Hack ou je sais pas :s

Bonjour, voila je me suis fais hacker mon msn , mon compte steam etc des petits truc comme ca .
J'ai lancer spybot mais il trouve rien et idem pour avast ...
Comment puis je savoir qui me hack et comment faire pour stoper se tdc ?
j'ai chercher sur le pc pour voir si j'ai un keylogger , j'ai rien trouver .
Bon il me reste plus a attendre une bonne ame pour m'aider Merci d'avance .
Configuration: Windows XP Internet Explorer 7.0

20 réponses

  1. salut :

    Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    ! Déconnecte toi et ferme toutes tes applications en cours !

    Double-clique sur " RSIT.exe " pour le lancer .

    -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    * Devant l'option "List files/folders created ..." , tu choisis : 2 months

    * clique ensuite sur " Continue " pour lancer l'analyse ...

    -> laisse faire le scan et ne touche pas au PC ...

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

    Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante
    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

    ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
    0
    1. info.txt logfile of random's system information tool 1.06 2009-07-25 16:39:49

      ======Uninstall list======

      -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
      -->MsiExec /X{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{22EB2FA7-1BA0-4FFB-972F-353EC6ABA9D5}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{28B97CAB-828F-49D8-A30A-675476F9BA92}\setup.exe" -l0x40c /cont -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4E7DC12A-3597-4A94-9429-F6C6987361B1}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6813C983-427E-4511-8456-E98FCAA1A125}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7DADB304-AF20-48C3-A780-4B4133A08817}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9C423CF6-2DAA-4A37-94B8-59D7ECC7DB13}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ACE66099-E18E-4037-83C8-9D182E5B9FA8}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B34B6E67-FCDD-4E03-8742-B5701427FAFB}\setup.exe" -l0x40c -removeonly
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FA6CC4B4-7741-4F8D-8E81-15C4BAB9869B}\setup.exe" -l0x40c -removeonly
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      1701 A.D. - The Sunken Dragon-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/7880
      7 Wonders - The Treasures of Seven-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/16030
      7 Wonders 2-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/15900
      Act of War: Direct Action-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/2710
      Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
      Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
      Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Reader 6.0.1-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A00000000001}
      Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
      Age of Booty-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/21600
      Age of Conan - Hyborian Adventures-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/6340
      Age of Conan: Hyborian Adventures-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/6330
      Age of Mythology - The Titans Expansion-->"C:\Program Files\Microsoft Games\Age of Mythology\UNINSTXP.EXE" /runtemp /addremove
      Age of Mythology-->"C:\Program Files\Microsoft Games\Age of Mythology\UNINSTAL.EXE" /runtemp /addremove
      AGEIA PhysX v7.11.13-->MsiExec.exe /X{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}
      Alien Shooter: Vengeance-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/6290
      Applian FLV Player-->"C:\WINDOWS\Applian FLV Player\uninstall.exe" "/U:C:\Program Files\FLV Player\Uninstall\uninstall.xml"
      Arcanum-->MsiExec.exe /I{08E9C35A-A0AE-43FA-AEA1-E4F58A87FBD1}
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Arx Fatalis-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/1700
      ATI Catalyst Control Center-->MsiExec.exe /I{0B4F3783-AC21-4A7D-9264-74D575EA3998}
      ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
      avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
      Bone: Out from Boneville-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/8310
      Braid Demo-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/26810
      Call of Duty 4: Modern Warfare-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/7940
      Call of Duty: United Offensive-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/2640
      Call of Duty: World at War-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/10090
      Call of Duty-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/2620
      Call of Juarez-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/3020
      Canon PIXMA iP3000-->C:\WINDOWS\system32\CNMCP61.exe "-PRINTERNAMECanon PIXMA iP3000" "-HELPERDLLC:\BJPrinter\CNMWINDOWS\Canon PIXMA iP3000 Installer\Inst2\cnmis.dll" "-RCDLLC:\BJPrinter\CNMWINDOWS\Canon PIXMA iP3000 Installer\Inst2\cnmi040c.dll"
      CloneCD-->"C:\Program Files\SlySoft\CloneCD\ccd-uninst.exe" /D="C:\Program Files\SlySoft\CloneCD"
      CloneDVD2-->"C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
      Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
      Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
      Command and Conquer: Red Alert 3-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/17480
      Commandos 2: Men of Courage-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/6830
      Commandos: Behind Enemy Lines-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/6800
      Correctif n° 2 pour Windows XP Édition Media Center 2005-->C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
      Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
      Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      Counter-Strike(TM)-->MsiExec.exe /I{DF5A03CC-D5AA-43D8-B948-D9903F2AF94A}
      Curse Client-->C:\Program Files\Curse\uninstall.exe
      DarkStar One-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/12330
      Dead Space-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/17470
      Deus Ex: Game of the Year Edition-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/6910
      DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
      DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
      Grand Theft Auto: San Andreas-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/12120
      Grey's Anatomy-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/21950
      High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
      Hotfix for Windows Media Player 10 (KB903157)-->"C:\WINDOWS\$NtUninstallKB903157$\spuninst\spuninst.exe"
      J2SE Runtime Environment 5.0 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150040}
      Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
      K-Lite Codec Pack 4.4.5 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
      KnightShift-->C:\PROGRA~1\DREAMC~1\KNIGHT~1\Unwise.exe /U C:\PROGRA~1\DREAMC~1\KNIGHT~1\install.log
      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
      LEGO Batman-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/21000
      MCE Software Encoder 1.0-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7655E113-C306-11D9-A373-0050BAE317E1}\setup.exe" -uninstall
      Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
      Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour le Codeur Windows Media (KB954156)-->"C:\WINDOWS\$NtUninstallKB954156_WM9L$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
      Mise à jour pour Lecteur Windows Media 10 (KB910393)-->"C:\WINDOWS\$NtUninstallKB910393$\spuninst\spuninst.exe"
      Mise à jour pour Lecteur Windows Media 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
      Mise à jour pour Lecteur Windows Media 10 (KB926251)-->"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
      Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
      MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
      NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
      Playboy - The Mansion-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{58D4AE57-ACDE-4A07-9BBD-34B15D54526C}\setup.exe" -l0x40c -removeonly
      PowerDVD-->"C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -l0x00040c /z-uninstall
      REALTEK GbE & FE Ethernet PCI NIC Driver-->C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\setup.exe -runfromtemp -l0x040c -removeonly
      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
      Sacred 2-->MsiExec.exe /I{1023383E-D9F6-478C-A965-23A4657B3C9A}
      Silverfall-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/4420
      Sonic Encoders-->MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011}
      Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
      Sony Picture Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5068583-D569-468B-9755-5FBF5848F46F}\setup.exe" -l0x40c /removeonly uninstall -removeonly
      Spore EP1-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/24720
      Spore: Creepy and Cute Parts-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/17440
      SPORE™-->"C:\Program Files\InstallShield Installation Information\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}\SPORESetup.exe" -runfromtemp -l0x040c -removeonly
      Spybot - Search & Destroy 1.5.2.20-->"C:\WINDOWS\unins000.exe"
      Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
      Star Wars Jedi Knight Jedi Academy-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1EECBA68-8BE4-4076-94DF-E9ED206B1D21}\Setup.exe" -l0x9
      Steam(TM)-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
      TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
      The Last Remnant Demo-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/23340
      THE SETTLERS - Bâtisseurs d'Empire-->"C:\Program Files\InstallShield Installation Information\{D3F80A98-05AB-4D8C-9272-766CCFA6A48D}\setup.exe" -runfromtemp -l0x040c -removeonly
      THE SETTLERS - L'Héritage des Rois (tous produits)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8FDC1610-3FB5-4EF2-A0D0-CEDC3A525A25}\setup.exe" -l0x40c -removeonly
      Tomb Raider: Anniversary-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/8000
      UFO: Afterlight-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/7500
      VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
      Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
      VideoLAN VLC media player 0.8.6h-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
      Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
      Windows XP Media Center Edition 2005 KB908246-->"C:\WINDOWS\$NtUninstallKB908246$\spuninst\spuninst.exe"
      Windows XP Media Center Edition 2005 KB912067-->"C:\WINDOWS\$NtUninstallKB912067$\spuninst\spuninst.exe"
      Windows XP Media Center Edition 2005 KB919803-->"C:\WINDOWS\$NtUninstallKB919803$\spuninst\spuninst.exe"
      Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
      World of Warcraft-->C:\Program Files\Fichiers communs\Blizzard Entertainment\World of Warcraft Public Test-PTR\Uninstall.exe
      X10 Hardware(TM)-->C:\WINDOWS\UNWISE.EXE C:\PROGRA~1\X10HAR~1\Install.log
      X-COM: Terror from the Deep-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/7650
      Zuma Deluxe-->"C:\Program Files\Valve\Steam\steam.exe" steam://uninstall/3330

