GOEC62 pop up vista: virus??

Bonjour la team,

Voila, depuis today j'ai une fenêtre pop up qui s'ouvre m'informant que

DLL C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL n'est pas valide.

Et ce à chaque fois ue j'ouvre une application quelconque.

J'ai déjà parcouru plusieurs discussions là dessus, et chose faite, j'ai télécharger HIJACKTHIS et voici le rapport ci dessous.

Je vous remercie d'avance pour le temps et l'éffort consacré aux âmes dispersées sur la toile.

Sur ce...

Kal

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:34:25, on 11.02.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\mobsync.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Windows\System32\nvraidservice.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\ehome\ehmsas.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Khalid\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6I2THAIH\HiJackThis[1].exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=100c&s=1&o=vp32&d=0309&m=aspire_m5641
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=100c&s=1&o=vp32&d=0309&m=aspire_m5641
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=100c&s=1&o=vp32&d=0309&m=aspire_m5641
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [Apanel] C:\ACERSW\config\SetApanel.cmd
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [USBToolTip] C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Khalid\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: ASETRES.EXE
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O13 - Gopher Prefix:
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-ch.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader2.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: Acer TV Share Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer TV Share\Kernel\DMSTV\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Service Google Update (gupdate1ca98f2ccd3d08b) (gupdate1ca98f2ccd3d08b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

--
End of file - 11211 bytes
Configuration: Windows Vista Internet Explorer 7.0

15 réponses

Résumé de la discussion

Une popup récurrente indique que la DLL C:\PROGRA~1\GOOGLE\GOOGLE~2\GOEC62~1.DLL n'est pas valide à chaque ouverture d'une application, laissant supposer une infection ou une modification indésirable du système. Le fil intègre un log HijackThis et un ensemble de processus et services Windows Vista SP2 susceptibles d'être compromis ou indésirables, notamment des barres d'outils et des éléments de Google et AVG. La recommandation clé est de relancer RSIT et de poster le rapport afin d'identifier les sites potentiellement infectés et de poursuivre le nettoyage en douceur et en rigueur. D'autres éléments évoquent des composants Microsoft Live Toolbar et AVG qui peuvent participer à des redirections ou des popups et exigent une vérification minutieuse des extensions et des démarrages.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonsoir

    Note importante :
    Pour les ordinateurs équipés de Windows Vista et Windows 7, la désactivation du Contrôle des comptes utilisateurs est obligatoire
    sous peine de ne pas pouvoir faire fonctionner correctement l'outil.
    Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

    Téléchargez et enregistrez le fichier d installation sur le bureau
    http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

    Double cliquez sur le fichier d'installation de AD-Remover, le programme s'installera automatiquement.
    Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"
    Au menu principal choisir
    Option L Lancer le nettoyage
    et tapez sur [entrée] .
    Laissez travailler l'outil et ne touchez à rien ...
    Postez le rapport qui apparait à la fin.

    ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

    (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    Note :Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

    ..........

    ensuite

    • Télécharge Random's System Information Tool (RSIT) de Random/Random.

    (outil de diagnostic)

    http://images.malwareremoval.com/random/RSIT.exe

    • Enregistre le sur ton Bureau.

    • Double clique sur RSIT.exe pour lancer l'outil.

    • Clique sur "Continue" à l'écran Disclaimer.

    • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

    et tu devras accepter la licence.

    • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

    Les rapports se trouvent à cet endroit:
    C:\rsit\info.txt
    C:\rsit\log.txt

    0
    1. Salut Moment De Grace,

      Merci pour ta réponse super rapide.

      Problème à l'étape de redémarrage de mon ordi, lors de l'analyse de AD-R: impossible d'avoir plus de 4% car le satané pop up s'affiche et bloque tout. Après 10minutes d'attente, j'ai fermé la fenêtre AD-R ainsi que le pop up.

      J'ai malgré tout entamer la partie RSIT, et voilà ce que j'ai eu (en deux messages séparés comme demandé):

      info.txt logfile of random's system information tool 1.06 2010-02-11 22:05:08

      ======Uninstall list======

      -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
      7-Zip 4.65-->"C:\Program Files\7-Zip\Uninstall.exe"
      Acer Arcade Live Main Page-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\Setup.exe" -uninstall
      Acer DV Magician-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6EFFB76-4A07-11DA-9D78-000129760D75}\Setup.exe" -uninstall
      Acer DVDivine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B145EC69-66F5-11D8-9D75-000129760D75}\Setup.exe" -uninstall
      Acer eDataSecurity Management-->C:\Acer\Empowering Technology\eDataSecurity\x86\eDSnstHelper.exe -Operation UNINSTALL
      Acer Empowering Technology-->"C:\Program Files\InstallShield Installation Information\{AB6097D9-D722-4987-BD9E-A076E2848EE2}\setup.exe" -runfromtemp -l0x040c -removeonly
      Acer ePerformance Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D462BF9E-0C35-4705-BF9B-3DF9F3816643}\setup.exe" -l0x40c -removeonly
      Acer eSettings Management-->"C:\Program Files\InstallShield Installation Information\{CE65A9A0-9686-45C6-9098-3C9543A412F0}\setup.exe" -runfromtemp -l0x040c -removeonly
      Acer GameZone Console DTV 2.0.1.1-->"C:\Program Files\Acer GameZone\GameConsole\unins000.exe"
      Acer HomeMedia Connect-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{132888AE-EF67-41C5-BCA2-7D5D2488AB63}\Setup.exe" -uninstall
      Acer HomeMedia Trial Creator-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B580C409-E16F-44FF-904D-3AE94E113BE0}\Setup.exe" -uninstall
      Acer HomeMedia-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\Setup.exe" -uninstall
      Acer ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
      Acer SlideShow DVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{41581EF5-45A7-11DA-9D78-000129760D75}\Setup.exe" -uninstall
      Acer TV Share-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0C297A75-3111-4B3F-9264-84D61FF79F0D}\Setup.exe" -uninstall
      Acer VideoMagician-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F79A208D-D929-11D9-9D77-000129760D75}\Setup.exe" -uninstall
      Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
      Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Reader 9.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A92000000001}
      Adobe Shockwave Player-->C:\Windows\System32\Macromed\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Macromed\SHOCKW~1\Install.log
      Ad-Remover By C_XX-->"C:\Ad-Remover\Un-ADR.exe"
      Agatha Christie Death on the Nile-->"C:\Program Files\Acer GameZone\Agatha Christie Death on the Nile\Uninstall.exe" "C:\Program Files\Acer GameZone\Agatha Christie Death on the Nile\install.log"
      Alice Greenfingers-->"C:\Program Files\Acer GameZone\Alice Greenfingers\Uninstall.exe" "C:\Program Files\Acer GameZone\Alice Greenfingers\install.log"
      Apple Software Update-->MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
      Ask Toolbar-->"C:\Program Files\AskBarDis\unins000.exe"
      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
      Audacity 1.3.9 (Unicode)-->"C:\Program Files\Audacity 1.3 Beta (Unicode)\unins000.exe"
      AVG 9.0-->C:\Program Files\AVG\AVG9\setup.exe /UNINSTALL
      Azada-->"C:\Program Files\Acer GameZone\Azada\Uninstall.exe" "C:\Program Files\Acer GameZone\Azada\install.log"
      Backspin Billiards-->"C:\Program Files\Acer GameZone\Backspin Billiards\Uninstall.exe" "C:\Program Files\Acer GameZone\Backspin Billiards\install.log"
      Big Kahuna Reef-->"C:\Program Files\Acer GameZone\Big Kahuna Reef\Uninstall.exe" "C:\Program Files\Acer GameZone\Big Kahuna Reef\install.log"
      Boilsoft 3GP/iPod/PSP/MP4 Converter 1.22-->"C:\Program Files\Boilsoft MP4 Converter\unins000.exe"
      Bricks of Egypt-->"C:\Program Files\Acer GameZone\Bricks of Egypt\Uninstall.exe" "C:\Program Files\Acer GameZone\Bricks of Egypt\install.log"
      Cake Mania-->"C:\Program Files\Acer GameZone\Cake Mania\Uninstall.exe" "C:\Program Files\Acer GameZone\Cake Mania\install.log"
      CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
      Chicken Invaders 3-->"C:\Program Files\Acer GameZone\Chicken Invaders 3\Uninstall.exe" "C:\Program Files\Acer GameZone\Chicken Invaders 3\install.log"
      Chuzzle-->"C:\Program Files\Acer GameZone\Chuzzle\Uninstall.exe" "C:\Program Files\Acer GameZone\Chuzzle\install.log"
      Diner Dash Flo on the Go-->"C:\Program Files\Acer GameZone\Diner Dash Flo on the Go\Uninstall.exe" "C:\Program Files\Acer GameZone\Diner Dash Flo on the Go\install.log"
      DivX Plus Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
      FormatFactory 1.90-->C:\Program Files\FormatFactory\uninst.exe
      Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
      Google Chrome-->"C:\Program Files\Google\Chrome\Application\4.0.249.78\Installer\setup.exe" --uninstall --system-level
      Google Talk Plugin-->MsiExec.exe /I{5299C5E1-70F9-3D1D-A1FA-BDECA4EC8015}
      Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
      Hauppauge MCE XP/Vista Software Encoder (2.0.25149)-->C:\PROGRA~1\WinTV\UNSftMCE.EXE C:\PROGRA~1\WinTV\softMCE.LOG
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
      Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
      Jewel Quest Solitaire-->"C:\Program Files\Acer GameZone\Jewel Quest Solitaire\Uninstall.exe" "C:\Program Files\Acer GameZone\Jewel Quest Solitaire\install.log"
      Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
      Kick N Rush-->"C:\Program Files\Acer GameZone\Kick N Rush\Uninstall.exe" "C:\Program Files\Acer GameZone\Kick N Rush\install.log"
      Mahjong Escape Ancient China-->"C:\Program Files\Acer GameZone\Mahjong Escape Ancient China\Uninstall.exe" "C:\Program Files\Acer GameZone\Mahjong Escape Ancient China\install.log"
      Mahjongg Artifacts-->"C:\Program Files\Acer GameZone\Mahjongg Artifacts\Uninstall.exe" "C:\Program Files\Acer GameZone\Mahjongg Artifacts\install.log"
      Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
      Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
      Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
      Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
      Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
      Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
      Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
      Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
      Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
      Mystery Case Files - Huntsville-->"C:\Program Files\Acer GameZone\Mystery Case Files - Huntsville\Uninstall.exe" "C:\Program Files\Acer GameZone\Mystery Case Files - Huntsville\install.log"
      Mystery Solitaire - Secret Island-->"C:\Program Files\Acer GameZone\Mystery Solitaire - Secret Island\Uninstall.exe" "C:\Program Files\Acer GameZone\Mystery Solitaire - Secret Island\install.log"
      NTI Backup NOW! 4.7-->C:\Program Files\InstallShield Installation Information\{1598034D-7147-432C-8CA8-888E0632D124}\setup.exe -runfromtemp -l0x040c
      NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
      NVIDIA Drivers-->C:\Windows\system32\nvuninst.exe UninstallGUI
      OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
      Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
      Pilote vidéo Pinnacle-->MsiExec.exe /X{6DE721A5-5E89-4D74-994C-652BB3C0672E}
      Pinnacle Studio 14-->MsiExec.exe /I{AADD1C8F-D59F-4D55-A726-768C71A205A8}
      QuickTime Alternative 1.47-->"C:\Program Files\QuickTime Alternative\unins000.exe"
      QuickTime-->MsiExec.exe /I{5B09BD67-4C99-46A1-8161-B7208CE18121}
      RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
      Realtek High Definition Audio Driver-->RtlUpd.exe -r -m -nrg2709
      Recuva (remove only)-->"C:\Program Files\Recuva\uninst.exe"
      Skype™ 4.0-->MsiExec.exe /X{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}
      TomTom HOME 2.7.3.1894-->C:\Program Files\TomTom HOME 2\Uninstall TomTom HOME.exe
      TomTom HOME Visual Studio Merge Modules-->MsiExec.exe /I{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}
      Turbo Pizza-->"C:\Program Files\Acer GameZone\Turbo Pizza\Uninstall.exe" "C:\Program Files\Acer GameZone\Turbo Pizza\install.log"
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
      VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
      VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      VoipDiscount-->"C:\Program Files\VoipDiscount.com\VoipDiscount\unins000.exe"
      Vuze-->C:\Program Files\Vuze\uninstall.exe
      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
      Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
      Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
      Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
      Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
      Windows Live Movie Maker-->MsiExec.exe /X{53B20C18-D8D4-4588-8737-9BBFE303C354}
      Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
      Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
      Zattoo 3.3.4 Beta-->C:\Program Files\Zattoo\uninst.exe
      Zuma Deluxe-->"C:\Program Files\Acer GameZone\Zuma Deluxe\Uninstall.exe" "C:\Program Files\Acer GameZone\Zuma Deluxe\install.log"

