Comment savoir si je suis infectée

Résolu
Bonjour,

aujourd'hui, sur Windows Live Messenger , j'ai reçu un message d'un de mes contacts (le problème c'est qu'il ne m'a pas envoyé de lien)

Ce message contenait un lien que j'ai copié et collé sur Firefox, puis j'ai téléchargé le fichier, puis cliqué sur celui-ci. Je n'ai pas fait attention car ce contact devait m'envoyer des photos...

Le lien renvoit sur le site lephoto.com

Le ficher téléchargé contenait "IMG-67463" suivis de chiffres ".jpeg-myspace.com+mon adresse mail"

je me tourne vers vous pour savoir si mon ordinateur est infecté par un virus, ver, spam ou cheval de Troie

merci par avance
Configuration: Windows XP
Firefox 3.0.17

25 réponses

  1. Contributeur sécurité
    slt,

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. Rapport log.txt :

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Elody at 2010-01-11 19:09:23
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 12 GB (33%) free of 36 GB
      Total RAM: 1014 MB (39% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:09:40, on 11/01/2010
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\AGI\common\win32\PythonService.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\AskBarDis\bar\bin\AskService.exe
      C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
      C:\Acer\Empowering Technology\admServ.exe
      C:\WINDOWS\system32\bgsvcgen.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
      C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
      C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Acer\Acer Arcade\PCMService.exe
      C:\Acer\Empowering Technology\eRecovery\Monitor.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
      C:\acer\Empowering Technology\ePower\epm-dm.exe
      C:\WINDOWS\system32\igfxsrvc.exe
      C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
      C:\Acer\Empowering Technology\admtray.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
      C:\Program Files\Kiwee Toolbar\2.9.201\kwtbaim.exe
      C:\WINDOWS\system32\igfxext.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\WINDOWS\system32\LVCOMSX.EXE
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\SuperCopier2\SuperCopier2.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      D:\RSIT.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Program Files\trend micro\Elody.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.acer.com/worldwide/selection.html
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.9.201\KiweeIEToolbar.dll
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Acer eDataSecurity Management - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\system32\ToolBand.dll
      O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
      O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
      O3 - Toolbar: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.9.201\KiweeIEToolbar.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [LaunchApp] Alaunch
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
      O4 - HKLM\..\Run: [EPM-DM] c:\acer\Empowering Technology\ePower\epm-dm.exe
      O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
      O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
      O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
      O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
      O4 - HKLM\..\Run: [KiweeHook] "C:\Program Files\Kiwee Toolbar\2.9.201\kwtbaim.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O8 - Extra context menu item: &Sample Toolband Serach - res://C:\WINDOWS\system32\ToolBand.dll/MENUSEARCH.HTM
      O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
      O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
      O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
      O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
      O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
      O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
      O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
      O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
      O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      0
      1. Rapport info.txt :

        info.txt logfile of random's system information tool 1.06 2010-01-11 19:09:43

        ======Uninstall list======

        -->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Acer Inc.\Acer French Guide Link\Uninst.isu"
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{13E613EF-BB55-11D9-9D77-000129760D75}\setup.exe" -uninstall
        -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC4F90EC-B1DA-11D9-9D77-000129760D75}\setup.exe" -uninstall
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        Acer Arcade-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.EXE" -uninstall
        Acer eDataSecurity Management 1.00.23-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E431C518-2EE2-471E-9234-BE995C36D513}\setup.exe" -l0x40c -removeonly
        Acer eLock Management-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}
        Acer Empowering Technology framework-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{15B70821-7893-4607-805A-BB80F3EA8279}
        Acer eNet Management-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C06554A1-2C1E-4D20-B613-EE62C79927CC}\Setup.exe" -l0x40c
        Acer ePerformance Management-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{DEE08946-40F0-4890-853E-60A6C3306041}
        Acer ePower Management-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{58E5844B-7CE2-413D-83D1-99294BF6C74F}\Setup.exe" -l0x9
        Acer ePresentation Management-->C:\WINDOWS\UnInst32.exe AcerePrj.UNI
        Acer eSettings Management-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}
        Acer GridVista-->C:\WINDOWS\UnInst32.exe GridV.UNI
        Acer Screensaver-->MsiExec.exe /I{D458BBDC-0363-42E0-8FF9-4736E3CB3CA2}
        Adobe Acrobat 5.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
        Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
        Adobe Reader 7.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
        Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
        Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
        Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
        Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
        ArcSoft PhotoStudio 5.5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85309D89-7BE9-4094-BB17-24999C6118FC}\SETUP.EXE" -l0x40c
        Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
        avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
        AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
        Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
        Canon MP Navigator 2.0-->"C:\Program Files\Canon\MP Navigator 2.0\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator 2.0\uninst.ini
        Canon MP150-->"C:\WINDOWS\system32\CanonMP Uninstaller Information\{CA9A3609-3ECC-4574-8824-A8161A71A603}\DelDrv.exe" /U:{CA9A3609-3ECC-4574-8824-A8161A71A603} /L0x000c
        Canon Utilities Easy-PhotoPrint-->C:\Program Files\Canon\Easy-PhotoPrint\uninst.exe uninst.ini
        Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
        DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
        DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
        DivX-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
        Easy-WebPrint-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Canon\Easy-WebPrint\Uninst.isu"
        Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
        HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_AcrS009E\HXFSETUP.EXE -U -IAcrS009E.inf
        High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
        HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
        Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
        Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
        Intel(R) Graphics Media Accelerator Driver for Mobile-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2792 PCI\VEN_8086&DEV_2592
        iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
        Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
        Kiwee Toolbar-->"C:\Program Files\AGI\common\bootstrapper.exe" -uninstall"\"C:/Program Files/AGI/Python25\pythonw.exe\" \"C:\Program Files\AGI\common\pyagcore\installer.pyc\" -u KiweeToolbar"
        Launch Manager-->C:\WINDOWS\UnInst32.exe QtZgAcer.UNI
        Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
        Logiciel Intel(R) PROSet/Wireless-->C:\WINDOWS\Installer\iProInst.exe
        mCore-->MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
        Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
        Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
        Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
        Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
        Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
        Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
        Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
        Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
        Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0122-040C-0000-0000000FF1CE}
        Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
        Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
        Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
        Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
        Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
        Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB976325)-->"C:\WINDOWS\ie8updates\KB976325-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
        Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB963027)-->"C:\WINDOWS\$NtUninstallKB963027$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB969897)-->"C:\WINDOWS\$NtUninstallKB969897$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
        Mise à jour pour Windows Internet Explorer 8 (KB973874)-->"C:\WINDOWS\ie8updates\KB973874-IE8\spuninst\spuninst.exe"
        Mise à jour pour Windows Internet Explorer 8 (KB976749)-->"C:\WINDOWS\ie8updates\KB976749-IE8\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
        mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
        Mozilla Firefox (3.0.17)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
        mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
        mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
        mXML-->MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401}
        NTI Backup NOW! 4-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{385979FE-DC4F-4140-8EAD-A59625000D72} /l1036 BUN4
        NTI CD & DVD-Maker-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
        OmniPage SE 2.0-->MsiExec.exe /I{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}
        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
        PHOTOfunSTUDIO HD Edition-->C:\Program Files\InstallShield Installation Information\{9A9DBEBC-C800-4776-A970-D76D6AA405B1}\setup.exe -runfromtemp -l0x040c -z"Uninstall" -removeonly
        Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
        Picthema-->"C:\Program Files\Picthema\unins000.exe"
        PowerProducer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
        Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
        QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
        Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x40c -removeonly
        RUNAWAY - A road adventure-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6CEE8642-A462-42CE-8C3B-22E370DE7947}\setup.exe"
        Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
        SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
        Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
        Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
        VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
        VideoLAN VLC media player 0.8.5-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        Videora iPod touch Converter 4.07-->C:\Program Files\Red Kawa\Video Converter App\uninstaller.exe
        Vuze Toolbar-->"C:\Program Files\AskBarDis\unins000.exe"
        Vuze-->C:\Program Files\Vuze\uninstall.exe
        Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
        Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
        Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
        Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
        Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
        Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
        Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

