Besoin d'aide pour analyser mon log

Bonjour,
Pourriez vous m'aider à analyser mon log réaliser sous Hijackthis.
J'ai depuis quelques temps un message d'erreur à l'ouverture de mon ordinateur concernant un fichier manquant : config/csrss.exe
Aujourd'hui je ne peux plus ouvrir mes applications ou répertoires après démarrage de l'ordi.
Merci par avance,

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:44:04, on 16/02/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Documents and Settings\Magali MADEC\Bureau\antivirus\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (file missing)
O2 - BHO: Lexmark - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [DriveIcons] C:\Program Files\Realtek Semiconductor Corp\Card Reader Software\DriveIcon\DriveIcon.exe
O4 - HKLM\..\Run: [{B179023B-6238-4499-8F26-CD73E9D90E0A}] "C:\Program Files\Mediafour\MacDrive 7\MacDrive.exe"
O4 - HKLM\..\Run: [MDGetStarted.exe] "C:\Program Files\Mediafour\MacDrive 7\MDGetStarted.exe" /auto
O4 - HKLM\..\Run: [VadeRetro Outlook] C:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [lxdumon.exe] "C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe"
O4 - HKLM\..\Run: [lxduamon] "C:\Program Files\Lexmark 5600-6600 Series\lxduamon.exe"
O4 - HKLM\..\Run: [Lexmark 5600-6600 Series Fax Server] "C:\Program Files\Lexmark 5600-6600 Series\fm3032.exe" /s
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\FICHIE~1\TEKNUM~1\update.exe /startup
O4 - HKCU\..\Run: [Emule_Init] C:\Program Files\emule\share.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [new2.exe] C:\Documents and Settings\Magali MADEC\Application Data\Microsoft\new2.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Magali MADEC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll (file missing)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/54.16/uploader2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.la-phototheque.com/admin/XUpload.ocx
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxduCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxduserv.exe
O23 - Service: lxdu_device - - C:\WINDOWS\system32\lxducoms.exe
O23 - Service: MacDriveService - Mediafour Corporation - C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\apache2\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
O24 - Desktop Component 0: (no name) - http://www.tonguide.com

--
End of file - 13212 bytes
Configuration: Windows XP

24 réponses

  1. Salut Chocolatine ,

    Plusieures infections présente sur ta machine .

    • Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
    • Double-clique sur RSIT.exe afin de lancer le programme.
    • Clique sur Continue à l'écran Disclaimer.
    • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
    • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

    Note : les rapports sont sauvegardés dans le dossier C:\rsit.
    0
    1. Merci pour ta réponse aussi rapide,
      Voici les logs réalisés sur RSIT

      info.txt

      info.txt logfile of random's system information tool 1.06 2010-02-16 15:25:53

      ======Uninstall list======

      -->"C:\Program Files\Fichiers communs\Teknum Systems\tsUninst.exe" "C:\Program Files\HandyBits\EasyCrypto\HandyBits EasyCrypto Deluxe.del"
      -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
      -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
      -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.EXE" -uninstall
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DC24971E-1946-445D-8A82-CE685433FA7D}\Setup.exe" -l0x9
      -->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      ABBYY FineReader 6.0 Sprint-->MsiExec.exe /X{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
      Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
      Adobe Illustrator CS2-->msiexec /I {B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}
      Adobe MPEG Encoder-->MsiExec.exe /I{9811A185-3D3D-11D6-9E14-00036D172B00}
      Adobe Photoshop 7.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
      Adobe Photoshop CS2-->msiexec /I {236BB7C4-4419-42FD-040C-2E257A25E34D}
      Adobe Premiere 6.5-->C:\WINDOWS\UNIN040C.EXE -f"C:\Program Files\Adobe\Premiere 6.5\DeIsL1.isu" -c"C:\Program Files\Adobe\Premiere 6.5\Uninst.dll"
      Adobe Reader 8.1.5 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
      Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
      Adobe SVG Viewer 3.0-->C:\Program Files\Fichiers communs\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Fichiers communs\Adobe\SVG Viewer 3.0\Uninstall\Install.log
      Advanced RealMedia Export Plug-in for Premiere 6.0-->C:\Program Files\Adobe\Premiere 6.5\Plug-ins\RNCompiler\rnuninst.exe RealNetworks|RNCompiler|6.0
      Ajaris-->"C:\Program Files\Ajaris\unins000.exe"
      Alice ADSL - Installation principale-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CE5D7CE8-27E7-4452-AF33-F38F074BBD08}\setup.exe" -l0x40c -eth -pri
      All To MP3 Converter 2.15-->"C:\Program Files\LitexMedia\All To MP3 Converter\unins000.exe"
      Ant Renamer-->"C:\Program Files\Ant Renamer\unins000.exe"
      Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      ArcSoft PhotoImpression-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6C5D7191-140A-11D6-B5A0-0050DA208A93}\setup.exe" -l0x40c -uninst
      Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
      ATI Catalyst Control Center-->MsiExec.exe /I{7815D9C1-99DD-49F0-B699-AA8C3EEF9BD3}
      Audacity 1.2.3-->"C:\Program Files\Audacity\unins000.exe"
      Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
      Camtasia Studio 3-->C:\Program Files\TechSmith\Camtasia Studio 3\CSuninst.EXE
      Capturino-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\Capturino\ST6UNST.LOG"
      Ciel Compta Libérale 13.20-->MsiExec.exe /I{E619C287-43B9-4FCC-8112-EEE1A92456BF}
      CleanUp!-->C:\Program Files\CleanUp!\uninstall.exe
      Click'N Design 3D for AfterBurner(tm) (V5)-->C:\PROGRA~1\CLICK'~1\UNWISE.EXE C:\PROGRA~1\CLICK'~1\INSTALL.LOG
      Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
      Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
      Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
      Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
      DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
      DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
      DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
      DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
      DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
      DVD Photo Slideshow Pro 7.92-->C:\Program Files\DVD Photo Slideshow Professional\uninst.exe
      E-Calc (Supprimer uniquement)-->C:\Program Files\CDDC-ECalc\Uninst.exe
      EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /r
      FileZilla (remove only)-->"C:\Program Files\FileZilla\uninstall.exe"
      FlippingBook PDF Publisher-->MsiExec.exe /I{42B2E062-0761-4273-90B4-0030D951B2D3}
      Font Explorer v.1.2-->"C:\Program Files\Font Explorer 1.2\unins000.exe"
      Free M4a to MP3 Converter 5.9-->"C:\Program Files\Free M4a to MP3 Converter\unins000.exe"
      Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
      Harry Potter TM-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F50AF3B-8997-4916-0095-99D63DDB785A}\setup.exe" -l0x40c Uninstall
      High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
      HijackThis 2.0.2-->"C:\Documents and Settings\Magali MADEC\Bureau\antivirus\HiJackThis\HijackThis.exe" /uninstall
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
      Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
      Intel(R) PRO Network Connections Drivers-->Prounstl.exe
      iView MediaPro3-->C:\Program Files\iView MediaPro3\Uninst.exe
      J2SE Runtime Environment 5.0 Update 10-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
      J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
      J2SE Runtime Environment 5.0 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150050}
      J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
      J2SE Runtime Environment 5.0 Update 9-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
      Java 2 Runtime Environment, SE v1.4.2_05-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142050}
      Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
      Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
      Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
      Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
      Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
      Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
      Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
      Lame ACM MP3 Codec-->C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_LameMP3 132 C:\WINDOWS\INF\LameACM.inf
      Le Pôle Express-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{4834AF50-6C57-4E7F-9BA7-39E193EA543D} /l1036
      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
      Lexmark -->regsvr32.exe /s /u "C:\Program Files\Lexmark Printable Web\bho.dll"
      Lexmark 5600-6600 Series-->C:\Program Files\Lexmark 5600-6600 Series\Install\x86\Uninst.exe
      Lexmark Barre d'outils-->regsvr32.exe /s /u "C:\Program Files\Lexmark Toolbar\toolband.dll"
      LimeWire PRO 4.12.3-->"C:\Program Files\LimeWire\uninstall.exe"
      Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x40c UNINSTALL
      Logitech Print Service-->C:\PROGRA~1\Logitech\PRINTS~1\UNWISE.EXE C:\PROGRA~1\Logitech\PRINTS~1\INSTALL.LOG
      Logitech QuickCam-->MsiExec.exe /I{A488D63E-B3DD-4423-892F-2F2EC8909518}
      Logitech SetPoint-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}\setup.exe" -l0x40c
      MacDrive 7-->MsiExec.exe /X{EC22C91E-33F4-499C-9B50-0450DB690CDE}
      Macromedia Dreamweaver 8-->MsiExec.exe /I{5FD788ED-1A37-4496-9BDD-463F493B27FA}
      Macromedia Extension Manager-->MsiExec.exe /I{3C8C9FB3-5FDF-40B4-B314-EAD722728C76}
      Macromedia Fireworks MX 2004-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E583ED6F-BD99-4066-A420-C815BF692B69}\Setup.exe" -l0x40c UNINSTALL
      Macromedia Flash 8 Video Encoder-->MsiExec.exe /X{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}
      Macromedia Flash 8-->MsiExec.exe /I{2BD5C305-1B27-4D41-B690-7A61172D2FEB}
      Macromedia Flash MX-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}\Setup.exe" -l0x40c UNINSTALL
      Macromedia Shockwave Player-->MsiExec.exe /X{7D1D6A24-65D4-454C-8815-4F08A5FFF12C}
      MediaCoder 0.6.0-->C:\Program Files\MediaCoder\uninst.exe
      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
      Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
      Microsoft .NET Framework 3.0 French Language Pack-->MsiExec.exe /X{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}
      Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
      Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
      Microsoft Office 97 Professional-->C:\Program Files\Microsoft Office\Office\Install\Acme.exe /w Off97Pro.STF
      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
      Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
      Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
      Mise à jour de sécurité pour le Codeur Windows Media (KB954156)-->"C:\WINDOWS\$NtUninstallKB954156_WM9L$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB976325)-->"C:\WINDOWS\ie8updates\KB976325-IE8\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB978207)-->"C:\WINDOWS\ie8updates\KB978207-IE8\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971468)-->"C:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975560)-->"C:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB977165)-->"C:\WINDOWS\$NtUninstallKB977165$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB977914)-->"C:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB978037)-->"C:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB978251)-->"C:\WINDOWS\$NtUninstallKB978251$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB978262)-->"C:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe"
      Mise à jour pour Windows Internet Explorer 8 (KB975364)-->"C:\WINDOWS\ie8updates\KB975364-IE8\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
      Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
      Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 French Language Pack\setup.exe
      Mozilla Firefox (3.5.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      Mozilla Thunderbird (1.0.6)-->C:\WINDOWS\UninstallThunderbird.exe /ua "1.0.6 (fr)"
      MP3 Player Utilities-->MsiExec.exe /I{5BBFB0E4-2250-49C3-A8A3-65BE2197D13B}
      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
      MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
      MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
      Musicmatch® Jukebox-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85D3CC30-8859-481A-9654-FD9B74310BEF}\setup.exe" -l0x9 -uninst
      OpenOffice.org 2.0-->MsiExec.exe /I{752783F5-0CFC-44C3-9E1F-CAF17C4508E7}
      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
      Panda ActiveScan-->C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan
      PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
      Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
      PSPad editor-->"C:\Program Files\PSPad editor\Uninst\unins000.exe"
      QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
      RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|12.0
      RealProducer Basic 11-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{265C893D-9D3D-4CE6-A317-9FFF1C6C9C44}\Setup.exe" -l0x9 RunSemiSilent
      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
      Safari-->MsiExec.exe /I{582D2A53-F426-4C5E-A2E6-43C1AB36B907}
      SAGEM F@st 800-840-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}\setup.exe" -l0x40c
      ScanToWeb-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}\setup.exe" ADDREMOVEDLG
      Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
      Skype web features-->MsiExec.exe /I{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}
      Skype™ 4.1-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
      Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
      Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
      SweetIM for Messenger 2.5-->MsiExec.exe /X{CFA9C824-A778-47EB-90CD-BB4DB82CF348}
      SweetIM Toolbar for Internet Explorer 3.2-->MsiExec.exe /X{83FA27D5-25B5-4D24-B796-DF742F08A5CF}
      SWiSHmax-->C:\WINDOWS\unvise32.exe C:\Program Files\SWiSHmax\uninstal.log
      Tomb Raider Chronicles-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Core Design\Tomb Raider Chronicles\Uninst.isu"
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
      VD Codec Pack 3.7-->C:\Program Files\VDCodecPack3.7\uninst.exe
      WAMP5 1.7.0-->c:\wamp\unins000.exe
      WD Diagnostics-->MsiExec.exe /X{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}
      webcamXP (remove only)-->"C:\Program Files\webcamXP\wxp-uninst.exe"
      Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
      Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
      Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
      Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
      Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
      Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
      Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
      Windows Presentation Foundation Language Pack (FRA)-->MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
      Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
      Windows Workflow Foundation FR Language Pack-->MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}
      Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
      XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
      Zend Optimizer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4C24C6EB-FF40-4855-9C1D-42F8AFC75112}\setup.exe" -l0x9 -removeonly

