Gros problème sous vista

Bonjour,
voilà je me tourne vers vous en dernier recours.

Je possède un PC portable acer aspire sous windows vista, il fonctionnait sans problèmes importants depuis un an mais voilà :
Tout à l'heure j'ai essayé de l'allumer, il y a eu un écran noir et l'ordinateur a apparemment vérifié un disque. L'ordi a ensuite démarré, je croyais être sorti d'affaire mais :

- D'abord il y a plusieurs messages de .exe qui ne veulent pas démarrer.

- Il y a également le centre de sécurité qui refuse de se lancer. J'ai essayé d'aller dans services, il n'était pas désactivé mais arrêté et on ne peut pas le démarrer car il y a une erreur 1068 me semble t-il.

-L'antivirus (antivir) est désactivé et je ne peux pas le réactiver.

Bref je ne sais plus quoi faire je me tourne donc vers vous, merci d'avance à ceux qui sauront apporter des solutions à mes problèmes.
Configuration: Windows Vista
Firefox 3.5.7

65 réponses

Résumé de la discussion

Un utilisateur sur Windows Vista rencontre un écran noir au démarrage, des erreurs d'exécution de fichiers .exe et le centre de sécurité qui ne démarre pas, avec une erreur 1068 sur les services. Plusieurs réponses recommandent de lancer CHKDSK pour vérifier l’intégrité du disque et éventuellement effectuer une restauration système si le registre a été modifié, ou d’envisager une réparation du système. D'autres propositions évoquent des outils de désinfection et de détection de rootkits, tels que GMER, ComboFix ou ZHPDiag, puis l’analyse des rapports pour orienter la suite des interventions. En complément, certaines méthodes préconisent d’utiliser les outils de restauration fournis par la machine plutôt que le formatage, pour éviter de supprimer l’OS et préserver les données.

Bobot (l’IA à votre service)
  1. Démarrer/exécuter/cmd puis tapez : chkdsk /f /r
    0
    1. Execute l'outil chkdsk
      Si t'a fais une manip involontaire il se peut que le registre eut été modifié donc une petite restauration du systeme serait la bienvenue
      0
      1. Il n y a aucun point de restauration disponible.
        0
    2. Je l'ai fait et ça me marque : Accès refusé, vous n'avez pas de privilèges suffisants. Vous devez invoquer cet utilitaire dans un mode d'exécution élevé. Merci vous t'intéresser à mon cas.
      0
      1. Excusez moi du double post, mais j'ai trouvé et donc chk dsk a en fait déjà exécuté c'était ce que je décrivais maladroitement dans le message d'origine, je vais également essayer de restaurer.
        0
    3. démarrer/tous les programmes/accessoires/invites de commandes ( avec le clic droit pour être administrateur ) puis : chkdsk /f /r
      0
      1. Contributeur sécurité
        bonsoir

        ton pc est un 32 ou 64 bits ?
        0
        1. C'est un 32 bits pourquoi ?
          0
      2. Contributeur sécurité
        pour la suite...
        • Téléchargez FindyKill sur le Bureau.

        http://pagesperso-orange.fr/NosTools/Chiquitine29/Setup.exe

        Mirroir :

        http://findykill.changelog.fr/Setup.exe

        • Double-cliquez sur FindyKill présent sur le Bureau.

        • Choisissez l'option 1 (Recherche).

        • Laissez travailler l'outil.

        • Ensuite postez le rapport FindyKill.txt qui apparaîtra (si vous avez créé un sujet sur un forum pour vous faire aider).

        • Note : Le rapport FindyKill.txt est sauvegardé à la racine du disque (C:\FindyKill.txt).

        (CTRL+A pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller)

        • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

        • Tuto : http://pagesperso-orange.fr/NosTools/index.html

        0
        1. Bonjour, excuse moi pour le temps que j'ai mis à répondre. Malgré plusieurs messages d'erreur au lancement de la recherche (des erreurs de dll), l'outil a fini de travailler et voilà le rapport :

          ############################## | FindyKill V5.032 |

          # User : Annick (Administrateurs) # PC-DE-ANNICK
          # Update on 03/02/2010 by El Desaparecido
          # Start at: 14:36:43 | 06/02/2010
          # Website : http://pagesperso-orange.fr/NosTools/index.html
          # Contact : FindyKill.Contact@gmail.com

          #
          #
          # Internet Explorer 8.0.6001.18882
          # Windows Firewall Status : Enabled

          ############################## | Processus actifs |

          C:\Windows\System32\smss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\Ati2evxx.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\vfsFPService.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\WLANExt.exe
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\Ati2evxx.exe
          C:\Program Files\Avira\AntiVir Desktop\sched.exe
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\a-squared Free\a2service.exe
          C:\Windows\system32\agrsmsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
          C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
          C:\Windows\system32\taskeng.exe
          C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
          C:\Program Files\Intel\WiFi\bin\EvtEng.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
          C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Acer\Mobility Center\MobilityService.exe
          C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
          C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
          C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Cyberlink\Shared files\RichVideo.exe
          C:\Program Files\Acer\Acer VCM\RS_Service.exe
          C:\Windows\PLFSetI.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Users\Annick\AppData\Local\Temp\RtkBtMnt.exe
          C:\Program Files\Launch Manager\LManager.exe
          C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
          C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Windows\ehome\ehtray.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\Micro Application\LauncherMA.exe
          C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
          C:\Windows\servicing\TrustedInstaller.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Windows\system32\conime.exe

          ################## | C: |

          F:\autorun.inf

          ################## | C:\Windows |

          ################## | C:\Windows\Prefetch |

          ################## | C:\Windows\system32 |

          ################## | C:\Windows\system32\drivers |

          ################## | C:\Users\Annick\AppData\Roaming |

          ################## | Zip File ... |

          ################## | Temporary Internet Files |

          ################## | Registre |

          ################## | Etat |

          # Affichage des fichiers cachés : OK

          # Mode sans echec : OK

          # Uac : OK

          # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
          # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
          # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
          # (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
          # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
          # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
          # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

          ################## | ! Fin du rapport # FindyKill V5.032 ! |

          Merci beaucoup de m'aider car ce problème est vraimment gênant.
          0
      3. Contributeur sécurité
        vu

        ! Déconnecte toi et ferme toutes application en cours (navigateur compris ) .

        • Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...

        • Double clique sur setup.exe présent sur ton bureau pour lancer l’outil.

        • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

        • Au second menu choisis l'option 2 (suppression) et tape sur [entrée]

        • Le pc va redémarrer automatiquement ...

        ▶ le programme va travailler, ne touche à rien ... , ton bureau ne sera pas accessible c est normal !

        ► Poste le rapport qui apparaît à la fin ( le rapport est sauvegardé aussi sous C:\FindyKill.txt)

        Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valide

        Findykill peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

        Il est enregistré sur ton bureau.

        Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de Findykill dans ses recherches.

        .............................

        ensuite
        • Télécharge Random's System Information Tool (RSIT) de Random/Random.

        (outil de diagnostic)

        http://images.malwareremoval.com/random/RSIT.exe

        • Enregistre le sur ton Bureau.

        • Double clique sur RSIT.exe pour lancer l'outil.

        • Clique sur "Continue" à l'écran Disclaimer.

        • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

        et tu devras accepter la licence.

        • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

        Les rapports se trouvent à cet endroit:
        C:\rsit\info.txt
        C:\rsit\log.txt

        0
        1. L'ordinateur a redémarré, il y a tout de même les messages d'erreur, je vais passer à la deuxième partie mais voilà pour l'instant le rapport de Findykill :

          ############################## | FindyKill V5.032 |

          # User : Annick (Administrateurs) # PC-DE-ANNICK
          # Update on 03/02/2010 by El Desaparecido
          # Start at: 15:02:09 | 06/02/2010
          # Website : http://pagesperso-orange.fr/NosTools/index.html
          # Contact : FindyKill.Contact@gmail.com

          #
          #
          # Internet Explorer 8.0.6001.18882
          # Windows Firewall Status : Enabled

          ############################## | Processus actifs |

          C:\Windows\System32\smss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\Ati2evxx.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\vfsFPService.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\WLANExt.exe
          C:\Windows\system32\LogonUI.exe
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\Ati2evxx.exe
          C:\Program Files\Avira\AntiVir Desktop\sched.exe
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\a-squared Free\a2service.exe
          C:\Windows\system32\agrsmsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
          C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
          C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
          C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
          C:\Program Files\Intel\WiFi\bin\EvtEng.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\Windows\system32\taskeng.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Acer\Mobility Center\MobilityService.exe
          C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
          C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
          C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
          C:\Program Files\Cyberlink\Shared files\RichVideo.exe
          C:\Program Files\Acer\Acer VCM\RS_Service.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Windows\system32\runonce.exe
          C:\Windows\system32\conime.exe

          ################## | C: |

          (!) Non supprimé ! F:\autorun.inf

          ################## | C:\Windows |

          ################## | C:\Windows\Prefetch |

          Supprimé ! C:\Windows\prefetch\WINUPGRO.EXE-C12B80B5.pf

          ################## | C:\Windows\system32 |

          ################## | C:\Windows\system32\drivers |

          ################## | C:\Users\Annick\AppData\Roaming |

          ################## | Autres suppressions ... |

          ################## | Zip File ... |

          ################## | Temporary Internet Files |

          ################## | Registre |

          ################## | Etat |

          # Mode sans echec : OK

          # Affichage des fichiers cachés : OK

          # Uac : OK

          # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
          # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
          # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
          # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
          # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
          # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
          # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

          ################## | PEH |

          ################## | Upload |

          Veuillez envoyer le fichier : C:\FindyKill_Upload_Me_PC-de-Annick.zip : https://www.ionos.fr/?affiliate_id=77097
          Merci pour votre contribution .

          ################## | ! Fin du rapport # FindyKill V5.032 ! |
          0
      4. Voici le fichier log

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by Annick at 2010-02-06 15:23:11
        WIN_VISTA Service Pack 2
        System drive C: has 55 GB (48%) free of 114 GB
        Total RAM: 3070 MB (61% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 15:23:51, on 06/02/2010
        Platform: Windows Vista SP2 (WinNT 6.00.1906)
        MSIE: Internet Explorer v8.00 (8.00.6001.18882)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\conime.exe
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
        C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
        C:\Windows\RtHDVCpl.exe
        C:\Windows\PLFSetI.exe
        C:\Program Files\Launch Manager\LManager.exe
        C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
        C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\Micro Application\LauncherMA.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Users\Annick\AppData\Local\Temp\RtkBtMnt.exe
        C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Users\Annick\Desktop\RSIT.exe
        C:\Program Files\trend micro\Annick.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
        O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
        O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
        O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
        O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
        O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
        O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
        O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
        O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
        O4 - HKLM\..\Run: [Skytel] Skytel.exe
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
        O4 - HKUS\S-1-5-21-2130128367-3722185353-714794325-1000\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User '?')
        O4 - S-1-5-21-2130128367-3722185353-714794325-1000 Startup: Lanceur.lnk = C:\Program Files\Micro Application\LauncherMA.exe (User '?')
        O4 - Startup: Lanceur.lnk = C:\Program Files\Micro Application\LauncherMA.exe
        O4 - Global Startup: Acer VCM.lnk = ?
        O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
        O8 - Extra context menu item: Visit in &3D using ExitReality - http://3d.exitreality.com/TransmogrifyPage.htm
        O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
        O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
        O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O13 - Gopher Prefix:
        O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
        O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
        O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
        O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
        O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
        O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
        O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
        O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
        O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
        O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
        O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
        O23 - Service: Google Update Service (gupdate1c98aee7353e51a) (gupdate1c98aee7353e51a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
        O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
        O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
        O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
        O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
        O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
        O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
        O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
        O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
        O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe
        0
        1. Excuse moi, c'est toujours moi mais il m"était impossible d'envoyer le fichier info, en espérant que ce message va passer :

          info.txt logfile of random's system information tool 1.06 2010-02-06 15:23:54

          ======Uninstall list======

          -->MsiExec /X{65F1CF63-31E0-450B-96F3-4A88BE7361A6}
          -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\Setup.exe" -uninstall
          4 Elements 1.0-->"C:\Program Files\4 Elements\unins000.exe"
          Acer Arcade Deluxe-->"C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" /z-uninstall
          Acer Arcade Deluxe-->"C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" /z-uninstall
          Acer Bio Protection