        ======Security center information======

        AV: avast! antivirus 4.8.1335 [VPS 100111-0]

        ======System event log======

        Computer Name: ELODIE
        Event Code: 1001
        Message: Le réseau n'a attribué aucune adresse à votre ordinateur (par le serveur
        DHCP) pour la carte réseau avec l'adresse réseau 0013CEEB7062. Il s'est produit
        l'erreur suivante :
        L'opération a été annulée par l'utilisateur.
        .
        Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du
        serveur d'adresse réseau (DHCP).

        Record Number: 11684
        Source Name: Dhcp
        Time Written: 20091031104040.000000+060
        Event Type: erreur
        User:

        Computer Name: ELODIE
        Event Code: 6005
        Message: Le service d'Enregistrement d'événement a démarré.

        Record Number: 11683
        Source Name: EventLog
        Time Written: 20091031104035.000000+060
        Event Type: Informations
        User:

        Computer Name: ELODIE
        Event Code: 6009
        Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 3 Uniprocessor Free.

        Record Number: 11682
        Source Name: EventLog
        Time Written: 20091031104035.000000+060
        Event Type: Informations
        User:

        Computer Name: ELODIE
        Event Code: 6006
        Message: Le service d'Enregistrement d'événement a été arrêté.

        Record Number: 11681
        Source Name: EventLog
        Time Written: 20091030182729.000000+060
        Event Type: Informations
        User:

        Computer Name: ELODIE
        Event Code: 7036
        Message: Le service Hôte de périphérique universel Plug-and-Play est entré dans l'état : en cours d'exécution.

        Record Number: 11680
        Source Name: Service Control Manager
        Time Written: 20091030134550.000000+060
        Event Type: Informations
        User:

        =====Application event log=====

        Computer Name: ELODIE
        Event Code: 0
        Message:
        Record Number: 848
        Source Name: RichVideo
        Time Written: 20090626084021.000000+120
        Event Type: Informations
        User:

        Computer Name: ELODIE
        Event Code: 0
        Message:
        Record Number: 847
        Source Name: RegSrvc
        Time Written: 20090626084021.000000+120
        Event Type: Informations
        User:

        Computer Name: ELODIE
        Event Code: 1
        Message:
        Record Number: 846
        Source Name: Bonjour Service
        Time Written: 20090626084021.000000+120
        Event Type: Informations
        User:

        Computer Name: ELODIE
        Event Code: 0
        Message:
        Record Number: 845
        Source Name: EvtEng
        Time Written: 20090626083958.000000+120
        Event Type: Informations
        User:

        Computer Name: ELODIE
        Event Code: 1002
        Message: L'environnement s'est arrêté de façon inattendue et Explorer.exe a redémarré.

        Record Number: 844
        Source Name: Winlogon
        Time Written: 20090625203457.000000+120
        Event Type: Informations
        User:

        =====Security event log=====

        Computer Name: ELODIE
        Event Code: 615
        Message: Services IPSec : Les services IPSec ont démarré correctement.

