Problème d'infection trojans

Bonjour,

J'ai un gros problème avec mon ordi depuis hier soir. (pas celui là mais un autre!)

J'ai attrapé les trojans TR/crypt.XPACK.gen; Tr/alureon.14848J et TR/Dropper.gen, que j'ai tenté de supprimer avec Antivir, en vain.
Il m'était aussi impossible d'ouvrir des programmes comme Malwarebytes, ni Mozilla, ni Internet Explorer, etc.
Je me suis donc dit que je verrai le problème ce matin.

Ce matin donc, toujours les mêmes problèmes, mais j'ai finalement réussi à supprimer directement un fichier infecté (C:\Users\alain\AppData\Local\Temp\tmp1BCD.tmp), et depuis Antivir ne m'a encore rien indiqué.

Seulement, toujours les mêmes problèmes, je ne peux toujours pas ouvrir ces programmes.
De plus; il m'est aussi impossible de démarrer en mode sans échec pour lancer Malwarebytes, aussi bien en appuyant que F8 qu'en le faisant a partir de msconfig.
Je ne sais donc pas si mon problème est toujours lié aux trojans où à autre chose.

J'ai lu quelques forums pour chercher une réponse à mon problème, mais j'ai pas trouvé grand chose sur le problème des programmes.

J'ai lancé CCleaner, où j'ai du m'y prendre 3 fois pour supprimer tous les problèmes rencontrés, mais il n'y a plus rien (j'ai gardé les 3 comptes rendus au cas où).

J'ai lancé Hijackthis, donc voici le rapport:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:34:24, on 08/05/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Windows\System32\rundll32.exe
C:\Users\alain\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=1008&m=aspire_6930g
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=1008&m=aspire_6930g
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=1008&m=aspire_6930g
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
O20 - Winlogon Notify: spba - C:\Program Files\Common Files\SPBA\homefus2.dll
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate1c9b181bfc42490) (gupdate1c9b181bfc42490) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11098 bytes

Merci de votre aide!
Configuration: Windows XP
Firefox 3.0.10

62 réponses

Résumé de la discussion

Une infection par plusieurs trojans, notamment TR/crypt.XPACK.gen, TR/alureon.14848J et TR/Dropper.gen, empêche le fonctionnement normal de l’ordinateur et rend difficile la suppression avec Antivir, ainsi que l’ouverture de certains programmes essentiels. Des tentatives de nettoyage ont été réalisées, avec suppression manuelle d’un fichier infecté et l’usage d’Antivir, CCleaner et HijackThis, mais les symptômes persistent et le démarrage en mode sans échec reste indisponible. Le rapport HijackThis signale de nombreuses entrées au démarrage et des modules potentiellement indésirables, notamment des barres d’outils et des composants liés à Acer, Google Desktop et d’autres outils système. En outre, le log révèle des paramètres modifiés et des éléments de démarrage, ce qui pourrait indiquer une persistance des outils malveillants et justifier une restauration système.

Bobot (l’IA à votre service)
  1. salut :

    Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

    - Vas dans "Démarrer" puis Panneau de configuration.
    - Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
    - Clique sur Continuer.
    - Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
    - Valide par OK et redémarre.

    Tuto

    ensuite :

    ####### | Install & recherche | #########

    Telecharge et install UsbFix de C_XX & Chiquitine29

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectés sans les ouvrir

    # Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi éxécuter en tant qu'administrateur .

    # Choisi l option 1 ( Recherche )

    # Laisse travailler l outil.

    # Ensuite post le rapport UsbFix.txt qui apparaitra.

    # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
    1. Merci pour ta réponse aussi rapide!
      Voila le rapport Usbfix:

      ############################## [ UsbFix V3.017 # Scan ]

      # User : alain (Administrateurs) # PC-DE-ANTHONY
      # Update on 06/05/09 by Chiquitine29, C_XX & Chimay8
      # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
      # Start at: 11:10:54 | 08/05/2009

      # Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
      # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
      # Internet Explorer 7.0.6001.18000
      # Windows Firewall Status : Disabled

      # C:\ # Disque fixe local # 144,04 Go (81,91 Go free) [ACER] # NTFS
      # D:\ # Disque fixe local # 140,5 Go (62,67 Go free) [DATA] # NTFS
      # E:\ # Disque CD-ROM
      # F:\ # Disque CD-ROM
      # G:\ # Disque amovible # 3,78 Go (3,77 Go free) [ANTHONY] # FAT32

      ############################## [ Processus actifs ]

      C:\Windows\System32\smss.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\nvvsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\rundll32.exe
      C:\Windows\System32\spoolsv.exe
      C:\Program Files\Common Files\SPBA\upeksvr.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
      C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
      C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
      C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
      C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Launch Manager\QtZgAcer.EXE
      C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
      C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
      C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
      C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
      C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
      C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
      C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
      C:\Program Files\Google\Update\GoogleUpdate.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
      C:\Program Files\Internet Download Manager\IDMan.exe
      C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Acer\Mobility Center\MobilityService.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
      C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Windows\system32\DRIVERS\xaudio.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Users\alain\AppData\Local\Temp\RtkBtMnt.exe
      C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
      C:\Windows\system32\WUDFHost.exe
      C:\Program Files\Internet Download Manager\IEMonitor.exe
      C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
      C:\Windows\system32\SearchProtocolHost.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Windows\system32\wbem\wmiprvse.exe