      =====HijackThis Backups=====

      O2 - BHO: (no name) - {61B0B03E-5EC9-4E1E-9EBB-E90076FC22A4} - C:\Program Files\Windows Media Player\kewy89104.dll [2008-03-14]
      O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2010-02-16]
      O4 - HKCU\..\Run: [new2.exe] C:\Documents and Settings\Magali MADEC\Application Data\Microsoft\new2.exe [2010-02-16]
      F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe [2010-02-16]

      ======Security center information======

      AV: AntiVir Desktop

      ======System event log======

      Computer Name: MIDIMOINSDIX
      Event Code: 18
      Message: TIMEOUT<jqs.exe> C:\...e6\bin\client\classes.jsa

      Record Number: 42985
      Source Name: avgntflt
      Time Written: 20091024231220.000000+120
      Event Type: Avertissement
      User:

      Computer Name: MIDIMOINSDIX
      Event Code: 18
      Message: TIMEOUT<jqs.exe> C:\...e6\bin\client\classes.jsa

      Record Number: 42984
      Source Name: avgntflt
      Time Written: 20091024231125.000000+120
      Event Type: Avertissement
      User:

      Computer Name: MIDIMOINSDIX
      Event Code: 18
      Message: TIMEOUT<realplay.exe> C:\...gins\rpcontrols2.dll

      Record Number: 42983
      Source Name: avgntflt
      Time Written: 20091024231057.000000+120
      Event Type: Avertissement
      User:

      Computer Name: MIDIMOINSDIX
      Event Code: 18
      Message: TIMEOUT<jqs.exe> C:\...e6\bin\client\classes.jsa

      Record Number: 42982
      Source Name: avgntflt
      Time Written: 20091024231030.000000+120
      Event Type: Avertissement
      User:

      Computer Name: MIDIMOINSDIX
      Event Code: 18
      Message: TIMEOUT<jqs.exe> C:\...e6\bin\client\classes.jsa

      Record Number: 42981
      Source Name: avgntflt
      Time Written: 20091024230935.000000+120
      Event Type: Avertissement
      User:

      =====Application event log=====

      Computer Name: MIDIMOINSDIX
      Event Code: 1002
      Message: Application bloquée msnmsgr.exe, version 8.5.1302.1018, module bloqué hungapp, version 0.0.0.0, adresse de blocage 0x00000000.

      Record Number: 5
      Source Name: Application Hang
      Time Written: 20090925112821.000000+120
      Event Type: erreur
      User:

      Computer Name: MIDIMOINSDIX
      Event Code: 4096
      Message: Le service AntiVir a bien démarré!

      Record Number: 4
      Source Name: Avira AntiVir
      Time Written: 20090925112630.000000+120
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      Computer Name: MIDIMOINSDIX
      Event Code: 1800
      Message: Le service Centre de sécurité Windows a démarré.

      Record Number: 3
      Source Name: SecurityCenter
      Time Written: 20090925112609.000000+120
      Event Type: Informations
      User:

      Computer Name: MIDIMOINSDIX
      Event Code: 0
      Message:
      Record Number: 2
      Source Name: CLSched
      Time Written: 20090925112518.000000+120
      Event Type: Informations
      User:

      Computer Name: MIDIMOINSDIX
      Event Code: 0
      Message:
      Record Number: 1
      Source Name: CLCapSvc
      Time Written: 20090925112457.000000+120
      Event Type: Informations
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\QuickTime\QTSystem\
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=15
      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
      "PROCESSOR_REVISION"=0401
      "NUMBER_OF_PROCESSORS"=1
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
      "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
      "SAFEBOOT_OPTION"=MINIMAL

      -----------------EOF-----------------

      log.txt

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Magali MADEC at 2010-02-16 15:25:36
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 105 GB (57%) free of 183 GB
      Total RAM: 1535 MB (82% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 15:25:47, on 16/02/2010
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Safe mode

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Documents and Settings\Magali MADEC\Bureau\antivirus\RSIT.exe
      C:\Documents and Settings\Magali MADEC\Bureau\antivirus\HiJackThis\Magali MADEC.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (file missing)
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (file missing)
      O2 - BHO: Lexmark - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
      O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
      O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
      O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
      O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
      O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
      O4 - HKLM\..\Run: [DriveIcons] C:\Program Files\Realtek Semiconductor Corp\Card Reader Software\DriveIcon\DriveIcon.exe
      O4 - HKLM\..\Run: [{B179023B-6238-4499-8F26-CD73E9D90E0A}] "C:\Program Files\Mediafour\MacDrive 7\MacDrive.exe"
      O4 - HKLM\..\Run: [MDGetStarted.exe] "C:\Program Files\Mediafour\MacDrive 7\MDGetStarted.exe" /auto
      O4 - HKLM\..\Run: [VadeRetro Outlook] C:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s
      O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [lxdumon.exe] "C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe"
      O4 - HKLM\..\Run: [lxduamon] "C:\Program Files\Lexmark 5600-6600 Series\lxduamon.exe"
      O4 - HKLM\..\Run: [Lexmark 5600-6600 Series Fax Server] "C:\Program Files\Lexmark 5600-6600 Series\fm3032.exe" /s
      O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\FICHIE~1\TEKNUM~1\update.exe /startup
      O4 - HKCU\..\Run: [Emule_Init] C:\Program Files\emule\share.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Magali MADEC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\S-1-5-18\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
      O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
      O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
      O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
      O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll (file missing)
      O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll (file missing)
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/54.16/uploader2.cab
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.la-phototheque.com/admin/XUpload.ocx
      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
      O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
      O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: lxduCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxduserv.exe
      O23 - Service: lxdu_device - - C:\WINDOWS\system32\lxducoms.exe
      O23 - Service: MacDriveService - Mediafour Corporation - C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe
      O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
      O23 - Service: wampapache - Apache Software Foundation - c:\wamp\apache2\bin\httpd.exe
      O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
      O24 - Desktop Component 0: (no name) - http://www.tonguide.com
      0
      1. Re ,

        Renvoi le rapport Log.txt ( C:\Rsit\Log.txt ) car il est incomplet .
        0
        1. ci joint...

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Magali MADEC at 2010-02-16 15:25:36
          Microsoft Windows XP Édition familiale Service Pack 3
          System drive C: has 105 GB (57%) free of 183 GB
          Total RAM: 1535 MB (82% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 15:25:47, on 16/02/2010
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v8.00 (8.00.6001.18702)
          Boot mode: Safe mode

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\Documents and Settings\Magali MADEC\Bureau\antivirus\RSIT.exe
          C:\Documents and Settings\Magali MADEC\Bureau\antivirus\HiJackThis\Magali MADEC.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://portail.free.fr/
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (file missing)
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (file missing)
          O2 - BHO: Lexmark - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
          O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
          O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
          O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
          O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
          O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
          O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
          O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
          O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
          O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
          O4 - HKLM\..\Run: [DriveIcons] C:\Program Files\Realtek Semiconductor Corp\Card Reader Software\DriveIcon\DriveIcon.exe
          O4 - HKLM\..\Run: [{B179023B-6238-4499-8F26-CD73E9D90E0A}] "C:\Program Files\Mediafour\MacDrive 7\MacDrive.exe"
          O4 - HKLM\..\Run: [MDGetStarted.exe] "C:\Program Files\Mediafour\MacDrive 7\MDGetStarted.exe" /auto
          O4 - HKLM\..\Run: [VadeRetro Outlook] C:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s
          O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [lxdumon.exe] "C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe"
          O4 - HKLM\..\Run: [lxduamon] "C:\Program Files\Lexmark 5600-6600 Series\lxduamon.exe"
          O4 - HKLM\..\Run: [Lexmark 5600-6600 Series Fax Server] "C:\Program Files\Lexmark 5600-6600 Series\fm3032.exe" /s
          O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
          O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\FICHIE~1\TEKNUM~1\update.exe /startup
          O4 - HKCU\..\Run: [Emule_Init] C:\Program Files\emule\share.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Magali MADEC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\S-1-5-18\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
          O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
          O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
          O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
          O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
          O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
          O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll (file missing)
          O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll (file missing)
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/54.16/uploader2.cab
          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
          O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
          O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.la-phototheque.com/admin/XUpload.ocx
          O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
          O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
          O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
          O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: lxduCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxduserv.exe
          O23 - Service: lxdu_device - - C:\WINDOWS\system32\lxducoms.exe
          O23 - Service: MacDriveService - Mediafour Corporation - C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe
          O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
          O23 - Service: wampapache - Apache Software Foundation - c:\wamp\apache2\bin\httpd.exe
          O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
          O24 - Desktop Component 0: (no name) - http://www.tonguide.com
          0
          1. Ok ,

            Plusieures infections comme je le disais , on va commencer par l infection Usb :

            • Télécharge UsbFix sur ton Bureau :

            (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir.

            • Double clic sur UsbFix.exe présent sur ton bureau .

            • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

            • Au second menu Choisis l'option " 2 " ( Suppression ) et tape sur [entrée]

            • Ton bureau disparaîtra et le pc redémarrera.

            • Au redémarrage, UsbFix scannera ton PC, laisse travailler l'outil.

            Ensuite poste le rapport UsbFix.txt qui apparaîtra avec le bureau.

            • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

            ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

            • Tuto : http://pagesperso-orange.fr/NosTools/tuto_usbfix3.html
            0
            1. ############################## | UsbFix V6.095 |

              User : Magali MADEC (Administrateurs) # MIDIMOINSDIX
              Update on 15/02/2010 by El Desaparecido , C_XX & Chimay8
              Start at: 16:28:45 | 16/02/2010
              Website : http://pagesperso-orange.fr/NosTools/index.html
              Contact : FindyKill.Contact@gmail.com

              Intel(R) Pentium(R) 4 CPU 3.06GHz
              Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
              Internet Explorer 8.0.6001.18702
              Windows Firewall Status : Enabled
              AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

              C:\ -> Disque fixe local # 178,49 Go (100,62 Go free) [HDD] # NTFS
              D:\ -> Disque CD-ROM
              E:\ -> Disque amovible
              I:\ -> Disque fixe local # 111,76 Go (38,25 Go free) [WD Passport] # FAT32

              ############################## | Processus actifs |

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir Desktop\sched.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
              c:\APPS\Powercinema\Kernel\TV\CLSched.exe
              C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
              C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxduserv.exe
              C:\WINDOWS\system32\lxducoms.exe
              C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Avira\AntiVir Desktop\update.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\WINDOWS\System32\alg.exe

              ################## | Elements infectieux |

              Supprimé ! C:\WINDOWS\cookies.ini
              Supprimé ! C:\WINDOWS\pskt.ini
              Supprimé ! C:\NOALPHA.VIR
              Supprimé ! C:\Recycler\S-1-5-21-1883487035-3411969556-3103654008-1003
              Supprimé ! C:\Recycler\S-1-5-21-27755743-3526866765-3032786834-1006
              Supprimé ! C:\Recycler\S-1-5-21-27755743-3526866765-3032786834-1007
              Supprimé ! I:\winamp_cache_0001.xml
              Supprimé ! I:\Recycler\S-1-5-21-1078073611-1993962763-839522115-1003

              ################## | Registre |

              Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"

              ################## | Mountpoints2 |

              Supprimé ! HKCU\...\Explorer\MountPoints2\{6c3261d8-70b4-11dc-b8f0-0014851b054d}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{908ce9a4-0b68-11df-ba47-0014851b054d}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{90cf2617-7bf1-11dd-b9c0-0014851b054d}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{a534ac6b-8a8f-11da-b6d4-0014851b054d}\Shell\AutoRun\Command

              ################## | Listing des fichiers présent |

              [23/03/2008 18:34|--a------|0] C:\asoutput.log
              [14/09/2009 08:56|-rahs----|296] C:\BOOT.INI
              [21/11/2005 19:27|--ahs----|296] C:\boot.ini.cf
              [05/08/2004 13:00|-rahs----|4952] C:\Bootfont.bin
              [05/08/2004 13:00|-rahs----|263488] C:\cmldr
              [21/10/2005 06:57|--a------|4260] C:\DWNLOG.TXT
              [24/02/2009 14:47|--a------|21157] C:\EyeCandyLog.txt
              [28/03/2006 18:53|--ah-----|5570] C:\ffastun.ffa
              [28/03/2006 18:53|--ah-----|2981888] C:\ffastun.ffl
              [28/03/2006 18:53|--ah-----|897024] C:\ffastun.ffo
              [28/03/2006 18:53|--ah-----|6512640] C:\ffastun0.ffx
              [28/03/2006 22:07|--a------|2981888] C:\ffastunT.ffl
              [24/03/2008 14:40|--a------|344] C:\finfos.txt
              [?|?|?] C:\hiberfil.sys
              [21/10/2005 07:13|-rahs----|0] C:\IO.SYS
              [05/12/2005 08:23|--a------|183] C:\LogiSetup.log
              [24/03/2008 14:39|--a------|439] C:\mpeg.txt
              [21/10/2005 07:13|-rahs----|0] C:\MSDOS.SYS
              [02/03/2006 20:58|--a------|68863] C:\newjoomla_2032006205845.sql
              [05/08/2004 13:00|--a------|47564] C:\NTDETECT.COM
              [28/12/2008 15:35|--a------|252240] C:\NTLDR
              [?|?|?] C:\pagefile.sys
              [21/10/2005 05:28|--a------|1093] C:\SAUDIT.TXT
              [31/10/2005 16:56|--a------|700416] C:\StubInstaller.exe
              [16/02/2010 16:45|--a------|4330] C:\UsbFix.txt
              [13/10/2007 07:45|--a------|150] C:\YServer.txt
              [13/02/2007 09:59|--ah-----|4096] I:\._.Trashes
              [07/01/2010 14:59|--ah-----|15364] I:\.DS_Store
              [15/02/2010 14:21|--ah-----|4096] I:\._.TemporaryItems
              [06/01/2010 19:26|--a------|692890] I:\javascriptfr_GESTIONNAIRE-CONTACTS-LOCALISES-SUR-CARTE-GOOGLE-MAP___Page.zip
              [15/02/2010 18:37|--ah-----|4096] I:\._javascriptfr_GESTIONNAIRE-CONTACTS-LOCALISES-SUR-CARTE-GOOGLE-MAP___Page.zip
              [29/09/2009 15:32|--ahs----|40960] I:\Thumbs.db
              [27/03/2009 12:05|--a------|41] I:\pmp_usb.ini
              [03/04/2009 13:52|--a------|86528] I:\evaluationsMADEC.xls
              [28/04/2009 22:53|--a------|27136] I:\CV.doc
              [06/05/2009 14:47|--a------|48899] I:\DREAMWEAVER_initiation.pdf
              [24/06/2009 14:20|--a------|77681] I:\devis_TristanDeschamps.pdf
              [07/07/2009 21:48|--a------|3420205] I:\Devis WINTERHALTER … Guebwiller.pdf
              [22/07/2009 10:37|--a------|107008] I:\evaluationsMADEC2.xls
              [16/02/2010 14:44|--a------|13214] I:\hijackthis.log

              ################## | Vaccination |

              # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
              # I:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

              ################## | Upload |

              Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_MIDIMOINSDIX.zip : https://www.ionos.fr/?affiliate_id=77097
              Merci pour votre contribution .

              ################## | ! Fin du rapport # UsbFix V6.095 ! |
              0
              1. • Télécharge Ad-remover ( de C_XX ) sur ton bureau :

                • Déconnecte toi et ferme toutes applications en cours !

                • Double clique sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

                • Double-clique sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

                ▶ Au menu principal choisis l'option "L" et tape sur [entrée] .

                • Laisse travailler l'outil et ne touche à rien ...

                • Poste le rapport qui apparait à la fin , sur le forum ...

                ( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
                ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                ▶ Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                • Tuto : http://pagesperso-orange.fr/NosTools/tuto_ad_r3.html
                0
                1. .
                  ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
                  .
                  Mis à jour par C_XX le 05.02.2010 à 17:34
                  Contact: AdRemover.contact@gmail.com
                  Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                  .
                  Lancé à: 17:15:54, 16/02/2010 | Mode Normal | Option: CLEAN
                  Exécuté de: C:\Ad-Remover\
                  Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                  Nom du PC: MIDIMOINSDIX | Utilisateur actuel: Magali MADEC
                  .
                  ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                  .

                  C:\DOCUME~1\MAGALI~1\APPLIC~1\Mozilla\FireFox\Profiles\r46uzoj8.default\searchplugins\sweetim.xml
                  C:\DOCUME~1\MAGALI~1\APPLIC~1\Mozilla\FireFox\Profiles\r46uzoj8.default\SweetIMToolbarData
                  C:\WINDOWS\Installer\{83FA27D5-25B5-4D24-B796-DF742F08A5CF}
                  C:\WINDOWS\Installer\{CFA9C824-A778-47EB-90CD-BB4DB82CF348}
                  C:\Program Files\SweetIM
                  C:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM
                  C:\Windows\Installer\2004486c.msi
                  C:\Windows\Installer\20044872.msi

                  (!) -- Fichiers temporaires supprimés.

