Rapport combofix

Bonjour,
aidez moi a decrypter mon rapport combofix stp
omboFix 09-04-29.07 - Cécilia 30/04/2009 19:17.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.566 [GMT 2:00]
Lancé depuis: c:\documents and settings\Cécilia\Bureau\prevention et supression des virus\ComboFix.exe
AV: Avira AntiVir PersonalEdition Classic *On-access scanning disabled* (Updated)
FW: Sunbelt Personal Firewall *enabled*
* Un nouveau point de restauration a été créé
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games

((((((((((((((((((((((((((((( Fichiers créés du 2009-05-28 au 2009-4-30 ))))))))))))))))))))))))))))))))))))
.

2009-04-30 12:04 . 2009-04-30 12:04 579584 -c--a-w c:\windows\system32\dllcache\user32.dll
2009-04-30 12:00 . 2009-04-30 12:01 -------- d-----w c:\windows\ERUNT
2009-04-30 11:09 . 2009-04-30 12:32 -------- d-----w C:\SDFix
2009-04-28 12:39 . 2009-04-28 12:44 -------- d-----w c:\program files\MessengerPlus! 3
2009-04-16 12:53 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 12:53 . 2009-03-06 14:20 286720 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-16 12:53 . 2009-02-09 11:23 111104 -c----w c:\windows\system32\dllcache\services.exe
2009-04-16 12:53 . 2009-02-09 10:53 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 12:53 . 2009-02-09 10:53 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 12:53 . 2009-02-09 10:53 685568 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 12:53 . 2009-02-09 10:53 735744 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 12:53 . 2009-02-09 10:53 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 12:53 . 2009-02-09 10:53 739840 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 12:36 . 2008-12-16 12:31 354304 -c----w c:\windows\system32\dllcache\winhttp.dll
2009-04-16 12:36 . 2008-04-21 21:15 219136 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-10 15:59 . 2009-04-10 15:59 -------- d-----w c:\windows\nview
2009-04-10 15:59 . 2009-03-27 08:03 453152 ----a-w c:\windows\system32\nvudisp.exe
2009-04-10 15:59 . 2009-03-27 06:14 453152 ----a-w c:\windows\system32\NVUNINST.EXE
2009-04-10 15:38 . 2009-04-10 15:38 -------- d-----w c:\program files\SystemRequirementsLab
2009-04-10 15:28 . 2009-04-10 15:29 -------- d-----w c:\program files\SecondLife
2009-04-10 15:17 . 2009-04-10 15:51 -------- d-----w c:\windows\NV29963772.TMP
2009-04-10 14:43 . 2009-04-10 14:43 -------- d--h--w c:\windows\PIF
2009-04-10 14:38 . 2009-04-10 15:51 -------- d-----w c:\windows\NV3596444.TMP
2009-04-10 14:31 . 2009-04-10 14:31 -------- d-----w c:\documents and settings\All Users\Application Data\LogiShrd
2009-04-10 14:28 . 2009-04-10 15:51 -------- d-----w c:\program files\Fichiers communs\Logishrd
2009-04-10 11:24 . 2009-04-10 11:24 -------- d-----w c:\documents and settings\All Users\Application Data\BOONTY
2009-04-10 11:24 . 2009-04-10 11:24 -------- d-----w c:\program files\Fichiers communs\BOONTY Shared
2009-04-10 11:24 . 2009-04-10 11:24 -------- d-----w c:\program files\BoontyGames
2009-04-10 11:24 . 2009-04-10 11:24 -------- d-----w c:\program files\Boonty
2009-04-10 08:21 . 2009-04-10 10:33 -------- d-----w c:\program files\Singles
2009-04-07 13:01 . 2006-06-29 11:07 14048 ------w c:\windows\system32\spmsg2.dll
2009-04-07 12:37 . 2009-04-07 13:00 -------- d-----w c:\windows\system32\XPSViewer
2009-04-07 12:37 . 2009-04-07 12:37 -------- d-----w c:\program files\MSBuild
2009-04-07 12:37 . 2009-04-07 12:37 -------- d-----w c:\program files\Reference Assemblies
2009-04-02 15:45 . 2009-04-02 15:45 -------- d-----w c:\program files\Fichiers communs\xing shared

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-30 11:41 . 2006-03-02 12:00 81734 ----a-w c:\windows\system32\perfc00C.dat
2009-04-30 11:41 . 2006-03-02 12:00 503570 ----a-w c:\windows\system32\perfh00C.dat
2009-04-23 13:56 . 2007-12-31 10:34 -------- d-----w c:\program files\EvilLyrics
2009-04-17 18:20 . 2007-12-21 17:07 -------- d-----w c:\program files\eMule
2009-04-10 15:43 . 2007-12-17 11:47 -------- d-----w c:\program files\Realtek
2009-04-10 14:44 . 2007-12-17 11:30 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-10 14:30 . 2009-04-10 14:30 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2009-04-10 14:30 . 2009-04-10 14:30 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-04-10 14:30 . 2009-04-10 14:30 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-04-10 14:19 . 2008-10-19 11:54 -------- d-----w c:\program files\ma-config.com
2009-04-10 14:19 . 2008-10-19 11:54 -------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
2009-04-07 12:40 . 2008-10-08 14:52 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-06 13:32 . 2008-10-08 14:52 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2008-10-08 14:52 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-02 15:45 . 2007-12-19 17:30 -------- d-----w c:\program files\Fichiers communs\Real
2009-04-01 14:09 . 2008-10-15 15:21 -------- d-----w c:\program files\Java
2009-03-30 19:53 . 2008-12-18 14:46 -------- d-----w c:\program files\Microsoft Silverlight
2009-03-30 16:32 . 2009-03-30 16:29 -------- d-----w c:\program files\HiYo
2009-03-30 15:13 . 2007-12-17 11:47 5063168 ----a-w c:\windows\system32\drivers\RtkHDAud.sys
2009-03-30 14:51 . 2008-09-10 17:28 -------- d-----w c:\program files\Freeplayer
2009-03-30 12:40 . 2008-10-04 20:58 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-27 09:22 . 2007-12-17 11:47 17567744 ----a-w c:\windows\RTHDCPL.EXE
2009-03-17 11:58 . 2007-12-17 11:47 540672 ----a-w c:\windows\RtlExUpd.dll
2009-03-10 12:32 . 2007-12-17 11:47 2168320 ----a-w c:\windows\MicCal.exe
2009-03-09 03:19 . 2008-12-14 11:41 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-06 14:20 . 2006-03-02 12:00 286720 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:13 . 2006-03-02 12:00 826368 ----a-w c:\windows\system32\wininet.dll
2009-03-02 09:14 . 2007-12-17 11:47 57344 ----a-w c:\windows\ALCMTR.EXE
2009-02-20 17:10 . 2006-03-02 12:00 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 14:05 . 2006-03-02 12:00 1846912 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:23 . 2004-08-19 16:04 2025984 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:23 . 2006-03-02 12:00 2147328 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:23 . 2006-03-02 12:00 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:53 . 2006-03-02 12:00 735744 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:53 . 2006-03-02 12:00 739840 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 10:53 . 2006-03-02 12:00 685568 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:53 . 2006-03-02 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-06 18:39 . 2009-02-06 18:39 308600 ----a-w c:\windows\WLXPGSS.SCR
2009-02-06 17:52 . 2009-02-06 17:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-06 17:08 . 2009-02-18 10:38 55152 ----a-w c:\windows\system32\drivers\fssfltr_tdi.sys
2009-02-06 10:39 . 2006-03-02 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:58 . 2006-03-02 12:00 56832 ----a-w c:\windows\system32\secur32.dll
2008-02-03 18:24 . 2008-02-03 18:26 774144 -c--a-w c:\program files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-25 68856]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2008-09-29 1279216]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2009-04-28 190024]
"msnmsgr"="c:\progra~1\WI1F86~1\MESSEN~1\msnmsgr.exe" [2009-02-06 3885408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-04-02 198160]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2009-04-28 190024]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-03-27 17567744]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-9-30 691720]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"c:\\Program Files\\Odebit Multimédia\\V3.2\\Odebit.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

R3 ATICDSDr;ATICDSDr; [x]
R3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2009-03-15 216232]
S0 PzWDM;PzWDM;c:\windows\system32\Drivers\PzWDM.sys [2005-06-29 15172]
S1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [2008-10-31 270888]
S1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [2008-06-21 66600]
S2 fssfltr;fssfltr;c:\windows\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
S2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-10-31 95528]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-10-31 1365288]
S2 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2007-09-30 51816]
S3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]
S3 V0260VID;Live! Cam Vista IM;c:\windows\system32\DRIVERS\V0260Vid.sys [2006-04-01 162176]

.
Contenu du dossier 'Tâches planifiées'

