Comment supprimer windowsclick.com?

Bonjour,
Comment retirer windowsclick.com?
Car je pense que c'est lui l'origine de mes problèmes

symptôme :
-La page désiré se remplace par une pub ( parfois même à caractère un peu grivois! XD)
-Port USB et SD ne peut pas s'ouvrir car :
"le nombre maximal de secret pouvant etre stockés sur un système donné a été dépassé"

ps : j'ai AVG 7.5 en antivirus

Je sais pas si je dois choisir ses démarches :
-http://www.commentcamarche.net/forum/affich 11474186 virus windowsclick et autres
-https://www.myantispyware.com/2009/01/24/how-to-remove-windowsclickcom-redirect-uacdsys-trojan/
Configuration: Windows XP
Internet Explorer 7.0

32 réponses

Résumé de la discussion

Windowsclick.com est identifié comme l’origine probable des redirections publicitaires et des erreurs sur Windows XP avec Internet Explorer 7, où la page désirée se remplace et des messages liés au stockage apparaissent. Des démarches proposées incluent Malwarebytes' Anti-Malware et OTM OldTimer pour l’élimination, la suppression de programmes adware comme AwesomeBestShoppingTipsProgram et SupremeAdvertisingProgram, ainsi que le nettoyage du registre et des extensions indésirables. Des échanges évoquent l’utilisation de HijackThis pour identifier les entrées nuisibles, le retrait d’Adware.PlayMP3z, et le nettoyage des caches et fichiers temporaires afin de prévenir les redirections. Des informations complémentaires portent sur des rapports de logs et des listes de désinstallation, avec des conseils sur l’usage prudent d’outils comme OTM sans aboutir à une conclusion unique.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Eric le retour ? :D

    2
    1. Salut.

      Mais de rien. Ce fut un plaisir !! :)

      Bon surf, sois prudent sur le net. En cas de soucis, tu peux revenir sur cette discussion ou m'envoyer un MP.

      Bonne journée.

      ++
      0
      1. [ Rapport ToolsCleaner version 2.3.10 (par A.Rothstein & dj QUIOU) ]

        --> Recherche:

        C:\Combofix.txt: trouvé !
        C:\Qoobox: trouvé !
        C:\_OTM: trouvé !
        C:\Rsit: trouvé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
        C:\Documents and Settings\Vincent\Bureau\HijackThis.lnk: trouvé !
        C:\Documents and Settings\Vincent\Bureau\OTM.exe: trouvé !
        C:\Documents and Settings\Vincent\Bureau\SmitFraudFix.exe: trouvé !
        C:\Documents and Settings\Vincent\Bureau\Rsit.exe: trouvé !
        C:\Documents and Settings\Vincent\Bureau\SmitFraudfix: trouvé !
        C:\Documents and Settings\Vincent\Mes documents\Téléchargements\HJTInstall.exe: trouvé !
        C:\Program Files\Trend Micro\HijackThis: trouvé !
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
        C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
        C:\Qoobox\Quarantine\catchme.log: trouvé !

        ---------------------------------
        --> Suppression:

        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
        C:\Documents and Settings\Vincent\Bureau\HijackThis.lnk: supprimé !
        C:\Documents and Settings\Vincent\Bureau\OTM.exe: supprimé !
        C:\Documents and Settings\Vincent\Bureau\SmitFraudFix.exe: supprimé !
        C:\Documents and Settings\Vincent\Mes documents\Téléchargements\HJTInstall.exe: supprimé !
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
        C:\Combofix.txt: supprimé !
        C:\Documents and Settings\Vincent\Bureau\Rsit.exe: supprimé !
        C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
        C:\Qoobox\Quarantine\catchme.log: supprimé !
        C:\Qoobox: supprimé !
        C:\_OTM: supprimé !
        C:\Rsit: supprimé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
        C:\Documents and Settings\Vincent\Bureau\SmitFraudfix: supprimé !
        C:\Program Files\Trend Micro\HijackThis: supprimé !

        appart sa tout est beau wow je ne cest pas quoi dire MERCI!
        0
        1. Parfait ! Cette fois ton rapport est clean ! :)

          On peut terminer :

          Relance HijackThis, mais choisis cette fois "Do a system scan only". La liste créée, coche les lignes suivantes :

          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          
          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"  
          
          O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"    
          
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
          
          O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"  
          
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          
          O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install 
          
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


          Clique ensuite sur "Fix Checked".

          =========================

          Redémarre ton. Navigue un peu pour voir si tout est ok. Si tout est bon, passe à la suite, sinon, dis-moi.

          ==========La suite===========

          Nettoyage des outils:

          ▶ Télécharge ToolsCleaner par A.Rothstein & dj QUIOU sur ton Bureau:

          Toolscleaner

          ▶ Clique sur Recherche et laisse le scan se terminer.

          ▶ Clique sur Suppression pour finaliser.

          ▶ Clique sur Quitter, pour que le rapport puisse se créer.

          ▶ Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).

          ============================

          ▶ Télécharge CCleaner, version Slim, sans toolbar:

          CCLEANER

          ▶ Va dans "Options">>"Avancé". Décoche la première ligne.

          ▶ Va dans la section "Nettoyeur". Lance l'analyse. La liste créée, lance le nettoyage deux fois de suite afin d'obtenir 0bytes supprimé!

          ▶ Ensuite dans "Registre", lance une recherche des erreurs. La liste créée, fais-les réparer.

          ▶ Recommence ensuite le cycle Recherche/Réparation des erreurs jusqu'à n'en trouver aucune lors de la recherche.