        Record Number: 19570
        Source Name: Security
        Time Written: 20091209083612.000000+060
        Event Type: Succès de l'audit
        User: AUTORITE NT\SERVICE RÉSEAU

        Computer Name: ELODIE
        Event Code: 540
        Message: Ouverture de session réseau réussie :

        Utilisateur :

        Domaine :

        Id. de la session : (0x0,0x1F427)

        Type de session : 3

        Processus de session : NtLmSsp

        Package d'authentification : NTLM

        Nom de la station de travail :

        GUID d'ouv. de session : -

        Record Number: 19569
        Source Name: Security
        Time Written: 20091209083612.000000+060
        Event Type: Succès de l'audit
        User: AUTORITE NT\ANONYMOUS LOGON

        Computer Name: ELODIE
        Event Code: 576
        Message: Privilèges spéciaux assignés à la nouvelle session :

        Utilisateur : SERVICE LOCAL

        Domaine : AUTORITE NT

        Id. de la session : (0x0,0x3E5)

        Privilèges : SeAuditPrivilege
        SeAssignPrimaryTokenPrivilege
        SeChangeNotifyPrivilege

        Record Number: 19568
        Source Name: Security
        Time Written: 20091209083608.000000+060
        Event Type: Succès de l'audit
        User: AUTORITE NT\SERVICE LOCAL

        Computer Name: ELODIE
        Event Code: 528
        Message: Ouverture de session réseau réussie :

        Utilisateur : SERVICE LOCAL

        Domaine : AUTORITE NT

        Id. de la session : (0x0,0x3E5)

        Type de session : 5

        Processus de session : Advapi

        Package d'authentification : Negotiate

        Station de travail :

        GUID d'ouv. de session : -

        Record Number: 19567
        Source Name: Security
        Time Written: 20091209083608.000000+060
        Event Type: Succès de l'audit
        User: AUTORITE NT\SERVICE LOCAL

        Computer Name: ELODIE
        Event Code: 515
        Message: Un Processus d'ouv. de session s'est fait reconnaître par l'autorité locale de sécurité.
        Ce Processus d'ouv. de session sera autorisé à soumettre des requêtes d'ouverture de session.

        Processus d'ouv. de session : KSecDD

        Record Number: 19566
        Source Name: Security
        Time Written: 20091209083608.000000+060
        Event Type: Succès de l'audit
        User: AUTORITE NT\SYSTEM

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Intel\Wireless\Bin\;C:\Program Files\QuickTime\QTSystem\
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=6
        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 13 Stepping 6, GenuineIntel
        "PROCESSOR_REVISION"=0d06
        "NUMBER_OF_PROCESSORS"=1
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
        "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

        -----------------EOF-----------------
        0
        1. Contributeur sécurité
          Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
          https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3

          * Lance l'installation du programme en exécutant le fichier téléchargé.
          * Double-clique maintenant sur le raccourci de Toolbar-S&D.
          * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
          * Choisis maintenant l'option 2. Patiente jusqu'à la fin de la recherche.
          * Poste le rapport généré. (C:\TB.txt)

          ______________________

          scan avec malwarebyte , fais un scan rapide et colle le rapport obtenu et vire ce qui est trouvé:

          https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­

          ______________________

          a plus
          0
          1. Merci de m'aider !
            Alors voici le rapport Toolbar-S&D TB.txt :

            -----------\\ ToolBar S&D 1.2.9 XP/Vista

            Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
            X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) M processor 1.70GHz )
            BIOS : Phoenix NoteBIOS 4.0 Release 6.1
            USER : Elody ( Administrator )
            BOOT : Normal boot
            Antivirus : avast! antivirus 4.8.1335 [VPS 100111-0] 4.8.1335 (Activated)
            C:\ (Local Disk) - FAT32 - Total:35 Go (Free:11 Go)
            D:\ (Local Disk) - FAT32 - Total:35 Go (Free:33 Go)
            E:\ (CD or DVD)

            "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
            Option : [2] ( 11/01/2010|19:39 )
            C:\DOCUME~1\Elody\LOCALS~1\Temp\mc23.tmp
            C:\DOCUME~1\Elody\LOCALS~1\Temp\mc22.tmp
            C:\DOCUME~1\Elody\LOCALS~1\Temp\mc21.tmp

            -----------\\ SUPPRESSION

            Supprime! - [Service] ASKService
            Supprime! - [Service] ASKUpgrade
            Supprime! - C:\DOCUME~1\Elody\Cookies\elody@www.bananalotto[1].txt
            Supprime! - C:\Program Files\AskBarDis\unins000.dat
            Supprime! - C:\Program Files\AskBarDis\unins000.exe
            Supprime! - C:\Program Files\AskBarDis\bar
            Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kiwee Toolbar\config
            Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kiwee Toolbar\images
            Echec ! - C:\Program Files\Kiwee Toolbar\2.9.201
            Echec ! - C:\Program Files\Kiwee Toolbar\2.9.201\AGTBCore.dll
            Echec ! - C:\Program Files\Kiwee Toolbar\2.9.201\KiweeTBCore.dll
            Echec ! - C:\Program Files\Kiwee Toolbar\2.9.201\MsnIMToolbar.dll
            Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1\Kiwee Toolbar
            Supprime! - C:\DOCUME~1\Elody\LOCALS~1\Temp\mc23.tmp
            Supprime! - C:\DOCUME~1\Elody\LOCALS~1\Temp\mc22.tmp
            Supprime! - C:\DOCUME~1\Elody\LOCALS~1\Temp\mc21.tmp
            Supprime! - C:\Program Files\AskBarDis
            Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kiwee Toolbar
            Echec ! - C:\Program Files\Kiwee Toolbar

            -----------\\ DEUXIEME PASSAGE

            Echec ! - C:\Program Files\Kiwee Toolbar\2.9.201
            Echec ! - C:\Program Files\Kiwee Toolbar\2.9.201\AGTBCore.dll
            Echec ! - C:\Program Files\Kiwee Toolbar\2.9.201\KiweeTBCore.dll
            Echec ! - C:\Program Files\Kiwee Toolbar\2.9.201\MsnIMToolbar.dll
            Echec ! - C:\Program Files\Kiwee Toolbar

            -----------\\ Recherche de Fichiers / Dossiers ...