      ======Security center information======

      AS: Windows Defender

      ======System event log======

      Computer Name: PC-de-Khalid
      Event Code: 1003
      Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir du serveur DHCP) pour la carte réseau dont l'adresse réseau est 00064F7A2503. Il s'est produit l'erreur suivante :
      Le délai de temporisation de sémaphore a expiré.. Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du serveur d'adresse réseau (DHCP).
      Record Number: 77838
      Source Name: Microsoft-Windows-Dhcp-Client
      Time Written: 20090928192702.000000-000
      Event Type: Avertissement
      User:

      Computer Name: PC-de-Khalid
      Event Code: 1003
      Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir du serveur DHCP) pour la carte réseau dont l'adresse réseau est 00218573AE2D. Il s'est produit l'erreur suivante :
      Le délai de temporisation de sémaphore a expiré.. Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du serveur d'adresse réseau (DHCP).
      Record Number: 77831
      Source Name: Microsoft-Windows-Dhcp-Client
      Time Written: 20090928192409.000000-000
      Event Type: Avertissement
      User:

      Computer Name: PC-de-Khalid
      Event Code: 1003
      Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir du serveur DHCP) pour la carte réseau dont l'adresse réseau est 00218573AE2D. Il s'est produit l'erreur suivante :
      L'opération a été annulée par l'utilisateur.. Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du serveur d'adresse réseau (DHCP).
      Record Number: 77828
      Source Name: Microsoft-Windows-Dhcp-Client
      Time Written: 20090928192329.000000-000
      Event Type: Avertissement
      User:

      Computer Name: PC-de-Khalid
      Event Code: 15016
      Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
      Record Number: 77660
      Source Name: Microsoft-Windows-HttpEvent
      Time Written: 20090928135630.850748-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Khalid
      Event Code: 4001
      Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

      Record Number: 77644
      Source Name: Microsoft-Windows-WLAN-AutoConfig
      Time Written: 20090928135505.166600-000
      Event Type: Avertissement
      User: AUTORITE NT\SYSTEM

      =====Application event log=====

      Computer Name: PC-de-Khalid
      Event Code: 8194
      Message: Erreur du service de cliché instantané des volumes : erreur lors de l’interrogation de l’interface IVssWriterCallback. hr = 0x80070005. Cette erreur est souvent due à des paramètres de sécurité incorrects dans le processus du rédacteur ou du demandeur.

      Opération :
      Données du rédacteur en cours de collecte

      Contexte :
      ID de classe du rédacteur: {e8132975-6f93-4464-a53e-1050253ae220}
      Nom du rédacteur: System Writer
      ID d’instance du rédacteur: {27da5895-07a4-4556-86e7-f936bc295770}
      Record Number: 496
      Source Name: VSS
      Time Written: 20090307165127.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Khalid
      Event Code: 8194
      Message: Erreur du service de cliché instantané des volumes : erreur lors de l’interrogation de l’interface IVssWriterCallback. hr = 0x80070005. Cette erreur est souvent due à des paramètres de sécurité incorrects dans le processus du rédacteur ou du demandeur.

      Opération :
      Données du rédacteur en cours de collecte

      Contexte :
      ID de classe du rédacteur: {e8132975-6f93-4464-a53e-1050253ae220}
      Nom du rédacteur: System Writer
      ID d’instance du rédacteur: {27da5895-07a4-4556-86e7-f936bc295770}
      Record Number: 486
      Source Name: VSS
      Time Written: 20090307165005.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Khalid
      Event Code: 10
      Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 410
      Source Name: Microsoft-Windows-WMI
      Time Written: 20090307162805.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-Khalid
      Event Code: 1008
      Message: Le service Windows Search tente de supprimer l’ancien catalogue.

      Record Number: 405
      Source Name: Microsoft-Windows-Search
      Time Written: 20090307162804.000000-000
      Event Type: Avertissement
      User:

      Computer Name: WIN-Q8Z23L9IFYB
      Event Code: 1036
      Message: Échec de InitializePrintProvider pour le fournisseur inetpp.dll. Cela peut se produire à la suite d’une instabilité du système ou d’une insuffisance des ressources système.
      Record Number: 390
      Source Name: Microsoft-Windows-SpoolerSpoolss
      Time Written: 20090307162246.000000-000
      Event Type: Avertissement
      User: AUTORITE NT\SYSTEM

      =====Security event log=====

      Computer Name: PC-de-Khalid
      Event Code: 4672
      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      ID d’ouverture de session : 0x3e7

      Privilèges : SeAssignPrimaryTokenPrivilege
      SeTcbPrivilege
      SeSecurityPrivilege
      SeTakeOwnershipPrivilege
      SeLoadDriverPrivilege
      SeBackupPrivilege
      SeRestorePrivilege
      SeDebugPrivilege
      SeAuditPrivilege
      SeSystemEnvironmentPrivilege
      SeImpersonatePrivilege
      Record Number: 6734
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090530151539.878317-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-Khalid
      Event Code: 4624
      Message: L’ouverture de session d’un compte s’est correctement déroulée.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : PC-DE-KHALID$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7

      Type d’ouverture de session : 5

      Nouvelle ouverture de session :
      ID de sécurité : S-1-5-18
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      ID d’ouverture de session : 0x3e7
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Informations sur le processus :
      ID du processus : 0x2a4
      Nom du processus : C:\Windows\System32\services.exe

      Informations sur le réseau :
      Nom de la station de travail :
      Adresse du réseau source : -
      Port source : -

      Informations détaillées sur l’authentification :
      Processus d’ouverture de session : Advapi
      Package d’authentification : Negotiate
      Services en transit : -
      Nom du package (NTLM uniquement) : -
      Longueur de la clé : 0

      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
      Record Number: 6733
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090530151539.878317-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-Khalid
      Event Code: 4648
      Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : PC-DE-KHALID$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Compte dont les informations d’identification ont été utilisées :
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Serveur cible :
      Nom du serveur cible : localhost
      Informations supplémentaires : localhost

      Informations sur le processus :
      ID du processus : 0x2a4
      Nom du processus : C:\Windows\System32\services.exe

      Informations sur le réseau :
      Adresse du réseau : -
      Port : -

      Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
      Record Number: 6732
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090530151539.878317-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-Khalid
      Event Code: 4672
      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      ID d’ouverture de session : 0x3e7

      Privilèges : SeAssignPrimaryTokenPrivilege
      SeTcbPrivilege
      SeSecurityPrivilege
      SeTakeOwnershipPrivilege
      SeLoadDriverPrivilege
      SeBackupPrivilege
      SeRestorePrivilege
      SeDebugPrivilege
      SeAuditPrivilege
      SeSystemEnvironmentPrivilege
      SeImpersonatePrivilege
      Record Number: 6731
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090530151539.691117-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-Khalid
      Event Code: 4624
      Message: L’ouverture de session d’un compte s’est correctement déroulée.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : PC-DE-KHALID$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7

