Mon pc plante

Résolu
Bonjour,
ça fait une semaine que mon pc plante il ne s'arrete au démarrage et je n'arrive pas à ouvrir mes navigateurs ou certains logiciels je clique, je clique mais rien ne se passe mes boites à messages ne s'ouvrent plus il est super lent et meme mon lecteur multimédia plante si quelqu'un pouvait m'aider ça serait sympas car ça commence à etre super chiant ! merci d'avance !
Configuration: Windows XP
Firefox 3.0.10

36 réponses

Résumé de la discussion

Le souci concerne un ordinateur sous Windows XP qui plante au démarrage et devient extrêmement lent, bloquant l’ouverture des navigateurs, des logiciels et des éléments de communication. Plusieurs éléments de réponse privilégient une désinfection, notamment l’usage d’un outil anti-malware comme SuperAntiSpyware, avec mise à jour des définitions et quarantaine complète des menaces. D’autres interventions suggèrent des nettoyages manuels et des vérifications après suppression de fichiers malveillants (.msnfix), ainsi que des tentatives en mode sans échec et des nettoyages de registre et de services. En cas de persistance, des échanges évoquent l’analyse de rapports et logs, le recours à des outils avancés (OTL, ComboFix) et des ajustements éventuels du pare-feu.

Bobot (l’IA à votre service)
  1. ca alors un vundo en txt mdr

    Télécharge Superantispyware (SAS)

    Choisis "enregistrer" et enregistre-le sur ton bureau.

    Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

    Créé une icône sur le bureau.

    Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

    - Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
    - Sous Configuration and Preferences, clique sur le bouton "Preferences"
    - Clique sur l'onglet "Scanning Control "
    - Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

    Close browsers before scanning
    Scan for tracking cookies
    Terminate memory threats before quarantining
    - Laisse les autres lignes décochées.

    - Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

    - Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

    Dans la colonne de gauche, coche C:\Fixed Drive.

    Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

    Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

    A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

    Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

    Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

    Pour recopier les informations sur le forum, fais ceci :

    - après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
    - Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
    - Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

    - Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

    - Copie son contenu dans ta réponse.

    Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
    1. SUPERAntiSpyware Scan Log
      https://www.superantispyware.com/

      Generated 06/24/2009 at 01:54 PM

      Application Version : 4.26.1006

      Core Rules Database Version : 3953
      Trace Rules Database Version: 1895

      Scan type : Complete Scan
      Total Scan Time : 00:54:41

      Memory items scanned : 615
      Memory threats detected : 0
      Registry items scanned : 6808
      Registry threats detected : 18
      File items scanned : 27788
      File threats detected : 6

      Adware.Tracking Cookie
      C:\Documents and Settings\christelle\Cookies\christelle@bs.serving-sys[2].txt
      C:\Documents and Settings\christelle\Cookies\christelle@imrworldwide[2].txt
      C:\Documents and Settings\christelle\Cookies\christelle@serving-sys[1].txt
      C:\Documents and Settings\christelle\Cookies\christelle@serving-sys[2].txt
      C:\Documents and Settings\christelle\Cookies\christelle@smartadserver[1].txt
      C:\Documents and Settings\christelle\Cookies\christelle@bs.serving-sys[1].txt

      Trojan.Downloader-Valentina
      HKLM\Software\Valentina
      HKLM\Software\Valentina#sn
      HKLM\Software\Valentina#pub_id
      HKLM\Software\Valentina#last_attempt
      HKLM\Software\Valentina#last_success
      HKLM\Software\Valentina#attempt_int
      HKLM\Software\Valentina#success_int
      HKLM\Software\Valentina#att_day
      HKLM\Software\Valentina#att_today
      HKLM\Software\Valentina#num_of_succ
      HKLM\Software\Valentina#num_of_fail
      HKLM\Software\Valentina#disclaimer
      HKLM\Software\Valentina#redir_url
      HKLM\Software\Valentina#u1
      HKLM\Software\Valentina#u2
      HKLM\Software\Valentina#u3
      HKLM\Software\Valentina#last_err

      Adware.UpMedia/SearchTool
      HKU\S-1-5-21-3985237481-2213558216-628593369-1006\Software\UptownInstaller

      voilà !
  2. salut je comprends lol

    ######## | XP _ Instal & recherche | #######

    Telecharge et install UsbFix (de C_XX & Chiquitine29)

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectés sans les ouvrir

    # Double clic sur le raccourci UsbFix présent sur ton bureau .

    # Choisi l option 1 ( Recherche )

    # Laisse travailler l outil.

    # Ensuite post le rapport UsbFix.txt qui apparaitra.

    # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

    1. ############################## [ UsbFix V3.029 | Scan ]

      # User : christelle (Administrateurs) # KIPSNY
      # Update on 05/06/09 by Chiquitine29, C_XX & Chimay8
      # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
      # Start at: 11:21:33 | 2009-06-11

      # Intel(R) Pentium(R) 4 CPU 3.06GHz
      # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
      # Internet Explorer 8.0.6001.18702
      # Windows Firewall Status : Enabled
      # AV : Norton AntiVirus 16.5.0.134 [ Enabled | Updated ]

      # A:\ # Lecteur de disquettes 3 ½ pouces # 1.39 Mo (0.16 Mo free) # FAT
      # C:\ # Disque fixe local # 90.96 Go (5.2 Go free) [ACER] # NTFS
      # D:\ # Disque fixe local # 91.43 Go (91.4 Go free) [ACERDATA] # FAT32
      # E:\ # Disque CD-ROM
      # F:\ # Disque amovible
      # G:\ # Disque amovible
      # H:\ # Disque amovible
      # I:\ # Disque amovible
      # J:\ # Disque amovible # 982.03 Mo (870.93 Mo free) # FAT32
      # K:\ # Disque amovible # 1.92 Go (1.2 Go free) [UDISK PRO] # FAT

      ############################## [ Processus actifs ]

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      c:\program files\a-squared free\a2service.exe
      C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\Program Files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
      C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\WINDOWS\system32\tcpsvcs.exe
      C:\WINDOWS\System32\snmp.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\WINDOWS\system32\wbem\unsecapp.exe
      C:\Program Files\Acer\Acer eConsole\MediaSync.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\WINDOWS\System32\alg.exe
      C:\Acer\Empowering Technology\eRecovery\Monitor.exe
      C:\Program Files\Acer\Acer eMode Management\AspireService.exe
      C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
      C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Documents and Settings\christelle\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      ################## [ Registre Startup ]

      HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
      HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
      HKCU_Main: "Start Page"="https://www.msn.com/fr-fr"
      HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      HKLM_logon: "DefaultUserName"="christelle"
      HKLM_logon: "AltDefaultUserName"="christelle"
      HKLM_logon: "LegalNoticeCaption"=""
      HKLM_logon: "LegalNoticeText"=""
      HKLM_Run: RTHDCPL=RTHDCPL.EXE
      HKLM_Run: RemoteControl="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      HKLM_Run: PHIME2002ASync=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      HKLM_Run: PHIME2002A=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      HKLM_Run: ntiMUI=c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
      HKLM_Run: MSPY2002=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
      HKLM_Run: MediaSync=C:\Program Files\Acer\Acer eConsole\MediaSync.exe
      HKLM_Run: LaunchApp=Alaunch
      HKLM_Run: IMJPMIG8.1="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      HKLM_Run: High Definition Audio Property Page Shortcut=HDAShCut.exe
      HKLM_Run: eRecoveryService=C:\Acer\Empowering Technology\eRecovery\Monitor.exe
      HKLM_Run: AspireService=C:\Program Files\Acer\Acer eMode Management\AspireService.exe
      HKLM_Run: WorksFUD=C:\Program Files\Microsoft Works\wkfud.exe
      HKLM_Run: Microsoft Works Portfolio=C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
      HKLM_Run: Microsoft Works Update Detection=C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
      HKLM_Run: NeroFilterCheck=C:\WINDOWS\system32\NeroCheck.exe
      HKLM_Run: Canal Widget="C:\Program Files\Canal\Canal Widget\Launcher.exe"
      HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      HKLM_Run: UserFaultCheck=%systemroot%\system32\dumprep 0 -u
      HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
      HKLM_Run: Ad-Watch=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
      HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
      HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
      HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
      HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      HKCU_Run: MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      HKCU_Run: SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

      ################## [ Fichiers # Dossiers infectieux ]

      ################## [ Registre # Clés Run infectieuses ]

      ################## [ Registre # Mountpoints2 ]

      ################## [ ! Fin du rapport # UsbFix V3.029 ! ]

      voilà le rapport que tu m'as demandé merci pour ton aide
      1. desinstalle AD-Aware il vaut rien

        ensuite :

        relances usbfix , option Vaccination puis option desinstallation

        ensuite :

        Pour voir ce qu'il en est,avoir un diagnostic et repérer les infections possibles et les neutraliser:

        Télécharges et installes le logiciel de diagnostic :

        ici Hijackthis
        ou ici Hijackthis
        ou ici Hijackthis

        1- Cliques sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'installation .
        A la fin de l'installe , le prg ce lance automatiquement : fermes le en cliquant sur la croix rouge .
        Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
        "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

        tuto pour utilisation :(merci balltrap34)
        Regardes ici, c'est parfaitement expliqué en images ,

        2- !! Déconnectes toi et fermes toute tes applications en cours !!

        Cliques sur le raccourci du bureau pour lancer le prg :

        S'il ne se lance pas clique ici

        fais un scan HijackThis en cliquant sur : "Do a system scan and save a logfile"

        --->copies-colles le rapport généré pour analyse
        1. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 14:44, on 2009-06-11
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v8.00 (8.00.6001.18702)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          c:\program files\a-squared free\a2service.exe
          C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          C:\Program Files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
          C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\WINDOWS\system32\tcpsvcs.exe
          C:\WINDOWS\System32\snmp.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
          C:\Program Files\Acer\Acer eConsole\MediaSync.exe
          C:\Acer\Empowering Technology\eRecovery\Monitor.exe
          C:\Program Files\Acer\Acer eMode Management\AspireService.exe
          C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Documents and Settings\christelle\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: (no name) - {010FA0FD-D72A-4D40-A968-2451339DCEE8} - (no file)
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {14370F76-7676-44A2-AD11-93A31C5FC9FC} - (no file)
          O2 - BHO: (no name) - {5208e0c5-833d-4410-bf04-ad2978b76dce} - (no file)
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\IPSBHO.DLL
          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
          O2 - BHO: (no name) - {6F638691-4537-4100-B4DE-44D0FA516896} - (no file)
          O2 - BHO: (no name) - {84CD36A9-8176-4E88-9C28-2071479D9621} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
          O2 - BHO: (no name) - {C14A32E9-EC69-4E3A-AA56-6F8043BABC5F} - (no file)
          O2 - BHO: (no name) - {c2118982-c409-4a52-ad41-2da3bda660b5} - (no file)
          O2 - BHO: (no name) - {D6D50BCB-A207-40E4-A465-FDFB1CDE463E} - (no file)
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
          O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
          O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
          O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
          O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
          O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
          O4 - HKLM\..\Run: [LaunchApp] Alaunch
          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
          O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
          O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
          O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
          O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
          O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
          O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [Canal Widget] "C:\Program Files\Canal\Canal Widget\Launcher.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\christelle\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
          O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O20 - Winlogon Notify: cbxwttq - C:\WINDOWS\
          O20 - Winlogon Notify: geBQJYPf - C:\WINDOWS\
          O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
          O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
          O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          O23 - Service: CanalPlus.VOD - Canal+ Active - C:\Program Files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe
          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
          O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
          O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
          1. Télécharge OTL de OLDTimer

            et enregistre le sur ton Bureau.

            Double clic sur OTL.exe pour le lancer.

            Copie la liste qui se trouve en gras ci-dessous,

            et colle-la dans la zone sous Customs Scans/Fixes


            :processes
            explorer.exe
            Boonty.exe
            iexplore.exe
            firefox.exe
            msnmsgr.exe
            mDNSResponder.exe

            :OTL
            O2 - BHO: (no name) - {010FA0FD-D72A-4D40-A968-2451339DCEE8} - (no file)
            O2 - BHO: (no name) - {14370F76-7676-44A2-AD11-93A31C5FC9FC} - (no file)
            O2 - BHO: (no name) - {5208e0c5-833d-4410-bf04-ad2978b76dce} - (no file)
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: (no name) - {6F638691-4537-4100-B4DE-44D0FA516896} - (no file)
            O2 - BHO: (no name) - {84CD36A9-8176-4E88-9C28-2071479D9621} - (no file)
            O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
            O2 - BHO: (no name) - {C14A32E9-EC69-4E3A-AA56-6F8043BABC5F} - (no file)
            O2 - BHO: (no name) - {c2118982-c409-4a52-ad41-2da3bda660b5} - (no file)
            O2 - BHO: (no name) - {D6D50BCB-A207-40E4-A465-FDFB1CDE463E} - (no file)
            O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

            :services
            Boonty Games
            Service Bonjour

            :reg
            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "RTHDCPL"=-
            "RemoteControl"=-
            "PHIME2002ASync"=-
            "PHIME2002A"=-
            "MSPY2002"=-
            "IMJPMIG8.1"=-
            "WorksFUD"=-
            "Microsoft Works Portfolio"=-
            "NeroFilterCheck"=-
            "Adobe Reader Speed Launcher"=-
            "QuickTime Task"=-
            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
            "swg"=-
            "MsnMsgr"=-
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxwttq]
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geBQJYPf]

            :commands
            [Purity]
            [emptytemp]
            [start explorer]
            [reboot]

            Clique sur RunFix pour lancer la suppression.

            Poste le rapport.