          ===============================

          !! Très Important !!

          Supprimer les anciens points de restauration:

          ▶ Clique droit sur "Poste de travail".
          ▶ Clique sur "Propriétés".
          ▶ Clique sur l'onglet "Restauration du système".
          ▶ Coche la case "Désactiver la restauration...", puis "Appliquer" et valide par "OK".
          ▶ Redémarre le pc.

          ▶ Clique droit sur "Poste de travail".
          ▶ Clique sur "Propriétés".
          ▶ Clique sur l'onglet "Restauration du système".
          ▶ Redécoche la case "Désactiver la restauration...", puis "Appliquer" et valide par "OK".

          Les points sont supprimés.

          Création d'un nouveau point:

          ▶ Clique sur "démarrer", "tous les programmes", "Accessoires" puis "Outils système".
          ▶ Clique sur "Restauration du système".
          ▶ Dans la nouvelle fenêtre, coche la case "Créer un point de restauration".
          ▶ Clique sur "Suivant".
          ▶ Entre un nom pour le point de restauration : ce nom doit être assez évocateur (comme: "Après désinfection...")
          ▶ Clique sur "Créer" et le point de restauration se créé automatiquement.

          =============

          Pour une navigation plus sûre et plus rapide:


          Addon à ajouter à firefox pour le sécuriser:

          ▶ Ici : WOT : https://addons.mozilla.org/en-US/firefox/addon/wot-safe-browsing-tool/
          ▶ Explications/Demo ici : http://www.mywot.com/fr/demo

          + ceux-ci: https://www.malekal.com/securiser-le-navigateur-web-firefox-2/

          =============

          Utile, à lire absolument, quelques minutes de prévention, notamment sur les cracks : https://www.malekal.com/fichiers/projetantimalwares/prevention-protection.pdf


          =============

          Si tu n'as plus de question et/ou problème, pour moi, c'est ok! (Si tu as encore des questions, n'hésite pas ! )

          ++
          0
          1. LE RAPPORT DE JAVA

            JavaRa 1.15 Removal Log.

            Report follows after line.

            ------------------------------------

            The JavaRa removal process was started on Mon Sep 28 08:20:46 2009

            Found and removed: C:\Documents and Settings\Vincent\Application Data\Sun\Java\jre1.6.0_10

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

            Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

            Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

            Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

            Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

            Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

            Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

            Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

            ------------------------------------

            Finished reporting.

            JavaRa 1.15 Removal Log.

            Report follows after line.

            ------------------------------------

            The JavaRa removal process was started on Mon Sep 28 08:21:47 2009

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

            ------------------------------------

            Finished reporting.

            ET POUR HIJACK

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 08:25:16, on 2009-09-28
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v8.00 (8.00.6001.18702)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\PnkBstrA.exe
            C:\WINDOWS\system32\PnkBstrB.exe
            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            C:\PROGRA~1\AVG\AVG8\avgrsx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\TUProgSt.exe
            C:\PROGRA~1\AVG\AVG8\avgemc.exe
            C:\Program Files\Canon\CAL\CALMAIN.exe
            C:\Program Files\AVG\AVG8\avgcsrvx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\PROGRA~1\AVG\AVG8\avgtray.exe
            C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
            C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
            C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\WINDOWS\system32\msiexec.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\WINDOWS\system32\wbem\wmiapsrv.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\FileHippo.com\UpdateChecker.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
            O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
            O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
            O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
            O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
            O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
            O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
            O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
            O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
            O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
            0
            1. Ok, si tu ne joues plus, tu peux supprimer le dossiers en gras, plus haut.

              Tout est clean alors ! Il reste à finaliser afin d'éviter toute ré-infection :

              Supprime encore ce fichier en gras : C:\WINDOWS\system32\tmp.txt

              ===================

              Java n'est pas à jour, c'est une faille de sécurité qui peut couter cher :

              JavaRa :

              ▶ Télécharge JavaRa.zip

              ▶ Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)

              ▶ Double-clique sur le répertoire JavaRa obtenu.

              ▶ Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)

              ▶ Clique sur Search For Updates.

              ▶ Sélectionne Update Using jucheck.exe puis clique sur Search.

              ▶ Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.

              ▶ Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.

              ▶ Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.

              ▶ Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.

              * Note : le rapport se trouve aussi là : ( C:\JavaRa.log )

              =================================

              Update Checker :

              Voici un excellent petit logiciel très utile qui te permettra de savoir les nouvelles mises à jour disponibles pour les différents logiciels installés sur ton PC. Je te conseille de le garder et de vérifier tes mises à jour de temps en temps :

              ▶ Télécharge Update Checker

              ▶ Installe le avec les paramètres par défaut en cliquant chaques fois sur Suivant.

              ▶ Une fois installé, patiente quelques secondes et tu verras apparaître une icône verte dans ta barre des tâches te signalant qu'il y a des mises à jour disponibles.

              ▶ Double-cliques sur l'icône pour être redirrigé sur le site de téléchargement des mises à jour.

              ▶ Un conseil : n'installe pas les BETA qui sont listées en dessous.

              ▶ Tu installes les mises à jour que tu désires, les plus importantes sont :

              ● Java

              ● Adobe Reader

              ● Adobe Flash Player

              ● Internet explorer

              ======================================

              Fais-moi un tout dernier rapport avec HijackThis, cette fois, afin de fixer les lignes superflues.

              ++
              0
              1. WOW Merci beaucoup sa marche merci infiniment pour ton temp MERCI ENCORE
                0
                1. Noadware etai toujour present alor je lai suprimer comme tu la dit et gunz est un jeu sur PC que je ne joue plus
                  et c:\program files\awesomebestshoppingtipsprogram est suprimer
                  0
                  1. Bonsoir.