      Type d’ouverture de session : 5

      Nouvelle ouverture de session :
      ID de sécurité : S-1-5-18
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      ID d’ouverture de session : 0x3e7
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Informations sur le processus :
      ID du processus : 0x2a4
      Nom du processus : C:\Windows\System32\services.exe

      Informations sur le réseau :
      Nom de la station de travail :
      Adresse du réseau source : -
      Port source : -

      Informations détaillées sur l’authentification :
      Processus d’ouverture de session : Advapi
      Package d’authentification : Negotiate
      Services en transit : -
      Nom du package (NTLM uniquement) : -
      Longueur de la clé : 0

      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
      Record Number: 6730
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090530151539.691117-000
      Event Type: Succès de l'audit
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Acer\Empowering Technology\eDataSecurity\;C:\Acer\Empowering Technology\eDataSecurity\x86;C:\Acer\Empowering Technology\eDataSecurity\x64;C:\Program Files\QuickTime Alternative\QTSystem\
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
      "PROCESSOR_ARCHITECTURE"=x86
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "USERNAME"=SYSTEM
      "windir"=%SystemRoot%
      "PROCESSOR_LEVEL"=6
      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
      "PROCESSOR_REVISION"=0f0b
      "NUMBER_OF_PROCESSORS"=4
      "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
      "DFSTRACINGON"=FALSE
      "CLASSPATH"=.;C:\Program Files\QuickTime Alternative\QTSystem\QTJava.zip
      "QTJAVA"=C:\Program Files\QuickTime Alternative\QTSystem\QTJava.zip

      -----------------EOF-----------------
      0
    2. Logfile of random's system information tool 1.06 (written by random/random)
      Run by Khalid at 2010-02-11 22:05:06
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
      System drive C: has 153 GB (51%) free of 300 GB
      Total RAM: 3070 MB (61% free)

      HijackThis download failed

      ======Scheduled tasks folder======

      C:\Windows\tasks\Google Software Updater.job
      C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
      C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
      C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4088667415-2200540918-1335641831-1000Core.job
      C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4088667415-2200540918-1335641831-1000UA.job
      C:\Windows\tasks\User_Feed_Synchronization-{D40D0641-247C-4951-9434-4536AB39A9A9}.job

      ======Registry dump======

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
      Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
      AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-12-09 333192]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
      RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-03-20 312928]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
      AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2009-12-11 1484056]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
      Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
      ShowBarObj Class - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-03-04 312880]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
      Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
      AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
      Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-10-31 764912]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
      Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
      {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-03-04 142896]
      {0BF43445-2F28-4351-9252-17FE6E806AA0}
      {3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-12-09 333192]
      {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
      {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
      "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
      "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-03-26 5369856]
      "Acer Empowering Technology Monitor"=C:\Acer\Empowering Technology\SysMonitor.exe [2008-01-09 326176]
      "eDataSecurity Loader"=C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [2008-03-04 526896]
      "Apanel"=C:\ACERSW\config\SetApanel.cmd []
      "WarReg_PopUp"=C:\Acer\WR_PopUp\WarReg_PopUp.exe [2006-11-05 57344]
      "eRecoveryService"= []
      "NVRaidService"=C:\Windows\system32\nvraidservice.exe [2008-06-06 203296]
      "PCMMediaSharing"=C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [2008-05-20 204908]
      "TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-03-20 198160]
      "QuickTime Task"=C:\Program Files\QuickTime Alternative\QTTask.exe [2007-10-19 286720]
      "NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-03-27 13687328]
      "NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2009-03-27 92704]
      "AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2009-12-22 2033432]
      "USBToolTip"=C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [2007-02-20 199752]
      "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
      "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
      "WindowsWelcomeCenter"=oobefldr.dll,ShowWelcomeCenter []
      "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-07 68856]
      "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
      "msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
      "Google Update"=C:\Users\Khalid\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-07 133104]
      "TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2009-11-13 247144]
      "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
      ASETRES.EXE
      Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe
      Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
      "EnableLUA"=0
      "dontdisplaylastusername"=0
      "legalnoticecaption"=
      "legalnoticetext"=
      "shutdownwithoutlogon"=1
      "undockwithoutlogon"=1
      "EnableUIADesktopToggle"=0

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      "BindDirectlyToPropertySetStorage"=

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{358c7aab-dcd5-11de-be16-00218573ae2d}]
      shell\Auto\command - J:\sal.xls.exe
      shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\sal.xls.exe

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{677c766c-9fb5-11de-803a-00218573ae2d}]
      shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{af5dfad7-e8a6-11de-a6b2-00218573ae2d}]
      shell\AutoRun\command - J:\InstallTomTomHOME.exe

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e358e2c7-1fb5-11de-b6fd-00218573ae2d}]
      shell\AutoRun\command - J:\FalloutLauncher.exe

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ec840563-1a31-11de-9427-00218573ae2d}]
      shell\AutoRun\command - J:\FalloutLauncher.exe

      ======File associations======

      .js - edit - C:\Windows\System32\Notepad.exe %1
      .js - open - C:\Windows\System32\WScript.exe "%1" %*

      ======List of files/folders created in the last 1 months======

      2010-02-11 22:05:06 ----D---- C:\rsit
      2010-02-11 22:05:06 ----D---- C:\Program Files\trend micro
      2010-02-11 21:44:16 ----D---- C:\Ad-Remover
      2010-02-11 20:36:45 ----D---- C:\Program Files\CCleaner
      2010-02-10 19:04:18 ----A---- C:\Windows\system32\ntoskrnl.exe
      2010-02-10 19:04:18 ----A---- C:\Windows\system32\ntkrnlpa.exe
      2010-02-10 19:04:16 ----A---- C:\Windows\system32\quartz.dll
      2010-02-10 19:04:15 ----A---- C:\Windows\system32\tsbyuv.dll
      2010-02-10 19:04:15 ----A---- C:\Windows\system32\msyuv.dll
      2010-02-10 19:04:15 ----A---- C:\Windows\system32\msvidc32.dll
      2010-02-10 19:04:15 ----A---- C:\Windows\system32\msvfw32.dll
      2010-02-10 19:04:15 ----A---- C:\Windows\system32\msrle32.dll
      2010-02-10 19:04:15 ----A---- C:\Windows\system32\mciavi32.dll
      2010-02-10 19:04:15 ----A---- C:\Windows\system32\iyuv_32.dll
      2010-02-10 19:04:15 ----A---- C:\Windows\system32\avifil32.dll
      2010-01-22 20:38:06 ----A---- C:\Windows\system32\mshtml.dll
      2010-01-22 20:38:06 ----A---- C:\Windows\system32\ieframe.dll
      2010-01-22 20:38:05 ----A---- C:\Windows\system32\wininet.dll
      2010-01-22 20:38:05 ----A---- C:\Windows\system32\urlmon.dll
      2010-01-22 20:38:05 ----A---- C:\Windows\system32\occache.dll
      2010-01-22 20:38:05 ----A---- C:\Windows\system32\msfeeds.dll
      2010-01-22 20:38:05 ----A---- C:\Windows\system32\iertutil.dll
      2010-01-22 20:38:05 ----A---- C:\Windows\system32\iedkcs32.dll
      2010-01-22 20:38:04 ----A---- C:\Windows\system32\msfeedssync.exe
      2010-01-22 20:38:04 ----A---- C:\Windows\system32\msfeedsbs.dll
      2010-01-22 20:38:04 ----A---- C:\Windows\system32\jsproxy.dll
      2010-01-22 20:38:04 ----A---- C:\Windows\system32\ieUnatt.exe
      2010-01-22 20:38:04 ----A---- C:\Windows\system32\ieui.dll
      2010-01-22 20:38:04 ----A---- C:\Windows\system32\iesysprep.dll
      2010-01-22 20:38:04 ----A---- C:\Windows\system32\iesetup.dll
      2010-01-22 20:38:04 ----A---- C:\Windows\system32\iernonce.dll
      2010-01-22 20:38:04 ----A---- C:\Windows\system32\iepeers.dll
      2010-01-22 20:38:04 ----A---- C:\Windows\system32\ie4uinit.exe
      2010-01-19 11:32:59 ----D---- C:\Program Files\Common Files\DivX Shared
      2010-01-13 11:07:27 ----A---- C:\Windows\system32\t2embed.dll
      2010-01-13 11:07:27 ----A---- C:\Windows\system32\fontsub.dll

      ======List of files/folders modified in the last 1 months======

      2010-02-11 22:05:06 ----RD---- C:\Program Files
      2010-02-11 22:04:52 ----D---- C:\Windows\Temp
      2010-02-11 21:50:51 ----AD---- C:\Windows\System32
      2010-02-11 21:50:51 ----A---- C:\Windows\system32\PerfStringBackup.INI
      2010-02-11 21:50:50 ----D---- C:\Windows\inf
      2010-02-11 21:48:52 ----D---- C:\Windows\Tasks
      2010-02-11 21:23:53 ----D---- C:\Windows\system32\WDI
      2010-02-11 21:23:20 ----D---- C:\Windows\Prefetch
      2010-02-11 20:12:42 ----SHD---- C:\System Volume Information
      2010-02-11 20:00:11 ----D---- C:\ProgramData\Google Updater
      2010-02-11 11:00:42 ----D---- C:\Program Files\Google
      2010-02-11 10:58:10 ----D---- C:\Windows\system32\drivers
      2010-02-11 10:50:21 ----D---- C:\Windows\winsxs
      2010-02-11 10:46:21 ----SHD---- C:\Windows\Installer
      2010-02-11 10:46:02 ----D---- C:\Windows\system32\catroot
      2010-02-10 19:04:12 ----D---- C:\Windows\system32\catroot2
      2010-02-02 23:19:52 ----D---- C:\Users\Khalid\AppData\Roaming\Azureus
      2010-02-02 21:45:59 ----D---- C:\Users\Khalid\AppData\Roaming\dvdcss
      2010-02-02 21:03:56 ----D---- C:\Windows
      2010-02-01 20:26:20 ----A---- C:\Windows\system32\mrt.exe
      2010-01-24 21:41:03 ----SHD---- C:\$RECYCLE.BIN
      2010-01-23 03:15:44 ----D---- C:\Windows\system32\migration
      2010-01-23 03:15:43 ----D---- C:\Program Files\Internet Explorer
      2010-01-22 15:13:04 ----D---- C:\Program Files\Microsoft Silverlight
      2010-01-19 11:43:45 ----D---- C:\Windows\system32\Tasks
      2010-01-19 11:38:08 ----D---- C:\ProgramData\AVG Security Toolbar
      2010-01-19 11:33:55 ----SD---- C:\Windows\Downloaded Program Files
      2010-01-19 11:33:02 ----D---- C:\Program Files\DivX
      2010-01-19 11:32:59 ----D---- C:\Program Files\Common Files

      ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

      R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2009-11-21 24856]
      R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2009-11-21 333192]
      R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2009-11-21 28424]
      R1 AvgTdiX;AVG8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2009-11-21 360584]
      R2 int15;int15; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys [2007-07-03 15392]
      R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-03-04 16944]
      R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-03-04 60464]
      R2 tvicport;tvicport; \??\C:\Windows\system32\drivers\tvicport.sys [2007-11-06 14544]
      R2 zntport;zntport; \??\C:\Windows\system32\drivers\zntport.sys [2007-11-06 6080]
      R3 AVGIDSDrivervtx;AVG9IDSDriver; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [2009-11-21 122376]
      R3 AVGIDSFiltervtx;AVG9IDSFilter; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [2009-11-21 30216]
      R3 AVGIDSShimvtx;AVG9IDSShim; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [2009-11-21 27800]
      R3 HCW85BDA;Hauppauge WinTV 885 Video Capture; C:\Windows\system32\drivers\HCW85BDA.sys [2007-10-01 1129344]
      R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-03-26 2103512]
      R3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys [2007-05-09 41888]
      R3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
      R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-11-18 1040544]
      R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2008-04-28 42528]
      R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-03-27 7738816]
      R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2007-07-07 12032]
      R3 pepifilter;Volume Adapter; C:\Windows\system32\DRIVERS\lv302af.sys [2007-05-09 14112]
      R3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\Windows\system32\DRIVERS\LV302V32.SYS [2007-05-09 1276832]
      R3 RTL85n86;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver; C:\Windows\system32\DRIVERS\RTL85n86.sys [2007-01-25 341504]
      R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
      R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
      R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
      S3 61883;Pilote d'unité 61883; C:\Windows\system32\DRIVERS\61883.sys [2008-01-21 45696]
      S3 Avc;Périphérique AVC; C:\Windows\system32\DRIVERS\avc.sys [2008-01-21 40448]
      S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
      S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
      S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2008-01-21 52608]
      S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
      S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
      S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
      S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
      S3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-03-21 6144]
      S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
      S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
      S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
      S4 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iastor.sys [2006-06-13 247808]
      S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

      ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

      R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service; C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448]
      R2 Acer TV Share Service;Acer TV Share Service; C:\Program Files\Acer Arcade Live\Acer TV Share\Kernel\DMSTV\CLMSServer.exe [2008-07-22 270426]
      R2 AcerMemUsageCheckService;ePerformance Service; C:\Acer\Empowering Technology\ePerformance\MemCheck.exe [2007-10-17 28672]
      R2 avg9emc;AVG E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2009-11-21 906520]
      R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2009-11-21 285392]
      R2 avgfws9;AVG Firewall; C:\Program Files\AVG\AVG9\avgfws9.exe [2010-01-14 2304192]
      R2 AVGIDSAgent;AVG9IDSAgent; C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2009-11-21 5832712]
      R2 eDataSecurity Service;eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-03-04 500784]
      R2 eRecoveryService;eRecovery Service; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [2007-09-10 57344]
      R2 eSettingsService;eSettings Service; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-12-19 24576]
      R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
      R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-03-27 207392]
      R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2008-06-13 241734]
      R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
      R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
      S2 gupdate1ca98f2ccd3d08b;Service Google Update (gupdate1ca98f2ccd3d08b); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-19 133104]
      S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 183280]

      -----------------EOF-----------------
      0
  2. Contributeur sécurité
    arrêtes Ad remover pour l'instant

    et tu fais ceci

    1)

    Téléchargez USBFIX de El Desaparecido, C_xx

    http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
    ou
    https://www.ionos.fr/?affiliate_id=77097

    /!\ Utilisateur de vista et windows 7 :
    ne pas oublier de désactiver Le contrôle des comptes utilisateurs
    https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

    /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

    • Double clic sur le raccourci UsbFix présent sur le bureau .

    Choisir l'option2 suppression
    (d’autres options disponibles, voir le tutoriel).
    • Laissez travailler l'outil.
    Le menu démarrer et les icônes vont disparaître.. c'est normal.

    Si un message te demande de redémarrer l'ordinateur fais le ...

    ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

    ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

    • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

    ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

    • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

    • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

    UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

    Il est enregistré sur ton bureau.

    Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

    ......................

    2)

    rends toi ici et fais le test

    http://consultaide.e-monsite.com/rubrique,conficker-simples-tests,355935.html

    0
    1. re salut Moment De Grace,

      La deuxième tentative en mode sans échec s'est soldé par un blocage à environ 40% jusqu'à ce que tu me dises de laisser tomber.

      Concernant USBFix, voilà maintenant en tous cas 15minutes qu'il est bloqué sur 10%... Est ce normal? rien ne se passe...

      Merci.
      0
  3. oups c'est bon ca repart de plus belle juste au moment ou j'ai posté le msg. :) désolé.

    Je te tiens au courant...
    0
    1. Contributeur sécurité
      ca peut être long

      tu es bien infecté
      0
      1. Contributeur sécurité
        en complément du post précédent

        si ca séternise

        redemarres le pc et fais usbfix
        Option 4 = nettoyage ( mode sans echec sans redémarrage )
        0
        1. Salut Moment de Grace,

          Voila, j'ai fais le test aussi (confiker): je vois bien tous les logo comme ca doit être.

          Et malgré tout toujours le même problème. La fenêtre pop up ne m'a pas laché même pendant l'analyse USB Fix: fallait que j'appui n continu sur enter pour fermer la fenetre sans quoi tout bloque...

          Oh désespoir... :P
          0
      2. Contributeur sécurité
        ok

        usbfix option 4 alors...
        0
        1. Salut Moment de Grace,

          Voilà donc, j'ai enfin exécuter l'option 4 faire, et toujours le même souci... :(

          Y aurait il une autre option?

          Salutations à toi et à l'équipe!

          Kal
          0
      3. Contributeur sécurité
        oui une option plus virile...

        Attention, avant de commencer, lit attentivement la procédure, et imprime la

        Télécharge ComboFix de sUBs sur ton Bureau :

        http://download.bleepingcomputer.com/sUBs/ComboFix.exe

        /!\ Déconnecte-toi du net et DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\

        ---> Double-clique sur ComboFix.exe
        Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

        SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
        (si il te propose de l’installer remets provisoirement internet)

        ---> Mets-le en langue française F
        Tape sur la touche 1 (Yes) pour démarrer le scan.

        Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

        En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

        Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

        /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

        Note : Le rapport se trouve également là : C:\ComboFix.txt

        0
        1. reSalut,

          Juste une chose avant de commener avec ComboFix: comment je fais pour "installer la console de récupération"?
          0
      4. Contributeur sécurité
        ca bug sévère

        tes posts ont disparus

        pour ta question

        https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

        0
        1. oups, ouaip la crise là dis donc... Pas grave, le sujet est cerné. :)

          Alors voilà, j'ai lancé comboFix comme expliqué. Et depuis, tout semble refonctionner normalement. Finis les pop up!! Yeah!! :)

          J'ai remis AVG, et le controle utilisateur.

          J'ai cru comprendre que même si les problème est résolu il faut envoyer le rapport. Alors je vais t'envoyer dans le prochain msg le résultat de comboFix.

          Est ce que maintenant je peux effacer comboFix, AD-R, R-SIT ?

          A tout de suite! MERCI mille fois surtout!

          Kal
          0
        2. @kaldorakvoilà donc le résultat.

          Avant, surtout, un grand merci pour ce dépannage corriace à toi Moment De Grace! Et un grand Olé à la team de CCM.com!

          Je reste à l'écoute si jamais suite au résultat de comboFix il y aurait une précaution à prendre afin de prévenir ce souci.

          Salutations.

          Kal

          **************************************************************************

          ComboFix 10-02-12.01 - Khalid 13.02.2010 19:43:15.1.4 - x86
          Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.41.1036.18.3070.1956 [GMT 1:00]
          Lancé depuis: c:\users\Khalid\Desktop\ComboFix.exe
          SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
          c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
          c:\users\Khalid\AppData\Roaming\.#

          ----- BITS: Il y a peut-être des sites infectés -----

          hxxp://armmf.adobe.com
          .
          ((((((((((((((((((((((((((((( Fichiers créés du 2010-01-13 au 2010-02-13 ))))))))))))))))))))))))))))))))))))
          .

