiveX/SearchEng...
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-02-28 22:11:43
    Windows 5.1.2600 Service Pack 3 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
    "ImagePath"="\??\c:\windows\system32\4DA0.tmp"
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
    "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\program files\Lavasoft\Ad-Aware\aawservice.exe
    c:\windows\system32\brss01a.exe
    c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Belkin\Belkin Wireless Network Utility\WLService.exe
    c:\program files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\system32\drivers\CDANTSRV.EXE
    c:\windows\system32\nvsvc32.exe
    c:\windows\system32\IoctlSvc.exe
    c:\program files\Logitech\Video\FxSvr2.exe
    c:\program files\OpenOffice.org 2.2\program\soffice.exe
    c:\program files\Brother\Brmfcmon\BrMfcMon.exe
    c:\program files\OpenOffice.org 2.2\program\soffice.bin
    c:\program files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Heure de fin: 2009-02-28 22:16:37 - La machine a redémarré
    ComboFix-quarantined-files.txt 2009-02-28 21:16:31

    Avant-CF: 16 656 740 352 octets libres
    Après-CF: 17,342,504,960 octets libres

    310 --- E O F --- 2009-02-25 02:01:01
    a b 8 Sécurité
    1 Mars 2009 20:43:57

    Il a fait un bon ménage.

    Sélectionne l'intégralité du cadre ci-dessous :

    File::
    c:\windows\system32\BrWebIn.dll

    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BD4A40D-8DFC-4F9F-B288-011490D5FCD1}]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
    "System"=-


  • Copie/colle le dans le Bloc Notes (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
  • Enregistre le sous sur ton bureau sous le nom de CFScript.txt
  • Glisse maintenant le fichier CFScript.txt dans ComboFix.exe comme ci-dessous :

  • Cela va relancer Combofix.
  • Tu devras accepter la licence.

    Poste le contenu du rapport ComboFix.txt après redémarrage s'il y en a un.

    Le rapport se trouve ici : %SystemDrive%\ComboFix.txt (%systemdrive% étant la partition où est installée Windows; C:\ en général)
    2 Mars 2009 07:14:56

    Bonjour,
    C'est fait, mais je n'ai pas réussi à aller sur le lien alors je l'ai glissé comme je le fais d'habitude en tenant le clic gauche appuyer!!je pense que c'est cela.


    ComboFix 09-03-01.01 - Compaq_Propriétaire 2009-03-02 6:53:45.2 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1023.476 [GMT 1:00]
    Lancé depuis: c:\documents and settings\Compaq_Propriétaire\Bureau\ComboFix.exe
    AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
    FW: ESET Personal firewall *disabled*
    * Un nouveau point de restauration a été créé
    .

    ((((((((((((((((((((((((((((( Fichiers créés du 2009-02-02 au 2009-03-02 ))))))))))))))))))))))))))))))))))))
    .

    2009-02-26 21:39 . 2009-02-26 21:39 <REP> d-------- C:\_OTMoveIt
    2009-02-24 22:41 . 2009-02-25 15:53 <REP> d-------- c:\program files\Navilog1
    2009-02-24 06:38 . 2009-02-24 06:40 <REP> d-------- C:\Rooter$
    2009-02-24 06:32 . 2009-02-24 06:33 <REP> d-------- C:\rsit
    2009-02-24 06:32 . 2009-02-28 12:46 <REP> d-------- c:\program files\trend micro
    2009-02-22 15:27 . 2009-02-22 15:27 <REP> d-------- c:\program files\Lavasoft
    2009-02-22 15:27 . 2009-02-22 15:27 <REP> d-------- c:\program files\Fichiers communs\Wise Installation Wizard
    2009-02-22 15:27 . 2009-02-22 15:30 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
    2009-02-22 12:54 . 2009-02-22 13:18 4,699,979,776 --a------ C:\Image.iso
    2009-02-22 11:42 . 2009-02-22 11:58 <REP> d-------- c:\documents and settings\Compaq_Propriétaire\Application Data\ImgBurn
    2009-02-22 11:41 . 2009-02-22 11:41 <REP> d-------- c:\program files\ImgBurn
    2009-02-22 11:03 . 2007-01-18 13:00 3,968 --a------ c:\windows\system32\drivers\AvgArCln.sys
    2009-02-19 17:07 . 2009-02-19 17:07 <REP> d-------- c:\program files\Sophos
    2009-02-17 20:33 . 2009-02-28 20:30 <REP> d-------- C:\UT2004Demo
    2009-02-12 03:51 . 2008-12-20 23:47 1,160,192 --a------ c:\windows\system32\SETC76.tmp
    2009-02-12 03:51 . 2008-12-20 23:47 826,368 --a------ c:\windows\system32\SETC74.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 459,264 --a------ c:\windows\system32\SETC7F.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 383,488 --a------ c:\windows\system32\SETC87.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 267,776 --a------ c:\windows\system32\SETC83.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 124,928 --a------ c:\windows\system32\SETC8F.tmp
    2009-02-12 03:51 . 2008-12-20 23:47 105,984 --a------ c:\windows\system32\SETC77.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 63,488 --a------ c:\windows\system32\SETC8C.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 52,224 --a------ c:\windows\system32\SETC7E.tmp
    2009-02-12 03:50 . 2008-12-20 23:46 6,066,688 --a------ c:\windows\system32\SETC85.tmp
    2009-02-11 21:46 . 2009-02-11 21:51 <REP> d--h----- C:\LG3G
    2009-02-11 21:46 . 2009-02-11 21:46 <REP> d-------- c:\documents and settings\Compaq_Propriétaire\Application Data\LG Electronics
    2009-02-11 21:44 . 2009-02-11 21:44 <REP> d-------- c:\program files\LG Electronics
    2009-02-11 21:44 . 2007-07-11 10:45 21,632 --a------ c:\windows\system32\drivers\lgusbmodem.sys
    2009-02-11 21:44 . 2007-07-11 15:51 19,840 --a------ c:\windows\system32\drivers\lgusbdiag.sys
    2009-02-11 21:44 . 2007-07-11 10:40 12,416 --a------ c:\windows\system32\drivers\lgusbbus.sys
    2009-02-11 21:43 . 2009-02-11 21:44 <REP> d-------- c:\program files\LG PC Suite 2
    2009-02-08 11:30 . 2002-10-31 00:09 96,256 --a------ c:\windows\system32\BrWebIn.dll