                    Vraiment pas de quoi ! C'est un plaisir d'aider des gens sérieux ! :)

                    Peux-tu vérifier si ces dossiers, en gras, sont présents sur ta machine, si oui, supprime-les :

                    c:\program files\awesomebestshoppingtipsprogram
                    c:\program files\noadware

                    Peux-tu me dire ce qu'est ce fichier, en gras ?

                    c:\documents and settings\vincent\mes documents\gunz

                    ++
                    0
                    1. apres que jai fait OTM il ma donner sa je ne cest pas si cest important
                      All processes killed
                      ========== PROCESSES ==========
                      No active process named explorer.exe was found!
                      ========== FILES ==========
                      C:\Program Files\AwesomeBestShoppingTipsProgram moved successfully.
                      ========== COMMANDS ==========

                      [EMPTYTEMP]

                      User: All Users

                      User: Default User
                      ->Temp folder emptied: 0 bytes
                      ->Temporary Internet Files folder emptied: 67 bytes

                      User: LocalService
                      ->Temp folder emptied: 0 bytes
                      ->Temporary Internet Files folder emptied: 67 bytes

                      User: NetworkService
                      ->Temp folder emptied: 0 bytes
                      ->Temporary Internet Files folder emptied: 67 bytes

                      User: Vincent
                      ->Temp folder emptied: 723374 bytes
                      ->Temporary Internet Files folder emptied: 55091952 bytes
                      ->Java cache emptied: 12162134 bytes
                      ->FireFox cache emptied: 53927313 bytes
                      ->Google Chrome cache emptied: 6315537 bytes

                      %systemdrive% .tmp files removed: 0 bytes
                      C:\WINDOWS\msdownld.tmp folder deleted successfully.
                      C:\WINDOWS\NV12801700.TMP folder deleted successfully.
                      %systemroot% .tmp files removed: 2258747 bytes
                      %systemroot%\System32 .tmp files removed: 3433472 bytes
                      Windows Temp folder emptied: 0 bytes
                      RecycleBin emptied: 0 bytes

                      Total Files Cleaned = 127,71 mb

                      OTM by OldTimer - Version 3.0.0.6 log created on 09272009_164529

                      Files moved on Reboot...

                      Registry entries deleted on Reboot...

                      et pour malware

                      Malwarebytes' Anti-Malware 1.41
                      Version de la base de données: 2866
                      Windows 5.1.2600 Service Pack 3

                      2009-09-27 16:57:17
                      mbam-log-2009-09-27 (16-57-17).txt

                      Type de recherche: Examen rapide
                      Eléments examinés: 93459
                      Temps écoulé: 5 minute(s), 17 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 6
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 0

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      HKEY_CLASSES_ROOT\awesomebestshoppingtipsprogram.awesomebestshoppingtipsprogram (Adware.PlayMP3z) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\supremeadvertisingprogram.supremeadvertisingprogram (Adware.PlayMP3z) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\AppID\AwesomeBestShoppingTipsProgram.dll (Adware.PlayMP3z) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\AppID\SupremeAdvertisingProgram.dll (Adware.PlayMP3z) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\AwesomeBestShoppingTipsProgram (Adware.PlayMP3z) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\SupremeAdvertisingProgram (Adware.PlayMP3z) -> Quarantined and deleted successfully.

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      ET POUR INFO.TXT ET LOG.TXT