            C:\Program Files\Kiwee Toolbar
            C:\Program Files\Kiwee Toolbar\2.9.201
            C:\Program Files\Kiwee Toolbar\2.9.201\AGTBCore.dll
            C:\Program Files\Kiwee Toolbar\2.9.201\KiweeTBCore.dll
            C:\Program Files\Kiwee Toolbar\2.9.201\MsnIMToolbar.dll

            -----------\\ Extensions

            (Elody) - {E9A1DEE0-C623-4439-8932-001E7D17607D} => ajtoolbar
            (Elody) - {4a428302-5267-4749-bb22-459b3236695f} => modoki
            (Elody) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user
            (Elody) - {7b821b0e-b102-4f9b-b6e3-433ede1fe379} => torrentbar
            (Elody) - {e2c58150-9d72-11dd-ad8b-0800200c9a66} => chrome

            -----------\\ [..\Internet Explorer\Main]

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
            "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
            "Search Page"="https://www.google.com/?gws_rd=ssl"
            "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
            "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
            "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
            "Start Page Redirect Cache"="https://www.msn.com/fr-fr?ocid=iehp"

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
            "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
            "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
            "Start Page"="https://www.msn.com/fr-fr/"

            --------------------\\ Recherche d'autres infections

            Aucune autre infection trouvée !

            1 - "C:\ToolBar SD\TB_1.txt" - 11/01/2010|19:40 - Option : [2]

            -----------\\ Fin du rapport a 19:40:52,21
            0
            1. Et voila le scan avec malwarebyte : (aucun fichier trouvé)
              Merci.

              Malwarebytes' Anti-Malware 1.44
              Version de la base de données: 3540
              Windows 5.1.2600 Service Pack 3
              Internet Explorer 8.0.6001.18702

              11/01/2010 20:17:16
              mbam-log-2010-01-11 (20-17-16).txt

              Type de recherche: Examen complet (C:\|D:\|)
              Eléments examinés: 176692
              Temps écoulé: 28 minute(s), 57 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 0
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 0

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              (Aucun élément nuisible détecté)
              0
              1. Contributeur sécurité
                télécharge OTM
                http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/ (de Old_Timer) sur ton Bureau.

                double-clique sur OTM.exe pour le lancer.
                copie la liste qui se trouve en citation ci-dessous,
                et colle-la dans le cadre de gauche de OTM :Paste instruction for items to be moved.

                :processes
                explorer.exe
                :files
                C:\Program Files\Kiwee Toolbar
                :reg
                [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}]
                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                {6638A9DE-0745-4292-8A2E-AE530E7B9B3F}
                :commands
                [purity]
                [emptytemp]
                [start explorer]

                clique sur MoveIt! pour lancer la suppression.
                le résultat apparaitra dans le cadre "Results".
                clique sur Exit pour fermer.
                poste le rapport situé dans C:\_OTM\MovedFiles.

                il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                _______________________

                *Téléchargez Tools Cleaner 2 sur votre bureau.
                --> https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/
                Double cliquez sur ToolsCleaner 2 pour l’exécuter. ( si vous êtes sous vista cliquez droit sur le fichier ToolsCleaner 2 et exécutez le en tant qu'administrateur )
                *Cliquez sur Recherche et laissez la se dérouler
                * Cliquez sur Suppression pour finaliser.
                * Vous pouvez , si vous le souhaitez, vous servir des Options facultatives.
                * Cliquez sur Quitter pour obtenir le rapport.
                * Postez le rapport (TCleaner.txt) qui se trouve à la racine de votre disque dur (C:\) dans le forum où cela vous a été demandé.

                __________________________

                pour vérifier que tout est bon:

                colle le rapport d'un scan en ligne
                avec un des suivants:

                bitdefender en ligne :
                http://www.bitdefender.fr/scan_fr/scan8/ie.html

                Panda en ligne :
                http://pandasoftware.fr

                Kaspersky en ligne
                https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

                Eset (Nod32) en ligne
                https://www.eset.com/
                0
                1. Impossible de supprimer le fichier C:\Program Files\Kiwee Toolbar
                  Voici le rapport du scan de ce fichier :
                  Je fais les prochaines manips de suite.

                  Malwarebytes' Anti-Malware 1.44
                  Version de la base de données: 3540
                  Windows 5.1.2600 Service Pack 3
                  Internet Explorer 8.0.6001.18702

                  11/01/2010 20:25:20
                  mbam-log-2010-01-11 (20-25-20).txt

                  Type de recherche: Examen rapide
                  Eléments examinés: 5
                  Temps écoulé: 4 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 0
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 0

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  (Aucun élément nuisible détecté)
                  0
                  1. Contributeur sécurité
                    fais ce que j'ai mis et colle OTM ...
                    0
                    1. J'ai suivi tes instructions, mon pc a planté puis au bout de quinze minutes a redémarré. Au redémarrage le rapport s'est affiché.
                      Rapport OTM :

                      Files moved on Reboot...
                      C:\Program Files\Kiwee Toolbar\2.9.201 folder moved successfully.
                      C:\Program Files\Kiwee Toolbar folder moved successfully.