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-02-28 21:27 --------- d-----w c:\documents and settings\Compaq_Propriétaire\Application Data\OpenOffice.org2
    2009-02-28 17:54 --------- d-----w c:\documents and settings\Compaq_Propriétaire\Application Data\LimeWire
    2009-02-27 18:25 --------- d-----w c:\program files\ESET
    2009-02-18 09:05 --------- d-----w c:\program files\MSECache
    2009-02-16 20:33 --------- d-----w c:\program files\eMule
    2009-02-16 18:01 --------- d-----w c:\program files\Jewel Quest
    2009-02-14 16:03 --------- d-----w c:\documents and settings\All Users\Application Data\Bluetooth
    2009-02-11 20:44 --------- d--h--w c:\program files\InstallShield Installation Information
    2009-02-11 10:05 --------- d-----w c:\program files\World of Warcraft
    2009-02-11 08:52 --------- d-----w c:\program files\Avanquest update
    2009-01-29 18:25 --------- d-----w c:\program files\Microsoft Games
    2009-01-27 07:01 98,304 ----a-w c:\windows\DUMP57b5.tmp
    2009-01-27 04:41 98,304 ----a-w c:\windows\DUMP5544.tmp
    2009-01-27 02:20 98,304 ----a-w c:\windows\DUMP54b7.tmp
    2009-01-27 01:36 98,304 ----a-w c:\windows\DUMP52d3.tmp
    2009-01-27 01:34 98,304 ----a-w c:\windows\DUMP5217.tmp
    2009-01-27 01:33 98,304 ----a-w c:\windows\DUMP5350.tmp
    2009-01-27 01:31 98,304 ----a-w c:\windows\DUMP5330.tmp
    2009-01-27 01:30 98,304 ----a-w c:\windows\DUMP52e2.tmp
    2009-01-27 01:29 98,304 ----a-w c:\windows\DUMP5296.tmp
    2009-01-27 01:27 98,304 ----a-w c:\windows\DUMP53ec.tmp
    2009-01-27 01:26 98,304 ----a-w c:\windows\DUMP5229.tmp
    2009-01-27 01:24 98,304 ----a-w c:\windows\DUMP5257.tmp
    2009-01-27 01:23 98,304 ----a-w c:\windows\DUMP52b4.tmp
    2009-01-27 01:21 98,304 ----a-w c:\windows\DUMP5340.tmp
    2009-01-27 01:20 98,304 ----a-w c:\windows\DUMP5295.tmp
    2009-01-27 01:19 98,304 ----a-w c:\windows\DUMP5294.tmp
    2009-01-27 01:18 98,304 ----a-w c:\windows\DUMP5321.tmp
    2009-01-27 01:16 98,304 ----a-w c:\windows\DUMP53dd.tmp
    2009-01-26 22:58 98,304 ----a-w c:\windows\DUMP5256.tmp
    2009-01-26 22:57 98,304 ----a-w c:\windows\DUMP5248.tmp
    2009-01-26 22:56 98,304 ----a-w c:\windows\DUMP53dc.tmp
    2009-01-26 22:54 98,304 ----a-w c:\windows\DUMP5287.tmp
    2009-01-26 22:53 98,304 ----a-w c:\windows\DUMP52c4.tmp
    2009-01-26 22:52 98,304 ----a-w c:\windows\DUMP52b3.tmp
    2009-01-26 22:50 98,304 ----a-w c:\windows\DUMP52f2.tmp
    2009-01-26 22:49 98,304 ----a-w c:\windows\DUMP5236.tmp
    2009-01-26 22:48 98,304 ----a-w c:\windows\DUMP51c9.tmp
    2009-01-26 22:46 98,304 ----a-w c:\windows\DUMP52a6.tmp
    2009-01-26 22:45 98,304 ----a-w c:\windows\DUMP53cd.tmp
    2009-01-26 22:44 98,304 ----a-w c:\windows\DUMP51da.tmp
    2009-01-26 22:42 98,304 ----a-w c:\windows\DUMP52a5.tmp
    2009-01-26 22:41 98,304 ----a-w c:\windows\DUMP516b.tmp
    2009-01-26 22:40 98,304 ----a-w c:\windows\DUMP5247.tmp
    2009-01-26 22:39 98,304 ----a-w c:\windows\DUMP5277.tmp
    2009-01-26 22:37 98,304 ----a-w c:\windows\DUMP5246.tmp
    2009-01-26 22:36 98,304 ----a-w c:\windows\DUMP5276.tmp
    2009-01-26 22:34 98,304 ----a-w c:\windows\DUMP5275.tmp
    2009-01-26 22:33 98,304 ----a-w c:\windows\DUMP51d9.tmp
    2009-01-26 22:32 98,304 ----a-w c:\windows\DUMP5228.tmp
    2009-01-26 22:30 98,304 ----a-w c:\windows\DUMP51b9.tmp
    2009-01-26 22:29 98,304 ----a-w c:\windows\DUMP53ad.tmp
    2009-01-26 22:28 98,304 ----a-w c:\windows\DUMP52a4.tmp
    2009-01-26 22:26 98,304 ----a-w c:\windows\DUMP51e8.tmp
    2009-01-26 22:25 98,304 ----a-w c:\windows\DUMP5265.tmp
    2009-01-26 22:24 98,304 ----a-w c:\windows\DUMP5303.tmp
    2009-01-26 22:22 98,304 ----a-w c:\windows\DUMP5286.tmp
    2009-01-26 22:20 98,304 ----a-w c:\windows\DUMP5208.tmp
    2009-01-26 22:19 98,304 ----a-w c:\windows\DUMP5227.tmp
    2009-01-26 22:17 98,304 ----a-w c:\windows\DUMP5302.tmp
    2009-01-26 22:16 98,304 ----a-w c:\windows\DUMP52c3.tmp
    2009-01-26 22:14 98,304 ----a-w c:\windows\DUMP5285.tmp
    2009-01-26 19:48 --------- d-----w c:\program files\KeyChain Photo Manager
    2009-01-18 16:20 --------- d-----w c:\program files\CDex_150
    2009-01-16 20:15 3,594,752 ----a-w c:\windows\system32\SETC7D.tmp
    2009-01-16 07:03 --------- d-----w c:\documents and settings\Compaq_Propriétaire\Application Data\kibisoft
    2009-01-16 06:03 --------- d-----w c:\program files\Kibisoft
    2009-01-15 21:03 --------- d-----w c:\program files\Pochette Express 2
    2009-01-11 20:26 0 ---ha-w c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
    2009-01-11 20:25 --------- d-----w c:\program files\MP3 Player Utilities 4.21
    2009-01-07 18:47 339,968 ----a-w c:\windows\system32\pythoncom25.dll
    2009-01-07 18:47 2,117,632 ----a-w c:\windows\system32\python25.dll
    2009-01-07 18:47 114,688 ----a-w c:\windows\system32\pywintypes25.dll
    2009-01-07 18:47 --------- d-----w c:\program files\AGI
    2008-12-21 16:33 81,920 ------r c:\windows\bwUnin-6.1.4.68-8876480L.exe
    2008-12-20 22:47 826,368 ----a-w c:\windows\system32\wininet.dll
    2008-12-12 10:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
    2008-12-12 10:11 61,440 ----a-w c:\windows\system32\dnssd.dll
    2008-12-06 23:02 49,206 ----a-w c:\program files\KeyChain Photo ManagerTmpBitmap.bmp
    2008-11-06 16:55 270 ----a-w c:\documents and settings\Compaq_Propriétaire\Application Data\avp.bat
    2008-11-06 16:54 1,697,280 ----a-w c:\documents and settings\Compaq_Propriétaire\Application Data\winexpl.exe
    2008-09-11 05:55 19,603 ----a-w c:\program files\Fichiers communs\qyky._sy
    2008-09-11 05:55 17,687 ----a-w c:\program files\Fichiers communs\gamyc._sy
    2008-09-11 05:55 16,444 ----a-w c:\program files\Fichiers communs\copure._dl
    2008-09-11 05:55 14,358 ----a-w c:\documents and settings\All Users\Application Data\riqazy.bat
    2008-09-11 05:55 13,785 ----a-w c:\program files\Fichiers communs\ahihado.db
    2008-09-11 05:55 13,499 ----a-w c:\program files\Fichiers communs\zone.com
    2008-08-19 14:50 0 ----a-w c:\program files\temp01
    2008-09-22 15:44 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008092220080923\index.dat
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BD4A40D-8DFC-4F9F-B288-011490D5FCD1}]
    2002-10-31 00:09 96256 --a------ c:\windows\system32\BrWebIn.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-07 68856]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-10 397312]
    "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
    "LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-12-21 20480]
    "LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-01-18 196608]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
    "System"="explorer.exe" [2008-04-14 c:\windows\explorer.exe]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-01 4112384]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
    "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-02-06 177472]
    "LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
    "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-01-18 458752]
    "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-01-18 217088]
    "NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
    "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-10-24 1451264]