                  .
                  HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                  HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
                  HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847}
                  HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
                  HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
                  HKCU\software\SweetIM
                  HKLM\Software\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
                  HKLM\Software\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
                  HKLM\Software\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
                  HKLM\Software\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
                  HKLM\Software\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
                  HKLM\software\classes\installer\Products\428C9AFC877ABE7409DCBBD48BC23F84
                  HKLM\software\classes\installer\Products\5D72AF385B5242D47B69FD47F2805AFC
                  HKLM\Software\Classes\Interface\{8954152E-2D31-11D2-A166-0060081C43D9}
                  HKLM\software\classes\MediaPlayer.GraphicsUtils
                  HKLM\software\classes\MediaPlayer.GraphicsUtils.1
                  HKLM\software\classes\MgMediaPlayer.GifAnimator
                  HKLM\software\classes\MgMediaPlayer.GifAnimator.1
                  HKLM\software\classes\SWEETIE.IEToolbar
                  HKLM\software\classes\SWEETIE.IEToolbar.1
                  HKLM\software\classes\SWEETIE.SWEETIE
                  HKLM\software\classes\SWEETIE.SWEETIE.3
                  HKLM\software\classes\SweetIM_URLSearchHook.ToolbarURLSearchHook
                  HKLM\software\classes\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
                  HKLM\software\classes\Toolbar3.SWEETIE
                  HKLM\software\classes\Toolbar3.SWEETIE.1
                  HKLM\Software\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
                  HKLM\Software\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}
                  HKLM\Software\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}
                  HKLM\Software\Microsoft\ESENT\Process\SweetIM
                  HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847}
                  HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
                  HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\1AC67655DD68F8240B2860F2D511EBD8
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\351716A953E21214898904032EAE2E81
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\5D19F074C042AD34BAB463D4175A062E
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A189D17A469616C4688D23E192996267
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\E337925F629CF4C4FB08F3D9674DD839
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\428C9AFC877ABE7409DCBBD48BC23F84
                  HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\5D72AF385B5242D47B69FD47F2805AFC
                  HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SweetIM
                  HKLM\software\microsoft\windows\currentversion\uninstall\{83FA27D5-25B5-4D24-B796-DF742F08A5CF}
                  HKLM\software\microsoft\windows\currentversion\uninstall\{CFA9C824-A778-47EB-90CD-BB4DB82CF348}
                  HKLM\software\SweetIM
                  .
                  ============== Scan additionnel ==============
                  .
                  .
                  * Mozilla FireFox Version 3.5.7 [fr] *
                  .
                  Nom du profil: r46uzoj8.default (Magali MADEC)
                  .
                  (MAGALI~1, prefs.js) Browser.download.lastDir, C:\Program Files\EasyPHP1-8\www\UPSIDE\images\stories
                  (MAGALI~1, prefs.js) Browser.search.defaultenginename, Bing
                  (MAGALI~1, prefs.js) Browser.search.defaulturl, hxxp://www.bing.com/search?FORM=IEFM1&q=
                  (MAGALI~1, prefs.js) Browser.startup.homepage, hxxp://www.google.fr/
                  (MAGALI~1, prefs.js) Extensions.enabledItems, fr@dictionaries.addons.mozilla.org:2.1,{b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7,firebug@software.joehewitt.com:1.5.0,{e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090920.2,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05,{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01,{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,OpenXMLViewer@Codeplex.com:1.0.0.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
                  (MAGALI~1, prefs.js) Keyword.URL, hxxp://www.bing.com/search?FORM=IEFM1&q=
                  .
                  (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.highlight.colors, #FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0
                  (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.logger.ConsoleHandler.MinReportLevel, 7
                  (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.logger.FileHandler.FileName, ff-toolbar.log
                  (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.logger.FileHandler.MaxFileSize, 200000
                  (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.logger.FileHandler.MinReportLevel, 7
                  (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.mode.debug, false
                  (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.search.external, <?xml version=\1.0\?><TOOLBAR><EXTERNAL_SEARCH engine=\hxxp://*google.*\ param=\q=\ /><EXTERNAL_SEARCH engine=\hxxp://search.yahoo.com/*\ param=\p=\ /><EXTERNAL_SEARCH engine=\hxxp://search.sweetim.*\ param=\q=\ /><EXTERNAL_SEARCH engine=\hxxp://*.live.*/*\ param=\q=\ /><EXTERNAL_SEARCH engine=\hxxp://*youtube.com/\ param=\search_query=\ /><EXTERNAL_SEARCH engine=\hxxp://*.ebay.*/search/*\ param=\satitle=\ /><EXTERNAL_SEARCH engine=\hxxp://*.amazon.com/s/*\ param=\field-keywords=\ /></TOOLBAR>
                  (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.search.history.capacity, 10
                  (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.simapp_id, {BE8BC492-8090-4FC4-8931-EBD0AB4DC7BF}
                  (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.version, 1.0.0.8
                  .
                  .
                  * Internet Explorer Version 8.0.6001.18702 *
                  .
                  [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                  .
                  Do404Search: 01000000
                  Local Page: C:\WINDOWS\system32\blank.htm
                  Show_ToolBar: yes
                  Start Page: hxxp://fr.msn.com/
                  Use Search Asst: no
                  Enable Browser Extensions: yes
                  Start Page Redirect Cache: hxxp://fr.msn.com/?ocid=iehp
                  Start Page Redirect Cache_TIMESTAMP: 3ed1f194bc5eca01
                  Start Page Redirect Cache AcceptLangs: fr
                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                  .
                  [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                  .
                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Delete_Temp_Files_On_Exit: yes
                  Local Page: C:\WINDOWS\system32\blank.htm
                  Start Page: hxxp://fr.msn.com/
                  Search Bar: hxxp://search.msn.com/spbasic.htm
                  .
                  [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                  .
                  Tabs: res://ieframe.dll/tabswelcome.htm
                  .
                  ============== Suspect (Cracks, Serials, ...) ==============
                  .
                  C:\Documents and Settings\Magali MADEC\DVD.Photo.Slideshow.Pro.v7.2.WinALL.Incl.Patch-CORE.rar
                  C:\Documents and Settings\Magali MADEC\WebcamXP.Pro.2007.v3.72.440.WinAll.KeyGen.Only-NeoX.rar
                  C:\Documents and Settings\Magali MADEC\Application Data\BitTorrent\4527 - The Legend of Zelda Spirit Tracks (M3 Patched).nds.torrent
                  C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\Joomla_1.5.8_to_1.5.9-Stable-Patch_Package-French.v1.zip
                  C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\patch_1.0.x_vers_1.0.13-Stable-fr.zip
                  C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\new_COMPOSANTS\PATCH MISE A JOUR\patch_1[1].0.x_vers_1.0.10-Stable-fr.zip
                  C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\new_COMPOSANTS\PEOPLEBOOK\mambatstaff_v2[1].1b_patch_txtareas.zip
                  C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\new_COMPOSANTS\PEOPLEBOOK\mambatstaff_v2[1].1b_patch_txtareas\patch_txtareas_de.zip
                  C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\new_COMPOSANTS\PEOPLEBOOK\mambatstaff_v2[1].1b_patch_txtareas\patch_txtareas_en.zip
                  C:\Documents and Settings\Magali MADEC\Favoris\code source\iView MediaPro 3 Serial, Key, Keygen, Key Generator.url
                  C:\Documents and Settings\Magali MADEC\Favoris\code source\Serialportal! - serial numbers, serials, serialkeys, codes - UNLOCK YOUR SOFTWARE, REMOVE ALL KIND OF PROTECTION.url
                  C:\Documents and Settings\Magali MADEC\Favoris\code source\langages WEB\FranceCrack.com.url
                  C:\Documents and Settings\Magali MADEC\MacDrive 7.0.10\Mediafour_MacDrive_v7.0.10_incl_Keygen-PARADOX.rar
                  C:\Documents and Settings\Magali MADEC\MacDrive 7.0.10\Mediafour_MacDrive_v7.0.10_incl_Keygen-PARADOX\Paradox.nfo
                  C:\Documents and Settings\Magali MADEC\MacDrive 7.0.10\Mediafour_MacDrive_v7.0.10_incl_Keygen-PARADOX\PARADOX\keygen.exe
                  C:\Documents and Settings\Magali MADEC\Mes documents\Downloads\4527 - The Legend of Zelda Spirit Tracks (M3 Patched).nds[www.torrent411.com].torrent
                  C:\Documents and Settings\Magali MADEC\webcamxp pro\WebcamXP.Pro.2007.v3.72.440.WinAll.KeyGen.Only-NeoX.rar
                  .
                  ===================================
                  .
                  15379 Octet(s) - C:\Ad-Report-CLEAN[1].log
                  .
                  11 Fichier(s) - C:\DOCUME~1\MAGALI~1\LOCALS~1\Temp
                  13 Fichier(s) - C:\WINDOWS\Temp
                  0 Fichier(s) - C:\WINDOWS\Prefetch
                  .
                  18 Fichier(s) - C:\Ad-Remover\BACKUP
                  88 Fichier(s) - C:\Ad-Remover\QUARANTINE
                  .
                  Fin à: 17:29:14 | 16/02/2010 - CLEAN[1]
                  .
                  ============== E.O.F ==============
                  .
                  0
              2. log Ad-remover
                .
                ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
                .
                Mis à jour par C_XX le 05.02.2010 à 17:34
                Contact: AdRemover.contact@gmail.com
                Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                .
                Lancé à: 17:15:54, 16/02/2010 | Mode Normal | Option: CLEAN
                Exécuté de: C:\Ad-Remover\
                Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                Nom du PC: MIDIMOINSDIX | Utilisateur actuel: Magali MADEC
                .
                ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                .

                C:\DOCUME~1\MAGALI~1\APPLIC~1\Mozilla\FireFox\Profiles\r46uzoj8.default\searchplugins\sweetim.xml
                C:\DOCUME~1\MAGALI~1\APPLIC~1\Mozilla\FireFox\Profiles\r46uzoj8.default\SweetIMToolbarData
                C:\WINDOWS\Installer\{83FA27D5-25B5-4D24-B796-DF742F08A5CF}
                C:\WINDOWS\Installer\{CFA9C824-A778-47EB-90CD-BB4DB82CF348}
                C:\Program Files\SweetIM
                C:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM
                C:\Windows\Installer\2004486c.msi
                C:\Windows\Installer\20044872.msi

                (!) -- Fichiers temporaires supprimés.

