Application Cannot Be executed

Résolu
Titedragonfly -  
 Remi2 -
Bonjour,
J'ai été sur un site de lunettes,((Taper dans google photo, "lunnette de vue dior"et 2eme photo,,si jme trompe pas) et en voulant agrandir la photo Antivir a "sonné".
Et depuis plus moyen de faire quoi que ce soit qui soit lié a Internet. Msn ect ni lancer des programmes dont mon Antivirus... Un message est ecrit en bas a droite "Application Cannot Be Executed....."
Quelqu'un pourrait-il m'aider?, J'ai déjà cherché un peu sur Internet mais en vain ....

Merci d'avance
Titedragonfly
Configuration: Windows Vista Internet Explorer 8.0

7 réponses

  1. Alfred
     
    bonjours,

    Procédure de téléchargement de ComboFix.exe.
    • Faites un clic-droit sur le lien de ComboFix (par sUBs) >>
    >> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    • Sélectionnez soit avec :
    - Internet Explorer : Enregistrer la cible sous...
    - Firefox : Enregistrer la cible du lien sous...

    ► Renommer ComboFix.exe pour CB-F.exe et sauvegarder le sur votre bureau.

    Procédures d'utilisation de ComboFix exe

    /|\ Désactivez votre antivirus et aute protection..
    /|\ Fermez tous les applications, n'ouvrez aucun programmes,
    /|\ Si ComboFix a besoin de redémarrer, laisser le aller.

    Double-cliquer sur Combofix et [Exécuter]
    • Si vous utilisez Windows Vista, cliquer sur le bouton [Continuer],
    • À la ’’Limitation de garantie du logiciel’’ -> [Oui],
    • Installerez la ’’Console de récupération’’ -> [Oui], (<-- Important)
    • Attendre la fermeture de l’outil (plus d’une 40aines d’étapes).

    /|\ Notez qu'une fois que vous avez lancé ComboFix,
    /|\ Vous ne devez pas cliquer dans la fenêtre de ComboFix,
    /|\ Cela pourrait même endommager Windows.

    ► Afficher le rapport de ComboFix (C:\Combofix.txt).

    Réactiver l'antivirus et autre protection.
    1
  2. Titedragonfly
     
    Bonjour,
    merci de votre reponse si rapide :))
    Je vais esssayer ce que vous m"avez dit, mais je ne suis pas très doué :s
    Pour desactiver l'antivirus je le desinstalle? vu que je ne peux pas "aller dedans"
    0
  3. Alfred
     
    re,

    L'intérêt de désactiver l'antivirus est que, celui-ci peut réagir au téléchargement ou à l'utilisation de combofix.

    Dans un tel cas, la désactivation est de mise, pour laisser aller combofix.

    Si l'antivirus est déjà désactiver par l'infection, n'en tenez pas compte et procédez..
    0
  4. Titedragonfly
     
    Re,

    Finalement après un examen complet du Pc avec MalwaresBytes tout est redevenu nickel :D

    Jvous remercie tout de meme pour votre aide qui pourra, surement, un jour m'etre utile.
    bonne soirée
    Titedragonfly
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Alfred
     
    re,

    C'est pas complet..

    Téléchargez RSIT (de random/random) sur votre bureau :
    http://images.malwareremoval.com/random/RSIT.exe
    • Double cliquez sur RSIT.exe,
    • Appuyez sur [Continue] à l'écran « Disclaimer »,
    • RSIT téléchargera HijackThis (s’il n’est pas installé) -> acceptez la licence,
    >> le rapport Log.txt va s'ouvrir à l'écran..
    >> l'autre est dans la barre de tâche, cliquez dessus pour l'ouvrir

    Postez les rapports qui sont aussi disponibles -> C:\RSIT\log.txt & info.txt
    0
    1. titeDragonfly
       
      bonjour,
      voilà les deux ""rapports""

      info.txt logfile of random's system information tool 1.06 2009-09-01 14:36:49

      ======Uninstall list======

      -->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
      32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
      Acer Arcade Live Main Page-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\SETUP.exe" -uninstall
      Acer DV Magician-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6EFFB76-4A07-11DA-9D78-000129760D75}\SETUP.exe" -uninstall
      Acer DVDivine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B145EC69-66F5-11D8-9D75-000129760D75}\SETUP.exe" -uninstall
      Acer eDataSecurity Management-->C:\Acer\Empowering Technology\eDataSecurity\eDSnstHelper.exe -Operation UNINSTALL
      Acer Empowering Technology-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB6097D9-D722-4987-BD9E-A076E2848EE2}\setup.exe" -l0x40c -removeonly
      Acer ePerformance Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D462BF9E-0C35-4705-BF9B-3DF9F3816643}\setup.exe" -l0x40c -removeonly
      Acer HomeMedia Connect-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{132888AE-EF67-41C5-BCA2-7D5D2488AB63}\SETUP.exe" -uninstall
      Acer HomeMedia-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\SETUP.exe" -uninstall
      Acer ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
      Acer SlideShow DVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{41581EF5-45A7-11DA-9D78-000129760D75}\SETUP.exe" -uninstall
      Acer Tour-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94389919-B0AA-4882-9BE8-9F0B004ECA35}\setup.exe" -l0x40c -removeonly
      Acer VideoMagician-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F79A208D-D929-11D9-9D77-000129760D75}\SETUP.exe" -uninstall
      Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
      Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Flash Player 10 Plugin-->MsiExec.exe /X{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
      Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
      Adobe Reader 7.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70000000000}
      a-squared Free 4.5-->"C:\Program Files\a-squared Free\unins000.exe"
      Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
      ATI Uninstaller-->C:\Program Files\ATI\CIM\Bin\Atisetup.exe -uninstall all
      Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
      Catalyst Control Center - Branding-->MsiExec.exe /I{D3B1C799-CB73-42DE-BA0F-2344793A095C}
      CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
      Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
      Coffret de pilotes Logitech Legacy USB Camera-->"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\legacyqcam\11.10.2016\LgDrvInst.exe" -remove -instdir"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\legacyqcam\" -enumdelay=2000 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -arpregkey"legacyqcam_11.10" /clone_wait /hide_progress
      Coffret de pilotes Logitech QuickCam-->"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\11.80.1048\LgDrvInst.exe" -remove -instdir"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\" -enumdelay=2000 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -arpregkey"lvdrivers_11.80" /clone_wait /hide_progress
      EA Download Manager-->C:\Program Files\Electronic Arts\EADM\Uninstall.exe
      Free Mp3 Wma Converter V 1.8.0-->"C:\Program Files\Free Audio Pack\unins000.exe"
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
      HP Customer Participation Program 8.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
      HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
      HP OCR Software 8.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
      HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
      HP Photosmart.All-In-One Driver Software 8.0 .A-->C:\Program Files\HP\Digital Imaging\{282E5AB2-8E47-4571-B6FA-6B512555B557}\setup\hpzscr01.exe -datfile hposcr18.dat -onestop -showdisconnect -forcereboot
      HP Solution Center 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
      HP Update-->MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
      HPSSupply-->MsiExec.exe /X{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}
      Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
      Les Sims™ 3-->"C:\Program Files\InstallShield Installation Information\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}\Sims3Setup.exe" -runfromtemp -l0x040c -removeonly
      LimeWire 5.2.13-->"C:\Users\MR RICHARD\Desktop\Zik Cec\NRJ\LimeWire\uninstall.exe"
      Logitech QuickCam-->MsiExec.exe /X{3AF8FCCD-F51A-4014-9002-F195E1CBC876}
      Ma-Config.com-->MsiExec.exe /X{6C4D4FC0-467B-4BD7-8D11-50E49B2770D2}
      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
      Marvell Miniport Driver-->C:\Program Files\Marvell\Miniport Driver\Uninst.exe
      Messenger Plus! Live-->"C:\Users\MR RICHARD\Pictures\2008-01-03\Messenger Plus! Live\Uninstall.exe"
      Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
      Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
      Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
      Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
      Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
      Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
      Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
      Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
      Microsoft WSE 3.0 Runtime-->MsiExec.exe /X{E3E71D07-CD27-46CB-8448-16D4FB29AA13}
      Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
      Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
      Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
      Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
      MSRedist-->MsiExec.exe /I{B7C61755-DB48-4003-948F-3D34DB8EAF69}
      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
      MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      NTI Backup NOW! 4.7-->"C:\Program Files\InstallShield Installation Information\{67ADE9AF-5CD9-4089-8825-55DE4B366799}\setup.exe" -removeonly
      NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
      ooVoo-->"C:\Program Files\InstallShield Installation Information\{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}\setup.exe" -runfromtemp -l0x040c -removeonly
      OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
      PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
      PhotoScape-->"C:\Program Files\PhotoScape\uninstall.exe"
      Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
      SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
      Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
      SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
      SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
      Samsung PC Studio 3 USB Driver Installer-->"C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -runfromtemp -l0x040c -removeonly
      Search Settings 1.2-->MsiExec.exe /X{D0C73318-7B4A-4D16-A0C4-3B83F075EA88}
      Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
      Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
      Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
      Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
      Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
      Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
      Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
      Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
      Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
      Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
      Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
      Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
      Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
      World of Warcraft FREE Trial-->MsiExec.exe /X{02EBDBB9-4600-41D3-B566-40CB861511D2}

      ======Hosts File======

      127.0.0.1 localhost
      ::1 localhost

      ======Security center information======

      AS: MalwareRemovalBot
      AS: Windows Defender (disabled)

      ======System event log======

      Computer Name: PC-de-MRRICHARD
      Event Code: 4321
      Message: Le nom "PC-DE-MRRICHARD:0" n'a pas pu être enregistré sur l'interface avec l'adresse IP 192.168.1.30. L'ordinateur avec l'adresse IP 192.168.1.18 n'a pas permis que le nom soit réclamé par cet ordinateur.
      Record Number: 127559
      Source Name: netbt
      Time Written: 20090901122414.717320-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-MRRICHARD
      Event Code: 3033
      Message: Le redirecteur n'a pas pu enregistrer l'adresse pour le transport NetBT_Tcpip_{016C67AB-3958-4532-94B9 pour la raison suivante : Vous n’étiez pas connecté car il y avait un nom en double sur le réseau. Si vous joignez un domaine, ouvrez le Panneau de configuration Système et modifiez le nom de l’ordinateur, puis réessayez. Si vous joignez un groupe de travail, choisissez un autre nom pour ce groupe.. Le transport a été déconnecté.
      Record Number: 127560
      Source Name: mrxsmb
      Time Written: 20090901122414.717320-000
      Event Type: Avertissement
      User:

      Computer Name: PC-de-MRRICHARD
      Event Code: 4321
      Message: Le nom "PC-DE-MRRICHARD:0" n'a pas pu être enregistré sur l'interface avec l'adresse IP 192.168.1.30. L'ordinateur avec l'adresse IP 192.168.1.18 n'a pas permis que le nom soit réclamé par cet ordinateur.
      Record Number: 127561
      Source Name: netbt
      Time Written: 20090901122414.744320-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-MRRICHARD
      Event Code: 2505
      Message: Le serveur n'a pas pu se lier au transport \Device\NetBT_Tcpip_{016C67AB-3958-4532-94B9-DE88A07AECF4} car un autre ordinateur du réseau porte le même nom. Le serveur n'a pas pu démarrer.
      Record Number: 127563
      Source Name: Server
      Time Written: 20090901122417.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-MRRICHARD
      Event Code: 4321
      Message: Le nom "PC-DE-MRRICHARD:20" n'a pas pu être enregistré sur l'interface avec l'adresse IP 192.168.1.30. L'ordinateur avec l'adresse IP 192.168.1.18 n'a pas permis que le nom soit réclamé par cet ordinateur.
      Record Number: 127564
      Source Name: netbt
      Time Written: 20090901122417.763320-000
      Event Type: Erreur
      User:

      =====Application event log=====

      Computer Name: PC-de-MRRICHARD
      Event Code: 1530
      Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

      DÉTAIL -
      31 user registry handles leaked from \Registry\User\S-1-5-21-1558475969-1620126114-2964982962-1000:
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000
      Process 1048 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\trust
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\trust
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\Root
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\Root
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\Disallowed
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\Disallowed
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\My
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\My
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\CA
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\CA
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\TrustedPeople
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Microsoft\SystemCertificates\TrustedPeople
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Policies\Microsoft\SystemCertificates
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Policies\Microsoft\SystemCertificates
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Policies\Microsoft\SystemCertificates
      Process 700 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Policies\Microsoft\SystemCertificates
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Policies\Microsoft\SystemCertificates
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Policies\Microsoft\SystemCertificates
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Policies\Microsoft\SystemCertificates
      Process 1220 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000\Software\Policies\Microsoft\SystemCertificates

      Record Number: 31033
      Source Name: Microsoft-Windows-User Profiles Service
      Time Written: 20090831133258.000000-000
      Event Type: Avertissement
      User: AUTORITE NT\SYSTEM

      Computer Name: PC-de-MRRICHARD
      Event Code: 1530
      Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

      DÉTAIL -
      1 user registry handles leaked from \Registry\User\S-1-5-21-1558475969-1620126114-2964982962-1000_Classes:
      Process 1048 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1558475969-1620126114-2964982962-1000_CLASSES

      Record Number: 31034
      Source Name: Microsoft-Windows-User Profiles Service
      Time Written: 20090831133259.000000-000
      Event Type: Avertissement
      User: AUTORITE NT\SYSTEM

      Computer Name: PC-de-MRRICHARD
      Event Code: 1002
      Message: Le programme ooVoo.exe version 2.1.0.51 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans l’application Rapports et solutions aux problèmes du Panneau de configuration. ID de processus : fac Heure de début : 01ca2a3fce5ba51e Heure de fin : 10
      Record Number: 31061
      Source Name: Application Hang
      Time Written: 20090831133522.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-MRRICHARD
      Event Code: 1002
      Message: Le programme wmplayer.exe version 11.0.6001.7007 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans l’application Rapports et solutions aux problèmes du Panneau de configuration. ID de processus : 24ec Heure de début : 01ca2a4bd7e3883e Heure de fin : 35
      Record Number: 31066
      Source Name: Application Hang
      Time Written: 20090831150243.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-MRRICHARD
      Event Code: 11
      Message: Échec de l'extraction de la liste racine tierce partie depuis le fichier CAB de mise à jour automatique à : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> avec l'erreur : Un certificat requis n'est pas dans sa période de validité selon la vérification par rapport à l'horloge système en cours ou le tampon daté dans le fichier signé.
      .
      Record Number: 31067
      Source Name: Microsoft-Windows-CAPI2
      Time Written: 20090831150302.000000-000
      Event Type: Erreur
      User:

      =====Security event log=====

      Computer Name: PC-de-MRRICHARD
      Event Code: 4648
      Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : PC-DE-MRRICHARD$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Compte dont les informations d’identification ont été utilisées :
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Serveur cible :
      Nom du serveur cible : localhost
      Informations supplémentaires : localhost

      Informations sur le processus :
      ID du processus : 0x27c
      Nom du processus : C:\Windows\System32\services.exe

      Informations sur le réseau :
      Adresse du réseau : -
      Port : -

      Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
      Record Number: 23500
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090320170514.722000-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-MRRICHARD
      Event Code: 4624
      Message: L’ouverture de session d’un compte s’est correctement déroulée.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : PC-DE-MRRICHARD$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7

      Type d’ouverture de session : 5

      Nouvelle ouverture de session :
      ID de sécurité : S-1-5-18
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      ID d’ouverture de session : 0x3e7
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Informations sur le processus :
      ID du processus : 0x27c
      Nom du processus : C:\Windows\System32\services.exe

      Informations sur le réseau :
      Nom de la station de travail :
      Adresse du réseau source : -
      Port source : -

      Informations détaillées sur l’authentification :
      Processus d’ouverture de session : Advapi
      Package d’authentification : Negotiate
      Services en transit : -
      Nom du package (NTLM uniquement) : -
      Longueur de la clé : 0

      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
      Record Number: 23501
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090320170514.722000-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-MRRICHARD
      Event Code: 4672
      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      ID d’ouverture de session : 0x3e7

      Privilèges : SeAssignPrimaryTokenPrivilege
      SeTcbPrivilege
      SeSecurityPrivilege
      SeTakeOwnershipPrivilege
      SeLoadDriverPrivilege
      SeBackupPrivilege
      SeRestorePrivilege
      SeDebugPrivilege
      SeAuditPrivilege
      SeSystemEnvironmentPrivilege
      SeImpersonatePrivilege
      Record Number: 23502
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090320170514.722000-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-MRRICHARD
      Event Code: 4616
      Message: L’heure du système a été modifiée.

      Sujet :
      ID de sécurité : S-1-5-19
      Nom du compte : SERVICE LOCAL
      Domaine du compte : AUTORITE NT
      ID d’ouverture de session : 0x3e5

      Informations sur le processus :
      ID du processus : 0x528
      Nom : C:\Windows\System32\svchost.exe

      Heure précédente : 18:05:16 20/03/2009
      Nouvelle heure : 18:05:16 20/03/2009

      Cet événement est généré lorsque l’heure du système est modifiée. Le changement régulier de l’heure du système est une opération normale de la part du service de temps Windows qui s’exécute avec des privilèges système. Mais, d’autres modifications de l’heure du système peuvent indiquer des tentatives de falsification de l’ordinateur.
      Record Number: 23503
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090320170516.406200-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-MRRICHARD
      Event Code: 1100
      Message: Le service d’enregistrement des événements a été arrêté.
      Record Number: 23504
      Source Name: Microsoft-Windows-Eventlog
      Time Written: 20090320170517.935000-000
      Event Type: Succès de l'audit
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
      "PROCESSOR_ARCHITECTURE"=x86
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "USERNAME"=SYSTEM
      "windir"=%SystemRoot%
      "PROCESSOR_LEVEL"=15
      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
      "PROCESSOR_REVISION"=6b01
      "NUMBER_OF_PROCESSORS"=2

      -----------------EOF-----------------










      Logfile of random's system information tool 1.06 (written by random/random)
      Run by MR RICHARD at 2009-09-01 14:36:47
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
      System drive C: has 54 GB (47%) free of 114 GB
      Total RAM: 1791 MB (57% free)

      HijackThis download failed

      ======Scheduled tasks folder======

      C:\Windows\tasks\MalwareRemovalBot System Startup.job

      ======Registry dump======

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
      AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
      SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
      ShowBarObj Class - C:\Windows\system32\ActiveToolBand.dll [2007-02-06 299008]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
      Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
      SearchSettings Class - C:\Program Files\Search Settings\kb127\SearchSettings.dll [2008-06-12 1111904]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
      {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Windows\system32\eDStoolbar.dll [2007-02-06 151552]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
      "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-18 1008184]
      "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-03-23 4423680]
      "Acer Tour"= []
      "Acer Empowering Technology Monitor"=C:\Acer\Empowering Technology\SysMonitor.exe [2007-01-24 319488]
      "eDataSecurity Loader"=C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe [2007-02-07 464168]
      "WarReg_PopUp"=C:\Acer\WR_PopUp\WarReg_PopUp.exe [2006-11-05 57344]
      "eRecoveryService"= []
      "Acer Tour Reminder"=C:\Acer\AcerTour\Reminder.exe [2007-02-15 151552]
      "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10 49152]
      "SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
      "SearchSettings"=C:\Program Files\Search Settings\SearchSettings.exe [2008-06-12 991584]
      "LogitechCommunicationsManager"=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2008-08-14 565008]
      "LogitechQuickCamRibbon"=C:\Program Files\Logitech\QuickCam\Quickcam.exe [2008-08-14 2407184]
      "avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
      "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-18 1233920]
      "MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
      "EA Core"=C:\Program Files\Electronic Arts\EADM\Core.exe -silent []
      "oovoo.exe"=C:\Program Files\ooVoo\oovoo.exe [2009-05-10 15337264]

      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
      Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe
      HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      PCM Media Sharing.lnk - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe

      C:\Users\MR RICHARD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
      Notification de cadeaux MSN.lnk - C:\Users\MR RICHARD\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
      OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
      "dontdisplaylastusername"=0
      "legalnoticecaption"=
      "legalnoticetext"=
      "shutdownwithoutlogon"=1
      "undockwithoutlogon"=1
      "EnableUIADesktopToggle"=0

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

      ======List of files/folders created in the last 1 months======

      2009-09-01 14:36:48 ----D---- C:\Program Files\trend micro
      2009-09-01 14:36:47 ----D---- C:\rsit
      2009-08-31 15:24:08 ----D---- C:\Users\MR RICHARD\AppData\Roaming\Malwarebytes
      2009-08-31 15:24:00 ----D---- C:\ProgramData\Malwarebytes
      2009-08-31 15:24:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
      2009-08-31 14:25:00 ----D---- C:\Program Files\Enigma Software Group
      2009-08-28 17:50:11 ----D---- C:\Program Files\a-squared Free
      2009-08-28 16:05:10 ----D---- C:\ProgramData\Avira
      2009-08-28 16:05:10 ----D---- C:\Program Files\Avira
      2009-08-28 15:23:08 ----D---- C:\Program Files\F-Secure Internet Security
      2009-08-27 09:56:09 ----A---- C:\Windows\system32\tzres.dll
      2009-08-26 17:34:31 ----A---- C:\Windows\system32\Apphlpdm.dll
      2009-08-26 17:34:27 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
      2009-08-13 11:28:20 ----A---- C:\Windows\system32\atl.dll
      2009-08-13 11:28:15 ----A---- C:\Windows\system32\wkssvc.dll
      2009-08-13 11:28:10 ----A---- C:\Windows\system32\mstscax.dll
      2009-08-13 11:28:06 ----A---- C:\Windows\system32\avifil32.dll
      2009-08-13 11:27:52 ----A---- C:\Windows\system32\wmp.dll
      2009-08-13 11:27:51 ----A---- C:\Windows\system32\wmpdxm.dll
      2009-08-13 11:27:50 ----A---- C:\Windows\system32\spwmp.dll
      2009-08-13 11:27:48 ----A---- C:\Windows\system32\dxmasf.dll
      2009-08-13 11:27:45 ----A---- C:\Windows\system32\wmploc.DLL
      2009-08-08 13:17:36 ----A---- C:\Windows\system32\infocardapi.dll
      2009-08-08 13:17:34 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
      2009-08-08 13:17:30 ----A---- C:\Windows\system32\icardagt.exe
      2009-08-08 13:17:29 ----A---- C:\Windows\system32\PresentationHostProxy.dll
      2009-08-08 13:17:29 ----A---- C:\Windows\system32\icardres.dll
      2009-08-08 13:17:24 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
      2009-08-08 13:17:07 ----A---- C:\Windows\system32\PresentationHost.exe
      2009-08-04 21:23:13 ----D---- C:\Users\MR RICHARD\AppData\Roaming\Mozilla
      2009-08-04 21:22:21 ----D---- C:\Users\MR RICHARD\AppData\Roaming\LimeWire

      ======List of files/folders modified in the last 1 months======

      2009-09-01 14:36:48 ----RD---- C:\Program Files
      2009-09-01 14:36:48 ----D---- C:\Windows\Prefetch
      2009-09-01 14:36:40 ----D---- C:\Windows\Temp
      2009-09-01 14:24:04 ----D---- C:\Windows\System32
      2009-09-01 14:21:49 ----D---- C:\Windows\system32\drivers
      2009-09-01 14:18:30 ----D---- C:\Windows\Tasks
      2009-09-01 08:29:57 ----D---- C:\Windows\system32\catroot
      2009-09-01 08:29:51 ----D---- C:\Windows\winsxs
      2009-09-01 01:46:32 ----SHD---- C:\System Volume Information
      2009-09-01 01:33:47 ----D---- C:\Windows\system32\catroot2
      2009-08-31 15:33:49 ----D---- C:\Windows
      2009-08-31 15:32:30 ----HD---- C:\ProgramData
      2009-08-31 14:27:31 ----D---- C:\Windows\inf
      2009-08-31 14:27:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
      2009-08-31 14:25:09 ----D---- C:\Windows\system32\Tasks
      2009-08-31 13:53:22 ----D---- C:\Windows\system32\wbem
      2009-08-31 13:52:50 ----D---- C:\Windows\system32\spool
      2009-08-31 13:52:50 ----D---- C:\Windows\system32\CodeIntegrity
      2009-08-31 13:52:49 ----D---- C:\Windows\registration
      2009-08-29 23:54:43 ----HD---- C:\Config.Msi
      2009-08-29 23:54:28 ----SHD---- C:\Windows\Installer
      2009-08-28 16:01:48 ----D---- C:\ProgramData\F-Secure
      2009-08-28 15:22:11 ----D---- C:\ProgramData\fssg
      2009-08-28 14:32:53 ----D---- C:\Windows\Debug
      2009-08-28 12:17:39 ----D---- C:\Windows\rescache
      2009-08-27 22:52:45 ----D---- C:\Windows\system32\fr-FR
      2009-08-27 22:52:44 ----D---- C:\Windows\AppPatch
      2009-08-14 13:42:38 ----D---- C:\Program Files\Windows Media Player
      2009-08-14 11:55:11 ----D---- C:\Program Files\Windows Mail
      2009-08-09 12:51:27 ----RSD---- C:\Windows\assembly
      2009-08-08 18:24:25 ----D---- C:\Windows\Microsoft.NET
      2009-08-08 13:25:29 ----D---- C:\Windows\system32\XPSViewer
      2009-08-08 13:25:29 ----D---- C:\Windows\system32\en-US

      ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

      R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [2009-02-13 11608]
      R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
      R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-08-28 28520]
      R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2009-08-28 55656]
      R2 int15;int15; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys [2006-12-07 76584]
      R3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\Windows\system32\drivers\AtiHdmi.sys [2009-02-20 95760]
      R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-02-26 4385792]
      R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-03-26 1761696]
      R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\Windows\system32\DRIVERS\LVPr2Mon.sys [2008-07-26 25624]
      R3 LVRS;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs.sys [2008-07-26 627864]
      R3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys [2008-07-26 41752]
      R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2007-05-06 6144]
      R3 pepifilter;Volume Adapter; C:\Windows\system32\DRIVERS\lv302af.sys [2008-07-26 13848]
      R3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\Windows\system32\DRIVERS\LV302V32.SYS [2008-07-26 2570520]
      R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2008-01-18 73088]
      R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-18 83328]
      R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2009-04-21 312320]
      S3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-18 131584]
      S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-18 16384]
      S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-18 36864]
      S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys [2009-05-29 14336]
      S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632]
      S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
      S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192]
      S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888]
      S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504]
      S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016]
      S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\Windows\system32\DRIVERS\ss_bus.sys [2007-05-02 83592]
      S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\Windows\system32\DRIVERS\ss_mdfl.sys [2007-05-02 15112]
      S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\Windows\system32\DRIVERS\ss_mdm.sys [2007-05-02 109704]
      S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-18 35328]
      S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-18 39936]
      S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

      ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

      R2 a2free;a-squared Free Service; C:\Program Files\a-squared Free\a2service.exe [2009-08-28 980512]
      R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service; C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-04-04 266343]
      R2 AcerMemUsageCheckService;ePerformance Service; C:\Acer\Empowering Technology\ePerformance\MemCheck.exe [2006-12-29 28672]
      R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-08-28 108289]
      R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-28 185089]
      R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2009-02-25 733184]
      R2 eDataSecurity Service;eDSService.exe; C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe [2007-02-07 457512]
      R2 eRecoveryService;eRecovery Service; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [2007-01-31 53248]
      R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-18 21504]
      R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
      R2 LVCOMSer;LVCOMSer; C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe [2008-07-26 186904]
      R2 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2008-07-26 150040]
      R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-18 21504]
      R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-18 21504]
      R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-04-09 143360]
      R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-18 21504]
      R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
      S2 CLTNetCnService;Symantec Lic NetConnect service; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
      S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2009-05-29 234864]
      S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
      S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
      S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

      -----------------EOF-----------------
      0
  7. Titedragonfly
     
    ok, je vous posterai ça demain. Hijackthis met beaucoup de temp à scanner le Pc?
    0
  8. Remi2
     
    Pas besoin d'rapport, utilisez ça et ça va être correct après..

    >>>>>>>>> Et n'utilisez pas combofix ,pas nécessaire <<<<<<<<<<<<

    Téléchargez sur votre bureau Ad-Remover ( C_XX) : http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

    /|\ Désactiver votre antivirus. /|\

    • Désactiver l’UAC : http://www.laboratoire-microsoft.org/tips-23933-desactiver-uac-vista.html
    • Installez Ad-remover et par un Clic droit > "Exécuter en tant qu'administrateur"
    • Lancez le (raccourci créé sur le bureau) par un Clic droit > "Exécuter en tant qu'administrateur"

    • Sélectionner la langue, "F" et validez par Entrée,
    • Déconnectez-vous, quittez les applications ouvertes
    • Sélectionner l'option [L. Lancer le nettoyage]

    >> Laisser le aller,
    • Lorsque le scan sera complété appuyez sur une touche pour ouvrir le rapport

    /|\ Réactiver votre antivirus. /|\
    0