                      info.txt logfile of random's system information tool 1.06 2009-09-27 16:58:40

                      ======Uninstall list======

                      -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
                      -->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                      Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                      Adobe Flash Player 10 Plugin-->MsiExec.exe /X{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
                      Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
                      Apple Mobile Device Support-->MsiExec.exe /I{8355F970-601D-442D-A79B-1D7DB4F24CAD}
                      Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                      Ask.com Search Assistant 1.0.1-->C:\Program Files\Ask Search Assistant\uninst.exe
                      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                      Autodesk Backburner 2008.1-->MsiExec.exe /I{3D347E6D-5A03-4342-B5BA-6A771885F379}
                      Autodesk FBX Plugin 2009.4 - 3ds Max 2010-->C:\Program Files\Autodesk\FBX\FBXPlugins\2009.4\3ds Max 2010\Uninstall.exe
                      AVG Free 8.5-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
                      AwesomeBestShoppingTipsProgram-->C:\Program Files\AwesomeBestShoppingTipsProgram\uninstall.exe uninstall=awesomebestshoppingtipsprogram
                      Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                      CamStudio-->C:\Program Files\CamStudio\uninstall.exe
                      Canon Camera Access Library-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CAL\Uninst.ini"
                      Canon Camera Support Core Library-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CSCLIB\Uninst.ini"
                      Canon G.726 WMP-Decoder-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\G726Decoder\G726DecUnInstall.ini"
                      Canon MovieEdit Task for ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\MVWUninst.ini"
                      Canon RAW Image Task for ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\RAW Image Task\Uninst.ini"
                      Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC\Uninst.ini"
                      Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC6\Uninst.ini"
                      Canon Utilities CameraWindow DC-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDC\Uninst.ini"
                      Canon Utilities CameraWindow-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowLauncher\Uninst.ini"
                      Canon Utilities EOS Utility-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\EOS Utility\Uninst.ini"
                      Canon Utilities MyCamera DC-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\MyCameraDC\Uninst.ini"
                      Canon Utilities MyCamera-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\MyCamera\Uninst.ini"
                      Canon Utilities PhotoStitch-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\PhotoStitch\Uninst.ini"
                      Canon Utilities RemoteCapture Task for ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\RemoteCaptureTask DC\Uninst.ini"
                      Canon Utilities ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\Uninst.ini"
                      Canon ZoomBrowser EX Memory Card Utility-->"C:\Program Files\Fichiers communs\Canon\UIW\1.4.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX MCU\Uninst.ini"
                      Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                      Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                      Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
                      Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
                      dBpoweramp Music Converter-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
                      DVD Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
                      Fraps (remove only)-->"C:\Fraps\uninstall.exe"
                      Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
                      GIMP 2.6.6-->"C:\Program Files\GIMP-2.0\setup\unins000.exe"
                      GoldWave v5.52-->"C:\Program Files\GoldWave\unstall.exe" "GoldWave v5.52" "C:\Program Files\GoldWave\unstall.log"
                      Grove ST. Families mod-->C:\Documents and Settings\Vincent\Bureau\Vehicule Skin GTA SA\Uninstal.exe
                      High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
                      HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                      HP Deskjet 3840-->msiexec /x{B1591C79-1C35-4E09-AA15-F7D6923AFB96}
                      HP Software Update-->MsiExec.exe /X{B81023A5-71ED-46EB-BE3B-9F974D1155F1}
                      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                      Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                      Java(TM) 6 Update 10-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
                      Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
                      LADSPA_plugins-win-0.4.15-->"C:\Program Files\Plug-Ins\unins000.exe"
                      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                      LimeWire 5.1.3-->"C:\Program Files\LimeWire\uninstall.exe"
                      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                      Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                      Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                      Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                      Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
                      Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                      Microsoft Kernel-Mode Driver Framework Feature Pack 1.7-->"C:\WINDOWS\$NtUninstallWdf01007$\spuninst\spuninst.exe"
                      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                      Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
                      Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0120-040C-0000-0000000FF1CE}
                      Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
                      Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
                      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                      Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                      Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                      Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                      Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
                      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                      Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
                      Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB963027)-->"C:\WINDOWS\$NtUninstallKB963027$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
                      Mise à jour pour Windows Internet Explorer 8 (KB971180)-->"C:\WINDOWS\ie8updates\KB971180-IE8\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
                      Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
                      Mozilla Firefox (3.5.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                      MSN Toolbar-->MsiExec.exe /I{3560CE5A-C4EF-4DB0-9ECC-BA035FE309C5}
                      MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
                      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                      Nero 7 Essentials-->MsiExec.exe /X{AAB93551-3FFE-42B2-8315-96252BBC1036}
                      NoAdware v5.0-->"C:\Program Files\NoAdware\unins000.exe"
                      NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
                      NVIDIA nView Desktop Manager-->C:\Program Files\NVIDIA Corporation\nView\nViewSetup.exe -uninstall
                      Opera 10.00-->MsiExec.exe /X{2085F05D-24C5-4E27-B7B4-A51DE890FFC9}
                      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                      PowerDVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
                      QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
                      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
                      San Andreas Mod Installer-->"C:\WINDOWS\San Andreas Mod Installer\uninstall.exe" "/U:C:\Program Files\San Andreas Mod Installer\Uninstall\uninstall.xml"
                      Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                      Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                      Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                      Spyware Doctor 6.0-->C:\Program Files\Spyware Doctor\unins000.exe /LOG
                      Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
                      System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
                      TuneUp Utilities 2009-->MsiExec.exe /I{55A29068-F2CE-456C-9148-C869879E2357}
                      Uniblue DriverScanner 2009-->"C:\Documents and Settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}\DriverScanner_Setup.exe" REMOVE=TRUE MODIFY=FALSE
                      Uniblue DriverScanner 2009-->C:\Documents and Settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}\DriverScanner_Setup.exe
                      Uniblue SpeedUpMyPC 2009-->"C:\Documents and Settings\All Users\Application Data\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}\speedupmypc2009.exe" REMOVE=TRUE MODIFY=FALSE
                      Uniblue SpeedUpMyPC 2009-->C:\Documents and Settings\All Users\Application Data\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}\speedupmypc2009.exe
                      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                      Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
                      Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
                      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                      Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                      Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
                      Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
                      Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                      Windows Live OneCare safety scanner-->RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
                      Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
                      Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                      Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
                      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                      Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                      WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe

                      ======Security center information======

                      AV: Spyware Doctor with AntiVirus (disabled)
                      AV: AVG Anti-Virus Free

                      ======System event log======

                      Computer Name: VINCENT01
                      Event Code: 7036
                      Message: Le service Téléphonie est entré dans l'état : en cours d'exécution.

                      Record Number: 6932
                      Source Name: Service Control Manager
                      Time Written: 20090821174813.000000-240
                      Event Type: Informations
                      User:

                      Computer Name: VINCENT01
                      Event Code: 7001
                      Message: Le service Service Partage réseau du Lecteur Windows Media dépend du service Hôte de périphérique universel Plug-and-Play qui n'a pas pu démarrer en raison de l'erreur :
                      Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.

                      Record Number: 6931
                      Source Name: Service Control Manager
                      Time Written: 20090821174813.000000-240
                      Event Type: erreur
                      User:

                      Computer Name: VINCENT01
                      Event Code: 268
                      Message: The driver initialization status is 0:0:0:0:0:0:0:0.

                      Record Number: 6930
                      Source Name: PCTCore
                      Time Written: 20090821174640.000000-240
                      Event Type: Informations
                      User:

                      Computer Name: VINCENT01
                      Event Code: 2
                      Message: Device identified.