                .
                HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
                HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847}
                HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
                HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
                HKCU\software\SweetIM
                HKLM\Software\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
                HKLM\Software\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
                HKLM\Software\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
                HKLM\Software\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
                HKLM\Software\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
                HKLM\software\classes\installer\Products\428C9AFC877ABE7409DCBBD48BC23F84
                HKLM\software\classes\installer\Products\5D72AF385B5242D47B69FD47F2805AFC
                HKLM\Software\Classes\Interface\{8954152E-2D31-11D2-A166-0060081C43D9}
                HKLM\software\classes\MediaPlayer.GraphicsUtils
                HKLM\software\classes\MediaPlayer.GraphicsUtils.1
                HKLM\software\classes\MgMediaPlayer.GifAnimator
                HKLM\software\classes\MgMediaPlayer.GifAnimator.1
                HKLM\software\classes\SWEETIE.IEToolbar
                HKLM\software\classes\SWEETIE.IEToolbar.1
                HKLM\software\classes\SWEETIE.SWEETIE
                HKLM\software\classes\SWEETIE.SWEETIE.3
                HKLM\software\classes\SweetIM_URLSearchHook.ToolbarURLSearchHook
                HKLM\software\classes\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
                HKLM\software\classes\Toolbar3.SWEETIE
                HKLM\software\classes\Toolbar3.SWEETIE.1
                HKLM\Software\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
                HKLM\Software\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}
                HKLM\Software\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}
                HKLM\Software\Microsoft\ESENT\Process\SweetIM
                HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847}
                HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
                HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\1AC67655DD68F8240B2860F2D511EBD8
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\351716A953E21214898904032EAE2E81
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\5D19F074C042AD34BAB463D4175A062E
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A189D17A469616C4688D23E192996267
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\E337925F629CF4C4FB08F3D9674DD839
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\428C9AFC877ABE7409DCBBD48BC23F84
                HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\5D72AF385B5242D47B69FD47F2805AFC
                HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SweetIM
                HKLM\software\microsoft\windows\currentversion\uninstall\{83FA27D5-25B5-4D24-B796-DF742F08A5CF}
                HKLM\software\microsoft\windows\currentversion\uninstall\{CFA9C824-A778-47EB-90CD-BB4DB82CF348}
                HKLM\software\SweetIM
                .
                ============== Scan additionnel ==============
                .
                .
                * Mozilla FireFox Version 3.5.7 [fr] *
                .
                Nom du profil: r46uzoj8.default (Magali MADEC)
                .
                (MAGALI~1, prefs.js) Browser.download.lastDir, C:\Program Files\EasyPHP1-8\www\UPSIDE\images\stories
                (MAGALI~1, prefs.js) Browser.search.defaultenginename, Bing
                (MAGALI~1, prefs.js) Browser.search.defaulturl, hxxp://www.bing.com/search?FORM=IEFM1&q=
                (MAGALI~1, prefs.js) Browser.startup.homepage, hxxp://www.google.fr/
                (MAGALI~1, prefs.js) Extensions.enabledItems, fr@dictionaries.addons.mozilla.org:2.1,{b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7,firebug@software.joehewitt.com:1.5.0,{e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090920.2,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05,{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01,{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,OpenXMLViewer@Codeplex.com:1.0.0.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
                (MAGALI~1, prefs.js) Keyword.URL, hxxp://www.bing.com/search?FORM=IEFM1&q=
                .
                (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.highlight.colors, #FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0
                (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.logger.ConsoleHandler.MinReportLevel, 7
                (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.logger.FileHandler.FileName, ff-toolbar.log
                (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.logger.FileHandler.MaxFileSize, 200000
                (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.logger.FileHandler.MinReportLevel, 7
                (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.mode.debug, false
                (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.search.external, <?xml version=\1.0\?><TOOLBAR><EXTERNAL_SEARCH engine=\hxxp://*google.*\ param=\q=\ /><EXTERNAL_SEARCH engine=\hxxp://search.yahoo.com/*\ param=\p=\ /><EXTERNAL_SEARCH engine=\hxxp://search.sweetim.*\ param=\q=\ /><EXTERNAL_SEARCH engine=\hxxp://*.live.*/*\ param=\q=\ /><EXTERNAL_SEARCH engine=\hxxp://*youtube.com/\ param=\search_query=\ /><EXTERNAL_SEARCH engine=\hxxp://*.ebay.*/search/*\ param=\satitle=\ /><EXTERNAL_SEARCH engine=\hxxp://*.amazon.com/s/*\ param=\field-keywords=\ /></TOOLBAR>
                (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.search.history.capacity, 10
                (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.simapp_id, {BE8BC492-8090-4FC4-8931-EBD0AB4DC7BF}
                (MAGALI~1, prefs.js) EFFACE - Sweetim.toolbar.version, 1.0.0.8
                .
                .
                * Internet Explorer Version 8.0.6001.18702 *
                .
                [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                .
                Do404Search: 01000000
                Local Page: C:\WINDOWS\system32\blank.htm
                Show_ToolBar: yes
                Start Page: hxxp://fr.msn.com/
                Use Search Asst: no
                Enable Browser Extensions: yes
                Start Page Redirect Cache: hxxp://fr.msn.com/?ocid=iehp
                Start Page Redirect Cache_TIMESTAMP: 3ed1f194bc5eca01
                Start Page Redirect Cache AcceptLangs: fr
                Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                .
                [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                .
                Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                Delete_Temp_Files_On_Exit: yes
                Local Page: C:\WINDOWS\system32\blank.htm
                Start Page: hxxp://fr.msn.com/
                Search Bar: hxxp://search.msn.com/spbasic.htm
                .
                [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                .
                Tabs: res://ieframe.dll/tabswelcome.htm
                .
                ============== Suspect (Cracks, Serials, ...) ==============
                .
                C:\Documents and Settings\Magali MADEC\DVD.Photo.Slideshow.Pro.v7.2.WinALL.Incl.Patch-CORE.rar
                C:\Documents and Settings\Magali MADEC\WebcamXP.Pro.2007.v3.72.440.WinAll.KeyGen.Only-NeoX.rar
                C:\Documents and Settings\Magali MADEC\Application Data\BitTorrent\4527 - The Legend of Zelda Spirit Tracks (M3 Patched).nds.torrent
                C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\Joomla_1.5.8_to_1.5.9-Stable-Patch_Package-French.v1.zip
                C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\patch_1.0.x_vers_1.0.13-Stable-fr.zip
                C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\new_COMPOSANTS\PATCH MISE A JOUR\patch_1[1].0.x_vers_1.0.10-Stable-fr.zip
                C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\new_COMPOSANTS\PEOPLEBOOK\mambatstaff_v2[1].1b_patch_txtareas.zip
                C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\new_COMPOSANTS\PEOPLEBOOK\mambatstaff_v2[1].1b_patch_txtareas\patch_txtareas_de.zip
                C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\new_COMPOSANTS\PEOPLEBOOK\mambatstaff_v2[1].1b_patch_txtareas\patch_txtareas_en.zip
                C:\Documents and Settings\Magali MADEC\Favoris\code source\iView MediaPro 3 Serial, Key, Keygen, Key Generator.url
                C:\Documents and Settings\Magali MADEC\Favoris\code source\Serialportal! - serial numbers, serials, serialkeys, codes - UNLOCK YOUR SOFTWARE, REMOVE ALL KIND OF PROTECTION.url
                C:\Documents and Settings\Magali MADEC\Favoris\code source\langages WEB\FranceCrack.com.url
                C:\Documents and Settings\Magali MADEC\MacDrive 7.0.10\Mediafour_MacDrive_v7.0.10_incl_Keygen-PARADOX.rar
                C:\Documents and Settings\Magali MADEC\MacDrive 7.0.10\Mediafour_MacDrive_v7.0.10_incl_Keygen-PARADOX\Paradox.nfo
                C:\Documents and Settings\Magali MADEC\MacDrive 7.0.10\Mediafour_MacDrive_v7.0.10_incl_Keygen-PARADOX\PARADOX\keygen.exe
                C:\Documents and Settings\Magali MADEC\Mes documents\Downloads\4527 - The Legend of Zelda Spirit Tracks (M3 Patched).nds[www.torrent411.com].torrent
                C:\Documents and Settings\Magali MADEC\webcamxp pro\WebcamXP.Pro.2007.v3.72.440.WinAll.KeyGen.Only-NeoX.rar
                .
                ===================================
                .
                15379 Octet(s) - C:\Ad-Report-CLEAN[1].log
                .
                11 Fichier(s) - C:\DOCUME~1\MAGALI~1\LOCALS~1\Temp
                13 Fichier(s) - C:\WINDOWS\Temp
                0 Fichier(s) - C:\WINDOWS\Prefetch
                .
                18 Fichier(s) - C:\Ad-Remover\BACKUP
                88 Fichier(s) - C:\Ad-Remover\QUARANTINE
                .
                Fin à: 17:29:14 | 16/02/2010 - CLEAN[1]
                .
                ============== E.O.F ==============
                .
                0
                1. Ok , parfait .

                  Refais un scan RSIT et post log.txt stp

                  0
                  1. Désolé du délai... voilà le scan RSIT et merci encore car mon ordi refonctionne depuis.

                    Logfile of random's system information tool 1.06 (written by random/random)
                    Run by Magali MADEC at 2010-02-16 19:27:49
                    Microsoft Windows XP Édition familiale Service Pack 3
                    System drive C: has 103 GB (56%) free of 183 GB
                    Total RAM: 1535 MB (63% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 19:27:58, on 16/02/2010
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Avira\AntiVir Desktop\sched.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                    c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                    c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                    C:\Program Files\Java\jre6\bin\jqs.exe
                    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxduserv.exe
                    C:\WINDOWS\system32\lxducoms.exe
                    C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\wbem\wmiapsrv.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\Apps\Powercinema\PCMService.exe
                    C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
                    C:\Program Files\Logitech\Video\LogiTray.exe
                    C:\Program Files\Realtek Semiconductor Corp\Card Reader Software\DriveIcon\DriveIcon.exe
                    C:\Program Files\Mediafour\MacDrive 7\MacDrive.exe
                    C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
                    C:\WINDOWS\system32\LVComS.exe
                    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe
                    C:\Program Files\Lexmark 5600-6600 Series\lxduMsdMon.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Documents and Settings\Magali MADEC\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
                    C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                    C:\Program Files\Logitech\SetPoint\KEM.exe
                    C:\Program Files\Microsoft Office\Office\OSA.EXE
                    C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
                    C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
                    C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
                    C:\Documents and Settings\Magali MADEC\Bureau\RSIT.exe
                    C:\Documents and Settings\Magali MADEC\Bureau\antivirus\HiJackThis\Magali MADEC.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
                    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (file missing)
                    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (file missing)
                    O2 - BHO: Lexmark - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                    O2 - BHO: (no name) - {EEE6C35C-6118-11DC-9C72-001320C79847} - (no file)
                    O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
                    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                    O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
                    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
                    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                    O4 - HKLM\..\Run: [DriveIcons] C:\Program Files\Realtek Semiconductor Corp\Card Reader Software\DriveIcon\DriveIcon.exe
                    O4 - HKLM\..\Run: [{B179023B-6238-4499-8F26-CD73E9D90E0A}] "C:\Program Files\Mediafour\MacDrive 7\MacDrive.exe"
                    O4 - HKLM\..\Run: [MDGetStarted.exe] "C:\Program Files\Mediafour\MacDrive 7\MDGetStarted.exe" /auto
                    O4 - HKLM\..\Run: [VadeRetro Outlook] C:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKLM\..\Run: [lxdumon.exe] "C:\Program Files\Lexmark 5600-6600 Series\lxdumon.exe"
                    O4 - HKLM\..\Run: [lxduamon] "C:\Program Files\Lexmark 5600-6600 Series\lxduamon.exe"
                    O4 - HKLM\..\Run: [Lexmark 5600-6600 Series Fax Server] "C:\Program Files\Lexmark 5600-6600 Series\fm3032.exe" /s
                    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                    O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                    O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\FICHIE~1\TEKNUM~1\update.exe /startup
                    O4 - HKCU\..\Run: [Emule_Init] C:\Program Files\emule\share.exe
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Magali MADEC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
                    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                    O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
                    O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
                    O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
                    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                    O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
                    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
                    O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                    O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll (file missing)
                    O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler Trillix\saveflash\iebt.dll (file missing)
                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/54.16/uploader2.cab
                    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.la-phototheque.com/admin/XUpload.ocx
                    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                    O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                    O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                    O23 - Service: lxduCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxduserv.exe
                    O23 - Service: lxdu_device - - C:\WINDOWS\system32\lxducoms.exe
                    O23 - Service: MacDriveService - Mediafour Corporation - C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe
                    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
                    O23 - Service: wampapache - Apache Software Foundation - c:\wamp\apache2\bin\httpd.exe
                    O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
                    O24 - Desktop Component 0: (no name) - http://www.tonguide.com
                    0
                    1. pas grave , moi meme je vais m absenter 2 heures , chercher une amie à la gare de vannes .

                      • Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
                      • Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
                      • Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
                      • Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
                      • Sélectionne Exécuter un examen rapide.
                      • Clique sur Rechercher. L'analyse démarre.
                      • A la fin de l'analyse, un message s'affiche :

                      "L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés."

                      • Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
                      • Ferme tes navigateurs.
                      • Si des malwares ont été détectés, clique sur Afficher les résultats.
                      • Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
                      • MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.

                      0
                      1. Voilà le résultat, par contre le problème est revenu : impossibilité d'ouvir mes applications.

                        Malwarebytes' Anti-Malware 1.44
                        Version de la base de données: 3747
                        Windows 5.1.2600 Service Pack 3
                        Internet Explorer 8.0.6001.18702

                        16/02/2010 21:17:17
                        mbam-log-2010-02-16 (21-17-17).txt

                        Type de recherche: Examen rapide
                        Eléments examinés: 136191
                        Temps écoulé: 6 minute(s), 44 second(s)

                        Processus mémoire infecté(s): 0
                        Module(s) mémoire infecté(s): 0
                        Clé(s) du Registre infectée(s): 10
                        Valeur(s) du Registre infectée(s): 0
                        Elément(s) de données du Registre infecté(s): 0
                        Dossier(s) infecté(s): 0
                        Fichier(s) infecté(s): 1

                        Processus mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Module(s) mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Clé(s) du Registre infectée(s):
                        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-0000-0000-0000-100005000004} (Rogue.Installer) -> Quarantined and deleted successfully.
                        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7aa32fc7-133b-4ae7-998e-ced0d9829b12} (Trojan.Dialer) -> Quarantined and deleted successfully.
                        HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
                        HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

                        Valeur(s) du Registre infectée(s):
                        (Aucun élément nuisible détecté)

                        Elément(s) de données du Registre infecté(s):
                        (Aucun élément nuisible détecté)

                        Dossier(s) infecté(s):
                        (Aucun élément nuisible détecté)

                        Fichier(s) infecté(s):
                        C:\WINDOWS\system32\winhost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                        0
                        1. Hello ,

                          Réouvre malewarebyte's , va sur quarantaine et supprime tout .

