Trojan.Vundo dans un fichier .exe

Résolu
Bonsoir à tous,
je viens d'acheter un pc portable à ma fillotte et j'ai commencer par supprimer Norton !
ayant installer Antivir, Spybot,CCleaner, Malwarebytes, et après un scan complet malwarebytes me detecte un Trojan.Vundo dans le fichier suivant : c:\SWSetup\CyberDVD\Stage1\PStarter\vcreditst_x86.exe
Et là je ne sais pas quoi faire ! je rechigne sur ce coup à "supprimer la selection" comme le suggere malware à cause de ce ".exe"
j'ai besoin de vos lumières pour trancher définitevement la question.
Un grand merci d'avance et à plusse
Configuration: Windows Vista
Firefox 3.0.6

41 réponses

Résumé de la discussion

La détection par Malwarebytes d'un Trojan.Vundo dans le fichier c:\SWSetup\CyberDVD\Stage1\PStarter\vcreditst_x86.exe survient après le retrait de Norton et l'installation d'Antivir, Spybot et Malwarebytes, dans le contexte d'un nettoyage antivirus. Des réponses proposent de vérifier le fichier sur VirusTotal pour confirmer un faux positif et d'utiliser un utilitaire de désinstallation Norton pour empêcher l'intrusion récurrent. D'autres évoquent des échanges sur le dossier SWSetup et la possibilité que ce soit un faux positif, avec des observations sur l'état du scan ou des conseils complémentaires. En cas de doute, la discussion évoque l'analyse multi-outil et l'attente des résultats, sans conclure sur l'état du fil ni proposer une résolution immédiate possible.

Bobot (l’IA à votre service)
  1. 1)je suppose un faux positif.

    va sur virus total et analyse le fichier:c:\SWSetup\CyberDVD\Stage1\PStarter\vcreditst_x86.exe
    , tu obtiens un rapport pour chacun d eux , colle le.
    https://www.virustotal.com/gui/

    2)pour bien enlever norton car il s incruste pas mal. utilise cet utilitaire

    http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924?Open&src=&docid=20040413131641928&nsf=SUPPORT\INTER\nisintl.nsf&view=833aab0c51f1b15a88256da6006a0505&dtype=&prod=&ver=&osv=&osv_lvl=
    1
    1. salut; alor la c'est la merde j'ai eu le coup moi meme de ce put... de vundo. le seul qui a pu me le virer c'est un logiciel super puissant autiliser avec précossion. alor je vais te filler le nom. va sur google et telecharge:
      combofix
      c'est gratuit mais c'est aussi a t'es risque et peril. moi nickel sa ma tout degager
      en ésperant t'voir aider
      bye
      0
      1. OK, vous etes des amours je vais commencer par virustotal et vous tiens au courant !
        0
        1. heuuuuuuu ! je suis un peu truffe, mais je vois ça sur la page d'analyse, c'est ce qu'il te faut ?

          Le fichier a déjà été analysé:
          MD5: 1f8e9fec647700b21d45e6cda97c39b7
          First received: 2007.02.06 04:43:13 (CET)
          Date 2009.03.05 22:54:18 (CET) [<1D]
          Résultats 0/39
          Permalink: analisis/55df9d75571de9ef61f634322603e478
          0
          1. bonsoir il faut cliquer sur analyser le fichier a nouveau
            0
            1. merci !
              resultat : Non Trouvé ! Alors faux positif ?
              0
              1. histoire de mieux se rendre compte :

                fais un scan avec Antivir
                0
                1. c'est la première chose que j'ai fait après avoir supprimer norton comme indiqué dans les astuces de CCM,
                  RAS
                  0
                  1. et en cliquant droit dessus(le fichier) et analyser avec MBAM mis a jour?
                    0
                    1. alors Totobetourne a raison !!!!