          AAV 6.0.00.13-->"C:\Program Files\Acer\Acer Bio Protection\uninstall.exe"
          Acer Crystal Eye webcam Ver:1.1.58.429-->C:\Program Files\InstallShield Installation Information\{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}\setup.exe -runfromtemp -l0x040c -removeonly
          Acer eAudio Management-->"C:\Program Files\InstallShield Installation Information\{57265292-228A-41FA-9AEC-4620CBCC2739}\Setup.exe" -uninstall
          Acer eDataSecurity Management-->C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSnstHelper.exe -Operation UNINSTALL
          Acer Empowering Technology-->"C:\Program Files\InstallShield Installation Information\{8F1B6239-FEA0-450A-A950-B05276CE177C}\setup.exe" -runfromtemp -l0x040c -removeonly
          Acer ePower Management-->"C:\Program Files\InstallShield Installation Information\{58E5844B-7CE2-413D-83D1-99294BF6C74F}\setup.exe" -runfromtemp -l0x040c -removeonly
          Acer eRecovery Management-->"C:\Program Files\InstallShield Installation Information\{7F811A54-5A09-4579-90E1-C93498E230D9}\setup.exe" -runfromtemp -l0x040c -removeonly
          Acer eSettings Management-->"C:\Program Files\InstallShield Installation Information\{13D85C14-2B85-419F-AC41-C7F21E68B25D}\setup.exe" -runfromtemp -l0x040c -removeonly
          Acer GameZone Console 2.0.1.1-->"C:\Program Files\Acer GameZone\GameConsole\unins000.exe"
          Acer GridVista-->C:\Windows\GVUni.exe GridV.UNI
          Acer Mobility Center Plug-In-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{11316260-6666-467B-AC34-183FCB5D4335}\setup.exe" -l0x40c -removeonly
          Acer ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
          Acer VCM-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}\setup.exe" -l0x40c -removeonly
          Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
          Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Reader 8.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
          Agatha Christie - Death on the Nile-->"C:\Program Files\Agatha Christie - Death on the Nile\Uninstall.exe"
          Agatha Christie - Mort sur le Nil-->"C:\Program Files\InstallShield Installation Information\{6C401FC7-36EF-4B83-ADDC-0695DD183254}\setup.exe" -runfromtemp -l0x040c -removeonly
          Agatha Christie Death on the Nile-->"C:\Program Files\Acer GameZone\Agatha Christie Death on the Nile\Uninstall.exe" "C:\Program Files\Acer GameZone\Agatha Christie Death on the Nile\install.log"
          Agatha Christie Peril at End House-->"C:\Program Files\orange\jeux\Agatha Christie Peril at End House\Uninstall.exe" "C:\Program Files\orange\jeux\Agatha Christie Peril at End House\install.log"
          AGEIA PhysX v7.07.09-->MsiExec.exe /X{65F1CF63-31E0-450B-96F3-4A88BE7361A6}
          Agere Systems HDA Modem-->agrsmdel
          Alice Greenfingers-->"C:\Program Files\Acer GameZone\Alice Greenfingers\Uninstall.exe" "C:\Program Files\Acer GameZone\Alice Greenfingers\install.log"
          Amazing Adventures The Lost Tomb 1.0.0.5-->C:\Program Files\PopCap Games\Amazing Adventures\PopUninstall.exe "C:\Program Files\PopCap Games\Amazing Adventures\Install.log"
          a-squared Free 4.5-->"C:\Program Files\a-squared Free\unins000.exe"
          Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
          Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver-->"C:\Program Files\InstallShield Installation Information\{3108C217-BE83-42E4-AE9E-A56A2A92E549}\setup.exe" -runfromtemp -l0x040c -removeonly
          Autour du Monde 1.0-->"C:\Program Files\Mindscape\Autour du Monde\unins000.exe"
          Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
          Azada-->"C:\Program Files\Acer GameZone\Azada\Uninstall.exe" "C:\Program Files\Acer GameZone\Azada\install.log"
          Backspin Billiards-->"C:\Program Files\Acer GameZone\Backspin Billiards\Uninstall.exe" "C:\Program Files\Acer GameZone\Backspin Billiards\install.log"
          Bejeweled 2 Deluxe 1.0-->C:\Program Files\PopCap Games\Bejeweled 2 Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Bejeweled 2 Deluxe\Install.log"
          Big Fish Games Client-->C:\Program Files\bfgclient\Uninstall.exe
          Big Kahuna Reef-->"C:\Program Files\Acer GameZone\Big Kahuna Reef\Uninstall.exe" "C:\Program Files\Acer GameZone\Big Kahuna Reef\install.log"
          Bricks of Egypt-->"C:\Program Files\Acer GameZone\Bricks of Egypt\Uninstall.exe" "C:\Program Files\Acer GameZone\Bricks of Egypt\install.log"
          Cake Mania 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9B29E14C-4B71-4BDC-860F-AAFB0C0BEACA}\setup.exe" -l0x40c -removeonly
          Cake Mania Deluxe-->"C:\Program Files\Zylom Games\Cake Mania Deluxe\GameInstlr.exe" --uninstall UnInstall.log
          Cake Mania-->"C:\Program Files\Acer GameZone\Cake Mania\Uninstall.exe" "C:\Program Files\Acer GameZone\Cake Mania\install.log"
          Call of Atlantis-->"C:\Program Files\Call of Atlantis\Uninstall.exe"
          Canon MP160-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160 /L0x000c
          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
          Cheat Engine 5.5-->"C:\Program Files\Cheat Engine\unins000.exe"
          Chicken Invaders 3-->"C:\Program Files\Acer GameZone\Chicken Invaders 3\Uninstall.exe" "C:\Program Files\Acer GameZone\Chicken Invaders 3\install.log"
          Cléopâtre-->c:\Nobilis\Cléopâtre\Uninstall.exe
          Cooking Academy-->"C:\Program Files\Cooking Academy\ReflexiveArcade\unins000.exe"
          CSI NY-->C:\Program Files\Ubisoft\Legacy Interactive\CSI NY\Uninstall.exe
          Diner Dash Flo on the Go-->"C:\Program Files\Acer GameZone\Diner Dash Flo on the Go\Uninstall.exe" "C:\Program Files\Acer GameZone\Diner Dash Flo on the Go\install.log"
          Diner Dash Hometown Hero-->C:\PROGRA~1\PLAYFI~1\DINERD~1\UNWISE.EXE C:\PROGRA~1\PLAYFI~1\DINERD~1\INSTALL.LOG
          Enigmes et Objets Cachés l île Mystérieuse-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2BCE6C52-F35D-4F80-981F-4C8299CD21A5}\Setup.exe" -l0x40c
          Enigmes et Objets Cachés Natalie Brooks-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5ECC8D81-AAAD-48B2-A415-CA8B745FD838}\Setup.exe" -l0x40c
          eSobi v2-->C:\Program Files\InstallShield Installation Information\{15D967B5-A4BE-42AE-9E84-64CD062B25AA}\setup.exe -runfromtemp -l0x040c
          Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
          GamesBar 2.0.1.12-->C:\Program Files\GamesBar\uninst.exe
          Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
          Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
          Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
          Google Earth-->MsiExec.exe /X{C084BC61-E537-11DE-8616-005056806466}
          Hidden Expedition: Titanic ™-->"C:\Program Files\Hidden Expedition Titanic\Uninstall.exe"
          HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
          IncrediMail-->MsiExec.exe /X{5E97F3BD-CDDC-4188-9D98-532E14FABB5D}
          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
          Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
          Intel PROSet Wireless-->Intel PROSet Wireless
          Intel® Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
          ITECIR Driver-->C:\Program Files\InstallShield Installation Information\{FCED9B62-34FF-4C15-8A23-F65221F7874D}\setup.exe -runfromtemp -l0x040c -removeonly
          Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
          Jewel Match 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3A54CCCA-DBA2-43DB-AE67-B92DCBEE757D}\Setup.exe" -l0x40c
          Jewel Quest Solitaire-->"C:\Program Files\Acer GameZone\Jewel Quest Solitaire\Uninstall.exe" "C:\Program Files\Acer GameZone\Jewel Quest Solitaire\install.log"
          JMicron JMB38X Flash Media Controller-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{26604C7E-A313-4D12-867F-7C6E7820BE4C}\setup.exe" -l0x40c -removeonly
          Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
          La boucle d'argent-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8167F503-3BE6-4EF3-AA61-A34AF232108B}\setup.exe" -l0x40c -removeonly
          Launch Manager-->C:\Windows\UnInst32.exe LManager.UNI
          LauncherMA-->MsiExec.exe /X{C06EFB22-B5DB-46C5-9215-BCB5C19C0858}
          Les derniers jours de Pompéi-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{706CC677-3CE5-4704-B983-AB65FFD85D69}\Setup.exe" -l0x40c
          Logiciel d'archivage WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          Logiciel Intel(R) PROSet/Wireless WiFi-->MsiExec.exe /I{F22FD942-651D-4EE8-BD6F-7E0AF5E17625}
          Ma-Config.com-->MsiExec.exe /X{494952B3-AA5A-486C-8495-6BF830962747}
