Pb recherche internet a cause antivirus plus

Résolu
Bonjour,

je suis nouvelle sur le site alors j'espère que quelqu'un pourra m'aider ....

voila j'utilise un netbook hercules sous windows xp, avec ie 7,
hier j'ai eu un souci avec antivirus plus, j'ai donc consulté le forum et j'ai installé malawarebytes et cela a reglé une partie de mon pb.

maintenant dès que j'ouvre une fenêtre de recheche par google, cela me renvoie vers d'autres sites sans me donner du tout les résultats de ma recherche , entre autres : http://supersearch11.com qui ne donne rien du tout.

pourtant lorsque je fais une analyse par malaware, aucun mauvais élément n'est détecté

en attendant votre aide, merci

31 réponses

Résumé de la discussion

Une utilisatrice sous Windows XP avec Internet Explorer 7 rencontre une redirection des recherches Google vers des sites externes, notamment supersearch11.com, après une infection détectée et partiellement corrigée par Malwarebytes. Plusieurs avis recommandent une analyse approfondie des éléments de démarrage et du registre, la purge de la restauration système et l’emploi d’outils tels que JavaRa et ToolsCleaner. Des recommandations ciblent la mise à jour d’Internet Explorer et de Java, puis la vérification des clés Run et des fichiers système pour écarter les entrées malveillantes. Certaines mesures évoquent la purge d’extensions et de services indésirables puis un nouveau balayage afin de confirmer le nettoyage et prévenir les redirections futures.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour

    peux tu poster ici le rapport de suppression de malawarebytes

    ensuite

    • Télécharge Random's System Information Tool (RSIT) de Random/Random.

    http://images.malwareremoval.com/random/RSIT.exe

    • Enregistre le sur ton Bureau.

    • Double clique sur RSIT.exe pour lancer l'outil.

    • Clique sur "Continue" à l'écran Disclaimer.

    • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

    et tu devras accepter la licence.

    • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

    Les rapports se trouvent à cet endroit:
    C:\rsit\info.txt
    C:\rsit\log.txt
    0
    1. voila ce que j'ai obtenu à mon premier nettoyage

      Malwarebytes' Anti-Malware 1.44
      Version de la base de données: 3575
      Windows 5.1.2600 Service Pack 3
      Internet Explorer 7.0.5730.13

      16/01/2010 13:11:05
      mbam-log-2010-01-16 (13-11-04).txt

      Type de recherche: Examen complet (C:\|)
      Eléments examinés: 188508
      Temps écoulé: 50 minute(s), 15 second(s)

      Processus mémoire infecté(s): 1
      Module(s) mémoire infecté(s): 1
      Clé(s) du Registre infectée(s): 7
      Valeur(s) du Registre infectée(s): 3
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 3
      Fichier(s) infecté(s): 14

      Processus mémoire infecté(s):
      C:\Documents and Settings\Utilisateur\Application Data\SystemProc\lsass.exe (Trojan.Inject) -> Unloaded process successfully.

      Module(s) mémoire infecté(s):
      C:\Documents and Settings\Utilisateur\Application Data\AntiVirus Plus\AntiVirus Plus.70700.dll (Trojan.FakeAlert) -> Delete on reboot.

      Clé(s) du Registre infectée(s):
      HKEY_CLASSES_ROOT\CLSID\{c2b5aab8-2183-4be7-81a6-f11493c45872} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c2b5aab8-2183-4be7-81a6-f11493c45872} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2b5aab8-2183-4be7-81a6-f11493c45872} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{4282125d-7529-973b-6ecb-6ba20bf39dcc} (Adware.BHO.AR) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4282125d-7529-973b-6ecb-6ba20bf39dcc} (Adware.BHO.AR) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4282125d-7529-973b-6ecb-6ba20bf39dcc} (Adware.BHO.AR) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\AppDataLow\HavingFunOnline (Adware.BHO.FL) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\rthdbpl (Trojan.Inject) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus plus (Rogue.AntivirusPlus) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus plus (Rogue.AntivirusPlus) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\AntiVirus Plus (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\AntiVirus Plus (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Utilisateur\Application Data\AntiVirus Plus (Rogue.AntiVirusPlus) -> Delete on reboot.

      Fichier(s) infecté(s):
      C:\Documents and Settings\Utilisateur\Application Data\SystemProc\lsass.exe (Trojan.Inject) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Utilisateur\Application Data\AntiVirus Plus\AntiVirus Plus.70700.dll (Trojan.FakeAlert) -> Delete on reboot.
      C:\Documents and Settings\Utilisateur\Local Settings\Temp\mxwsacnreo.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Utilisateur\Local Settings\Temp\Setup.tmp (Adware.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\-4b8Zl.dll (Adware.BHO.AR) -> Quarantined and deleted successfully.
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\AntiVirus Plus\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\AntiVirus Plus\EULA.url (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\AntiVirus Plus\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\AntiVirus Plus\EULA.url (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Utilisateur\Application Data\avp.ico (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Utilisateur\Bureau\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Utilisateur\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Démarrage\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.

      ensuite j'en ai fait un 2ème et voila les résultats

      Malwarebytes' Anti-Malware 1.44
      Version de la base de données: 3575
      Windows 5.1.2600 Service Pack 3
      Internet Explorer 7.0.5730.13

      16/01/2010 15:32:53
      mbam-log-2010-01-16 (15-32-53).txt

      Type de recherche: Examen rapide
      Eléments examinés: 105308
      Temps écoulé: 7 minute(s), 45 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 0

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      (Aucun élément nuisible détecté

      ensuite je reviens pour la suite !!!
      0
      1. et voici le premier rapport :