    c:\documents and settings\cindy\Menu D‚marrer\Programmes\D‚marrage\
    OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 393216]

    c:\documents and settings\Compaq_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
    OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 393216]

    c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    Contr“leur d'‚tat.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2007-09-02 802816]
    Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-12-21 450560]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "ForceClassicControlPanel"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\eMule\\emule.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
    "c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\HomePlayer\\HomePlayer.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "c:\\Program Files\\River Past\\Audio Converter Pro\\AudioConverter.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

    R0 gdjnipcx;gdjnipcx;c:\windows\system32\drivers\gdjnipcx.sys [2007-09-01 23424]
    R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
    S2 .EsetTrialReset;Eset Trial Reset;c:\windows\system32\regedt32.exe [2007-09-01 3584]
    S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2008-02-24 16512]
    S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\4DA0.tmp --> c:\windows\system32\4DA0.tmp [?]
    S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\drivers\s916bus.sys [2008-07-14 83496]
    S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\system32\drivers\s916mdfl.sys [2008-07-14 15016]
    S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\system32\drivers\s916mdm.sys [2008-07-14 109992]
    S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s916mgmt.sys [2008-07-14 103976]
    S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface;c:\windows\system32\drivers\s916obex.sys [2008-07-14 100008]
    S3 UsbSagCom;Mobile Device Full USB Driver;c:\windows\system32\drivers\UsbSagCom.sys [2007-06-29 51712]
    S3 w200bus;Sony Ericsson W200 driver (WDM);c:\windows\system32\drivers\w200bus.sys [2008-01-05 61504]
    S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;c:\windows\system32\drivers\w200mdfl.sys [2008-01-05 9328]
    S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;c:\windows\system32\drivers\w200mdm.sys [2008-01-05 97056]
    S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w200mgmt.sys [2008-01-05 88560]
    S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;c:\windows\system32\drivers\w200obex.sys [2008-01-05 86368]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
    \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
    .
    Contenu du dossier 'Tâches planifiées'

    2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

    2009-03-02 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
    - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.fr/
    uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=presario&pf=desktop
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.google.com
    mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=presario&pf=desktop
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = *.local;localhost
    IE: c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d32c1a7c185643c7bce11ae098e15e13
    IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?d32c1a7c185643c7bce11ae098e15e13
    IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d32c1a7c185643c7bce11ae098e15e13
    DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} - hxxp://www.myheritage.fr/Genoogle/Components/ActiveX/SearchEng...
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-02 06:57:32
    Windows 5.1.2600 Service Pack 3 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
    "ImagePath"="\??\c:\windows\system32\4DA0.tmp"
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
    "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
    .
    Heure de fin: 2009-03-02 6:59:39
    ComboFix-quarantined-files.txt 2009-03-02 05:59:25
    ComboFix2.txt 2009-02-28 21:16:39

    Avant-CF: 40 653 647 872 octets libres
    Après-CF: 40,736,935,936 octets libres

    259 --- E O F --- 2009-02-25 02:01:01
    a b 8 Sécurité
    2 Mars 2009 17:11:52

    Yep faut que je change le lien.

    Citation :
    Lancé depuis: c:\documents and settings\Compaq_Propriétaire\Bureau\ComboFix.exe

    Tu as bien glissé le fichier texte dans Combofix ?
    2 Mars 2009 19:07:53

    oui mais ça a cacafouillé, j'ai fermé sans faire exprès et je l'ai relancé avec double clic je re commence l'opération
    a b 8 Sécurité
    2 Mars 2009 19:26:34

    Ok ;) 
    2 Mars 2009 19:27:10

    voilà j'ai recommencé

    ComboFix 09-03-01.01 - Compaq_Propriétaire 2009-03-02 19:12:03.3 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1023.511 [GMT 1:00]
    Lancé depuis: c:\documents and settings\Compaq_Propriétaire\Bureau\ComboFix.exe
    Commutateurs utilisés :: c:\documents and settings\Compaq_Propriétaire\Bureau\CFScript.txt
    AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
    FW: ESET Personal firewall *disabled*
    * Un nouveau point de restauration a été créé

    FILE ::
    c:\windows\system32\BrWebIn.dll
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\BrWebIn.dll . . . . impossible à supprimer

    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2009-02-02 au 2009-03-02 ))))))))))))))))))))))))))))))))))))
    .

    2009-02-26 21:39 . 2009-02-26 21:39 <REP> d-------- C:\_OTMoveIt
    2009-02-24 22:41 . 2009-02-25 15:53 <REP> d-------- c:\program files\Navilog1
    2009-02-24 06:38 . 2009-02-24 06:40 <REP> d-------- C:\Rooter$
    2009-02-24 06:32 . 2009-02-24 06:33 <REP> d-------- C:\rsit
    2009-02-24 06:32 . 2009-02-28 12:46 <REP> d-------- c:\program files\trend micro
    2009-02-22 15:27 . 2009-02-22 15:27 <REP> d-------- c:\program files\Lavasoft
    2009-02-22 15:27 . 2009-02-22 15:27 <REP> d-------- c:\program files\Fichiers communs\Wise Installation Wizard
    2009-02-22 15:27 . 2009-02-22 15:30 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
    2009-02-22 12:54 . 2009-02-22 13:18 4,699,979,776 --a------ C:\Image.iso
    2009-02-22 11:42 . 2009-02-22 11:58 <REP> d-------- c:\documents and settings\Compaq_Propriétaire\Application Data\ImgBurn
    2009-02-22 11:41 . 2009-02-22 11:41 <REP> d-------- c:\program files\ImgBurn
    2009-02-22 11:03 . 2007-01-18 13:00 3,968 --a------ c:\windows\system32\drivers\AvgArCln.sys
    2009-02-19 17:07 . 2009-02-19 17:07 <REP> d-------- c:\program files\Sophos
    2009-02-17 20:33 . 2009-02-28 20:30 <REP> d-------- C:\UT2004Demo
    2009-02-12 03:51 . 2008-12-20 23:47 1,160,192 --a------ c:\windows\system32\SETC76.tmp
    2009-02-12 03:51 . 2008-12-20 23:47 826,368 --a------ c:\windows\system32\SETC74.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 459,264 --a------ c:\windows\system32\SETC7F.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 383,488 --a------ c:\windows\system32\SETC87.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 267,776 --a------ c:\windows\system32\SETC83.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 124,928 --a------ c:\windows\system32\SETC8F.tmp
    2009-02-12 03:51 . 2008-12-20 23:47 105,984 --a------ c:\windows\system32\SETC77.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 63,488 --a------ c:\windows\system32\SETC8C.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 52,224 --a------ c:\windows\system32\SETC7E.tmp
    2009-02-12 03:50 . 2008-12-20 23:46 6,066,688 --a------ c:\windows\system32\SETC85.tmp
    2009-02-11 21:46 . 2009-02-11 21:51 <REP> d--h----- C:\LG3G
    2009-02-11 21:46 . 2009-02-11 21:46 <REP> d-------- c:\documents and settings\Compaq_Propriétaire\Application Data\LG Electronics
    2009-02-11 21:44 . 2009-02-11 21:44 <REP> d-------- c:\program files\LG Electronics
    2009-02-11 21:44 . 2007-07-11 10:45 21,632 --a------ c:\windows\system32\drivers\lgusbmodem.sys
    2009-02-11 21:44 . 2007-07-11 15:51 19,840 --a------ c:\windows\system32\drivers\lgusbdiag.sys
    2009-02-11 21:44 . 2007-07-11 10:40 12,416 --a------ c:\windows\system32\drivers\lgusbbus.sys
    2009-02-11 21:43 . 2009-02-11 21:44 <REP> d-------- c:\program files\LG PC Suite 2
    2009-02-08 11:30 . 2002-10-31 00:09 96,256 --a------ c:\windows\system32\BrWebIn.dll