          Mah Jong Le Secret des Mayas-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{10B24547-31C1-49D5-8AD0-62BD97DDFFD7}\Setup.exe" -l0x40c
          Mahjong Escape Ancient China-->"C:\Program Files\Acer GameZone\Mahjong Escape Ancient China\Uninstall.exe" "C:\Program Files\Acer GameZone\Mahjong Escape Ancient China\install.log"
          Mahjongg Artifacts-->"C:\Program Files\Acer GameZone\Mahjongg Artifacts\Uninstall.exe" "C:\Program Files\Acer GameZone\Mahjongg Artifacts\install.log"
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Medal of Honor Airborne-->MsiExec.exe /X{25F28E39-FDBB-11DB-8314-0800200C9A66}
          Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
          Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
          Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
          Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
          Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
          Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
          Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
          Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
          Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
          Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
          Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
          Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
          Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
          Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
          Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
          Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
          Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
          Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
          Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
          Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
          Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
          Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
          Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
          Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
          Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
          Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
          Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
          Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
          Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
          Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
          Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
          Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
          Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
          Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
          Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
          Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
          Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
          Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
          Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
          Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
          Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
          Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
          Mozilla Firefox (3.5.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
          Mystery Case Files - Huntsville-->"C:\Program Files\Acer GameZone\Mystery Case Files - Huntsville\Uninstall.exe" "C:\Program Files\Acer GameZone\Mystery Case Files - Huntsville\install.log"
          Mystery Solitaire - Secret Island-->"C:\Program Files\Acer GameZone\Mystery Solitaire - Secret Island\Uninstall.exe" "C:\Program Files\Acer GameZone\Mystery Solitaire - Secret Island\install.log"
          Naissance de Rome-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9BCE54DD-8A2E-4530-9409-3AE7866BE590}\Setup.exe" -l0x40c
          NTI Backup Now 5-->C:\Program Files\InstallShield Installation Information\{12EFA1A4-AC3B-443C-8143-237EDE760403}\setup.exe -runfromtemp -l0x040c
          NTI Media Maker 8-->C:\Program Files\InstallShield Installation Information\{2413930C-8309-47A6-BC61-5EF27A4222BC}\setup.exe -runfromtemp -l0x040c
          NVIDIA GAME System Software 2.8.1-->MsiExec.exe /I{4F0C7CCF-5666-474B-B02E-AC514A95EC93}
          Opera 10.10-->MsiExec.exe /X{690BE098-6D0D-493D-B079-BD7E8F81A141}
          Orion-->MsiExec.exe /X{5B63A470-9334-44D1-AF61-6CE2DB565AE9}
          Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
          PhotoMail Maker-->MsiExec.exe /X{15382D89-6EF6-4D21-9484-B500F2B10E46}
          PhotoMail Maker-->MsiExec.exe /X{15382D89-6EF6-4D21-9484-B500F2B10E46} ARPVAL="UnInst" /qf /L*V "%temp%\PhotoMailUninstallLog.log"
          PhotoNow!-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\Setup.exe" -uninstall
          Play Movie-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A450831D-25F6-4F42-9662-D000B25E0D82}\Setup.exe" -uninst
          PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
          Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
          Remue-méninges la saison des fruits-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F4F88D0-99D4-4D8F-8529-444BB169FB6B}\Setup.exe" -l0x40c
          Retour sur l'île mystérieuse-->C:\Program Files\The Adventure Company\Retour sur l'île mystérieuse\Uninstall.exe
          RUNAWAY 2 - The dream of the turtle-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DE0CE4-F38A-4DA7-81DF-949E615EA0AB}\setup.exe"
          Sandlot Games Client Services 1.2.2-->"C:\Program Files\Common Files\Sandlot Shared\unins000.exe"
          Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
          Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
          Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
          Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
          Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
          Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
          Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
          Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
          Sherlock Holmes - la Nuit des Sacrifies - Remasterisee-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{760BF94F-4FAF-4EF6-96D9-B55B12993992}\setup.exe" -l0x40c -removeonly
          Sherlock Holmes contre Arsene Lupin-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63686BEF-04CA-461C-B364-53BBC322F7BF}\setup.exe" -l0x40c -removeonly
          Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
          Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
          Syberia 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Microids\Syberia 2\Uninstall\Setup.exe" -l0x40c
          Syberia-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Microids\Syberia\Uninstall\Setup.exe" -l0x40c
          Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
          Turbo Pizza-->"C:\Program Files\Oberon Media\Turbo Pizza\Uninstall.exe" "C:\Program Files\Oberon Media\Turbo Pizza\install.log"
          Turbo Pizza-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{972A8B3F-411D-4A19-A7C3-351A0D04AA80}\setup.exe" -l0x40c -removeonly
          Uniblue RegistryBooster 2010-->"C:\Program Files\Uniblue\RegistryBooster\unins000.exe"
          Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
          Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
          Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
          Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
          Validity Sensors software-->MsiExec.exe /X{567E8236-C414-4888-8211-3D61608D57AE}
          WIDCOMM Bluetooth Software 6.0.1.5000-->MsiExec.exe /X{03D1988F-469F-4843-8E6E-E5FE9D17889D}
          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
          Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
          Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
          Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
          Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
          Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
          Windows Live Movie Maker-->MsiExec.exe /X{53B20C18-D8D4-4588-8737-9BBFE303C354}
          Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
          Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
          Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
          Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\unyt.exe
          Zuma Deluxe-->"C:\Program Files\Acer GameZone\Zuma Deluxe\Uninstall.exe" "C:\Program Files\Acer GameZone\Zuma Deluxe\install.log"