      ################## [ Registre # Startup ]

      HKCU_Main: "Local Page"="C:\\Windows\\system32\\blank.htm"
      HKCU_Main: "Search Page"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2fbr%2faccess%2fallinone.asp%3f"
      HKCU_Main: "Start Page"="http://mystart.incredimail.com/"
      HKCU_Main: "Secondary Start Pages"=hex(7):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,67,00,\
      HKLM_logon: "Userinit"="C:\\Windows\\system32\\userinit.exe,"
      HKLM_logon: "LegalNoticeCaption"=""
      HKLM_logon: "LegalNoticeText"=""
      HKLM_Run: IAAnotif=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      HKLM_Run: RtHDVCpl=RtHDVCpl.exe
      HKLM_Run: SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      HKLM_Run: eDataSecurity Loader=C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
      HKLM_Run: eAudio="C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
      HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      HKLM_Run: LManager=C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
      HKLM_Run: ePower_DMC=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
      HKLM_Run: ZPdtWzdVitaKey MC3000="C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
      HKLM_Run: ArcadeDeluxeAgent="C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
      HKLM_Run: CLMLServer="C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
      HKLM_Run: PlayMovie="C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
      HKLM_Run: WarReg_PopUp=C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
      HKLM_Run: Google Desktop Search="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      HKLM_Run: AdobeCS4ServiceManager="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
      HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
      HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      HKLM_Run: Nikon Transfer Monitor=C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
      HKLM_Run: Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
      HKLM_Run: PLFSetI=C:\Windows\PLFSetI.exe
      HKLM_Run: BkupTray="C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
      HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
      HKCU_Run: ehTray.exe=C:\Windows\ehome\ehTray.exe
      HKCU_Run: MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      HKCU_Run: IDMan=C:\Program Files\Internet Download Manager\IDMan.exe /onboot
      HKCU_Run: Eraser=C:\Program Files\Eraser\Eraser.exe -hide

      ################## [ Informations ]

      ################## [ Fichiers # Dossiers infectieux ]

      C:\autorun.inf # -> fichier appelé : "C:\"RECYCLER\S-3-5-79-100008499-100013170-100031679-7558.com c:\"" ( absent ! )
      Found ! C:\autorun.inf
      Found ! C:\recycler\S-3-5-79-100008499-100013170-100031679-7558.com
      D:\autorun.inf # -> fichier appelé : "D:\"RECYCLER\S-3-5-79-100008499-100013170-100031679-7558.com d:\"" ( absent ! )
      Found ! D:\autorun.inf
      Found ! D:\recycler\S-3-5-79-100008499-100013170-100031679-7558.com

      ################## [ Registre # Clés Run infectieuses ]

      ################## [ Registre # Mountpoints2 ]

      HKCU\Software\Microsoft\....\MountPoints2\{1c584961-f85f-11dd-b877-00238b055027}\Shell\AutoRun\command
      HKCU\Software\Microsoft\....\MountPoints2\{426e8f24-dcd1-11dd-944d-00238b055027}\Shell\AutoRun\command
      HKCU\Software\Microsoft\....\MountPoints2\{c2bf36c1-e0bb-11dd-9f2a-00238b055027}\Shell\AutoRun\command
      HKCU\Software\Microsoft\....\MountPoints2\{eb673e70-f1e4-11dd-aa11-00238b055027}\Shell\Auto\command
      HKCU\Software\Microsoft\....\MountPoints2\{eb673e70-f1e4-11dd-aa11-00238b055027}\Shell\AutoRun\command
      HKCU\Software\Microsoft\....\MountPoints2\{f5c41698-d278-11dd-a674-00238b055027}\Shell\AutoRun\command

      ################## [ ! Fin du rapport # UsbFix V3.017 ! ]
      1. ##### | Suppression | ######

        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectés sans les ouvrir

        # Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi éxécuter en tant qu'administrateur .

        # choisi l option 2 ( Suppression )

        # Ton bureau disparaitra et le pc redémarrera .

        # Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

        # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

        # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        ######### | Désinstallation | #########

        # Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi éxécuter en tant qu'administrateur .

        # Choisi l option Désinstaller ....
        1. Voila!

          ############################## [ UsbFix V3.017 # Cleaning ]

          # User : alain (Administrateurs) # PC-DE-ANTHONY
          # Update on 06/05/09 by Chiquitine29, C_XX & Chimay8
          # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
          # Start at: 11:25:24 | 08/05/2009

          # Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
          # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
          # Internet Explorer 7.0.6001.18000
          # Windows Firewall Status : Disabled

          # C:\ # Disque fixe local # 144,04 Go (81,92 Go free) [ACER] # NTFS
          # D:\ # Disque fixe local # 140,5 Go (62,67 Go free) [DATA] # NTFS
          # E:\ # Disque CD-ROM
          # F:\ # Disque CD-ROM
          # G:\ # Disque amovible # 3,78 Go (3,77 Go free) [ANTHONY] # FAT32

          ############################## [ Processus actifs ]