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-03-02 18:19 --------- d-----w c:\documents and settings\Compaq_Propriétaire\Application Data\OpenOffice.org2
    2009-02-28 17:54 --------- d-----w c:\documents and settings\Compaq_Propriétaire\Application Data\LimeWire
    2009-02-27 18:25 --------- d-----w c:\program files\ESET
    2009-02-18 09:05 --------- d-----w c:\program files\MSECache
    2009-02-16 20:33 --------- d-----w c:\program files\eMule
    2009-02-16 18:01 --------- d-----w c:\program files\Jewel Quest
    2009-02-14 16:03 --------- d-----w c:\documents and settings\All Users\Application Data\Bluetooth
    2009-02-11 20:44 --------- d--h--w c:\program files\InstallShield Installation Information
    2009-02-11 10:05 --------- d-----w c:\program files\World of Warcraft
    2009-02-11 08:52 --------- d-----w c:\program files\Avanquest update
    2009-01-29 18:25 --------- d-----w c:\program files\Microsoft Games
    2009-01-27 07:01 98,304 ----a-w c:\windows\DUMP57b5.tmp
    2009-01-27 04:41 98,304 ----a-w c:\windows\DUMP5544.tmp
    2009-01-27 02:20 98,304 ----a-w c:\windows\DUMP54b7.tmp
    2009-01-27 01:36 98,304 ----a-w c:\windows\DUMP52d3.tmp
    2009-01-27 01:34 98,304 ----a-w c:\windows\DUMP5217.tmp
    2009-01-27 01:33 98,304 ----a-w c:\windows\DUMP5350.tmp
    2009-01-27 01:31 98,304 ----a-w c:\windows\DUMP5330.tmp
    2009-01-27 01:30 98,304 ----a-w c:\windows\DUMP52e2.tmp
    2009-01-27 01:29 98,304 ----a-w c:\windows\DUMP5296.tmp
    2009-01-27 01:27 98,304 ----a-w c:\windows\DUMP53ec.tmp
    2009-01-27 01:26 98,304 ----a-w c:\windows\DUMP5229.tmp
    2009-01-27 01:24 98,304 ----a-w c:\windows\DUMP5257.tmp
    2009-01-27 01:23 98,304 ----a-w c:\windows\DUMP52b4.tmp
    2009-01-27 01:21 98,304 ----a-w c:\windows\DUMP5340.tmp
    2009-01-27 01:20 98,304 ----a-w c:\windows\DUMP5295.tmp
    2009-01-27 01:19 98,304 ----a-w c:\windows\DUMP5294.tmp
    2009-01-27 01:18 98,304 ----a-w c:\windows\DUMP5321.tmp
    2009-01-27 01:16 98,304 ----a-w c:\windows\DUMP53dd.tmp
    2009-01-26 22:58 98,304 ----a-w c:\windows\DUMP5256.tmp
    2009-01-26 22:57 98,304 ----a-w c:\windows\DUMP5248.tmp
    2009-01-26 22:56 98,304 ----a-w c:\windows\DUMP53dc.tmp
    2009-01-26 22:54 98,304 ----a-w c:\windows\DUMP5287.tmp
    2009-01-26 22:53 98,304 ----a-w c:\windows\DUMP52c4.tmp
    2009-01-26 22:52 98,304 ----a-w c:\windows\DUMP52b3.tmp
    2009-01-26 22:50 98,304 ----a-w c:\windows\DUMP52f2.tmp
    2009-01-26 22:49 98,304 ----a-w c:\windows\DUMP5236.tmp
    2009-01-26 22:48 98,304 ----a-w c:\windows\DUMP51c9.tmp
    2009-01-26 22:46 98,304 ----a-w c:\windows\DUMP52a6.tmp
    2009-01-26 22:45 98,304 ----a-w c:\windows\DUMP53cd.tmp
    2009-01-26 22:44 98,304 ----a-w c:\windows\DUMP51da.tmp
    2009-01-26 22:42 98,304 ----a-w c:\windows\DUMP52a5.tmp
    2009-01-26 22:41 98,304 ----a-w c:\windows\DUMP516b.tmp
    2009-01-26 22:40 98,304 ----a-w c:\windows\DUMP5247.tmp
    2009-01-26 22:39 98,304 ----a-w c:\windows\DUMP5277.tmp
    2009-01-26 22:37 98,304 ----a-w c:\windows\DUMP5246.tmp
    2009-01-26 22:36 98,304 ----a-w c:\windows\DUMP5276.tmp
    2009-01-26 22:34 98,304 ----a-w c:\windows\DUMP5275.tmp
    2009-01-26 22:33 98,304 ----a-w c:\windows\DUMP51d9.tmp
    2009-01-26 22:32 98,304 ----a-w c:\windows\DUMP5228.tmp
    2009-01-26 22:30 98,304 ----a-w c:\windows\DUMP51b9.tmp
    2009-01-26 22:29 98,304 ----a-w c:\windows\DUMP53ad.tmp
    2009-01-26 22:28 98,304 ----a-w c:\windows\DUMP52a4.tmp
    2009-01-26 22:26 98,304 ----a-w c:\windows\DUMP51e8.tmp
    2009-01-26 22:25 98,304 ----a-w c:\windows\DUMP5265.tmp
    2009-01-26 22:24 98,304 ----a-w c:\windows\DUMP5303.tmp
    2009-01-26 22:22 98,304 ----a-w c:\windows\DUMP5286.tmp
    2009-01-26 22:20 98,304 ----a-w c:\windows\DUMP5208.tmp
    2009-01-26 22:19 98,304 ----a-w c:\windows\DUMP5227.tmp
    2009-01-26 22:17 98,304 ----a-w c:\windows\DUMP5302.tmp
    2009-01-26 22:16 98,304 ----a-w c:\windows\DUMP52c3.tmp
    2009-01-26 22:14 98,304 ----a-w c:\windows\DUMP5285.tmp
    2009-01-26 19:48 --------- d-----w c:\program files\KeyChain Photo Manager
    2009-01-18 16:20 --------- d-----w c:\program files\CDex_150
    2009-01-16 07:03 --------- d-----w c:\documents and settings\Compaq_Propriétaire\Application Data\kibisoft
    2009-01-16 06:03 --------- d-----w c:\program files\Kibisoft
    2009-01-15 21:03 --------- d-----w c:\program files\Pochette Express 2
    2009-01-11 20:26 0 ---ha-w c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
    2009-01-11 20:25 --------- d-----w c:\program files\MP3 Player Utilities 4.21
    2009-01-07 18:47 --------- d-----w c:\program files\AGI
    2008-12-21 16:33 81,920 ------r c:\windows\bwUnin-6.1.4.68-8876480L.exe
    2008-12-06 23:02 49,206 ----a-w c:\program files\KeyChain Photo ManagerTmpBitmap.bmp
    2008-11-06 16:55 270 ----a-w c:\documents and settings\Compaq_Propriétaire\Application Data\avp.bat
    2008-11-06 16:54 1,697,280 ----a-w c:\documents and settings\Compaq_Propriétaire\Application Data\winexpl.exe
    2008-09-11 05:55 19,603 ----a-w c:\program files\Fichiers communs\qyky._sy
    2008-09-11 05:55 17,687 ----a-w c:\program files\Fichiers communs\gamyc._sy
    2008-09-11 05:55 16,444 ----a-w c:\program files\Fichiers communs\copure._dl
    2008-09-11 05:55 14,358 ----a-w c:\documents and settings\All Users\Application Data\riqazy.bat
    2008-09-11 05:55 13,785 ----a-w c:\program files\Fichiers communs\ahihado.db
    2008-09-11 05:55 13,499 ----a-w c:\program files\Fichiers communs\zone.com
    2008-08-19 14:50 0 ----a-w c:\program files\temp01
    2008-09-22 15:44 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008092220080923\index.dat
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BD4A40D-8DFC-4F9F-B288-011490D5FCD1}]
    2002-10-31 00:09 96256 --a------ c:\windows\system32\BrWebIn.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-07 68856]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-10 397312]
    "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
    "LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-12-21 20480]
    "LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-01-18 196608]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-01 4112384]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
    "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-02-06 177472]
    "LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
    "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-01-18 458752]
    "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-01-18 217088]
    "NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
    "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-10-24 1451264]