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by Utilisateur at 2010-01-16 16:45:53
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 35 GB (68%) free of 52 GB
        Total RAM: 1015 MB (46% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 16:46:42, on 16/01/2010
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16945)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\hkcmd.exe
        C:\WINDOWS\system32\igfxpers.exe
        C:\WINDOWS\system32\igfxsrvc.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\Program Files\Idesk\iDesk.exe
        C:\Program Files\acpiosd\acpiosd.exe
        C:\Program Files\Hercules\eCAFE CONNECT\eCAFE_CONNECT.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Skype\Phone\Skype.exe
        C:\Program Files\Bouygues\GlobeTrotter Connect\GlobeTrotter Connect.exe
        C:\Documents and Settings\Utilisateur\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Skype\Plugin Manager\skypePM.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\wbem\wmiapsrv.exe
        C:\Program Files\Windows Live\Toolbar\wltuser.exe
        C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
        C:\WINDOWS\system32\NOTEPAD.EXE
        C:\WINDOWS\system32\NOTEPAD.EXE
        C:\Documents and Settings\Utilisateur\Bureau\RSIT.exe
        C:\Program Files\trend micro\Utilisateur.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fdajo%3f
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: (no name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
        O1 - Hosts: 78.159.110.36 www.google.no
        O1 - Hosts: 78.159.110.36 www.google.com.mx
        O1 - Hosts: 78.159.110.36 www.google.co.za
        O1 - Hosts: 78.159.110.36 www.google.fi
        O1 - Hosts: 78.159.110.36 www.google.dk
        O1 - Hosts: 78.159.110.36 www.google.es
        O1 - Hosts: 78.159.110.36 www.google.se
        O1 - Hosts: 78.159.110.36 www.google.be
        O1 - Hosts: 78.159.110.36 www.google.com
        O1 - Hosts: 78.159.110.36 www.google.at
        O1 - Hosts: 78.159.110.36 www.google.it
        O1 - Hosts: 78.159.110.36 www.google.com.au
        O1 - Hosts: 78.159.110.36 search.yahoo.com
        O1 - Hosts: 78.159.110.36 www.google.com.br
        O1 - Hosts: 78.159.110.36 www.google.ca
        O1 - Hosts: 78.159.110.36 uk.search.yahoo.com
        O1 - Hosts: 78.159.110.36 www.google.ch
        O1 - Hosts: 78.159.110.36 www.google.pt
        O1 - Hosts: 78.159.110.36 www.google.gr
        O1 - Hosts: 78.159.110.36 www.google.de
        O1 - Hosts: 78.159.110.36 www.google.ie
        O1 - Hosts: 78.159.110.36 www.google.co.jp
        O1 - Hosts: 78.159.110.36 www.google.nl
        O1 - Hosts: 78.159.110.36 www.google.fr
        O1 - Hosts: 78.159.110.36 us.search.yahoo.com
        O1 - Hosts: 78.159.110.36 www.google.co.uk
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [iDesk] C:\Program Files\Idesk\iDesk.exe
        O4 - HKLM\..\Run: [ACPIOSD] C:\Program Files\acpiosd\acpiosd.exe
        O4 - HKLM\..\Run: [eConnect] "C:\Program Files\Hercules\eCAFE CONNECT\eCAFE_CONNECT.exe" -s
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
        O4 - HKLM\..\Run: [IMBooster] C:\Program Files\Iminent\IMBooster\IMBooster.exe /warmup
        O4 - HKLM\..\Run: [Iminent.Notifier] C:\Program Files\Iminent\SearchTheWeb\Iminent.Notifier.exe
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\Utilisateur\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
        O4 - Global Startup: GlobeTrotter Connect.lnk = C:\Program Files\Bouygues\GlobeTrotter Connect\GlobeTrotter Connect.exe
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe
        O23 - Service: Service Google Update (gupdate1c9d31aba8b2964) (gupdate1c9d31aba8b2964) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: HerculesWiFi - Unknown owner - C:\WINDOWS\system32\HerculesWiFiService.exe (file missing)
        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        0
        1. info.txt logfile of random's system information tool 1.06 2010-01-16 16:46:48

          ======Uninstall list======

          -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
          Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Reader 9.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A92000000001}
          Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
          Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
          Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
          Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
          avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
          Big City Adventure - New York City-->"C:\Program Files\WildGames\Big City Adventure - New York City\Uninstall.exe"
          Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
          CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
          Cérébral Challenge-->"C:\Program Files\Gameloft\Brain Challenge\unins000.exe"
          Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
          DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
          DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
          DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
          DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
          DivX Plus Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
          Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
          GlobeTrotter Connect-->MsiExec.exe /X{DDEB70E9-34C5-4DF3-8B39-85358859B049}
          Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
          Google Earth-->MsiExec.exe /X{C084BC61-E537-11DE-8616-005056806466}
          Hercules eCAFÉ CONNECT-->C:\Program Files\InstallShield Installation Information\{DECE22F4-EEDD-4615-BC56-2F4827FAD64B}\setup.exe -runfromtemp -l0x040c -removeonly
          Hercules eCAFÉ Webcam Station-->C:\Program Files\InstallShield Installation Information\{7D5206EB-50FF-4F79-9840-9334E5311182}\setup.exe -runfromtemp -l0x040c -removeonly
          HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
          Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
          HP Game Console-->"C:\Program Files\HP Games\HP Game Console\Uninstall.exe"
          HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
          Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
          Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
          iPuissance 4D-->C:\Program Files\iPuissance 4D\Uninst.exe
          iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
          Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
          Jeux WildTangent-->"C:\Program Files\WildGames\Uninstall.exe"
          Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
          Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
          LoudMo Contextual Ad Assistant-->C:\WINDOWS\system32\iY_g--Y4FK-um.exe
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
          Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
          Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
          Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
          Microsoft Bootvis-->MsiExec.exe /I{0F9196C6-58B4-445B-B56E-B1200FECC151}
          Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
          Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
          Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
          Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
          Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
          Microsoft Office Home and Student 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
          Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
          Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
          Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
          Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
          Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
          Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
          Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
          Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
          Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
          Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
          Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
          Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
          Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
          Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
          Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
          Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
          Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
          Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
          Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
          Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
          Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
          Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB974455)-->"C:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB976325)-->"C:\WINDOWS\ie7updates\KB976325-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
          Mise à jour pour Windows Internet Explorer 7 (KB976749)-->"C:\WINDOWS\ie7updates\KB976749-IE7\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
          Mystery Masterpiece - The Moonstone-->"C:\Program Files\HP Games\Mystery Masterpiece - The Moonstone\Uninstall.exe"
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
          REALTEK GbE & FE Ethernet PCI-E NIC Driver-->C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x040c -removeonly
          Realtek High Definition Audio Driver-->RtlUpd.exe -r -m -nrg2709
          Safari-->MsiExec.exe /I{E56D39F8-2A9F-44B4-B068-A72E45A073E6}
          Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
          Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
          Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
          Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
          Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
          Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
          Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
          Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
          Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
          Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
          Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
          Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
          Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
          Skype web features-->MsiExec.exe /I{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}
          Skype™ 4.1-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
          Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
          Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
          Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
          VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
          WildTangent ORB Game Console-->"C:\Program Files\WildGames\Game Console - WildGames\Uninstall.exe"
          Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
          Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
          Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
          Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
          Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
          Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
          Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
          Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
          Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"

          ======Hosts File======

          78.159.110.36 www.google.no
          78.159.110.36 www.google.com.mx
          78.159.110.36 www.google.co.za
          78.159.110.36 www.google.fi
          78.159.110.36 www.google.dk
          78.159.110.36 www.google.es
          78.159.110.36 www.google.se
          78.159.110.36 www.google.be
          78.159.110.36 www.google.com
          78.159.110.36 www.google.at

          ======Security center information======

          AV: avast! antivirus 4.8.1368 [VPS 100116-0]

          ======System event log======

          Computer Name: EC-900
          Event Code: 6006
          Message: Le service d'Enregistrement d'événement a été arrêté.

          Record Number: 1248
          Source Name: EventLog
          Time Written: 20091128004022.000000+060
          Event Type: Informations
          User:

          Computer Name: EC-900
          Event Code: 7036
          Message: Le service Carte de performance WMI est entré dans l'état : arrêté.

          Record Number: 1247
          Source Name: Service Control Manager
          Time Written: 20091128004005.000000+060
          Event Type: Informations
          User:

          Computer Name: EC-900
          Event Code: 21
          Message: Redémarrage nécessaire : pour terminer l'installation des mises à jour suivantes, l'ordinateur doit être redémarré. Tant que ce redémarrage n'aura pas eu lieu, Windows ne pourra pas rechercher ou télécharger de nouvelles mises à jour :
          - Mise à jour pour Windows XP (KB973687)
          - Mise à jour pour Windows XP (KB976098)

          Record Number: 1246
          Source Name: Windows Update Agent
          Time Written: 20091128003800.000000+060
          Event Type: Informations
          User:

          Computer Name: EC-900
          Event Code: 19
          Message: Installation réussie : Windows a installé la mise à jour suivante : Mise à jour pour Windows XP (KB976098)

          Record Number: 1245
          Source Name: Windows Update Agent
          Time Written: 20091128003800.000000+060
          Event Type: Informations
          User:

          Computer Name: EC-900
          Event Code: 4377
          Message: Le correctif Windows XP KB976098-v2 a été installé.