                          Télécharge ComboFix (de sUBs) sur ton Bureau (et pas ailleurs !) :

                          http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                          >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>[ ! ATTENTION ! ]<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<

                          Ferme tes applications en cours ( ainsi que ton navigateur ) .
                          DESACTIVE TOUTES TES DEFENSES (anti-virus, garde anti spy-ware, pare-feu) le temps de la manipe.
                          En effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !
                          > Important : si tu rencontres des difficultés à ce niveau là, fais m'en part avant de poursuivre ...

                          Tuto ( aide ) ici : http://www.bleepingcomputer.com/co [...] r-combofix
                          Note : pour XP, il est IMPERATIF d'installer la Console de Récupération de Windows si l'outil le demande ( voir tuto ci-dessus ).

                          >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>[ ! ATTENTION ! ]<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<

                          Ensuite :
                          > Clique droit / "executer en tant qu'admin..." sur l'icône "Combofix.exe" pour lancer l'outil .
                          > A la fenêtre "DISCLAIMER..." , clique sur "oui" et laisse travailler ...

                          Notes importantes :
                          -> n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi .
                          -> Il se peut que le PC redémarre de lui même ( pour finaliser le nettoyage ) , laisse le faire .
                          -> Si l'outil t'anonce ceci : "combofix a détecté la présence de rootkit et a besoin de faire redémarer votre machine", tu acceptes ...
                          -> si un message d'erreur windows apparait à un moment : clique sur la croix rouge en haut à droite de la fenêtre pour la fermer ( et pas sur autre chose ! sinon pas de rapport ... )

                          Le rapport sera crée ici : C:\Combofix.txt

                          Réactive bien tes défenses .

                          > Poste le rapport Combofix pour analyse et attends la suite ...
                          0
                          1. Salut,

                            alors juste pour info avant de continuer, j'ai fait des conneries pour essayer d'avancer....
                            J'ai lancé ce matin regcleaner qui m'a tout planté et j'ai fait une restauration du système à la date de dimanche où j'avais fait une installation d'une nouvelle imprimante.

                            Depuis, cafarnaum... toutes les applications web sont bloquées (IE , Firefox, MSN, Mail ...)
                            Les applications ne s'ouvent plus ni les répertoires.
                            J'arrive à redémarrer en mode sans echec.

                            Est ce que je poursuis la manip avec ComboFix ou est-ce que je dois reprendre certaines étapes ?

                            Merci de ton aide
                            0
                            1. Re ,

                              Oui passes combofix , on refera un point ensuite .
                              0
                              1. Ca a été super long, mais voila le log Combofix
                                J'ai pu ouvrir Mail mes répertoires ont l'air de s'ouvrir correctement.
                                IE est planté

                                ComboFix 10-02-12.01 - Magali MADEC 17/02/2010 15:58:19.1.1 - x86
                                Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1535.1002 [GMT 1:00]
                                Lancé depuis: c:\documents and settings\Magali MADEC\Bureau\ComboFix.exe
                                AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
                                .

                                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                .

                                c:\recycler\S-1-5-21-1883487035-3411969556-3103654008-1003
                                c:\recycler\S-1-5-21-27755743-3526866765-3032786834-1006(2)
                                c:\windows\cookies.ini
                                c:\windows\Fonts\'
                                c:\windows\pskt.ini
                                c:\windows\system32\cafgdsuu.ini
                                c:\windows\system32\Ijl11.dll
                                c:\windows\system32\SHELLLNK.TLB

                                .
                                ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                                .

                                -------\Legacy_BOONTY_GAMES
                                -------\Service_Boonty Games
                                -------\Service_System

                                ((((((((((((((((((((((((((((( Fichiers créés du 2010-01-17 au 2010-02-17 ))))))))))))))))))))))))))))))))))))
                                .

                                2010-02-17 13:46 . 2010-02-17 13:46 -------- d-----w- c:\windows\system32\wbem\Repository
                                2010-02-17 13:44 . 2010-02-17 13:44 -------- d-----w- c:\documents and settings\Magali MADEC\Application Data\PC Tools
                                2010-02-17 13:43 . 2010-02-17 13:45 -------- d-----w- c:\program files\Spyware Doctor
                                2010-02-17 13:42 . 2010-02-17 13:42 -------- d-----w- c:\program files\SweetIM
                                2010-02-17 13:42 . 2010-02-17 13:42 -------- d-----w- c:\documents and settings\All Users\Application Data\SweetIM
                                2010-02-17 13:16 . 2005-10-21 06:07 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\ATI
                                2010-02-17 13:16 . 2010-02-17 13:42 -------- d-s---w- c:\documents and settings\Administrateur
                                2010-02-16 19:05 . 2010-02-16 19:05 -------- d-----w- c:\documents and settings\Magali MADEC\Application Data\Malwarebytes
                                2010-02-16 19:05 . 2010-02-16 19:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                                2010-02-16 19:05 . 2010-02-17 13:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                                2010-02-16 16:13 . 2010-02-17 13:42 -------- d-----w- C:\Ad-Remover
                                2010-02-16 15:46 . 2010-02-16 15:46 4025 ----a-w- C:\UsbFix_Upload_Me_MIDIMOINSDIX.zip
                                2010-02-16 14:25 . 2010-02-16 16:05 -------- d-----w- C:\rsit
                                2010-02-16 09:48 . 2010-02-17 13:44 -------- d-----w- c:\program files\Spybot - Search & Destroy
                                2010-02-16 09:48 . 2010-02-17 13:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                                2010-02-14 17:37 . 2010-02-14 17:38 -------- d-----w- c:\documents and settings\All Users\Application Data\ThumbnailCache4R
                                2010-02-14 17:34 . 2010-02-14 17:34 -------- d-----w- c:\documents and settings\Magali MADEC\Application Data\Lexmark Productivity Studio
                                2010-02-14 14:33 . 2010-02-17 11:32 -------- d-----w- c:\documents and settings\Magali MADEC\Application Data\5600-6600 Series
                                2010-02-14 14:33 . 2010-02-14 17:02 -------- d-----w- c:\documents and settings\All Users\Lx_cats
                                2010-02-14 14:27 . 2008-05-23 12:17 40960 ----a-w- c:\windows\system32\lxduvs.dll
                                2010-02-14 14:27 . 2008-04-23 16:34 360448 ----a-w- c:\windows\system32\lxducoin.dll
                                2010-02-14 14:27 . 2008-05-23 12:17 121856 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\lxdudrpp.dll
                                2010-02-14 14:27 . 2001-08-23 16:47 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
                                2010-02-14 14:27 . 2001-08-23 16:47 87040 ----a-w- c:\windows\system32\dllcache\wiafbdrv.dll
                                2010-02-14 14:26 . 2008-05-09 13:42 81920 ----a-w- c:\windows\system32\lxducaps.dll
                                2010-02-14 14:26 . 2008-05-09 13:42 1036288 ----a-w- c:\windows\system32\lxdudrs.dll
                                2010-02-14 14:26 . 2008-05-09 13:29 69632 ----a-w- c:\windows\system32\lxducnv4.dll
                                2010-02-14 14:26 . 2008-09-10 09:43 86016 ----a-w- c:\windows\system32\lxduoem.dll
                                2010-02-14 14:26 . 2008-09-10 09:41 32768 ----a-w- c:\windows\system32\LXDUFXPU.DLL
                                2010-02-14 14:26 . 2008-09-10 09:41 98345 ----a-w- c:\windows\system32\IMHOST32.DLL
                                2010-02-14 14:26 . 2008-09-10 09:41 339968 ----a-w- c:\windows\system32\IMGMAN32.DLL
                                2010-02-14 14:26 . 2008-05-01 00:41 45056 ----a-w- c:\windows\system32\LXDUPMON.DLL
                                2010-02-14 14:26 . 2010-02-14 14:26 -------- d-----w- c:\documents and settings\All Users\Application Data\5600-6600 Series
                                2010-02-14 14:25 . 2010-02-14 14:25 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
                                2010-02-14 14:23 . 2010-02-14 14:40 -------- d-----w- c:\program files\Lexmark Toolbar
                                2010-02-14 14:23 . 2010-02-14 14:23 -------- d-----w- c:\program files\Lexmark Printable Web
                                2010-02-14 14:23 . 2008-05-23 12:58 17064 ----a-w- c:\windows\system32\LXDUwupd.exe
                                2010-02-14 14:23 . 2008-04-15 11:08 352256 ----a-w- c:\windows\system32\LXDUwupd.dll
                                2010-02-14 14:21 . 2010-02-14 14:33 -------- d-----w- c:\program files\Lexmark 5600-6600 Series

                                .
                                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2010-02-17 15:19 . 2005-11-22 13:17 -------- d-----w- c:\documents and settings\Magali MADEC\Application Data\Skype
                                2010-02-17 15:18 . 2006-08-01 13:50 -------- d-----w- c:\documents and settings\Magali MADEC\Application Data\OpenOffice.org2
                                2010-02-17 14:45 . 2004-08-16 15:41 87322 ----a-w- c:\windows\system32\perfc00C.dat
                                2010-02-17 14:45 . 2004-08-16 15:41 514458 ----a-w- c:\windows\system32\perfh00C.dat
                                2010-02-17 13:49 . 2005-11-21 20:34 -------- d-----w- c:\program files\Fichiers communs\EPSON
                                2010-02-17 13:42 . 2009-07-10 17:30 -------- d-----w- c:\documents and settings\Magali MADEC\Application Data\BitTorrent
                                2010-02-17 13:37 . 2010-02-17 13:37 -------- d-----w- c:\documents and settings\Administrateur\Application Data\OpenOffice.org2
                                2010-02-16 20:54 . 2006-03-05 10:18 341 ----a-w- c:\windows\system32\CRUNX.BIN
                                2010-02-16 16:39 . 2005-11-22 17:02 -------- d-----w- c:\program files\eMule
                                2010-02-16 07:31 . 2010-01-04 08:24 -------- d-----w- c:\documents and settings\Magali MADEC\Application Data\skypePM
                                2010-02-14 14:56 . 2005-10-21 06:05 -------- d--h--w- c:\program files\InstallShield Installation Information
                                2010-02-14 14:55 . 2005-11-21 20:33 -------- d-----w- c:\program files\EPSON
                                2010-02-14 14:48 . 2005-11-29 20:09 -------- d-----w- c:\documents and settings\Magali MADEC\Application Data\EPSON
                                2010-02-14 14:48 . 2008-01-15 20:33 -------- d-----w- c:\documents and settings\Christophe BENOIT\Application Data\EPSON
                                2010-01-25 12:03 . 2009-06-03 16:01 -------- d-----w- c:\program files\Microsoft Silverlight
                                2010-01-11 17:12 . 2005-11-21 18:26 115568 -c--a-w- c:\documents and settings\Magali MADEC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                                2010-01-07 17:35 . 2006-10-29 09:47 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
                                2010-01-04 08:25 . 2010-01-04 08:25 56 ---ha-w- c:\windows\system32\ezsidmv.dat
                                2010-01-04 08:23 . 2005-11-22 13:17 -------- d-----r- c:\program files\Skype
                                2010-01-04 08:23 . 2010-01-04 08:23 -------- d-----w- c:\program files\Fichiers communs\Skype
                                2010-01-04 08:23 . 2005-11-22 13:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
                                2010-01-04 08:05 . 2006-08-25 09:38 -------- d-----w- c:\program files\Google
                                2009-12-21 19:07 . 2004-08-16 15:41 916480 ----a-w- c:\windows\system32\wininet.dll
                                2009-12-11 07:47 . 2009-09-06 16:26 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
                                2009-11-21 15:58 . 2004-08-16 15:39 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
                                2004-08-05 12:00 . 2005-11-24 18:49 73728 -csha-w- c:\windows\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
                                .