    c:\documents and settings\cindy\Menu D‚marrer\Programmes\D‚marrage\
    OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 393216]

    c:\documents and settings\Compaq_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
    OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 393216]

    c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    Contr“leur d'‚tat.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2007-09-02 802816]
    Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-12-21 450560]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "ForceClassicControlPanel"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\eMule\\emule.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
    "c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\HomePlayer\\HomePlayer.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "c:\\Program Files\\River Past\\Audio Converter Pro\\AudioConverter.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

    R0 gdjnipcx;gdjnipcx;c:\windows\system32\drivers\gdjnipcx.sys [2007-09-01 23424]
    R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
    S2 .EsetTrialReset;Eset Trial Reset;c:\windows\system32\regedt32.exe [2007-09-01 3584]
    S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2008-02-24 16512]
    S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\4DA0.tmp --> c:\windows\system32\4DA0.tmp [?]
    S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\drivers\s916bus.sys [2008-07-14 83496]
    S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\system32\drivers\s916mdfl.sys [2008-07-14 15016]
    S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\system32\drivers\s916mdm.sys [2008-07-14 109992]
    S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s916mgmt.sys [2008-07-14 103976]
    S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface;c:\windows\system32\drivers\s916obex.sys [2008-07-14 100008]
    S3 UsbSagCom;Mobile Device Full USB Driver;c:\windows\system32\drivers\UsbSagCom.sys [2007-06-29 51712]
    S3 w200bus;Sony Ericsson W200 driver (WDM);c:\windows\system32\drivers\w200bus.sys [2008-01-05 61504]
    S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;c:\windows\system32\drivers\w200mdfl.sys [2008-01-05 9328]
    S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;c:\windows\system32\drivers\w200mdm.sys [2008-01-05 97056]
    S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w200mgmt.sys [2008-01-05 88560]
    S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;c:\windows\system32\drivers\w200obex.sys [2008-01-05 86368]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
    \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
    .
    Contenu du dossier 'Tâches planifiées'

    2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

    2009-03-02 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
    - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.fr/
    uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=presario&pf=desktop
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.google.com
    mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=presario&pf=desktop
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = *.local;localhost
    IE: c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d32c1a7c185643c7bce11ae098e15e13
    IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?d32c1a7c185643c7bce11ae098e15e13
    IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d32c1a7c185643c7bce11ae098e15e13
    DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} - hxxp://www.myheritage.fr/Genoogle/Components/ActiveX/SearchEng...
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-02 19:18:31
    Windows 5.1.2600 Service Pack 3 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
    "ImagePath"="\??\c:\windows\system32\4DA0.tmp"
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
    "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\program files\Lavasoft\Ad-Aware\aawservice.exe
    c:\windows\system32\brss01a.exe
    c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Belkin\Belkin Wireless Network Utility\WLService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    c:\windows\system32\drivers\CDANTSRV.EXE
    c:\windows\system32\nvsvc32.exe
    c:\windows\system32\IoctlSvc.exe
    c:\program files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\program files\OpenOffice.org 2.2\program\soffice.exe
    c:\program files\OpenOffice.org 2.2\program\soffice.bin
    c:\program files\Logitech\Video\FxSvr2.exe
    c:\program files\Brother\Brmfcmon\BrMfcMon.exe
    c:\windows\system32\wscntfy.exe
    .
    **************************************************************************
    .
    Heure de fin: 2009-03-02 19:23:59 - La machine a redémarré
    ComboFix-quarantined-files.txt 2009-03-02 18:23:55
    ComboFix2.txt 2009-03-02 05:59:43
    ComboFix3.txt 2009-02-28 21:16:39

    Avant-CF: 40 621 314 048 octets libres
    Après-CF: 40,697,982,976 octets libres

    280 --- E O F --- 2009-02-25 02:01:01
    a b 8 Sécurité
    2 Mars 2009 19:39:03

    Analyse le fichier suivant sur VirusTotal puis poste le rapport :
    c:\windows\system32\drivers\gdjnipcx.sys
    2 Mars 2009 20:34:32

    voici le rapport, merci pour ta patience!