                      Faux Positif(quoique pour Vundo quand meme !!!!)
                      0
                      1. ok, je vais tenir ça à l'oeil, le truc c'est ce fichier ce ".exe", je me suis mis dans la tête (bêtement ?) que cette cochonerie apparaissait en ".dll".
                        0
                        1. fais ceci par securite au cas ou :

                          > Télécharge Dr.Web CureIt sur ton Bureau : Dr Web

                          - Double clique <drweb-cureit.exe> et ensuite clique sur <Analyse>;

                          - Clique <Ok> à l'invite de l'analyse rapide. S'il trouve des processus infectés alors clique le bouton <Oui>.
                          Note : une fenêtre s'ouvrira avec options pour "Commander" ou "50% de réduction" : Quitte en cliquant le "X".
                          - Lorsque le scan rapide est terminé, clique sur le menu <Options> puis <Changer la configuration> ; Choisis l'onglet <Scanner>, et décoche <Analyse heuristique>. Clique ensuite sur <Ok>.
                          - De retour à la fenêtre principale : clique pour activer <Analyse complète>
                          - Clique le bouton avec flèche verte sur la droite, et le scan débutera.
                          - Clique <Oui> pour tout à l'invite "Désinfecter ?" lorsqu'un fichier est détecté, et ensuite clique "Désinfecter".
                          - Lorsque le scan sera complété, regarde si tu peux cliquer sur l' icône, adjacente aux fichiers détectés (plusieurs feuilles l'une sur l'autre). Si oui, alors clique dessus et ensuite clique sur l'icône <Suivant>, au dessous, et choisis <Déplacer en quarantaine l'objet indésirable>.
                          - Du menu principal de l'outil, au haut à gauche, clique sur le menu <Fichier> et choisis <Enregistrer le rapport>. Sauvegarde le rapport sur ton Bureau. Ce dernier se nommera DrWeb.csv
                          - Ferme Dr.Web Cureit
                          - Redémarre ton ordi (important car certains fichiers peuvent être déplacés/réparés au redémarrage).
                          - Suite au redémarrage, poste (Copie/Colle) le contenu du rapport de Dr.Web dans ta prochaine réponse.
                          0
                          1. ok, mais je ferai ça demain car mes petits nyeux sont un peu fatigués !
                            A demain, bonne nuit et merci pour tous !
                            0
                            1. bonsoir,
                              voilà le rapport (en fichier exel c'est pas très cool !)
                              j'avais oublié qu'avira avait trouvé le 1er, mais les suivants il ne les a pas vu ! j'ai executée les actions recommandées et donc voili, voulou.
                              tu en penses quoi ? (ou quelqu'un d'autre !)

                              gameconsoleservice.exe c:\program files\hp games\my hp game console Probablement MULDROP.Trojan Quarantaine.
                              RegUBP2b-Eline.reg C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2 Trojan.StartPage.1505 Supprimé.
                              SlgClientServicesRedists.exe\data002 C:\Program Files\HP Games\Granny in Paradise\wtmui_de\SlgClientServicesRedists.exe Adware.SpywareStorm
                              SlgClientServicesRedists.exe C:\Program Files\HP Games\Granny in Paradise\wtmui_de L'archive contient des éléments infectés Quarantaine.
                              SlgClientServicesRedists.exe\data002 C:\Program Files\HP Games\Granny in Paradise\wtmui_es\SlgClientServicesRedists.exe Adware.SpywareStorm
                              SlgClientServicesRedists.exe C:\Program Files\HP Games\Granny in Paradise\wtmui_es L'archive contient des éléments infectés Quarantaine.
                              SlgClientServicesRedists.exe\data002 C:\Program Files\HP Games\Granny in Paradise\wtmui_fr\SlgClientServicesRedists.exe Adware.SpywareStorm
                              SlgClientServicesRedists.exe C:\Program Files\HP Games\Granny in Paradise\wtmui_fr L'archive contient des éléments infectés Quarantaine.
                              SlgClientServicesRedists.exe\data002 C:\Program Files\HP Games\Granny in Paradise\wtmui_ko\SlgClientServicesRedists.exe Adware.SpywareStorm
                              SlgClientServicesRedists.exe C:\Program Files\HP Games\Granny in Paradise\wtmui_ko L'archive contient des éléments infectés Quarantaine.
                              0
                              1. Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                                -> RSIT

                                ! Déconnecte toi et ferme toutes tes applications en cours !

                                Double-clique sur " RSIT.exe " pour le lancer .

                                -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                                * Devant l'option "List files/folders created ..." , tu choisis : 2 months

                                * clique ensuite sur " Continue " pour lancer l'analyse ...

                                -> laisse faire le scan et ne touche pas au PC ...