          2010-02-13 18:50 . 2010-02-13 18:50 -------- d-----w- c:\users\Khalid\AppData\Local\temp
          2010-02-13 18:50 . 2010-02-13 18:50 -------- d-----w- c:\users\Default\AppData\Local\temp
          2010-02-11 22:39 . 2010-02-12 17:37 1393 ----a-w- C:\UsbFix_Upload_Me_PC-de-Khalid.zip
          2010-02-11 22:08 . 2010-02-12 17:47 -------- d-----w- C:\UsbFix
          2010-02-11 21:05 . 2010-02-11 21:05 -------- d-----w- C:\rsit
          2010-02-11 21:05 . 2010-02-11 21:05 -------- d-----w- c:\program files\trend micro
          2010-02-11 20:44 . 2010-02-11 22:05 -------- d-----w- C:\Ad-Remover
          2010-02-11 19:36 . 2010-02-11 19:36 -------- d-----w- c:\program files\CCleaner
          2010-02-09 19:40 . 2010-02-09 19:44 -------- d-----w- c:\users\Khalid\AppData\Local\Deployment
          2010-02-09 19:40 . 2010-02-09 19:40 -------- d-----w- c:\users\Khalid\AppData\Local\Apps
          2010-01-24 19:21 . 2010-01-24 19:21 15884 ----a-w- c:\users\Khalid\AppData\Roaming\Azureus\plugins\azitunes\libProcessAccess.dll
          2010-01-24 19:21 . 2010-01-24 19:21 102400 ----a-w- c:\users\Khalid\AppData\Roaming\Azureus\plugins\azitunes\jacob-1.14.3-x86.dll
          2010-01-24 19:21 . 2010-01-24 19:21 4141117 ----a-w- c:\users\Khalid\AppData\Roaming\Azureus\plugins\vuzexcode\mediainfo.exe
          2010-01-24 19:21 . 2010-01-24 19:21 6516755 ----a-w- c:\users\Khalid\AppData\Roaming\Azureus\plugins\vuzexcode\ffmpeg.exe
          2010-01-19 10:32 . 2010-01-19 10:32 -------- d-----w- c:\program files\Common Files\DivX Shared

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2010-02-13 18:48 . 2008-01-21 08:40 669328 ----a-w- c:\windows\system32\perfh00C.dat
          2010-02-13 18:48 . 2008-01-21 08:40 123350 ----a-w- c:\windows\system32\perfc00C.dat
          2010-02-13 18:30 . 2009-11-21 19:15 -------- d-----w- c:\programdata\avg9
          2010-02-13 16:48 . 2009-03-09 18:25 -------- d-----w- c:\programdata\Google Updater
          2010-02-11 23:43 . 2009-03-07 23:30 -------- d-----w- c:\users\Khalid\AppData\Roaming\Azureus
          2010-02-11 10:00 . 2009-03-07 16:32 -------- d-----w- c:\program files\Google
          2010-02-06 17:59 . 2009-12-11 19:50 439816 ----a-w- c:\users\Khalid\AppData\Roaming\Real\Update\setup3.09\setup.exe
          2010-02-02 20:45 . 2009-03-24 19:43 -------- d-----w- c:\users\Khalid\AppData\Roaming\dvdcss
          2010-01-22 14:13 . 2009-10-02 13:34 -------- d-----w- c:\program files\Microsoft Silverlight
          2010-01-19 10:33 . 2009-07-05 17:00 -------- d-----w- c:\program files\DivX
          2010-01-14 14:10 . 2010-01-14 14:10 2091768 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
          2010-01-06 13:16 . 2009-03-08 11:23 -------- d-----w- c:\users\Khalid\AppData\Roaming\Skype
          2010-01-06 12:52 . 2009-03-08 11:25 -------- d-----w- c:\users\Khalid\AppData\Roaming\skypePM
          2010-01-02 06:38 . 2010-01-22 19:38 916480 ----a-w- c:\windows\system32\wininet.dll
          2010-01-02 06:32 . 2010-01-22 19:38 71680 ----a-w- c:\windows\system32\iesetup.dll
          2010-01-02 06:32 . 2010-01-22 19:38 109056 ----a-w- c:\windows\system32\iesysprep.dll
          2010-01-02 04:57 . 2010-01-22 19:38 133632 ----a-w- c:\windows\system32\ieUnatt.exe
          2009-12-28 13:20 . 2009-03-07 23:30 -------- d-----w- c:\program files\Vuze
          2009-12-28 13:20 . 2009-04-30 21:23 176 ----a-w- c:\users\Khalid\AppData\Roaming\Azureus\restart.bat
          2009-12-23 20:25 . 2009-09-22 18:28 -------- d-----w- c:\program files\Common Files\Adobe
          2009-12-22 22:19 . 2009-09-06 21:34 -------- d-----w- c:\users\Khalid\AppData\Roaming\Audacity
          2009-12-16 20:29 . 2009-07-21 22:02 612 ----a-w- c:\users\Khalid\AppData\Roaming\wklnhst.dat
          2009-12-11 11:43 . 2010-02-10 18:04 302080 ----a-w- c:\windows\system32\drivers\srv.sys
          2009-12-11 11:43 . 2010-02-10 18:04 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
          2009-12-08 20:01 . 2010-02-10 18:04 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
          2009-12-08 20:01 . 2010-02-10 18:04 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
          2009-12-08 20:01 . 2010-02-10 18:04 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
          2009-12-08 17:26 . 2010-02-10 18:04 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
          2009-12-04 18:30 . 2010-02-10 18:04 12288 ----a-w- c:\windows\system32\tsbyuv.dll
          2009-12-04 18:29 . 2010-02-10 18:04 1314816 ----a-w- c:\windows\system32\quartz.dll
          2009-12-04 18:28 . 2010-02-10 18:04 22528 ----a-w- c:\windows\system32\msyuv.dll
          2009-12-04 18:28 . 2010-02-10 18:04 31744 ----a-w- c:\windows\system32\msvidc32.dll
          2009-12-04 18:28 . 2010-02-10 18:04 123904 ----a-w- c:\windows\system32\msvfw32.dll
          2009-12-04 18:28 . 2010-02-10 18:04 13312 ----a-w- c:\windows\system32\msrle32.dll
          2009-12-04 18:28 . 2010-02-10 18:04 82944 ----a-w- c:\windows\system32\mciavi32.dll
          2009-12-04 18:28 . 2010-02-10 18:04 50176 ----a-w- c:\windows\system32\iyuv_32.dll
          2009-12-04 18:27 . 2010-02-10 18:04 91136 ----a-w- c:\windows\system32\avifil32.dll
          2009-12-04 15:56 . 2010-02-10 18:04 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
          2009-12-04 15:56 . 2010-02-10 18:04 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
          2009-12-04 09:03 . 2009-12-04 09:03 251376 ----a-w- c:\users\Khalid\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
          2009-11-27 17:16 . 2009-03-07 16:33 100952 ----a-w- c:\users\Khalid\AppData\Local\GDIPFONTCACHEV1.DAT
          2009-11-27 17:15 . 2009-11-27 17:15 29926 ----a-r- c:\users\Khalid\AppData\Roaming\Microsoft\Installer\{6DE721A5-5E89-4D74-994C-652BB3C0672E}\ARPPRODUCTICON.exe
          2009-11-18 15:18 . 2009-10-28 17:18 3775256 ----a-w- c:\programdata\TEMP\AVG\setup.exe
          .

          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
          @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
          [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
          2008-03-04 22:38 121392 ----a-w- c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
          "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-07 68856]
          "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
          "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
          "Google Update"="c:\users\Khalid\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-05-07 133104]
          "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144]
          "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
          "RtHDVCpl"="RtHDVCpl.exe" [2008-03-26 5369856]
          "Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2008-01-09 326176]
          "eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896]
          "WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
          "NVRaidService"="c:\windows\system32\nvraidservice.exe" [2008-06-06 203296]
          "PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-05-20 204908]
          "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-20 198160]
          "QuickTime Task"="c:\program files\QuickTime Alternative\QTTask.exe" [2007-10-19 286720]
          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
          "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]
          "USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
          "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
          "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

          c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
          ASETRES.EXE [2008-4-14 20480]
          Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2008-3-21 535336]
          Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
          "EnableLUA"= 0 (0x0)
          "EnableUIADesktopToggle"= 0 (0x0)

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
          "HonorAutoRunSetting"= 0 (0x0)

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
          "HonorAutoRunSetting"= 0 (0x0)

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
          @="Service"

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
          "VistaSp2"=hex(b):cf,7b,6b,1e,8f,60,ca,01

          R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [08.03.2009 01:51 269448]
          R2 Acer TV Share Service;Acer TV Share Service;c:\program files\Acer Arcade Live\Acer TV Share\Kernel\DMSTV\CLMSServer.exe [08.03.2009 01:55 270426]
          R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [13.11.2009 12:31 92008]
          R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\System32\drivers\HCW85BDA.sys [08.03.2009 02:18 1129344]
          R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [08.03.2009 02:18 42528]
          R3 RTL85n86;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;c:\windows\System32\drivers\RTL85n86.sys [21.03.2008 19:49 341504]
          S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [26.03.2009 19:10 717296]
          S2 gupdate1ca98f2ccd3d08b;Service Google Update (gupdate1ca98f2ccd3d08b);c:\program files\Google\Update\GoogleUpdate.exe [19.01.2010 11:33 133104]
          .
          Contenu du dossier 'Tâches planifiées'

          2010-02-13 c:\windows\Tasks\Google Software Updater.job
          - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-07 01:26]

          2010-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
          - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-19 10:33]

          2010-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
          - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-19 10:33]

          2010-02-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4088667415-2200540918-1335641831-1000Core.job
          - c:\users\Khalid\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-20 16:35]

          2010-02-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4088667415-2200540918-1335641831-1000UA.job
          - c:\users\Khalid\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-20 16:35]

          2010-02-13 c:\windows\Tasks\User_Feed_Synchronization-{D40D0641-247C-4951-9434-4536AB39A9A9}.job
          - c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
          .
          .
          ------- Examen supplémentaire -------
          .
          uStart Page = hxxp://www.google.ch/
          IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
          DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
          .
          - - - - ORPHELINS SUPPRIMES - - - -

          BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\AskBarDis\bar\bin\askBar.dll
          Toolbar-{3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\AskBarDis\bar\bin\askBar.dll
          Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
          WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - c:\program files\AskBarDis\bar\bin\askBar.dll
          WebBrowser-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
          WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
          HKLM-Run-Apanel - c:\acersw\config\SetApanel.cmd
          HKLM-Run-eRecoveryService - (no file)
          AddRemove-Ask Toolbar_is1 - c:\program files\AskBarDis\unins000.exe

          **************************************************************************

          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2010-02-13 19:50
          Windows 6.0.6002 Service Pack 2 NTFS

          Recherche de processus cachés ...