            ==========
            1. j'ai fait ce que tu m'as dit et j'ai un soucis otl s'est mis en route et s'est bloqué à cette ligne
              O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file) plus rien ne s'est passé pendant plus d'une heure j'ai redémarré mon système et j'ai un fichier appellé thumbs.db sur le bureau quand je clique dessus windows me met un message d'erreur et s'éteind et quand tout redémarre il me met un rapport d'erreur à envoyer et que le système a dut récupérer d'une grave erreur
              je fais quoi ?
              1. non on va le faire autrement

                Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                ! Déconnecte toi et ferme toutes tes applications en cours !

                Double-clique sur " RSIT.exe " pour le lancer .

                -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                * Devant l'option "List files/folders created ..." , tu choisis : 2 months

                * clique ensuite sur " Continue " pour lancer l'analyse ...

                -> laisse faire le scan et ne touche pas au PC ...

                Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

                Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                Important : poste un rapport, puis l'autre dans la réponse suivante
                Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

                ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
                1. Logfile of random's system information tool 1.06 (written by random/random)
                  Run by christelle at 2009-06-11 19:20:11
                  Microsoft Windows XP Édition familiale Service Pack 3
                  System drive C: has 5 GB (6%) free of 93 GB
                  Total RAM: 767 MB (34% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 19:20, on 2009-06-11
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  c:\program files\a-squared free\a2service.exe
                  C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                  C:\Program Files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
                  C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                  C:\WINDOWS\system32\tcpsvcs.exe
                  C:\WINDOWS\System32\snmp.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\RTHDCPL.EXE
                  C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                  C:\Program Files\Acer\Acer eConsole\MediaSync.exe
                  C:\Program Files\Acer\Acer eMode Management\AspireService.exe
                  C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Documents and Settings\christelle\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                  C:\Program Files\Windows Live\Contacts\wlcomm.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\Documents and Settings\christelle\Bureau\RSIT.exe
                  C:\Program Files\Trend Micro\HijackThis\christelle.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\IPSBHO.DLL
                  O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
                  O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                  O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                  O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                  O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                  O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
                  O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                  O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
                  O4 - HKLM\..\Run: [LaunchApp] Alaunch
                  O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                  O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                  O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                  O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
                  O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
                  O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
                  O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [Canal Widget] "C:\Program Files\Canal\Canal Widget\Launcher.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\christelle\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                  O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                  O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                  O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                  O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
                  O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O20 - Winlogon Notify: cbxwttq - C:\WINDOWS\
                  O20 - Winlogon Notify: geBQJYPf - C:\WINDOWS\
                  O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
                  O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                  O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                  O23 - Service: CanalPlus.VOD - Canal+ Active - C:\Program Files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe
                  O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
                  O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
                  O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                  1. info.txt logfile of random's system information tool 1.06 2009-06-11 19:13:58