                                Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

                                Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                                Important : poste un rapport, puis l'autre dans la réponse suivante
                                Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

                                ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

                                0
                                1. voici le 1er rapport :

                                  Logfile of random's system information tool 1.05 (written by random/random)
                                  Run by Eline at 2009-03-06 22:27:13
                                  Microsoft® Windows Vista™ Édition Familiale Basique Service Pack 1
                                  System drive C: has 93 GB (65%) free of 142 GB
                                  Total RAM: 3068 MB (69% free)

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 22:27:45, on 06/03/2009
                                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\system32\Dwm.exe
                                  C:\Windows\Explorer.EXE
                                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                  C:\Windows\System32\rundll32.exe
                                  C:\Program Files\HP\QuickPlay\QPService.exe
                                  C:\Program Files\Windows Defender\MSASCui.exe
                                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                                  C:\Program Files\Java\jre6\bin\jusched.exe
                                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                                  C:\Program Files\iTunes\iTunesHelper.exe
                                  C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                                  C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
                                  C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
                                  C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                  C:\Windows\system32\wuauclt.exe
                                  C:\Windows\System32\wsqmcons.exe
                                  C:\Windows\system32\SearchFilterHost.exe
                                  C:\Users\Eline\Desktop\RSIT.exe
                                  C:\Users\Eline\Downloads\Eline.exe

                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                  O1 - Hosts: ::1 localhost
                                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                  O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
                                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                  O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                                  O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
                                  O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
                                  O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
                                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                  O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
                                  O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                                  O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                  O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                  O8 - Extra context menu item: &Recherche AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\fr-FR\local\search.html
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                                  O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                  O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O13 - Gopher Prefix:
                                  O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                  O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
                                  O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                  O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                                  O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
                                  O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
                                  O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                  0
                                  1. et le 2d - comme tu dis c'est long ! :