          ======Hosts File======

          127.0.0.1 www.007guard.com
          127.0.0.1 007guard.com
          127.0.0.1 008i.com
          127.0.0.1 www.008k.com
          127.0.0.1 008k.com
          127.0.0.1 www.00hq.com
          127.0.0.1 00hq.com
          127.0.0.1 010402.com
          127.0.0.1 www.032439.com
          127.0.0.1 032439.com

          Securitycenter WMI appears to be broken

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Acer\Empowering Technology\eDataSecurity\;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\Intel\WiFi\bin\
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
          "PROCESSOR_ARCHITECTURE"=x86
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "USERNAME"=SYSTEM
          "windir"=%SystemRoot%
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
          "PROCESSOR_REVISION"=0f0d
          "NUMBER_OF_PROCESSORS"=2
          "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
          "DFSTRACINGON"=FALSE
          "Pathtem"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Acer\Empowering Technology\eDataSecurity\;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64
          "NTIPath"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Acer\Empowering Technology\eDataSecurity\;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86;C:\Program Files\Acer\Empowering Technology\eDataSecurity\x64;C:\Program Files\NewTech Infosystems\NTI Backup Now 5\;

          -----------------EOF-----------------
          0
          1. Contributeur sécurité
            Téléchargez USBFIX de El Desaparecido, C_xx

            http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
            ou
            https://www.ionos.fr/?affiliate_id=77097

            /!\ Utilisateur de vista et windows 7 :
            ne pas oublier de désactiver Le contrôle des comptes utilisateurs
            https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

            /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

            • Double clic sur le raccourci UsbFix présent sur le bureau .

            Choisir Option 2 = Nettoyage
            (d’autres options disponibles, voir le tutoriel).
            • Laissez travailler l'outil.
            Le menu démarrer et les icônes vont disparaître.. c'est normal.

            Si un message te demande de redémarrer l'ordinateur fais le ...

            ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

            ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

            • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

            ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

            • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
            Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

            • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

            UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

            Il est enregistré sur ton bureau.

            Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

            ..................

            lances MalwareByte's Anti-Malware que tu as déjà
            mets le à jour
            examen complet
            poster le rapport

            0
            1. Bonjour c'est toujours moi, je n'ai pas pu poster le deuxième rapport de RSIT sr le forum, voilà le rapport USBFIX :

              ############################## | UsbFix V6.091 |

              User : Annick (Administrateurs) # PC-DE-ANNICK
              Update on 05/02/2010 by El Desaparecido , C_XX & Chimay8
              Start at: 15:55:45 | 06/02/2010
              Website : http://pagesperso-orange.fr/NosTools/index.html
              Contact : FindyKill.Contact@gmail.com

              Internet Explorer 8.0.6001.18882
              Windows Firewall Status : Enabled

              ############################## | Processus actifs |

              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\Ati2evxx.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\vfsFPService.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\WLANExt.exe
              C:\Windows\system32\LogonUI.exe
              C:\Windows\System32\spoolsv.exe
              C:\Program Files\Avira\AntiVir Desktop\sched.exe
              C:\Windows\system32\Ati2evxx.exe
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\a-squared Free\a2service.exe
              C:\Windows\system32\agrsmsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
              C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
              C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
              C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
              C:\Program Files\Intel\WiFi\bin\EvtEng.exe
              C:\Program Files\Google\Update\GoogleUpdate.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
              C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\Acer\Mobility Center\MobilityService.exe
              C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
              C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
              C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
              C:\Program Files\Cyberlink\Shared files\RichVideo.exe
              C:\Program Files\Acer\Acer VCM\RS_Service.exe
              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\runonce.exe
              C:\Windows\system32\conime.exe

              ################## | Elements infectieux |

              Supprimé ! C:\$Recycle.Bin\S-1-5-21-2130128367-3722185353-714794325-1000
              Supprimé ! C:\$Recycle.Bin\S-1-5-21-2130128367-3722185353-714794325-500
              Supprimé ! D:\$Recycle.Bin\S-1-5-21-2130128367-3722185353-714794325-1000
              Supprimé ! D:\$Recycle.Bin\S-1-5-21-2130128367-3722185353-714794325-500
              Non supprimé ! F:\autorun.ini
              Non supprimé ! F:\autorun.inf

              ################## | Registre |

              ################## | Mountpoints2 |

              Supprimé ! HKCU\...\Explorer\MountPoints2\{ad6fe418-42bf-11dd-8fa5-806e6f6e6963}\Shell\AutoRun\Command

              ################## | Listing des fichiers présent |

              [18/09/2006 22:43|--a------|24] C:\autoexec.bat
              [11/04/2009 07:36|-rahs----|333257] C:\bootmgr
              [21/03/2008 04:12|-ra-s----|8192] C:\BOOTSECT.BAK
              [18/09/2006 22:43|--a------|10] C:\config.sys
              [06/02/2010 15:13|--a------|1312] C:\FindyKill_Upload_Me_PC-de-Annick.zip
              [06/02/2010 15:13|--a------|4180] C:\FyK.txt
              [?|?|?] C:\hiberfil.sys
              [25/06/2008 15:33|--a------|20] C:\Medion.ini
              [?|?|?] C:\pagefile.sys
              [25/06/2008 15:26|--a------|60] C:\Partition.txt
              [21/03/2008 11:33|--a------|477] C:\RHDSetup.log
              [06/02/2010 15:58|--a------|4036] C:\UsbFix.txt
              [14/12/2008 12:40|--a------|669] E:\Sample Pictures.lnk
              [05/02/2010 18:47|---hs----|85] E:\desktop.ini
              [19/12/2006 10:09|-r-------|120904] F:\AUTORUN.EXE
              [19/06/2003 07:57|-r-------|45] F:\AUTORUN.INF
              [23/01/2007 09:33|-r-------|123] F:\AUTORUN.INI
              [29/08/2002 11:44|-r-------|1703936] F:\GdiPlus.dll
              [17/09/2004 07:16|-r-------|13942] F:\MICRO.ICO
              [09/07/2007 10:52|-r-------|522112] F:\NavigMA.exe
              [07/04/2008 13:31|-r-h-----|7168] F:\Thumbs.db
              [03/06/2008 16:44|-r-------|18449] F:\navigma.xml

              ################## | Vaccination |

              # C:\autorun.inf -> Dossier créé par UsbFix .
              # D:\autorun.inf -> Dossier créé par UsbFix .
              # E:\autorun.inf -> Dossier créé par UsbFix .

              ################## | Upload |

              Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_PC-de-Annick.zip : https://www.ionos.fr/?affiliate_id=77097
              Merci pour votre contribution .

              ################## | ! Fin du rapport # UsbFix V6.091 ! |
              0
              1. Contributeur sécurité
                ok

                => MBAM donc
                0
                1. Voilà :

                  Malwarebytes' Anti-Malware 1.44
                  Version de la base de données: 3697
                  Windows 6.0.6002 Service Pack 2
                  Internet Explorer 8.0.6001.18882

                  06/02/2010 17:09:09
                  mbam-log-2010-02-06 (17-09-09).txt

                  Type de recherche: Examen complet (C:\|D:\|E:\|F:\|)
                  Eléments examinés: 279361
                  Temps écoulé: 1 hour(s), 1 minute(s), 0 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 0
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 0

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  (Aucun élément nuisible détecté)
                  0
                  1. Contributeur sécurité
                    ok

                    où en sont tres soucis du début ?

                    ton centre de sécurité et antivir sont ils opérationnels ?

                    0
                    1. Le centre de sécurité ne démarre pas, on ne peut toujours pas le faire démarrer par le menu "services".

                      J'ai une fenêtre : Event Monitor User Notification Tool cessé de fonctionner.

                      Et j'ai plusieurs fenêtres avec des noms en .exe différents par exemple :

                      AcerVCM.exe-Image incorrecte

                      C:\Windows\system32\wbemcomn.dll n'est pas conçu pour s'exécuter sous Windows ou il contient une erreur. Installez à nouveau le programme à l'aide du support d'installation d'origine, ou bien contactez votre administrateur système ou le fournisseur du logiciel pour obtenir du support.

                      La dll mise en cause est toujours la même et ce message est également apparu lors des lancements de recherches de Findykill, RSIT et USBFIX par contre je ne sais pas si c'était la même dll pour ceux-là.
                      0
                      1. Contributeur sécurité
                        tu avais un debut de bagle et il me semble que tu as fait une restauration systeme recement

                        qu'est ce qui a motvé cette restauration ?
                        0
                        1. Je n'ai pas fais de restauration système, j'ai essayé suite à un des premiers messages de la discussion mais il n y avait pas de point de restauration.
                          0
                          1. Contributeur sécurité
                            Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                            ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
                            http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

                            double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                            coche la case "creer une icone sur le bureau"

                            une fois terminée , clic sur "terminer" et le programme se lancer seul

                            choisis la langue puis choisis l'option 1 = Mode Recherche

                            ▶ laisse travailler l'outil

                            à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                            un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                            ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                            tu peux supprimer le rapport catchme.log de ton bureau maintenant.

                            0
                            1. Voilà le rapport, encore merci de m'aider :

                              List'em by g3n-h@ckm@n 1.2.4.0

                              User : Annick (Administrateurs)
                              Update on 05/02/2010 by g3n-h@ckm@n ::::: 18.40
                              Start at: 18:01:06 | 06/02/2010
                              Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                              Internet Explorer 8.0.6001.18882
                              Windows Firewall Status : Disabled