                    ======Uninstall list======

                    -->C:\WINDOWS\IsUn040c.exe -fC:\Sierra\LeGrandHuit\Uninst.isu
                    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                    7 Wonders of the Ancient World-->C:\Program Files\MumboJumbo\7 Wonders\uninst.exe
                    ABBYY FineReader 6.0 Sprint-->MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
                    Acer eConsole-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EC028E6B-F3F1-4192-B63E-A7C97302ED5A}\setup.exe" -l0x40c
                    Acer eMode Management-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{65CDEC30-4BF4-48FB-8059-9FC480E4E94F}\setup.exe" -l0x40c
                    Adobe Acrobat 5.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
                    Adobe AIR-->c:\Program Files\Fichiers communs\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
                    Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
                    Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                    Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                    Adobe Photoshop 7.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
                    Adobe Reader 8.1.5 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
                    adsl TV-->C:\Program Files\adslTV\Uninstal.exe
                    ALZip-->"C:\Program Files\ESTsoft\ALZip\unins000.exe"
                    Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
                    Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                    Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                    ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
                    Backgammon-->MsiExec.exe /I{FD128599-B6EC-4763-B1F5-00447C78E333}
                    Barre d'outils Outlook de Windows Live (Windows Live Toolbar)-->MsiExec.exe /X{6E15BEDF-7EB5-4010-998E-B430DB4EFE45}
                    Bejeweled 2 fr-->"C:\Program Files\BoontyGames\Bejeweled 2\unins000.exe"
                    Bloqueur de fenêtres pop-up (Windows Live Toolbar)-->MsiExec.exe /X{A425C250-A0E1-4D78-B1C1-A5CBC7385E7C}
                    Bobble Puzzle 0.90-->"C:\Program Files\Bobble Puzzle\unins000.exe"
                    Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                    CANAL WIDGET-->MsiExec.exe /X{09B6B322-325F-4A5F-9051-830ED194A1A7}
                    CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                    Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                    Code de la Route - 10 examens blancs-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{087EEDB6-0794-45CF-BD9D-907AED13A51A}\SETUP.EXE" -l0x40c
                    Correctif pour le Lecteur Windows Media [Voir Q828026 pour plus d'informations]-->C:\WINDOWS\$NtUninstallQ828026$\spuninst\spuninst.exe
                    Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                    Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
                    Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                    Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
                    Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{EFFCB0F1-CFEC-48D4-B793-EBFCAE852976}
                    Encyclopédie Standard Microsoft Encarta 2002-->MsiExec.exe /I{01020202-823E-46CD-A70E-BEE818F97169}
                    EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
                    EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
                    EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F19D07BC-6240-49D3-BA5C-59B015DF8916}\SETUP.EXE" -l0x40c UNINST
                    EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
                    EPSON Image Clip Palette-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{314F6D08-A8B7-11D8-8446-0050BA1D384D}\Setup.exe" -l0x40c -u
                    EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
                    EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
                    EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
                    EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
                    ESDX3800 Guide d'utilisation-->C:\Program Files\EPSON\TPMANUAL\ESDX3800\USE_G\DOCUNINS.EXE
                    Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{0CA6047C-D28B-4295-834A-07C52BA20C2D}
                    Fairy Treasure-->MsiExec.exe /I{F02C070C-3C95-4EB3-84A0-2452653A0402}
                    FpTest 3.0-->C:\Program Files\FpTest\uninst.exe
                    Freeplayer-->C:\Program Files\Freeplayer\Uninstall.exe
                    Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
                    getPlus(R)_dll-->rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\inf\GETPLUSd.INF, DefaultUninstall
                    Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
                    Google Toolbar for Firefox-->MsiExec.exe /X{2CCBABCB-6427-4A55-B091-49864623C43F}
                    Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
                    Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
                    Hercules WebCam Station-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D208F4A7-6B73-4C2A-8B1E-8756FCBA831E}\Setup.exe" -l0x40c
                    Hercules Webcam-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A250D351-A07F-4D5D-AB6C-693C69B9BFAF}\Setup.exe" -l0x40c
                    High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
                    HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                    Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                    InCD EasyWrite Reader-->C:\WINDOWS\unmrw.exe /UNINSTALL
                    Indeo® software-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Intel\Indeo® software\Uninst.isu"
                    Installation de Microsoft Works Suite 2002-->C:\Program Files\Microsoft Works Suite 2002\Setup\Launcher.exe E:\
                    Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                    Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                    Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
                    Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
                    Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
                    Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
                    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                    Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
                    Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
                    Kings Mahjongg-->C:\PROGRA~1\KINGSM~1\UNWISE.EXE C:\PROGRA~1\KINGSM~1\INSTALL.LOG
                    Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                    Maxi Puzzles-->"C:\Program Files\Micro Application\Maxi Puzzles\unins000.exe"
                    MegaCam-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{77F69001-4D35-4BEA-A074-26DA04EA0CDA}\Setup.exe" -l0x40c
                    Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
                    Micro Application - Super Casse-Briques 2-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Micro Application\Super Casse-Briques 2\Uninst.isu"
                    Micro Application - Super Casse-Briques-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Micro Application\Super Casse-Briques\Uninst.isu"
                    Micro Application - Super Patiences et Réussites-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Micro Application\Super Patiences et Réussites\Uninst.isu"
                    Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                    Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                    Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                    Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                    Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
                    Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                    Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
                    Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
                    Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                    Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                    Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                    Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                    Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                    Microsoft Media Manager 1.5-->C:\Program Files\Media Manager\Setup\Setup.exe
                    Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                    Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
                    Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0120-040C-0000-0000000FF1CE}
                    Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
                    Microsoft Picture It! Photo 2002-->MsiExec.exe /I{C769A271-7E1C-48F9-B331-474600DD4C06}
                    Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
                    Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                    Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                    Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                    Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                    Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                    Microsoft Works 6.0-->MsiExec.exe /I{FB12FDAC-457D-40D6-B6D6-9075AF29208E}
                    Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
                    Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
                    Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
                    Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
                    Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                    Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                    Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
                    Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                    Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
                    Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                    Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                    Mozilla Thunderbird (1.5)-->C:\WINDOWS\UninstallThunderbird.exe /ua "1.5 (fr)"
                    MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
                    MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                    MSXML 4.0 SP2 (KB925672)-->MsiExec.exe /I{A9CF9052-F4A0-475D-A00F-A8388C62DD63}
                    MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                    MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                    MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
                    Nero Media Player-->C:\WINDOWS\UNNMP.exe /UNINSTALL
                    Nero OEM-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
                    NeroVision Express 2-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
                    neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
                    Norton AntiVirus-->C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV\562C4DD5\16.5.0.134\InstStub.exe /X
                    Norton™ Security Scan-->MsiExec.exe /I{666CF041-77BE-414E-9A9D-0A227E9B48F8}
                    Nostale Online FR (Remove)-->"C:\Nostale(FR)\unins000.exe"
                    NTI Backup NOW! 4-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{385979FE-DC4F-4140-8EAD-A59625000D72} /l1036 BUN4
                    NTI CD & DVD-Maker-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
                    NTI HomeVideo-Maker-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B8A6F713-D72D-47AD-A92D-B5C0E13F98C1}\setup.exe" -l0x40c
                    OneCare Advisor (Windows Live Toolbar)-->MsiExec.exe /X{6D7F8D4B-D1A4-402A-973E-31E90940E585}
                    OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
                    Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
                    Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                    Panda ActiveScan 2.0-->C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
                    Panda ActiveScan-->C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan
                    Panda NanoScan-->C:\Program Files\Panda Security\NanoScan\nanounst.exe
                    Pharaon-->C:\WINDOWS\IsUn040c.exe -fC:\SIERRA\Pharaon\Uninst.isu
                    PIF DESIGNER-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B90450DF-E781-46FD-B1F1-0C86DA40E443}\SETUP.EXE" -l0x40c anything
                    Poker-->MsiExec.exe /I{58A7D3F8-0EBC-4AC6-9782-FC2C4F457E85}
                    PowerDVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
                    QuickTime Alternative 1.75-->"C:\Program Files\QuickTime Alternative\unins000.exe"
                    QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
                    QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
                    Rami-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4E5A0181-149F-4118-B28D-15862A4FDBE3}\SETUP.EXE" -l0x40c
                    Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x40c -removeonly
                    Reversi 3D Deluxe 1.4-->"C:\Program Files\Micro Application\Reversi 3D Deluxe\unins000.exe"
                    Rocket Mania 1.01-->C:\Program Files\PopCap Games\Rocket Mania Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Rocket Mania Deluxe\Install.log"
                    Rolling Marbles-->"C:\Program Files\Micro Application\Rolling Marbles\unins000.exe"
                    SafeCast Shared Components-->C:\Program Files\Fichiers communs\Macrovision Shared\SafeCast\Install\CDAC13BA.EXE /uninstall
                    Satsuki Decoder Pack-->C:\Program Files\Satsuki Decoder Pack\Uninstall.exe
                    Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                    Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                    Shareaza 2.4.0.0-->"C:\Program Files\Shareaza\Uninstall\unins001.exe"
                    Shockwave-->C:\WINDOWS\system32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~2\Install.log
                    Spybot - Search & Destroy 1.5.2.20-->"C:\WINDOWS\unins000.exe"
                    Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
                    Super Casse-briques 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4E63A075-4252-48C4-AFEB-3E13C8424426}\SETUP.EXE" -l0x40c
                    Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
                    Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
                    Votre Budget 2005 - Edition Micro Classic-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5A159497-7084-4BB6-83A9-0070FBCCAD34}\Setup.exe" -l0x40c
                    Winamax Poker (remove only)-->"C:\Program Files\WinamaxPoker\uninst.exe"
                    Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
                    Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                    Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                    Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
                    Windows Live Favorites pour Windows Live Toolbar-->MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
                    Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
                    Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                    Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
                    Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                    Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
                    Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                    Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                    Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                    Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                    WinFlyer-->"rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,UnInstall
                    XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
                    Yahoo! Toolbar avec bloqueur de fenêtres pop-up-->C:\PROGRA~1\Yahoo!\Common\unyt.exe

                    ======Hosts File======

                    127.0.0.1 www.007guard.com
                    127.0.0.1 007guard.com
                    127.0.0.1 008i.com
                    127.0.0.1 www.008k.com
                    127.0.0.1 008k.com
                    127.0.0.1 www.00hq.com
                    127.0.0.1 00hq.com
                    127.0.0.1 010402.com
                    127.0.0.1 www.032439.com
                    127.0.0.1 032439.com

                    ======Security center information======

                    AV: Norton AntiVirus (disabled)

                    ======System event log======

                    Computer Name: KIPSNY
                    Event Code: 29
                    Message: Le fournisseur de temps NtpClient est configuré pour acquérir le temps à partir d'une
                    ou plusieurs sources de temps, cependant aucune source n'est actuellement accessible.
                    Aucune tentative pour en contacter une ne sera effectuée d'ici 479 minutes.
                    NtpClient n'a pas de source de temps précis.