    a-squared 4.0.0.101 2009.03.02 -
    AhnLab-V3 5.0.0.2 2009.02.27 -
    AntiVir 7.9.0.98 2009.03.02 -
    Authentium 5.1.0.4 2009.03.02 -
    Avast 4.8.1335.0 2009.03.02 -
    AVG 8.0.0.237 2009.03.01 -
    BitDefender 7.2 2009.03.02 -
    CAT-QuickHeal 10.00 2009.03.02 -
    ClamAV 0.94.1 2009.03.02 -
    Comodo 986 2009.02.20 -
    DrWeb 4.44.0.09170 2009.03.02 -
    eSafe 7.0.17.0 2009.03.02 -
    eTrust-Vet 31.6.6380 2009.03.02 -
    F-Prot 4.4.4.56 2009.03.02 -
    F-Secure 8.0.14470.0 2009.03.02 -
    Fortinet 3.117.0.0 2009.03.02 -
    GData 19 2009.03.02 -
    Ikarus T3.1.1.45.0 2009.03.02 -
    K7AntiVirus 7.10.654 2009.03.02 -
    Kaspersky 7.0.0.125 2009.03.02 -
    McAfee 5541 2009.03.02 -
    McAfee+Artemis 5541 2009.03.02 -
    Microsoft 1.4306 2009.03.02 -
    NOD32 3901 2009.03.02 -
    Norman 6.00.06 2009.03.02 -
    nProtect 2009.1.8.0 2009.03.02 -
    Panda 10.0.0.10 2009.03.02 -
    PCTools 4.4.2.0 2009.03.02 -
    Prevx1 V2 2009.03.02 -
    Rising 21.19.02.00 2009.03.02 -
    SecureWeb-Gateway 6.7.6 2009.03.02 -
    Sophos 4.39.0 2009.03.02 -
    Sunbelt 3.2.1858.2 2009.03.02 -
    Symantec 10 2009.03.02 -
    TheHacker 6.3.2.6.269 2009.03.02 -
    TrendMicro 8.700.0.1004 2009.03.02 -
    VBA32 3.12.10.1 2009.03.01 -
    ViRobot 2009.3.2.1630 2009.03.02 -
    VirusBuster 4.5.11.0 2009.03.02 -
    Information additionnelle
    File size: 23424 bytes
    MD5...: 0a7c26943221d893344a39a3a09d29e9
    SHA1..: 9c805b2229b2eba68fd531201f1c870babf55129
    SHA256: 7d4bb0abcfbce7629c63d228050c6cba1143374ea35c1ff0d3938a21ea7f9080
    SHA512: 7971be977044e19f55e55649a4425eaedce20f898e2afe5324e1d236180fe405
    14a606dc5d6ee1418b71c417e108f71b71fd93dd5056d4517be41831c7609fc2
    ssdeep: 384:o C/3tIeDoWv+Wp658DSEEwnq6HoDeffxX9FuE7FPmQ0H5xviDncWv+Wp:o C/
    eed4wB1HoiHxX9kiFuQqHsl

    PEiD..: -
    TrID..: File type identification
    Win64 Executable Generic (95.5%)
    Generic Win/DOS Executable (2.2%)
    DOS Executable Generic (2.2%)
    Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
    PEInfo: PE Structure information

    ( base data )
    entrypointaddress.: 0x66c
    timedatestamp.....: 0x3b7d82e5 (Fri Aug 17 20:47:33 2001)
    machinetype.......: 0x14c (I386)

    ( 6 sections )
    name viradd virsiz rawdsiz ntrpy md5
    .text 0x300 0x424 0x480 6.38 f22ffe559a3b1656d1aac70fa7483e04
    .rdata 0x780 0xad 0x100 2.62 0ace5f365131534c66de4137833221ad
    INIT 0x880 0x284 0x300 4.44 13a9d0bea8490140305ffa9291acfd99
    .sklw 0xb80 0x4b00 0x4b00 7.89 e8d8976735cfc47f477956fa531c0e80
    .rsrc 0x5680 0x3c8 0x400 3.22 e12b798b7c7c48bc204f5da182d6b206
    .reloc 0x5a80 0x9a 0x100 2.80 e4e5cbf534b254217ed05c1d1015eea9

    ( 2 imports )
    > ntoskrnl.exe: MmLockPagableDataSection, KeCancelTimer, MmUnlockPagableImageSection, IoStartNextPacket, KeSetTimer, _allmul, IoStartPacket, KeInitializeEvent, KeInitializeTimer, KeInitializeDpc, IoCreateDevice, RtlInitUnicodeString, IoAcquireCancelSpinLock, KeRemoveDeviceQueue, KeRemoveEntryDeviceQueue, IoReleaseCancelSpinLock, IoDeleteDevice, IofCompleteRequest
    > HAL.dll: ExReleaseFastMutex, KfRaiseIrql, KfLowerIrql, HalMakeBeep, ExAcquireFastMutex

    ( 0 exports )



    ATTENTION: VirusTotal est un service gratuit offert par Hispasec Sistemas. Il n'y a aucune garantie quant à la disponibilité et la continuité de ce service. Bien que le taux de détection permis par l'utilisation de multiples moteurs antivirus soit bien supérieur à celui offert par seulement un produit, ces résultats NE garantissent PAS qu'un fichier est sans danger. Il n'y a actuellement aucune solution qui offre un taux d'efficacité de 100% pour la détection des virus et malwares.
    a b 8 Sécurité
    2 Mars 2009 21:14:01

    Tente le script Combofix suivant :

    Rootkit::
    c:\windows\system32\BrWebIn.dll
    3 Mars 2009 06:31:42

    voici le rapport
    ComboFix 09-03-01.01 - Compaq_Propriétaire 2009-03-03 6:08:45.4 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1023.560 [GMT 1:00]
    Lancé depuis: c:\documents and settings\Compaq_Propriétaire\Bureau\ComboFix.exe
    Commutateurs utilisés :: c:\documents and settings\Compaq_Propriétaire\Bureau\CFScript.txt
    AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
    FW: ESET Personal firewall *disabled*
    * Un nouveau point de restauration a été créé
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\BrWebIn.dll

    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2009-02-03 au 2009-03-03 ))))))))))))))))))))))))))))))))))))
    .