2009-04-30 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-12-19 14:05]
.
- - - - ORPHELINS SUPPRIMES - - - -

HKLM-Run-Bluetooth Connection Assistant - LBTWIZ.EXE

.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: microsoft.com\office
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-30 19:26
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_USERS\S-1-5-21-448539723-963894560-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-448539723-963894560-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:98,22,f1,fd,6f,a7,8e,cc,2c,7e,e4,0e,2e,e8,10,31,3c,26,44,b9,69,
eb,42,0e,29,da,34,11,15,46,14,26,2f,6b,cb,2c,04,29,b6,9f,fa,99,f5,bd,f5,09,\
"rkeysecu"=hex:40,74,11,be,97,20,3c,ef,32,02,b8,59,9a,13,e5,ed
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'explorer.exe'(3656)
c:\program files\MessengerPlus! 3\MsgPlusLoader1.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Sunbelt Software\Personal Firewall\SbPFCl.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
c:\program files\Windows Live\Messenger\msnmsgr.exe
.
**************************************************************************
.
Heure de fin: 2009-04-30 19:31 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-04-30 17:31

Avant-CF: 83 852 505 088 octets libres
Après-CF: 83 792 072 704 octets libres

WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

226 --- E O F --- 2009-04-29 06:44

Merci d'avance
Configuration: Windows XP Internet Explorer 7.0

22 réponses

Résumé de la discussion

Question : l’objectif est d’interpréter un rapport ComboFix et d’évaluer l’étendue possible d’infections sur une machine Windows XP après des signes de logiciels indésirables et d’alertes de sécurité. Des réponses indiquent que Malwarebytes' Anti-Malware a effectué un examen complet et n’a détecté aucun élément nuisible, confirmant l’absence d’infections détectées, et montrent que la machine peut nécessite des nettoyages complémentaires. Pour le nettoyage, Spybot - Search & Destroy est mentionné avec TeaTimer potentiellement désactivé, accompagné de suppressions et déplacements d’éléments dans le registre et les fichiers temporaires. En cas de doute, il est conseillé de poursuivre avec MBAM et des outils de suppression complémentaires et de vérifier les éléments créés par ComboFix, notamment les entrées de démarrage et les dossiers temporaires.

Bobot (l’IA à votre service)
  1. ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

    ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :

    ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

    ---> Copie (Ctrl+C) le texte suivant ci-dessous :



    :processes
    explorer.exe

    :services
    ATICDSDr

    :files
    c:\windows\NV29963772.TMP
    c:\windows\NV3596444.TMP

    :reg
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    "MessengerPlus3"=-
    "msnmsgr"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NeroFilterCheck"=-
    "SunJavaUpdateSched"=-
    "TkBellExe"=-
    "MessengerPlus3"=-

    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]



    ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

    ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

    Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
    Accepte en cliquant sur YES.

    ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
    Le nom du rapport correspond au moment de sa création : date_heure.log
    0
    1. Merci pour ta reponse voici mon rapport
      ========== PROCESSES ==========
      Process explorer.exe killed successfully.
      ========== SERVICES/DRIVERS ==========

      Service\Driver ATICDSDr deleted successfully.
      ========== FILES ==========
      c:\windows\NV29963772.TMP moved successfully.
      c:\windows\NV3596444.TMP moved successfully.
      ========== REGISTRY ==========
      Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\swg deleted successfully.
      Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MessengerPlus3 deleted successfully.
      Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\msnmsgr deleted successfully.
      Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck deleted successfully.
      Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
      Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\TkBellExe deleted successfully.
      Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MessengerPlus3 deleted successfully.
      ========== COMMANDS ==========
      User's Temp folder emptied.
      User's Internet Explorer cache folder emptied.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\QXE3XPI2\ads[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\QXE3XPI2\ads[4].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\QXE3XPI2\favicon[1].ico scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\QXE3XPI2\signin[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\QXE3XPI2\ToastFull[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\QXE3XPI2\ToastMini[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\QIRVGWR0\01[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\QIRVGWR0\anti-v10[1].jpg scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\QIRVGWR0\OTMoveIt3[1].exe scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\HM8MJYNN\01[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\HM8MJYNN\ADSAdClient31[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\HM8MJYNN\ads[4].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\HM8MJYNN\ads[5].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\HM8MJYNN\affich-12245596-aide-pour-un-rapport-sdfix[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\HM8MJYNN\affich-12250129-rapport-combofix[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\HM8MJYNN\favicon[1].ico scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\HM8MJYNN\im[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\HM8MJYNN\topdepart[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\063BMWS3\ads[3].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\063BMWS3\aide-pour-rapport-sdfix-t600[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\063BMWS3\default[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\063BMWS3\favicon[1].ico scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\063BMWS3\InboxLight[1].htm scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
      User's Temporary Internet Files folder emptied.
      Local Service Temp folder emptied.
      File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
      Local Service Temporary Internet Files folder emptied.
      Network Service Temp folder emptied.
      Network Service Temporary Internet Files folder emptied.
      File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_d8.dat scheduled to be deleted on reboot.
      Windows Temp folder emptied.
      Java cache emptied.
      FireFox cache emptied.
      Temp folders emptied.
      Explorer started successfully

      OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04302009_204311
      0
  2. Salut,

    commences par ceci pour voir ce qu'il en est,avoir un diagnostic précis et donc repérer les infections possibles et les neutraliser:

    Télécharges et installes le logiciel de diagnostic :

    ici Hijackthis
    ou ici Hijackthis
    ou ici Hijackthis

    1- Cliques sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'installation .
    A la fin de l'installe , le prg ce lance automatiquement : fermes le en cliquant sur la croix rouge .
    Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
    "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

    tuto pour utilisation :(merci balltrap34)
    Regardes ici, c'est parfaitement expliqué en images ,

    2- !! Déconnectes toi et fermes toute tes applications en cours !!

    Cliques sur le raccourci du bureau pour lancer le prg :

    S'il ne se lance pas clique ici

    fais un scan HijackThis en cliquant sur : "Do a system scan and save a logfile"

    --->copies-colles le rapport généré pour analyse
    0
    1. voici mon rapport hijackthis
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:22:46, on 30/04/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16827)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
      C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
      C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Windows Live\Toolbar\wltuser.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\WINDOWS\explorer.exe
      C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus\HiJackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
      O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
      O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
      O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://express.foto.com/ImageUploader5.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
      O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://www.ma-config.com/activex/hardwaredetection_3_1_2_0.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\WINDOWS\system32\Skype4COM.dll
      O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
      O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
      O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
      0
      1. Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

        Télécharges :
        Malwarebytes ou :
        Malwarebytes

        * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

        (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

        * Potasses le Tuto pour te familiariser avec le prg :

        ( cela dit, il est très simple d'utilisation ).

        relance malwarebytes en suivant scrupuleusement ces consignes :

        ! Déconnecte toi et ferme toutes applications en cours !

        * Lance Malwarebyte's .

        Fais un examen dit "Complet" .

        --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
        --> à la fin tu cliques sur "résultat" .
        --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

        Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

        Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

        0
        1. Malwarebytes' Anti-Malware 1.36
          Version de la base de données: 2064
          Windows 5.1.2600 Service Pack 3

          01/05/2009 20:37:46
          mbam-log-2009-05-01 (20-37-46).txt

          Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|)
          Eléments examinés: 165893
          Temps écoulé: 49 minute(s), 35 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 0

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          a Parement le rapport est correct pense tu que je suis debarasser de tout problemes?
          Merci
          0
      2. trop facile je trouve...