                                    info.txt logfile of random's system information tool 1.05 2009-03-06 22:27:46

                                    ======Uninstall list======

                                    -->"C:\Program Files\HP Games\5 Card Deluxe\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Agatha Christie - Death on the Nile\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Age of Castles\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Build-a-lot 2\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Cake Mania\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\FATE\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Fish Tycoon\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Granny in Paradise\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Mahjongg Artifacts\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Polar Pool\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\SPORE Creature Creator Trial Edition\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\The Treasures of Montezuma\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Virtual Villagers - The Secret City\Uninstall.exe"
                                    -->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
                                    -->C:\Program Files\Conexant\SmartAudio\SETUP.EXE -U -ISmartAudio -SM=SMAUDIO.EXE,1801
                                    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                                    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                                    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                                    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
                                    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
                                    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
                                    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
                                    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
                                    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
                                    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                                    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
                                    Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
                                    ActiveCheck component for HP Active Support Library-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
                                    Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                                    Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                                    Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
                                    Adobe Shockwave Player-->MsiExec.exe /X{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}
                                    AOL Toolbar 5.0-->"C:\Program Files\AOL\AOL Toolbar 5.0\uninstall.exe"
                                    Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
                                    Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                                    Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
                                    Atheros Driver Installation Program-->C:\Program Files\InstallShield Installation Information\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}\setup.exe -runfromtemp -l0x040c
                                    Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
                                    Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
                                    CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                                    Cisco EAP-FAST Module-->MsiExec.exe /I{415B2719-AD3A-4944-B404-C472DB6085B3}
                                    Cisco LEAP Module-->MsiExec.exe /I{83770D14-21B9-44B3-8689-F7B523F94560}
                                    Cisco PEAP Module-->MsiExec.exe /I{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}
                                    Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU32a.exe -U -IWAHerza.INF
                                    CyberLink DVD Suite-->"C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\Setup.exe" /z-uninstall
                                    CyberLink DVD Suite-->"C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\Setup.exe" /z-uninstall
                                    CyberLink YouCam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
                                    CyberLink YouCam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
                                    eMule-->"C:\Program Files\eMule\Uninstall.exe"
                                    ESU for Microsoft Vista-->MsiExec.exe /I{3877C901-7B90-4727-A639-B6ED2DD59D43}
                                    HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_HERMOSA_HSF\UIU32m.exe -U -IHPQHERzm.inf
                                    HijackThis 2.0.2-->"C:\Users\Eline\Downloads\HijackThis.exe" /uninstall
                                    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                                    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                                    HP Active Support Library-->"C:\Program Files\InstallShield Installation Information\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}\setup.exe" -runfromtemp -l0x0409 -removeonly
                                    HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57A5AEC1-97FC-474D-92C4-908FCC2253D4}\setup.exe" -l0x9 -removeonly
                                    HP Doc Viewer-->MsiExec.exe /I{082702D5-5DD8-4600-BCE5-48B15174687F}
                                    HP DVD Play 3.7-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
                                    HP Help and Support-->MsiExec.exe /I{0054A0F6-00C9-4498-B821-B5C9578F433E}
                                    HP Quick Launch Buttons 6.40 H2-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x040c uninst
                                    HP Total Care Advisor-->MsiExec.exe /X{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}
                                    HP Update-->MsiExec.exe /X{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}
                                    HP User Guides 0118-->MsiExec.exe /I{B6D0B141-B2BE-4DD0-B08F-B9186F3E36B3}
                                    HP Wireless Assistant-->MsiExec.exe /I{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}
                                    HPAsset component for HP Active Support Library-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
                                    HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
                                    HPTCSSetup-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{846DDADA-0239-4B67-A6B1-33658863793B}\setup.exe" -l0x9 -removeonly
                                    iTunes-->MsiExec.exe /I{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}
                                    Java(TM) 6 Update 12-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
                                    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                                    LabelPrint-->"C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall
                                    LabelPrint-->"C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall
                                    LightScribe System Software 1.14.17.1-->MsiExec.exe /X{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}
                                    Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                                    Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                                    Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                                    Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                                    Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                                    Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                                    Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
                                    Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
                                    Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
                                    Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
                                    Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
                                    Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                                    Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
                                    Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                                    Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                                    Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                                    Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                                    Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                                    Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                                    Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                                    Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                                    Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                                    Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                                    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                                    Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
                                    Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
                                    Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                                    Mozilla Firefox (3.0.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                                    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                                    muvee Reveal-->MsiExec.exe /X{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}
                                    My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
                                    NetWaiting-->C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x040c -removeonly
                                    NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
                                    PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
                                    Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
                                    Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
                                    PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
                                    PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
                                    QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
                                    Realtek 8169 8168 8101E 8102E Ethernet Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
                                    Realtek USB 2.0 Card Reader-->C:\Program Files\InstallShield Installation Information\{DC24971E-1946-445D-8A82-CE685433FA7D}\setup.exe -runfromtemp -l0x040c -removeonly
                                    Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
                                    Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
                                    Security Update for 2007 Microsoft Office System (KB958439)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6491B8AA-D11C-4648-A461-6234B31EB7E2}
                                    Security Update for Microsoft Office Excel 2007 (KB958437)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {648FC016-2D6B-4A16-8D87-404533642F4B}
                                    Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
                                    Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
                                    Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
                                    Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
                                    Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
                                    SPORE Creature Creator Trial Edition-->"C:\Program Files\HP Games\SPORE Creature Creator Trial Edition\Uninstall.exe"
                                    Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                                    StuffPlug 3-->C:\Program Files\StuffPlug3\Uninstall.exe
                                    Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                                    Update for Microsoft Office Excel 2007 Help (KB957242)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {49E314EE-81FA-4007-8F1A-8D39BDBB4498}
                                    Update for Office 2007 (KB946691)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
                                    Vista Shortcut Manager-->MsiExec.exe /I{47609E69-4C5E-48B1-A889-24C6B82B5C04}
                                    VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                                    Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                                    Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
                                    Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
                                    Zylom Games Player Plugin-->"C:\Program Files\Zylom Games\UninstallPlugin.exe" --uninstall

                                    ======Hosts File======

                                    127.0.0.1 www.007guard.com
                                    127.0.0.1 007guard.com
                                    127.0.0.1 008i.com
                                    127.0.0.1 www.008k.com
                                    127.0.0.1 008k.com
                                    127.0.0.1 www.00hq.com
                                    127.0.0.1 00hq.com
                                    127.0.0.1 010402.com
                                    127.0.0.1 www.032439.com
                                    127.0.0.1 032439.com

                                    ======Security center information======

                                    AS: Spybot - Search and Destroy (disabled)
                                    AS: Windows Defender