                              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                              C:\Windows\System32\smss.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\wininit.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\services.exe
                              C:\Windows\system32\lsass.exe
                              C:\Windows\system32\lsm.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\Ati2evxx.exe
                              C:\Windows\system32\winlogon.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\SLsvc.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\vfsFPService.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\WLANExt.exe
                              C:\Windows\System32\spoolsv.exe
                              C:\Program Files\Avira\AntiVir Desktop\sched.exe
                              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\Ati2evxx.exe
                              C:\Program Files\a-squared Free\a2service.exe
                              C:\Windows\system32\agrsmsvc.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
                              C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
                              C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
                              C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
                              C:\Program Files\Intel\WiFi\bin\EvtEng.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                              C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
                              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              C:\Acer\Mobility Center\MobilityService.exe
                              C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
                              C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
                              C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
                              C:\Program Files\Cyberlink\Shared files\RichVideo.exe
                              C:\Program Files\Acer\Acer VCM\RS_Service.exe
                              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\SearchIndexer.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\Explorer.EXE
                              C:\Program Files\Windows Defender\MSASCui.exe
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
                              C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
                              C:\Windows\RtHDVCpl.exe
                              C:\Windows\PLFSetI.exe
                              C:\Program Files\Launch Manager\LManager.exe
                              C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
                              C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
                              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Windows\ehome\ehtray.exe
                              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              C:\Program Files\Micro Application\LauncherMA.exe
                              C:\Windows\ehome\ehmsas.exe
                              C:\Users\Annick\AppData\Local\Temp\RtkBtMnt.exe
                              C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                              C:\Program Files\List_Kill'em\List_Kill'em.scr
                              C:\Windows\system32\conime.exe
                              C:\Windows\system32\cmd.exe
                              C:\Users\Annick\AppData\Local\Temp\6798.tmp\pv.exe

                              ======================
                              Keys "Run"
                              ======================
                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
                              SpybotSD TeaTimer REG_SZ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              SynTPEnh REG_SZ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              eDataSecurity Loader REG_SZ C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
                              eAudio REG_SZ "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
                              RtHDVCpl REG_SZ RtHDVCpl.exe
                              IAAnotif REG_SZ C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                              PLFSetI REG_SZ C:\Windows\PLFSetI.exe
                              LManager REG_SZ C:\PROGRA~1\LAUNCH~1\LManager.exe
                              eRecoveryService REG_SZ
                              ArcadeDeluxeAgent REG_SZ "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
                              ePower_DMC REG_SZ C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
                              WarReg_PopUp REG_SZ C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
                              CLMLServer REG_SZ "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
                              avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                              =====================
                              Other Keys
                              =====================
                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                              ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
                              ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
                              EnableInstallerDetection REG_DWORD 1 (0x1)
                              EnableLUA REG_DWORD 1 (0x1)
                              EnableSecureUIAPaths REG_DWORD 1 (0x1)
                              EnableVirtualization REG_DWORD 1 (0x1)
                              PromptOnSecureDesktop REG_DWORD 1 (0x1)
                              ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
                              dontdisplaylastusername REG_DWORD 0 (0x0)
                              legalnoticecaption REG_SZ
                              legalnoticetext REG_SZ
                              scforceoption REG_DWORD 0 (0x0)
                              shutdownwithoutlogon REG_DWORD 1 (0x1)
                              undockwithoutlogon REG_DWORD 1 (0x1)
                              FilterAdministratorToken REG_DWORD 0 (0x0)
                              EnableUIADesktopToggle REG_DWORD 0 (0x0)
                              UacDisableNotify REG_DWORD 0 (0x0)

                              ===============
                              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                              NoDriveAutoRun REG_DWORD 255 (0xff)
                              NoDriveTypeAutoRun REG_DWORD 255 (0xff)
                              HonorAutoRunSetting REG_DWORD 0 (0x0)

                              ===============
                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                              BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)
                              NoDriveAutoRun REG_DWORD 255 (0xff)
                              NoDriveTypeAutoRun REG_DWORD 255 (0xff)
                              HonorAutoRunSetting REG_DWORD 0 (0x0)

                              ===============
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                              AppInit_DLLS REG_SZ

                              ===============
                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                              ReportBootOk REG_SZ 1
                              Shell REG_SZ explorer.exe
                              Userinit REG_SZ C:\Windows\system32\userinit.exe,
                              VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                              AutoRestartShell REG_DWORD 1 (0x1)
                              LegalNoticeCaption REG_SZ
                              LegalNoticeText REG_SZ
                              PowerdownAfterShutdown REG_SZ 0
                              ShutdownWithoutLogon REG_SZ 0
                              cachedlogonscount REG_SZ 10
                              forceunlocklogon REG_DWORD 0 (0x0)
                              passwordexpirywarning REG_DWORD 14 (0xe)
                              Background REG_SZ 0 0 0
                              DebugServerCommand REG_SZ no
                              WinStationsDisabled REG_SZ 0
                              DisableCAD REG_DWORD 1 (0x1)
                              scremoveoption REG_SZ 0
                              ShutdownFlags REG_DWORD 39 (0x27)

                              ===============
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]

                              ===============
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

                              ===============
                              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                              ===============
                              ActivX controls
                              ===============
                              HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

                              ===============
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                              HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                              ==============
                              BHO :
                              ======
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

                              ================
                              Internet Explorer :
                              ================
                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                              Start Page REG_SZ https://www.msn.com/fr-fr

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                              Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                              ========
                              Services
                              ========
                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                              Ndisuio : 0x3 ( OK = 3 )
                              EapHost : 0x2 ( OK = 2 )
                              Wlansvc : 0x2 ( OK = 2 )
                              SharedAccess : 0x2 ( OK = 2 )
                              windefend : 0x2 ( OK = 2 )
                              wuauserv : 0x2 ( OK = 2 )
                              wscsvc : 0x2 ( OK = 2 )

                              =========
                              Atapi.sys
                              =========

                              %%%% HASHDEEP-1.0
                              %%%% size,md5,sha256,filename
                              ## Invoked from: C:\Users\Annick\AppData\Local\Temp\6798.tmp
                              ## C:\> hashdeep C:\Windows\System32\Drivers\atapi.sys
                              ##
                              19944,1f05b78ab91c9075565a9d8a4b880bc4,737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd,C:\Windows\System32\Drivers\atapi.sys

                              Sources
                              =======

                              C:\Windows\System32\drivers\atapi.sys
                              C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
                              C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
                              C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
                              C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
                              C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys

                              Référence :
                              ==========

                              Win XP_32b : a64013e98426e1877cb653685c5c0009
                              Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                              Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                              Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                              Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                              Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                              Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                              Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                              Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                              F:\Autorun.inf :
                              ----------------
                              [autorun]
                              OPEN=AUTORUN.EXE
                              ICON=Micro.ico

                              =======
                              Drive :
                              =======

                              D‚fragmenteur de disque Windows
                              Copyright (c) 2006 Microsoft Corp.