      ======Hosts File======

      127.0.0.1 www.007guard.com
      127.0.0.1 007guard.com
      127.0.0.1 008i.com
      127.0.0.1 www.008k.com
      127.0.0.1 008k.com
      127.0.0.1 www.00hq.com
      127.0.0.1 00hq.com
      127.0.0.1 010402.com
      127.0.0.1 www.032439.com
      127.0.0.1 032439.com

      ======Security center information======

      AV: avast! antivirus 4.8.1335 [VPS 090724-0]

      ======System event log======

      Computer Name: SN117718850312
      Event Code: 2505
      Message: Le serveur n'a pas pu se lier au transport \Device\NetBT_Tcpip_{0397FC24-E0CC-47FC-8E9E-80FF9C358D0A} car un autre ordinateur du réseau porte le même nom. Le serveur n'a pas pu démarrer.

      Record Number: 5
      Source Name: Server
      Time Written: 20090714170309.000000+120
      Event Type: erreur
      User:

      Computer Name: SN117718850312
      Event Code: 1007
      Message: Votre ordinateur a automatiquement configuré l'adresse IP pour la
      carte avec l'adresse réseau 0016E6174286. L'adresse IP utilisée est 169.254.218.34.

      Record Number: 4
      Source Name: Dhcp
      Time Written: 20090714170303.000000+120
      Event Type: Avertissement
      User:

      Computer Name: SN117718850312
      Event Code: 1003
      Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir
      du serveur DHCP) pour la carte réseau dont l'adresse réseau est 0016E6174286. Il s'est
      produit l'erreur suivante :
      Le délai de temporisation de sémaphore a expiré.
      .
      Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du
      serveur d'adresse réseau (DHCP).

      Record Number: 3
      Source Name: Dhcp
      Time Written: 20090714170253.000000+120
      Event Type: Avertissement
      User:

      Computer Name: SN117718850312
      Event Code: 6005
      Message: Le service d'Enregistrement d'événement a démarré.

      Record Number: 2
      Source Name: EventLog
      Time Written: 20090714170224.000000+120
      Event Type: Informations
      User:

      Computer Name: SN117718850312
      Event Code: 6009
      Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 3 Multiprocessor Free.

      Record Number: 1
      Source Name: EventLog
      Time Written: 20090714170224.000000+120
      Event Type: Informations
      User:

      =====Application event log=====

      Computer Name: SN117718850312
      Event Code: 0
      Message:
      Record Number: 1378
      Source Name: RichVideo
      Time Written: 20090203024206.000000+060
      Event Type: Informations
      User:

      Computer Name: SN117718850312
      Event Code: 1800
      Message: Le service Centre de sécurité Windows a démarré.

      Record Number: 1377
      Source Name: SecurityCenter
      Time Written: 20090202172927.000000+060
      Event Type: Informations
      User:

      Computer Name: SN117718850312
      Event Code: 0
      Message:
      Record Number: 1376
      Source Name: RichVideo
      Time Written: 20090202172917.000000+060
      Event Type: Informations
      User:

      Computer Name: SN117718850312
      Event Code: 1005
      Message: Windows Installer a initié un redémarrage système afin de terminer ou de continuer la configuration de 'ATI Catalyst Control Center'.