                      Record Number: 6929
                      Source Name: nvata
                      Time Written: 20090821174640.000000-240
                      Event Type: Informations
                      User:

                      Computer Name: VINCENT01
                      Event Code: 1001
                      Message: L'ordinateur a redémarré après une vérification d'erreur. La vérification d'erreur était :
                      0x100000d1 (0xe1c2e000, 0x00000002, 0x00000000, 0xf3b810a5).
                      Un vidage a été enregistré dans : C:\WINDOWS\Minidump\Mini082109-01.dmp.

                      Record Number: 6928
                      Source Name: Save Dump
                      Time Written: 20090821174637.000000-240
                      Event Type: Informations
                      User:

                      =====Application event log=====

                      Computer Name: VINCENT01
                      Event Code: 1017
                      Message: Démarrer l'inscription ASP.NET (version 2.0.50727.0) (indicateur interne : 0x00000406)

                      Record Number: 582
                      Source Name: ASP.NET 2.0.50727.0
                      Time Written: 20090623192656.000000-240
                      Event Type: Informations
                      User:

                      Computer Name: VINCENT01
                      Event Code: 1025
                      Message: Produit : Microsoft .NET Framework 2.0 Service Pack 2. Le fichier c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll est actuellement utilisé par le processus de nom 'jqs' et d'identificateur '216'.

                      Record Number: 581
                      Source Name: MsiInstaller
                      Time Written: 20090623192605.000000-240
                      Event Type: Informations
                      User: VINCENT01\Vincent

                      Computer Name: VINCENT01
                      Event Code: 1025
                      Message: Produit : Microsoft .NET Framework 2.0 Service Pack 2. Le fichier c:\WINDOWS\system32\mscoree.dll est actuellement utilisé par le processus de nom 'jqs' et d'identificateur '216'.

                      Record Number: 580
                      Source Name: MsiInstaller
                      Time Written: 20090623192605.000000-240
                      Event Type: Informations
                      User: VINCENT01\Vincent

                      Computer Name: VINCENT01
                      Event Code: 1025
                      Message: Produit : Microsoft .NET Framework 2.0 Service Pack 2. Le fichier c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll est actuellement utilisé par le processus de nom 'jqs' et d'identificateur '216'.

                      Record Number: 579
                      Source Name: MsiInstaller
                      Time Written: 20090623192602.000000-240
                      Event Type: Informations
                      User: VINCENT01\Vincent

                      Computer Name: VINCENT01
                      Event Code: 1025
                      Message: Produit : Microsoft .NET Framework 2.0 Service Pack 2. Le fichier c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll est actuellement utilisé par le processus de nom 'jqs' et d'identificateur '216'.

                      Record Number: 578
                      Source Name: MsiInstaller
                      Time Written: 20090623192601.000000-240
                      Event Type: Informations
                      User: VINCENT01\Vincent

                      ======Environment variables======

                      "ComSpec"=%SystemRoot%\system32\cmd.exe
                      "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Autodesk\Backburner;C:\Program Files\Fichiers communs\Autodesk Shared
                      "windir"=%SystemRoot%
                      "FP_NO_HOST_CHECK"=NO
                      "OS"=Windows_NT
                      "PROCESSOR_ARCHITECTURE"=x86
                      "PROCESSOR_LEVEL"=15
                      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 95 Stepping 2, AuthenticAMD
                      "PROCESSOR_REVISION"=5f02
                      "NUMBER_OF_PROCESSORS"=1
                      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                      "TEMP"=%SystemRoot%\TEMP
                      "TMP"=%SystemRoot%\TEMP
                      "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                      "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

                      -----------------EOF-----------------

                      ET LOG

                      Logfile of random's system information tool 1.06 (written by random/random)
                      Run by Vincent at 2009-09-27 16:58:27
                      Microsoft Windows XP Édition familiale Service Pack 3
                      System drive C: has 103 GB (68%) free of 153 GB
                      Total RAM: 895 MB (46% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 16:58:38, on 2009-09-27
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      C:\WINDOWS\system32\PnkBstrA.exe
                      C:\WINDOWS\system32\PnkBstrB.exe
                      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\TUProgSt.exe
                      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                      C:\PROGRA~1\AVG\AVG8\avgemc.exe
                      C:\Program Files\Canon\CAL\CALMAIN.exe
                      C:\Program Files\AVG\AVG8\avgcsrvx.exe
                      C:\WINDOWS\system32\wbem\wmiapsrv.exe
                      C:\WINDOWS\RTHDCPL.EXE
                      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                      C:\PROGRA~1\AVG\AVG8\avgtray.exe
                      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
                      C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                      C:\WINDOWS\system32\RUNDLL32.EXE
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Documents and Settings\Vincent\Bureau\RSIT.exe
                      C:\Program Files\Trend Micro\HijackThis\Vincent.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/?gws_rd=ssl
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                      O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
                      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                      O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                      O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
                      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
                      O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
                      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                      O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
                      O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
                      0
                      1. Salut.

                        Eh béh ! Belle collection ;) On peut remercier, une fois de plus, Combofix. :)

                        OTM :

                        ▶ Télécharge OTM (de Old_Timer) sur ton Bureau

                        ▶ Double-clique sur OTM.exe pour le lancer.

                        ▶ Assure toi que la case Unregister Dll's and Ocx's soit bien cochée.

                        ▶ Copie la liste qui se trouve en gras dans la citation ci-dessous et colle-la dans le cadre de gauche de OTM sous "Paste instructions for item to be moved".