          C:\Windows\System32\smss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\nvvsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\LogonUI.exe
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\rundll32.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\Program Files\Common Files\SPBA\upeksvr.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Windows\system32\userinit.exe
          C:\Windows\system32\Dwm.exe
          C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
          C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
          C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
          C:\Windows\system32\runonce.exe
          C:\Windows\system32\taskeng.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
          C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Acer\Mobility Center\MobilityService.exe
          C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
          C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Windows\system32\DRIVERS\xaudio.exe
          C:\Windows\system32\WUDFHost.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\system32\wbem\wmiprvse.exe

          ################## [ Fichiers # Dossiers infectieux ]

          C:\autorun.inf # -> fichier appelé : "C:\"RECYCLER\S-3-5-79-100008499-100013170-100031679-7558.com c:\"" ( absent ! )
          Deleted ! C:\autorun.inf
          Deleted ! C:\recycler\S-3-5-79-100008499-100013170-100031679-7558.com
          D:\autorun.inf # -> fichier appelé : "D:\"RECYCLER\S-3-5-79-100008499-100013170-100031679-7558.com d:\"" ( absent ! )
          Deleted ! D:\autorun.inf
          Deleted ! D:\recycler\S-3-5-79-100008499-100013170-100031679-7558.com

          ################## [ Registre # Clés Run infectieuses ]

          ################## [ Registre # Mountpoints2 ]

          Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{1c584961-f85f-11dd-b877-00238b055027}\Shell\AutoRun\command
          Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{426e8f24-dcd1-11dd-944d-00238b055027}\Shell\AutoRun\command
          Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{c2bf36c1-e0bb-11dd-9f2a-00238b055027}\Shell\AutoRun\command
          Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{eb673e70-f1e4-11dd-aa11-00238b055027}\Shell\Auto\command
          Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{f5c41698-d278-11dd-a674-00238b055027}\Shell\AutoRun\command

          ################## [ Listing des fichiers présent ]

          [25/04/2009 04:47|--a------|220] - C:\aaw7boot.log
          [18/09/2006 23:43|--a------|24] - C:\autoexec.bat
          [21/01/2008 04:24|-rahs----|333203] - C:\bootmgr
          [25/07/2008 23:59|-ra-s----|8192] - C:\BOOTSECT.BAK
          [18/09/2006 23:43|--a------|10] - C:\config.sys
          [?|?|?] - C:\hiberfil.sys
          [25/01/2009 19:42|-rahs----|0] - C:\IO.SYS
          [11/10/2008 02:48|--a------|20] - C:\Medion.ini
          [25/01/2009 19:42|-rahs----|0] - C:\MSDOS.SYS
          [?|?|?] - C:\pagefile.sys
          [11/10/2008 02:44|--a------|60] - C:\Partition.txt
          [25/07/2008 14:41|--a------|426] - C:\RHDSetup.log
          [08/05/2009 11:28|--a------|4859] - C:\UsbFix.txt
          [07/05/2009 23:31|--a------|228936] - D:\2373294468_793f03265f.jpg
          [08/04/2009 15:51|--a------|288428815] - D:\29032009117.mp4
          [03/05/2009 15:48|--a------|30720] - D:\Agressivit‚.doc
          [10/01/2009 17:41|---hs----|3502] - D:\AlbumArtSmall.jpg
          [10/01/2009 17:41|---hs----|15301] - D:\AlbumArt_{5D2F4331-7AE9-4780-94AC-7FC817B6E966}_Large.jpg
          [10/01/2009 17:41|---hs----|3502] - D:\AlbumArt_{5D2F4331-7AE9-4780-94AC-7FC817B6E966}_Small.jpg
          [10/01/2009 17:41|---hs----|7872] - D:\AlbumArt_{C4E46492-1F1C-42FB-82A5-51D1779F996D}_Large.jpg
          [10/01/2009 17:41|---hs----|2229] - D:\AlbumArt_{C4E46492-1F1C-42FB-82A5-51D1779F996D}_Small.jpg
          [31/03/2009 15:30|--a------|208] - D:\arna 2009.txt
          [21/04/2009 11:59|--a------|176] - D:\arna2009 2.txt
          [22/03/2009 14:23|--a------|34816] - D:\Bilan Aniv.xls
          [07/04/2009 18:31|--a------|29184] - D:\Club aventure 2009.xls
          [10/01/2009 17:42|---hs----|371] - D:\desktop.ini
          [25/04/2009 02:24|--a------|131780608] - D:\DSCN0137.mpg
          [07/05/2009 18:30|--a------|2437339] - D:\DSC_6939.jpg
          [01/04/2009 03:28|--a------|22811369] - D:\final.avi.FLV
          [10/01/2009 17:41|---hs----|15301] - D:\Folder.jpg
          [03/05/2009 15:55|--a------|2078] - D:\gaetan.txt
          [04/05/2009 04:33|--a------|21044] - D:\helene.docx
          [08/05/2009 10:51|--a------|11100] - D:\hijackthis.log
          [22/04/2009 21:56|--a------|47091] - D:\La table de verre doit briller.docx
          [22/04/2009 21:53|--a------|53068] - D:\La table de verre doit briller2.docx
          [06/05/2009 16:37|--a------|590912] - D:\N952371.jpg
          [27/04/2009 00:10|--a----t-|3253398] - D:\P1250568.JPG
          [27/04/2009 00:10|--a----t-|3459273] - D:\P1250573.JPG
          [09/04/2009 13:58|--a------|166912] - D:\RAPPORT FINAL2.doc
          [07/03/2006 18:08|--a------|218112] - D:\VSplitterPro.ax
          [28/04/2009 22:11|--a------|60622] - D:\_Agressivit‚,.pdf
          [27/03/2009 10:57|---hs----|81920] - G:\Thumbs.db
          [08/05/2009 09:25|--a------|34] - G:\1.txt
          [08/05/2009 10:06|--a------|3227248] - G:\ccsetup219.exe
          [08/05/2009 10:33|--a------|812344] - G:\HJTInstall.exe
          [08/05/2009 10:51|--a------|11100] - G:\hijackthis.log
          [08/05/2009 11:07|--a------|708885] - G:\UsbFix.exe
          [08/05/2009 11:13|--a------|8918] - G:\UsbFix.txt
          [08/05/2009 11:24|--a------|1542] - G:\BOOTEX.LOG