                      Registry entries deleted on Reboot...
                      0
                      1. [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

                        --> Recherche:

                        C:\TB.txt: trouvé !
                        C:\Toolbar SD: trouvé !
                        C:\Rsit: trouvé !
                        C:\Program Files\trend micro\HijackThis.exe: trouvé !
                        C:\Program Files\trend micro\hijackthis.log: trouvé !
                        0
                        1. Alors, avec bitdefender , l'analyse se bloque à 30% pour finalement afficher un rapport d'erreur de windows quelques secondes et le pc effectue un redémarrage. Après celui-ci, windows me signale une erreur dans les fichiers C:\DOCUME~1\Elody\LOCALS~1\Temp\WERef66.dir00\Mini01111-02.dmp et C:\DOCUME~1\Elody\LOCALS~1\Temp\WERef66.dir00\sysdata.xml
                          Que dois-je faire ?
                          Je lance un scan avec un autre ?
                          Merci
                          0
                          1. Voici ce que les rapports d'erreurs de Microsoft me disent :

                            Résumé du rapport de problèmes

                            Type de problème

                            Erreur d''arrêt Windows (un message s''affiche sur un écran bleu avec des informations de code d''erreur)

                            Solution disponible ?

                            Non

                            Que signifie ce problème ?

                            Windows a rencontré un problème qu''il ne peut pas résoudre et doit redémarrer.

                            Cause

                            Inconnue

                            Symptômes

                            Un message s''affiche sur un écran bleu avec des informations de code d''erreur (par exemple : 0x0000001E, KMODE_EXCEPTION_NOT_HANDLED)

                            Autres mesures à prendre

                            Continuez à envoyer des rapports de problèmes afin que les analystes de Microsoft étudient le problème et essaient de le corriger le plus rapidement possible.
                            0
                            1. Contributeur sécurité
                              utilise pour supprimer tes traces

                              CCLEANER: (lance un nettoyage et répare 3 fois les erreurs) sans installer la barre yahoo
                              (dans les options puis avancé :désactive la case: effacer les fichiers de plus de 48 heures)
                              https://www.malekal.com/tutoriel-ccleaner/
                              https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

                              ________________________

                              télécharge combofix (par sUBs) ici :

                              http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                              et enregistre le sur le bureau.

                              déconnecte toi d'internet et ferme toutes tes applications.

                              désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

                              double-clique sur combofix.exe et suis les instructions

                              à la fin, il va produire un rapport C:\ComboFix.txt

                              réactive ton parefeu, ton antivirus, la garde de ton antispyware

                              copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

                              Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

                              Tu as un tutoriel complet ici :

                              https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                              0
                              1. Voici le rapport complet :
                                bonne chance !

                                ComboFix 10-01-11.01 - Elody 11/01/2010 22:18:40.1.1 - FAT32x86
                                Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1014.568 [GMT 1:00]
                                Lancé depuis: c:\documents and settings\Elody\Bureau\ComboFix.exe
                                Commutateurs utilisés :: c:\documents and settings\Elody\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
                                AV: avast! antivirus 4.8.1335 [VPS 100111-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
                                .

                                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                .

                                c:\program files\WinPCap
                                c:\program files\WinPCap\daemon_mgm.exe
                                c:\program files\WinPCap\npf_mgm.exe
                                c:\program files\WinPCap\rpcapd.exe
                                c:\windows\system32\drivers\npf.sys
                                c:\windows\system32\Packet.dll
                                c:\windows\system32\pthreadVC.dll
                                c:\windows\system32\WanPacket.dll
                                c:\windows\system32\wpcap.dll

                                .
                                ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                                .

                                -------\Service_NPF

                                ((((((((((((((((((((((((((((( Fichiers créés du 2009-12-11 au 2010-01-11 ))))))))))))))))))))))))))))))))))))
                                .