          Recherche d'éléments en démarrage automatique cachés ...

          Recherche de fichiers cachés ...

          Scan terminé avec succès
          Fichiers cachés: 0

          **************************************************************************
          .
          Heure de fin: 2010-02-13 19:52:18
          ComboFix-quarantined-files.txt 2010-02-13 18:52

          Avant-CF: 164'557'094'912 octets libres
          Après-CF: 163'847'585'792 octets libres

          - - End Of File - - 205A0D81742240FD1DABF181B320BA16
          0
      5. Contributeur sécurité
        vas pas trop vite

        et colles ici le rapport combo stp
        0
        1. Contributeur sécurité
          ----- BITS: Il y a peut-être des sites infectés -----

          hxxp://armmf.adobe.com


          je ne connais pas ca...

          relances RSIT et postes le rapport log stp

          (les outils tu les gardes pour l'instant)

          0
          1. Logfile of random's system information tool 1.06 (written by random/random)
            Run by Khalid at 2010-02-13 23:40:58
            Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
            System drive C: has 160 GB (53%) free of 300 GB
            Total RAM: 3070 MB (59% free)

            HijackThis download failed

            ======Scheduled tasks folder======

            C:\Windows\tasks\Google Software Updater.job
            C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
            C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
            C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4088667415-2200540918-1335641831-1000Core.job
            C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4088667415-2200540918-1335641831-1000UA.job
            C:\Windows\tasks\User_Feed_Synchronization-{D40D0641-247C-4951-9434-4536AB39A9A9}.job

            ======Registry dump======

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
            Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
            RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-03-20 312928]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
            AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-02-13 1484056]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
            Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
            ShowBarObj Class - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-03-04 312880]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
            Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
            AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
            Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-10-31 764912]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
            Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
            {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-03-04 142896]
            {0BF43445-2F28-4351-9252-17FE6E806AA0}
            {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
            {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
            "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-03-26 5369856]
            "Acer Empowering Technology Monitor"=C:\Acer\Empowering Technology\SysMonitor.exe [2008-01-09 326176]
            "eDataSecurity Loader"=C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [2008-03-04 526896]
            "WarReg_PopUp"=C:\Acer\WR_PopUp\WarReg_PopUp.exe [2006-11-05 57344]
            "NVRaidService"=C:\Windows\system32\nvraidservice.exe [2008-06-06 203296]
            "PCMMediaSharing"=C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [2008-05-20 204908]
            "TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-03-20 198160]
            "QuickTime Task"=C:\Program Files\QuickTime Alternative\QTTask.exe [2007-10-19 286720]
            "NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-03-27 13687328]
            "NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2009-03-27 92704]
            "USBToolTip"=C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [2007-02-20 199752]
            "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
            "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
            "AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-02-13 2033432]

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
            "WindowsWelcomeCenter"=oobefldr.dll,ShowWelcomeCenter []
            "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-07 68856]
            "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
            "msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
            "Google Update"=C:\Users\Khalid\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-07 133104]
            "TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2009-11-13 247144]
            "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

            C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
            ASETRES.EXE
            Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe
            Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLS"="avgrsstx.dll"

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
            "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
            "dontdisplaylastusername"=0
            "legalnoticecaption"=
            "legalnoticetext"=
            "shutdownwithoutlogon"=1
            "undockwithoutlogon"=1
            "EnableUIADesktopToggle"=0

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "NoDriveAutoRun"=255
            "NoDriveTypeAutoRun"=255
            "HonorAutoRunSetting"=0
            "NoDrives"=0

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "BindDirectlyToPropertySetStorage"=
            "NoDriveAutoRun"=
            "NoDriveTypeAutoRun"=
            "HonorAutoRunSetting"=
            "NoDrives"=

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

            ======File associations======

            .js - edit - C:\Windows\System32\Notepad.exe %1

            ======List of files/folders created in the last 1 months======

            2010-02-13 20:11:29 ----D---- C:\ProgramData\Downloaded Installations
            2010-02-13 20:11:08 ----A---- C:\Windows\system32\avgrsstx.dll
            2010-02-13 20:11:01 ----D---- C:\ProgramData\AVG Security Toolbar
            2010-02-13 19:52:21 ----SHD---- C:\$RECYCLE.BIN
            2010-02-13 19:52:18 ----A---- C:\ComboFix.txt
            2010-02-13 19:41:46 ----A---- C:\Windows\zip.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\SWSC.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\SWREG.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\sed.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\PEV.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\NIRCMD.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\MBR.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\grep.exe
            2010-02-13 19:41:33 ----D---- C:\Windows\ERDNT
            2010-02-13 19:39:19 ----D---- C:\ComboFix
            2010-02-13 19:38:13 ----A---- C:\Windows\SWXCACLS.exe
            2010-02-13 18:58:49 ----D---- C:\Qoobox
            2010-02-12 18:26:04 ----RAD---- C:\autorun.inf
            2010-02-12 18:21:03 ----A---- C:\Windows\ntbtlog.txt
            2010-02-11 23:42:05 ----A---- C:\UsbFixrapport.txt
            2010-02-11 23:08:51 ----D---- C:\UsbFix
            2010-02-11 22:05:06 ----D---- C:\rsit
            2010-02-11 22:05:06 ----D---- C:\Program Files\trend micro
            2010-02-11 21:44:16 ----D---- C:\Ad-Remover
            2010-02-11 20:36:45 ----D---- C:\Program Files\CCleaner
            2010-02-10 19:04:18 ----A---- C:\Windows\system32\ntoskrnl.exe
            2010-02-10 19:04:18 ----A---- C:\Windows\system32\ntkrnlpa.exe
            2010-02-10 19:04:16 ----A---- C:\Windows\system32\quartz.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\tsbyuv.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\msyuv.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\msvidc32.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\msvfw32.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\msrle32.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\mciavi32.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\iyuv_32.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\avifil32.dll
            2010-01-22 20:38:06 ----A---- C:\Windows\system32\mshtml.dll
            2010-01-22 20:38:06 ----A---- C:\Windows\system32\ieframe.dll
            2010-01-22 20:38:05 ----A---- C:\Windows\system32\wininet.dll
            2010-01-22 20:38:05 ----A---- C:\Windows\system32\urlmon.dll
            2010-01-22 20:38:05 ----A---- C:\Windows\system32\occache.dll
            2010-01-22 20:38:05 ----A---- C:\Windows\system32\msfeeds.dll
            2010-01-22 20:38:05 ----A---- C:\Windows\system32\iertutil.dll
            2010-01-22 20:38:05 ----A---- C:\Windows\system32\iedkcs32.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\msfeedssync.exe
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\msfeedsbs.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\jsproxy.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\ieUnatt.exe
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\ieui.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\iesysprep.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\iesetup.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\iernonce.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\iepeers.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\ie4uinit.exe
            2010-01-19 11:32:59 ----D---- C:\Program Files\Common Files\DivX Shared

            ======List of files/folders modified in the last 1 months======

            2010-02-13 23:40:55 ----D---- C:\Windows\Temp
            2010-02-13 21:00:17 ----SHD---- C:\System Volume Information
            2010-02-13 20:45:12 ----AD---- C:\Windows\System32
            2010-02-13 20:45:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
            2010-02-13 20:45:11 ----D---- C:\Windows\inf
            2010-02-13 20:41:35 ----D---- C:\Windows\system32\catroot2
            2010-02-13 20:41:19 ----D---- C:\Windows\Tasks
            2010-02-13 20:35:23 ----D---- C:\Windows\system32\drivers
            2010-02-13 20:35:23 ----D---- C:\ProgramData
            2010-02-13 20:34:51 ----D---- C:\ProgramData\avg9
            2010-02-13 20:34:43 ----SHD---- C:\Windows\Installer
            2010-02-13 20:34:24 ----D---- C:\Windows
            2010-02-13 20:10:31 ----D---- C:\Windows\system32\catroot
            2010-02-13 19:55:26 ----HD---- C:\Windows\system32\GroupPolicy
            2010-02-13 19:50:43 ----A---- C:\Windows\system.ini
            2010-02-13 19:47:11 ----D---- C:\Windows\AppPatch
            2010-02-13 19:47:10 ----D---- C:\Program Files\Common Files
            2010-02-13 17:48:00 ----D---- C:\ProgramData\Google Updater
            2010-02-13 17:45:52 ----RD---- C:\Program Files
            2010-02-12 00:43:16 ----D---- C:\Windows\Minidump
            2010-02-12 00:43:16 ----D---- C:\Windows\Debug
            2010-02-12 00:43:16 ----D---- C:\Users\Khalid\AppData\Roaming\Azureus
            2010-02-11 23:28:14 ----SD---- C:\Windows\Downloaded Program Files
            2010-02-11 21:23:53 ----D---- C:\Windows\system32\WDI
            2010-02-11 21:23:20 ----D---- C:\Windows\Prefetch
            2010-02-11 11:00:42 ----D---- C:\Program Files\Google
            2010-02-11 10:50:21 ----D---- C:\Windows\winsxs
            2010-02-02 21:45:59 ----D---- C:\Users\Khalid\AppData\Roaming\dvdcss
            2010-02-01 20:26:20 ----A---- C:\Windows\system32\mrt.exe
            2010-01-23 03:15:44 ----D---- C:\Windows\system32\migration
            2010-01-23 03:15:43 ----D---- C:\Program Files\Internet Explorer
            2010-01-22 15:13:04 ----D---- C:\Program Files\Microsoft Silverlight
            2010-01-19 11:43:45 ----D---- C:\Windows\system32\Tasks
            2010-01-19 11:33:02 ----D---- C:\Program Files\DivX
            2010-01-14 11:12:06 ----N---- C:\Windows\system32\MpSigStub.exe

            ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2010-02-13 24856]
            R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2010-02-13 333192]
            R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2010-02-13 28424]
            R1 AvgTdiX;AVG8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2010-02-13 360584]
            R2 int15;int15; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys [2007-07-03 15392]
            R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-03-04 16944]
            R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-03-04 60464]
            R2 tvicport;tvicport; \??\C:\Windows\system32\drivers\tvicport.sys [2007-11-06 14544]
            R2 zntport;zntport; \??\C:\Windows\system32\drivers\zntport.sys [2007-11-06 6080]
            R3 AVGIDSDrivervtx;AVG9IDSDriver; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [2010-02-13 122376]
            R3 AVGIDSFiltervtx;AVG9IDSFilter; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [2010-02-13 30216]
            R3 AVGIDSShimvtx;AVG9IDSShim; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [2010-02-13 27800]
            R3 HCW85BDA;Hauppauge WinTV 885 Video Capture; C:\Windows\system32\drivers\HCW85BDA.sys [2007-10-01 1129344]
            R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-03-26 2103512]
            R3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys [2007-05-09 41888]
            R3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
            R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-11-18 1040544]
            R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2008-04-28 42528]
            R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-03-27 7738816]
            R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2007-07-07 12032]
            R3 pepifilter;Volume Adapter; C:\Windows\system32\DRIVERS\lv302af.sys [2007-05-09 14112]
            R3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\Windows\system32\DRIVERS\LV302V32.SYS [2007-05-09 1276832]
            R3 RTL85n86;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver; C:\Windows\system32\DRIVERS\RTL85n86.sys [2007-01-25 341504]
            R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
            R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
            S3 61883;Pilote d'unité 61883; C:\Windows\system32\DRIVERS\61883.sys [2008-01-21 45696]
            S3 Avc;Périphérique AVC; C:\Windows\system32\DRIVERS\avc.sys [2008-01-21 40448]
            S3 catchme;catchme; \??\C:\Users\Khalid\AppData\Local\Temp\catchme.sys []
            S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
            S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
            S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2008-01-21 52608]
            S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
            S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
            S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
            S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
            S3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-03-21 6144]
            S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
            S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
            S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
            S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
            S4 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iastor.sys [2006-06-13 247808]
            S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

            ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service; C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448]
            R2 Acer TV Share Service;Acer TV Share Service; C:\Program Files\Acer Arcade Live\Acer TV Share\Kernel\DMSTV\CLMSServer.exe [2008-07-22 270426]
            R2 AcerMemUsageCheckService;ePerformance Service; C:\Acer\Empowering Technology\ePerformance\MemCheck.exe [2007-10-17 28672]
            R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-02-13 285392]
            R2 avgfws9;AVG Firewall; C:\Program Files\AVG\AVG9\avgfws9.exe [2010-02-13 2304192]
            R2 AVGIDSAgent;AVG9IDSAgent; C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-02-13 5832712]
            R2 eDataSecurity Service;eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-03-04 500784]
            R2 eRecoveryService;eRecovery Service; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [2007-09-10 57344]
            R2 eSettingsService;eSettings Service; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-12-19 24576]
            R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
            R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-03-27 207392]
            R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2008-06-13 241734]
            R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
            R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
            S2 gupdate1ca98f2ccd3d08b;Service Google Update (gupdate1ca98f2ccd3d08b); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-19 133104]
            S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 183280]

            -----------------EOF-----------------
            0
          2. @kaldorakMoment De Grace,

            Je te file le rapport AVEC les clés usb et le disque dur externe brachés... Sorry de ne pas l'avoir fait avant. Voici ce que cela donne:

            Logfile of random's system information tool 1.06 (written by random/random)
            Run by Khalid at 2010-02-13 23:46:13
            Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
            System drive C: has 160 GB (53%) free of 300 GB
            Total RAM: 3070 MB (56% free)

            HijackThis download failed

            ======Scheduled tasks folder======

            C:\Windows\tasks\Google Software Updater.job
            C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
            C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
            C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4088667415-2200540918-1335641831-1000Core.job
            C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4088667415-2200540918-1335641831-1000UA.job
            C:\Windows\tasks\User_Feed_Synchronization-{D40D0641-247C-4951-9434-4536AB39A9A9}.job

            ======Registry dump======

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
            Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
            RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-03-20 312928]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
            AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-02-13 1484056]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
            Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
            ShowBarObj Class - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-03-04 312880]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
            Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
            AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
            Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-10-31 764912]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
            Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
            {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-03-04 142896]
            {0BF43445-2F28-4351-9252-17FE6E806AA0}
            {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
            {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
            "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-03-26 5369856]
            "Acer Empowering Technology Monitor"=C:\Acer\Empowering Technology\SysMonitor.exe [2008-01-09 326176]
            "eDataSecurity Loader"=C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [2008-03-04 526896]
            "WarReg_PopUp"=C:\Acer\WR_PopUp\WarReg_PopUp.exe [2006-11-05 57344]
            "NVRaidService"=C:\Windows\system32\nvraidservice.exe [2008-06-06 203296]
            "PCMMediaSharing"=C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [2008-05-20 204908]
            "TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-03-20 198160]
            "QuickTime Task"=C:\Program Files\QuickTime Alternative\QTTask.exe [2007-10-19 286720]
            "NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-03-27 13687328]
            "NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2009-03-27 92704]
            "USBToolTip"=C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [2007-02-20 199752]
            "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
            "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
            "AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-02-13 2033432]

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
            "WindowsWelcomeCenter"=oobefldr.dll,ShowWelcomeCenter []
            "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-07 68856]
            "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
            "msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
            "Google Update"=C:\Users\Khalid\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-07 133104]
            "TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2009-11-13 247144]
            "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

            C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
            ASETRES.EXE
            Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe
            Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLS"="avgrsstx.dll"

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
            "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
            "dontdisplaylastusername"=0
            "legalnoticecaption"=
            "legalnoticetext"=
            "shutdownwithoutlogon"=1
            "undockwithoutlogon"=1
            "EnableUIADesktopToggle"=0

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "NoDriveAutoRun"=255
            "NoDriveTypeAutoRun"=255
            "HonorAutoRunSetting"=0
            "NoDrives"=0

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "BindDirectlyToPropertySetStorage"=
            "NoDriveAutoRun"=
            "NoDriveTypeAutoRun"=
            "HonorAutoRunSetting"=
            "NoDrives"=

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

            ======File associations======

            .js - edit - C:\Windows\System32\Notepad.exe %1

            ======List of files/folders created in the last 1 months======

            2010-02-13 20:11:29 ----D---- C:\ProgramData\Downloaded Installations
            2010-02-13 20:11:08 ----A---- C:\Windows\system32\avgrsstx.dll
            2010-02-13 20:11:01 ----D---- C:\ProgramData\AVG Security Toolbar
            2010-02-13 19:52:21 ----SHD---- C:\$RECYCLE.BIN
            2010-02-13 19:52:18 ----A---- C:\ComboFix.txt
            2010-02-13 19:41:46 ----A---- C:\Windows\zip.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\SWSC.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\SWREG.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\sed.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\PEV.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\NIRCMD.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\MBR.exe
            2010-02-13 19:41:46 ----A---- C:\Windows\grep.exe
            2010-02-13 19:41:33 ----D---- C:\Windows\ERDNT
            2010-02-13 19:39:19 ----D---- C:\ComboFix
            2010-02-13 19:38:13 ----A---- C:\Windows\SWXCACLS.exe
            2010-02-13 18:58:49 ----D---- C:\Qoobox
            2010-02-12 18:26:04 ----RAD---- C:\autorun.inf
            2010-02-12 18:21:03 ----A---- C:\Windows\ntbtlog.txt
            2010-02-11 23:42:05 ----A---- C:\UsbFixrapport.txt
            2010-02-11 23:08:51 ----D---- C:\UsbFix
            2010-02-11 22:05:06 ----D---- C:\rsit
            2010-02-11 22:05:06 ----D---- C:\Program Files\trend micro
            2010-02-11 21:44:16 ----D---- C:\Ad-Remover
            2010-02-11 20:36:45 ----D---- C:\Program Files\CCleaner
            2010-02-10 19:04:18 ----A---- C:\Windows\system32\ntoskrnl.exe
            2010-02-10 19:04:18 ----A---- C:\Windows\system32\ntkrnlpa.exe
            2010-02-10 19:04:16 ----A---- C:\Windows\system32\quartz.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\tsbyuv.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\msyuv.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\msvidc32.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\msvfw32.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\msrle32.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\mciavi32.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\iyuv_32.dll
            2010-02-10 19:04:15 ----A---- C:\Windows\system32\avifil32.dll
            2010-01-22 20:38:06 ----A---- C:\Windows\system32\mshtml.dll
            2010-01-22 20:38:06 ----A---- C:\Windows\system32\ieframe.dll
            2010-01-22 20:38:05 ----A---- C:\Windows\system32\wininet.dll
            2010-01-22 20:38:05 ----A---- C:\Windows\system32\urlmon.dll
            2010-01-22 20:38:05 ----A---- C:\Windows\system32\occache.dll
            2010-01-22 20:38:05 ----A---- C:\Windows\system32\msfeeds.dll
            2010-01-22 20:38:05 ----A---- C:\Windows\system32\iertutil.dll
            2010-01-22 20:38:05 ----A---- C:\Windows\system32\iedkcs32.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\msfeedssync.exe
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\msfeedsbs.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\jsproxy.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\ieUnatt.exe
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\ieui.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\iesysprep.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\iesetup.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\iernonce.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\iepeers.dll
            2010-01-22 20:38:04 ----A---- C:\Windows\system32\ie4uinit.exe
            2010-01-19 11:32:59 ----D---- C:\Program Files\Common Files\DivX Shared