        ######## | XP _ Instal & recherche | #######

        Telecharge et install UsbFix (de C_XX & Chiquitine29)

        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectés sans les ouvrir

        # Double clic sur le raccourci UsbFix présent sur ton bureau .

        # Choisi l option 1 ( Recherche )

        # Laisse travailler l outil.

        # Ensuite post le rapport UsbFix.txt qui apparaitra.

        # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

        0
        1. voila le nouveau rapport

          ############################## [ UsbFix V3.016 # Scan ]

          # User : Cécilia (Administrateurs) # MON_PC
          # Update on 02/05/09 by Chiquitine29, C_XX & Chimay8
          # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
          # Start at: 18:24:14 | 02/05/2009

          # Intel(R) Pentium(R) D CPU 2.66GHz
          # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
          # Internet Explorer 7.0.5730.13
          # Windows Firewall Status : Disabled
          # AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]
          # FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T

          # C:\ # Disque fixe local # 149,04 Go (77,98 Go free) # NTFS
          # D:\ # Disque CD-ROM
          # E:\ # Disque amovible
          # F:\ # Disque amovible
          # G:\ # Disque amovible
          # H:\ # Disque amovible
          # I:\ # Disque amovible

          ############################## [ Processus actifs ]

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
          C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
          C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\system32\wbem\wmiapsrv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
          C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Windows Live\Toolbar\wltuser.exe
          C:\WINDOWS\system32\NOTEPAD.EXE
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          ################## [ Registre # Startup ]

          HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
          HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
          HKCU_Main: "Start Page"="https://www.google.fr/?gws_rd=ssl"
          HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
          HKLM_logon: "DefaultUserName"="Cécilia"
          HKLM_logon: "AltDefaultUserName"="Cécilia"
          HKLM_Run: ISUSPM Startup=C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
          HKLM_Run: BluetoothAuthenticationAgent=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
          HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          HKLM_Run: RTHDCPL=RTHDCPL.EXE
          HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          HKLM_Run: nwiz=nwiz.exe /install
          HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
          HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
          HKCU_Run: ccleaner="C:\Program Files\CCleaner\CCleaner.exe" /AUTO
          HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

          ################## [ Informations ]

          ################## [ Fichiers # Dossiers infectieux ]

          ################## [ Registre # Clés Run infectieuses ]

          ################## [ Registre # Mountpoints2 ]

          # -> Not Found !

          ################## [ ! Fin du rapport # UsbFix V3.016 ! ]
          0
      3. tu n as aucune clé usb ni mp3 ?
        0
        1. non je n'ai rien de tout ca uniquement la souris sans fil branché sur le port usb
          0
      4. relance usbfix puis desinstallation

        ensuite

        > Télécharge Dr Web CureIt sur ton Bureau :

        - Double clique <drweb-cureit.exe> et ensuite clique sur <Analyse>;

        - Clique <Ok> à l'invite de l'analyse rapide. S'il trouve des processus infectés alors clique le bouton <Oui>.
        Note : une fenêtre s'ouvrira avec options pour "Commander" ou "50% de réduction" : Quitte en cliquant le "X".
        - Lorsque le scan rapide est terminé, clique sur le menu <Options> puis <Changer la configuration> ; Choisis l'onglet <Scanner>, et décoche <Analyse heuristique>. Clique ensuite sur <Ok>.
        - De retour à la fenêtre principale : clique pour activer <Analyse complète>
        - Clique le bouton avec flèche verte sur la droite, et le scan débutera.
        - Clique <Oui> pour tout à l'invite "Désinfecter ?" lorsqu'un fichier est détecté, et ensuite clique "Désinfecter".
        - Lorsque le scan sera complété, regarde si tu peux cliquer sur l' icône, adjacente aux fichiers détectés (plusieurs feuilles l'une sur l'autre). Si oui, alors clique dessus et ensuite clique sur l'icône <Suivant>, au dessous, et choisis <Déplacer en quarantaine l'objet indésirable>.
        - Du menu principal de l'outil, au haut à gauche, clique sur le menu <Fichier> et choisis <Enregistrer le rapport>. Sauvegarde le rapport sur ton Bureau. Ce dernier se nommera DrWeb.csv
        - Ferme Dr.Web Cureit
        - Redémarre ton ordi (important car certains fichiers peuvent être déplacés/réparés au redémarrage).
        - Suite au redémarrage, poste (Copie/Colle) le contenu du rapport de Dr.Web dans ta prochaine réponse.
        0
        1. voivi le rapport de dr.web

          ComboFix.exe/data002\32788R22FWJFW\psexec.cfexe C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus\ComboFix.exe/data002 Program.PsExec.171
          data002 C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus L'archive contient des éléments infectés
          ComboFix.exe C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus Conteneur comporte des objets infectés
          SDFix.exe\SDFix\apps\Process.exe C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus\SDFix.exe Tool.Prockill
          SDFix.exe\SDFix\apps\HPFix.reg C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus\SDFix.exe Trojan.StartPage.1505
          SDFix.exe\SDFix\apps\HPFix2.reg C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus\SDFix.exe Trojan.StartPage.1505
          SDFix.exe C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus L'archive contient des éléments infectés
          Process.exe C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus\MSNFix\incl Tool.Prockill
          UsbFix[1].exe\data013 C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\VUVCRCDB\UsbFix[1].exe Tool.Prockill
          UsbFix[1].exe C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\VUVCRCDB Conteneur comporte des objets infectés
          HPFix.reg C:\SDFix\apps Trojan.StartPage.1505 Supprimé.
          HPFix2.reg C:\SDFix\apps Trojan.StartPage.1505 Supprimé.
          Process.exe C:\SDFix\apps Tool.Prockill
          A0006888.exe\SmitfraudFix\Process.exe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP29\A0006888.exe Tool.Prockill
          A0006888.exe\SmitfraudFix\restart.exe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP29\A0006888.exe Tool.ShutDown.14
          A0006888.exe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP29 L'archive contient des éléments infectés
          A0013316.exe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87 Tool.Prockill
          A0013355.exe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87 Tool.Prockill
          A0013385.reg C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87 Trojan.StartPage.1505 Supprimé.
          A0013386.reg C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87 Trojan.StartPage.1505 Supprimé.
          A0013450.exe/data002\32788R22FWJFW\psexec.cfexe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87\A0013450.exe/data002 Program.PsExec.171
          data002 C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87 L'archive contient des éléments infectés
          A0013450.exe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87 Conteneur comporte des objets infectés
          A0013526.EXE C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP88 Program.PsExec.170
          A0013641.reg C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP90 Trojan.StartPage.1505 Supprimé.
          A0013642.reg C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP90 Trojan.StartPage.1505 Supprimé.

          Apparement pas mal de trojans et autre ont ete supprimé
          est ce que je suis debarassé de toutes infections?
          0
        2. voivi le rapport de dr.web

          ComboFix.exe/data002\32788R22FWJFW\psexec.cfexe C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus\ComboFix.exe/data002 Program.PsExec.171
          data002 C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus L'archive contient des éléments infectés
          ComboFix.exe C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus Conteneur comporte des objets infectés
          SDFix.exe\SDFix\apps\Process.exe C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus\SDFix.exe Tool.Prockill
          SDFix.exe\SDFix\apps\HPFix.reg C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus\SDFix.exe Trojan.StartPage.1505
          SDFix.exe\SDFix\apps\HPFix2.reg C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus\SDFix.exe Trojan.StartPage.1505
          SDFix.exe C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus L'archive contient des éléments infectés
          Process.exe C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus\MSNFix\incl Tool.Prockill
          UsbFix[1].exe\data013 C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\VUVCRCDB\UsbFix[1].exe Tool.Prockill
          UsbFix[1].exe C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\VUVCRCDB Conteneur comporte des objets infectés
          HPFix.reg C:\SDFix\apps Trojan.StartPage.1505 Supprimé.
          HPFix2.reg C:\SDFix\apps Trojan.StartPage.1505 Supprimé.
          Process.exe C:\SDFix\apps Tool.Prockill
          A0006888.exe\SmitfraudFix\Process.exe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP29\A0006888.exe Tool.Prockill
          A0006888.exe\SmitfraudFix\restart.exe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP29\A0006888.exe Tool.ShutDown.14
          A0006888.exe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP29 L'archive contient des éléments infectés
          A0013316.exe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87 Tool.Prockill
          A0013355.exe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87 Tool.Prockill
          A0013385.reg C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87 Trojan.StartPage.1505 Supprimé.
          A0013386.reg C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87 Trojan.StartPage.1505 Supprimé.
          A0013450.exe/data002\32788R22FWJFW\psexec.cfexe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87\A0013450.exe/data002 Program.PsExec.171
          data002 C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87 L'archive contient des éléments infectés
          A0013450.exe C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP87 Conteneur comporte des objets infectés
          A0013526.EXE C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP88 Program.PsExec.170
          A0013641.reg C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP90 Trojan.StartPage.1505 Supprimé.
          A0013642.reg C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP90 Trojan.StartPage.1505 Supprimé.

          Apparement pas mal de trojans et autre ont ete supprimé
          est ce que je suis debarassé de toutes infections?
          0
        3. desolé pour le doublon mais mon pc beug encor pas mal......
          0
      5. bonjour on va voir ca :

        Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

        ! Déconnecte toi et ferme toutes tes applications en cours !

        Double-clique sur " RSIT.exe " pour le lancer .

        -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

        * Devant l'option "List files/folders created ..." , tu choisis : 2 months

        * clique ensuite sur " Continue " pour lancer l'analyse ...

        -> laisse faire le scan et ne touche pas au PC ...

        Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

        Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

        Important : poste un rapport, puis l'autre dans la réponse suivante
        Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

        ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
        0
        1. 1er rapport log.txt

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Cécilia at 2009-05-03 12:27:05
          Microsoft Windows XP Édition familiale Service Pack 3
          System drive C: has 80 GB (52%) free of 153 GB
          Total RAM: 1023 MB (65% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 12:27:19, on 03/05/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16827)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
          C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
          C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\wbem\wmiapsrv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
          C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Windows Live\Toolbar\wltuser.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\VUVCRCDB\RSIT[1].exe
          C:\Documents and Settings\Cécilia\Bureau\prevention et supression des virus\Cécilia.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
          O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
          O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
          O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
          O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
          O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://express.foto.com/ImageUploader5.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
          O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
          O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://www.ma-config.com/activex/hardwaredetection_3_1_2_0.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\WINDOWS\system32\Skype4COM.dll
          O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
          O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
          O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
          O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
          O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
          0
        2. et le 2eme je l'ai trouver dans le fichier c:\rist il n'y avais que celui la appeler info.txt mais je ne suis pas sur que se soit le bon (date)

          info.txt logfile of random's system information tool 1.06 2009-05-02 18:06:45

          ======Uninstall list======

          -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
          -->C:\WINDOWS\UNRecode.exe /UNINSTALL
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E5ABA5FD-EE3D-4F15-895D-B32321E6C96B}\setup.exe" -l0x40c
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe -q
          Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002}
          Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
          Ad-remover-->C:\Documents and Settings\Cécilia\Mes documents\Uninstal.exe
          Advanced RAR Password Recovery (remove only)-->C:\Program Files\ElcomSoft\ARPR\uninstall.exe
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
          Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
          Barre d'outils MSN-->C:\Program Files\MSN Toolbar\01.01.2607.0\fr\mtbs.exe c
          Bluesoleil2.7.0.8 VoIP Release 070930-->MsiExec.exe /X{3A56CA23-F10D-4755-BD25-57578CBFD59C}
          Browser Optimizer Milehighads-->C:\WINDOWS\system32\milehighads-remove.exe
          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
          Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
          Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
          Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
          Creative Live! Cam Vista IM Driver (1.00.07.0401)-->C:\WINDOWS\CtDrvIns.exe -uninstall -script VF0260.uns -unsext NT -plugin V0260Pin.dll -pluginres CtCamPin.crl
          Creative Software AutoUpdate-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c /remove
          Creative System Information-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c /remove
          Creative WebCam Center-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E5ABA5FD-EE3D-4F15-895D-B32321E6C96B}\setup.exe" -l0x40c /remove
          DriverAgent by TouchStone Software-->RunDll32.exe advpack.dll,LaunchINFSection driveragent_exe.inf,TVICHW32Remove
          eMule-->"C:\Program Files\eMule\Uninstall.exe"
          EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
          EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
          EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5DA7BC15-18D3-41A0-9F59-838DA3EAEF17}\SETUP.EXE" -l0x40c UNINST
          EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
          EPSON Image Clip Palette-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{314F6D08-A8B7-11D8-8446-0050BA1D384D}\Setup.exe" -l0x40c -u
          EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
          EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
          EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
          EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
          ESDX4800_4200 Guide util.-->C:\Program Files\EPSON\TPMANUAL\ESDX4800_4200\USE_G\DOCUNINS.EXE
          EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
          EvilLyrics-->"C:\Program Files\EvilLyrics\uninst.exe"
          Freeplayer-->C:\Program Files\Freeplayer\Uninstall.exe
          Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
          Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
          Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
          Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
          High Definition Audio Driver Package - KB888111-->C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe
          HijackThis 2.0.2-->"C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\JG2KXB6V\HijackThis.exe" /uninstall
          HomePlayer 1.5.6b-->C:\Program Files\HomePlayer\uninst.exe
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
          Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
          HP Product Detection-->MsiExec.exe /X{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
          Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
          Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
          Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
          Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
          Kaspersky Online Scanner-->C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
          LG PC Suite-->C:\Program Files\InstallShield Installation Information\{993960EE-CA4D-443F-8F88-E24260DD5FD2}\setup.exe -runfromtemp -l0x040c -removeonly
          LG USB Modem driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C3ABE126-2BB2-4246-BFE1-6797679B3579}\setup.exe" -l0x40c LG -removeonly
          LimeWire 4.18.6-->"C:\Program Files\LimeWire\uninstall.exe"
          Ma-Config.com-->MsiExec.exe /X{560BD6E0-0BA6-43AF-B423-E1DF4D2EB3C3}
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Manuel d'utilisation de Creative Live! Cam Vista IM (Français)-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Creative\Creative Live! Cam Vista IM\Manuel d'utilisation de Creative Live! Cam Vista IM\French\CTManual.isu"
          Messenger Plus! 3-->"C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /Remove
          Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
          Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
          Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
          Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
          Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
          Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
          Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
          Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
          Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
          Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
          Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
          Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
          Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
          Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
          Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
          Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
          Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0120-040C-0000-0000000FF1CE}
          Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
          Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
          Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
          Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
          Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
          Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
          Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
          Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
          Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
          Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
          Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
          Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
          Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
          Microsoft Office XP Professional with FrontPage-->MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
          Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
          Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
          Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
          Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
          Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
          Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Microsoft WorldWide Telescope-->MsiExec.exe /I{3F692FA9-348B-4264-B4EA-DE6BFA45D8AE}
          Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
          Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
          Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
          MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          Nero 7 Demo-->MsiExec.exe /I{84B2CF01-194D-2284-B313-F2E0D78D1036}
          neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
          NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
          Odebit Multimédia V3.2-->"C:\Program Files\Odebit Multimédia\V3.2\unins000.exe"
          ONES Trial (F)-->C:\WINDOWS\InZU31.exe /U:C:\Program Files\ONES Trial (F)\Uninstall.inz /L:f /K:ONES(F)
          OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
          Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          QuickTime Alternative 2.1.1-->"C:\Program Files\QuickTime Alternative\unins000.exe"
          Real Alternative 1.60-->"C:\Program Files\Real Alternative\unins000.exe"
          RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
          Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
          SafeCast Shared Components-->C:\Program Files\Fichiers communs\Macrovision Shared\SafeCast\Install\CDAC13BA.EXE /uninstall
          SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
          SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
          Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
          SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
          SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
          Samsung PC Studio 3 USB Driver Installer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -l0x40c -removeonly
          Samsung PC Studio 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x40c -removeonly
          SecondLife (remove only)-->"C:\Program Files\SecondLife\uninst.exe"
          Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
          Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
          Security Update for 2007 Microsoft Office System (KB960003)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F04F8702-18D0-458D-921E-146FB7CD38CF}
          Security Update for Microsoft Office Excel 2007 (KB959997)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {9EAC3AEC-5C81-4856-A05B-DE9DC236D740}
          Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
          Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
          Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
          Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
          Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
          Security Update for Visio 2007 (KB947590)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
          Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
          SLD Codec Pack-->C:\Program Files\SLD Codec Pack\uninstall.exe
          Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
          SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
          Sunbelt Personal Firewall-->MsiExec.exe /X{82B1150E-9B37-49FC-83EB-D52197D900D0}
          SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
          TypingMaster Pro-->"C:\Program Files\TypingMaster\unins000.exe"
          Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
          Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
          Update for Outlook 2007 Junk Email Filter (kb968503)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5DD98950-4D10-4B79-8BF6-59726705207D}
          VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
          VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
          Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
          Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
          Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
          Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
          Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
          Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
          Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
          Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
          Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
          Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
          XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

          =====HijackThis Backups=====

          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) [2009-03-30]

          ======Security center information======

          AV: Avira AntiVir PersonalEdition Classic
          FW: Sunbelt Personal Firewall

          ======System event log======

          Computer Name: MON_PC
          Event Code: 6009
          Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 3 Multiprocessor Free.

          Record Number: 1254
          Source Name: EventLog
          Time Written: 20090204144908.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 6006
          Message: Le service d'Enregistrement d'événement a été arrêté.

          Record Number: 1253
          Source Name: EventLog
          Time Written: 20090204144816.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 1074
          Message: Le processus winlogon.exe a initialisé le redémarrage de MON_PC pour la raison suivante : Aucun titre à cette raison n'a pu être trouvé

          Raison mineure : 0x2

          Type d'arrêt : redémarrer.

          Commentaire : avast! Setup requires Windows to be restarted.

          Record Number: 1252
          Source Name: USER32
          Time Written: 20090204144758.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: MON_PC
          Event Code: 7036
          Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.

          Record Number: 1251
          Source Name: Service Control Manager
          Time Written: 20090204144707.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 7036
          Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.

          Record Number: 1250
          Source Name: Service Control Manager
          Time Written: 20090204144701.000000+060
          Event Type: Informations
          User:

          =====Application event log=====

          Computer Name: MON_PC
          Event Code: 102
          Message: msnmsgr (2536) \\.\C:\Documents and Settings\Cécilia\Local Settings\Application Data\Microsoft\Messenger\ceciliaa01@hotmail.com\SharingMetadata\Working\database_E624_5AA7_245A_7A8F\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

          Record Number: 5
          Source Name: ESENT
          Time Written: 20081215135242.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 100
          Message: msnmsgr (2536) Le moteur de base de données 5.01.2600.5512 est démarré.