          ################## [ Vaccination ]

          # C:\autorun.inf -> Folder created by UsbFix.
          # D:\autorun.inf -> Folder created by UsbFix.
          # G:\autorun.inf -> Folder created by UsbFix.

          ################## [ Cracks / Keygens / Serials ]

          # -> Nothing found !

          ################## [ ! Fin du rapport # UsbFix V3.017 ! ]
          1. Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

            Télécharges :
            Malwarebytes ou :
            Malwarebytes

            * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

            (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

            * Potasses le Tuto pour te familiariser avec le prg :

            ( cela dit, il est très simple d'utilisation ).

            relance malwarebytes en suivant scrupuleusement ces consignes :

            ! Déconnecte toi et ferme toutes applications en cours !

            * Lance Malwarebyte's .

            Fais un examen dit "Complet" .

            --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
            --> à la fin tu cliques sur "résultat" .
            --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

            Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

            Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

            1. Le problème de Malwarebytes, comme je le dis dans mon sujet, c'est qu'il veut pas se lancer (ni meme en tant qu'administrateur), et que même en le réinstallant ça en change rien!
              1. *****************************************************
                ************** Option 1 (Recherche) **************
                *****************************************************

                Télécharge FindyKill ( de Chiquitine29) sur ton bureau :

                ! Déconnecte toi et ferme toutes applications en cours !

                * Double clique sur "FindyKill.exe" pour lancer l'installation et laisse les paramètres d'instalation par défaut .

                * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)

                * Double-clique sur le raccourci FindyKill qui est sur ton bureau pour lancer l'outil .

                * Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

                * Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]

                Laisse travailler l'outil et ne touche à rien ...

                --> Poste le rapport qui apparait à la fin , sur le forum ...

                ( le rapport est sauvegardé aussi sous C:\FindyKill.txt )
                ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                Aides en images ( Installation )
                Aides en images ( Recherche )
                1. ############################## [ FindyKill V4.728 ]

                  # User : alain (Administrateurs) # PC-DE-ANTHONY
                  # Update on 03/05/09 by Chiquitine29
                  # Start at: 11:43:08 | 08/05/2009
                  # Website : http://pagesperso-orange.fr/NosTools/findykill.html

                  # Intel(R) Core(TM)2 Duo CPU T5800 @ 2.00GHz
                  # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                  # Internet Explorer 7.0.6001.18000
                  # Windows Firewall Status : Enabled

                  # C:\ # Disque fixe local # 144,04 Go (81,91 Go free) [ACER] # NTFS
                  # D:\ # Disque fixe local # 140,5 Go (62,67 Go free) [DATA] # NTFS
                  # E:\ # Disque CD-ROM
                  # F:\ # Disque CD-ROM
                  # G:\ # Disque amovible # 3,78 Go (3,77 Go free) [ANTHONY] # FAT32

                  ############################## [ Processus actifs ]

                  C:\Windows\System32\smss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\nvvsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\Program Files\Common Files\SPBA\upeksvr.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
                  C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
                  C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Google\Update\GoogleUpdate.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                  C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  C:\Acer\Mobility Center\MobilityService.exe
                  C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
                  C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Windows\system32\DRIVERS\xaudio.exe
                  C:\Windows\explorer.exe
                  C:\Windows\system32\wuauclt.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\WUDFHost.exe
                  C:\Windows\system32\SearchProtocolHost.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Windows\system32\conime.exe
                  \\?\C:\Windows\system32\wbem\WMIADAP.EXE
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\system32\wbem\wmiprvse.exe

                  ################## [ Fichiers / Dossiers infectieux ]

                  ################## [ Infected Temp Files ]

                  ################## [ Registre / Clés infectieuses ]

                  ################## [ Recherche dans supports amovibles]

                  # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                  # D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                  # G:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

                  ################## [ Registre / Mountpoints2 ]

                  # -> Not found !

                  ################## [ ! Fin du rapport # FindyKill V4.728 ! ]
              2. relances Findykill , puis option desinstaller

                ensuite :

                Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                Télécharges :
                Malwarebytes ou :
                Malwarebytes

                * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                * Potasses le Tuto pour te familiariser avec le prg :

                ( cela dit, il est très simple d'utilisation ).

                relance malwarebytes en suivant scrupuleusement ces consignes :

                ! Déconnecte toi et ferme toutes applications en cours !

                * Lance Malwarebyte's .