                    Record Number: 82552
                    Source Name: W32Time
                    Time Written: 20090509170250.000000+120
                    Event Type: erreur
                    User:

                    Computer Name: KIPSNY
                    Event Code: 17
                    Message: Fournisseur de temps NtpClient : une erreur s'est produite lors de la recherche DNS de
                    l'homologue manuellement configuré 'time.windows.com,0x1'. NtpClient va essayer à nouveau
                    la recherche DNS dans 480 minutes.
                    L'erreur était : Une opération a été tentée sur un hôte impossible à atteindre. (0x80072751)

                    Record Number: 82551
                    Source Name: W32Time
                    Time Written: 20090509170250.000000+120
                    Event Type: erreur
                    User:

                    Computer Name: KIPSNY
                    Event Code: 29
                    Message: Le fournisseur de temps NtpClient est configuré pour acquérir le temps à partir d'une
                    ou plusieurs sources de temps, cependant aucune source n'est actuellement accessible.
                    Aucune tentative pour en contacter une ne sera effectuée d'ici 239 minutes.
                    NtpClient n'a pas de source de temps précis.

                    Record Number: 82550
                    Source Name: W32Time
                    Time Written: 20090509130256.000000+120
                    Event Type: erreur
                    User:

                    Computer Name: KIPSNY
                    Event Code: 17
                    Message: Fournisseur de temps NtpClient : une erreur s'est produite lors de la recherche DNS de
                    l'homologue manuellement configuré 'time.windows.com,0x1'. NtpClient va essayer à nouveau
                    la recherche DNS dans 240 minutes.
                    L'erreur était : Une opération a été tentée sur un hôte impossible à atteindre. (0x80072751)

                    Record Number: 82549
                    Source Name: W32Time
                    Time Written: 20090509130256.000000+120
                    Event Type: erreur
                    User:

                    Computer Name: KIPSNY
                    Event Code: 7036
                    Message: Le service Google Software Updater est entré dans l'état : arrêté.

                    Record Number: 82548
                    Source Name: Service Control Manager
                    Time Written: 20090509113503.000000+120
                    Event Type: Informations
                    User:

                    =====Application event log=====

                    Computer Name: KIPSNY
                    Event Code: 218
                    Message: Operation could not complete because volume I:\ is not inserted in the drive.

                    Record Number: 86515
                    Source Name: Media Manager Indexer
                    Time Written: 20090513152641.000000+120
                    Event Type: erreur
                    User:

                    Computer Name: KIPSNY
                    Event Code: 218
                    Message: Operation could not complete because volume H:\ is not inserted in the drive.

                    Record Number: 86514
                    Source Name: Media Manager Indexer
                    Time Written: 20090513152641.000000+120
                    Event Type: erreur
                    User:

                    Computer Name: KIPSNY
                    Event Code: 218
                    Message: Operation could not complete because volume G:\ is not inserted in the drive.

                    Record Number: 86513
                    Source Name: Media Manager Indexer
                    Time Written: 20090513152641.000000+120
                    Event Type: erreur
                    User:

                    Computer Name: KIPSNY
                    Event Code: 218
                    Message: Operation could not complete because volume F:\ is not inserted in the drive.

                    Record Number: 86512
                    Source Name: Media Manager Indexer
                    Time Written: 20090513152641.000000+120
                    Event Type: erreur
                    User:

                    Computer Name: KIPSNY
                    Event Code: 101
                    Message:
                    Record Number: 86511
                    Source Name: Automatic LiveUpdate Scheduler
                    Time Written: 20090513152202.000000+120
                    Event Type: Informations
                    User: AUTORITE NT\SYSTEM

                    ======Environment variables======

                    "ComSpec"=%SystemRoot%\system32\cmd.exe
                    "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Samsung\Samsung PC Studio 3;C:\Program Files\ESTsoft\ALZip;C:\Program Files\QuickTime\QTSystem;C:\Program Files\QuickTime\QTSystem\
                    "windir"=%SystemRoot%
                    "FP_NO_HOST_CHECK"=NO
                    "OS"=Windows_NT
                    "PROCESSOR_ARCHITECTURE"=x86
                    "PROCESSOR_LEVEL"=15
                    "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 9, GenuineIntel
                    "PROCESSOR_REVISION"=0409
                    "NUMBER_OF_PROCESSORS"=2
                    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                    "TEMP"=%SystemRoot%\TEMP
                    "TMP"=%SystemRoot%\TEMP
                    "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                    "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

                    -----------------EOF-----------------
                    1. ---> Désactive ton antivirus le temps de la manipulation car OTM est détecté comme une infection à tort.

                      ---> Télécharge OTM (OldTimer) sur ton Bureau :

                      ---> Double-clique sur OTM.exe afin de le lancer.

                      ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                      :processes
                      explorer.exe

                      :services
                      Boonty Games
                      Service Bonjour

                      :files
                      C:\Windows\system32\reg.exe
                      C:\Windows\system32\tmp.txt
                      C:\Users\gaindja\AppData\Roaming\vlc(33)
                      C:\Windows\system32\un2065.txt
                      C:\Windows\system32\2065.txt

                      :reg
                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run]
                      "RTHDCPL"=-
                      "RemoteControl"=-
                      "PHIME2002ASync"=-
                      "PHIME2002A"=-
                      "MSPY2002"=-
                      "IMJPMIG8.1"=-
                      "WorksFUD"=-
                      "Microsoft Works Portfolio"=-
                      "NeroFilterCheck"=-
                      "Adobe Reader Speed Launcher"=-
                      "QuickTime Task"=-
                      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                      "swg"=-
                      "MsnMsgr"=-
                      [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxwttq]
                      [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geBQJYPf]

                      :commands
                      [purity]
                      [emptytemp]
                      [start explorer]
                      [reboot]

                      ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                      ---> Clique maintenant sur le bouton MoveIt! puis ferme OTM

                      Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                      Accepte en cliquant sur YES.

                      ---> Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
                      Le nom du rapport correspond au moment de sa création : date_heure.log
                      1. ========== PROCESSES ==========
                        Process explorer.exe killed successfully.
                        ========== SERVICES/DRIVERS ==========

                        Service\Driver Boonty Games deleted successfully.
                        Service\Driver Service Bonjour not found.
                        Service\Driver Service Bonjour not found.
                        ========== FILES ==========
                        C:\Windows\system32\reg.exe moved successfully.
                        File/Folder C:\Windows\system32\tmp.txt not found.
                        File/Folder C:\Users\gaindja\AppData\Roaming\vlc(33) not found.
                        File/Folder C:\Windows\system32\un2065.txt not found.
                        File/Folder C:\Windows\system32\2065.txt not found.
                        ========== REGISTRY ==========
                        Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                        Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                        Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                        Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                        Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                        Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                        Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                        Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                        Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                        Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                        Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                        Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\swg deleted successfully.
                        Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MsnMsgr deleted successfully.
                        Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxwttq\\ deleted successfully.
                        Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geBQJYPf\\ deleted successfully.
                        ========== COMMANDS ==========
                        User's Temp folder emptied.
                        User's Internet Explorer cache folder emptied.
                        File delete failed. C:\Documents and Settings\christelle\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                        User's Temporary Internet Files folder emptied.
                        File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
                        File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
                        File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
                        Local Service Temp folder emptied.
                        Local Service Temporary Internet Files folder emptied.
                        Network Service Temp folder emptied.
                        Network Service Temporary Internet Files folder emptied.
                        File delete failed. C:\WINDOWS\temp\JET92B5.tmp scheduled to be deleted on reboot.
                        File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_264.dat scheduled to be deleted on reboot.
                        File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_368.dat scheduled to be deleted on reboot.
                        File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5a0.dat scheduled to be deleted on reboot.
                        Windows Temp folder emptied.
                        Java cache emptied.
                        FireFox cache emptied.
                        Temp folders emptied.
                        Explorer started successfully

                        OTM by OldTimer - Version 2.1.0.1 log created on 06122009_131855

                        Files moved on Reboot...
                        File C:\WINDOWS\temp\JET92B5.tmp not found!
                        File C:\WINDOWS\temp\Perflib_Perfdata_264.dat not found!
                        C:\WINDOWS\temp\Perflib_Perfdata_368.dat moved successfully.
                        C:\WINDOWS\temp\Perflib_Perfdata_5a0.dat moved successfully.