          Record Number: 4
          Source Name: ESENT
          Time Written: 20081215135242.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 1002
          Message: Application bloquée WINWORD.EXE, version 12.0.6331.5000, module bloqué hungapp, version 0.0.0.0, adresse de blocage 0x00000000.

          Record Number: 3
          Source Name: Application Hang
          Time Written: 20081215125949.000000+060
          Event Type: erreur
          User:

          Computer Name: MON_PC
          Event Code: 101
          Message: MsnMsgr (272) Le moteur de base de données est arrêté.

          Record Number: 2
          Source Name: ESENT
          Time Written: 20081215124927.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 103
          Message: MsnMsgr (272) \\.\C:\Documents and Settings\Cécilia\Local Settings\Application Data\Microsoft\Messenger\ceciliaa01@hotmail.com\SharingMetadata\Working\database_E624_5AA7_245A_7A8F\dfsr.db: Le moteur de base de données a arrêté une instance (0).

          Record Number: 1
          Source Name: ESENT
          Time Written: 20081215124927.000000+060
          Event Type: Informations
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Samsung\Samsung PC Studio 3
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=15
          "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 7, GenuineIntel
          "PROCESSOR_REVISION"=0407
          "NUMBER_OF_PROCESSORS"=2
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP

          -----------------EOF-----------------
          0
        3. et le 2eme je l'ai trouver dans le fichier c:\rist il n'y avais que celui la appeler info.txt mais je ne suis pas sur que se soit le bon (date)

          info.txt logfile of random's system information tool 1.06 2009-05-02 18:06:45

          ======Uninstall list======

          -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
          -->C:\WINDOWS\UNRecode.exe /UNINSTALL
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E5ABA5FD-EE3D-4F15-895D-B32321E6C96B}\setup.exe" -l0x40c
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe -q
          Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002}
          Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
          Ad-remover-->C:\Documents and Settings\Cécilia\Mes documents\Uninstal.exe
          Advanced RAR Password Recovery (remove only)-->C:\Program Files\ElcomSoft\ARPR\uninstall.exe
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
          Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
          Barre d'outils MSN-->C:\Program Files\MSN Toolbar\01.01.2607.0\fr\mtbs.exe c
          Bluesoleil2.7.0.8 VoIP Release 070930-->MsiExec.exe /X{3A56CA23-F10D-4755-BD25-57578CBFD59C}
          Browser Optimizer Milehighads-->C:\WINDOWS\system32\milehighads-remove.exe
          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
          Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
          Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
          Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
          Creative Live! Cam Vista IM Driver (1.00.07.0401)-->C:\WINDOWS\CtDrvIns.exe -uninstall -script VF0260.uns -unsext NT -plugin V0260Pin.dll -pluginres CtCamPin.crl
          Creative Software AutoUpdate-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c /remove
          Creative System Information-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c /remove
          Creative WebCam Center-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E5ABA5FD-EE3D-4F15-895D-B32321E6C96B}\setup.exe" -l0x40c /remove
          DriverAgent by TouchStone Software-->RunDll32.exe advpack.dll,LaunchINFSection driveragent_exe.inf,TVICHW32Remove
          eMule-->"C:\Program Files\eMule\Uninstall.exe"
          EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
          EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
          EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5DA7BC15-18D3-41A0-9F59-838DA3EAEF17}\SETUP.EXE" -l0x40c UNINST
          EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
          EPSON Image Clip Palette-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{314F6D08-A8B7-11D8-8446-0050BA1D384D}\Setup.exe" -l0x40c -u
          EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
          EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
          EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
          EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
          ESDX4800_4200 Guide util.-->C:\Program Files\EPSON\TPMANUAL\ESDX4800_4200\USE_G\DOCUNINS.EXE
          EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
          EvilLyrics-->"C:\Program Files\EvilLyrics\uninst.exe"
          Freeplayer-->C:\Program Files\Freeplayer\Uninstall.exe
          Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
          Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
          Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
          Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
          High Definition Audio Driver Package - KB888111-->C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe
          HijackThis 2.0.2-->"C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\JG2KXB6V\HijackThis.exe" /uninstall
          HomePlayer 1.5.6b-->C:\Program Files\HomePlayer\uninst.exe
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
          Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
          HP Product Detection-->MsiExec.exe /X{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
          Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
          Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
          Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
          Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
          Kaspersky Online Scanner-->C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
          LG PC Suite-->C:\Program Files\InstallShield Installation Information\{993960EE-CA4D-443F-8F88-E24260DD5FD2}\setup.exe -runfromtemp -l0x040c -removeonly
          LG USB Modem driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C3ABE126-2BB2-4246-BFE1-6797679B3579}\setup.exe" -l0x40c LG -removeonly
          LimeWire 4.18.6-->"C:\Program Files\LimeWire\uninstall.exe"
          Ma-Config.com-->MsiExec.exe /X{560BD6E0-0BA6-43AF-B423-E1DF4D2EB3C3}
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Manuel d'utilisation de Creative Live! Cam Vista IM (Français)-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Creative\Creative Live! Cam Vista IM\Manuel d'utilisation de Creative Live! Cam Vista IM\French\CTManual.isu"
          Messenger Plus! 3-->"C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /Remove
          Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
          Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
          Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
          Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
          Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
          Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
          Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
          Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
          Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
          Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
          Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
          Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
          Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
          Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
          Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
          Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
          Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0120-040C-0000-0000000FF1CE}
          Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
          Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
          Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
          Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
          Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
          Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
          Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
          Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
          Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
          Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
          Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
          Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
          Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
          Microsoft Office XP Professional with FrontPage-->MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
          Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
          Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
          Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
          Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
          Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
          Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Microsoft WorldWide Telescope-->MsiExec.exe /I{3F692FA9-348B-4264-B4EA-DE6BFA45D8AE}
          Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
          Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
          Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
          MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          Nero 7 Demo-->MsiExec.exe /I{84B2CF01-194D-2284-B313-F2E0D78D1036}
          neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
          NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
          Odebit Multimédia V3.2-->"C:\Program Files\Odebit Multimédia\V3.2\unins000.exe"
          ONES Trial (F)-->C:\WINDOWS\InZU31.exe /U:C:\Program Files\ONES Trial (F)\Uninstall.inz /L:f /K:ONES(F)
          OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
          Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          QuickTime Alternative 2.1.1-->"C:\Program Files\QuickTime Alternative\unins000.exe"
          Real Alternative 1.60-->"C:\Program Files\Real Alternative\unins000.exe"
          RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
          Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
          SafeCast Shared Components-->C:\Program Files\Fichiers communs\Macrovision Shared\SafeCast\Install\CDAC13BA.EXE /uninstall
          SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
          SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
          Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
          SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
          SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
          Samsung PC Studio 3 USB Driver Installer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -l0x40c -removeonly
          Samsung PC Studio 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x40c -removeonly
          SecondLife (remove only)-->"C:\Program Files\SecondLife\uninst.exe"
          Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
          Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
          Security Update for 2007 Microsoft Office System (KB960003)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F04F8702-18D0-458D-921E-146FB7CD38CF}
          Security Update for Microsoft Office Excel 2007 (KB959997)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {9EAC3AEC-5C81-4856-A05B-DE9DC236D740}
          Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
          Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
          Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
          Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
          Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
          Security Update for Visio 2007 (KB947590)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
          Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
          SLD Codec Pack-->C:\Program Files\SLD Codec Pack\uninstall.exe
          Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
          SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
          Sunbelt Personal Firewall-->MsiExec.exe /X{82B1150E-9B37-49FC-83EB-D52197D900D0}
          SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
          TypingMaster Pro-->"C:\Program Files\TypingMaster\unins000.exe"
          Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
          Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
          Update for Outlook 2007 Junk Email Filter (kb968503)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5DD98950-4D10-4B79-8BF6-59726705207D}
          VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
          VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
          Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
          Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
          Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
          Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
          Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
          Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
          Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
          Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
          Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
          Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
          XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

          =====HijackThis Backups=====

          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) [2009-03-30]

          ======Security center information======

          AV: Avira AntiVir PersonalEdition Classic
          FW: Sunbelt Personal Firewall

          ======System event log======

          Computer Name: MON_PC
          Event Code: 6009
          Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 3 Multiprocessor Free.

          Record Number: 1254
          Source Name: EventLog
          Time Written: 20090204144908.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 6006
          Message: Le service d'Enregistrement d'événement a été arrêté.

          Record Number: 1253
          Source Name: EventLog
          Time Written: 20090204144816.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 1074
          Message: Le processus winlogon.exe a initialisé le redémarrage de MON_PC pour la raison suivante : Aucun titre à cette raison n'a pu être trouvé

          Raison mineure : 0x2

          Type d'arrêt : redémarrer.

          Commentaire : avast! Setup requires Windows to be restarted.

          Record Number: 1252
          Source Name: USER32
          Time Written: 20090204144758.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: MON_PC
          Event Code: 7036
          Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.