                        -----------------------------------------------------------------------------

                        :processes
                        explorer.exe

                        :files
                        C:\Program Files\AwesomeBestShoppingTipsProgram

                        :commands
                        [purity]
                        [emptytemp]
                        [start explorer]


                        -----------------------------------------------------------------------------

                        ▶ clique sur MoveIt! pour lancer la suppression.

                        ▶ Le résultat apparaitra dans le cadre "Results".

                        ▶ Clique sur Exit pour fermer.

                        ▶ Poste le rapport situé dans C:\_OTM\MovedFiles.

                        ▶ Il te sera peut-être demandé de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.

                        =================================

                        ▶ Télécharge Malwarebytes Anti-Malware (MBAM):

                        MBAM

                        ▶ Installe-le en vérifiant que la case de mise à jour soit bien cochée en fin d'installation.

                        ▶ Après la mise à jour, lance-le et coche "Examen Rapide". Puis "Rechercher".

                        ▶ Si MBAM trouve quelque chose: fais "Voir les résultats" puis "Supprimer la sélection".

                        ▶ Poste le rapport généré.

                        ===================================

                        ▶ Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

                        http://images.malwareremoval.com/random/RSIT.exe

                        ▶ Double-clique sur RSIT.exe.

                        ▶ Clique sur Continue à l'écran Disclaimer.

                        ▶ Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

                        ▶ Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

                        ▶ A noter: Les rapports se trouvent également ici: C:\rsit.

                        ++
                        0
                        1. voici se que sa ma donner
                          ComboFix 09-09-25.01 - Vincent 2009-09-26 17:32.1.1 - NTFSx86
                          Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.895.524 [GMT -4:00]
                          Lancé depuis: c:\documents and settings\Vincent\Bureau\vinceLevs.exe
                          AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
                          AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
                          * Un nouveau point de restauration a été créé
                          .

                          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          c:\program files\AwesomeBestShoppingTipsProgram\AwESomebestshoppingtipsprogram.dll
                          c:\windows\Installer\2eef95f.msp
                          c:\windows\Installer\2f533.msp
                          c:\windows\Installer\47348.msp
                          c:\windows\Installer\9b984.msp
                          c:\windows\Installer\9b9b3.msp
                          c:\windows\system32\404Fix.exe
                          c:\windows\system32\Agent.OMZ.Fix.exe
                          c:\windows\system32\drivers\UACeekxqqkmxo.sys
                          c:\windows\system32\dumphive.exe
                          c:\windows\system32\IEDFix.C.exe
                          c:\windows\system32\IEDFix.exe
                          c:\windows\system32\o4Patch.exe
                          c:\windows\system32\Process.exe
                          c:\windows\system32\SrchSTS.exe
                          c:\windows\system32\tmp.reg
                          c:\windows\system32\UACawlcjsntxh.dll
                          c:\windows\system32\UACcnlpajdjyy.dll
                          c:\windows\system32\UACgroayxiqow.dll
                          c:\windows\system32\uacinit.dll
                          c:\windows\system32\UACjjdokevgkn.dll
                          c:\windows\system32\UACneppglrspt.dat
                          c:\windows\system32\UACqeuklpgfty.db
                          c:\windows\system32\UACquoendotlm.dll
                          c:\windows\system32\VACFix.exe
                          c:\windows\system32\VCCLSID.exe
                          c:\windows\system32\WS2Fix.exe

                          .
                          ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          -------\Service_UACd.sys
                          -------\Legacy_UACd.sys

                          ((((((((((((((((((((((((((((( Fichiers créés du 2009-08-26 au 2009-09-26 ))))))))))))))))))))))))))))))))))))
                          .

