Ordinateur desesperement lent .....

Bonjour, depuis 15 jours, mon ordinateur fait la greve du zele !!!!
meme ma grand mere va plus pour trouver une info avec son minitel que moi sur internet (ou pour ouvrir n'importe quel programme...)
l'autre jour, il lui a fallu, chrono en main, 7 minutes pour demarrer et afficher le bureau!!!!!
pourtant j'ai fait toute la panoplie, defragmentation, nettoyage du registre, etc (avec tuneup 2009), desinfection avec adaware et avg!!!
rien n'y fait
je sais que ma config n'est pas un foudre de guerre (ci joint le lien), mais bon, il tourné super bien jusqu'a la rentrée scolaire et depuis plus rien.
comprends pas
d'avacnce merci

http://www.ma-config.com/AfficheTempResume-16856.html

17 réponses

  1. Modérateur
    Salut,
    Niveau matériel, ça a l'air de tenir un peu la route, même si tu n'as pas assez de RAM, ...

    Fais ceci et on verra ensemble si tu es éventuellement infecté plus tard :

    * Télécharge Ccleaner Slim :
    = = = = >>> En cliquant ici <<< = = = =

    * Installe le.
    * Choisis l’onglet Nettoyeur

    Quitte ton navigateur Internet avant de le lancer, décoche la dernière case (Avancé si elle est cochée) puis clique sur "lancer le nettoyage" quand il aura terminé le scan cliques en bas à droite sur "lancer le nettoyage" et accepte par oui.
    Attention, il risque de vider ta corbeille : si tu veux récupérer des fichiers effacés par erreur, mieux vaut le faire maintenant.

    * Choisis l’onglet Registre

    - Clique sur Chercher des erreurs
    - Une fois la recherche terminée, clic sur Réparer les erreurs sélectionnées (par défaut, tout est sélectionné, laisse comme ça)
    - Au message Voulez-vous sauvegarder les changements faits dans le registre, réponds Oui et enregistre le fichier au format « .reg » en le nommant par la date par exemple en le mettant sur le bureau. Puis continue.
    - A la fenêtre qui s’ouvre ensuite, clique sur Corriger toutes les erreurs sélectionnées puis OK
    - Recommence jusqu’à ce qu’aucune erreur n’apparaisse (ou une seule récurrente).
    - Ferme Ccleaner.

    * Tutoriel en images ICI si besoin.

    Note : La sauvegarde utilisée permet de remettre tel que la base était avant la manipulation au cas où il y aurait des soucis mais cela ne m’est jamais arrivé ! Il vaut mieux prendre des précautions, c’est tout. ;-)
    0
    1. bonjour,
      merci de votre reponse
      j'ai lancé le nettoyage de ccleaner, ainsi que pour le registre
      il est propre et il n'y aplus de cle de registre invalide....
      mais toujours aussi lent
      merci
      0
      1. oui, j'ai assemblé mon pc moi-même, donc de ce coté là, va va!
        je fais la poussiere tous les six mois grand max.
        je suis en train de parcourir le tuto que tu m'as envoyé pour voir s'il a des modifs que je puisse faire.
        0
        1. Modérateur
          On va explorer ensuite la piste de l'infection ensuite...
          Tiens moi au courant de ce que tu as fait et des éventuels changements / améliorations
          0
          1. bon alors, j'etais en mode PIO, j'ai tout mis en DMA.
            j'ai redemaré, cela va un peu plus vite mais c'est pas encore ca pour l'ouverture des fichiers, logiciels et internet!!!
            ensuite comme c'est indiqué dans: "[Virus] Méthode préliminaire de désinfection"
            j'ai effectué RSIT, MBAM, et Bitdefender.
            pour Bitdefender, rien....
            Pour le reste, je te mets les rapports dans des posts differents
            0
            1. rapport MBAM

              Malwarebytes' Anti-Malware 1.41
              Version de la base de données: 2790
              Windows 5.1.2600 Service Pack 2

              13/09/2009 15:24:59
              mbam-log-2009-09-13 (15-24-59).txt

              Type de recherche: Examen rapide
              Eléments examinés: 92077
              Temps écoulé: 8 minute(s), 0 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 0
              Valeur(s) du Registre infectée(s): 1
              Elément(s) de données du Registre infecté(s): 3
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 0

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Valeur(s) du Registre infectée(s):
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.

              Elément(s) de données du Registre infecté(s):
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              (Aucun élément nuisible détecté)
              0
              1. Modérateur
                RSIT => Envoie le rapport.
                MBAM => Rien détecté ? Tu l'avais mis à jour avant de faire le scan ?
                Je veux bien le rapport aussi de MBAM (Malwarebytes' Anti Malware).
                0
                1. RSIT info.txt

                  info.txt logfile of random's system information tool 1.06 2009-09-13 15:11:26

                  ======Uninstall list======

                  -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00BA-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
                  ACDSee Gestionnaire de photos 2009-->MsiExec.exe /I{300578F9-9EFF-4B93-9AB1-C0E5707EF463}
                  ACDSee RAW Image Decoder Plug-In Update 4.0-->MsiExec.exe /X{1BF38C77-E678-49AF-885A-BBD10AED2FF3}
                  Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
                  Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
                  Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                  Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
                  Advertising Center-->MsiExec.exe /X{b2ec4a38-b545-4a00-8214-13fe0e915e6d}
                  Apple Application Support-->MsiExec.exe /I{0C34B801-6AEC-4667-B053-03A67E2D0415}
                  Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
                  Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                  Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                  AVG Free 8.5-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
                  Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                  CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                  CDBurnerXP-->"C:\Program Files\CDBurnerXP\unins000.exe"
                  Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                  DolbyFiles-->MsiExec.exe /X{b1adf008-e898-4fe2-8a1f-690d9a06acaf}
                  eMule-->"C:\Program Files\eMule\Uninstall.exe"
                  FileHippo.com Update Checker-->"C:\Program Files\FileHippo.com\uninstall.exe"
                  foobar2000 v0.9.6.8-->"C:\Program Files\foobar2000\uninstall.exe" _?=C:\Program Files\foobar2000
                  Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
                  HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                  Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                  Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                  ImgBurn-->"C:\Program Files\ImgBurn\uninstall.exe"
                  Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                  Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                  iTunes-->MsiExec.exe /I{EC2A8F27-4FBF-4E41-B27B-FE822511B761}
                  Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                  Ma-Config.com-->MsiExec.exe /X{494952B3-AA5A-486C-8495-6BF830962747}
                  Menu Templates - Starter Kit-->MsiExec.exe /X{b78120a0-cf84-4366-a393-4d0a59bc546c}
                  Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
                  Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                  Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
                  Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
                  Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                  Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                  Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                  Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
                  Microsoft Office Enterprise 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
                  Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
                  Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                  Microsoft Office Groove MUI (French) 2007-->MsiExec.exe /X{90120000-00BA-040C-0000-0000000FF1CE}
                  Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
                  Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
                  Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
                  Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                  Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                  Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                  Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                  Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                  Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                  Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                  Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                  Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
                  Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                  Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                  Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                  Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                  Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                  Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                  Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
                  Mise à jour pour Windows Internet Explorer 8 (KB972636)-->"C:\WINDOWS\ie8updates\KB972636-IE8\spuninst\spuninst.exe"
                  Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                  Movie Templates - Starter Kit-->MsiExec.exe /X{e498385e-1c51-459a-b45f-1721e37aa1a0}
                  MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                  MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                  MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                  MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{97AA1F3C-DD64-4AA6-AEC5-F8F9F4CC21C5}
                  Nero 9 Essentials-->C:\Program Files\Fichiers communs\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="XM02-508X-MHAT-19WU-9Z3Z-0CH0-3U6E-85W5-MMHH-6647-1Z5L-7M8C-0U45-758P-0000"
                  Nero 9 Trial-->C:\Program Files\Fichiers communs\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="8M01-209M-AH6P-5UW0-WHAW-C53X-473X-79MH"
                  Nero BurnRights-->MsiExec.exe /X{7829db6f-a066-4e40-8912-cb07887c20bb}
                  Nero ControlCenter-->MsiExec.exe /X{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}
                  Nero CoverDesigner-->MsiExec.exe /X{62ac81f6-bdd3-4110-9d36-3e9eaab40999}
                  Nero DiscSpeed-->MsiExec.exe /X{869200db-287a-4dc0-b02b-2b6787fbcd4c}
                  Nero DriveSpeed-->MsiExec.exe /X{33cf58f5-48d8-4575-83d6-96f574e4d83a}
                  Nero InfoTool-->MsiExec.exe /X{fbcdfd61-7dcf-4e71-9226-873ba0053139}
                  Nero Installer-->MsiExec.exe /X{e8a80433-302b-4ff1-815d-fcc8eac482ff}
                  Nero Live-->MsiExec.exe /X{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}
                  Nero PhotoSnap-->MsiExec.exe /X{9e82b934-9a25-445b-b8df-8012808074ac}
                  Nero Recode-->MsiExec.exe /X{359cfc0a-beb1-440d-95ba-cf63a86da34f}
                  Nero Rescue Agent-->MsiExec.exe /X{368ba326-73ad-4351-84ed-3c0a7a52cc53}
                  Nero ShowTime-->MsiExec.exe /X{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}
                  Nero StartSmart-->MsiExec.exe /X{7748ac8c-18e3-43bb-959b-088faea16fb2}
                  Nero Vision-->MsiExec.exe /X{43e39830-1826-415d-8bae-86845787b54b}
                  Nero WaveEditor-->MsiExec.exe /X{a209525b-3377-43f4-b886-32f6b6e7356f}
                  NeroBurningROM-->MsiExec.exe /X{d025a639-b9c9-417d-8531-208859000af8}
                  NeroExpress-->MsiExec.exe /X{595a3116-40bb-4e0f-a2e8-d7951da56270}
                  NeroLiveGadget-->MsiExec.exe /X{9e9fdde6-2c26-492a-85a0-05646b3f2795}
                  neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
                  NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
                  Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                  QuickTime-->MsiExec.exe /I{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}
                  Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
                  Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                  Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
                  Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
                  Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
                  Security Update for Microsoft Office Publisher 2007 (KB969693)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
                  Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
                  Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
                  Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                  SoundTrax-->MsiExec.exe /X{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}
                  Tag&Rename 3.5.1-->"C:\Program Files\TagRename\unins000.exe"
                  TuneUp Utilities 2009-->MsiExec.exe /I{55A29068-F2CE-456C-9148-C869879E2357}
                  Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                  Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                  Update for Microsoft Office Outlook 2007 (KB969907)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {74F98B24-AFBD-4800-9BD6-87D349B5C462}
                  Update for Outlook 2007 Junk Email Filter (kb972691)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {AA020E6E-E2FB-45EF-B732-2400E2296742}
                  Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
                  Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
                  VLC media player 1.0.1-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                  Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
                  Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                  Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                  Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                  Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
                  Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                  WinISO 5.3-->"C:\Program Files\WinISO\unins000.exe"
                  WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
                  WinSCP 4.1.9-->"C:\Program Files\WinSCP\unins000.exe"
                  WinZip 12.1-->MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}
                  ZoneAlarm-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

                  ======Hosts File======

                  127.0.0.1 babe.the-killer.bz
                  127.0.0.1 www.babe.the-killer.bz
                  127.0.0.1 babe.k-lined.com
                  127.0.0.1 www.babe.k-lined.com
                  127.0.0.1 did.i-used.cc
                  127.0.0.1 www.did.i-used.cc
                  127.0.0.1 coolwwwsearch.com
                  127.0.0.1 www.coolwwwsearch.com
                  127.0.0.1 coolwebsearch.com
                  127.0.0.1 www.coolwebsearch.com

                  ======Security center information======

                  AV: AVG Anti-Virus Free
                  FW: ZoneAlarm Firewall

                  ======System event log======

                  Computer Name: ORDINATEUR
                  Event Code: 6005
                  Message: Le service d'Enregistrement d'événement a démarré.

                  Record Number: 131
                  Source Name: EventLog
                  Time Written: 20090731230218.000000+120
                  Event Type: Informations
                  User:

                  Computer Name: ORDINATEUR
                  Event Code: 6009
                  Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Uniprocessor Free.

                  Record Number: 130
                  Source Name: EventLog
                  Time Written: 20090731230218.000000+120
                  Event Type: Informations
                  User:

                  Computer Name: ORDINATEUR
                  Event Code: 6006
                  Message: Le service d'Enregistrement d'événement a été arrêté.

                  Record Number: 129
                  Source Name: EventLog
                  Time Written: 20090731230127.000000+120
                  Event Type: Informations
                  User:

                  Computer Name: ORDINATEUR
                  Event Code: 7035
                  Message: Un contrôle Démarrer a correctement été envoyé au service vsdatant.

                  Record Number: 128
                  Source Name: Service Control Manager
                  Time Written: 20090731225315.000000+120
                  Event Type: Informations
                  User: ORDINATEUR\kafpa

                  Computer Name: ORDINATEUR
                  Event Code: 7036
                  Message: Le service Emplacement protégé est entré dans l'état : en cours d'exécution.

                  Record Number: 127
                  Source Name: Service Control Manager
                  Time Written: 20090731225031.000000+120
                  Event Type: Informations
                  User:

                  =====Application event log=====

                  Computer Name: ORDINATEUR
                  Event Code: 1000
                  Message: Les compteurs de performances pour le service MSDTC (MSDTC) ont été chargés.
                  Les données d'enregistrement contiennent les nouvelles valeurs d'index
                  assignées à ce service.

                  Record Number: 5
                  Source Name: LoadPerf
                  Time Written: 20090730221255.000000+120
                  Event Type: Informations
                  User:

                  Computer Name: ORDINATEUR
                  Event Code: 1000
                  Message: Les compteurs de performances pour le service TermService (Services Terminal Server) ont été chargés.
                  Les données d'enregistrement contiennent les nouvelles valeurs d'index
                  assignées à ce service.

                  Record Number: 4
                  Source Name: LoadPerf
                  Time Written: 20090730221252.000000+120
                  Event Type: Informations
                  User:

                  Computer Name: ORDINATEUR
                  Event Code: 1000
                  Message: Les compteurs de performances pour le service RemoteAccess (Routage et accès distant) ont été chargés.
                  Les données d'enregistrement contiennent les nouvelles valeurs d'index
                  assignées à ce service.

                  Record Number: 3
                  Source Name: LoadPerf
                  Time Written: 20090730221123.000000+120
                  Event Type: Informations
                  User:

                  Computer Name: ORDINATEUR
                  Event Code: 1000
                  Message: Les compteurs de performances pour le service PSched (PSched) ont été chargés.
                  Les données d'enregistrement contiennent les nouvelles valeurs d'index
                  assignées à ce service.

                  Record Number: 2
                  Source Name: LoadPerf
                  Time Written: 20090730221048.000000+120
                  Event Type: Informations
                  User:

                  Computer Name: ORDINATEUR
                  Event Code: 1000
                  Message: Les compteurs de performances pour le service RSVP (QoS RSVP) ont été chargés.
                  Les données d'enregistrement contiennent les nouvelles valeurs d'index
                  assignées à ce service.

                  Record Number: 1
                  Source Name: LoadPerf
                  Time Written: 20090730221047.000000+120
                  Event Type: Informations
                  User:

                  ======Environment variables======

                  "ComSpec"=%SystemRoot%\system32\cmd.exe
                  "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
                  "windir"=%SystemRoot%
                  "FP_NO_HOST_CHECK"=NO
                  "OS"=Windows_NT
                  "PROCESSOR_ARCHITECTURE"=x86
                  "PROCESSOR_LEVEL"=6
                  "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 6 Stepping 2, AuthenticAMD
                  "PROCESSOR_REVISION"=0602
                  "NUMBER_OF_PROCESSORS"=1
                  "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                  "TEMP"=%SystemRoot%\TEMP
                  "TMP"=%SystemRoot%\TEMP
                  "DEVMGR_SHOW_DETAILS"=1
                  "tvdumpflags"=8
                  "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
                  "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

                  -----------------EOF-----------------
                  0
                  1. Modérateur
                    RSIT génère deux rapports.
                    Il me faut le log.txt.

                    Vide la quarantaine de Malwarebytes' anti Malware.
                    0
                    1. Logfile of random's system information tool 1.06 (written by random/random)
                      Run by kafpa at 2009-09-13 15:10:03
                      Microsoft Windows XP Professionnel Service Pack 2
                      System drive C: has 17 GB (22%) free of 79 GB
                      Total RAM: 511 MB (6% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 15:11:10, on 13/09/2009
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\PROGRA~1\AVG\AVG8\avgtray.exe
                      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                      C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                      C:\WINDOWS\lclock.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\CDBurnerXP\NMSAccessU.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                      C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                      C:\WINDOWS\System32\TUProgSt.exe
                      C:\PROGRA~1\AVG\AVG8\avgemc.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\AVG\AVG8\avgcsrvx.exe
                      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Documents and Settings\kafpa\Local Settings\Temporary Internet Files\Content.IE5\SE4L1DQS\RSIT[1].exe
                      C:\Program Files\trend micro\kafpa.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/toolbar/ie8/sidebar.html
                      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.fr/?gws_rd=ssl
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKCU\..\Run: [LClock] lclock.exe
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-20\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\S-1-5-18\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - HKUS\.DEFAULT\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'Default user')
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
                      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://www.ma-config.com/activex/MaConfig_3_5_2_1.cab
                      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
                      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                      O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                      O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
                      O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
                      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                      0
                      1. Modérateur
                        Quel est ce programme ?
                        Advertising Center

                        ****

                        Le lecteur D correspond à ton lecteur CD ?

                        ****

                        Analyse ce fichier :
                        C:\WINDOWS\DUMPe629.tmp

                        Sur le site de virustotal :
                        https://www.virustotal.com/gui/

                        Parcourir > Sélectionne ton fichier > Analyser, patiente que l’analyse soit terminée.

                        Poste bien le rapport.

                        (Si VirusTotal indique que le fichier a déjà été analysé, clique sur le bouton Ré-analyse le fichier maintenant).
                        0
                        1. Advertising Center ????? connais pas!!!!!

                          **********************

                          lecteur D = lecteur CD

                          ***********************************

                          Fichier DUMPe629.tmp reçu le 2009.09.13 14:02:02 (UTC)
                          Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE

                          Résultat: 1/40 (2.5%)
                          en train de charger les informations du serveur...
                          Votre fichier est dans la file d'attente, en position: 24.
                          L'heure estimée de démarrage est entre 3 et 5 minutes.
                          Ne fermez pas la fenêtre avant la fin de l'analyse.
                          L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
                          Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
                          Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
                          les résultats seront affichés au fur et à mesure de leur génération.
                          Formaté Impression des résultats Votre fichier a expiré ou n'existe pas.
                          Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.
                          Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée. Email:

                          Antivirus Version Dernière mise à jour Résultat
                          a-squared 4.5.0.24 2009.09.13 -
                          AhnLab-V3 5.0.0.2 2009.09.13 -
                          AntiVir 7.9.1.14 2009.09.11 -
                          Antiy-AVL 2.0.3.7 2009.09.11 -
                          Authentium 5.1.2.4 2009.09.12 -
                          Avast 4.8.1351.0 2009.09.12 -
                          AVG 8.5.0.412 2009.09.13 -
                          BitDefender 7.2 2009.09.13 -
                          CAT-QuickHeal 10.00 2009.09.12 -
                          ClamAV 0.94.1 2009.09.13 -
                          Comodo 2304 2009.09.13 -
                          DrWeb 5.0.0.12182 2009.09.13 -
                          eSafe 7.0.17.0 2009.09.10 -
                          eTrust-Vet 31.6.6733 2009.09.11 -
                          F-Prot 4.5.1.85 2009.09.12 -
                          Fortinet 3.120.0.0 2009.09.13 -
                          GData 19 2009.09.13 -
                          Ikarus T3.1.1.72.0 2009.09.13 -
                          Jiangmin 11.0.800 2009.09.13 -
                          K7AntiVirus 7.10.843 2009.09.12 -
                          Kaspersky 7.0.0.125 2009.09.13 -
                          McAfee 5739 2009.09.12 -
                          McAfee+Artemis 5739 2009.09.12 -
                          McAfee-GW-Edition 6.8.5 2009.09.13 Heuristic.BehavesLike.Exploit.CodeExec.PGPG
                          Microsoft 1.5005 2009.09.13 -
                          NOD32 4421 2009.09.13 -
                          Norman 6.01.09 2009.09.11 -
                          nProtect 2009.1.8.0 2009.09.12 -
                          Panda 10.0.2.2 2009.09.13 -
                          PCTools 4.4.2.0 2009.09.11 -
                          Prevx 3.0 2009.09.13 -
                          Rising 21.46.61.00 2009.09.13 -
                          Sophos 4.45.0 2009.09.13 -
                          Sunbelt 3.2.1858.2 2009.09.12 -
                          Symantec 1.4.4.12 2009.09.13 -
                          TheHacker 6.3.4.4.402 2009.09.12 -
                          TrendMicro 8.950.0.1094 2009.09.13 -
                          VBA32 3.12.10.10 2009.09.11 -
                          ViRobot 2009.9.12.1932 2009.09.12 -
                          VirusBuster 4.6.5.0 2009.09.12 -
                          Information additionnelle
                          File size: 98304 bytes
                          MD5...: 4250e6977b59fe4d7186e495c099a333
                          SHA1..: 6749c8672d34094c633f8207d8630602d3a37c4f
                          SHA256: 7860cb2f2806dd6bb062bcd3371b7762c3a6c15165b7646497448af778df5a0f
                          ssdeep: 768:At3xfIl8wDly2ss7MLt+BqzLF3tE3KoFeo9fIDC4xHgj3cISLGHwd6a:ym8H
                          2m+Bq93tEvlSC4xHk3cbKHwd6a

                          PEiD..: -
                          PEInfo: -
                          RDS...: NSRL Reference Data Set
                          -
                          pdfid.: -
                          trid..: Windows memory dump (100.0%)
                          0
                          1. Modérateur
                            Supprime de la liste ajout/suppression de programmes "Advertiing center".

                            *******

                            Je ne vois pas d'infection.

                            *******

                            - Fais un scan en ligne avec Kaspersky = = = = >>> En cliquant ici <<< = = = = (avec Internet Explorer)

                            - En bas à droite, clique sur Démarrer Online-scaner

                            - Dans la nouvelle fenêtre qui s’affiche, clique sur J’accepte

                            - Accepte les Contrôles ActiveX

                            - Choisis Poste de travail pour le scan.

                            - Celui-ci terminé, sauvegarde (Choisis fichier texte) et poste le rapport

                            - Pour t’aider à utiliser le scan en ligne, tu as un tuto ICI

                            Note :
                            Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.
                            0
                            1. je n'est pas trouvé "advertising center" dans la liste ajout/suppression de programmes.
                              j'ai fait une recherche dans C:
                              mais rien
                              tu l'a vu où????
                              0
                              1. Modérateur
                                Ici :
                                Advertising Center-->MsiExec.exe /X{b2ec4a38-b545-4a00-8214-13fe0e915e6d} 


                                Télécharge OAD sur ton bureau :
                                = = = = =>>> En cliquant ici <<<= = = = =

                                * Double clique sur le OAD pour le lancer.
                                * Tape ceci dans la fenêtre qui s’ouvre

                                advertising

                                * Type de recherche : sélectionne l’option 6 puis valide [Entrée].

                                OAD va maintenant rechercher le fichier. Laisse le travailler jusqu’à ce qu’il ait terminé.
                                Le rapport de recherche s’affichera automatiquement à dès qu’il en aura terminé. (résultat.txt).

                                * Fais un copier / coller de ce rapport dans ton prochain message.

                                Note :
                                Suivant la taille des disques durs cette recherche peut prendre plusieurs minutes. Sois patient(e) !
                                0
                                1. 13/09/2009 ---- 16:34:13,90

                                  ----------------------------------
                                  §§§§§§ [advertising] §§§§§§
                                  ----------------------------------
                                  [X] Registre
                                  [ ] Fichier (rapide)
                                  [ ] Fichier (disque systeme)
                                  [X] Fichier (complete)

                                  ********************
                                  [Registre]
                                  ********************

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\83a4ce2b545b00a4284131efe019e5d6]
                                  "ProductName"="Advertising Center"

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BF35A546-B97C-4F53-8062-6CFB6087BE2D}]
                                  @="IAdvertisingSession2"

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Dynamic Directory\Conference]
                                  "advertisingScope"="local"

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\83a4ce2b545b00a4284131efe019e5d6\InstallProperties]
                                  "DisplayName"="Advertising Center"

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{b2ec4a38-b545-4a00-8214-13fe0e915e6d}]
                                  "DisplayName"="Advertising Center"

                                  [HKEY_USERS\S-1-5-21-1708537768-813497703-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU]
                                  "001"="advertising center"

                                  *******************
                                  [Fichier]
                                  *******************

                                  *********************
                                  [Même date]
                                  *********************

                                  Aucun fichier créé à la même date détecté

                                  ----------------------------------
                                  §§§§§ Fin Rapport §§§§§
                                  ----------------------------------
                                  0