          Record Number: 1251
          Source Name: Service Control Manager
          Time Written: 20090204144707.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 7036
          Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.

          Record Number: 1250
          Source Name: Service Control Manager
          Time Written: 20090204144701.000000+060
          Event Type: Informations
          User:

          =====Application event log=====

          Computer Name: MON_PC
          Event Code: 102
          Message: msnmsgr (2536) \\.\C:\Documents and Settings\Cécilia\Local Settings\Application Data\Microsoft\Messenger\ceciliaa01@hotmail.com\SharingMetadata\Working\database_E624_5AA7_245A_7A8F\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

          Record Number: 5
          Source Name: ESENT
          Time Written: 20081215135242.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 100
          Message: msnmsgr (2536) Le moteur de base de données 5.01.2600.5512 est démarré.

          Record Number: 4
          Source Name: ESENT
          Time Written: 20081215135242.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 1002
          Message: Application bloquée WINWORD.EXE, version 12.0.6331.5000, module bloqué hungapp, version 0.0.0.0, adresse de blocage 0x00000000.

          Record Number: 3
          Source Name: Application Hang
          Time Written: 20081215125949.000000+060
          Event Type: erreur
          User:

          Computer Name: MON_PC
          Event Code: 101
          Message: MsnMsgr (272) Le moteur de base de données est arrêté.

          Record Number: 2
          Source Name: ESENT
          Time Written: 20081215124927.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 103
          Message: MsnMsgr (272) \\.\C:\Documents and Settings\Cécilia\Local Settings\Application Data\Microsoft\Messenger\ceciliaa01@hotmail.com\SharingMetadata\Working\database_E624_5AA7_245A_7A8F\dfsr.db: Le moteur de base de données a arrêté une instance (0).

          Record Number: 1
          Source Name: ESENT
          Time Written: 20081215124927.000000+060
          Event Type: Informations
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Samsung\Samsung PC Studio 3
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=15
          "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 7, GenuineIntel
          "PROCESSOR_REVISION"=0407
          "NUMBER_OF_PROCESSORS"=2
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP

          -----------------EOF-----------------
          0
        4. et le 2eme je l'ai trouver dans le fichier c:\rist il n'y avais que celui la appeler info.txt mais je ne suis pas sur que se soit le bon (date)

          info.txt logfile of random's system information tool 1.06 2009-05-02 18:06:45

          ======Uninstall list======

          -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
          -->C:\WINDOWS\UNRecode.exe /UNINSTALL
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E5ABA5FD-EE3D-4F15-895D-B32321E6C96B}\setup.exe" -l0x40c
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe -q
          Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002}
          Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
          Ad-remover-->C:\Documents and Settings\Cécilia\Mes documents\Uninstal.exe
          Advanced RAR Password Recovery (remove only)-->C:\Program Files\ElcomSoft\ARPR\uninstall.exe
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
          Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
          Barre d'outils MSN-->C:\Program Files\MSN Toolbar\01.01.2607.0\fr\mtbs.exe c
          Bluesoleil2.7.0.8 VoIP Release 070930-->MsiExec.exe /X{3A56CA23-F10D-4755-BD25-57578CBFD59C}
          Browser Optimizer Milehighads-->C:\WINDOWS\system32\milehighads-remove.exe
          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
          Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
          Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
          Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
          Creative Live! Cam Vista IM Driver (1.00.07.0401)-->C:\WINDOWS\CtDrvIns.exe -uninstall -script VF0260.uns -unsext NT -plugin V0260Pin.dll -pluginres CtCamPin.crl
          Creative Software AutoUpdate-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c /remove
          Creative System Information-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c /remove
          Creative WebCam Center-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E5ABA5FD-EE3D-4F15-895D-B32321E6C96B}\setup.exe" -l0x40c /remove
          DriverAgent by TouchStone Software-->RunDll32.exe advpack.dll,LaunchINFSection driveragent_exe.inf,TVICHW32Remove
          eMule-->"C:\Program Files\eMule\Uninstall.exe"
          EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
          EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
          EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5DA7BC15-18D3-41A0-9F59-838DA3EAEF17}\SETUP.EXE" -l0x40c UNINST
          EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
          EPSON Image Clip Palette-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{314F6D08-A8B7-11D8-8446-0050BA1D384D}\Setup.exe" -l0x40c -u
          EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
          EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
          EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
          EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
          ESDX4800_4200 Guide util.-->C:\Program Files\EPSON\TPMANUAL\ESDX4800_4200\USE_G\DOCUNINS.EXE
          EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
          EvilLyrics-->"C:\Program Files\EvilLyrics\uninst.exe"
          Freeplayer-->C:\Program Files\Freeplayer\Uninstall.exe
          Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
          Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
          Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
          Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
          High Definition Audio Driver Package - KB888111-->C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe
          HijackThis 2.0.2-->"C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\JG2KXB6V\HijackThis.exe" /uninstall
          HomePlayer 1.5.6b-->C:\Program Files\HomePlayer\uninst.exe
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
          Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
          HP Product Detection-->MsiExec.exe /X{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
          Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
          Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
          Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
          Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
          Kaspersky Online Scanner-->C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
          LG PC Suite-->C:\Program Files\InstallShield Installation Information\{993960EE-CA4D-443F-8F88-E24260DD5FD2}\setup.exe -runfromtemp -l0x040c -removeonly
          LG USB Modem driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C3ABE126-2BB2-4246-BFE1-6797679B3579}\setup.exe" -l0x40c LG -removeonly
          LimeWire 4.18.6-->"C:\Program Files\LimeWire\uninstall.exe"
          Ma-Config.com-->MsiExec.exe /X{560BD6E0-0BA6-43AF-B423-E1DF4D2EB3C3}
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Manuel d'utilisation de Creative Live! Cam Vista IM (Français)-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Creative\Creative Live! Cam Vista IM\Manuel d'utilisation de Creative Live! Cam Vista IM\French\CTManual.isu"
          Messenger Plus! 3-->"C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /Remove
          Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
          Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
          Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
          Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
          Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
          Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
          Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
          Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
          Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
          Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
          Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
          Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
          Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
          Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
          Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
          Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
          Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0120-040C-0000-0000000FF1CE}
          Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
          Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
          Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
          Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
          Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
          Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
          Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
          Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
          Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
          Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
          Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
          Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
          Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
          Microsoft Office XP Professional with FrontPage-->MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
          Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
          Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
          Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
          Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
          Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
          Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Microsoft WorldWide Telescope-->MsiExec.exe /I{3F692FA9-348B-4264-B4EA-DE6BFA45D8AE}
          Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
          Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
          Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
          MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          Nero 7 Demo-->MsiExec.exe /I{84B2CF01-194D-2284-B313-F2E0D78D1036}
          neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
          NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
          Odebit Multimédia V3.2-->"C:\Program Files\Odebit Multimédia\V3.2\unins000.exe"
          ONES Trial (F)-->C:\WINDOWS\InZU31.exe /U:C:\Program Files\ONES Trial (F)\Uninstall.inz /L:f /K:ONES(F)
          OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
          Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          QuickTime Alternative 2.1.1-->"C:\Program Files\QuickTime Alternative\unins000.exe"
          Real Alternative 1.60-->"C:\Program Files\Real Alternative\unins000.exe"
          RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
          Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
          SafeCast Shared Components-->C:\Program Files\Fichiers communs\Macrovision Shared\SafeCast\Install\CDAC13BA.EXE /uninstall
          SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
          SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
          Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
          SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
          SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
          Samsung PC Studio 3 USB Driver Installer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -l0x40c -removeonly
          Samsung PC Studio 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x40c -removeonly
          SecondLife (remove only)-->"C:\Program Files\SecondLife\uninst.exe"
          Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
          Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
          Security Update for 2007 Microsoft Office System (KB960003)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F04F8702-18D0-458D-921E-146FB7CD38CF}
          Security Update for Microsoft Office Excel 2007 (KB959997)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {9EAC3AEC-5C81-4856-A05B-DE9DC236D740}
          Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
          Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
          Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
          Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
          Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
          Security Update for Visio 2007 (KB947590)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
          Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
          SLD Codec Pack-->C:\Program Files\SLD Codec Pack\uninstall.exe
          Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
          SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
          Sunbelt Personal Firewall-->MsiExec.exe /X{82B1150E-9B37-49FC-83EB-D52197D900D0}
          SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
          TypingMaster Pro-->"C:\Program Files\TypingMaster\unins000.exe"
          Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
          Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
          Update for Outlook 2007 Junk Email Filter (kb968503)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5DD98950-4D10-4B79-8BF6-59726705207D}
          VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
          VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
          Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
          Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
          Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
          Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
          Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
          Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
          Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
          Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
          Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
          Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
          XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

          =====HijackThis Backups=====

          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) [2009-03-30]

          ======Security center information======

          AV: Avira AntiVir PersonalEdition Classic
          FW: Sunbelt Personal Firewall

          ======System event log======

          Computer Name: MON_PC
          Event Code: 6009
          Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 3 Multiprocessor Free.