    2009-02-26 21:39 . 2009-02-26 21:39 <REP> d-------- C:\_OTMoveIt
    2009-02-24 22:41 . 2009-02-25 15:53 <REP> d-------- c:\program files\Navilog1
    2009-02-24 06:38 . 2009-02-24 06:40 <REP> d-------- C:\Rooter$
    2009-02-24 06:32 . 2009-02-24 06:33 <REP> d-------- C:\rsit
    2009-02-24 06:32 . 2009-02-28 12:46 <REP> d-------- c:\program files\trend micro
    2009-02-22 15:27 . 2009-02-22 15:27 <REP> d-------- c:\program files\Lavasoft
    2009-02-22 15:27 . 2009-02-22 15:27 <REP> d-------- c:\program files\Fichiers communs\Wise Installation Wizard
    2009-02-22 15:27 . 2009-02-22 15:30 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
    2009-02-22 12:54 . 2009-02-22 13:18 4,699,979,776 --a------ C:\Image.iso
    2009-02-22 11:42 . 2009-02-22 11:58 <REP> d-------- c:\documents and settings\Compaq_Propriétaire\Application Data\ImgBurn
    2009-02-22 11:41 . 2009-02-22 11:41 <REP> d-------- c:\program files\ImgBurn
    2009-02-22 11:03 . 2007-01-18 13:00 3,968 --a------ c:\windows\system32\drivers\AvgArCln.sys
    2009-02-19 17:07 . 2009-02-19 17:07 <REP> d-------- c:\program files\Sophos
    2009-02-17 20:33 . 2009-02-28 20:30 <REP> d-------- C:\UT2004Demo
    2009-02-12 03:51 . 2008-12-20 23:47 1,160,192 --a------ c:\windows\system32\SETC76.tmp
    2009-02-12 03:51 . 2008-12-20 23:47 826,368 --a------ c:\windows\system32\SETC74.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 459,264 --a------ c:\windows\system32\SETC7F.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 383,488 --a------ c:\windows\system32\SETC87.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 267,776 --a------ c:\windows\system32\SETC83.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 124,928 --a------ c:\windows\system32\SETC8F.tmp
    2009-02-12 03:51 . 2008-12-20 23:47 105,984 --a------ c:\windows\system32\SETC77.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 63,488 --a------ c:\windows\system32\SETC8C.tmp
    2009-02-12 03:51 . 2008-12-20 23:46 52,224 --a------ c:\windows\system32\SETC7E.tmp
    2009-02-12 03:50 . 2008-12-20 23:46 6,066,688 --a------ c:\windows\system32\SETC85.tmp
    2009-02-11 21:46 . 2009-02-11 21:51 <REP> d--h----- C:\LG3G
    2009-02-11 21:46 . 2009-02-11 21:46 <REP> d-------- c:\documents and settings\Compaq_Propriétaire\Application Data\LG Electronics
    2009-02-11 21:44 . 2009-02-11 21:44 <REP> d-------- c:\program files\LG Electronics
    2009-02-11 21:44 . 2007-07-11 10:45 21,632 --a------ c:\windows\system32\drivers\lgusbmodem.sys
    2009-02-11 21:44 . 2007-07-11 15:51 19,840 --a------ c:\windows\system32\drivers\lgusbdiag.sys
    2009-02-11 21:44 . 2007-07-11 10:40 12,416 --a------ c:\windows\system32\drivers\lgusbbus.sys
    2009-02-11 21:43 . 2009-02-11 21:44 <REP> d-------- c:\program files\LG PC Suite 2
    2009-02-08 11:30 . 2002-10-31 00:09 96,256 --a------ c:\windows\system32\BrWebIn.dll

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-03-03 05:19 --------- d-----w c:\documents and settings\Compaq_Propriétaire\Application Data\OpenOffice.org2
    2009-02-28 17:54 --------- d-----w c:\documents and settings\Compaq_Propriétaire\Application Data\LimeWire
    2009-02-27 18:25 --------- d-----w c:\program files\ESET
    2009-02-18 09:05 --------- d-----w c:\program files\MSECache
    2009-02-16 20:33 --------- d-----w c:\program files\eMule
    2009-02-16 18:01 --------- d-----w c:\program files\Jewel Quest
    2009-02-14 16:03 --------- d-----w c:\documents and settings\All Users\Application Data\Bluetooth
    2009-02-11 20:44 --------- d--h--w c:\program files\InstallShield Installation Information
    2009-02-11 10:05 --------- d-----w c:\program files\World of Warcraft
    2009-02-11 08:52 --------- d-----w c:\program files\Avanquest update
    2009-01-29 18:25 --------- d-----w c:\program files\Microsoft Games
    2009-01-27 07:01 98,304 ----a-w c:\windows\DUMP57b5.tmp
    2009-01-27 04:41 98,304 ----a-w c:\windows\DUMP5544.tmp
    2009-01-27 02:20 98,304 ----a-w c:\windows\DUMP54b7.tmp
    2009-01-27 01:36 98,304 ----a-w c:\windows\DUMP52d3.tmp
    2009-01-27 01:34 98,304 ----a-w c:\windows\DUMP5217.tmp
    2009-01-27 01:33 98,304 ----a-w c:\windows\DUMP5350.tmp
    2009-01-27 01:31 98,304 ----a-w c:\windows\DUMP5330.tmp
    2009-01-27 01:30 98,304 ----a-w c:\windows\DUMP52e2.tmp
    2009-01-27 01:29 98,304 ----a-w c:\windows\DUMP5296.tmp
    2009-01-27 01:27 98,304 ----a-w c:\windows\DUMP53ec.tmp
    2009-01-27 01:26 98,304 ----a-w c:\windows\DUMP5229.tmp
    2009-01-27 01:24 98,304 ----a-w c:\windows\DUMP5257.tmp
    2009-01-27 01:23 98,304 ----a-w c:\windows\DUMP52b4.tmp
    2009-01-27 01:21 98,304 ----a-w c:\windows\DUMP5340.tmp
    2009-01-27 01:20 98,304 ----a-w c:\windows\DUMP5295.tmp
    2009-01-27 01:19 98,304 ----a-w c:\windows\DUMP5294.tmp
    2009-01-27 01:18 98,304 ----a-w c:\windows\DUMP5321.tmp
    2009-01-27 01:16 98,304 ----a-w c:\windows\DUMP53dd.tmp
    2009-01-26 22:58 98,304 ----a-w c:\windows\DUMP5256.tmp
    2009-01-26 22:57 98,304 ----a-w c:\windows\DUMP5248.tmp
    2009-01-26 22:56 98,304 ----a-w c:\windows\DUMP53dc.tmp
    2009-01-26 22:54 98,304 ----a-w c:\windows\DUMP5287.tmp
    2009-01-26 22:53 98,304 ----a-w c:\windows\DUMP52c4.tmp
    2009-01-26 22:52 98,304 ----a-w c:\windows\DUMP52b3.tmp
    2009-01-26 22:50 98,304 ----a-w c:\windows\DUMP52f2.tmp
    2009-01-26 22:49 98,304 ----a-w c:\windows\DUMP5236.tmp
    2009-01-26 22:48 98,304 ----a-w c:\windows\DUMP51c9.tmp
    2009-01-26 22:46 98,304 ----a-w c:\windows\DUMP52a6.tmp
    2009-01-26 22:45 98,304 ----a-w c:\windows\DUMP53cd.tmp
    2009-01-26 22:44 98,304 ----a-w c:\windows\DUMP51da.tmp
    2009-01-26 22:42 98,304 ----a-w c:\windows\DUMP52a5.tmp
    2009-01-26 22:41 98,304 ----a-w c:\windows\DUMP516b.tmp
    2009-01-26 22:40 98,304 ----a-w c:\windows\DUMP5247.tmp
    2009-01-26 22:39 98,304 ----a-w c:\windows\DUMP5277.tmp
    2009-01-26 22:37 98,304 ----a-w c:\windows\DUMP5246.tmp
    2009-01-26 22:36 98,304 ----a-w c:\windows\DUMP5276.tmp
    2009-01-26 22:34 98,304 ----a-w c:\windows\DUMP5275.tmp
    2009-01-26 22:33 98,304 ----a-w c:\windows\DUMP51d9.tmp
    2009-01-26 22:32 98,304 ----a-w c:\windows\DUMP5228.tmp
    2009-01-26 22:30 98,304 ----a-w c:\windows\DUMP51b9.tmp
    2009-01-26 22:29 98,304 ----a-w c:\windows\DUMP53ad.tmp
    2009-01-26 22:28 98,304 ----a-w c:\windows\DUMP52a4.tmp
    2009-01-26 22:26 98,304 ----a-w c:\windows\DUMP51e8.tmp
    2009-01-26 22:25 98,304 ----a-w c:\windows\DUMP5265.tmp
    2009-01-26 22:24 98,304 ----a-w c:\windows\DUMP5303.tmp
    2009-01-26 22:22 98,304 ----a-w c:\windows\DUMP5286.tmp
    2009-01-26 22:20 98,304 ----a-w c:\windows\DUMP5208.tmp
    2009-01-26 22:19 98,304 ----a-w c:\windows\DUMP5227.tmp
    2009-01-26 22:17 98,304 ----a-w c:\windows\DUMP5302.tmp
    2009-01-26 22:16 98,304 ----a-w c:\windows\DUMP52c3.tmp
    2009-01-26 22:14 98,304 ----a-w c:\windows\DUMP5285.tmp
    2009-01-26 19:48 --------- d-----w c:\program files\KeyChain Photo Manager
    2009-01-18 16:20 --------- d-----w c:\program files\CDex_150
    2009-01-16 07:03 --------- d-----w c:\documents and settings\Compaq_Propriétaire\Application Data\kibisoft
    2009-01-16 06:03 --------- d-----w c:\program files\Kibisoft
    2009-01-15 21:03 --------- d-----w c:\program files\Pochette Express 2
    2009-01-11 20:26 0 ---ha-w c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
    2009-01-11 20:25 --------- d-----w c:\program files\MP3 Player Utilities 4.21
    2009-01-07 18:47 --------- d-----w c:\program files\AGI
    2008-12-21 16:33 81,920 ------r c:\windows\bwUnin-6.1.4.68-8876480L.exe
    2008-12-06 23:02 49,206 ----a-w c:\program files\KeyChain Photo ManagerTmpBitmap.bmp
    2008-11-06 16:55 270 ----a-w c:\documents and settings\Compaq_Propriétaire\Application Data\avp.bat
    2008-11-06 16:54 1,697,280 ----a-w c:\documents and settings\Compaq_Propriétaire\Application Data\winexpl.exe
    2008-09-11 05:55 19,603 ----a-w c:\program files\Fichiers communs\qyky._sy
    2008-09-11 05:55 17,687 ----a-w c:\program files\Fichiers communs\gamyc._sy
    2008-09-11 05:55 16,444 ----a-w c:\program files\Fichiers communs\copure._dl
    2008-09-11 05:55 14,358 ----a-w c:\documents and settings\All Users\Application Data\riqazy.bat
    2008-09-11 05:55 13,785 ----a-w c:\program files\Fichiers communs\ahihado.db
    2008-09-11 05:55 13,499 ----a-w c:\program files\Fichiers communs\zone.com
    2008-08-19 14:50 0 ----a-w c:\program files\temp01
    2008-09-22 15:44 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008092220080923\index.dat
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BD4A40D-8DFC-4F9F-B288-011490D5FCD1}]
    2002-10-31 00:09 96256 --a------ c:\windows\system32\BrWebIn.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-07 68856]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-10 397312]
    "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
    "LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-12-21 20480]
    "LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-01-18 196608]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-01 4112384]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
    "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-02-06 177472]
    "LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
    "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-01-18 458752]
    "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-01-18 217088]
    "NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
    "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-10-24 1451264]