                          2009-09-26 21:22 . 2009-09-26 21:23 -------- d-----w- C:\vinceLevs
                          2009-09-26 16:53 . 2009-09-26 16:54 -------- d-----w- c:\program files\CamStudio
                          2009-09-18 01:11 . 2009-09-26 14:52 -------- d-----w- c:\program files\Gta Sa
                          2009-09-16 11:48 . 2009-06-21 21:47 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
                          2009-09-12 18:38 . 2009-09-12 18:38 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2009-09-26 21:36 . 2009-07-15 18:17 -------- d-----w- c:\program files\AwesomeBestShoppingTipsProgram
                          2009-09-26 21:22 . 2009-07-28 00:52 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
                          2009-09-26 17:15 . 2009-06-13 19:03 -------- d-----w- c:\documents and settings\Vincent\Application Data\LimeWire
                          2009-09-26 16:37 . 2009-06-09 16:33 -------- d-----w- c:\program files\Steam
                          2009-09-26 14:49 . 2009-06-11 00:47 -------- d-----w- c:\program files\Opera
                          2009-09-21 00:34 . 2009-07-01 16:19 -------- d-----w- c:\documents and settings\Vincent\Application Data\gtk-2.0
                          2009-09-16 20:14 . 2009-05-31 17:55 -------- d-----w- c:\program files\Microsoft Silverlight
                          2009-08-28 14:20 . 2009-07-28 23:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                          2009-08-27 00:47 . 2009-08-27 00:46 -------- d-----w- c:\program files\San Andreas Mod Installer
                          2009-08-22 03:49 . 2006-03-02 12:00 86182 ----a-w- c:\windows\system32\perfc00C.dat
                          2009-08-22 03:49 . 2006-03-02 12:00 512960 ----a-w- c:\windows\system32\perfh00C.dat
                          2009-08-18 13:40 . 2009-05-30 21:54 11952 ----a-w- c:\windows\system32\avgrsstx.dll
                          2009-08-18 13:40 . 2009-05-30 21:54 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
                          2009-08-18 13:40 . 2009-05-30 21:54 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
                          2009-08-17 20:37 . 2009-06-25 02:34 -------- d-----w- c:\program files\Windows Live Safety Center
                          2009-08-13 20:36 . 2009-08-13 20:35 -------- d-----w- c:\documents and settings\Vincent\Application Data\CameraWindowDC
                          2009-08-13 20:36 . 2009-08-13 20:36 -------- d-----w- c:\documents and settings\Vincent\Application Data\ZoomBrowser EX
                          2009-08-13 20:35 . 2009-08-13 20:35 -------- d-----w- c:\documents and settings\Vincent\Application Data\CANON INC
                          2009-08-05 09:00 . 2006-03-02 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
                          2009-08-01 01:47 . 2009-08-01 01:47 -------- d-----w- c:\program files\Common Files
                          2009-07-31 23:11 . 2009-05-30 20:40 -------- d--h--w- c:\program files\InstallShield Installation Information
                          2009-07-29 00:51 . 2009-07-29 00:51 -------- d-----w- c:\program files\Trend Micro
                          2009-07-29 00:13 . 2009-07-28 02:41 -------- d-----w- c:\program files\Enigma Software Group
                          2009-07-28 23:54 . 2009-07-28 23:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                          2009-07-28 21:42 . 2009-07-28 00:51 -------- d-----w- c:\program files\Spyware Doctor
                          2009-07-28 21:04 . 2009-07-28 00:52 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
                          2009-07-26 20:56 . 2009-07-26 19:41 189672 ----a-w- c:\windows\system32\PnkBstrB.exe
                          2009-07-26 20:37 . 2009-07-26 20:38 139072 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
                          2009-07-26 19:41 . 2009-07-26 19:41 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
                          2009-07-17 19:03 . 2006-03-02 12:00 58880 ----a-w- c:\windows\system32\atl.dll
                          2009-07-15 01:19 . 2009-07-15 01:19 14373 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
                          2009-07-15 01:18 . 2009-07-15 01:19 5433520 ----a-w- c:\windows\system32\SpoonUninstall.exe
                          2009-07-14 18:54 . 2009-07-26 17:40 2189856 ----a-w- c:\windows\system32\nvcuvid.dll
                          2009-07-14 18:54 . 2009-07-26 17:40 2002944 ----a-w- c:\windows\system32\nvcuda.dll
                          2009-07-14 18:54 . 2009-07-26 17:40 1706528 ----a-w- c:\windows\system32\nvcuvenc.dll
                          2009-07-14 18:54 . 2009-07-26 17:39 1597690 ----a-w- c:\windows\system32\nvdata.bin
                          2009-07-14 18:54 . 2009-05-30 20:37 485920 ----a-w- c:\windows\system32\nvudisp.exe
                          2009-07-14 18:54 . 2006-10-31 06:35 868352 ----a-w- c:\windows\system32\nvapi.dll
                          2009-07-14 18:54 . 2006-10-31 06:35 7741664 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
                          2009-07-14 18:54 . 2006-10-31 06:35 5842816 ----a-w- c:\windows\system32\nv4_disp.dll
                          2009-07-14 18:54 . 2006-10-31 06:35 151552 ----a-w- c:\windows\system32\nvcodins.dll
                          2009-07-14 18:54 . 2006-10-31 06:35 151552 ----a-w- c:\windows\system32\nvcod.dll
                          2009-07-14 18:54 . 2006-10-31 06:35 10457088 ----a-w- c:\windows\system32\nvoglnt.dll
                          2009-07-14 17:34 . 2009-07-14 17:34 86016 ----a-w- c:\windows\system32\nvmctray.dll
                          2009-07-14 17:34 . 2009-07-14 17:34 8085504 ----a-w- c:\windows\system32\nvdispsr.dll
                          2009-07-14 17:34 . 2009-07-14 17:34 4923392 ----a-w- c:\windows\system32\nvdisps.dll
                          2009-07-14 17:34 . 2009-07-14 17:34 4640768 ----a-w- c:\windows\system32\nvgamesr.dll
                          2009-07-14 17:34 . 2009-07-14 17:34 458752 ----a-w- c:\windows\system32\nvmccssr.dll
                          2009-07-14 17:34 . 2009-07-14 17:34 3547136 ----a-w- c:\windows\system32\nvgames.dll
                          2009-07-14 17:34 . 2009-07-14 17:34 2854912 ----a-w- c:\windows\system32\nvmoblsr.dll
                          2009-07-14 17:34 . 2009-07-14 17:34 188416 ----a-w- c:\windows\system32\nvmccss.dll
                          2009-07-14 17:34 . 2009-07-14 17:34 168004 ----a-w- c:\windows\system32\nvsvc32.exe
                          2009-07-14 17:34 . 2009-07-14 17:34 143360 ----a-w- c:\windows\system32\nvcolor.exe
                          2009-07-14 17:34 . 2009-07-14 17:34 13877248 ----a-w- c:\windows\system32\nvcpl.dll
                          2009-07-14 17:34 . 2009-07-14 17:34 1286144 ----a-w- c:\windows\system32\nvmobls.dll
                          2009-07-14 17:34 . 2009-07-14 17:34 229376 ----a-w- c:\windows\system32\nvmccs.dll
                          2009-07-14 03:43 . 2006-03-02 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
                          2009-07-10 14:32 . 2009-07-10 14:32 664 ----a-w- c:\windows\system32\d3d9caps.dat
                          2009-07-10 11:01 . 2009-05-30 20:37 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
                          2009-07-09 00:35 . 2009-07-09 00:35 604416 ----a-w- c:\windows\system32\TUProgSt.exe
                          2009-07-09 00:34 . 2009-07-09 00:34 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
                          2009-07-06 01:16 . 2009-07-06 01:16 130 ----a-w- c:\documents and settings\Vincent\Local Settings\Application Data\fusioncache.dat
                          2009-07-03 16:57 . 2006-03-02 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
                          .