      Record Number: 1375
      Source Name: MsiInstaller
      Time Written: 20090202172759.000000+060
      Event Type: Informations
      User: AZERTY\moi

      Computer Name: SN117718850312
      Event Code: 11707
      Message: Product: ATI Catalyst Control Center -- Installation operation completed successfully.

      Record Number: 1374
      Source Name: MsiInstaller
      Time Written: 20090202172759.000000+060
      Event Type: Informations
      User: AZERTY\moi

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=15
      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 7, GenuineIntel
      "PROCESSOR_REVISION"=0407
      "NUMBER_OF_PROCESSORS"=2
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP

      -----------------EOF-----------------
      0
      1. Logfile of random's system information tool 1.06 (written by random/random)
        Run by moi at 2009-07-25 16:39:30
        Microsoft Windows XP Professionnel Service Pack 3
        System drive C: has 228 GB (80%) free of 286 GB
        Total RAM: 1790 MB (64% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 16:39:46, on 25/07/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16850)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\ehome\ehtray.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\APPS\SAXO\HIDSERV.EXE
        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        C:\WINDOWS\system32\svchost.exe
        C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\WINDOWS\eHome\ehmsas.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\dllhost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Documents and Settings\moi\Bureau\RSIT.exe
        C:\Program Files\trend micro\moi.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
        O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
        O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
        O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
        O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
        O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
        O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
        O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
        O4 - HKCU\..\Run: [CurseClient] C:\Program Files\Curse\CurseClient.exe -silent
        O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
        O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
        O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
        O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Packard Bell BV - C:\APPS\SAXO\HIDSERV.EXE
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
        O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
        0
        1. merci l'ami et comme je dirais bonne chance ^^
          0
          1. ######## | XP _ Instal & recherche | #######

            Telecharge et install UsbFix (de C_XX & Chiquitine29)

            Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectés sans les ouvrir

            # Double clic sur le raccourci UsbFix présent sur ton bureau .

            # Choisi l option 1 ( Recherche )

            # Laisse travailler l outil.

            # Ensuite post le rapport UsbFix.txt qui apparaitra.

            # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

            ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

            # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
            Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

            0
            1. ############################## | UsbFix V6.011 |

              User : moi (Administrateurs) # AZERTY
              Update on 24/07/09 by Chiquitine29 & C_XX
              Start at: 17:09:22 | 25/07/2009
              Website : http://pagesperso-orange.fr/NosTools/index.html

              Intel(R) Pentium(R) D CPU 2.66GHz
              Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
              Internet Explorer 7.0.5730.13
              Windows Firewall Status : Enabled
              AV : avast! antivirus 4.8.1335 [VPS 090724-0] 4.8.1335 [ Enabled | Updated ]

              C:\ -> Disque fixe local # 279,45 Go (235,45 Go free) [HDD] # NTFS
              D:\ -> Disque CD-ROM # 0 Mo (0 Mo free) [Audio CD] # CDFS
              E:\ -> Disque CD-ROM
              F:\ -> Disque CD-ROM
              G:\ -> Disque CD-ROM
              H:\ -> Disque CD-ROM
              I:\ -> Disque CD-ROM
              J:\ -> Disque CD-ROM
              K:\ -> Disque fixe local # 596,17 Go (157,55 Go free) [DATA] # NTFS

              ############################## | Processus actifs |

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\ehome\ehtray.exe
              C:\WINDOWS\RTHDCPL.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\eHome\ehRecvr.exe
              C:\WINDOWS\eHome\ehSched.exe
              C:\APPS\SAXO\HIDSERV.EXE
              C:\Program Files\CyberLink\Shared Files\RichVideo.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
              C:\WINDOWS\ehome\mcrdsvc.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\WINDOWS\eHome\ehmsas.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\system32\dllhost.exe
              C:\WINDOWS\System32\alg.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
              C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              ################## | Fichiers # Dossiers infectieux |

              Présent ! K:\AUTORUN.FCB
              Présent ! K:\autorun.inf

              ################## | Registre # Clés Run infectieuses |

              ################## | Registre # Mountpoints2 |

              HKCU\..\..\Explorer\MountPoints2\{2b26bcb6-1591-11de-ba22-0022b06d6393}
              Shell\AutoRun\command =wd_windows_tools\WDSetup.exe

              HKCU\..\..\Explorer\MountPoints2\{62e5f0a4-9571-11dd-ab66-0016e6174286}
              Shell\AutoRun\command =K:\setupSNK.exe

              HKCU\..\..\Explorer\MountPoints2\{cc8cc65f-c08f-11dc-933c-0016e6174286}
              Shell\AutoRun\command =F:\autorun.exe
              Shell\dxinstall\command =F:\.\directx\dxsetup.exe
              Shell\readme\command =notepad readme.txt

              ################## | Cracks / Keygens / Serials |

              ################## | ! Fin du rapport # UsbFix V6.011 ! |
              0
              1. ########### | XP _ Suppression | ########

                (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

                • Double clic (clic droit "en tant qu'administrateur" pour Vista)sur le raccourci UsbFix présent sur ton bureau

                • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

                • Au second menu Choisis l'option " 2 " ( Suppression ) et tape sur [entrée]

                • Ton bureau disparaitra et le pc redémarrera .

                • Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

                • Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

                • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
                0
                1. ############################## | UsbFix V6.011 |

                  User : moi (Administrateurs) # AZERTY
                  Update on 24/07/09 by Chiquitine29 & C_XX
                  Start at: 17:58:57 | 25/07/2009
                  Website : http://pagesperso-orange.fr/NosTools/index.html

                  Intel(R) Pentium(R) D CPU 2.66GHz
                  Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                  Internet Explorer 7.0.5730.13
                  Windows Firewall Status : Enabled
                  AV : avast! antivirus 4.8.1335 [VPS 090724-0] 4.8.1335 [ Enabled | Updated ]

                  C:\ -> Disque fixe local # 279,45 Go (235,45 Go free) [HDD] # NTFS
                  D:\ -> Disque CD-ROM # 0 Mo (0 Mo free) [Audio CD] # CDFS
                  E:\ -> Disque CD-ROM
                  F:\ -> Disque CD-ROM
                  G:\ -> Disque CD-ROM
                  H:\ -> Disque CD-ROM
                  I:\ -> Disque CD-ROM
                  J:\ -> Disque CD-ROM
                  K:\ -> Disque fixe local # 596,17 Go (166,02 Go free) [DATA] # NTFS

                  ############################## | Processus actifs |

                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\csrss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Alwil Software\Avast4\setup\avast.setup
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\eHome\ehRecvr.exe
                  C:\WINDOWS\eHome\ehSched.exe
                  C:\APPS\SAXO\HIDSERV.EXE
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\WINDOWS\eHome\ehRec.exe
                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                  C:\WINDOWS\ehome\mcrdsvc.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINDOWS\system32\dllhost.exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                  C:\WINDOWS\System32\alg.exe

                  ################## | Fichiers # Dossiers infectieux |

                  ################## | All Drives ... |

                  Supprimé ! K:\AUTORUN.FCB
                  Supprimé ! K:\autorun.inf

                  ################## | Registre # Clés Run infectieuses |

                  ################## | Registre # Mountpoints2 |

                  Supprimé ! HKCU\...\Explorer\MountPoints2\{2b26bcb6-1591-11de-ba22-0022b06d6393}\Shell\AutoRun\Command
                  Supprimé ! HKCU\...\Explorer\MountPoints2\{cc8cc65f-c08f-11dc-933c-0016e6174286}\Shell\AutoRun\Command

                  ################## | Listing des fichiers présent |

                  [03/01/2006 06:12|-rahs----|208] -> C:\BOOT.BAK
                  [03/01/2006 06:20|-rahs----|289] -> C:\BOOT.INI
                  [10/08/2004 15:00|-rahs----|4952] -> C:\Bootfont.bin
                  [10/08/2004 15:00|-rahs----|263488] -> C:\cmldr
                  [03/01/2006 07:38|--a------|6447] -> C:\DWNLOG.TXT
                  [?|?|?] -> C:\hiberfil.sys
                  [09/01/2008 19:09|-rahs----|0] -> C:\IO.SYS
                  [03/01/2006 07:38|--a------|6447] -> C:\MCDLOG.TXT
                  [09/01/2008 19:09|-rahs----|0] -> C:\MSDOS.SYS
                  [10/08/2004 15:00|--a------|47564] -> C:\NTDETECT.COM
                  [18/01/2009 16:27|--a------|252240] -> C:\NTLDR
                  [18/01/2009 21:15|--ah-----|9175040] -> C:\NTUSER.DAT
                  [26/02/2009 13:30|--ah-----|1024] -> C:\ntuser.dat.LOG
                  [16/09/2008 04:44|--ahs----|184] -> C:\ntuser.ini
                  [?|?|?] -> C:\pagefile.sys
                  [25/07/2009 18:06|--a------|3473] -> C:\UsbFix.txt
                  [01/01/1995 02:00|-r-------|44] -> D:\Track01.cda
                  [01/01/1995 02:03|-r-------|44] -> D:\Track02.cda
                  [01/01/1995 02:07|-r-------|44] -> D:\Track03.cda
                  [01/01/1995 02:11|-r-------|44] -> D:\Track04.cda
                  [01/01/1995 02:13|-r-------|44] -> D:\Track05.cda
                  [01/01/1995 02:16|-r-------|44] -> D:\Track06.cda
                  [01/01/1995 02:20|-r-------|44] -> D:\Track07.cda
                  [01/01/1995 02:25|-r-------|44] -> D:\Track08.cda
                  [01/01/1995 02:28|-r-------|44] -> D:\Track09.cda
                  [01/01/1995 02:32|-r-------|44] -> D:\Track10.cda
                  [01/01/1995 02:37|-r-------|44] -> D:\Track11.cda
                  [01/01/1995 02:42|-r-------|44] -> D:\Track12.cda
                  [01/01/1995 02:46|-r-------|44] -> D:\Track13.cda
                  [01/01/1995 02:50|-r-------|44] -> D:\Track14.cda
                  [01/01/1995 02:54|-r-------|44] -> D:\Track15.cda
                  [01/01/1995 02:57|-r-------|44] -> D:\Track16.cda
                  [18/05/2009 07:00|--a------|48] -> K:\clep wep.txt
                  [?|?|?] -> K:\Instructions sur la r‚cup‚ration d'un disque.txt
                  [18/05/2009 06:59|--a------|0] -> K:\link.ftf
                  [16/07/2007 07:35|--ah-----|71738] -> K:\Maxtor_Desktop.ico
                  [04/12/2008 18:22|-rah-----|528] -> K:\MediaID.bin
                  [04/08/2004 00:55|--a------|28672] -> K:\setupSNK.exe
                  [26/11/2008 10:01|--ahs----|6656] -> K:\Thumbs.db

                  ################## | Vaccination |

                  # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                  # K:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

                  ################## | Cracks / Keygens / Serials |

                  ################## | ! Fin du rapport # UsbFix V6.011 ! |
                  0
                  1. Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                    Télécharges :

                    Malwarebytes

                    ou :

                    Malwarebytes

                    * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                    (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                    * Potasses le Tuto pour te familiariser avec le prg :

                    ( cela dit, il est très simple d'utilisation ).

                    relance malwarebytes en suivant scrupuleusement ces consignes :

                    ! Déconnecte toi et ferme toutes applications en cours !

                    * Lance Malwarebyte's .

                    Fais un examen dit "Complet" .

                    --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                    --> à la fin tu cliques sur "résultat" .
                    --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                    Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                    Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                    0
                    1. Malwarebytes' Anti-Malware 1.39
                      Version de la base de données: 2500
                      Windows 5.1.2600 Service Pack 3

                      25/07/2009 19:53:37
                      mbam-log-2009-07-25 (19-53-37).txt

                      Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|)
                      Eléments examinés: 150750
                      Temps écoulé: 23 minute(s), 17 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 1

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      k:\pc1\jeux\alcool+crac\alcohol 120% fr v1.9.6.5429 (xp_vista) + crack\alcohol 120% fr v1.9.6.5429 (crack)\Alcohol.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      0
                      1. Télécharge OTL de OLDTimer

                        et enregistre le sur ton Bureau.

                        Double clic sur OTL.exe pour le lancer.

                        Coche les 2 cases Lop et Purity

                        Coche la case devant scan all users

                        Clic sur Run Scan.

                        A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

                        Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

                        NE LE POSTE PAS SUR LE FORUM

                        Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

                        Clique sur Parcourir et cherche le fichier ci-dessus.

                        Clique sur Ouvrir.

                        Clique sur "Cliquez ici pour déposer le fichier".

                        Un lien de cette forme :

                        http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

                        est ajouté dans la page.

                        Copie ce lien dans ta réponse.

                        Tu feras la meme chose avec le "Extra.txt" s'il t'est demandé
                        0
                        1. Voila , j'ai aussi suprimer manuellement tout les dossiers et fichier alcohol et les starwind qui etais en exe dans le processus.
                          http://www.cijoint.fr/cjlink.php?file=cj200907/cijlyIcWoG.txt

                          http://www.cijoint.fr/cjlink.php?file=cj200907/cijhOh2IJW.txt
                          0
                          1. Télécharge HostXpert sur ton Bureau :

                            ---> Décompresse-le (Clic droit >> Extraire ici)

                            ---> Double-clique sur HostsXpert pour le lancer

                            ---> clique sur le bouton "Restore MS Hosts File" puis ferme le programme

                            PS : Avant de cliquer sur le bouton "Restore MS Hosts File", vérifie que le cadenas en haut à gauche est ouvert sinon tu vas avoir un message d'erreur.

                            s'il est fermé , clique dessus :)

                            ensuite :


                            Télécharge Zeb-Restore http://telechargement.zebulon.fr/zeb-restore.html enregistre ce fichier sur le bureau.

                            -Clic droit Zeb-Restore.zip ==> Extraire tout choisis comme lieu d'enregistrement le bureau.
                            -Ouvre le dossier ZR_1.0.0.37 ==> double clic sur Zeb-Restore.exe
                            - Coche la case devant :sites de confiance
                            - Ne coche aucune autre case
                            -Clique sur Restaurer
                            -Redémarre ton PC

                            ensuite :


                            Double clic sur OTL.exe pour le lancer.

                            Copie la liste qui se trouve en gras ci-dessous,

                            et colle-la dans la zone sous Customs Scans/Fixes

                            :processes
                            explorer.exe
                            iexplore.exe
                            firefox.exe
                            msnmsgr.exe
                            TeaTimer.exe

                            :OTL
                            @Alternate Data Stream - 72 bytes -> C:\WINDOWS:FE366DAAFB3FDE80

                            :commands
                            [emptytemp]
                            [start explorer]
                            [reboot]

                            Clique sur RunFix pour lancer la suppression.

                            Poste le rapport.

                            ensuite :

                            ♦ Passer de Avast à AntiVir :

                            ♦ Télécharge Désinstalleur d'Avast!.

                            ♦ redemarre en mode sans echec :

                            Comment aller en Mode sans échec
                            1) Redémarres ton ordi
                            2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                            3) Tu verras un écran avec options de démarrage apparaître
                            4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                            5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                            (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

                            ♦ Désinstalle via Ajout/Suppression de Programmes (si présents) :

                            * Avast!

                            ♦ ensuite execute le desinstaller

                            Ceci effacera la majorité des traces du produit Avast! d'Alwil Software.