          Record Number: 1244
          Source Name: NtServicePack
          Time Written: 20091128003754.000000+060
          Event Type: Informations
          User: EC-900\Utilisateur

          =====Application event log=====

          Computer Name: EC-900
          Event Code: 0
          Message:
          Record Number: 985
          Source Name: gupdate1c9d31aba8b2964
          Time Written: 20090906215600.000000+120
          Event Type: Informations
          User:

          Computer Name: EC-900
          Event Code: 1
          Message:
          Record Number: 984
          Source Name: Bonjour Service
          Time Written: 20090906215558.000000+120
          Event Type: Informations
          User:

          Computer Name: EC-900
          Event Code: 0
          Message: Service started successfully.

          Record Number: 983
          Source Name: idsvc
          Time Written: 20090903113754.000000+120
          Event Type: Informations
          User:

          Computer Name: EC-900
          Event Code: 0
          Message: Service stopped successfully.

          Record Number: 982
          Source Name: idsvc
          Time Written: 20090903110709.000000+120
          Event Type: Informations
          User:

          Computer Name: EC-900
          Event Code: 518
          Message: The Windows CardSpace service has been idle for some time. It has been shut down to make resources available for other programs.

          Record Number: 981
          Source Name: CardSpace 3.0.0.0
          Time Written: 20090903110709.000000+120
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Fichiers communs\DivX Shared\;C:\Program Files\QuickTime\QTSystem\
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 28 Stepping 2, GenuineIntel
          "PROCESSOR_REVISION"=1c02
          "NUMBER_OF_PROCESSORS"=2
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
          "QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

          -----------------EOF-----------------

          et voila, j'espère que ca pourra aider, en tout cas, j'avoue que je n'y comprends pas grand chose
          merci
          0
          1. info.txt logfile of random's system information tool 1.06 2010-01-16 16:46:48

            ======Uninstall list======

            -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
            Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Reader 9.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A92000000001}
            Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
            Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
            Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
            Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
            avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
            Big City Adventure - New York City-->"C:\Program Files\WildGames\Big City Adventure - New York City\Uninstall.exe"
            Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
            CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
            Cérébral Challenge-->"C:\Program Files\Gameloft\Brain Challenge\unins000.exe"
            Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
            DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
            DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
            DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
            DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
            DivX Plus Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
            Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
            GlobeTrotter Connect-->MsiExec.exe /X{DDEB70E9-34C5-4DF3-8B39-85358859B049}
            Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
            Google Earth-->MsiExec.exe /X{C084BC61-E537-11DE-8616-005056806466}
            Hercules eCAFÉ CONNECT-->C:\Program Files\InstallShield Installation Information\{DECE22F4-EEDD-4615-BC56-2F4827FAD64B}\setup.exe -runfromtemp -l0x040c -removeonly
            Hercules eCAFÉ Webcam Station-->C:\Program Files\InstallShield Installation Information\{7D5206EB-50FF-4F79-9840-9334E5311182}\setup.exe -runfromtemp -l0x040c -removeonly
            HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
            Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
            HP Game Console-->"C:\Program Files\HP Games\HP Game Console\Uninstall.exe"
            HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
            Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
            Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
            Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
            iPuissance 4D-->C:\Program Files\iPuissance 4D\Uninst.exe
            iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
            Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
            Jeux WildTangent-->"C:\Program Files\WildGames\Uninstall.exe"
            Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
            Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
            LoudMo Contextual Ad Assistant-->C:\WINDOWS\system32\iY_g--Y4FK-um.exe
            Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
            Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
            Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
            Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
            Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
            Microsoft Bootvis-->MsiExec.exe /I{0F9196C6-58B4-445B-B56E-B1200FECC151}
            Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
            Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
            Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
            Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
            Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
            Microsoft Office Home and Student 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
            Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
            Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
            Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
            Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
            Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
            Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
            Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
            Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
            Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
            Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
            Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
            Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
            Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
            Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
            Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
            Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
            Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
            Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
            Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
            Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
            Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
            Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB974455)-->"C:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB976325)-->"C:\WINDOWS\ie7updates\KB976325-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
            Mise à jour pour Windows Internet Explorer 7 (KB976749)-->"C:\WINDOWS\ie7updates\KB976749-IE7\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
            MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
            Mystery Masterpiece - The Moonstone-->"C:\Program Files\HP Games\Mystery Masterpiece - The Moonstone\Uninstall.exe"
            Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
            QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
            REALTEK GbE & FE Ethernet PCI-E NIC Driver-->C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x040c -removeonly
            Realtek High Definition Audio Driver-->RtlUpd.exe -r -m -nrg2709
            Safari-->MsiExec.exe /I{E56D39F8-2A9F-44B4-B068-A72E45A073E6}
            Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
            Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
            Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
            Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
            Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
            Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
            Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
            Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
            Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
            Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
            Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
            Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
            Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
            Skype web features-->MsiExec.exe /I{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}
            Skype™ 4.1-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
            Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
            Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
            Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
            VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
            WildTangent ORB Game Console-->"C:\Program Files\WildGames\Game Console - WildGames\Uninstall.exe"
            Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
            Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
            Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
            Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
            Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
            Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
            Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
            Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
            Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
            Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
            Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
            Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"

            ======Hosts File======

            78.159.110.36 www.google.no
            78.159.110.36 www.google.com.mx
            78.159.110.36 www.google.co.za
            78.159.110.36 www.google.fi
            78.159.110.36 www.google.dk
            78.159.110.36 www.google.es
            78.159.110.36 www.google.se
            78.159.110.36 www.google.be
            78.159.110.36 www.google.com
            78.159.110.36 www.google.at

            ======Security center information======

            AV: avast! antivirus 4.8.1368 [VPS 100116-0]

            ======System event log======

            Computer Name: EC-900
            Event Code: 6006
            Message: Le service d'Enregistrement d'événement a été arrêté.

            Record Number: 1248
            Source Name: EventLog
            Time Written: 20091128004022.000000+060
            Event Type: Informations
            User:

            Computer Name: EC-900
            Event Code: 7036
            Message: Le service Carte de performance WMI est entré dans l'état : arrêté.

            Record Number: 1247
            Source Name: Service Control Manager
            Time Written: 20091128004005.000000+060
            Event Type: Informations
            User:

            Computer Name: EC-900
            Event Code: 21
            Message: Redémarrage nécessaire : pour terminer l'installation des mises à jour suivantes, l'ordinateur doit être redémarré. Tant que ce redémarrage n'aura pas eu lieu, Windows ne pourra pas rechercher ou télécharger de nouvelles mises à jour :
            - Mise à jour pour Windows XP (KB973687)
            - Mise à jour pour Windows XP (KB976098)

            Record Number: 1246
            Source Name: Windows Update Agent
            Time Written: 20091128003800.000000+060
            Event Type: Informations
            User:

            Computer Name: EC-900
            Event Code: 19
            Message: Installation réussie : Windows a installé la mise à jour suivante : Mise à jour pour Windows XP (KB976098)

            Record Number: 1245
            Source Name: Windows Update Agent
            Time Written: 20091128003800.000000+060
            Event Type: Informations
            User:

            Computer Name: EC-900
            Event Code: 4377
            Message: Le correctif Windows XP KB976098-v2 a été installé.