          Record Number: 1254
          Source Name: EventLog
          Time Written: 20090204144908.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 6006
          Message: Le service d'Enregistrement d'événement a été arrêté.

          Record Number: 1253
          Source Name: EventLog
          Time Written: 20090204144816.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 1074
          Message: Le processus winlogon.exe a initialisé le redémarrage de MON_PC pour la raison suivante : Aucun titre à cette raison n'a pu être trouvé

          Raison mineure : 0x2

          Type d'arrêt : redémarrer.

          Commentaire : avast! Setup requires Windows to be restarted.

          Record Number: 1252
          Source Name: USER32
          Time Written: 20090204144758.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: MON_PC
          Event Code: 7036
          Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.

          Record Number: 1251
          Source Name: Service Control Manager
          Time Written: 20090204144707.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 7036
          Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.

          Record Number: 1250
          Source Name: Service Control Manager
          Time Written: 20090204144701.000000+060
          Event Type: Informations
          User:

          =====Application event log=====

          Computer Name: MON_PC
          Event Code: 102
          Message: msnmsgr (2536) \\.\C:\Documents and Settings\Cécilia\Local Settings\Application Data\Microsoft\Messenger\ceciliaa01@hotmail.com\SharingMetadata\Working\database_E624_5AA7_245A_7A8F\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

          Record Number: 5
          Source Name: ESENT
          Time Written: 20081215135242.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 100
          Message: msnmsgr (2536) Le moteur de base de données 5.01.2600.5512 est démarré.

          Record Number: 4
          Source Name: ESENT
          Time Written: 20081215135242.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 1002
          Message: Application bloquée WINWORD.EXE, version 12.0.6331.5000, module bloqué hungapp, version 0.0.0.0, adresse de blocage 0x00000000.

          Record Number: 3
          Source Name: Application Hang
          Time Written: 20081215125949.000000+060
          Event Type: erreur
          User:

          Computer Name: MON_PC
          Event Code: 101
          Message: MsnMsgr (272) Le moteur de base de données est arrêté.

          Record Number: 2
          Source Name: ESENT
          Time Written: 20081215124927.000000+060
          Event Type: Informations
          User:

          Computer Name: MON_PC
          Event Code: 103
          Message: MsnMsgr (272) \\.\C:\Documents and Settings\Cécilia\Local Settings\Application Data\Microsoft\Messenger\ceciliaa01@hotmail.com\SharingMetadata\Working\database_E624_5AA7_245A_7A8F\dfsr.db: Le moteur de base de données a arrêté une instance (0).

          Record Number: 1
          Source Name: ESENT
          Time Written: 20081215124927.000000+060
          Event Type: Informations
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Samsung\Samsung PC Studio 3
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=15
          "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 7, GenuineIntel
          "PROCESSOR_REVISION"=0407
          "NUMBER_OF_PROCESSORS"=2
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP

          -----------------EOF-----------------
          0
      6. Désactiver le TeaTimer de Spybot (Merci à Nico):

        Pour désactiver le TeaTimer :
        => Ouvrir Spybot S&D
        => Dans le menu "Mode", séléctionner le mode avancé.
        => Une fenêtre demande confirmation cliquer sur "oui".
        => Une fois le mode avancé actif, ouvrir l'onglet "Outils".
        => Cliquer sur Résident.
        => La partie Résident comporte deux lignes qui sont normalement cochées :
        *Résident "SDHelper" (bloqueur de téléchargements nuisibles pour Internet Explorer) actif.

        * Résident "TeaTimer" (Protection des réglages système fondamentaux) actif.

        => Décocher la ligne TeaTimer.
        => Redémarrer Spybot (le fermer et le réouvrir)
        => Retourner dans le menu Résident et vérifier qu'il soit bien désactivé.

        ensuite


        ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

        ---> Copie (Ctrl+C) le texte suivant ci-dessous :



        :processes
        explorer.exe

        :services
        a0za9ghu

        :files
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk

        :reg
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
        "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"=-
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
        "RTHDCPL"=-
        "nwiz"=-
        "TkBellExe"=-
        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
        "swg"=-
        "msnmsgr"=-
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        "AppInit_DLLS"=""

        :commands
        [purity]
        [emptytemp]
        [start explorer]
        [reboot]


        ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

        ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

        Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
        Accepte en cliquant sur YES.

        ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
        Le nom du rapport correspond au moment de sa création : date_heure.log
        0
        1. Pour la 1ere manip sur spybot, le "TeaTimer etais deja desactiver
          et voici le rapport

          ========== PROCESSES ==========
          Process explorer.exe killed successfully.
          ========== SERVICES/DRIVERS ==========
          Service\Driver a0za9ghu not found.
          Service\Driver key a0za9ghu deleted successfully.
          ========== FILES ==========
          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk moved successfully.
          ========== REGISTRY ==========
          Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} deleted successfully.
          Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\ deleted successfully.
          Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RTHDCPL deleted successfully.
          Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz deleted successfully.
          Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\TkBellExe deleted successfully.
          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\swg deleted successfully.
          Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\msnmsgr deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLS"|"" /E : value set successfully!
          ========== COMMANDS ==========
          User's Temp folder emptied.
          User's Internet Explorer cache folder emptied.
          File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\YY78GHNL\signin[1].htm scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\YY78GHNL\topdepart[1].htm scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\VUVCRCDB\6DJCAM9B2SPCAC8GZN9CAJ3DID6CAO6810ACAAHA1ODCASUJVQKCA3V2DFLCAERUVD5CACKIILYCAR2LRC9CAWWVOM7CA9GIQ7ZCAII7CV2CAED73YKCATSU9X9CAHCN8UICAVA6JQQCA6J16K4CAEI23RW.htm scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\VUVCRCDB\7U7CAS6JUUVCAMR42SLCAYDP25ZCAJSUVYQCAI0BSL8CAXLPP20CAK5H274CANZQ2CMCACR7ACRCAM50QVLCAOHQ1LOCA263XOGCARRYZW2CA4ZA3FJCA22PFXJCA7ZBGQICAKI9MV1CAERSL30CANU5FAT.htm scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\VUVCRCDB\favicon[4].ico scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\TZ7R0QRW\PD8CAM9GGPICAIUF4KXCA1D6UR1CAN8KM1YCAEUIQCLCATSMTBACASAI9M6CAC1Q953CAAOAPX6CAOEVPVHCAOBVKSACAIBJFR6CAR3U1PZCASY1OARCA4MRR1MCASAYPXSCA99FPFQCAMN0JQ8CA40IVT2.htm scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\JNCJN3QZ\affich-12245596-aide-pour-un-rapport-sdfix[1].htm scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\JNCJN3QZ\NE2CAB33R6KCATAHCY2CAZFSY7RCAL67P2YCAPH1SJ7CALOZXM9CA8A4B04CAVDCVTKCAFAP4NKCA7B8AOCCAMSUNA7CAMVZJ66CATTSLN9CAXZL5E1CAVB522KCA1MU9XQCAFKAAY6CATXQL9FCA0ABH67.htm scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\CG4DJ77Y\affich-12250129-rapport-combofix[1].htm scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
          File delete failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
          User's Temporary Internet Files folder emptied.
          Local Service Temp folder emptied.
          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
          Local Service Temporary Internet Files folder emptied.
          Network Service Temp folder emptied.
          Network Service Temporary Internet Files folder emptied.
          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_188.dat scheduled to be deleted on reboot.
          Windows Temp folder emptied.
          Java cache emptied.
          FireFox cache emptied.
          Temp folders emptied.
          Explorer started successfully

          OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05032009_125403

          Files moved on Reboot...
          File move failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\YY78GHNL\signin[1].htm scheduled to be moved on reboot.
          File move failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\YY78GHNL\topdepart[1].htm scheduled to be moved on reboot.
          C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\VUVCRCDB\6DJCAM9B2SPCAC8GZN9CAJ3DID6CAO6810ACAAHA1ODCASUJVQKCA3V2DFLCAERUVD5CACKIILYCAR2LRC9CAWWVOM7CA9GIQ7ZCAII7CV2CAED73YKCATSU9X9CAHCN8UICAVA6JQQCA6J16K4CAEI23RW.htm moved successfully.
          C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\VUVCRCDB\7U7CAS6JUUVCAMR42SLCAYDP25ZCAJSUVYQCAI0BSL8CAXLPP20CAK5H274CANZQ2CMCACR7ACRCAM50QVLCAOHQ1LOCA263XOGCARRYZW2CA4ZA3FJCA22PFXJCA7ZBGQICAKI9MV1CAERSL30CANU5FAT.htm moved successfully.
          File move failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\VUVCRCDB\favicon[4].ico scheduled to be moved on reboot.
          C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\TZ7R0QRW\PD8CAM9GGPICAIUF4KXCA1D6UR1CAN8KM1YCAEUIQCLCATSMTBACASAI9M6CAC1Q953CAAOAPX6CAOEVPVHCAOBVKSACAIBJFR6CAR3U1PZCASY1OARCA4MRR1MCASAYPXSCA99FPFQCAMN0JQ8CA40IVT2.htm moved successfully.
          File move failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\JNCJN3QZ\affich-12245596-aide-pour-un-rapport-sdfix[1].htm scheduled to be moved on reboot.
          C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\JNCJN3QZ\NE2CAB33R6KCATAHCY2CAZFSY7RCAL67P2YCAPH1SJ7CALOZXM9CA8A4B04CAVDCVTKCAFAP4NKCA7B8AOCCAMSUNA7CAMVZJ66CATTSLN9CAXZL5E1CAVB522KCA1MU9XQCAFKAAY6CATXQL9FCA0ABH67.htm moved successfully.
          File move failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\Content.IE5\CG4DJ77Y\affich-12250129-rapport-combofix[1].htm scheduled to be moved on reboot.
          File move failed. C:\Documents and Settings\Cécilia\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be moved on reboot.
          File move failed. C:\WINDOWS\temp\Perflib_Perfdata_188.dat scheduled to be moved on reboot.
          0
      7. Télécharge Superantispyware (SAS)

        Choisis "enregistrer" et enregistre-le sur ton bureau.

        Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

        Créé une icône sur le bureau.

        Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

        - Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
        - Sous Configuration and Preferences, clique sur le bouton "Preferences"
        - Clique sur l'onglet "Scanning Control "
        - Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

        Close browsers before scanning
        Scan for tracking cookies
        Terminate memory threats before quarantining
        - Laisse les autres lignes décochées.

        - Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

        - Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

        Dans la colonne de gauche, coche C:\Fixed Drive.

        Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

        Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

        A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

        Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

        Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

        Pour recopier les informations sur le forum, fais ceci :

        - après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
        - Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
        - Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

        - Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

        - Copie son contenu dans ta réponse.

        Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
        0
        1. voici le nouveau rapport de super antispyware

          SUPERAntiSpyware journal de bord
          https://www.superantispyware.com/

          Généré 05/03/2009 at 05:00 PM

          Version du Logiciel : 4.26.1002

          Core Rules Database Version : 3875
          Trace Rules Database Version: 1823

          Genre de Scan : Scan Complète
          Temps total du Scan : 00:48:20

          Articles du Mémoire analysés : 461
          Risques de dommage de Mémoire détectés : 0
          Articles du Registre analysés : 6425
          Risques de dommage de Registre détectés : 0
          Articles de fichier scannés : 23974
          Risques du Dommage de Fichier Détectés : 0
          0
      8. encore des soucis ? on nettoie ?
        0
        1. Merci encore pour ton aide ca vas beaucoup mieux j'attend juste des nouvelles de mes contacts msn pour savoir si il ne recoivent plus de liens bizar de ma part.
          Si tu as quelque conseil de nettoyage je veux bien car je ne sais pas si il faut que je garde tout les logiciels que tu m'as demandé de telecharger? et comment etre sur qu'il n'y a plus du tout infection?
          0
          1. télécharge GenProc sur ton bureau

            dézippe le dossier, double-clique sur GenProc.exe (le".exe" peut ne pas apparaitre)

            laisse travailler l outil

            et poste le contenu du rapport qui s'ouvre

            0
            1. voici le rapport qui c'est ouvert tout de suite

              Rapport GenProc 2.532 [1] - 03/05/2009 à 17:40:32 - Windows XP

              GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :

              Poste un rapport Nod32 https://www.eset.com/ (il faut utiliser Internet Explorer)
              - coche toutes les cases à chaque fois, et lorsque c'est terminé, colle le rapport :
              - C:\Program Files\EsetOnlineScanner\log.txt

              ----------------------------------------------------------------------
              Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
              ----------------------------------------------------------------------

              je ne trouve pas ce fichier la: C :\Program Files\EsetOnlineScanner\log.txt
              0
          2. ok ben on va plutot prendre celui ci et ensuite le menage :

            -> Scan BitDefender

            Fais une analyse antivirus en ligne sur BitDefender on line avec Internet Explorer

            * Clique en bas à gauche sur Scan on line.
            * Accepte la licence et laisse-le installer l'Active x..
            * Laisse-toi guider. Colle son rapport ici.

            Aide
            0
            1. voila la rapport de bitdefender

              BitDefender Online Scanner

              Rapport d'analyse généré à: Sun, May 03, 2009 - 18:51:42

              Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;I:\;

              Statistiques

              Temps
              00:25:45

              Fichiers
              90896

              Directoires
              6681

              Secteurs de boot
              0

              Archives
              1318

              Paquets programmes
              10998

              Résultats

              Virus identifiés
              1

              Fichiers infectés
              2

              Fichiers suspects
              0

              Avertissements
              0

              Désinfectés
              0

              Fichiers effacés
              2

              Info sur les moteurs

              Définition virus
              2901629

              Version des moteurs
              AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

              Analyse des plugins
              17

              Archive des plugins
              45

              Unpack des plugins
              7

              E-mail plugins
              6

              Système plugins
              4

              Paramètres d'analyse

              Première action
              Supprimé

              Seconde Action
              Aucun

              Heuristique
              Oui

              Acceptez les avertissements
              Oui

              Extensions analysées
              exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

              Excludez les extensions

              Analyse d'emails
              Oui

              Analyse des Archives
              Oui

              Analyser paquets programmes
              Oui

              Analyse des fichiers
              Oui

              Analyse de boot
              Oui

              Fichier analysé
              Statut

              C:\Documents and Settings\Cécilia\DoctorWeb\Quarantine\SmitfraudFix[1].exe
              Détecté avec: Application.Generic.27054

              C:\Documents and Settings\Cécilia\DoctorWeb\Quarantine\SmitfraudFix[1].exe
              Supprimé

              C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP94\A0014888.exe
              Détecté avec: Application.Generic.27054

              C:\System Volume Information\_restore{164AB5B5-DA97-4C03-A843-AEC00C1D9138}\RP94\A0014888.exe
              Supprimé
              0
              1. je pense que tu es clean encore des soucis ? on nettoie ?
                0
                1. Tout vas bien, mon pc a retrouver la peche, il rame beaucoup moins on peux passer au nettoyage
                  Par contre j'ai un soucis avec Mon disque local (C:) une fenetre Prevention de l'execution des données Windows....etc
                  sur quel forum je doit aller??
                  Merci pour ton aide
                  0
              2. ca se rapporte à un fichier donné ?
                0
                1. je ne peux pas repondre a ta question je peux juste te dire que a chaque fois que j'ouvre disque C j'ai u ne fenetre qui s'ouvre Prevention de l'execution des données- Microsoft windows
                  Pour proteger votre ordinateur, windows a fermé ce programme
                  Je clic sur fermer ce message
                  une fentre explorer.exe s'ouvre pour le rapport d'erreur et ca plante je ne peux plus acceder au disque C:
                  A uel forum je doit m'adresser?
                  0
              3. Télécharge ZHPDiag (de Nicolas Coolman) sur ton bureau :

                ou :ZHPDiag

                !! déconnecte toi et ferme toutes tes applications en cours !!

                * Clique droit sur le .zip que tu viens de télécharger et choisis " extraire tout " sur ton bureau ...

                * Double-clique sur "ZHPDiag.exe" pour lancer l'outil :

                > Clique sur le bouton " Tous " ( important ).

                > puis clique sur le bouton de "la loupe" pour lancer le scan .

                Laisses travailler l'outil ...

                > Une fois terminé , le rapport s'affiche : clique sur bouton "appareil photo" pour sauvegarder le rapport obtenu ...

                Enregistres bien ZHPDiag.txt de façon à le retrouver facilement ( sur le bureau par exemple ).

                Puis ferme le programme ...

                Enfin , depose le rappport en te faisant parcourir sur ce site et envoyer le fichier puis redonnes le lien reçu en échange
                0
                1. Voici le lien:

                  http://www.cijoint.fr/cjlink.php?file=cj200905/cijbVyZ7tk.txt
                  0
              4. une fentre explorer.exe s'ouvre pour le rapport d'erreur et ca plante je ne peux plu.....

                explorer ? ou internet explorer ?
                0
                1. c'est bien une fenetre explorer. exe a rencontré un probleme et doit fermer. Nous prions de nous excusez.....etc

                  Veuillez signaler le probleme a microsoft avec l'envoie du rapport
                  0
              5. l'envoies-tu ?
                0
                1. ca arrive tellement souvent que des fois oui je l'envoie et des fois non j'ai deja essayer les 2
                  0
              • 1
              • 2