                Fais un examen dit "Complet" .

                --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                --> à la fin tu cliques sur "résultat" .
                --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                1. Malwarebytes ne se lance toujours pas... il me met toujours la fenêtre "Malwarebytes Anti-malware a cessé de fonctionner, Un problème a fait que le programme a cessé de fonctionner... (...) Fermer le programme.
              3. Rien trouvé...

                Malwarebytes' Anti-Malware 1.36
                Version de la base de données: 1945
                Windows 6.0.6001 Service Pack 1

                08/05/2009 12:47:04
                mbam-log-2009-05-08 (12-47-04).txt

                Type de recherche: Examen complet (C:\|D:\|G:\|)
                Eléments examinés: 197728
                Temps écoulé: 46 minute(s), 48 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 0
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 0

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                (Aucun élément nuisible détecté)
                1. Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                  ! Déconnecte toi et ferme toutes tes applications en cours !

                  Double-clique sur " RSIT.exe " pour le lancer .

                  -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                  * Devant l'option "List files/folders created ..." , tu choisis : 2 months

                  * clique ensuite sur " Continue " pour lancer l'analyse ...

                  -> laisse faire le scan et ne touche pas au PC ...

                  Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

                  Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                  Important : poste un rapport, puis l'autre dans la réponse suivante
                  Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

                  ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
                  1. log:

                    Logfile of random's system information tool 1.06 (written by random/random)
                    Run by alain at 2009-05-08 13:11:36
                    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                    System drive C: has 84 GB (57%) free of 148 GB
                    Total RAM: 3066 MB (52% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 13:11:44, on 08/05/2009
                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                    MSIE: Internet Explorer v7.00 (7.00.6001.18226)
                    Boot mode: Normal

                    Running processes:
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\explorer.exe
                    C:\Windows\system32\wuauclt.exe
                    C:\Windows\system32\conime.exe
                    G:\RSIT.exe
                    C:\Windows\system32\SearchFilterHost.exe
                    C:\Users\alain\Desktop\RSIT.exe
                    C:\Program Files\Trend Micro\HijackThis\alain.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=1008&m=aspire_6930g
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=1008&m=aspire_6930g
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    O1 - Hosts: ::1 localhost
                    O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
                    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                    O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
                    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
                    O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
                    O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
                    O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
                    O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
                    O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
                    O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
                    O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
                    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                    O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                    O4 - HKLM\..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                    O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
                    O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                    O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
                    O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                    O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
                    O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
                    O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
                    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                    O13 - Gopher Prefix:
                    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
                    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
                    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
                    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                    O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
                    O20 - Winlogon Notify: spba - C:\Program Files\Common Files\SPBA\homefus2.dll
                    O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
                    O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
                    O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
                    O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
                    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
                    O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                    O23 - Service: Service Google Update (gupdate1c9b181bfc42490) (gupdate1c9b181bfc42490) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                    O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                    O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
                    O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
                    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                    1. Info:

                      info.txt logfile of random's system information tool 1.06 2009-05-08 13:11:17

                      ======Uninstall list======

                      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A450831D-25F6-4F42-9662-D000B25E0D82}\Setup.exe" -uninstall
                      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\Setup.exe" -uninstall
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
                      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                      Acer Arcade Deluxe-->"C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" /z-uninstall
                      Acer Arcade Deluxe-->"C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" /z-uninstall
                      Acer Bio Protection