                                    System event log

                                    Computer Name: PC-de-Eline
                                    Event Code: 4201
                                    Message: Le système a détecté que la carte réseau Connexion au réseau local était connectée au réseau, et a lancé une opération normale.
                                    Record Number: 14426
                                    Source Name: Tcpip
                                    Time Written: 20090306201843.753492-000
                                    Event Type: Information
                                    User:

                                    Computer Name: PC-de-Eline
                                    Event Code: 4201
                                    Message: Le système a détecté que la carte réseau Connexion au réseau local était connectée au réseau, et a lancé une opération normale.
                                    Record Number: 14427
                                    Source Name: Tcpip
                                    Time Written: 20090306201843.753492-000
                                    Event Type: Information
                                    User:

                                    Computer Name: PC-de-Eline
                                    Event Code: 7036
                                    Message: Le service Service de découverte automatique de Proxy Web pour les services HTTP Windows est entré dans l'état : en cours d'exécution.
                                    Record Number: 14428
                                    Source Name: Service Control Manager
                                    Time Written: 20090306201846.000000-000
                                    Event Type: Information
                                    User:

                                    Computer Name: PC-de-Eline
                                    Event Code: 7036
                                    Message: Le service Office Source Engine est entré dans l'état : en cours d'exécution.
                                    Record Number: 14429
                                    Source Name: Service Control Manager
                                    Time Written: 20090306202946.000000-000
                                    Event Type: Information
                                    User:

                                    Computer Name: PC-de-Eline
                                    Event Code: 7036
                                    Message: Le service Service de découverte automatique de Proxy Web pour les services HTTP Windows est entré dans l'état : arrêté.
                                    Record Number: 14430
                                    Source Name: Service Control Manager
                                    Time Written: 20090306203516.000000-000
                                    Event Type: Information
                                    User:

                                    Application event log

                                    Computer Name: PC-de-Eline
                                    Event Code: 102
                                    Message: msnmsgr (1228) \\.\C:\Users\Eline\AppData\Local\Microsoft\Messenger\lachieuz_2602@hotmail.fr\SharingMetadata\Working\database_7CC9_FF99_4594_A58\dfsr.db: Le moteur de la base de données (6.00.6001.0000) a démarré une nouvelle instance (0).
                                    Record Number: 1368
                                    Source Name: ESENT
                                    Time Written: 20090306211507.000000-000
                                    Event Type: Information
                                    User:

                                    Computer Name: PC-de-Eline
                                    Event Code: 103
                                    Message: msnmsgr (1228) \\.\C:\Users\Eline\AppData\Local\Microsoft\Messenger\lachieuz_2602@hotmail.fr\SharingMetadata\Working\database_7CC9_FF99_4594_A58\dfsr.db: Le moteur de la base de données a arrêté l'instance (0).
                                    Record Number: 1369
                                    Source Name: ESENT
                                    Time Written: 20090306211620.000000-000
                                    Event Type: Information
                                    User:

                                    Computer Name: PC-de-Eline
                                    Event Code: 102
                                    Message: msnmsgr (1616) \\.\C:\Users\Eline\AppData\Local\Microsoft\Messenger\lachieuz_2602@hotmail.fr\SharingMetadata\Working\database_7CC9_FF99_4594_A58\dfsr.db: Le moteur de la base de données (6.00.6001.0000) a démarré une nouvelle instance (0).
                                    Record Number: 1370
                                    Source Name: ESENT
                                    Time Written: 20090306211657.000000-000
                                    Event Type: Information
                                    User:

                                    Computer Name: PC-de-Eline
                                    Event Code: 103
                                    Message: msnmsgr (1616) \\.\C:\Users\Eline\AppData\Local\Microsoft\Messenger\lachieuz_2602@hotmail.fr\SharingMetadata\Working\database_7CC9_FF99_4594_A58\dfsr.db: Le moteur de la base de données a arrêté l'instance (0).
                                    Record Number: 1371
                                    Source Name: ESENT
                                    Time Written: 20090306212607.000000-000
                                    Event Type: Information
                                    User:

                                    Computer Name: PC-de-Eline
                                    Event Code: 5
                                    Message: Unsupported service control request (see data below)
                                    Record Number: 1372
                                    Source Name: LightScribeService
                                    Time Written: 20090306212746.000000-000
                                    Event Type: Information
                                    User:

                                    Security event log

                                    Computer Name: PC-de-Eline
                                    Event Code: 5038
                                    Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                    Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                                    Record Number: 2885
                                    Source Name: Microsoft-Windows-Security-Auditing
                                    Time Written: 20090306212745.306292-000
                                    Event Type: Échec de l'audit
                                    User:

                                    Computer Name: PC-de-Eline
                                    Event Code: 5038
                                    Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                    Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                                    Record Number: 2886
                                    Source Name: Microsoft-Windows-Security-Auditing
                                    Time Written: 20090306212745.321892-000
                                    Event Type: Échec de l'audit
                                    User:

                                    Computer Name: PC-de-Eline
                                    Event Code: 5038
                                    Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                    Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                                    Record Number: 2887
                                    Source Name: Microsoft-Windows-Security-Auditing
                                    Time Written: 20090306212745.353092-000
                                    Event Type: Échec de l'audit
                                    User:

                                    Computer Name: PC-de-Eline
                                    Event Code: 5038
                                    Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                    Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                                    Record Number: 2888
                                    Source Name: Microsoft-Windows-Security-Auditing
                                    Time Written: 20090306212745.368692-000
                                    Event Type: Échec de l'audit
                                    User:

                                    Computer Name: PC-de-Eline
                                    Event Code: 5038
                                    Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                    Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                                    Record Number: 2889
                                    Source Name: Microsoft-Windows-Security-Auditing
                                    Time Written: 20090306212745.399892-000
                                    Event Type: Échec de l'audit
                                    User:

                                    ======Environment variables======

                                    "ComSpec"=%SystemRoot%\system32\cmd.exe
                                    "FP_NO_HOST_CHECK"=NO
                                    "OS"=Windows_NT
                                    "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\CyberLink\Power2Go;C:\Program Files\QuickTime\QTSystem\
                                    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                                    "PROCESSOR_ARCHITECTURE"=x86
                                    "TEMP"=%SystemRoot%\TEMP
                                    "TMP"=%SystemRoot%\TEMP
                                    "USERNAME"=SYSTEM
                                    "windir"=%SystemRoot%
                                    "PROCESSOR_LEVEL"=6
                                    "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
                                    "PROCESSOR_REVISION"=0f0d
                                    "NUMBER_OF_PROCESSORS"=2
                                    "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
                                    "DFSTRACINGON"=FALSE
                                    "OnlineServices"=Online Services
                                    "Platform"=MCD
                                    "PCBRAND"=Presario
                                    "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
                                    "QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

                                    -----------------EOF-----------------
                                    0
                                    1. Désactiver le TeaTimer de Spybot (Merci à Nico):

                                      Pour désactiver le TeaTimer :
                                      => Ouvrir Spybot S&D
                                      => Dans le menu "Mode", séléctionner le mode avancé.
                                      => Une fenêtre demande confirmation cliquer sur "oui".
                                      => Une fois le mode avancé actif, ouvrir l'onglet "Outils".
                                      => Cliquer sur Résident.
                                      => La partie Résident comporte deux lignes qui sont normalement cochées :
                                      *Résident "SDHelper" (bloqueur de téléchargements nuisibles pour Internet Explorer) actif.

                                      * Résident "TeaTimer" (Protection des réglages système fondamentaux) actif.

                                      => Décocher la ligne TeaTimer.
                                      => Redémarrer Spybot (le fermer et le réouvrir)
                                      => Retourner dans le menu Résident et vérifier qu'il soit bien désactivé.

                                      ensuite :


                                      ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

                                      ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :

                                      OtMoveIt 3

                                      ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                                      ---> Copie (Ctrl+C) le texte suivant ci-dessous :


                                      :processes
                                      explorer.exe

                                      :files
                                      C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

                                      :commands
                                      [purity]
                                      [emptytemp]
                                      [start explorer]
                                      [reboot]


                                      ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                                      ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                                      Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                                      Accepte en cliquant sur YES.

                                      ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                                      Le nom du rapport correspond au moment de sa création : date_heure.log

                                      ensuite :

                                      mets Malwarebytes a jour et fais un scan complet avec
                                      0
                                      • 1
                                      • 2
                                      • 3

                                      Discussions similaires

                                      question pix mot caché

                                      7 réponses