            Record Number: 1244
            Source Name: NtServicePack
            Time Written: 20091128003754.000000+060
            Event Type: Informations
            User: EC-900\Utilisateur

            =====Application event log=====

            Computer Name: EC-900
            Event Code: 0
            Message:
            Record Number: 985
            Source Name: gupdate1c9d31aba8b2964
            Time Written: 20090906215600.000000+120
            Event Type: Informations
            User:

            Computer Name: EC-900
            Event Code: 1
            Message:
            Record Number: 984
            Source Name: Bonjour Service
            Time Written: 20090906215558.000000+120
            Event Type: Informations
            User:

            Computer Name: EC-900
            Event Code: 0
            Message: Service started successfully.

            Record Number: 983
            Source Name: idsvc
            Time Written: 20090903113754.000000+120
            Event Type: Informations
            User:

            Computer Name: EC-900
            Event Code: 0
            Message: Service stopped successfully.

            Record Number: 982
            Source Name: idsvc
            Time Written: 20090903110709.000000+120
            Event Type: Informations
            User:

            Computer Name: EC-900
            Event Code: 518
            Message: The Windows CardSpace service has been idle for some time. It has been shut down to make resources available for other programs.

            Record Number: 981
            Source Name: CardSpace 3.0.0.0
            Time Written: 20090903110709.000000+120
            Event Type: Informations
            User: AUTORITE NT\SYSTEM

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Fichiers communs\DivX Shared\;C:\Program Files\QuickTime\QTSystem\
            "windir"=%SystemRoot%
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "PROCESSOR_ARCHITECTURE"=x86
            "PROCESSOR_LEVEL"=6
            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 28 Stepping 2, GenuineIntel
            "PROCESSOR_REVISION"=1c02
            "NUMBER_OF_PROCESSORS"=2
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
            "QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

            -----------------EOF-----------------

            et voila, j'espère que ca pourra aider, en tout cas, j'avoue que je n'y comprends pas grand chose
            merci
            0
            1. Contributeur sécurité
              ok

              dans cet ordre

              1)
              Télécharge HostsXpert sur ton Bureau :

              http://www.funkytoad.com/download/HostsXpert.zip

              ---> Décompresse-le (Clic droit >> Extraire ici)

              /!\Utilisateur de Vista : Clique droit sur le logo de HostsXpert, « exécuter en tant qu’Administrateur »

              ---> Double-clique sur HostsXpert pour le lancer , laisse travailler l’outil.

              ---> clique sur le bouton "Restore MS Hosts File" puis ferme le programme

              PS : Avant de cliquer sur le bouton "Restore MS Hosts File", vérifie que le cadenas en haut à gauche est ouvert sinon tu vas avoir un message d'erreur.
              .....

              2)

              Téléchargez USBFIX de Chiquitine29, C_xx

              http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
              ou
              https://www.ionos.fr/?affiliate_id=77097

              /!\ Utilisateur de vista et windows 7 :
              ne pas oublier de désactiver Le contrôle des comptes utilisateurs
              https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

              /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

              • Double clic sur le raccourci UsbFix présent sur le bureau .

              Choisir l'option2
              (d’autres options disponibles, voir le tutoriel).
              • Laissez travailler l'outil.
              Le menu démarrer et les icônes vont disparaître.. c'est normal.

              Si un message te demande de redémarrer l'ordinateur fais le ...

              ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

              ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

              • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

              ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

              • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
              Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

              • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

              UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

              Il est enregistré sur ton bureau.

              Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

              Merci

              .............

              3)Téléchargez et enregistrez le fichier d installation sur le bureau
              http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

              Double cliquez sur le fichier d'installation de AD-Remover, le programme s'installera automatiquement.
              Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"
              Au menu principal choisir Option L Lancer le nettoyage et tapez sur [entrée] .
              Laissez travailler l'outil et ne touchez à rien ...
              Postez le rapport qui apparait à la fin.

              ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

              (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

              Note :Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
              Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

              0
              1. ############################## | UsbFix V6.074 |

                User : Utilisateur (Administrateurs) # EC-900
                Update on 15/01/2010 by El Desaparecido , C_XX & Chimay8
                Start at: 17:17:56 | 16/01/2010
                Website : http://pagesperso-orange.fr/NosTools/index.html
                Contact : FindyKill.Contact@gmail.com

                Intel(R) Atom(TM) CPU N270 @ 1.60GHz
                Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                Internet Explorer 7.0.5730.13
                Windows Firewall Status : Enabled
                AV : avast! antivirus 4.8.1368 [VPS 100116-0] 4.8.1368 [ Enabled | Updated ]

                C:\ -> Disque fixe local # 50,53 Go (34,53 Go free) [Système] # NTFS

                ############################## | Processus actifs |

                C:\WINDOWS\System32\smss.exe 452
                C:\WINDOWS\system32\csrss.exe 500
                C:\WINDOWS\system32\winlogon.exe 524
                C:\WINDOWS\system32\services.exe 568
                C:\WINDOWS\system32\lsass.exe 580
                C:\WINDOWS\system32\svchost.exe 756
                C:\WINDOWS\system32\svchost.exe 804
                C:\WINDOWS\System32\svchost.exe 872
                C:\WINDOWS\system32\svchost.exe 932
                C:\WINDOWS\system32\svchost.exe 1008
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1028
                C:\Program Files\Alwil Software\Avast4\ashServ.exe 1076
                C:\WINDOWS\Explorer.EXE 1288
                C:\WINDOWS\system32\igfxpers.exe 1432
                C:\WINDOWS\system32\igfxsrvc.exe 1452
                C:\WINDOWS\RTHDCPL.EXE 1464
                C:\Program Files\Idesk\iDesk.exe 1492
                C:\Program Files\acpiosd\acpiosd.exe 1520
                C:\Program Files\Hercules\eCAFE CONNECT\eCAFE_CONNECT.exe 1536
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe 1556
                C:\Program Files\iTunes\iTunesHelper.exe 1672
                C:\WINDOWS\system32\ctfmon.exe 1680
                C:\Program Files\Messenger\msmsgs.exe 1692
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe 1700
                C:\Program Files\Skype\Phone\Skype.exe 1716
                C:\Program Files\Bouygues\GlobeTrotter Connect\GlobeTrotter Connect.exe 1844
                C:\Documents and Settings\Utilisateur\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe 1880
                C:\WINDOWS\system32\spoolsv.exe 432
                C:\WINDOWS\system32\svchost.exe 1764
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1580
                C:\Program Files\Bonjour\mDNSResponder.exe 1884
                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2056
                C:\WINDOWS\system32\svchost.exe 2244
                C:\Program Files\Skype\Plugin Manager\skypePM.exe 2488
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 3148
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 3172
                C:\Program Files\Internet Explorer\iexplore.exe 3224
                C:\Program Files\iPod\bin\iPodService.exe 3384
                C:\WINDOWS\system32\wbem\wmiapsrv.exe 3620
                C:\Program Files\Windows Live\Toolbar\wltuser.exe 3828
                C:\WINDOWS\System32\alg.exe 3968
                c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 2944
                C:\Documents and Settings\Utilisateur\Local Settings\Temporary Internet Files\Content.IE5\52FSY6U4\HostsXpert[1]\HostsXpert\HostsXpert.exe 1640
                C:\WINDOWS\system32\wbem\wmiprvse.exe 2608