                                ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                REGEDIT4

                                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                                "{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-07-06 173368]

                                [HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
                                [HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
                                [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
                                [HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]

                                [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
                                2008-07-06 10:44 1164600 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                                "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-07-06 1164600]

                                [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
                                [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
                                [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
                                [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]

                                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                                "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-07-06 1164600]

                                [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
                                [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
                                [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
                                [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-06 67128]
                                "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
                                "Update Service"="c:\progra~1\FICHIE~1\TEKNUM~1\update.exe" [2005-10-21 30208]
                                "Emule_Init"="c:\program files\emule\share.exe" [2006-08-13 150526]
                                "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-04 39408]
                                "Google Update"="c:\documents and settings\Magali MADEC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-10-02 133104]
                                "Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
                                "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
                                "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
                                "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
                                "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952]
                                "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2004-12-21 32768]
                                "RTHDCPL"="RTHDCPL.EXE" [2005-06-29 14720000]
                                "PCMService"="c:\apps\Powercinema\PCMService.exe" [2005-01-28 110740]
                                "MimBoot"="c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe" [2005-05-10 11776]
                                "MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-05-10 110592]
                                "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2003-12-16 188416]
                                "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2003-12-16 77824]
                                "DriveIcons"="c:\program files\Realtek Semiconductor Corp\Card Reader Software\DriveIcon\DriveIcon.exe" [2004-10-12 662528]
                                "!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2008-03-14 6731312]
                                "{B179023B-6238-4499-8F26-CD73E9D90E0A}"="c:\program files\Mediafour\MacDrive 7\MacDrive.exe" [2007-07-12 179288]
                                "MDGetStarted.exe"="c:\program files\Mediafour\MacDrive 7\MDGetStarted.exe" [2007-06-13 139264]
                                "VadeRetro Outlook"="c:\program files\Goto Software\Vade Retro\VrMoRegister.exe" [2008-02-20 87552]
                                "SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2008-07-06 111928]
                                "SDTray"="c:\program files\Spyware Doctor\SDTrayApp.exe" [2007-08-14 1063752]
                                "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
                                "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
                                "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
                                "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-10-05 198160]
                                "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
                                "lxdumon.exe"="c:\program files\Lexmark 5600-6600 Series\lxdumon.exe" [2008-09-10 676520]
                                "lxduamon"="c:\program files\Lexmark 5600-6600 Series\lxduamon.exe" [2008-09-10 16040]
                                "Lexmark 5600-6600 Series Fax Server"="c:\program files\Lexmark 5600-6600 Series\fm3032.exe" [2008-09-10 311976]

                                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
                                "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2004-12-21 32768]

                                c:\documents and settings\Christophe BENOIT\Menu D‚marrer\Programmes\D‚marrage\
                                OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-1-25 61440]

                                c:\documents and settings\Magali MADEC\Menu D‚marrer\Programmes\D‚marrage\
                                Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-11-21 110592]
                                D‚marrage d'Office.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1996-12-17 51984]
                                Microsoft Recherche acc‚l‚r‚e.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1996-12-17 111376]
                                OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-1-25 61440]

                                c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                                Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-11-21 110592]
                                ATI CATALYST System Tray.lnk - c:\program files\ATI Technologies\ATI.ACE\CLI.exe [2004-12-21 32768]
                                DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-8-6 962663]
                                Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-3-6 67128]
                                Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2006-5-10 581632]

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
                                @="Service"

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
                                @=""

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
                                @=""

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                                "AntiVirusOverride"=dword:00000001

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                "c:\\Program Files\\webcamXP\\webcamXP.exe"=
                                "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
                                "c:\\Program Files\\Ajaris\\Ajaris-Server\\Ajaris Server.exe"=
                                "c:\\StubInstaller.exe"=
                                "c:\\Program Files\\LimeWire\\LimeWire.exe"=
                                "c:\\Program Files\\Macromedia\\Dreamweaver 8\\Dreamweaver.exe"=
                                "c:\\Program Files\\iView MediaPro3\\IVIEW_MP.exe"=
                                "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                "%windir%\\system32\\sessmgr.exe"=
                                "c:\\wamp\\Apache2\\bin\\httpd.exe"=
                                "c:\\Program Files\\BitTorrent\\bittorrent.exe"=
                                "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                                "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
                                "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
                                "c:\\WINDOWS\\system32\\lxducoms.exe"=

                                R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [31/07/2007 14:54 276352]
                                R0 MDPMGRNT;MDPMGRNT;c:\windows\system32\drivers\MDPMGRNT.sys [28/02/2007 10:15 19072]
                                R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [06/09/2009 17:26 108289]
                                R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [06/11/2009 09:06 54752]
                                R2 lxdu_device;lxdu_device;c:\windows\system32\lxducoms.exe -service --> c:\windows\system32\lxducoms.exe -service [?]
                                R2 lxduCATSCustConnectService;lxduCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxduserv.exe [14/02/2010 15:27 98984]
                                R2 MacDriveService;MacDriveService;c:\program files\Mediafour\MacDrive 7\MacDriveService.exe [01/05/2007 13:55 143360]
                                S?2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [02/12/2009 15:55 135664]
                                S2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\svcntaux.exe [03/09/2007 12:45 729416]
                                S3 ATHFMWDL;NETGEAR WG111T bootloader driver;c:\windows\system32\Drivers\ATHFMWDL.sys --> c:\windows\system32\Drivers\ATHFMWDL.sys [?]
                                S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22:48 704864]
                                S3 gsplittm;gsplittm;\??\c:\docume~1\MAGALI~1\LOCALS~1\Temp\gsplittm.sys --> c:\docume~1\MAGALI~1\LOCALS~1\Temp\gsplittm.sys [?]
                                .
                                Contenu du dossier 'Tâches planifiées'

                                2009-12-12 c:\windows\Tasks\AppleSoftwareUpdate.job
                                - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

                                2010-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                                - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-02 14:55]

                                2010-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                                - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-02 14:55]

                                2010-02-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-27755743-3526866765-3032786834-1006Core.job
                                - c:\documents and settings\Magali MADEC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-02 14:21]

                                2010-02-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-27755743-3526866765-3032786834-1006UA.job
                                - c:\documents and settings\Magali MADEC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-02 14:21]

                                2010-02-17 c:\windows\Tasks\User_Feed_Synchronization-{7C3443A4-32CE-4CCB-AF0C-742985D1A592}.job
                                - c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
                                .
                                .
                                ------- Examen supplémentaire -------
                                .
                                uStart Page = hxxp://www.google.fr/
                                uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
                                mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
                                uInternet Settings,ProxyOverride = localhost
                                uSearchAssistant = hxxp://www.aliceadsl.fr
                                Trusted Zone: musicmatch.com\online
                                Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                                FF - ProfilePath - c:\documents and settings\Magali MADEC\Application Data\Mozilla\Firefox\Profiles\r46uzoj8.default\
                                FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
                                FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
                                FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
                                FF - plugin: c:\documents and settings\Magali MADEC\Application Data\Mozilla\Firefox\Profiles\r46uzoj8.default\extensions\OpenXMLViewer@Codeplex.com\plugins\npDocX.dll
                                FF - plugin: c:\documents and settings\Magali MADEC\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
                                FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
                                FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
                                FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
                                .
                                - - - - ORPHELINS SUPPRIMES - - - -

                                ShellIconOverlayIdentifiers-MacDrive Volume Icons - (no file)
                                HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
                                HKLM-Run-AzMixerSel - c:\program files\Realtek\InstallShield\AzMixerSel.exe
                                ShellExecuteHooks-{70AB0A8B-8A8A-496F-A339-4CD2F3352991} - (no file)
                                SafeBoot-AVG Anti-Spyware Driver

                                **************************************************************************

                                catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2010-02-17 16:27
                                Windows 5.1.2600 Service Pack 3 NTFS

                                Recherche de processus cachés ...

                                Recherche d'éléments en démarrage automatique cachés ...

                                Recherche de fichiers cachés ...

                                Scan terminé avec succès
                                Fichiers cachés: 0

                                **************************************************************************
                                .
                                --------------------- DLLs chargées dans les processus actifs ---------------------

                                - - - - - - - > 'winlogon.exe'(680)
                                c:\windows\system32\Ati2evxx.dll

                                - - - - - - - > 'explorer.exe'(2908)
                                c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll
                                c:\program files\Logitech\SetPoint\lgscroll.dll
                                c:\program files\Mediafour\MacDrive 7\MDVolumeIcons.dll
                                c:\program files\Mediafour\MacDrive 7\MACDRAPI.DLL
                                c:\windows\system32\eappprxy.dll
                                c:\windows\system32\webcheck.dll
                                c:\windows\system32\WPDShServiceObj.dll
                                c:\windows\system32\PortableDeviceTypes.dll
                                c:\windows\system32\PortableDeviceApi.dll
                                .
                                ------------------------ Autres processus actifs ------------------------
                                .
                                c:\windows\system32\Ati2evxx.exe
                                c:\program files\Avira\AntiVir Desktop\avguard.exe
                                c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                c:\apps\Powercinema\Kernel\TV\CLCapSvc.exe
                                c:\apps\Powercinema\Kernel\TV\CLSched.exe
                                c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                                c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                                c:\program files\Java\jre6\bin\jqs.exe
                                c:\windows\system32\lxducoms.exe
                                c:\windows\system32\Ati2evxx.exe
                                c:\windows\RTHDCPL.EXE
                                c:\progra~1\MUSICM~1\MUSICM~1\MMDiag.exe
                                c:\windows\system32\LVComS.exe
                                c:\program files\Musicmatch\Musicmatch Jukebox\mim.exe
                                c:\program files\Lexmark 5600-6600 Series\lxduMsdMon.exe
                                c:\program files\Avira\AntiVir Desktop\update.exe
                                c:\documents and settings\Magali MADEC\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
                                c:\program files\Fichiers communs\Teknum Systems\updsvc.exe
                                c:\program files\Logitech\SetPoint\KHALMNPR.EXE
                                c:\program files\OpenOffice.org 2.0\program\soffice.exe
                                c:\program files\OpenOffice.org 2.0\program\soffice.BIN
                                c:\progra~1\MUSICM~1\Common\COMPON~1\MMCOMP~1.EXE
                                .
                                **************************************************************************
                                .
                                Heure de fin: 2010-02-17 16:29:00 - La machine a redémarré
                                ComboFix-quarantined-files.txt 2010-02-17 15:28

                                Avant-CF: 107 814 903 808 octets libres
                                Après-CF: 107 903 074 304 octets libres

                                - - End Of File - - 860C81BC54BF742181F5E17EC9A1ED6B
                                0
                                1. Redémarre le pc ensuite repasse Ad-Remover option L stp
                                  0
                                  1. Je repasse Ad-remover. Pour info, après redemarrage de l'ordi, impossibilité de lancer mes applications, alors que tout fonctionnait bien avant le redemarrage de l'ordi.
                                    J'ai également un nouveau message d'erreur au demarrage de l'ordi : SDTrayApp.exe composnt introuvable
                                    rtl100.bpl introuvable

                                    Je lance le scan et le post dés que c'est fini
                                    0
                                    1. .
                                      ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
                                      .
                                      Mis à jour par C_XX le 05.02.2010 à 17:34
                                      Contact: AdRemover.contact@gmail.com
                                      Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                                      .
                                      Lancé à: 17:41:22, 17/02/2010 | Mode Normal | Option: CLEAN
                                      Exécuté de: C:\Ad-Remover\
                                      Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                                      Nom du PC: MIDIMOINSDIX | Utilisateur actuel: Magali MADEC
                                      .
                                      ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                                      .