                        Registry entries deleted on Reboot...

                        il m a demandai de redemarrer mais au redemarrage le pc à planté
                        1. j'ai un soucis j'arrive pas à l'allumer en mode sans echec
                          je faits F8 l'écran noir apparait je choisis mode sans echec puis windows et tout deviend noir et au bout d'un moment il redemarre normalement

                          1. /!\ ATTENTION SUIVRE SCRUPULEUSEMENT A LA LETTRE CES INDICATIONS/!\

                            _________________________________________________________________
                            >Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.<
                            >>>>>>>Ne pas utiliser en dehors de ce cas de figure : dangereux!<<<<<<<<
                            =====================================================


                            On va utiliser ComboFix.exe. Rends toi sur cette page web pour obtenir les liens de téléchargement, ainsi que des instructions pour exécuter l'outil:

                            https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                            Avant d'utiliser ComboFix :
                            ______________________________________________________________________
                            >> referme les fenêtres de tous les programmes en cours.
                            >> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix,
                            >>la protection en temps réel de ton Antivirus et de tes Antispywares,
                            >>qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

                            °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°


                            !!!!!NE TOUCHE A RIEN PENDANT LE TRAVAIL DE COMBOFIX (SOURIS/CLAVIER.....)!!!!!

                            n'oublie pas de reactiver la garde de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                            >> Reviens sur le forum, et

                            copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

                            1. ComboFix 09-06-14.02 - christelle 2009-06-15 8:13.7 - NTFSx86
                              Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.767.318 [GMT 2:00]
                              Lancé depuis: c:\documents and settings\christelle\Bureau\ComboFix.exe
                              AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

                              AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
                              .

                              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              c:\windows\BMe7eef818.txt
                              c:\windows\dcddeg.ini
                              c:\windows\ddfhii.ini
                              c:\windows\fggfii.ini
                              c:\windows\hgjihk.ini
                              c:\windows\kmonoq.ini
                              c:\windows\opppru.ini
                              c:\windows\patch.exe
                              c:\windows\ruwvxx.ini
                              c:\windows\system32\dumphive.exe
                              c:\windows\system32\SrchSTS.exe
                              c:\windows\system32\tmp.reg
                              c:\windows\system32\usfrxvda.ini
                              c:\windows\system32\VCCLSID.exe
                              c:\windows\system32\WS2Fix.exe
                              c:\windows\wayyxx.ini
                              c:\windows\yabddd.ini
                              c:\windows\ybbehk.ini

                              .
                              ((((((((((((((((((((((((((((( Fichiers créés du 2009-05-15 au 2009-06-15 ))))))))))))))))))))))))))))))))))))
                              .

                              2009-06-15 05:46 . 2009-05-30 08:31 165240 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
                              2009-06-15 05:39 . 2009-05-30 08:31 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090614.035\NAVENG.SYS
                              2009-06-15 05:39 . 2009-05-30 08:31 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090614.035\NAVEX15.SYS
                              2009-06-15 05:39 . 2009-05-30 08:31 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090614.035\NAVENG32.DLL
                              2009-06-15 05:39 . 2009-05-30 08:31 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090614.035\NAVEX32A.DLL
                              2009-06-15 05:39 . 2009-05-30 08:31 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090614.035\EECTRL.SYS
                              2009-06-15 05:39 . 2009-05-30 08:31 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090614.035\ERASER.SYS
                              2009-06-15 05:39 . 2009-05-30 08:31 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090614.035\ECMSVR32.DLL
                              2009-06-15 05:39 . 2009-05-30 08:31 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090614.035\CCERASER.DLL
                              2009-06-12 20:13 . 2009-05-30 08:31 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys
                              2009-06-12 20:13 . 2009-05-30 08:31 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSviA64.sys
                              2009-06-12 20:13 . 2009-05-30 08:31 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSvix86.sys
                              2009-06-12 20:13 . 2009-05-30 08:31 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSxpx86.dll
                              2009-06-12 20:13 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\Scxpx86.dll
                              2009-06-12 11:18 . 2009-06-12 11:18 -------- d-----w- C:\_OTM
                              2009-06-12 06:17 . 2009-03-06 06:47 38208 ----a-w- c:\documents and settings\christelle\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
                              2009-06-11 17:13 . 2009-06-11 17:13 -------- d-----w- C:\rsit
                              2009-06-11 14:16 . 2009-06-11 14:16 -------- d-----w- C:\_OTL
                              2009-06-11 06:21 . 2009-04-30 21:16 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
                              2009-06-11 06:21 . 2009-04-30 21:16 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
                              2009-06-08 19:01 . 2009-05-30 08:31 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSXpx86.sys
                              2009-06-08 19:01 . 2009-05-30 08:31 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSviA64.sys
                              2009-06-08 19:01 . 2009-05-30 08:31 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSvix86.sys
                              2009-06-08 19:01 . 2009-05-30 08:31 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\IDSxpx86.dll
                              2009-06-08 19:01 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090604.001\Scxpx86.dll
                              2009-06-03 08:53 . 2009-06-03 08:53 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
                              2009-05-30 08:33 . 2009-05-30 08:31 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
                              2009-05-30 08:32 . 2009-05-30 08:32 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
                              2009-05-30 08:32 . 2009-05-30 08:32 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
                              2009-05-30 08:32 . 2009-05-30 08:32 -------- d-----w- c:\program files\Symantec
                              2009-05-30 08:31 . 2009-05-30 08:31 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.sys
                              2009-05-30 08:31 . 2009-05-30 08:31 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvia64.sys
                              2009-05-30 08:31 . 2009-05-30 08:31 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
                              2009-05-30 08:31 . 2009-05-30 08:31 1290592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
                              2009-05-30 08:31 . 2009-05-30 08:31 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
                              2009-05-30 08:31 . 2009-05-30 08:31 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\idsxpx86.dll
                              2009-05-30 08:31 . 2009-05-30 08:31 796016 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
                              2009-05-30 08:29 . 2009-05-30 08:29 -------- d-----w- c:\windows\system32\drivers\NAV
                              2009-05-30 08:29 . 2009-05-30 08:30 -------- d-----w- c:\program files\Norton AntiVirus
                              2009-05-30 08:16 . 2009-05-30 08:16 -------- d-----w- c:\documents and settings\All Users\Application Data\PCSettings
                              2009-05-30 08:16 . 2009-05-30 08:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
                              2009-05-30 08:16 . 2009-05-30 08:29 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
                              2009-05-30 08:16 . 2009-05-30 08:16 -------- d-----w- c:\program files\NortonInstaller
                              2009-05-25 07:13 . 2009-05-25 07:13 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
                              2009-05-23 20:02 . 2009-05-23 20:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Alawar Stargaze
                              2009-05-23 17:22 . 2009-05-23 17:22 -------- d-sh--w- c:\documents and settings\christelle\PrivacIE
                              2009-05-23 13:52 . 2009-05-23 13:52 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
                              2009-05-23 13:51 . 2009-05-23 13:51 -------- d-sh--w- c:\documents and settings\christelle\IETldCache
                              2009-05-23 13:16 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
                              2009-05-23 13:06 . 2009-05-23 13:16 -------- d-----w- c:\windows\system32\XPSViewer
                              2009-05-23 13:06 . 2009-05-23 13:06 -------- d-----w- c:\program files\MSBuild
                              2009-05-23 13:06 . 2009-05-23 13:06 -------- d-----w- c:\program files\Reference Assemblies
                              2009-05-23 13:05 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
                              2009-05-23 13:05 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
                              2009-05-23 13:05 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
                              2009-05-23 13:05 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
                              2009-05-23 13:05 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
                              2009-05-23 13:05 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
                              2009-05-23 13:05 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
                              2009-05-23 12:56 . 2009-06-11 08:07 -------- d-----w- c:\windows\ie8updates
                              2009-05-23 12:54 . 2009-05-23 12:56 -------- dc-h--w- c:\windows\ie8
                              2009-05-23 11:58 . 2008-04-14 01:57 32128 ----a-w- c:\windows\system32\drivers\wceusbsh.sys
                              2009-05-23 11:58 . 2008-04-14 01:57 32128 ----a-w- c:\windows\system32\dllcache\wceusbsh.sys