                ################## | Elements infectieux |

                ################## | Registre |

                ################## | Mountpoints2 |

                HKCU\..\..\Explorer\MountPoints2\{c248c6f4-3f08-11de-9195-000df059bd56}
                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL NoLimit.exe

                HKCU\..\..\Explorer\MountPoints2\{c37c98d6-e310-11dd-850e-000df0501c0b}
                Shell\AutoRun\command =E:\setup.exe

                HKCU\..\..\Explorer\MountPoints2\{f32c4d58-565e-11de-91d5-000df059bd56}
                Shell\AutoRun\command =D:\setup.exe AUTORUN=1

                ################## | Cracks > Keygens > Serials |

                ################## | ! Fin du rapport # UsbFix V6.074 ! |
                0
                1. Contributeur sécurité
                  vu

                  tu peux enchainer...
                  0
                  1. .
                    ======= RAPPORT D'AD-REMOVER 1.1.4.6_H | UNIQUEMENT XP/VISTA/7 =======
                    .
                    Mis à jour par C_XX le 16.01.2010 à 11:37
                    Contact: AdRemover.contact@gmail.com
                    Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                    .
                    Lancé à: 17:25:28, 16/01/2010 | Mode Normal | Option: CLEAN
                    Exécuté de: C:\Ad-Remover\
                    Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                    Nom du PC: EC-900 | Utilisateur actuel: Utilisateur
                    .
                    ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                    .

                    C:\WINDOWS\Installer\{E1B94435-241E-4519-B1C3-C4DD9EB352A2}
                    C:\Program Files\Kiwee Toolbar
                    C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Iminent
                    C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Kiwee Toolbar
                    C:\Documents and Settings\LocalService\Application Data\agi

                    (!) -- Fichiers temporaires supprimés.

                    .
                    HKCU\software\Iminent
                    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
                    HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847} ... [b]ERREUR SUPPRESSION !!/b
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
                    HKCU\software\SweetIM
                    HKLM\software\Iminent
                    HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchTheWeb
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\IMBooster
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Iminent.Notifier
                    HKLM\software\SweetIM
                    .
                    ============== Scan additionnel ==============
                    .
                    .
                    * Mozilla FireFox Version [Impossible d'obtenir la version] *
                    .
                    Nom du profil: lgv68x2o.default (Utilisateur)
                    .
                    (UTILIS~1, prefs.js) Browser.download.lastDir, C:\Documents and Settings\Utilisateur\Bureau
                    (UTILIS~1, prefs.js) Browser.search.defaultenginename, MyStart Rechercher
                    (UTILIS~1, prefs.js) Browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2032792&SearchSource=3&q=
                    (UTILIS~1, prefs.js) Browser.search.selectedEngine, Google
                    (UTILIS~1, prefs.js) Browser.startup.homepage, hxxp://fr.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
                    (UTILIS~1, prefs.js) Extensions.enabledItems, {20a82645-c095-46ed-80e3-08825760534b}:1.1,{B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3789,{8CE11043-9A15-4207-A565-0C94C42D590D}:1.0,{35296b0e-9c86-e1f8-2bc5-528badd28392}:4.6.6.2,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.6
                    (UTILIS~1, prefs.js) Keyword.URL, hxxp://mystart.hiyo.com/?loc=ff_address&search=
                    (UTILIS~1, prefs.js) Privacy.popups.showBrowserMessage, false
                    .
                    (UTILIS~1, prefs.js) EFFACE - Browser.search.defaultthis.engineName, iminent-en Customized Web Search
                    .
                    .
                    .
                    * Internet Explorer Version 7.0.5730.13 *
                    .
                    [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                    .
                    Do404Search: 01000000
                    Local Page: C:\WINDOWS\system32\blank.htm
                    Show_ToolBar: yes
                    Start Page: hxxp://fr.msn.com/
                    Enable Browser Extensions: yes
                    Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                    SearchAssistant:
                    Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    .
                    [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                    .
                    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Delete_Temp_Files_On_Exit: yes
                    Local Page: %SystemRoot%\system32\blank.htm
                    Start Page: hxxp://fr.msn.com/
                    Search bar: hxxp://search.msn.com/spbasic.htm
                    .
                    [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                    .
                    Tabs: res://ieframe.dll/tabswelcome.htm
                    .
                    ===================================
                    .
                    3893 Octet(s) - C:\Ad-Report-CLEAN[1].log
                    .
                    48 Fichier(s) - C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp
                    5 Fichier(s) - C:\WINDOWS\Temp
                    8 Fichier(s) - C:\WINDOWS\Prefetch
                    .
                    19 Fichier(s) - C:\Ad-Remover\BACKUP
                    13 Fichier(s) - C:\Ad-Remover\QUARANTINE
                    .
                    Fin à: 17:29:06 | 16/01/2010 - CLEAN[1]
                    .
                    ============== E.O.F ==============
                    .
                    0
                    1. Contributeur sécurité
                      ca devrait aller mieux maintenant ?

                      relances RSIT et postes juste le rapport log stp
                      0
                      1. ok

                        Logfile of random's system information tool 1.06 (written by random/random)
                        Run by Utilisateur at 2010-01-16 17:37:00
                        Microsoft Windows XP Édition familiale Service Pack 3
                        System drive C: has 35 GB (68%) free of 52 GB
                        Total RAM: 1015 MB (45% free)

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 17:37:10, on 16/01/2010
                        Platform: Windows XP SP3 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16945)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\WINDOWS\system32\hkcmd.exe
                        C:\WINDOWS\system32\igfxpers.exe
                        C:\WINDOWS\system32\igfxsrvc.exe
                        C:\WINDOWS\RTHDCPL.EXE
                        C:\Program Files\Idesk\iDesk.exe
                        C:\Program Files\acpiosd\acpiosd.exe
                        C:\Program Files\Hercules\eCAFE CONNECT\eCAFE_CONNECT.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\Skype\Phone\Skype.exe
                        C:\Program Files\Bouygues\GlobeTrotter Connect\GlobeTrotter Connect.exe
                        C:\Documents and Settings\Utilisateur\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\Program Files\Skype\Plugin Manager\skypePM.exe
                        C:\WINDOWS\system32\wbem\wmiapsrv.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Windows Live\Toolbar\wltuser.exe
                        c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
                        C:\Documents and Settings\Utilisateur\Bureau\RSIT.exe
                        C:\Program Files\trend micro\Utilisateur.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - Default URLSearchHook is missing
                        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                        O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                        O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                        O4 - HKLM\..\Run: [iDesk] C:\Program Files\Idesk\iDesk.exe
                        O4 - HKLM\..\Run: [ACPIOSD] C:\Program Files\acpiosd\acpiosd.exe
                        O4 - HKLM\..\Run: [eConnect] "C:\Program Files\Hercules\eCAFE CONNECT\eCAFE_CONNECT.exe" -s
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\Utilisateur\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                        O4 - Global Startup: GlobeTrotter Connect.lnk = C:\Program Files\Bouygues\GlobeTrotter Connect\GlobeTrotter Connect.exe
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                        O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe
                        O23 - Service: Service Google Update (gupdate1c9d31aba8b2964) (gupdate1c9d31aba8b2964) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                        O23 - Service: HerculesWiFi - Unknown owner - C:\WINDOWS\system32\HerculesWiFiService.exe (file missing)
                        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        0
                        1. Contributeur sécurité
                          encore ennuyée avec internet ?