    c:\documents and settings\cindy\Menu D‚marrer\Programmes\D‚marrage\
    OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 393216]

    c:\documents and settings\Compaq_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
    OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 393216]

    c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    Contr“leur d'‚tat.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2007-09-02 802816]
    Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-12-21 450560]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "ForceClassicControlPanel"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\eMule\\emule.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
    "c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\HomePlayer\\HomePlayer.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "c:\\Program Files\\River Past\\Audio Converter Pro\\AudioConverter.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

    R0 gdjnipcx;gdjnipcx;c:\windows\system32\drivers\gdjnipcx.sys [2007-09-01 23424]
    R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
    S2 .EsetTrialReset;Eset Trial Reset;c:\windows\system32\regedt32.exe [2007-09-01 3584]
    S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2008-02-24 16512]
    S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\4DA0.tmp --> c:\windows\system32\4DA0.tmp [?]
    S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\drivers\s916bus.sys [2008-07-14 83496]
    S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\system32\drivers\s916mdfl.sys [2008-07-14 15016]
    S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\system32\drivers\s916mdm.sys [2008-07-14 109992]
    S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s916mgmt.sys [2008-07-14 103976]
    S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface;c:\windows\system32\drivers\s916obex.sys [2008-07-14 100008]
    S3 UsbSagCom;Mobile Device Full USB Driver;c:\windows\system32\drivers\UsbSagCom.sys [2007-06-29 51712]
    S3 w200bus;Sony Ericsson W200 driver (WDM);c:\windows\system32\drivers\w200bus.sys [2008-01-05 61504]
    S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;c:\windows\system32\drivers\w200mdfl.sys [2008-01-05 9328]
    S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;c:\windows\system32\drivers\w200mdm.sys [2008-01-05 97056]
    S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w200mgmt.sys [2008-01-05 88560]
    S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;c:\windows\system32\drivers\w200obex.sys [2008-01-05 86368]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
    \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
    .
    Contenu du dossier 'Tâches planifiées'

    2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

    2009-03-03 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
    - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.fr/
    uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=presario&pf=desktop
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.google.com
    mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=presario&pf=desktop
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = *.local;localhost
    IE: c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d32c1a7c185643c7bce11ae098e15e13
    IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?d32c1a7c185643c7bce11ae098e15e13
    IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?d32c1a7c185643c7bce11ae098e15e13
    DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} - hxxp://www.myheritage.fr/Genoogle/Components/ActiveX/SearchEng...
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-03 06:19:52
    Windows 5.1.2600 Service Pack 3 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
    "ImagePath"="\??\c:\windows\system32\4DA0.tmp"
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
    "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\program files\Lavasoft\Ad-Aware\aawservice.exe
    c:\windows\system32\brss01a.exe
    c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Belkin\Belkin Wireless Network Utility\WLService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    c:\windows\system32\drivers\CDANTSRV.EXE
    c:\windows\system32\nvsvc32.exe
    c:\windows\system32\IoctlSvc.exe
    c:\program files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
    c:\program files\OpenOffice.org 2.2\program\soffice.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\program files\OpenOffice.org 2.2\program\soffice.bin
    c:\program files\Brother\Brmfcmon\BrMfcMon.exe
    c:\program files\Logitech\Video\FxSvr2.exe
    c:\windows\system32\wscntfy.exe
    .
    **************************************************************************
    .
    Heure de fin: 2009-03-03 6:24:18 - La machine a redémarré
    ComboFix-quarantined-files.txt 2009-03-03 05:24:15
    ComboFix2.txt 2009-03-02 18:24:03
    ComboFix3.txt 2009-03-02 05:59:43
    ComboFix4.txt 2009-02-28 21:16:39

    Avant-CF: 40 680 976 384 octets libres
    Après-CF: 40,663,298,048 octets libres

    279 --- E O F --- 2009-02-25 02:01:01

    je crois que ça a marché, il n'est plus en quarantaine et n'a pas l'air de revenir :bounce:  :bounce:  :bounce:  :bounce: 
    Vraiment un GROS GROS GROS merci pour ton aide et ta patience .
    Je me reconnecte dans la soirée pour confirmer
        • 1 / 2
        • 2
        • Dernier
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS