Virus sur mon pc ?

Résolu
Bonjour,

Je pense être infecté par un virus inconnu, pouvez-vous me conseiller, voici ci-dessous le rappot hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:50:39, on 03/11/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\HaloLighting\HaloLighting.exe
C:\Program Files\Second Display Control\WisAvCtrl.exe
C:\Program Files\Second Display Control\WisOSD.exe
C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
C:\Program Files\Lenovo\ReadyComm\ReadyComm.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\SFR\Kit\9props.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\administrateur\AppData\Local\lbhfkafd.exe
C:\Program Files\Anti Trojan Elite\TJEnder.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Carbonite\CarbonitePreinstaller.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.francefootball.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.lenovo.com/fr/fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2flenovo.live.com%2f%3f
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Unattend0000000001{70EB91E7-FAAB-44A4-BA19-C0A45B228BC0}] C:\Windows\test.bat
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HaloLighting] C:\Program Files\Lenovo\HaloLighting\HaloLighting.exe
O4 - HKLM\..\Run: [WisAvCtrl] "C:\Program Files\Second Display Control\WisAvCtrl.exe"
O4 - HKLM\..\Run: [WisOSD] "C:\Program Files\Second Display Control\WisOSD.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled /pausefor=600
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Readycomm] C:\Program Files\Lenovo\ReadyComm\ReadyComm.exe -TrayMode
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [UUSeeMediaCenter] "C:\Program Files\Common Files\uusee\UUSeeMediaCenter.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [lbhfkafd] "c:\users\administrateur\appdata\local\lbhfkafd.exe" lbhfkafd
O4 - HKCU\..\Run: [Anti Trojan Elite] C:\Program Files\Anti Trojan Elite\TJEnder.exe :NO
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Service Google Update (gupdate1ca59b449148f70) (gupdate1ca59b449148f70) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Second Display Control\WisLMSvc.exe

--
End of file - 10233 bytes

Merci,
Configuration: Windows Vista Internet Explorer 7.0

26 réponses

Résumé de la discussion

Plusieurs utilisateurs échangent sur une suspicion d'infection par un virus inconnu et analysent un log HijackThis pour identifier les éléments potentiellement malveillants dans des scans et des rapports fournis. Des suggestions portent sur des outils comme Ad-Remover et des rapports RSIT, soulignant que certains éléments signalés peuvent être légitimes et nécessitent une vérification approfondie. Des exemples concrets illustrent des programmes préinstallés ou suspects et des mesures d’assainissement incluant des outils externes et des recommandations d’analyse plus approfondie pour éviter les faux positifs. En cas de doute, il est suggéré de partager les rapports consolidés et de vérifier les éléments nommément listés afin de déterminer les composants réellement malveillants et les actions pertinentes.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonsoir

    il faudrait télécharger navilog1 sur le bureau :
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    Certaines infections bloquent les telechargements d' outils de desinfection utilisez ce lien alternatif:
    http://ww38.toofiles.com/fr/oip/documents/exe/yop3.html

    /!\ Utilisateur de VISTA: il faudait déactiver l’UAC juste le temps de désinfection de votre pc, Vous le réactiverez plus tard :

    Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

    1°Double-clique sur navilog1.exe présent sur ton bureau
    2°Sélectionnez la langue désirée dans le menu puis valide le choix par la touche « entrer »
    3°Petit message d’avertissement, appuiez sur une touche pour passe à la suite
    4°un nouveau avertissement, appuie sur une touche pour suivre
    5°Vérification de l’installation de Navilog1 : si tout est bon, appuiez sur une touche pour continuer
    6°Choisir option 1 : recherche/désinfection automatique
    7°La recherche va se lancer automatiquement et peut durée quelques minutes, patientez
    8°Une fois l’analyse terminé, fermez et enregistrez votre travail en cours, puis appuiez sur une touche pour que votre pc puisse démarrer
    9°Au redémarrage du pc, Navilog va supprimer ce qu’il a trouvé, patientez quelques instants.

    Un rapport est gèneré par l'outil. Il se trouve à cette emplacement :
    XP : demarrer/poste de travail/c:/cleannavi.txt
    Vista : logo « demarrer »/ordinateur/c:/ cleannavi.txt

    Note : Vous pouvez désinstaller Navilog via ajout/surpression de programme de windows.

    Tuto en image : https://kerio.probb.fr/t3324-tuto-navilog
    1. Merci pour vos conseils,
      ci-dessou pour info le log navilog

      ix Navipromo version 4.0.4 commencé le 03/11/2009 23:08:05,46

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!

      Outil exécuté depuis C:\Program Files\navilog1

      Mise à jour le 02.11.2009 à 22h00 par IL-MAFIOSO

      Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
      X86-based PC ( Multiprocessor Free : Pentium(R) Dual-Core CPU T4200 @ 2.00GHz )
      BIOS : Ver 1.00
      USER : administrateur ( Not Administrator ! )
      BOOT : Normal boot

      Antivirus : Norton Internet Security 15.5.0.23 (Activated)
      Firewall : Norton Internet Security 15.5.0.23 (Activated)

      C:\ (Local Disk) - NTFS - Total:252 Go (Free:165 Go)
      D:\ (Local Disk) - NTFS - Total:30 Go (Free:28 Go)
      E:\ (CD or DVD)
      F:\ (USB)
      G:\ (CD or DVD) - UDF - Total:0 Go (Free:0 Go)
      H:\ (CD or DVD)

      Recherche executée en mode normal

      Nettoyage exécuté au redémarrage de l'ordinateur

      C:\Users\administrateur\AppData\Local\lbhfkafd.exe supprimé !
      C:\Users\administrateur\AppData\Local\lbhfkafd.dat supprimé !
      C:\Users\administrateur\AppData\Local\lbhfkafd_nav.dat supprimé !
      C:\Users\administrateur\AppData\Local\lbhfkafd_navps.dat supprimé !
      C:\Users\administrateur\AppData\Local\qnitolv.bat supprimé !

      Nettoyage contenu C:\Windows\Temp effectué !
      Nettoyage contenu C:\Users\ADMINI~1\AppData\Local\Temp effectué !

      *** Sauvegarde du Registre vers dossier Safebackup ***

      sauvegarde du Registre réalisée avec succès !

      *** Nettoyage Registre ***

      Nettoyage Registre Ok

      *** Scan terminé 03/11/2009 23:18:20,74 *
      1. Contributeur sécurité
        bien

        tu as dans ton pc

        C:\Program Files\Carbonite\CarbonitePreinstaller.exe

        qui est considéré comme infectieux
        alors

        Note importante :
        Pour les ordinateurs équipés de Windows Vista et Windows 7, la désactivation du Contrôle des comptes utilisateurs est obligatoire
        sous peine de ne pas pouvoir faire fonctionner correctement l'outil.
        Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

        Téléchargez et enregistrez ce fichier d installation sur le bureau
        http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

        Double cliquez sur le fichier d'installation de AD-Remover, le programme s'installera automatiquement.
        Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"
        Au menu principal choisir l'option "s" et tapez sur [entrée] .
        Laissez travailler l'outil et ne touchez à rien ...
        Postez le rapport qui apparait à la fin.

        ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

        (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        Note :Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
        1. Bonjour,

          Voici le nouveau rapport :

          ======= RAPPORT D'AD-REMOVER 1.1.4.5_Z | UNIQUEMENT XP/VISTA/7 =======
          .
          Mit à jour par C_XX le 17.10.2009 à 11:48
          Contact: AdRemover.contact@gmail.com
          Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
          .
          Lancé à: 9:16:47, 04/11/2009 | Mode Normal | Option: SCAN
          Exécuté de: C:\Program Files\Ad-Remover\
          Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 1 v6.0.6001
          Nom du PC: BABYBACH | Utilisateur actuel: administrateur
          .
          ============== ÉLÉMENT(S) TROUVÉ(S) ==============
          .

          HKCU\Software\Grand Virtual
          HKCU\Software\Poker 770
          HKCU\Software\Titan Poker
          HKLM\Software\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543}
          HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker
          HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Poker 770
          HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Titan Poker
          HKLM\Software\Poker 770
          HKLM\Software\Titan Poker
          HKU\S-1-5-21-1989916942-1817888777-3009363108-1004\Software\Titan Poker
          .
          C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Everest Poker
          C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Poker 770
          C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Titan Poker
          C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Titan Poker.lnk
          C:\Program Files\Everest Poker
          C:\Users\administrateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Titan Poker.lnk
          C:\Poker\Poker 770
          C:\Poker\Titan Poker
          C:\Users\Public\Desktop\Everest Poker.lnk
          C:\Users\ADMINI~1\AppData\Roaming\MICROS~1\Windows\Cookies\administrateur@everestpoker[2].txt
          .
          ============== Scan additionnel ==============
          .
          .
          * Mozilla FireFox Version 3.5.4 [fr] *
          .
          Nom du profil: vzakmizv.default (administrateur)
          .
          (Prefs.js) user_pref("browser.search.defaultenginename", "Chercher Malin");
          (Prefs.js) user_pref("browser.search.selectedEngine", "Google");
          (Prefs.js) user_pref("browser.startup.homepage", "www.google.fr");
          (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.1.4");
          .
          .
          * Internet Explorer Version 7.0.6001.18000 *
          .
          [HKEY_CURRENT_USER\..\Internet Explorer\Main]
          .
          Start Page: hxxp://www.francefootball.fr/
          Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
          .
          [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
          .
          Start Page: hxxp://lenovo.live.com/
          Default_Page_URL: hxxp://www.lenovo.com
          Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
          Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
          .
          [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
          .
          Tabs: res://ieframe.dll/tabswelcome.htm
          1. Contributeur sécurité
            Même outil

            En mode sans échec
            https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php

            Option L Lancer le nettoyage
            poster le rapport

            ensuite

            • Télécharge Random's System Information Tool (RSIT) de Random/Random.

            http://images.malwareremoval.com/random/RSIT.exe

            • Enregistre le sur ton Bureau.

            • Double clique sur RSIT.exe pour lancer l'outil.

            • Clique sur "Continue" à l'écran Disclaimer.

            • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

            et tu devras accepter la licence.

            • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp
            1. Alors voici le premier rapport appelé info :

              info.txt logfile of random's system information tool 1.06 2009-11-04 10:42:08

              ======Uninstall list======

              -->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
              -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
              2007 Microsoft Office system-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROHYBRIDR /dll OSETUP.DLL
              Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
              Ad-Aware-->"C:\ProgramData\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe" REMOVE=TRUE MODIFY=FALSE
              Ad-Aware-->C:\ProgramData\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
              Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
              Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
              Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
              Ad-Remover By C_XX-->"C:\Program Files\Ad-Remover\Uninstall ADR.exe"
              Anti Trojan Elite 4.7.4-->"C:\Program Files\Anti Trojan Elite\unins000.exe"
              AppCore-->MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
              Apple Application Support-->MsiExec.exe /I{0C34B801-6AEC-4667-B053-03A67E2D0415}
              Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
              Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
              Athan Basic 3.3-->C:\Windows\iun6002.exe "C:\Program Files\Athan\irunin.ini"
              Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
              Broadcom Gigabit Integrated Controller-->MsiExec.exe /X{FC57FC53-104C-415C-98D7-B05E659461A9}
              Carbonite Online Backup Setup-->"C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled /pausefor=600 /uninstall
              Catalyst Control Center - Branding-->MsiExec.exe /I{45160C56-61F6-468D-A5B0-9FAE2C3E68D6}
              ccCommon-->MsiExec.exe /I{B24E05CC-46FF-4787-BBB8-5CD516AFB118}
              Championship Manager 2010 (September Data Patch)-->"C:\Program Files\InstallShield Installation Information\{14592A8E-4DA6-4338-A9D5-E16449647EC3}\setup.exe" -runfromtemp -l0x0009 -removeonly
              Championship Manager 2010-->"C:\Program Files\InstallShield Installation Information\{5CA7899B-FFEC-4254-A05B-448420831F37}\Setup.exe" -runfromtemp -l0x0009 -removeonly
              Component Framework-->MsiExec.exe /I{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}
              Comptes et Budget (Mono-compte) V6.0-->"C:\Program Files\Comptes et Budget Free V6.0\unins000.exe"
              DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
              DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
              DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
              DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
              DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
              Dolby Control Center-->MsiExec.exe /I{DE66EFAD-B9CC-4FD4-9157-6C18E5100161}
              EasyCapture-->C:\Program Files\Lenovo\EasyCapture\Uninstall.exe
              Energy Management-->C:\Program Files\InstallShield Installation Information\{AE1E24C2-E720-42D5-B8E1-48F71A97B4DB}\setup.exe -runfromtemp -l0x040c -removeonly
              EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
              Everest Poker (Remove Only)-->C:\Program Files\Everest Poker\cstart.exe /uninstall
              Fichiers de prise en charge de l'installation de Microsoft SQL Server (Français)-->MsiExec.exe /X{3380F354-C5F7-4E71-8F51-EEE6C3F06C62}
              GDR 4053 for SQL Server Database Services 2005 ENU (KB970892)-->C:\Windows\SQL9_KB970892_ENU\Hotfix.exe /Uninstall
              Gestionnaire de contacts professionnels pour Outlook 2007 SP2-->"C:\Program Files\Microsoft Small Business\Business Contact Manager\SetupBootstrap\Setup.exe" /remove {69ca8988-1c6c-4285-b8af-db780a6e42af}
              Gestionnaire de contacts professionnels pour Outlook 2007 SP2-->MsiExec.exe /X{69CA8988-1C6C-4285-B8AF-DB780A6E42AF}
              Google Chrome-->"C:\Program Files\Google\Chrome\Application\3.0.195.27\Installer\setup.exe" --uninstall --system-level
              Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
              HaloLighting-->C:\Program Files\InstallShield Installation Information\{85D5BE6D-293F-4BBF-ACDA-40956A8207D6}\setup.exe -runfromtemp -l0x040c -removeonly
              HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
              Intel® Matrix Storage Manager-->C:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
              iTunes-->MsiExec.exe /I{EC2A8F27-4FBF-4E41-B27B-FE822511B761}
              Java(TM) 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
              Lenovo EasyCamera-->C:\Program Files\InstallShield Installation Information\{4BB1DCED-84D3-47F9-B718-5947E904593E}\setup.exe -runfromtemp -l0x040c -removeonly
              Lenovo OneKey Recovery-->"C:\Program Files\InstallShield Installation Information\{46F4D124-20E5-4D12-BE52-EC177A7A4B42}\setup.exe" /z-uninstall
              Lenovo ReadyComm 4.0 -->MsiExec.exe /X{76C66170-C538-4E77-B54D-48E136B5B533}
              Lenovo System Repair - Windows Update Monitor-->C:\Program Files\InstallShield Installation Information\{717E0AD5-91EB-459F-AB8B-1B5219BAF7CE}\setup.exe -runfromtemp -l0x040c -removeonly
              LiveUpdate (Symantec Corporation)-->MsiExec.exe /x {E80F62FF-5D3C-4A19-8409-9721F2928206} /l*v "C:\ProgramData\LuUninstall.LiveUpdate"
              LiveUpdate (Symantec Corporation)-->MsiExec.exe /X{E80F62FF-5D3C-4A19-8409-9721F2928206}
              Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
              Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
              Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
              Microsoft Office 2003 Web Components-->MsiExec.exe /I{90A4040C-6000-11D3-8CFE-0150048383C9}
              Microsoft Office 2007 Primary Interop Assemblies-->MsiExec.exe /X{50120000-1105-0000-0000-0000000FF1CE}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
              Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
              Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
              Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
              Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
              Microsoft Office Professional Hybrid 2007-->MsiExec.exe /X{91120000-0031-0000-0000-0000000FF1CE}
              Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
              Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
              Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
              Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
              Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
              Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
              Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
              Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
              Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
              Microsoft Office Small Business Connectivity Components-->MsiExec.exe /X{A939D341-5A04-4E0A-BB55-3E65B386432D}
              Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
              Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
              Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)-->MsiExec.exe /I{480DBB60-F0B6-45F2-B26F-1A2E11197791}
              Microsoft SQL Server 2005-->"c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
              Microsoft SQL Server Native Client-->MsiExec.exe /I{1F24E48F-7692-4E89-8784-68DD4D2712A0}
              Microsoft SQL Server VSS Writer-->MsiExec.exe /I{A30179B7-997A-4D47-AA43-57AE59A9C78B}
              Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
              Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
              Mise à jour Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {51EFB347-1F3D-4BAC-8B79-F056B904FE21}
              Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
              Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
              Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
              Motorola SM56 Data Fax Modem-->rundll32.exe sm56co85.dll,SM56UnInstaller
              Mozilla Firefox (3.5.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
              Norton AntiVirus Help-->MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
              Norton AntiVirus-->MsiExec.exe /X{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}
              Norton Confidential Core-->MsiExec.exe /I{55A6283C-638A-4EE0-B491-51118554BDA2}
              Norton Internet Security (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\SymSetup\{C1C185CA-C531-49F5-A6FA-B838405A049D}_15_5_0_23\setup.exe" /X
              Norton Internet Security-->MsiExec.exe /I{3672B097-EA69-4BFE-B92F-29AE6D9D2B34}
              Norton Internet Security-->MsiExec.exe /I{C1C185CA-C531-49F5-A6FA-B838405A049D}
              Norton Protection Center-->MsiExec.exe /I{62120008-8E1E-4807-860D-A8B48F8552DB}
              Poker 770-->"C:\Poker\Poker 770\_SetupPoker[1].exe" /uninstall
              Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
              QuickTime-->MsiExec.exe /I{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}
              Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
              RICOH R5C83x/84x Flash Media Controller Driver Ver.3.55.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x40c anything
              Safari-->MsiExec.exe /I{E56D39F8-2A9F-44B4-B068-A72E45A073E6}
              Second Display Control-->C:\Program Files\InstallShield Installation Information\{A4E856D8-6150-4E89-8F97-8F45E799ED72}\setup.exe -runfromtemp -l0x0009 -removeonly
              Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
              Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
              Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
              Security Update for Microsoft Office Outlook 2007 (KB972363)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {120BE9A0-9B09-4855-9E0C-7DEE45CB03C0}
              Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
              Security Update for Microsoft Office Publisher 2007 (KB969693)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
              Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
              Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
              Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
              Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
              Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
              SFR - Kit de connexion-->C:\Program Files\SFR\Kit\uninstall.exe
              SFR - Media Center-->C:\Program Files\SFR\Media Center\uninstall.exe
              SFR - Widget neufbox-->C:\Program Files\SFR\Widget neufbox\uninstall.exe
              SPBBC 32bit-->MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
              Symantec Real Time Storage Protection Component-->MsiExec.exe /I{D6E6FA4A-5445-4850-8365-CF216C1CBB7A}
              Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
              Titan Poker-->"C:\Poker\Titan Poker\_SetupPoker[1].exe" /uninstall
              Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
              Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
              Update for Outlook 2007 Junk Email Filter (KB974810)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C05FBAD5-A211-4E86-BB51-7E07B80C9233}
              Utilitaire de configuration iPhone-->MsiExec.exe /I{FA54AFB1-5745-4389-B8C1-9F7509672ED1}
              VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
              VeriFace III-->C:\Program Files\Lenovo\VeriFaceIII\Uninstall.exe
              Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
              Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
              VLC media player 1.0.1-->C:\Program Files\VideoLAN\VLC\uninstall.exe
              Winbond CIR Device Drivers-->MsiExec.exe /I{2207226D-993D-4026-AD4F-1944FF954FA8}
              Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {E8A81E1F-665E-4F81-B04D-B6D164A8F360}
              Windows Live Toolbar-->MsiExec.exe /X{E8A81E1F-665E-4F81-B04D-B6D164A8F360}
              WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
              WinSCP 4.1.9-->"C:\Program Files\WinSCP\unins000.exe"

              ======Security center information======

              AV: Norton Internet Security
              FW: Norton Internet Security
              AS: Windows Defender
              AS: Norton Internet Security

              ======System event log======

              Computer Name: BABYBACH
              Event Code: 4376
              Message: Servicing a requis un redémarrage pour terminer la définition du package KB974455(Security Update) à l’état Installation demandée(Install Requested)
              Record Number: 51891
              Source Name: Microsoft-Windows-Servicing
              Time Written: 20091104020157.000000-000
              Event Type: Avertissement
              User: AUTORITE NT\SYSTEM

              Computer Name: BABYBACH
              Event Code: 4001
              Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

              Record Number: 51933
              Source Name: Microsoft-Windows-WLAN-AutoConfig
              Time Written: 20091104021714.194200-000
              Event Type: Avertissement
              User: AUTORITE NT\SYSTEM

              Computer Name: BABYBACH
              Event Code: 4
              Message: Broadcom NetLink (TM) Fast Ethernet: The network link is down. Check to make sure the network cable is properly connected.
              Record Number: 51945
              Source Name: b57nd60x
              Time Written: 20091104021802.770904-000
              Event Type: Avertissement
              User:

              Computer Name: BABYBACH
              Event Code: 15016
              Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
              Record Number: 51950
              Source Name: Microsoft-Windows-HttpEvent
              Time Written: 20091104021845.073310-000
              Event Type: Erreur
              User:

              Computer Name: BABYBACH
              Event Code: 1001
              Message: L’initialisation de l’application a échoué. Dernière erreur : 0x80070032
              Record Number: 52046
              Source Name: Microsoft-Windows-LanguagePackSetup
              Time Written: 20091104021948.436910-000
              Event Type: Erreur
              User: AUTORITE NT\SYSTEM

              =====Application event log=====

              Computer Name: BABYBACH
              Event Code: 20
              Message:
              Record Number: 12176
              Source Name: Google Update
              Time Written: 20091104031905.000000-000
              Event Type: Erreur
              User: AUTORITE NT\SYSTEM

              Computer Name: BABYBACH
              Event Code: 20
              Message:
              Record Number: 12189
              Source Name: Google Update
              Time Written: 20091104041905.000000-000
              Event Type: Erreur
              User: AUTORITE NT\SYSTEM

              Computer Name: BABYBACH
              Event Code: 20
              Message:
              Record Number: 12202
              Source Name: Google Update
              Time Written: 20091104051905.000000-000
              Event Type: Erreur
              User: AUTORITE NT\SYSTEM

              Computer Name: BABYBACH
              Event Code: 20
              Message:
              Record Number: 12215
              Source Name: Google Update
              Time Written: 20091104061905.000000-000
              Event Type: Erreur
              User: AUTORITE NT\SYSTEM

              Computer Name: BABYBACH
              Event Code: 20
              Message:
              Record Number: 12228
              Source Name: Google Update
              Time Written: 20091104071905.000000-000
              Event Type: Erreur
              User: AUTORITE NT\SYSTEM

              =====Security event log=====

              Computer Name: BABYBACH
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
              Record Number: 10673
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20091104094203.305110-000
              Event Type: Échec de l'audit
              User:

              Computer Name: BABYBACH
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
              Record Number: 10674
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20091104094203.375110-000
              Event Type: Échec de l'audit
              User:

              Computer Name: BABYBACH
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
              Record Number: 10675
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20091104094203.445110-000
              Event Type: Échec de l'audit
              User:

              Computer Name: BABYBACH
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
              Record Number: 10676
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20091104094203.527110-000
              Event Type: Échec de l'audit
              User:

              Computer Name: BABYBACH
              Event Code: 5038
              Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

              Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
              Record Number: 10677
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20091104094203.635110-000
              Event Type: Échec de l'audit
              User:

              ======Environment variables======

              "ComSpec"=%SystemRoot%\system32\cmd.exe
              "FP_NO_HOST_CHECK"=NO
              "OS"=Windows_NT
              "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\Microsoft SQL Server\90\Tools\binn\;C:\Program Files\Smart Projects\IsoBuster;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\DivX Shared\
              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
              "PROCESSOR_ARCHITECTURE"=x86
              "TEMP"=%SystemRoot%\TEMP
              "TMP"=%SystemRoot%\TEMP
              "USERNAME"=SYSTEM
              "windir"=%SystemRoot%
              "PROCESSOR_LEVEL"=6
              "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
              "PROCESSOR_REVISION"=170a
              "NUMBER_OF_PROCESSORS"=2
              "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
              "DFSTRACINGON"=FALSE
              "configsetroot"=%SystemRoot%\ConfigSetRoot
              "LenovoTestLogFile"=preload.log
              "LenovoTestPath"=C:\test\WINTEST\
              "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
              "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

              -----------------EOF-----------------
              1. et le second rapport "log" :

                Logfile of random's system information tool 1.06 (written by random/random)
                Run by administrateur at 2009-11-04 10:50:01
                Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                System drive C: has 170 GB (66%) free of 259 GB
                Total RAM: 3068 MB (85% free)

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 10:50:19, on 04/11/2009
                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                MSIE: Internet Explorer v7.00 (7.00.6001.18319)
                Boot mode: Safe mode

                Running processes:
                C:\Windows\Explorer.EXE
                C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                C:\Users\administrateur\Desktop\RSIT.exe
                C:\Program Files\Trend Micro\HijackThis\administrateur.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.francefootball.fr/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2flenovo.live.com%2f%3f
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                O1 - Hosts: ::1 localhost
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
                O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [Unattend0000000001{70EB91E7-FAAB-44A4-BA19-C0A45B228BC0}] C:\Windows\test.bat
                O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [HaloLighting] C:\Program Files\Lenovo\HaloLighting\HaloLighting.exe
                O4 - HKLM\..\Run: [WisAvCtrl] "C:\Program Files\Second Display Control\WisAvCtrl.exe"
                O4 - HKLM\..\Run: [WisOSD] "C:\Program Files\Second Display Control\WisOSD.exe"
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled /pausefor=600
                O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
                O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
                O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                O4 - HKLM\..\Run: [Readycomm] C:\Program Files\Lenovo\ReadyComm\ReadyComm.exe -TrayMode
                O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
                O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
                O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                O4 - HKLM\..\Run: [UUSeeMediaCenter] "C:\Program Files\Common Files\uusee\UUSeeMediaCenter.exe"
                O4 - HKLM\..\Run: [Anti Trojan Elite] C:\Program Files\Anti Trojan Elite\TJEnder.exe :NO
                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
                O4 - HKCU\..\Run: [Anti Trojan Elite] C:\Program Files\Anti Trojan Elite\TJEnder.exe :NO
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                O13 - Gopher Prefix:
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                O23 - Service: Service Google Update (gupdate1ca59b449148f70) (gupdate1ca59b449148f70) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
                O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
                O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Second Display Control\WisLMSvc.exe
                1. Contributeur sécurité
                  je n'ai pas vu passer le rapport de Ad remover en suppression
                  peux tu le poster
                  et

                  Téléchargez USBFIX de Chiquitine29, C_xx
                  https://www.androidworld.fr/

                  /!\ Utilisateur de vista et windows 7 : ne pas oublier de désactiver Le contrôle des comptes utilisateurs
                  https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                  /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

                  • Double clic sur le raccourci UsbFix présent sur le bureau .

                  • Choisir l'option 1 (Recherche)
                  (d’autres options disponibles, voir le tutoriel).
                  • Laissez travailler l'outil.

                  • Ensuite postez le rapport UsbFix.txt qui apparaîtra.

                  • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                  ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                  • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                  Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                  Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                  • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html
                  1. Voici le rapport Usbfix, concernant la rapport ad-remover je l'ai posté plus haut :

                    ############################## | UsbFix V6.047 |

                    User : administrateur (Administrateurs) # BABYBACH
                    Update on 02/11/2009 by Chiquitine29, C_XX & Chimay8
                    Start at: 11:49:25 | 04/11/2009
                    Website : http://pagesperso-orange.fr/NosTools/index.html
                    Contact : FindyKill.Contact@gmail.com

                    Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
                    Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                    Internet Explorer 7.0.6001.18000
                    Windows Firewall Status : Disabled
                    AV : Norton Internet Security 15.5.0.23 [ Enabled | Updated ]
                    FW : Norton Internet Security[ Enabled ]15.5.0.23

                    C:\ -> Disque fixe local # 252,81 Go (163,18 Go free) # NTFS
                    D:\ -> Disque fixe local # 30,52 Go (28,79 Go free) [LENOVO] # NTFS
                    E:\ -> Disque CD-ROM
                    F:\ -> Disque CD-ROM
                    G:\ -> Disque CD-ROM
                    H:\ -> Disque amovible
                    I:\ -> Disque amovible # 7,45 Go (1,26 Go free) # FAT32

                    ############################## | Processus actifs |

                    C:\Windows\System32\smss.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\wininit.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\services.exe
                    C:\Windows\system32\lsass.exe
                    C:\Windows\system32\lsm.exe
                    C:\Windows\system32\winlogon.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\Ati2evxx.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\SLsvc.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\Ati2evxx.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                    C:\Windows\System32\spoolsv.exe
                    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
                    C:\Program Files\Bonjour\mDNSResponder.exe
                    C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\IgrsSvcs.exe
                    c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
                    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\SearchIndexer.exe
                    C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                    C:\Windows\system32\WUDFHost.exe
                    C:\Windows\system32\wbem\unsecapp.exe
                    C:\Windows\system32\wbem\wmiprvse.exe
                    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\Explorer.EXE
                    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                    C:\Windows\RtHDVCpl.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                    C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\Lenovo\HaloLighting\HaloLighting.exe
                    C:\Program Files\Second Display Control\WisAvCtrl.exe
                    C:\Program Files\Second Display Control\WisOSD.exe
                    C:\Program Files\Carbonite\CarbonitePreinstaller.exe
                    C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
                    C:\Program Files\Lenovo\ReadyComm\ReadyComm.exe
                    C:\Program Files\Lenovo\Energy Management\utility.exe
                    C:\Program Files\Lenovo\Energy Management\Energy Management.exe
                    C:\Program Files\Athan\Athan.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\Second Display Control\WisLMSvc.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Windows\ehome\ehtray.exe
                    C:\Program Files\SFR\Kit\9props.exe
                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                    C:\Program Files\Windows Media Player\wmpnetwk.exe
                    C:\Windows\ehome\ehmsas.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\Windows\system32\wuauclt.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Windows\system32\conime.exe
                    C:\Windows\system32\wbem\wmiprvse.exe

                    ################## | Fichiers # Dossiers infectieux |

                    C:\Users\ADMINI~1\AppData\Local\Temp\Anti-Trojan_Elite_4.7.4.rar
                    C:\Users\ADMINI~1\AppData\Local\Temp\Dj Rhettmatic - Pure funk mode-mko.rar
                    C:\Users\ADMINI~1\AppData\Local\Temp\funk tuerie 2.rar
                    C:\Users\ADMINI~1\AppData\Local\Temp\Selection Rare de Funk By Dark-Side.rar
                    C:\Users\ADMINI~1\AppData\Local\Temp\VA Rare Funk Vol 01.rar
                    C:\Users\ADMINI~1\AppData\Local\Temp\VA Rare Funk Vol 05.rar
                    C:\Users\ADMINI~1\AppData\Local\Temp\VA Rare Funk Vol 06.rar

                    ################## | Registre # Clés Run infectieuses |

                    ################## | Registre # Mountpoints2 |

                    HKCU\..\..\Explorer\MountPoints2\{fd8de7f4-aa0f-11de-b24c-001f161cfff5}
                    shell\AutoRun\command =G:\autorun.exe

                    ################## | Suspect | https://www.virustotal.com/gui/ |

                    ################## | Cracks / Keygens / Serials |

                    "C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe"
                    11/06/2008 11:16 |Size 1454080 |Crc32 f802b629 |Md5 1da493f361ee0bd8c7e7f8bf05d2123d

                    "C:\Users\administrateur\Desktop\Anti-Trojan Elite 4.7.4\crack\tjender.exe"
                    11/10/2009 19:35 |Size 4076544 |Crc32 b18ea032 |Md5 17b3ff9084fa1fc57452b0511373f63e

                    "C:\Users\administrateur\Desktop\Anti-Trojan Elite 4.7.4\crack\updat.exe"
                    11/10/2009 19:35 |Size 681472 |Crc32 34430d6e |Md5 7af73c7b1b346453c375841d1d853d86

                    ################## | ! Fin du rapport # UsbFix V6.047 ! |
                    1. Voici le rapport Usbfix, concernant la rapport ad-remover je l'ai posté plus haut :

                      ############################## | UsbFix V6.047 |

                      User : administrateur (Administrateurs) # BABYBACH
                      Update on 02/11/2009 by Chiquitine29, C_XX & Chimay8
                      Start at: 11:49:25 | 04/11/2009
                      Website : http://pagesperso-orange.fr/NosTools/index.html
                      Contact : FindyKill.Contact@gmail.com

                      Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
                      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                      Internet Explorer 7.0.6001.18000
                      Windows Firewall Status : Disabled
                      AV : Norton Internet Security 15.5.0.23 [ Enabled | Updated ]
                      FW : Norton Internet Security[ Enabled ]15.5.0.23

                      C:\ -> Disque fixe local # 252,81 Go (163,18 Go free) # NTFS
                      D:\ -> Disque fixe local # 30,52 Go (28,79 Go free) [LENOVO] # NTFS
                      E:\ -> Disque CD-ROM
                      F:\ -> Disque CD-ROM
                      G:\ -> Disque CD-ROM
                      H:\ -> Disque amovible
                      I:\ -> Disque amovible # 7,45 Go (1,26 Go free) # FAT32

                      ############################## | Processus actifs |

                      C:\Windows\System32\smss.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\wininit.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\services.exe
                      C:\Windows\system32\lsass.exe
                      C:\Windows\system32\lsm.exe
                      C:\Windows\system32\winlogon.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\Ati2evxx.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\SLsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\Ati2evxx.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                      C:\Windows\System32\spoolsv.exe
                      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\IgrsSvcs.exe
                      c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
                      c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                      C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\SearchIndexer.exe
                      C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                      C:\Windows\system32\WUDFHost.exe
                      C:\Windows\system32\wbem\unsecapp.exe
                      C:\Windows\system32\wbem\wmiprvse.exe
                      C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                      C:\Windows\RtHDVCpl.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                      C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Program Files\Lenovo\HaloLighting\HaloLighting.exe
                      C:\Program Files\Second Display Control\WisAvCtrl.exe
                      C:\Program Files\Second Display Control\WisOSD.exe
                      C:\Program Files\Carbonite\CarbonitePreinstaller.exe
                      C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
                      C:\Program Files\Lenovo\ReadyComm\ReadyComm.exe
                      C:\Program Files\Lenovo\Energy Management\utility.exe
                      C:\Program Files\Lenovo\Energy Management\Energy Management.exe
                      C:\Program Files\Athan\Athan.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\Program Files\Second Display Control\WisLMSvc.exe
                      C:\Program Files\Java\jre6\bin\jusched.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\SFR\Kit\9props.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                      C:\Program Files\Windows Media Player\wmpnetwk.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\Windows\system32\wuauclt.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                      C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Windows\system32\conime.exe
                      C:\Windows\system32\wbem\wmiprvse.exe

                      ################## | Fichiers # Dossiers infectieux |

                      C:\Users\ADMINI~1\AppData\Local\Temp\Anti-Trojan_Elite_4.7.4.rar
                      C:\Users\ADMINI~1\AppData\Local\Temp\Dj Rhettmatic - Pure funk mode-mko.rar
                      C:\Users\ADMINI~1\AppData\Local\Temp\funk tuerie 2.rar
                      C:\Users\ADMINI~1\AppData\Local\Temp\Selection Rare de Funk By Dark-Side.rar
                      C:\Users\ADMINI~1\AppData\Local\Temp\VA Rare Funk Vol 01.rar
                      C:\Users\ADMINI~1\AppData\Local\Temp\VA Rare Funk Vol 05.rar
                      C:\Users\ADMINI~1\AppData\Local\Temp\VA Rare Funk Vol 06.rar

                      ################## | Registre # Clés Run infectieuses |

                      ################## | Registre # Mountpoints2 |

                      HKCU\..\..\Explorer\MountPoints2\{fd8de7f4-aa0f-11de-b24c-001f161cfff5}
                      shell\AutoRun\command =G:\autorun.exe

                      ################## | Suspect | https://www.virustotal.com/gui/ |

                      ################## | Cracks / Keygens / Serials |

                      "C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe"
                      11/06/2008 11:16 |Size 1454080 |Crc32 f802b629 |Md5 1da493f361ee0bd8c7e7f8bf05d2123d

                      "C:\Users\administrateur\Desktop\Anti-Trojan Elite 4.7.4\crack\tjender.exe"
                      11/10/2009 19:35 |Size 4076544 |Crc32 b18ea032 |Md5 17b3ff9084fa1fc57452b0511373f63e

                      "C:\Users\administrateur\Desktop\Anti-Trojan Elite 4.7.4\crack\updat.exe"
                      11/10/2009 19:35 |Size 681472 |Crc32 34430d6e |Md5 7af73c7b1b346453c375841d1d853d86

                      ################## | ! Fin du rapport # UsbFix V6.047 ! |
                      1. Contributeur sécurité
                        désolé mais je ne vois pas le rapport suppression Ad remover
                        il se trouve ici: C:\Ad-Report-SCAN.log

                        as tu bien fait l'option L en mode sans echec ?

                        pour usbfix

                        ● Relance UsbFix

                        ● Dans le menu principale cette fois choisit l'option2

                        Le menu démarrer et les icônes vont à nouveau disparaître.. c'est normal.

                        Si un message te demande de redémarrer l'ordinateur fais le ...

                        ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

                        ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse
                        1. Voici dans un premier temps le rapport de suppression usbfix, je relance adremover en mode sans echec :

                          ############################## | UsbFix V6.047 |

                          User : administrateur (Administrateurs) # BABYBACH
                          Update on 02/11/2009 by Chiquitine29, C_XX & Chimay8
                          Start at: 12:09:48 | 04/11/2009
                          Website : http://pagesperso-orange.fr/NosTools/index.html
                          Contact : FindyKill.Contact@gmail.com

                          Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
                          Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                          Internet Explorer 7.0.6001.18000
                          Windows Firewall Status : Disabled
                          AV : Norton Internet Security 15.5.0.23 [ Enabled | Updated ]
                          FW : Norton Internet Security[ Enabled ]15.5.0.23

                          C:\ -> Disque fixe local # 252,81 Go (163,22 Go free) # NTFS
                          D:\ -> Disque fixe local # 30,52 Go (28,79 Go free) [LENOVO] # NTFS
                          E:\ -> Disque CD-ROM
                          F:\ -> Disque CD-ROM
                          G:\ -> Disque CD-ROM
                          H:\ -> Disque amovible
                          I:\ -> Disque amovible # 7,45 Go (1,26 Go free) # FAT32

                          ############################## | Processus actifs |

                          C:\Windows\System32\smss.exe
                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\wininit.exe
                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\services.exe
                          C:\Windows\system32\lsass.exe
                          C:\Windows\system32\lsm.exe
                          C:\Windows\system32\winlogon.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\LogonUI.exe
                          C:\Windows\system32\Ati2evxx.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\SLsvc.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\Ati2evxx.exe
                          C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\System32\spoolsv.exe
                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\IgrsSvcs.exe
                          c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
                          c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                          C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\SearchIndexer.exe
                          C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                          C:\Windows\system32\WUDFHost.exe
                          C:\Windows\system32\wbem\unsecapp.exe
                          C:\Windows\system32\wbem\wmiprvse.exe
                          C:\Windows\servicing\TrustedInstaller.exe
                          C:\Program Files\Lavasoft\Ad-Aware\AAWWSC.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                          C:\Windows\system32\runonce.exe
                          C:\Windows\system32\conime.exe
                          C:\Windows\system32\wbem\wmiprvse.exe

                          ################## | Fichiers # Dossiers infectieux |

                          Supprimé ! C:\Users\ADMINI~1\AppData\Local\Temp\100 FUNK.rar
                          Supprimé ! C:\Users\ADMINI~1\AppData\Local\Temp\Anti-Trojan_Elite_4.7.4.rar
                          Supprimé ! C:\Users\ADMINI~1\AppData\Local\Temp\Dj Rhettmatic - Pure funk mode-mko.rar
                          Supprimé ! C:\Users\ADMINI~1\AppData\Local\Temp\funk tuerie 2.rar
                          Supprimé ! C:\Users\ADMINI~1\AppData\Local\Temp\Selection Rare de Funk By Dark-Side.rar
                          Supprimé ! C:\Users\ADMINI~1\AppData\Local\Temp\VA Rare Funk Vol 01.rar
                          Supprimé ! C:\Users\ADMINI~1\AppData\Local\Temp\VA Rare Funk Vol 05.rar
                          Supprimé ! C:\Users\ADMINI~1\AppData\Local\Temp\VA Rare Funk Vol 06.rar

                          ################## | Registre # Clés Run infectieuses |

                          ################## | Registre # Mountpoints2 |

                          Supprimé ! HKCU\...\Explorer\MountPoints2\{fd8de7f4-aa0f-11de-b24c-001f161cfff5}\Shell\AutoRun\Command

                          ################## | Listing des fichiers présent |

                          [04/11/2009 12:08|--a------|1564] C:\aaw7boot.log
                          [04/11/2009 09:27|--a------|3215] C:\Ad-Report-SCAN[1].log
                          [18/09/2006 22:43|--a------|24] C:\autoexec.bat
                          [21/01/2008 03:24|-rahs----|333203] C:\bootmgr
                          [03/02/2008 22:34|-ra-s----|8192] C:\BOOTSECT.BAK
                          [03/11/2009 23:18|--a------|1644] C:\cleannavi.txt
                          [18/09/2006 22:43|--a------|10] C:\config.sys
                          [04/11/2009 12:10|--a------|290138] C:\FaceProv.log
                          [?|?|?] C:\hiberfil.sys
                          [?|?|?] C:\pagefile.sys
                          [03/07/2009 00:42|--a------|560] C:\RHDSetup.log
                          [03/07/2009 00:49|--a------|86] C:\setup.log
                          [04/11/2009 12:09|--a------|6302867] C:\sysiclog.txt
                          [17/10/2009 02:26|--a------|21081336] C:\sysiclog.txt.bak
                          [04/11/2009 12:12|--a------|4625] C:\UsbFix.txt
                          [04/11/2009 12:09|--ahs----|56] C:\_PartitionInfo
                          [14/09/2008 19:24|-r-h-----|474] H:\winamp_cache_0001.xml
                          [14/09/2008 19:24|--a------|41] H:\pmp_usb.ini
                          [01/11/2009 20:56|--a------|728633344] I:\Safari.FRENCH.DVDRip.XviD-rachidddu75.avi
                          [24/10/2009 21:46|--a------|733990912] I:\Law Abiding Citizen.avi

                          ################## | Vaccination |

                          # C:\autorun.inf -> Dossier créé par UsbFix.
                          # D:\autorun.inf -> Dossier créé par UsbFix.
                          # H:\autorun.inf -> Dossier créé par UsbFix.
                          # I:\autorun.inf -> Dossier créé par UsbFix.

                          ################## | Suspect | https://www.virustotal.com/gui/ |

                          ################## | Cracks / Keygens / Serials |

                          "C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe"
                          11/06/2008 11:16 |Size 1454080 |Crc32 f802b629 |Md5 1da493f361ee0bd8c7e7f8bf05d2123d

                          "C:\Users\administrateur\Desktop\Anti-Trojan Elite 4.7.4\crack\tjender.exe"
                          11/10/2009 19:35 |Size 4076544 |Crc32 b18ea032 |Md5 17b3ff9084fa1fc57452b0511373f63e

                          "C:\Users\administrateur\Desktop\Anti-Trojan Elite 4.7.4\crack\updat.exe"
                          11/10/2009 19:35 |Size 681472 |Crc32 34430d6e |Md5 7af73c7b1b346453c375841d1d853d86

                          ################## | Upload |

                          Veuillez envoyer le fichier : C:\Users\ADMINI~1\Desktop\UsbFix_Upload_Me_BABYBACH.zip : https://www.androidworld.fr/
                          Merci pour votre contribution .

                          ################## | ! Fin du rapport # UsbFix V6.047 ! |
                          1. Contributeur sécurité
                            d'accord

                            apres Ad remover

                            peux tu refaire un nouveau Rsit stp
                            1. voici le rapport ad remover :

                              .
                              ======= RAPPORT D'AD-REMOVER 1.1.4.5_Z | UNIQUEMENT XP/VISTA/7 =======
                              .
                              Mit à jour par C_XX le 17.10.2009 à 11:48
                              Contact: AdRemover.contact@gmail.com
                              Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                              .
                              Lancé à: 12:23:18, 04/11/2009 | Mode sans echec | Option: CLEAN
                              Exécuté de: C:\Program Files\Ad-Remover\
                              Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 1 v6.0.6001
                              Nom du PC: BABYBACH | Utilisateur actuel: administrateur
                              .
                              ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                              .

                              HKCU\Software\Grand Virtual
                              HKCU\Software\Poker 770
                              HKCU\Software\Titan Poker
                              HKLM\Software\Microsoft\Internet Explorer\Extensions\{49783ED4-258D-4f9f-BE11-137C18D3E543}
                              HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker
                              HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Poker 770
                              HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Titan Poker
                              HKLM\Software\Poker 770
                              HKLM\Software\Titan Poker
                              .
                              C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Everest Poker
                              C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Poker 770
                              C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Titan Poker
                              C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Titan Poker.lnk
                              C:\Program Files\Everest Poker
                              C:\Users\administrateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Titan Poker.lnk
                              C:\Poker\Poker 770
                              C:\Poker\Titan Poker
                              C:\Users\Public\Desktop\Everest Poker.lnk
                              C:\Users\ADMINI~1\AppData\Roaming\MICROS~1\Windows\Cookies\administrateur@everestpoker[2].txt

                              (!) -- Fichiers temporaires supprimés.

                              .
                              ============== Scan additionnel ==============
                              .
                              .
                              * Mozilla FireFox Version 3.5.4 [fr] *
                              .
                              Nom du profil: vzakmizv.default (administrateur)
                              .
                              (Prefs.js) user_pref("browser.search.defaultenginename", "Chercher Malin");
                              (Prefs.js) user_pref("browser.search.selectedEngine", "Google");
                              (Prefs.js) user_pref("browser.startup.homepage", "www.google.fr");
                              (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.1.4");
                              .
                              .
                              * Internet Explorer Version 7.0.6001.18000 *
                              .
                              [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                              .
                              Start Page: hxxp://fr.msn.com/
                              Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                              Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                              Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                              Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                              .
                              [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                              .
                              Start Page: hxxp://fr.msn.com/
                              Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                              Search bar: hxxp://search.msn.com/spbasic.htm
                              .
                              [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                              .
                              Tabs: res://ieframe.dll/tabswelcome.htm
                              .
                              ============== Suspect (Cracks, Serials ... ) ==============
                              .
                              C:\Users\administrateur\Desktop\Anti-Trojan Elite 4.7.4\crack\tjender.exe
                              C:\Users\administrateur\Desktop\Anti-Trojan Elite 4.7.4\crack\updat.exe
                              .
                              ===================================
                              .
                              3186 Octet(s) - C:\Ad-Report-CLEAN[1].log
                              3215 Octet(s) - C:\Ad-Report-SCAN[1].log
                              .
                              5 Fichier(s) - C:\Users\ADMINI~1\AppData\Local\Temp
                              0 Fichier(s) - C:\Windows\Temp
                              .
                              22 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
                              3224 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
                              .
                              Fin à: 12:29:50 | 04/11/2009 - CLEAN[1]
                              .
                              ============== E.O.F ==============
                              .
                              1. voici les nouveaux rapports rsit :

                                Logfile of random's system information tool 1.06 (written by random/random)
                                Run by administrateur at 2009-11-04 12:40:12
                                Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                                System drive C: has 167 GB (65%) free of 259 GB
                                Total RAM: 3068 MB (53% free)

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 12:40:35, on 04/11/2009
                                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                MSIE: Internet Explorer v7.00 (7.00.6001.18319)
                                Boot mode: Normal

                                Running processes:
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\Explorer.EXE
                                C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                C:\Windows\RtHDVCpl.exe
                                C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                C:\Program Files\Lenovo\HaloLighting\HaloLighting.exe
                                C:\Program Files\Second Display Control\WisAvCtrl.exe
                                C:\Program Files\Second Display Control\WisOSD.exe
                                C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                                C:\Program Files\Carbonite\CarbonitePreinstaller.exe
                                C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
                                C:\Program Files\Lenovo\ReadyComm\ReadyComm.exe
                                C:\Program Files\Lenovo\Energy Management\utility.exe
                                C:\Program Files\Lenovo\Energy Management\Energy Management.exe
                                C:\Program Files\Athan\Athan.exe
                                C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\Java\jre6\bin\jusched.exe
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Windows\ehome\ehtray.exe
                                C:\Program Files\SFR\Kit\9props.exe
                                C:\Program Files\Windows Media Player\wmpnscfg.exe
                                C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                                C:\Windows\ehome\ehmsas.exe
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                                C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                                C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                                C:\Windows\system32\wuauclt.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Users\administrateur\Desktop\RSIT.exe
                                C:\Program Files\Trend Micro\HijackThis\administrateur.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
                                O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [Unattend0000000001{70EB91E7-FAAB-44A4-BA19-C0A45B228BC0}] C:\Windows\test.bat
                                O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                                O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                O4 - HKLM\..\Run: [HaloLighting] C:\Program Files\Lenovo\HaloLighting\HaloLighting.exe
                                O4 - HKLM\..\Run: [WisAvCtrl] "C:\Program Files\Second Display Control\WisAvCtrl.exe"
                                O4 - HKLM\..\Run: [WisOSD] "C:\Program Files\Second Display Control\WisOSD.exe"
                                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled /pausefor=600
                                O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
                                O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
                                O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                O4 - HKLM\..\Run: [Readycomm] C:\Program Files\Lenovo\ReadyComm\ReadyComm.exe -TrayMode
                                O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
                                O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
                                O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                O4 - HKLM\..\Run: [UUSeeMediaCenter] "C:\Program Files\Common Files\uusee\UUSeeMediaCenter.exe"
                                O4 - HKLM\..\Run: [Anti Trojan Elite] C:\Program Files\Anti Trojan Elite\TJEnder.exe :NO
                                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
                                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
                                O4 - HKCU\..\Run: [Anti Trojan Elite] C:\Program Files\Anti Trojan Elite\TJEnder.exe :NO
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                                O13 - Gopher Prefix:
                                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                                O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                                O23 - Service: Service Google Update (gupdate1ca59b449148f70) (gupdate1ca59b449148f70) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                                O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
                                O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                                O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                                O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                                O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                                O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
                                O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Second Display Control\WisLMSvc.exe
                                1. et la rapport info et le même je pense :

                                  info.txt logfile of random's system information tool 1.06 2009-11-04 10:42:08

                                  ======Uninstall list======

                                  -->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
                                  -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                                  2007 Microsoft Office system-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROHYBRIDR /dll OSETUP.DLL
                                  Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
                                  Ad-Aware-->"C:\ProgramData\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe" REMOVE=TRUE MODIFY=FALSE
                                  Ad-Aware-->C:\ProgramData\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
                                  Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                                  Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                                  Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
                                  Ad-Remover By C_XX-->"C:\Program Files\Ad-Remover\Uninstall ADR.exe"
                                  Anti Trojan Elite 4.7.4-->"C:\Program Files\Anti Trojan Elite\unins000.exe"
                                  AppCore-->MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
                                  Apple Application Support-->MsiExec.exe /I{0C34B801-6AEC-4667-B053-03A67E2D0415}
                                  Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
                                  Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                                  Athan Basic 3.3-->C:\Windows\iun6002.exe "C:\Program Files\Athan\irunin.ini"
                                  Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                                  Broadcom Gigabit Integrated Controller-->MsiExec.exe /X{FC57FC53-104C-415C-98D7-B05E659461A9}
                                  Carbonite Online Backup Setup-->"C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled /pausefor=600 /uninstall
                                  Catalyst Control Center - Branding-->MsiExec.exe /I{45160C56-61F6-468D-A5B0-9FAE2C3E68D6}
                                  ccCommon-->MsiExec.exe /I{B24E05CC-46FF-4787-BBB8-5CD516AFB118}
                                  Championship Manager 2010 (September Data Patch)-->"C:\Program Files\InstallShield Installation Information\{14592A8E-4DA6-4338-A9D5-E16449647EC3}\setup.exe" -runfromtemp -l0x0009 -removeonly
                                  Championship Manager 2010-->"C:\Program Files\InstallShield Installation Information\{5CA7899B-FFEC-4254-A05B-448420831F37}\Setup.exe" -runfromtemp -l0x0009 -removeonly
                                  Component Framework-->MsiExec.exe /I{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}
                                  Comptes et Budget (Mono-compte) V6.0-->"C:\Program Files\Comptes et Budget Free V6.0\unins000.exe"
                                  DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
                                  DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                                  DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
                                  DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
                                  DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
                                  Dolby Control Center-->MsiExec.exe /I{DE66EFAD-B9CC-4FD4-9157-6C18E5100161}
                                  EasyCapture-->C:\Program Files\Lenovo\EasyCapture\Uninstall.exe
                                  Energy Management-->C:\Program Files\InstallShield Installation Information\{AE1E24C2-E720-42D5-B8E1-48F71A97B4DB}\setup.exe -runfromtemp -l0x040c -removeonly
                                  EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
                                  Everest Poker (Remove Only)-->C:\Program Files\Everest Poker\cstart.exe /uninstall
                                  Fichiers de prise en charge de l'installation de Microsoft SQL Server (Français)-->MsiExec.exe /X{3380F354-C5F7-4E71-8F51-EEE6C3F06C62}
                                  GDR 4053 for SQL Server Database Services 2005 ENU (KB970892)-->C:\Windows\SQL9_KB970892_ENU\Hotfix.exe /Uninstall
                                  Gestionnaire de contacts professionnels pour Outlook 2007 SP2-->"C:\Program Files\Microsoft Small Business\Business Contact Manager\SetupBootstrap\Setup.exe" /remove {69ca8988-1c6c-4285-b8af-db780a6e42af}
                                  Gestionnaire de contacts professionnels pour Outlook 2007 SP2-->MsiExec.exe /X{69CA8988-1C6C-4285-B8AF-DB780A6E42AF}
                                  Google Chrome-->"C:\Program Files\Google\Chrome\Application\3.0.195.27\Installer\setup.exe" --uninstall --system-level
                                  Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
                                  HaloLighting-->C:\Program Files\InstallShield Installation Information\{85D5BE6D-293F-4BBF-ACDA-40956A8207D6}\setup.exe -runfromtemp -l0x040c -removeonly
                                  HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                                  Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                                  Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                                  Intel® Matrix Storage Manager-->C:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
                                  iTunes-->MsiExec.exe /I{EC2A8F27-4FBF-4E41-B27B-FE822511B761}
                                  Java(TM) 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
                                  Lenovo EasyCamera-->C:\Program Files\InstallShield Installation Information\{4BB1DCED-84D3-47F9-B718-5947E904593E}\setup.exe -runfromtemp -l0x040c -removeonly
                                  Lenovo OneKey Recovery-->"C:\Program Files\InstallShield Installation Information\{46F4D124-20E5-4D12-BE52-EC177A7A4B42}\setup.exe" /z-uninstall
                                  Lenovo ReadyComm 4.0 -->MsiExec.exe /X{76C66170-C538-4E77-B54D-48E136B5B533}
                                  Lenovo System Repair - Windows Update Monitor-->C:\Program Files\InstallShield Installation Information\{717E0AD5-91EB-459F-AB8B-1B5219BAF7CE}\setup.exe -runfromtemp -l0x040c -removeonly
                                  LiveUpdate (Symantec Corporation)-->MsiExec.exe /x {E80F62FF-5D3C-4A19-8409-9721F2928206} /l*v "C:\ProgramData\LuUninstall.LiveUpdate"
                                  LiveUpdate (Symantec Corporation)-->MsiExec.exe /X{E80F62FF-5D3C-4A19-8409-9721F2928206}
                                  Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                                  Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                                  Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                                  Microsoft Office 2003 Web Components-->MsiExec.exe /I{90A4040C-6000-11D3-8CFE-0150048383C9}
                                  Microsoft Office 2007 Primary Interop Assemblies-->MsiExec.exe /X{50120000-1105-0000-0000-0000000FF1CE}
                                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                                  Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
                                  Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                                  Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
                                  Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                                  Microsoft Office Professional Hybrid 2007-->MsiExec.exe /X{91120000-0031-0000-0000-0000000FF1CE}
                                  Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                                  Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                                  Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                                  Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                                  Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                                  Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                                  Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                                  Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                                  Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                                  Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                                  Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                                  Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                                  Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                                  Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
                                  Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                                  Microsoft Office Small Business Connectivity Components-->MsiExec.exe /X{A939D341-5A04-4E0A-BB55-3E65B386432D}
                                  Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                                  Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                                  Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)-->MsiExec.exe /I{480DBB60-F0B6-45F2-B26F-1A2E11197791}
                                  Microsoft SQL Server 2005-->"c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
                                  Microsoft SQL Server Native Client-->MsiExec.exe /I{1F24E48F-7692-4E89-8784-68DD4D2712A0}
                                  Microsoft SQL Server VSS Writer-->MsiExec.exe /I{A30179B7-997A-4D47-AA43-57AE59A9C78B}
                                  Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                                  Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                                  Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                                  Mise à jour Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {51EFB347-1F3D-4BAC-8B79-F056B904FE21}
                                  Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
                                  Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                                  Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                                  Motorola SM56 Data Fax Modem-->rundll32.exe sm56co85.dll,SM56UnInstaller
                                  Mozilla Firefox (3.5.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                                  Norton AntiVirus Help-->MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
                                  Norton AntiVirus-->MsiExec.exe /X{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}
                                  Norton Confidential Core-->MsiExec.exe /I{55A6283C-638A-4EE0-B491-51118554BDA2}
                                  Norton Internet Security (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\SymSetup\{C1C185CA-C531-49F5-A6FA-B838405A049D}_15_5_0_23\setup.exe" /X
                                  Norton Internet Security-->MsiExec.exe /I{3672B097-EA69-4BFE-B92F-29AE6D9D2B34}
                                  Norton Internet Security-->MsiExec.exe /I{C1C185CA-C531-49F5-A6FA-B838405A049D}
                                  Norton Protection Center-->MsiExec.exe /I{62120008-8E1E-4807-860D-A8B48F8552DB}
                                  Poker 770-->"C:\Poker\Poker 770\_SetupPoker[1].exe" /uninstall
                                  Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
                                  QuickTime-->MsiExec.exe /I{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}
                                  Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
                                  RICOH R5C83x/84x Flash Media Controller Driver Ver.3.55.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x40c anything
                                  Safari-->MsiExec.exe /I{E56D39F8-2A9F-44B4-B068-A72E45A073E6}
                                  Second Display Control-->C:\Program Files\InstallShield Installation Information\{A4E856D8-6150-4E89-8F97-8F45E799ED72}\setup.exe -runfromtemp -l0x0009 -removeonly
                                  Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                                  Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
                                  Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
                                  Security Update for Microsoft Office Outlook 2007 (KB972363)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {120BE9A0-9B09-4855-9E0C-7DEE45CB03C0}
                                  Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
                                  Security Update for Microsoft Office Publisher 2007 (KB969693)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
                                  Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
                                  Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
                                  Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                                  Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                                  Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
                                  SFR - Kit de connexion-->C:\Program Files\SFR\Kit\uninstall.exe
                                  SFR - Media Center-->C:\Program Files\SFR\Media Center\uninstall.exe
                                  SFR - Widget neufbox-->C:\Program Files\SFR\Widget neufbox\uninstall.exe
                                  SPBBC 32bit-->MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
                                  Symantec Real Time Storage Protection Component-->MsiExec.exe /I{D6E6FA4A-5445-4850-8365-CF216C1CBB7A}
                                  Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                                  Titan Poker-->"C:\Poker\Titan Poker\_SetupPoker[1].exe" /uninstall
                                  Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                                  Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                                  Update for Outlook 2007 Junk Email Filter (KB974810)-->msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C05FBAD5-A211-4E86-BB51-7E07B80C9233}
                                  Utilitaire de configuration iPhone-->MsiExec.exe /I{FA54AFB1-5745-4389-B8C1-9F7509672ED1}
                                  VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
                                  VeriFace III-->C:\Program Files\Lenovo\VeriFaceIII\Uninstall.exe
                                  Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
                                  Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
                                  VLC media player 1.0.1-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                                  Winbond CIR Device Drivers-->MsiExec.exe /I{2207226D-993D-4026-AD4F-1944FF954FA8}
                                  Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {E8A81E1F-665E-4F81-B04D-B6D164A8F360}
                                  Windows Live Toolbar-->MsiExec.exe /X{E8A81E1F-665E-4F81-B04D-B6D164A8F360}
                                  WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
                                  WinSCP 4.1.9-->"C:\Program Files\WinSCP\unins000.exe"

                                  ======Security center information======

                                  AV: Norton Internet Security
                                  FW: Norton Internet Security
                                  AS: Windows Defender
                                  AS: Norton Internet Security

                                  ======System event log======

                                  Computer Name: BABYBACH
                                  Event Code: 4376
                                  Message: Servicing a requis un redémarrage pour terminer la définition du package KB974455(Security Update) à l’état Installation demandée(Install Requested)
                                  Record Number: 51891
                                  Source Name: Microsoft-Windows-Servicing
                                  Time Written: 20091104020157.000000-000
                                  Event Type: Avertissement
                                  User: AUTORITE NT\SYSTEM

                                  Computer Name: BABYBACH
                                  Event Code: 4001
                                  Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

                                  Record Number: 51933
                                  Source Name: Microsoft-Windows-WLAN-AutoConfig
                                  Time Written: 20091104021714.194200-000
                                  Event Type: Avertissement
                                  User: AUTORITE NT\SYSTEM

                                  Computer Name: BABYBACH
                                  Event Code: 4
                                  Message: Broadcom NetLink (TM) Fast Ethernet: The network link is down. Check to make sure the network cable is properly connected.
                                  Record Number: 51945
                                  Source Name: b57nd60x
                                  Time Written: 20091104021802.770904-000
                                  Event Type: Avertissement
                                  User:

                                  Computer Name: BABYBACH
                                  Event Code: 15016
                                  Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
                                  Record Number: 51950
                                  Source Name: Microsoft-Windows-HttpEvent
                                  Time Written: 20091104021845.073310-000
                                  Event Type: Erreur
                                  User:

                                  Computer Name: BABYBACH
                                  Event Code: 1001
                                  Message: L’initialisation de l’application a échoué. Dernière erreur : 0x80070032
                                  Record Number: 52046
                                  Source Name: Microsoft-Windows-LanguagePackSetup
                                  Time Written: 20091104021948.436910-000
                                  Event Type: Erreur
                                  User: AUTORITE NT\SYSTEM

                                  =====Application event log=====

                                  Computer Name: BABYBACH
                                  Event Code: 20
                                  Message:
                                  Record Number: 12176
                                  Source Name: Google Update
                                  Time Written: 20091104031905.000000-000
                                  Event Type: Erreur
                                  User: AUTORITE NT\SYSTEM

                                  Computer Name: BABYBACH
                                  Event Code: 20
                                  Message:
                                  Record Number: 12189
                                  Source Name: Google Update
                                  Time Written: 20091104041905.000000-000
                                  Event Type: Erreur
                                  User: AUTORITE NT\SYSTEM

                                  Computer Name: BABYBACH
                                  Event Code: 20
                                  Message:
                                  Record Number: 12202
                                  Source Name: Google Update
                                  Time Written: 20091104051905.000000-000
                                  Event Type: Erreur
                                  User: AUTORITE NT\SYSTEM

                                  Computer Name: BABYBACH
                                  Event Code: 20
                                  Message:
                                  Record Number: 12215
                                  Source Name: Google Update
                                  Time Written: 20091104061905.000000-000
                                  Event Type: Erreur
                                  User: AUTORITE NT\SYSTEM

                                  Computer Name: BABYBACH
                                  Event Code: 20
                                  Message:
                                  Record Number: 12228
                                  Source Name: Google Update
                                  Time Written: 20091104071905.000000-000
                                  Event Type: Erreur
                                  User: AUTORITE NT\SYSTEM

                                  =====Security event log=====

                                  Computer Name: BABYBACH
                                  Event Code: 5038
                                  Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                  Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                                  Record Number: 10673
                                  Source Name: Microsoft-Windows-Security-Auditing
                                  Time Written: 20091104094203.305110-000
                                  Event Type: Échec de l'audit
                                  User:

                                  Computer Name: BABYBACH
                                  Event Code: 5038
                                  Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                  Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                                  Record Number: 10674
                                  Source Name: Microsoft-Windows-Security-Auditing
                                  Time Written: 20091104094203.375110-000
                                  Event Type: Échec de l'audit
                                  User:

                                  Computer Name: BABYBACH
                                  Event Code: 5038
                                  Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                  Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                                  Record Number: 10675
                                  Source Name: Microsoft-Windows-Security-Auditing
                                  Time Written: 20091104094203.445110-000
                                  Event Type: Échec de l'audit
                                  User:

                                  Computer Name: BABYBACH
                                  Event Code: 5038
                                  Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                  Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                                  Record Number: 10676
                                  Source Name: Microsoft-Windows-Security-Auditing
                                  Time Written: 20091104094203.527110-000
                                  Event Type: Échec de l'audit
                                  User:

                                  Computer Name: BABYBACH
                                  Event Code: 5038
                                  Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

                                  Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
                                  Record Number: 10677
                                  Source Name: Microsoft-Windows-Security-Auditing
                                  Time Written: 20091104094203.635110-000
                                  Event Type: Échec de l'audit
                                  User:

                                  ======Environment variables======

                                  "ComSpec"=%SystemRoot%\system32\cmd.exe
                                  "FP_NO_HOST_CHECK"=NO
                                  "OS"=Windows_NT
                                  "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;c:\Program Files\Microsoft SQL Server\90\Tools\binn\;C:\Program Files\Smart Projects\IsoBuster;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\DivX Shared\
                                  "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                                  "PROCESSOR_ARCHITECTURE"=x86
                                  "TEMP"=%SystemRoot%\TEMP
                                  "TMP"=%SystemRoot%\TEMP
                                  "USERNAME"=SYSTEM
                                  "windir"=%SystemRoot%
                                  "PROCESSOR_LEVEL"=6
                                  "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
                                  "PROCESSOR_REVISION"=170a
                                  "NUMBER_OF_PROCESSORS"=2
                                  "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
                                  "DFSTRACINGON"=FALSE
                                  "configsetroot"=%SystemRoot%\ConfigSetRoot
                                  "LenovoTestLogFile"=preload.log
                                  "LenovoTestPath"=C:\test\WINTEST\
                                  "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
                                  "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

                                  -----------------EOF-----------------
                                  1. Contributeur sécurité
                                    peux tu desinstaller manuellement

                                    C:\Program Files\Carbonite\CarbonitePreinstaller.exe

                                    et supprimer son dossier installation de program files

                                    ensuite

                                    Téléchargez MalwareByte's Anti-Malware
                                    https://www.majorgeeks.com/files/details/malwarebytes_anti_malware.html

                                    . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
                                    . enregistres le sur le bureau
                                    . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                                    . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                                    . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
                                    . Une fois la mise à jour terminé
                                    . rend-toi dans l'onglet, Recherche
                                    . Sélectionnes Exécuter un examen complet
                                    . Cliques sur Rechercher
                                    . Le scan démarre.
                                    . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                                    . Cliques sur Ok pour poursuivre.
                                    . Si des malwares ont été détectés, cliques sur Afficher les résultats
                                    . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                                    . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                                    . rends toi dans l'onglet rapport/log
                                    . tu cliques dessus pour l'afficher une fois affiché
                                    . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
                                    . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                                    . tu cliques droit dans le cadre de la reponse et coller

                                    Si tu as besoin d'aide regarde ces tutoriels :
                                    Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                                    http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
                                    1. Voici le dernier rapport demandé :

                                      Malwarebytes' Anti-Malware 1.41
                                      Version de la base de données: 3098
                                      Windows 6.0.6001 Service Pack 1

                                      04/11/2009 15:02:20
                                      mbam-log-2009-11-04 (15-02-20).txt

                                      Type de recherche: Examen complet (C:\|D:\|I:\|)
                                      Eléments examinés: 261486
                                      Temps écoulé: 1 hour(s), 26 minute(s), 54 second(s)

                                      Processus mémoire infecté(s): 0
                                      Module(s) mémoire infecté(s): 0
                                      Clé(s) du Registre infectée(s): 0
                                      Valeur(s) du Registre infectée(s): 0
                                      Elément(s) de données du Registre infecté(s): 0
                                      Dossier(s) infecté(s): 0
                                      Fichier(s) infecté(s): 0

                                      Processus mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Module(s) mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Clé(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)

                                      Valeur(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)

                                      Elément(s) de données du Registre infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Dossier(s) infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Fichier(s) infecté(s):
                                      (Aucun élément nuisible détecté)
                                      1. Contributeur sécurité
                                        as tu desinstallé C:\Program Files\Carbonite\CarbonitePreinstaller.exe ?
                                        • 1
                                        • 2