                          un petit dernier

                          Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                          ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
                          http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe
                          double clique ( clic droit "executer en tant qu'administrateur" pour Vista/Seven ) sur le raccourci sur ton bureau pour lancer l'installation

                          coche la case "creer une icone sur le bureau"

                          une fois terminée , clic sur "terminer" et le programme se lancer seul

                          choisis la langue puis choisis l'option 1 = Mode Recherche

                          ▶ laisse travailler l'outil

                          à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                          un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                          ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                          tu peux supprimer le rapport catchme.log de ton bureau maintenant.

                          0
                          1. ca a l'air de fonctionner correctement, je fais la derniere manip ...
                            0
                            1. List'em by g3n-h@ckm@n 1.1.8.3

                              Thx to El Desaparecido.....& CCM team

                              User : Utilisateur (Administrateurs)
                              Update on 14/01/2010 by g3n-h@ckm@n ::::: 18:30
                              Start at: 17:57:31 | 16/01/2010
                              Contact : g3n-h@ckm@n sur CCM

                              Intel(R) Atom(TM) CPU N270 @ 1.60GHz
                              Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                              Internet Explorer 7.0.5730.13
                              Windows Firewall Status : Enabled
                              AV : avast! antivirus 4.8.1368 [VPS 100116-0] 4.8.1368 [ (!) Disabled | Updated ]

                              C:\ -> Disque fixe local | 50,53 Go (34,56 Go free) [Système] | NTFS

                              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\alg.exe
                              C:\WINDOWS\system32\hkcmd.exe
                              C:\WINDOWS\system32\igfxpers.exe
                              C:\WINDOWS\system32\igfxsrvc.exe
                              C:\WINDOWS\RTHDCPL.EXE
                              C:\Program Files\Idesk\iDesk.exe
                              C:\Program Files\acpiosd\acpiosd.exe
                              C:\Program Files\Hercules\eCAFE CONNECT\eCAFE_CONNECT.exe
                              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Messenger\msmsgs.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\Skype\Phone\Skype.exe
                              C:\Program Files\Bouygues\GlobeTrotter Connect\GlobeTrotter Connect.exe
                              C:\Documents and Settings\Utilisateur\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\Program Files\Skype\Plugin Manager\skypePM.exe
                              C:\WINDOWS\system32\wbem\wmiapsrv.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Windows Live\Toolbar\wltuser.exe
                              c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\Program Files\List_Kill'em\List_Kill'em.exe
                              C:\WINDOWS\system32\cmd.exe
                              C:\WINDOWS\system32\wbem\wmiprvse.exe
                              C:\Documents and Settings\Utilisateur\Local Settings\Temp\C.tmp\pv.exe

                              ======================
                              Keys "Run"
                              ======================
                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
                              MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background
                              msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              Skype REG_SZ "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              HotKeysCmds REG_SZ C:\WINDOWS\system32\hkcmd.exe
                              Persistence REG_SZ C:\WINDOWS\system32\igfxpers.exe
                              RTHDCPL REG_SZ RTHDCPL.EXE
                              Alcmtr REG_SZ ALCMTR.EXE
                              iDesk REG_SZ C:\Program Files\Idesk\iDesk.exe
                              ACPIOSD REG_SZ C:\Program Files\acpiosd\acpiosd.exe
                              eConnect REG_SZ "C:\Program Files\Hercules\eCAFE CONNECT\eCAFE_CONNECT.exe" -s
                              avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              fssui REG_SZ "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                              KernelFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -k
                              Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              Adobe ARM REG_SZ "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
                              QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                              =====================
                              Other Keys
                              =====================
                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                              dontdisplaylastusername REG_DWORD 0 (0x0)
                              legalnoticecaption REG_SZ
                              legalnoticetext REG_SZ
                              shutdownwithoutlogon REG_DWORD 1 (0x1)
                              undockwithoutlogon REG_DWORD 1 (0x1)

                              ===============
                              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                              NoDriveTypeAutoRun REG_DWORD 145 (0x91)

                              ===============
                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                              HonorAutoRunSetting REG_DWORD 1 (0x1)

                              ===============
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                              AppInit_DLLS REG_SZ

                              ===============
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                              ===============
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                              {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                              ===============
                              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                              %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                              %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                              C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote
                              C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
                              C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                              C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                              C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
                              C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype

                              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                              %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                              %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                              C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                              C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare

                              ===============
                              ActivX controls
                              ===============
                              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}

                              ===============
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73fa19d0-2d75-11d2-995d-00c04f98bbc9}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                              ==============
                              BHO :
                              ======
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

                              ================
                              Internet Explorer :
                              ================
                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                              Start Page REG_SZ https://www.msn.com/fr-fr

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                              Start Page REG_SZ https://www.google.fr/?gws_rd=ssl

                              ========
                              Services
                              ========
                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                              Ndisuio : 0x3
                              EapHost : 0x3
                              SharedAccess : 0x2
                              wuauserv : 0x2

                              =========

                              =======
                              Drive :
                              =======

                              D‚fragmenteur de disque Windows
                              Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                              Rapport d'analyse
                              50,53 Go total, 34,59 Go libre (68%), 5% fragment‚ (fragmentation du fichier 10%)

                              Il ne vous est pas n‚cessaire de d‚fragmenter ce volume.

                              ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                              C:\WINDOWS\System32\drivers\etc\hosts.msn

                              ¤¤¤¤¤¤¤¤¤¤ Keys :

                              "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                              "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"

                              ================
                              Other infections
                              ================

                              catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2010-01-16 18:05:49
                              Windows 5.1.2600 Service Pack 3 NTFS

                              scanning hidden processes ...

                              scanning hidden services & system hive ...

                              scanning hidden registry entries ...

                              scanning hidden files ...

                              scan completed successfully
                              hidden processes: 0
                              hidden services: 0
                              hidden files: 0

                              Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                              device: opened successfully
                              user: MBR read successfully
                              kernel: MBR read successfully
                              user & kernel MBR OK

                              ==========
                              Programs
                              ==========

                              acpiosd
                              Adobe
                              Alwil Software
                              Apple Software Update
                              Bonjour
                              Bouygues
                              CCleaner
                              Chess
                              ComPlus Applications
                              Conduit
                              DivX
                              eCAFE_WebRadio
                              FFT
                              Fichiers communs
                              Gameloft
                              Google
                              GTris
                              Hercules
                              HP Games
                              Idesk
                              Incredijeux
                              InstallShield Installation Information
                              Intel
                              Internet Explorer
                              iPod
                              iPuissance 4D
                              iTunes
                              Java
                              List_Kill'em
                              Malwarebytes' Anti-Malware
                              Messenger
                              Microsoft
                              Microsoft Bootvis
                              microsoft frontpage
                              Microsoft Office
                              Microsoft Silverlight
                              Microsoft SQL Server Compact Edition
                              Microsoft Sync Framework
                              Microsoft Works
                              Microsoft.NET
                              Movie Maker
                              Mozilla Firefox
                              MSBuild
                              MSN
                              MSN Gaming Zone
                              NetMeeting
                              Oberon Media
                              OpenOffice.org 3
                              Outlook Express
                              QuickTime
                              Realtek
                              Reference Assemblies
                              Safari
                              Services en ligne
                              Skype
                              Sudoku3D
                              trend micro
                              Uninstall Information
                              WildGames
                              Windows Live
                              Windows Live SkyDrive
                              Windows Media Connect 2
                              Windows Media Player
                              Windows NT
                              WindowsUpdate
                              xerox