                                2010-01-11 20:52 . 2010-01-11 20:52 -------- d-----w- c:\program files\AskBardis
                                2010-01-11 20:51 . 2010-01-11 20:51 -------- d-----w- c:\program files\CCleaner
                                2010-01-11 20:15 . 2010-01-11 20:15 -------- d-----w- C:\FOUND.002
                                2010-01-11 19:59 . 2010-01-11 19:59 -------- d-----w- C:\FOUND.001
                                2010-01-11 19:55 . 2010-01-11 19:55 -------- d-----w- c:\documents and settings\Elody\Application Data\QuickScan
                                2010-01-11 19:55 . 2010-01-11 16:33 789320 ----a-w- c:\documents and settings\Elody\Application Data\Mozilla\Firefox\Profiles\gk06sy83.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
                                2010-01-11 19:55 . 2010-01-11 16:32 698184 ----a-w- c:\documents and settings\Elody\Application Data\Mozilla\Firefox\Profiles\gk06sy83.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
                                2010-01-11 19:39 . 2010-01-11 19:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Kiwee Toolbar
                                2010-01-11 18:46 . 2010-01-11 18:46 -------- d-----w- c:\documents and settings\Elody\Application Data\Malwarebytes
                                2010-01-11 18:46 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                                2010-01-11 18:46 . 2010-01-11 18:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                                2010-01-11 18:46 . 2010-01-11 18:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                                2010-01-11 18:46 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
                                2010-01-11 18:38 . 2010-01-11 18:38 -------- d-----w- C:\ToolBar SD
                                2010-01-11 18:18 . 2010-01-11 18:18 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
                                2010-01-11 18:18 . 2010-01-11 18:18 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
                                2010-01-11 18:18 . 2010-01-11 18:18 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
                                2010-01-11 18:18 . 2010-01-11 18:18 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
                                2010-01-11 18:12 . 2010-01-11 18:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                                2010-01-11 18:12 . 2010-01-11 18:12 -------- d-----w- c:\program files\Spybot - Search & Destroy
                                2010-01-11 18:09 . 2010-01-11 18:09 -------- d-----w- c:\program files\trend micro
                                2010-01-11 18:09 . 2010-01-11 18:09 -------- d-----w- C:\rsit
                                2009-12-19 12:32 . 2009-12-19 12:32 -------- d-----w- c:\program files\iPod
                                2009-12-19 12:31 . 2009-12-19 12:31 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
                                2009-12-19 12:28 . 2009-12-19 12:29 -------- d-----w- c:\program files\QuickTime
                                2009-12-19 12:18 . 2009-12-19 12:18 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
                                2009-12-17 16:14 . 2008-04-13 19:39 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
                                2009-12-17 16:14 . 2008-04-13 19:39 5504 ----a-w- c:\windows\system32\dllcache\mstee.sys
                                2009-12-17 16:14 . 2008-04-13 19:46 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
                                2009-12-17 16:14 . 2008-04-13 19:46 10880 ----a-w- c:\windows\system32\dllcache\ndisip.sys
                                2009-12-17 16:04 . 2005-07-19 16:31 53248 ----a-r- c:\windows\system32\InstMed.exe
                                2009-12-17 16:04 . 2005-01-31 10:20 211712 ----a-w- c:\windows\system32\drivers\LV561AV.SYS
                                2009-12-17 16:04 . 2005-01-31 10:00 106496 ----a-w- c:\windows\system32\lvcoinst.dll
                                2009-12-17 16:04 . 2005-05-27 09:36 372736 ----a-w- c:\windows\system32\LVUI2RC.dll
                                2009-12-17 16:04 . 2005-05-27 09:31 22016 ----a-w- c:\windows\system32\drivers\LVUSBSta.sys
                                2009-12-17 16:04 . 2005-05-27 09:29 204800 ----a-w- c:\windows\system32\LVUI2.dll
                                2009-12-17 16:04 . 2005-01-31 10:08 204800 ----a-w- c:\windows\system32\LVCodec2.dll
                                2009-12-17 16:04 . 2009-12-17 16:04 -------- d-----w- c:\program files\Fichiers communs\Logitech

                                .
                                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2009-12-09 11:17 . 2006-01-06 16:16 85834 ----a-w- c:\windows\system32\perfc00C.dat
                                2009-12-09 11:17 . 2006-01-06 16:16 512530 ----a-w- c:\windows\system32\perfh00C.dat
                                2009-11-13 11:26 . 2009-11-13 11:26 152576 ----a-w- c:\documents and settings\Elody\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
                                2009-11-13 11:26 . 2009-11-13 11:26 79488 ----a-w- c:\documents and settings\Elody\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
                                2009-10-29 23:09 . 2009-10-29 23:09 10686001 ----a-w- c:\documents and settings\Elody\Application Data\Azureus\plugins\azump\mplayer.exe
                                2009-10-29 07:42 . 2004-08-05 04:00 916480 ----a-w- c:\windows\system32\wininet.dll
                                2009-10-28 17:56 . 2009-10-21 16:58 36541 ----a-w- c:\documents and settings\Elody\Application Data\mdbu.bin
                                2009-10-21 05:39 . 2004-08-05 04:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
                                2009-10-21 05:39 . 2004-08-05 04:00 25088 ----a-w- c:\windows\system32\httpapi.dll
                                2009-10-20 16:20 . 2004-08-05 04:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
                                2006-05-06 17:42 . 2009-04-29 15:02 7260160 ----a-w- c:\program files\mozilla firefox\plugins\libvlc.dll
                                2009-02-24 20:34 . 2009-02-24 20:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
                                2009-02-24 20:34 . 2009-02-24 20:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
                                .

                                ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                REGEDIT4

                                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                                "{0BC6E3FA-78EF-4886-842C-5A1258C4455A}"= "c:\program files\AGI\common\agcutils.dll" [2010-01-11 43520]

                                [HKEY_CLASSES_ROOT\clsid\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
                                [HKEY_CLASSES_ROOT\agcutils.AGSearchHook.1]
                                [HKEY_CLASSES_ROOT\TypeLib\{647B16D8-AD7B-4983-82D7-82A270FC9E6D}]
                                [HKEY_CLASSES_ROOT\agcutils.AGSearchHook]

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
                                "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "LaunchApp"="Alaunch" [X]
                                "RTHDCPL"="RTHDCPL.EXE" [2005-11-16 15600128]
                                "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-07 102491]
                                "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-07 692315]
                                "PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2005-08-31 147456]
                                "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
                                "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
                                "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
                                "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
                                "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-17 94208]
                                "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-17 77824]
                                "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-17 114688]
                                "eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-10-19 69632]
                                "EPM-DM"="c:\acer\Empowering Technology\ePower\epm-dm.exe" [2005-11-25 212992]
                                "Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2005-11-09 3084288]
                                "LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2005-12-01 458752]
                                "eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 397312]
                                "ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
                                "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
                                "OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
                                "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
                                "LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
                                "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
                                "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]

                                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                                c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                                Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