                            ♦ redemarre

                            ♦ Télécharge Ccleaner sur ton Bureau. :

                            ♦ Clique sur "download the latest version"
                            ♦ Installe-le en laissant seulement les options suivantes cochées :

                            - Ajouter un raccourci sur le Bureau
                            - Contrôler automatiquement les mises à jour de CCleaner

                            ♦ Lance le Nettoyage
                            ♦ Clique sur Chercher des erreurs et sauvegarde si tu le souhaites.

                            plus de precision sur la configuration de ccleaner te seront donnees plus tard

                            tuto Comment utiliser CCleaner.
                            ***************

                            ♦ Télécharge Antivir en Francais ou Antivir en Francais sur ton Bureau.:

                            ♦ Double clique sur l'exécutable téléchargé pour lancer l'installation.
                            ♦ À la fin de l'installation, clique sur Finish.
                            ♦ Ouvre Antivir, assure-toi qu’il soit bien à jour !
                            ♦ Dans l'onglet Protection Locale, choisis Contrôler.
                            ♦ Active la recherche de rootkits via le + de Recherche de Rootkits, puis dans Sélection manuelle, coche tout (tes partitions de disque dur).
                            ♦ Clique sur la loupe du milieu pour lancer le scan en tant qu'Administrateur.
                            ♦ Poste moi le rapport généré : Pour cela, clique sur l'onglet Aperçu, puis choisis Rapports, tu trouveras son rapport..
                            ♦ Sélectionne le rapport et clique sur l'icône "Afficher le fichier de rapport du rapport sélectionné.

                            ♦ Note : Pour une éradication des menaces plus efficace, lance le scan en mode sans échec.

                            Pourquoi changer ? :Avast Vs Antivir

                            Tuto de configuration en vidéo (Merci Nico)

                            0
                            1. All processes killed
                              ========== PROCESSES ==========
                              No active process named explorer.exe was found!
                              Process iexplore.exe killed successfully!
                              No active process named firefox.exe was found!
                              No active process named msnmsgr.exe was found!
                              No active process named TeaTimer.exe was found!
                              ========== OTL ==========
                              ADS C:\WINDOWS:FE366DAAFB3FDE80 deleted successfully.
                              ========== COMMANDS ==========

                              [EMPTYTEMP]

                              User: Administrateur
                              ->Temp folder emptied: 0 bytes
                              ->Temporary Internet Files folder emptied: 32768 bytes

                              User: All Users

                              User: Default User
                              ->Temp folder emptied: 0 bytes
                              ->Temporary Internet Files folder emptied: 32768 bytes

                              User: LocalService
                              File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
                              File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
                              File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
                              ->Temp folder emptied: 115348 bytes
                              ->Temporary Internet Files folder emptied: 32902 bytes

                              User: moi
                              ->Temp folder emptied: 401 bytes
                              ->Temporary Internet Files folder emptied: 55135944 bytes

                              User: NetworkService
                              ->Temp folder emptied: 0 bytes
                              ->Temporary Internet Files folder emptied: 32902 bytes

                              %systemdrive% .tmp files removed: 0 bytes
                              C:\WINDOWS\msdownld.tmp folder deleted successfully.
                              %systemroot% .tmp files removed: 19569 bytes
                              %systemroot%\System32 .tmp files removed: 3072 bytes
                              File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                              File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_634.dat scheduled to be deleted on reboot.
                              Windows Temp folder emptied: 32768 bytes
                              RecycleBin emptied: 836 bytes

                              Total Files Cleaned = 52,87 mb

                              OTL by OldTimer - Version 3.0.10.3 log created on 07262009_033840

                              Files\Folders moved on Reboot...
                              File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
                              C:\WINDOWS\temp\Perflib_Perfdata_634.dat moved successfully.

                              Registry entries deleted on Reboot...
                              0
                              1. ok desolé j avais oublié de mettre en gras lol ^^

                                nickel j'attends le rappport de antivir
                                0
                                1. Oui , pas grave ^^ je l'intalle la :)
                                  0