            ======List of files/folders modified in the last 1 months======

            2010-02-13 23:46:14 ----D---- C:\Windows\Temp
            2010-02-13 21:00:17 ----SHD---- C:\System Volume Information
            2010-02-13 20:45:12 ----AD---- C:\Windows\System32
            2010-02-13 20:45:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
            2010-02-13 20:45:11 ----D---- C:\Windows\inf
            2010-02-13 20:41:35 ----D---- C:\Windows\system32\catroot2
            2010-02-13 20:41:19 ----D---- C:\Windows\Tasks
            2010-02-13 20:35:23 ----D---- C:\Windows\system32\drivers
            2010-02-13 20:35:23 ----D---- C:\ProgramData
            2010-02-13 20:34:51 ----D---- C:\ProgramData\avg9
            2010-02-13 20:34:43 ----SHD---- C:\Windows\Installer
            2010-02-13 20:34:24 ----D---- C:\Windows
            2010-02-13 20:10:31 ----D---- C:\Windows\system32\catroot
            2010-02-13 19:55:26 ----HD---- C:\Windows\system32\GroupPolicy
            2010-02-13 19:50:43 ----A---- C:\Windows\system.ini
            2010-02-13 19:47:11 ----D---- C:\Windows\AppPatch
            2010-02-13 19:47:10 ----D---- C:\Program Files\Common Files
            2010-02-13 17:48:00 ----D---- C:\ProgramData\Google Updater
            2010-02-13 17:45:52 ----RD---- C:\Program Files
            2010-02-12 00:43:16 ----D---- C:\Windows\Minidump
            2010-02-12 00:43:16 ----D---- C:\Windows\Debug
            2010-02-12 00:43:16 ----D---- C:\Users\Khalid\AppData\Roaming\Azureus
            2010-02-11 23:28:14 ----SD---- C:\Windows\Downloaded Program Files
            2010-02-11 21:23:53 ----D---- C:\Windows\system32\WDI
            2010-02-11 21:23:20 ----D---- C:\Windows\Prefetch
            2010-02-11 11:00:42 ----D---- C:\Program Files\Google
            2010-02-11 10:50:21 ----D---- C:\Windows\winsxs
            2010-02-02 21:45:59 ----D---- C:\Users\Khalid\AppData\Roaming\dvdcss
            2010-02-01 20:26:20 ----A---- C:\Windows\system32\mrt.exe
            2010-01-23 03:15:44 ----D---- C:\Windows\system32\migration
            2010-01-23 03:15:43 ----D---- C:\Program Files\Internet Explorer
            2010-01-22 15:13:04 ----D---- C:\Program Files\Microsoft Silverlight
            2010-01-19 11:43:45 ----D---- C:\Windows\system32\Tasks
            2010-01-19 11:33:02 ----D---- C:\Program Files\DivX
            2010-01-14 11:12:06 ----N---- C:\Windows\system32\MpSigStub.exe

            ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R1 Avgfwfd;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6x.sys [2010-02-13 24856]
            R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2010-02-13 333192]
            R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2010-02-13 28424]
            R1 AvgTdiX;AVG8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2010-02-13 360584]
            R2 int15;int15; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys [2007-07-03 15392]
            R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-03-04 16944]
            R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-03-04 60464]
            R2 tvicport;tvicport; \??\C:\Windows\system32\drivers\tvicport.sys [2007-11-06 14544]
            R2 zntport;zntport; \??\C:\Windows\system32\drivers\zntport.sys [2007-11-06 6080]
            R3 AVGIDSDrivervtx;AVG9IDSDriver; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [2010-02-13 122376]
            R3 AVGIDSFiltervtx;AVG9IDSFilter; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [2010-02-13 30216]
            R3 AVGIDSShimvtx;AVG9IDSShim; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [2010-02-13 27800]
            R3 HCW85BDA;Hauppauge WinTV 885 Video Capture; C:\Windows\system32\drivers\HCW85BDA.sys [2007-10-01 1129344]
            R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-03-26 2103512]
            R3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys [2007-05-09 41888]
            R3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
            R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-11-18 1040544]
            R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2008-04-28 42528]
            R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-03-27 7738816]
            R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2007-07-07 12032]
            R3 pepifilter;Volume Adapter; C:\Windows\system32\DRIVERS\lv302af.sys [2007-05-09 14112]
            R3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\Windows\system32\DRIVERS\LV302V32.SYS [2007-05-09 1276832]
            R3 RTL85n86;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver; C:\Windows\system32\DRIVERS\RTL85n86.sys [2007-01-25 341504]
            R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
            R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
            R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
            S3 61883;Pilote d'unité 61883; C:\Windows\system32\DRIVERS\61883.sys [2008-01-21 45696]
            S3 Avc;Périphérique AVC; C:\Windows\system32\DRIVERS\avc.sys [2008-01-21 40448]
            S3 catchme;catchme; \??\C:\Users\Khalid\AppData\Local\Temp\catchme.sys []
            S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
            S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
            S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2008-01-21 52608]
            S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
            S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
            S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
            S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
            S3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-03-21 6144]
            S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
            S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
            S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
            S4 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iastor.sys [2006-06-13 247808]
            S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

            ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service; C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448]
            R2 Acer TV Share Service;Acer TV Share Service; C:\Program Files\Acer Arcade Live\Acer TV Share\Kernel\DMSTV\CLMSServer.exe [2008-07-22 270426]
            R2 AcerMemUsageCheckService;ePerformance Service; C:\Acer\Empowering Technology\ePerformance\MemCheck.exe [2007-10-17 28672]
            R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-02-13 285392]
            R2 avgfws9;AVG Firewall; C:\Program Files\AVG\AVG9\avgfws9.exe [2010-02-13 2304192]
            R2 AVGIDSAgent;AVG9IDSAgent; C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-02-13 5832712]
            R2 eDataSecurity Service;eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-03-04 500784]
            R2 eRecoveryService;eRecovery Service; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [2007-09-10 57344]
            R2 eSettingsService;eSettings Service; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-12-19 24576]
            R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
            R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-03-27 207392]
            R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2008-06-13 241734]
            R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
            R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
            S2 gupdate1ca98f2ccd3d08b;Service Google Update (gupdate1ca98f2ccd3d08b); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-19 133104]
            S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 183280]

            -----------------EOF-----------------
            0
        2. Contributeur sécurité
          télécharges Hijackthis sur le bureau
          https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/
          Lancer HijackThis en double-cliquant sur l'icône du logiciel
          Au menu principal, cliquer sur Do a system Scan only and Save a Logfile
          Un rapport sera alors généré dans un fichier bloc-notes, il sera situé dans le dossier désinfection initialement créé pour l'installation.
          Postes le ici
          0
          1. Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 12:05:55, on 14.02.2010
            Platform: Windows Vista SP2 (WinNT 6.00.1906)
            MSIE: Internet Explorer v8.00 (8.00.6001.18882)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Windows\RtHDVCpl.exe
            C:\Acer\Empowering Technology\SysMonitor.exe
            C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
            C:\Windows\System32\nvraidservice.exe
            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
            C:\Program Files\AVG\AVG9\avgtray.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
            C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
            C:\Windows\System32\mobsync.exe
            C:\Program Files\Windows Media Player\wmplayer.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Windows Live\Toolbar\wltuser.exe
            C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
            C:\Users\Khalid\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Windows\system32\SearchFilterHost.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ch/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
            O1 - Hosts: ::1 localhost
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
            O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
            O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
            O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
            O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
            O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
            O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
            O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
            O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
            O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
            O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [USBToolTip] C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
            O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
            O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
            O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [Google Update] "C:\Users\Khalid\AppData\Local\Google\Update\GoogleUpdate.exe" /c
            O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - Global Startup: ASETRES.EXE
            O4 - Global Startup: Empowering Technology Launcher.lnk = ?
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
            O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
            O20 - AppInit_DLLs: avgrsstx.dll
            O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
            O23 - Service: Acer TV Share Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer TV Share\Kernel\DMSTV\CLMSServer.exe
            O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
            O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
            O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
            O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
            O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
            O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
            O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
            O23 - Service: Service Google Update (gupdate1ca98f2ccd3d08b) (gupdate1ca98f2ccd3d08b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
            0
        3. Contributeur sécurité
          Téléchargez MalwareByte's Anti-Malware

          http://www.malwarebytes.org/mbam/program/mbam-setup.exe

          . Enregistres le sur le bureau
          . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
          . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
          . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
          . Une fois la mise à jour terminé
          . Rend-toi dans l'onglet, Recherche
          . Sélectionnes Exécuter un examen complet (examen assez long)
          . Cliques sur Rechercher
          . Le scan démarre.
          . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
          . Cliques sur Ok pour poursuivre.
          . Si des malwares ont été détectés, clique sur Afficher les résultats
          . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine. . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
          . Rends toi dans l'onglet rapport/log
          . Tu cliques dessus pour l'afficher, une fois affiché
          . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
          . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
          . tu cliques droit dans le cadre de la reponse et coller

          Si tu as besoin d'aide regarde ces tutoriels :
          Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
          http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

          0
          1. mbam-log-2010-02-14 (13-30-51).txt

            Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|L:\|)
            Eléments examinés: 236930
            Temps écoulé: 37 minute(s), 55 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 0
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 0
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 0

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            (Aucun élément nuisible détecté)

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            (Aucun élément nuisible détecté)
            0
        4. Contributeur sécurité
          ok

          relances HIJACKTHIS

          Au menu principal, choisir do a scan only, puis cocher la case devant les lignes suivantes à corriger et cliquer en bas sur Fix Checked

          O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
          O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
          O4 - Global Startup: Empowering Technology Launcher.lnk = ?
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab


          .........................

          IMPORTANT

          Purger la restauration systeme vista
          https://www.commentcamarche.net/faq/13214-vista-desactiver-reactiver-la-restauration-systeme-de-vista

          ..................

          Télécharge ToolsCleaner2sur ton Bureau.
          https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/

          * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur ToolsCleaner2.exe pour le lancer.
          * Clique sur Recherche et laisse le scan agir.
          * Clique sur Suppression pour finaliser.
          * Tu peux, si tu le souhaites, te servir des Options Facultatives.
          * Clique sur Quitter pour obtenir le rapport.
          * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

          Tu peux supprimer ToolCleaner ensuite

          0