                                [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^PHOTOfunSTUDIO HD Edition.lnk]
                                path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\PHOTOfunSTUDIO HD Edition.lnk
                                backup=c:\windows\pss\PHOTOfunSTUDIO HD Edition.lnkCommon Startup

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                                "EnableFirewall"= 0 (0x0)

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                "%windir%\\system32\\sessmgr.exe"=
                                "c:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"=
                                "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                                "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                "c:\\Program Files\\Vuze\\Azureus.exe"=
                                "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
                                "c:\\Program Files\\Messenger\\msmsgs.exe"=
                                "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                                "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
                                "c:\\Program Files\\iTunes\\iTunes.exe"=

                                R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [28/04/2009 20:52 114768]
                                R2 AGWinService;AG Windows Service;c:\program files\AGI\common\win32\pythonservice.exe [14/06/2009 20:57 10240]
                                R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [28/04/2009 20:52 20560]

                                --- Autres Services/Pilotes en mémoire ---

                                *Deregistered* - mchInjDrv
                                .
                                Contenu du dossier 'Tâches planifiées'

                                2009-09-29 c:\windows\Tasks\AppleSoftwareUpdate.job
                                - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
                                .
                                .
                                ------- Examen supplémentaire -------
                                .
                                uDefault_Search_URL = hxxp://www.google.com/ie
                                mWindow Title =
                                uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
                                uInternet Settings,ProxyOverride = *.local
                                uSearchAssistant = hxxp://www.google.com/ie
                                uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
                                IE: &Sample Toolband Serach - c:\windows\system32\ToolBand.dll/MENUSEARCH.HTM
                                IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
                                IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
                                IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
                                IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
                                IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
                                DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                                FF - ProfilePath - c:\documents and settings\Elody\Application Data\Mozilla\Firefox\Profiles\gk06sy83.default\
                                FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/ig
                                FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q=
                                FF - component: c:\documents and settings\Elody\Application Data\Mozilla\Firefox\Profiles\gk06sy83.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
                                FF - plugin: c:\documents and settings\Elody\Application Data\Mozilla\Firefox\Profiles\gk06sy83.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
                                FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
                                FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
                                FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
                                FF - plugin: c:\program files\Mozilla Firefox\plugins\npvlc.dll
                                FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
                                FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
                                .
                                - - - - ORPHELINS SUPPRIMES - - - -

                                WebBrowser-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
                                WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
                                AddRemove-Ask Toolbar_is1 - c:\program files\AskBarDis\unins000.exe

                                **************************************************************************

                                catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2010-01-11 22:24
                                Windows 5.1.2600 Service Pack 3 FAT NTAPI

                                Recherche de processus cachés ...

                                Recherche d'éléments en démarrage automatique cachés ...

                                Recherche de fichiers cachés ...

                                Scan terminé avec succès
                                Fichiers cachés: 0

                                **************************************************************************

                                [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
                                "ImagePath"="\??\c:\docume~1\Elody\LOCALS~1\Temp\mc21.tmp"
                                .
                                --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                                [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
                                "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
                                .
                                --------------------- DLLs chargées dans les processus actifs ---------------------

                                - - - - - - - > 'winlogon.exe'(604)
                                c:\windows\system32\Ati2evxx.dll

                                - - - - - - - > 'explorer.exe'(2820)
                                c:\program files\SuperCopier2\SC2Hook.dll
                                c:\windows\system32\MSNChatHook.dll
                                c:\windows\system32\sysenv.dll
                                c:\windows\system32\MSVCR71.dll
                                c:\program files\ScanSoft\OmniPageSE2.0\ophookSE2.dll
                                c:\windows\system32\eappprxy.dll
                                c:\windows\system32\webcheck.dll
                                c:\windows\system32\WPDShServiceObj.dll
                                c:\windows\system32\PortableDeviceTypes.dll
                                c:\windows\system32\PortableDeviceApi.dll
                                .
                                ------------------------ Autres processus actifs ------------------------
                                .
                                c:\program files\Intel\Wireless\Bin\EvtEng.exe
                                c:\program files\Intel\Wireless\Bin\S24EvMon.exe
                                c:\program files\Alwil Software\Avast4\aswUpdSv.exe
                                c:\program files\Alwil Software\Avast4\ashServ.exe
                                c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                c:\acer\Empowering Technology\admServ.exe
                                c:\windows\RTHDCPL.EXE
                                c:\windows\system32\bgsvcgen.exe
                                c:\program files\Bonjour\mDNSResponder.exe
                                c:\program files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
                                c:\program files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
                                c:\program files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
                                c:\program files\Java\jre6\bin\jqs.exe
                                c:\program files\Intel\Wireless\Bin\RegSrvc.exe
                                c:\program files\CyberLink\Shared Files\RichVideo.exe
                                c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                c:\windows\system32\igfxext.exe
                                c:\windows\system32\igfxsrvc.exe
                                c:\program files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
                                c:\program files\Alwil Software\Avast4\ashMaiSv.exe
                                c:\program files\Alwil Software\Avast4\ashWebSv.exe
                                c:\program files\iPod\bin\iPodService.exe
                                c:\windows\system32\wbem\wmiapsrv.exe
                                c:\program files\Microsoft Office\OFFICE11\POWERPNT.EXE
                                c:\program files\Microsoft\Office Live\OfficeLiveSignIn.exe
                                c:\progra~1\FICHIE~1\MICROS~1\DW\DW20.EXE
                                c:\windows\system32\wscntfy.exe
                                .
                                **************************************************************************
                                .
                                Heure de fin: 2010-01-11 22:27:21 - La machine a redémarré
                                ComboFix-quarantined-files.txt 2010-01-11 21:27

                                Avant-CF: 13 272 547 328 octets libres
                                Après-CF: 13 219 954 688 octets libres

                                WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
                                [boot loader]
                                timeout=2
                                default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
                                [operating systems]
                                c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                                multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

                                - - End Of File - - 00C90FFAD592BCD2DA394BABCF0E9ECA
                                0
                                1. Contributeur sécurité
                                  télécharge OTM
                                  http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/ (de Old_Timer) sur ton Bureau.