                      AAU 6.0.00.17-->"C:\Program Files\Acer\Acer Bio Protection\uninstall.exe"
                      Acer Crystal Eye Webcam 2.0.8-->C:\Program Files\InstallShield Installation Information\{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}\setup.exe -runfromtemp -l0x040c -removeonly
                      Acer eAudio Management-->"C:\Program Files\InstallShield Installation Information\{57265292-228A-41FA-9AEC-4620CBCC2739}\Setup.exe" -uninstall
                      Acer eDataSecurity Management-->C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSnstHelper.exe -Operation UNINSTALL
                      Acer Empowering Technology-->"C:\Program Files\InstallShield Installation Information\{8F1B6239-FEA0-450A-A950-B05276CE177C}\setup.exe" -runfromtemp -l0x040c -removeonly
                      Acer ePower Management-->"C:\Program Files\InstallShield Installation Information\{58E5844B-7CE2-413D-83D1-99294BF6C74F}\setup.exe" -runfromtemp -l0x040c -removeonly
                      Acer eSettings Management-->"C:\Program Files\InstallShield Installation Information\{13D85C14-2B85-419F-AC41-C7F21E68B25D}\setup.exe" -runfromtemp -l0x040c -removeonly
                      Acer GridVista-->C:\Windows\GVUni.exe GridV.UNI
                      Acer Mobility Center Plug-In-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{11316260-6666-467B-AC34-183FCB5D4335}\setup.exe" -l0x40c -removeonly
                      Acer ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
                      Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
                      Adobe Anchor Service CS4-->MsiExec.exe /I{1618734A-3957-4ADD-8199-F973763109A8}
                      Adobe Bridge CS4-->MsiExec.exe /I{83877DB1-8B77-45BC-AB43-2BAC22E093E0}
                      Adobe CMaps CS4-->MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191}
                      Adobe Color - Photoshop Specific CS4-->MsiExec.exe /I{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
                      Adobe Color EU Extra Settings CS4-->MsiExec.exe /I{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
                      Adobe Color JA Extra Settings CS4-->MsiExec.exe /I{0D6013AB-A0C7-41DC-973C-E93129C9A29F}
                      Adobe Color NA Recommended Settings CS4-->MsiExec.exe /I{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
                      Adobe Color Video Profiles CS CS4-->MsiExec.exe /I{63C24A08-70F3-4C8E-B9FB-9F21A903801D}
                      Adobe CSI CS4-->MsiExec.exe /I{0F723FC1-7606-4867-866C-CE80AD292DAF}
                      Adobe Default Language CS4-->MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683}
                      Adobe ExtendScript Toolkit CS4-->MsiExec.exe /I{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}
                      Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                      Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                      Adobe Fonts All-->MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
                      Adobe Linguistics CS4-->MsiExec.exe /I{931AB7EA-3656-4BB7-864D-022B09E3DD67}
                      Adobe Output Module-->MsiExec.exe /I{BB4E33EC-8181-4685-96F7-8554293DEC6A}
                      Adobe PDF Library Files CS4-->MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353}
                      Adobe Photoshop CS4 Support-->MsiExec.exe /I{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}
                      Adobe Photoshop CS4-->C:\Program Files\Common Files\Adobe\Installers\faf656ef605427ee2f42989c3ad31b8\Setup.exe --uninstall=1
                      Adobe Photoshop CS4-->MsiExec.exe /I{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}
                      Adobe Photoshop CS4-->MsiExec.exe /I{E4848436-0345-47E2-B648-8B522FCDA623}
                      Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
                      Adobe Search for Help-->MsiExec.exe /I{F0E64E2E-3A60-40D8-A55D-92F6831875DA}
                      Adobe Service Manager Extension-->MsiExec.exe /I{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
                      Adobe Setup-->MsiExec.exe /I{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}
                      Adobe Type Support CS4-->MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
                      Adobe Update Manager CS4-->MsiExec.exe /I{05308C4E-7285-4066-BAE3-6B50DA6ED755}
                      Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
                      Adobe XMP Panels CS4-->MsiExec.exe /I{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
                      AdobeColorCommonSetCMYK-->MsiExec.exe /I{68243FF8-83CA-466B-B2B8-9F99DA5479C4}
                      AdobeColorCommonSetRGB-->MsiExec.exe /I{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
                      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                      Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver-->"C:\Program Files\InstallShield Installation Information\{3108C217-BE83-42E4-AE9E-A56A2A92E549}\setup.exe" -runfromtemp -l0x040c -removeonly
                      Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
                      Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
                      CamStudio 2.02 Fr-->"C:\Program Files\CamStudio\unins000.exe"
                      Capture NX 2-->C:\Program Files\Nikon\Capture NX 2\uninstall.exe
                      CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                      Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                      Connect-->MsiExec.exe /I{B29AD377-CC12-490A-A480-1452337C618D}
                      DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
                      eMule-->"C:\Program Files\eMule\Uninstall.exe"
                      File Uploader-->MsiExec.exe /X{237CD223-1B9D-47E8-A76C-E478B83CCEA2}
                      FileZilla Client 3.1.5-->C:\Program Files\FileZilla FTP Client\uninstall.exe
                      Football Manager 2009-->"C:\Program Files\Sports Interactive\Football Manager 2009\Uninstall_Football Manager 2009\Désinstaller Football Manager 2009.exe"
                      getPlus(R) for Adobe-->"C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1
                      Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
                      Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
                      Google Earth-->MsiExec.exe /X{548EAC70-EE00-11DD-908C-005056806466}
                      HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDA_HSF\UIU32m.exe -U -IAcrZUn32z.INF
                      HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                      Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                      Intel® Matrix Storage Manager-->C:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
                      Internet Download Manager-->C:\Program Files\Internet Download Manager\Uninstall.exe
                      Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
                      kuler-->MsiExec.exe /I{098727E1-775A-4450-B573-3F441F1CA243}
                      Launch Manager-->C:\Windows\UnInst32.exe QtZgAcer.UNI
                      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins001.exe"
                      Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                      Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
                      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                      Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
                      Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
                      Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
                      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                      Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
                      Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
                      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                      Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
                      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                      Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
                      Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                      Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
                      Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                      Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                      Mozilla Thunderbird (2.0.0.21)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
                      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                      Nikon Message Center-->MsiExec.exe /X{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}
                      Nikon Transfer-->MsiExec.exe /X{E9757890-7EC5-46C8-99AB-B00F07B6525C}
                      NTI Backup Now 5-->C:\Program Files\InstallShield Installation Information\{12EFA1A4-AC3B-443C-8143-237EDE760403}\setup.exe -runfromtemp -l0x040c
                      NTI Media Maker 8-->C:\Program Files\InstallShield Installation Information\{2413930C-8309-47A6-BC61-5EF27A4222BC}\setup.exe -runfromtemp -l0x040c
                      NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
                      Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
                      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                      Outils Club Internet-->"C:\Program Files\Club-Internet\Assistance\OutilsCI\uninstall.exe"
                      PDF Settings CS4-->MsiExec.exe /I{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
                      PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
                      PhotoNow!-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\Setup.exe" -uninstall
                      Photoshop Camera Raw-->MsiExec.exe /I{CC75AB5C-2110-4A7F-AF52-708680D22FE8}
                      Picture Control Utility-->MsiExec.exe /X{87441A59-5E64-4096-A170-14EFE67200C3}
                      Pokerbility 1.10.25-->"C:\Program Files\Pokerbility\unins000.exe"
                      PokerStars-->"C:\Program Files\PokerStars\PokerStarsUninstall.exe" /u:PokerStars
                      Pro Evolution Soccer 2009-->MsiExec.exe /X{A8DB611A-D80E-450D-85F6-3ACDD164BE31}
                      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
                      Realtek USB 2.0 Card Reader-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DC24971E-1946-445D-8A82-CE685433FA7D}\setup.exe" -l0x9 -removeonly
                      Recover My Files-->"C:\Program Files\GetData\Recover My Files\unins000.exe"
                      Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
                      Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
                      Security Update for 2007 Microsoft Office System (KB960003)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F04F8702-18D0-458D-921E-146FB7CD38CF}
                      Security Update for Microsoft Office Excel 2007 (KB959997)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {9EAC3AEC-5C81-4856-A05B-DE9DC236D740}
                      Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
                      Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
                      Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
                      Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
                      Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
                      SFR - Kit de connexion-->C:\Program Files\SFR\Kit\uninstall.exe
                      SopCast 2.0.4-->C:\Program Files\SopCast\uninst.exe
                      SPBA 5.8-->MsiExec.exe /I{ECCD28B2-8798-4D16-8126-625D728294A1}
                      SPX Instant Screen Capture-->"C:\Program Files\Moodysoft\SPX Instant Screen Capture\unins000.exe"
                      Suite Shared Configuration CS4-->MsiExec.exe /I{842B4B72-9E8F-4962-B3C1-1C422A5C4434}
                      SUPER © Version 2008.bld.33 (Sep 2, 2008)-->C:\PROGRA~1\ERIGHT~1\SUPER\Setup.exe /remove /q0
                      Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                      TVAnts 1.0-->C:\PROGRA~1\TVAnts\UNWISE.EXE C:\PROGRA~1\TVAnts\INSTALL.LOG
                      UDPixel.exe-->"C:\Program Files\UDPixel\uninstall.exe"
                      Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                      Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
                      Update for Microsoft Office Outlook 2007 Help (KB957246)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {80E46078-C1C5-4AE8-8744-3EAFC812E118}
                      Update for Outlook 2007 Junk Email Filter (kb968503)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5DD98950-4D10-4B79-8BF6-59726705207D}
                      UsbFix-->C:\UsbFix\Uninstal.exe
                      Veetle TV 0.9.14-->C:\Program Files\Veetle\UninstallVeetleTV.exe
                      VerySoft WebCamSplitter Pro-->"C:\Program Files\WebCamSplitter Pro\unins000.exe"
                      Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
                      Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
                      VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                      VSO Image Resizer 2.1.5.5c-->"C:\Program Files\VSO\Image Resizer\unins000.exe"
                      Web Acappella-->"C:\Program Files\Intuisphere\Web Acappella\unins000.exe"
                      Winbond CIR Device Drivers-->MsiExec.exe /I{10F498FF-5392-4DF3-8F73-FE172A9F3800}
                      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                      Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                      Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                      Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
                      Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
                      Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
                      Xilisoft Video Converter Ultimate-->C:\Program Files\Xilisoft\Video Converter Ultimate\Uninstall.exe