                              ============
                              Lecteur C:
                              ============

                              $RECYCLE.BIN
                              6c72b725e0201aaecb66129694
                              Ad-Remover
                              Ad-Report-CLEAN[1].log
                              AUTOEXEC.BAT
                              Avenger
                              BOOT.BAK
                              boot.ini
                              Bootfont.bin
                              BOOTSECT.DAT
                              cmdcons
                              cmldr
                              CONFIG.SYS
                              Documents and Settings
                              I386
                              Install
                              Intel
                              IO.SYS
                              Kill'em
                              List'em.txt
                              minint
                              MSDOS.SYS
                              MSOCache
                              NTDETECT.COM
                              ntldr
                              pagefile.sys
                              Program Files
                              RECYCLER
                              rsit
                              System Volume Information
                              UsbFix
                              UsbFix.txt
                              WINDOWS

                              ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                              0
                              1. Contributeur sécurité
                                ▶ Relance List&Kill'em (clic droit "exécuter en tant qu'administrateur" pour Vista/Seven) avec le raccourci sur ton bureau ,

                                mais cette fois-ci :

                                ▶ choisis l'option 2 = Mode Suppression

                                laisse travailler l'outil.

                                en fin de scan un rapport s'ouvre

                                ▶ colle le contenu dans ta reponse

                                ...................

                                apres ca ton pc est à priori ok

                                je te posterai ce soir ou demain matin (de chez moi, d'où je suis il me manque mes outils) une procédure de nettoyage
                                0
                                1. ok en tout cas, merci beaucoup !!!!
                                  0
                                  1. Kill'em by g3n-h@ckm@n 1.1.8.3

                                    User : Utilisateur (Administrateurs)
                                    Update on 14/01/2010 by g3n-h@ckm@n ::::: 18:30
                                    Start at: 18:18:56 | 16/01/2010
                                    Contact : g3n-h@ckm@n sur CCM

                                    Intel(R) Atom(TM) CPU N270 @ 1.60GHz
                                    Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                    Internet Explorer 7.0.5730.13
                                    Windows Firewall Status : Disabled
                                    AV : avast! antivirus 4.8.1368 [VPS 100116-0] 4.8.1368 [ (!) Disabled | Updated ]

                                    C:\ -> Disque fixe local | 50,53 Go (34,56 Go free) [Système] | NTFS

                                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\csrss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    C:\Program Files\Bonjour\mDNSResponder.exe
                                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\alg.exe
                                    C:\WINDOWS\system32\hkcmd.exe
                                    C:\WINDOWS\system32\igfxpers.exe
                                    C:\WINDOWS\system32\igfxsrvc.exe
                                    C:\WINDOWS\RTHDCPL.EXE
                                    C:\Program Files\Idesk\iDesk.exe
                                    C:\Program Files\acpiosd\acpiosd.exe
                                    C:\Program Files\Hercules\eCAFE CONNECT\eCAFE_CONNECT.exe
                                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    C:\Program Files\iTunes\iTunesHelper.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\Messenger\msmsgs.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Program Files\Skype\Phone\Skype.exe
                                    C:\Program Files\Bouygues\GlobeTrotter Connect\GlobeTrotter Connect.exe
                                    C:\Documents and Settings\Utilisateur\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                                    C:\Program Files\iPod\bin\iPodService.exe
                                    C:\Program Files\Skype\Plugin Manager\skypePM.exe
                                    C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Windows Live\Toolbar\wltuser.exe
                                    c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
                                    C:\WINDOWS\system32\rundll32.exe
                                    C:\Program Files\List_Kill'em\List_Kill'em.exe
                                    C:\WINDOWS\system32\cmd.exe
                                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                                    C:\Documents and Settings\Utilisateur\Local Settings\Temp\E.tmp\pv.exe

                                    Detections :
                                    ==========

                                    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                    Quaranteend & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn

                                    ==============
                                    host file OK !
                                    ==============

                                    ========
                                    Registry
                                    ========
                                    Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe
                                    Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe

                                    ============
                                    Disk Cleaned
                                    ============

                                    ================
                                    Prefetch cleaned
                                    ================

                                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                                    0
                                    1. Contributeur sécurité
                                      pas nettoyage ce soir

                                      USBFIX a été passé en option 1 au lieu de la 2

                                      ● Relance UsbFix

                                      ● Dans le menu principale cette fois choisit l'option2

                                      Le menu démarrer et les icônes vont à nouveau disparaître.. c'est normal.

                                      Si un message te demande de redémarrer l'ordinateur fais le ...

                                      ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

                                      ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

                                      UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

                                      Il est enregistré sur ton bureau.

                                      Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

                                      Merci

                                      ....................

                                      également en reste un cache que MBAM aurait dû attraper

                                      Lances MalwareByte's Anti-Malware
                                      . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                                      . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
                                      . Une fois la mise à jour terminé
                                      . Rend-toi dans l'onglet, Recherche
                                      . Sélectionnes Exécuter un examen complet
                                      . Cliques sur Rechercher
                                      . Le scan démarre.
                                      . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                                      . Cliques sur Ok pour poursuivre.
                                      . Si des malwares ont été détectés, clique sur Afficher les résultats
                                      . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                                      . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                                      . Rends toi dans l'onglet rapport/log
                                      . Tu cliques dessus pour l'afficher, une fois affiché
                                      . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
                                      . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                                      . tu cliques droit dans le cadre de la reponse et coller

                                      Si tu as besoin d'aide regarde ces tutoriels :
                                      Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                                      http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

                                      0
                                      1. ok

                                        ############################## | UsbFix V6.074 |

                                        User : Utilisateur (Administrateurs) # EC-900
                                        Update on 15/01/2010 by El Desaparecido , C_XX & Chimay8
                                        Start at: 23:41:20 | 16/01/2010
                                        Website : http://pagesperso-orange.fr/NosTools/index.html
                                        Contact : FindyKill.Contact@gmail.com

                                        Intel(R) Atom(TM) CPU N270 @ 1.60GHz
                                        Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                        Internet Explorer 7.0.5730.13
                                        Windows Firewall Status : Enabled
                                        AV : avast! antivirus 4.8.1368 [VPS 100116-0] 4.8.1368 [ Enabled | Updated ]