                              Rapport d'analyse pour le volume C: ACER

                              Taille du volume = 111 Go
                              Espace libre = 53.63 Go
                              tendue d'espace libre la plus grande = 37.65 Go
                              Pourcentage de fragmentation des fichiers = 7 %

                              Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

                              Il n'est pas n‚cessaire de d‚fragmenter ce volume.

                              ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                              Present !! : C:\Program Files\GamesBar
                              Present !! : C:\Windows\System32\ACER.exe
                              Present !! : C:\Users\Annick\LOCAL Settings\Temp\RtkBtMnt.exe

                              ¤¤¤¤¤¤¤¤¤¤ Keys :

                              Present !! : HKCR\Install.Install
                              Present !! : HKCR\Install.Install\CLSID
                              Present !! : HKCR\Install.Install\CurVer
                              Present !! : HKCR\Install.Install.1
                              Present !! : HKCR\Install.Install.1\CLSID

                              ============

                              catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2010-02-06 18:10:36
                              Windows 6.0.6002 Service Pack 2 NTFS

                              scanning hidden processes ...

                              scanning hidden services & system hive ...

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BthPort\Parameters\Keys\001f3acdf8bb]
                              "0023390a0158"=hex:b3,81,3b,ac,d7,f5,a9,87,e9,ec,45,66,e2,7d,75,25
                              "001df6ae284d"=hex:4d,37,7f,f8,63,d4,49,20,44,1d,07,25,1e,ea,ec,a3
                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BthPort\Parameters\Keys\001f3acdf8bb]
                              "0023390a0158"=hex:b3,81,3b,ac,d7,f5,a9,87,e9,ec,45,66,e2,7d,75,25
                              "001df6ae284d"=hex:4d,37,7f,f8,63,d4,49,20,44,1d,07,25,1e,ea,ec,a3

                              scanning hidden registry entries ...

                              scanning hidden files ...

                              scan completed successfully
                              hidden processes: 0
                              hidden services: 0
                              hidden files: 0

                              Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                              device: opened successfully
                              user: MBR read successfully
                              called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys
                              kernel: MBR read successfully
                              user & kernel MBR OK

                              ==========
                              Programs
                              ==========

                              4 Elements
                              a-squared Free
                              Acer
                              Acer Arcade Deluxe
                              Acer GameZone
                              Acer Inc
                              Activation Assistant for the 2007 Microsoft Office suites
                              Adobe
                              Agatha Christie - Death on the Nile
                              AGEIA Technologies
                              Alwil Software
                              ATI
                              Avira
                              bfgclient
                              Big Kahuna Reef
                              Call of Atlantis
                              Canon
                              CanonBJ
                              CCleaner
                              Cheat Engine
                              Cisco
                              Common Files
                              Convesoft
                              Cooking Academy
                              Cradle of Persia
                              Cyberlink
                              desktop.ini
                              directx
                              Electronic Arts
                              eSobi
                              Fichiers communs
                              Focus
                              GamesBar
                              Google
                              Hidden Expedition Titanic
                              InstallShield Installation Information
                              Intel
                              Internet Explorer
                              Java
                              Launch Manager
                              List_Kill'em
                              ma-config.com
                              Malwarebytes' Anti-Malware
                              Micro Application
                              Microids
                              Microsoft
                              Microsoft Games
                              Microsoft Office
                              Microsoft Silverlight
                              Microsoft SQL Server Compact Edition
                              Microsoft Sync Framework
                              Microsoft Works
                              Microsoft.NET
                              Mindscape
                              Movie Maker
                              Mozilla Firefox
                              MSBuild
                              MSXML 4.0
                              NewTech Infosystems
                              Oberon Media
                              Opera
                              orange
                              PENDULO Studios
                              PhotoFiltre
                              PhotoMail Maker
                              playfirst
                              PopCap Games
                              Realtek
                              Reference Assemblies
                              ReflexiveArcade
                              Spybot - Search & Destroy
                              Synaptics
                              The Adventure Company
                              trend micro
                              Ubisoft
                              Uniblue
                              Uninstall Information
                              Validity Sensors, Inc
                              WIDCOMM
                              Windows Calendar
                              Windows Collaboration
                              Windows Defender
                              Windows Journal
                              Windows Live
                              Windows Live SkyDrive
                              Windows Mail
                              Windows Media Player
                              Windows NT
                              Windows Photo Gallery
                              Windows Portable Devices
                              Windows Sidebar
                              WinRAR
                              Yahoo!
                              Zylom Games

                              ============
                              Drive C:
                              ============

                              $RECYCLE.BIN
                              ACER
                              ACERSW
                              ATI
                              autoexec.bat
                              autorun.inf
                              BigFishGamesCache
                              book
                              Boot
                              bootmgr
                              BOOTSECT.BAK
                              CLSetup
                              Config.Msi
                              config.sys
                              Documents and Settings
                              FindyKill_Upload_Me_PC-de-Annick.zip
                              found.000
                              found.001
                              FyK
                              FyK.txt
                              hiberfil.sys
                              Intel
                              Kill'em
                              List'em.txt
                              Medion.ini
                              MSOCache
                              Nobilis
                              pagefile.sys
                              Partition.txt
                              PerfLogs
                              Program Files
                              ProgramData
                              RHDSetup.log
                              rsit
                              System Volume Information
                              TEMP
                              UsbFix
                              UsbFix.txt
                              UsbFix_Upload_Me_PC-de-Annick.zip
                              Users
                              Windows

                              ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                              C:\ACER\Preload\PatchLog
                              C:\ACER\Preload\PatchLog\CodeTracer
                              C:\ACER\Preload\PatchLog\DecompressFM2008-06-25 15-03-52.log
                              C:\ACER\Preload\PatchLog\PAP0100C86000006.csv
                              C:\ACER\Preload\PatchLog\CodeTracer\CodeTracer2008-06-25 15-01-47.log
                              C:\ACER\AcerPatch\eDS_Patch.exe
                              C:\ACER\AcerPatch\YTB_Patch.exe
                              C:\ACER\Preload\Autorun\DRV\ABIG Finger Print BioProtection_Validity\Install.exe

                              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                              0
                              • 1
                              • 2
                              • 3
                              • 4