                              .
                              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              2009-06-14 17:33 . 2008-05-29 08:41 -------- d-----w- c:\program files\WinamaxPoker
                              2009-06-14 12:23 . 2007-02-21 12:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
                              2009-06-13 14:59 . 2008-11-04 10:53 -------- d-----w- c:\program files\Mario Forever
                              2009-06-12 20:44 . 2008-11-29 18:23 -------- d-----w- c:\program files\adslTV
                              2009-06-12 12:26 . 2005-12-16 01:18 99918 ----a-w- c:\windows\system32\perfc00C.dat
                              2009-06-12 12:26 . 2005-12-16 01:18 542922 ----a-w- c:\windows\system32\perfh00C.dat
                              2009-06-11 21:42 . 2007-02-12 11:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                              2009-06-11 12:43 . 2008-03-29 10:22 -------- d-----w- c:\program files\Trend Micro
                              2009-06-11 12:10 . 2008-04-10 20:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
                              2009-06-11 12:10 . 2007-02-12 14:32 -------- d-----w- c:\program files\Lavasoft
                              2009-06-08 16:12 . 2007-03-08 11:22 51 ----a-w- c:\windows\popcinfo.dat
                              2009-06-05 20:17 . 2007-08-11 10:15 -------- d-----w- c:\program files\CCleaner
                              2009-05-30 09:36 . 2007-02-23 15:53 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
                              2009-05-30 08:32 . 2009-05-30 08:32 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
                              2009-05-30 08:32 . 2009-05-30 08:32 7386 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
                              2009-05-30 08:29 . 2005-12-16 09:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
                              2009-05-25 06:04 . 2006-06-30 20:46 101904 ----a-w- c:\documents and settings\christelle\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                              2009-05-23 19:50 . 2008-12-01 09:30 -------- d-----w- c:\program files\BoontyGames
                              2009-05-23 13:50 . 2007-02-12 11:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
                              2009-05-21 17:09 . 2007-05-28 09:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Ahead
                              2009-05-13 05:04 . 2005-07-03 02:16 915456 ----a-w- c:\windows\system32\wininet.dll
                              2009-05-07 15:33 . 2004-08-05 05:00 348672 ----a-w- c:\windows\system32\localspl.dll
                              2009-04-21 13:05 . 2009-04-21 13:05 86016 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\Zylom\fitnessdash\fr-FR\ZylomHost.exe
                              2009-04-21 13:05 . 2009-04-21 13:05 49152 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\Zylom\fitnessdash\fr-FR\ZylomAdapter.dll
                              2009-04-21 13:05 . 2009-04-21 13:05 2080768 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\Zylom\fitnessdash\fr-FR\fitnessdash.exe
                              2009-04-19 19:50 . 2007-04-09 17:13 1847296 ----a-w- c:\windows\system32\win32k.sys
                              2009-04-15 14:53 . 2004-08-05 05:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
                              2009-04-11 06:25 . 2009-04-11 06:25 152576 ----a-w- c:\documents and settings\christelle\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
                              2009-04-07 17:51 . 2009-04-07 17:51 135680 ----a-w- c:\documents and settings\christelle\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                              2009-04-07 17:51 . 2008-09-29 20:49 86576 ----a-w- c:\documents and settings\christelle\Application Data\Microsoft\Services Windows Live\Raccourci Galerie de Photos Windows Live.exe
                              2009-04-07 17:51 . 2008-09-29 20:49 392728 ----a-w- c:\documents and settings\christelle\Application Data\Microsoft\Services Windows Live\Services Windows Live.dll
                              2009-04-07 17:51 . 2008-09-29 20:49 132672 ----a-w- c:\documents and settings\christelle\Application Data\Microsoft\Services Windows Live\Raccourci Windows Live Messenger.exe
                              2009-04-06 10:14 . 2009-04-06 10:14 86016 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\Zylom\petshophop\fr-FR\ZylomHost.exe
                              2009-04-06 10:14 . 2009-04-06 10:14 49152 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\Zylom\petshophop\fr-FR\ZylomAdapter.dll
                              2009-04-06 10:14 . 2009-04-06 10:14 1974272 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\Zylom\petshophop\fr-FR\PetShopHop.exe
                              2009-03-19 07:08 . 2009-03-19 07:08 152576 ----a-w- c:\documents and settings\christelle\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
                              2007-07-04 11:14 . 2007-07-04 11:13 4704 ----a-w- c:\program files\satsukidecodersettings.ini
                              2007-07-04 11:13 . 2007-07-04 11:13 680 ----a-w- c:\program files\mpc2.reg
                              2007-07-04 11:13 . 2007-07-04 11:13 558 ----a-w- c:\program files\mpc1.reg
                              2007-07-04 11:13 . 2007-07-04 11:13 3476 ----a-w- c:\program files\mpc7.reg
                              2007-07-04 11:13 . 2007-07-04 11:13 30772 ----a-w- c:\program files\ffdsvsetts.reg
                              2007-07-04 11:13 . 2007-07-04 11:13 3026 ----a-w- c:\program files\mpc3.reg
                              2007-07-04 11:13 . 2007-07-04 11:13 236 ----a-w- c:\program files\mpc4.reg
                              2007-07-04 11:13 . 2007-07-04 11:13 18156 ----a-w- c:\program files\mpc6.reg
                              2007-07-04 11:13 . 2007-07-04 11:13 16290 ----a-w- c:\program files\mpc5.reg
                              2007-07-04 11:13 . 2007-07-04 11:13 32422 ----a-w- c:\program files\ffdssetts.reg
                              2007-07-04 11:13 . 2007-07-04 11:13 13366 ----a-w- c:\program files\ffdsasetts.reg
                              2007-04-04 11:33 . 2007-04-04 11:33 774144 ----a-w- c:\program files\RngInterstitial.dll
                              2007-02-21 12:05 . 2007-02-21 12:05 141312 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
                              2007-05-09 08:44 . 2007-05-09 08:44 977166 --sh--w- c:\windows\hgjihk.tmp
                              2007-04-27 09:16 . 2007-04-27 09:15 1064969 --sh--w- c:\windows\ruwvxx.tmp
                              2007-04-26 07:39 . 2007-04-26 07:39 1064858 --sh--w- c:\windows\ybbehk.tmp
                              .