                                  double-clique sur OTM.exe pour le lancer.
                                  copie la liste qui se trouve en citation ci-dessous,
                                  et colle-la dans le cadre de gauche de OTM :Paste instruction for items to be moved.

                                  :processes
                                  explorer.exe
                                  :files
                                  c:\program files\AskBardis
                                  c:\documents and settings\All Users\Application Data\Kiwee Toolbar
                                  c:\program files\AGI\common\agcutils.dll
                                  :reg
                                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                                  "{0BC6E3FA-78EF-4886-842C-5A1258C4455A}"=-
                                  [-HKEY_CLASSES_ROOT\clsid\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
                                  [-HKEY_CLASSES_ROOT\agcutils.AGSearchHook.1]
                                  [-HKEY_CLASSES_ROOT\TypeLib\{647B16D8-AD7B-4983-82D7-82A270FC9E6D}]
                                  [-HKEY_CLASSES_ROOT\agcutils.AGSearchHook]
                                  :commands
                                  [purity]
                                  [emptytemp]
                                  [start explorer]

                                  clique sur MoveIt! pour lancer la suppression.
                                  le résultat apparaitra dans le cadre "Results".
                                  clique sur Exit pour fermer.
                                  poste le rapport situé dans C:\_OTM\MovedFiles.

                                  il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
                                  0
                                  1. Bonjour,
                                    je lance OTM comme tu dis, copie, lance et comme la première fois le pc plante. Je suis obligé de redémarrer. Mais cette fois ci contrairement a la première fois, le rapport ne s'affiche pas au démarrage. Le fichier MovedFiles existe bien mais le rapport ne s'y trouve pas. Dedans il y a deux dossiers c_documents and settins et c_program files.
                                    0
                                    1. Contributeur sécurité
                                      comment va le pc?

                                      pour voir si tout a été viré mets un rapport rsit
                                      0
                                      1. Rien d'anormal pour le pc, il fonctionne normalement.

                                        Rapport rsit :

                                        Logfile of random's system information tool 1.06 (written by random/random)
                                        Run by Elody at 2010-01-12 12:04:40
                                        Microsoft Windows XP Édition familiale Service Pack 3
                                        System drive C: has 13 GB (35%) free of 36 GB
                                        Total RAM: 1014 MB (50% free)

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 12:04:47, on 12/01/2010
                                        Platform: Windows XP SP3 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\csrss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\AGI\common\win32\PythonService.exe
                                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        C:\Acer\Empowering Technology\admServ.exe
                                        C:\WINDOWS\system32\bgsvcgen.exe
                                        C:\Program Files\Bonjour\mDNSResponder.exe
                                        C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
                                        C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
                                        C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
                                        C:\Program Files\Java\jre6\bin\jqs.exe
                                        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
                                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                        C:\WINDOWS\System32\alg.exe
                                        C:\WINDOWS\RTHDCPL.EXE
                                        C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                        C:\Program Files\Acer\Acer Arcade\PCMService.exe
                                        C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                                        C:\WINDOWS\system32\hkcmd.exe
                                        C:\WINDOWS\system32\igfxpers.exe
                                        C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                        C:\acer\Empowering Technology\ePower\epm-dm.exe
                                        C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
                                        C:\Acer\Empowering Technology\admtray.exe
                                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                        C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
                                        C:\Program Files\Java\jre6\bin\jusched.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\LVCOMSX.EXE
                                        C:\Program Files\iTunes\iTunesHelper.exe
                                        C:\Program Files\SuperCopier2\SuperCopier2.exe
                                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                        C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                        C:\WINDOWS\system32\igfxext.exe
                                        C:\WINDOWS\system32\igfxsrvc.exe
                                        C:\Program Files\iPod\bin\iPodService.exe
                                        C:\Program Files\Mozilla Firefox\firefox.exe
                                        D:\RSIT.exe
                                        C:\WINDOWS\system32\wbem\wmiprvse.exe
                                        C:\Program Files\trend micro\Elody.exe

                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
                                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                        R3 - URLSearchHook: (no name) - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
                                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                                        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                        O3 - Toolbar: Acer eDataSecurity Management - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\system32\ToolBand.dll
                                        O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
                                        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                        O4 - HKLM\..\Run: [LaunchApp] Alaunch
                                        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                        O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                        O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
                                        O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                                        O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                                        O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                                        O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                                        O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                                        O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                                        O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                                        O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                                        O4 - HKLM\..\Run: [EPM-DM] c:\acer\Empowering Technology\ePower\epm-dm.exe
                                        O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
                                        O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
                                        O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                                        O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
                                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                        O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                        O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                        O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
                                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                        O8 - Extra context menu item: &Sample Toolband Serach - res://C:\WINDOWS\system32\ToolBand.dll/MENUSEARCH.HTM
                                        O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
                                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                        O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
                                        O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
                                        O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
                                        O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
                                        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                                        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
                                        O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
                                        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                        O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
                                        O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
                                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                        O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
                                        O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
                                        O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
                                        O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                        O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                        O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
                                        O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                        0
                                        • 1
                                        • 2