                      ======Hosts File======

                      127.0.0.1 activate.adobe.com

                      ======Security center information======

                      AS: Windows Defender

                      ======System event log======

                      Computer Name: PC-de-Anthony
                      Event Code: 15016
                      Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
                      Record Number: 54958
                      Source Name: Microsoft-Windows-HttpEvent
                      Time Written: 20090508090737.999453-000
                      Event Type: Erreur
                      User:

                      Computer Name: PC-de-Anthony
                      Event Code: 4001
                      Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

                      Record Number: 55083
                      Source Name: Microsoft-Windows-WLAN-AutoConfig
                      Time Written: 20090508092327.097800-000
                      Event Type: Avertissement
                      User: AUTORITE NT\SYSTEM

                      Computer Name: PC-de-Anthony
                      Event Code: 15016
                      Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
                      Record Number: 55096
                      Source Name: Microsoft-Windows-HttpEvent
                      Time Written: 20090508092458.713198-000
                      Event Type: Erreur
                      User:

                      Computer Name: PC-de-Anthony
                      Event Code: 10000
                      Message: Le démarrage d'un serveur DCOM : {98D9A6F1-4696-4B5E-A2E8-36B3F9C1E12C} n'est pas possible. L'erreur :
                      "3"
                      s'est produite lors du démarrage de la commande :
                      "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcrobatInfo.exe" /PDFShell -Embedding
                      Record Number: 55201
                      Source Name: Microsoft-Windows-DistributedCOM
                      Time Written: 20090508093846.000000-000
                      Event Type: Erreur
                      User:

                      Computer Name: PC-de-Anthony
                      Event Code: 7000
                      Message: Le service MBAMSwissArmy n'a pas pu démarrer en raison de l'erreur :
                      Le texte du message associé au numéro 0xMBAMSwissArmy est introuvable dans le fichier de messages pour Le texte du message associé au numéro 0x%1 est introuvable dans le fichier de messages pour %2..
                      Record Number: 55203
                      Source Name: Service Control Manager
                      Time Written: 20090508100019.000000-000
                      Event Type: Erreur
                      User:

                      =====Application event log=====

                      Computer Name: PC-de-Anthony
                      Event Code: 1000
                      Message: Application défaillante mbam.exe, version 1.36.0.0, horodatage 0x49da6531, module défaillant mbam.exe, version 1.36.0.0, horodatage 0x49da6531, code d’exception 0x80000003, décalage d’erreur 0x00002e88, ID du processus 0xf14, heure de début de l’application 0x01c9cfc2090bf7db.
                      Record Number: 12220
                      Source Name: Application Error
                      Time Written: 20090508094744.000000-000
                      Event Type: Erreur
                      User:

                      Computer Name: PC-de-Anthony
                      Event Code: 1000
                      Message: Application défaillante mbam.exe, version 1.36.0.0, horodatage 0x49da6531, module défaillant mbam.exe, version 1.36.0.0, horodatage 0x49da6531, code d’exception 0x80000003, décalage d’erreur 0x00002e88, ID du processus 0x4d0, heure de début de l’application 0x01c9cfc21348c1bb.
                      Record Number: 12222
                      Source Name: Application Error
                      Time Written: 20090508094801.000000-000
                      Event Type: Erreur
                      User:

                      Computer Name: PC-de-Anthony
                      Event Code: 1000
                      Message: Application défaillante mbam.exe, version 1.36.0.0, horodatage 0x49da6531, module défaillant mbam.exe, version 1.36.0.0, horodatage 0x49da6531, code d’exception 0x80000003, décalage d’erreur 0x00002e88, ID du processus 0xb0c, heure de début de l’application 0x01c9cfc27d5c07bb.
                      Record Number: 12224
                      Source Name: Application Error
                      Time Written: 20090508095059.000000-000
                      Event Type: Erreur
                      User:

                      Computer Name: PC-de-Anthony
                      Event Code: 1000
                      Message: Application défaillante mbam.exe, version 1.36.0.0, horodatage 0x49da6531, module défaillant mbam.exe, version 1.36.0.0, horodatage 0x49da6531, code d’exception 0x80000003, décalage d’erreur 0x00002e88, ID du processus 0x130, heure de début de l’application 0x01c9cfc283a78a9b.
                      Record Number: 12225
                      Source Name: Application Error
                      Time Written: 20090508095109.000000-000
                      Event Type: Erreur
                      User:

                      Computer Name: PC-de-Anthony
                      Event Code: 1015
                      Message: L'ID événement 3013 du service Windows Search a été supprimé 44 fois depuis 11:10:00. Cet événement est utilisé pour supprimer les événements du service Windows Search qui se sont produits fréquemment dans une courte période. Voir l'ID événement 3013 pour plus de détails sur cet événement.
                      Record Number: 12228
                      Source Name: Microsoft-Windows-Search
                      Time Written: 20090508095516.000000-000
                      Event Type: Avertissement
                      User:

                      =====Security event log=====

                      Computer Name: PC-de-Anthony
                      Event Code: 5038
                      Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                      Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                      Record Number: 12778
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090508111143.844413-000
                      Event Type: Échec de l'audit
                      User:

                      Computer Name: PC-de-Anthony
                      Event Code: 5038
                      Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                      Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                      Record Number: 12779
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090508111143.922413-000
                      Event Type: Échec de l'audit
                      User:

                      Computer Name: PC-de-Anthony
                      Event Code: 5038
                      Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                      Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                      Record Number: 12780
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090508111144.000413-000
                      Event Type: Échec de l'audit
                      User:

                      Computer Name: PC-de-Anthony
                      Event Code: 5038
                      Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                      Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                      Record Number: 12781
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090508111144.078413-000
                      Event Type: Échec de l'audit
                      User:

                      Computer Name: PC-de-Anthony
                      Event Code: 5038
                      Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                      Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
                      Record Number: 12782
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090508111144.140813-000
                      Event Type: Échec de l'audit
                      User:

                      ======Environment variables======

                      "ComSpec"=%SystemRoot%\system32\cmd.exe
                      "FP_NO_HOST_CHECK"=NO
                      "OS"=Windows_NT
                      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Acer\Empowering Technology\eDataSecurity\;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64
                      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                      "PROCESSOR_ARCHITECTURE"=x86
                      "TEMP"=%SystemRoot%\TEMP
                      "TMP"=%SystemRoot%\TEMP
                      "USERNAME"=SYSTEM
                      "windir"=%SystemRoot%
                      "PROCESSOR_LEVEL"=6
                      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
                      "PROCESSOR_REVISION"=0f0d
                      "NUMBER_OF_PROCESSORS"=2
                      "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
                      "DFSTRACINGON"=FALSE
                      "Pathtem"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Acer\Empowering Technology\eDataSecurity\;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64
                      "NTIPath"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Acer\Empowering Technology\eDataSecurity\;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\;

                      -----------------EOF-----------------
                      1. Je ne connais de patch pour Emule, donc je pense que non... Et ça fait bien 3 mois que je me suis pas servi d'Emule...
                        1. verifies si tu as bien ce fichier de 292 Ko stp :

                          C:\WINDOWS\System32\Kerberos.dll
                          • 1
                          • 2
                          • 3
                          • 4