                                      C:\DOCUME~1\MAGALI~1\APPLIC~1\Mozilla\FireFox\Profiles\r46uzoj8.default\SweetIMToolbarData
                                      C:\WINDOWS\Installer\{83FA27D5-25B5-4D24-B796-DF742F08A5CF}
                                      C:\WINDOWS\Installer\{CFA9C824-A778-47EB-90CD-BB4DB82CF348}
                                      C:\Program Files\SweetIM
                                      C:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM
                                      C:\Windows\Installer\2004486c.msi
                                      C:\Windows\Installer\20044872.msi

                                      (!) -- Fichiers temporaires supprimés.

                                      .
                                      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                                      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
                                      HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847}
                                      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
                                      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
                                      HKCU\software\SweetIM
                                      HKLM\Software\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
                                      HKLM\Software\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
                                      HKLM\Software\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
                                      HKLM\Software\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
                                      HKLM\Software\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
                                      HKLM\software\classes\installer\Products\428C9AFC877ABE7409DCBBD48BC23F84
                                      HKLM\software\classes\installer\Products\5D72AF385B5242D47B69FD47F2805AFC
                                      HKLM\Software\Classes\Interface\{8954152E-2D31-11D2-A166-0060081C43D9}
                                      HKLM\software\classes\MediaPlayer.GraphicsUtils
                                      HKLM\software\classes\MediaPlayer.GraphicsUtils.1
                                      HKLM\software\classes\MgMediaPlayer.GifAnimator
                                      HKLM\software\classes\MgMediaPlayer.GifAnimator.1
                                      HKLM\software\classes\SWEETIE.IEToolbar
                                      HKLM\software\classes\SWEETIE.IEToolbar.1
                                      HKLM\software\classes\SWEETIE.SWEETIE
                                      HKLM\software\classes\SWEETIE.SWEETIE.3
                                      HKLM\software\classes\SweetIM_URLSearchHook.ToolbarURLSearchHook
                                      HKLM\software\classes\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
                                      HKLM\software\classes\Toolbar3.SWEETIE
                                      HKLM\software\classes\Toolbar3.SWEETIE.1
                                      HKLM\Software\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
                                      HKLM\Software\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}
                                      HKLM\Software\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}
                                      HKLM\Software\Microsoft\ESENT\Process\SweetIM
                                      HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847}
                                      HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
                                      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\1AC67655DD68F8240B2860F2D511EBD8
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\351716A953E21214898904032EAE2E81
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\5D19F074C042AD34BAB463D4175A062E
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A189D17A469616C4688D23E192996267
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\E337925F629CF4C4FB08F3D9674DD839
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\428C9AFC877ABE7409DCBBD48BC23F84
                                      HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\5D72AF385B5242D47B69FD47F2805AFC
                                      HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SweetIM
                                      HKLM\software\microsoft\windows\currentversion\uninstall\{83FA27D5-25B5-4D24-B796-DF742F08A5CF}
                                      HKLM\software\microsoft\windows\currentversion\uninstall\{CFA9C824-A778-47EB-90CD-BB4DB82CF348}
                                      HKLM\software\SweetIM
                                      .
                                      ============== Scan additionnel ==============
                                      .
                                      .
                                      * Mozilla FireFox Version 3.5.7 [fr] *
                                      .
                                      Nom du profil: r46uzoj8.default (Magali MADEC)
                                      .
                                      (MAGALI~1, prefs.js) Browser.download.lastDir, C:\Program Files\EasyPHP1-8\www\UPSIDE\images\stories
                                      (MAGALI~1, prefs.js) Browser.search.defaultenginename, Bing
                                      (MAGALI~1, prefs.js) Browser.search.defaulturl, hxxp://www.bing.com/search?FORM=IEFM1&q=
                                      (MAGALI~1, prefs.js) Browser.startup.homepage, hxxp://www.google.fr/
                                      (MAGALI~1, prefs.js) Extensions.enabledItems, fr@dictionaries.addons.mozilla.org:2.1,{b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7,firebug@software.joehewitt.com:1.5.0,{e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090920.2,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05,{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01,{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,OpenXMLViewer@Codeplex.com:1.0.0.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
                                      (MAGALI~1, prefs.js) Keyword.URL, hxxp://www.bing.com/search?FORM=IEFM1&q=
                                      .
                                      .
                                      * Internet Explorer Version 8.0.6001.18702 *
                                      .
                                      [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                                      .
                                      Do404Search: 01000000
                                      Local Page: C:\WINDOWS\system32\blank.htm
                                      Show_ToolBar: yes
                                      Start Page: hxxp://fr.msn.com/
                                      Use Search Asst: no
                                      Enable Browser Extensions: yes
                                      Start Page Redirect Cache: hxxp://fr.msn.com/?ocid=iehp
                                      Start Page Redirect Cache_TIMESTAMP: 3ed1f194bc5eca01
                                      Start Page Redirect Cache AcceptLangs: fr
                                      Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                      Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                      Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                                      .
                                      [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                                      .
                                      Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                      Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                      Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                      Delete_Temp_Files_On_Exit: yes
                                      Local Page: C:\WINDOWS\system32\blank.htm
                                      Start Page: hxxp://fr.msn.com/
                                      Search Bar: hxxp://search.msn.com/spbasic.htm
                                      .
                                      [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                                      .
                                      Tabs: res://ieframe.dll/tabswelcome.htm
                                      .
                                      ============== Suspect (Cracks, Serials, ...) ==============
                                      .
                                      C:\Documents and Settings\Magali MADEC\DVD.Photo.Slideshow.Pro.v7.2.WinALL.Incl.Patch-CORE.rar
                                      C:\Documents and Settings\Magali MADEC\WebcamXP.Pro.2007.v3.72.440.WinAll.KeyGen.Only-NeoX.rar
                                      C:\Documents and Settings\Magali MADEC\Application Data\BitTorrent\4527 - The Legend of Zelda Spirit Tracks (M3 Patched).nds.torrent
                                      C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\Joomla_1.5.8_to_1.5.9-Stable-Patch_Package-French.v1.zip
                                      C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\patch_1.0.x_vers_1.0.13-Stable-fr.zip
                                      C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\new_COMPOSANTS\PATCH MISE A JOUR\patch_1[1].0.x_vers_1.0.10-Stable-fr.zip
                                      C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\new_COMPOSANTS\PEOPLEBOOK\mambatstaff_v2[1].1b_patch_txtareas.zip
                                      C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\new_COMPOSANTS\PEOPLEBOOK\mambatstaff_v2[1].1b_patch_txtareas\patch_txtareas_de.zip
                                      C:\Documents and Settings\Magali MADEC\Bureau\JOOMLA\JOOMLA\new_COMPOSANTS\PEOPLEBOOK\mambatstaff_v2[1].1b_patch_txtareas\patch_txtareas_en.zip
                                      C:\Documents and Settings\Magali MADEC\Favoris\code source\iView MediaPro 3 Serial, Key, Keygen, Key Generator.url
                                      C:\Documents and Settings\Magali MADEC\Favoris\code source\Serialportal! - serial numbers, serials, serialkeys, codes - UNLOCK YOUR SOFTWARE, REMOVE ALL KIND OF PROTECTION.url
                                      C:\Documents and Settings\Magali MADEC\Favoris\code source\langages WEB\FranceCrack.com.url
                                      C:\Documents and Settings\Magali MADEC\MacDrive 7.0.10\Mediafour_MacDrive_v7.0.10_incl_Keygen-PARADOX.rar
                                      C:\Documents and Settings\Magali MADEC\MacDrive 7.0.10\Mediafour_MacDrive_v7.0.10_incl_Keygen-PARADOX\Paradox.nfo
                                      C:\Documents and Settings\Magali MADEC\MacDrive 7.0.10\Mediafour_MacDrive_v7.0.10_incl_Keygen-PARADOX\PARADOX\keygen.exe
                                      C:\Documents and Settings\Magali MADEC\Mes documents\Downloads\4527 - The Legend of Zelda Spirit Tracks (M3 Patched).nds[www.torrent411.com].torrent
                                      C:\Documents and Settings\Magali MADEC\webcamxp pro\WebcamXP.Pro.2007.v3.72.440.WinAll.KeyGen.Only-NeoX.rar
                                      .
                                      ===================================
                                      .
                                      15721 Octet(s) - C:\Ad-Report-CLEAN[1].log
                                      13995 Octet(s) - C:\Ad-Report-CLEAN[2].log
                                      .
                                      2 Fichier(s) - C:\DOCUME~1\MAGALI~1\LOCALS~1\Temp
                                      3 Fichier(s) - C:\WINDOWS\Temp
                                      0 Fichier(s) - C:\WINDOWS\Prefetch
                                      .
                                      33 Fichier(s) - C:\Ad-Remover\BACKUP
                                      125 Fichier(s) - C:\Ad-Remover\QUARANTINE
                                      .
                                      Fin à: 17:57:19 | 17/02/2010 - CLEAN[2]
                                      .
                                      ============== E.O.F ==============
                                      .
                                      0
                                      1. • Télécharge OTM (OldTimer) sur ton Bureau.
                                        • Clique droit sur OTM.exe et choisis Exécuter en tant qu'administrateur.
                                        • Copie (Ctrl+C) le texte suivant ci-dessous :

                                        :services
                                        gsplittm
                                        ATHFMWDL

                                        :files
                                        c:\docume~1\MAGALI~1\LOCALS~1\Temp\gsplittm.sys
                                        c:\windows\system32\Drivers\ATHFMWDL.sys
                                        c:\progra~1\FICHIE~1\TEKNUM~1\update.exe
                                        c:\program files\emule\share.exe
                                        c:\documents and settings\Magali MADEC\Local Settings\Application Data\Google\Update

                                        :reg
                                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                        "Update Service"=-
                                        "Emule_Init"=-
                                        "Google Update"=-

                                        :commands
                                        [purity]
                                        [emptytemp]
                                        [reboot]


                                        • Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
                                        • Clique maintenant sur le bouton MoveIt! puis ferme OTM.

                                        ---> Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                                        Accepte en cliquant sur YES.

                                        Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
                                        ---> Le nom du rapport correspond au moment de sa création : date_heure.log

                                        0
                                        • 1
                                        • 2