                              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              .
                              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                              REGEDIT4

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                              "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
                              "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "LaunchApp"="Alaunch" [X]
                              "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
                              "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
                              "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
                              "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
                              "ntiMUI"="c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 45056]
                              "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
                              "MediaSync"="c:\program files\Acer\Acer eConsole\MediaSync.exe" [2005-09-21 425984]
                              "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
                              "eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 397312]
                              "AspireService"="c:\program files\Acer\Acer eMode Management\AspireService.exe" [2005-09-29 114688]
                              "WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2001-10-09 24576]
                              "Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2001-10-05 331830]
                              "Microsoft Works Update Detection"="c:\program files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2001-09-04 28738]
                              "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
                              "Canal Widget"="c:\program files\Canal\Canal Widget\Launcher.exe" [2009-04-22 170072]
                              "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
                              "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
                              "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
                              "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2005-09-22 14854144]
                              "High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                              "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                              c:\documents and settings\christelle\Menu D‚marrer\Programmes\D‚marrage\
                              Notification de cadeaux MSN.lnk - c:\documents and settings\christelle\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe [2009-4-7 135680]

                              c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                              Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-11-27 110592]

                              [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
                              BootExecute REG_MULTI_SZ autocheck autochk *\[u]0/upfdnnt c:\windows\system32\pfdnnt_actions.sys

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
                              @="FSFilter Activity Monitor"

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                              "DisableMonitoring"=dword:00000001

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                              "DisableMonitoring"=dword:00000001

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                              "DisableMonitoring"=dword:00000001

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                              "%windir%\\system32\\sessmgr.exe"=
                              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                              "c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
                              "c:\\WINDOWS\\system32\\ftp.exe"=
                              "c:\\Program Files\\Outlook Express\\msimn.exe"=
                              "c:\\WINDOWS\\system32\\rtcshare.exe"=
                              "c:\\Program Files\\Canal\\Canal Widget\\Launcher.exe"=
                              "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
                              "c:\\Program Files\\Shareaza\\Shareaza.exe"=
                              "c:\\Program Files\\adslTV\\adsltv.exe"=
                              "c:\\Program Files\\Messenger\\msmsgs.exe"=
                              "c:\\Program Files\\adslTV\\vlc.exe"=
                              "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                              "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                              "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                              "3587:TCP"= 3587:TCP:Groupement homologue Windows
                              "3540:UDP"= 3540:UDP:Protocole PNRP (Peer Name Resolution Protocol)
                              "6346:TCP"= 6346:TCP:shareaza
                              "6346:UDP"= 6346:UDP:shareaza

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
                              "AllowInboundEchoRequest"= 1 (0x1)

                              R0 m5287;m5287;c:\windows\system32\drivers\m5287.sys [2005-02-05 85888]
                              R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1005000.086\SymEFA.sys [2009-05-30 310320]
                              R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1005000.086\BHDrvx86.sys [2009-05-30 258608]
                              R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1005000.086\cchpx86.sys [2009-05-30 482352]
                              R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys [2009-06-12 276344]
                              R2 CanalPlus.VOD;CanalPlus.VOD;c:\program files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe [2008-06-03 188416]
                              R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-02-21 55152]
                              R2 MMIndexer;Media Manager Indexer;c:\program files\Fichiers communs\Microsoft Shared\Media Manager\AIRSVCU.EXE [1997-07-15 136704]
                              R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe [2009-05-30 115560]
                              R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-05-30 101936]
                              S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
                              S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
                              S3 MBAMCatchMe;MBAMCatchMe;\??\c:\windows\system32\drivers\mbamcatchme.sys --> c:\windows\system32\drivers\mbamcatchme.sys [?]
                              S3 ovt530;Webcam Classic;c:\windows\system32\drivers\ov530vid.sys [2007-08-23 161792]
                              S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [2008-02-02 44928]

                              --- Autres Services/Pilotes en mémoire ---

                              *NewlyCreated* - INT15.SYS

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                              p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

                              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                              "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
                              .
                              Contenu du dossier 'Tâches planifiées'

                              2009-06-11 c:\windows\Tasks\AppleSoftwareUpdate.job
                              - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

                              2009-06-15 c:\windows\Tasks\Google Software Updater.job
                              - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-21 18:56]
                              .
                              .
                              ------- Examen supplémentaire -------
                              .
                              uInternet Connection Wizard,ShellNext = iexplore
                              uInternet Settings,ProxyOverride = *.local
                              IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                              IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                              DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                              FF - ProfilePath -
                              .

                              **************************************************************************

                              catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2009-06-15 08:17
                              Windows 5.1.2600 Service Pack 3 NTFS

                              Recherche de processus cachés ...

                              Recherche d'éléments en démarrage automatique cachés ...

                              Recherche de fichiers cachés ...

                              Scan terminé avec succès
                              Fichiers cachés: 0

                              **************************************************************************

                              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
                              "ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.5.0.134\diMaster.dll\" /prefetch:1"
                              .
                              --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                              [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
                              "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
                              .
                              --------------------- DLLs chargées dans les processus actifs ---------------------

                              - - - - - - - > 'winlogon.exe'(1068)
                              c:\windows\system32\Ati2evxx.dll
                              .
                              Heure de fin: 2009-06-15 8:21
                              ComboFix-quarantined-files.txt 2009-06-15 06:21

                              Avant-CF: 6,883,876,864 octets libres
                              Après-CF: 6,863,417,344 octets libres

                              281 --- E O F --- 2009-06-11 08:08

                              voilà c'est fait combo fix n'a pas pu télécharger la console de récupération car je n'avais plus de connection internet est ce que je peux la télécharger manuellement ?
                              merci
                              • 1
                              • 2