                                        C:\ -> Disque fixe local # 50,53 Go (34,55 Go free) [Système] # NTFS

                                        ############################## | Processus actifs |

                                        C:\WINDOWS\System32\smss.exe 448
                                        C:\WINDOWS\system32\csrss.exe 500
                                        C:\WINDOWS\system32\winlogon.exe 528
                                        C:\WINDOWS\system32\services.exe 572
                                        C:\WINDOWS\system32\lsass.exe 584
                                        C:\WINDOWS\system32\svchost.exe 760
                                        C:\WINDOWS\system32\svchost.exe 824
                                        C:\WINDOWS\System32\svchost.exe 908
                                        C:\WINDOWS\system32\svchost.exe 976
                                        C:\WINDOWS\system32\svchost.exe 1084
                                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1108
                                        C:\Program Files\Alwil Software\Avast4\ashServ.exe 1168
                                        C:\WINDOWS\Explorer.EXE 1300
                                        C:\WINDOWS\system32\spoolsv.exe 1676
                                        C:\Program Files\Alwil Software\Avast4\setup\avast.setup 1692
                                        C:\WINDOWS\system32\svchost.exe 896
                                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 984
                                        C:\Program Files\Bonjour\mDNSResponder.exe 1000
                                        C:\Program Files\Google\Update\GoogleUpdate.exe 1064
                                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 1352
                                        C:\WINDOWS\system32\svchost.exe 1784
                                        C:\WINDOWS\system32\wuauclt.exe 2008
                                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 156
                                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 228
                                        C:\WINDOWS\System32\alg.exe 2068
                                        C:\WINDOWS\system32\wbem\wmiprvse.exe 2152

                                        ################## | Elements infectieux |

                                        Supprimé ! C:\$Recycle.Bin\S-1-5-21-2927205761-3241211063-1412961460-1000
                                        Supprimé ! C:\$Recycle.Bin\S-1-5-21-725345543-1644491937-2146829589-4545
                                        Supprimé ! C:\Recycler\S-1-5-21-1117423691-257026972-1517896382-1005
                                        Supprimé ! C:\Recycler\S-1-5-21-1741909875-3725559198-897148257-1005
                                        Supprimé ! C:\Recycler\S-1-5-21-1759062537-3657687911-126783224-1016
                                        Supprimé ! C:\Recycler\S-1-5-21-1796079445-3559988837-2502578843-1005
                                        Supprimé ! C:\Recycler\S-1-5-21-1930751373-2264955443-3438463612-1016
                                        Supprimé ! C:\Recycler\S-1-5-21-2690257717-2165553054-1184112195-1016
                                        Supprimé ! C:\Recycler\S-1-5-21-2733139425-3706711456-1893861947-1016
                                        Supprimé ! C:\Recycler\S-1-5-21-3367461445-465511453-1693789023-1016
                                        Supprimé ! C:\Recycler\S-1-5-21-3565301792-516909588-1905422501-1005
                                        Supprimé ! C:\Recycler\S-1-5-21-3569639492-1459788040-3674529797-1016
                                        Supprimé ! C:\Recycler\S-1-5-21-4148742737-647566383-4164866851-1005
                                        Supprimé ! C:\Recycler\S-1-5-21-4160571827-3887858823-1751089855-1016
                                        Supprimé ! C:\Recycler\S-1-5-21-4281131894-2058245212-2894927741-1005
                                        Supprimé ! C:\Recycler\S-1-5-21-448539723-1390067357-299502267-1003
                                        Supprimé ! C:\Recycler\S-1-5-21-527545453-310131232-1425393842-1005
                                        Supprimé ! C:\Recycler\S-1-5-21-53844827-887924898-2035372866-1016
                                        Supprimé ! C:\Recycler\S-1-5-21-646300841-2386647206-2214244849-1016
                                        Supprimé ! C:\Recycler\S-1-5-21-725345543-1644491937-2146829589-4514
                                        Supprimé ! C:\Recycler\S-1-5-21-785388120-4213088088-2760757481-1005
                                        Supprimé ! C:\Recycler\S-1-5-21-821095657-1864731330-1189076455-1005
                                        Supprimé ! C:\Recycler\S-1-5-21-954308910-3426076957-609612491-1005

                                        ################## | Registre |

                                        ################## | Mountpoints2 |

                                        Supprimé ! HKCU\...\Explorer\MountPoints2\{c248c6f4-3f08-11de-9195-000df059bd56}\Shell\AutoRun\Command
                                        Supprimé ! HKCU\...\Explorer\MountPoints2\{c37c98d6-e310-11dd-850e-000df0501c0b}\Shell\AutoRun\Command
                                        Supprimé ! HKCU\...\Explorer\MountPoints2\{f32c4d58-565e-11de-91d5-000df059bd56}\Shell\AutoRun\Command

                                        ################## | Listing des fichiers présent |

                                        [16/01/2010 17:29|--a------|4233] C:\Ad-Report-CLEAN[1].log
                                        [16/01/2010 23:36|--a------|4] C:\AUTOEXEC.BAT
                                        [13/01/2009 15:55|--ahs----|216] C:\BOOT.BAK
                                        [15/01/2009 10:24|-rah-----|258] C:\boot.ini
                                        [14/04/2008 13:00|-rahs----|4952] C:\Bootfont.bin
                                        [13/01/2009 20:21|-rah-----|8192] C:\BOOTSECT.DAT
                                        [14/04/2008 13:00|-rahs----|263504] C:\cmldr
                                        [22/12/2008 17:48|--a------|0] C:\CONFIG.SYS
                                        [22/12/2008 17:48|-rahs----|0] C:\IO.SYS
                                        [16/01/2010 23:36|--a------|2870] C:\Kill'em.txt
                                        [16/01/2010 18:12|--a------|17729] C:\List'em.txt
                                        [22/12/2008 17:48|-rahs----|0] C:\MSDOS.SYS
                                        [14/04/2008 13:00|-rahs----|47564] C:\NTDETECT.COM
                                        [14/04/2008 13:00|-rahs----|252240] C:\ntldr
                                        [?|?|?] C:\pagefile.sys
                                        [16/01/2010 23:44|--a------|4749] C:\UsbFix.txt

                                        ################## | Vaccination |

                                        # C:\autorun.inf -> Dossier créé par UsbFix.

                                        ################## | Crack > Keygen > Serial |
                                        0
                                        1. Malwarebytes' Anti-Malware 1.44
                                          Version de la base de données: 3580
                                          Windows 5.1.2600 Service Pack 3
                                          Internet Explorer 7.0.5730.13

                                          17/01/2010 00:42:57
                                          mbam-log-2010-01-17 (00-42-57).txt

                                          Type de recherche: Examen complet (C:\|)
                                          Eléments examinés: 184756
                                          Temps écoulé: 53 minute(s), 27 second(s)

                                          Processus mémoire infecté(s): 0
                                          Module(s) mémoire infecté(s): 0
                                          Clé(s) du Registre infectée(s): 0
                                          Valeur(s) du Registre infectée(s): 0
                                          Elément(s) de données du Registre infecté(s): 0
                                          Dossier(s) infecté(s): 0
                                          Fichier(s) infecté(s): 0

                                          Processus mémoire infecté(s):
                                          (Aucun élément nuisible détecté)

                                          Module(s) mémoire infecté(s):
                                          (Aucun élément nuisible détecté)

                                          Clé(s) du Registre infectée(s):
                                          (Aucun élément nuisible détecté)

                                          Valeur(s) du Registre infectée(s):
                                          (Aucun élément nuisible détecté)

                                          Elément(s) de données du Registre infecté(s):
                                          (Aucun élément nuisible détecté)

                                          Dossier(s) infecté(s):
                                          (Aucun élément nuisible détecté)

                                          Fichier(s) infecté(s):
                                          (Aucun élément nuisible détecté)
                                          0
                                          • 1
                                          • 2