                          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                          REGEDIT4

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
                          "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
                          "NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
                          "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-30 136600]
                          "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-18 2007832]
                          "HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
                          "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
                          "HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 49152]
                          "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
                          "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-07-09 1657376]
                          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-14 13877248]
                          "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-07-14 86016]
                          "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-08-01 16049664]
                          "SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
                          2009-08-18 13:40 11952 ----a-w- c:\windows\system32\avgrsstx.dll

                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
                          @=""

                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
                          @=""

                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
                          @="Driver"

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                          "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                          "QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                          "%windir%\\system32\\sessmgr.exe"=
                          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                          "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
                          "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
                          "c:\\Program Files\\Messenger\\msmsgs.exe"=
                          "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                          "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                          "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
                          "c:\\Program Files\\Steam\\steamapps\\hotsauce73\\counter-strike source\\hl2.exe"=
                          "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
                          "c:\\Program Files\\LimeWire\\LimeWire.exe"=
                          "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
                          "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                          "c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
                          "c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
                          "c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
                          "c:\\Documents and Settings\\Vincent\\Mes documents\\GUNz\\svchost.exe"=
                          "c:\\Program Files\\Steam\\Steam.exe"=
                          "c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
                          "c:\\Program Files\\Steam\\steamapps\\hotsauce73\\insurgency\\hl2.exe"=

                          R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-07-27 130936]
                          R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-05-30 335240]
                          R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-05-30 108552]
                          R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-05-30 908056]
                          R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-05-30 297752]
                          R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-06-01 55152]
                          R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-07-08 604416]
                          S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
                          S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-07-27 348752]

                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
                          UxTuneUp
                          .
                          Contenu du dossier 'Tâches planifiées'

                          2009-09-26 c:\windows\Tasks\1-Click Maintenance.job
                          - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 19:37]

                          2009-08-28 c:\windows\Tasks\AppleSoftwareUpdate.job
                          - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

                          2009-09-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-436374069-839522115-1004Core.job
                          - c:\documents and settings\Vincent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-31 17:52]

                          2009-09-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-436374069-839522115-1004UA.job
                          - c:\documents and settings\Vincent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-31 17:52]

                          2009-09-26 c:\windows\Tasks\User_Feed_Synchronization-{151B9499-0F7D-4045-828F-4BEBD777E432}.job
                          - c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
                          .
                          .
                          ------- Examen supplémentaire -------
                          .
                          uLocal Page = \blank.htm
                          uStart Page = hxxp://google.ca/
                          uInternet Settings,ProxyOverride = *.local
                          IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                          FF - ProfilePath - c:\documents and settings\Vincent\Application Data\Mozilla\Firefox\Profiles\won0ex5x.default\
                          FF - plugin: c:\documents and settings\Vincent\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
                          FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
                          FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
                          FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
                          .
                          - - - - ORPHELINS SUPPRIMES - - - -

                          WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)

                          **************************************************************************

                          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2009-09-26 17:37
                          Windows 5.1.2600 Service Pack 3 NTFS

                          Recherche de processus cachés ...

                          Recherche d'éléments en démarrage automatique cachés ...

                          Recherche de fichiers cachés ...

                          Scan terminé avec succès
                          Fichiers cachés: 0

                          **************************************************************************
                          .
                          --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                          [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
                          "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
                          .
                          Heure de fin: 2009-09-26 17:38
                          ComboFix-quarantined-files.txt 2009-09-26 21:38

                          Avant-CF: 107 022 602 240 octets libres
                          Après-CF: 108 052 471 808 octets libres

                          WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
                          [boot loader]
                          timeout=2
                          default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
                          [operating systems]
                          c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                          multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

                          234 --- E O F --- 2009-09-16 13:01
                          0
                          1. Ok, supprime combofix sur ton bureau.

                            Télécharge-le ici : http://sd-1.archive-host.com/membres/up/21362097671547645/vinceLevs.exe

                            Lance-le en double-cliquant sur vinceLevs.exe.

                            ++
                            0
                            1. jai sauvegarder combofix sur mon bureau mais quand je clique dessu rien ne se passe
                              0
                              1. Salut.

                                Suite à ton MP:

                                /!\ A l'attention de ceux qui passent sur ce sujet : L'outil qui suit ne doit pas être utilisé sans avis /!\

                                /!\ Désactive tes protections résidentes (Antivirus, Antispywares, etc...) /!\


                                Télécharge ComboFix (de sUBs) sur ton Bureau.

                                http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                                * Double-clique sur ComboFix.exe (le .exe n'est pas forcément visible) afin de le lancer.
                                * Il va te demander d'installer la console de récupération : ACCEPTE !.
                                * Ne touche pas au pc durant le scan.
                                * Lorsque la recherche sera terminée, un rapport apparaîtra. Poste ce rapport (C:\Combofix.txt) dans ta prochaine réponse.

                                Pour t'aider : Un Tutoriel sur l'utilisation de ComboFix (à lire avant de le lancer)

                                -->> https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                                ++
                                0
                                1. Desoler pour tout ses post mais mon probleme dicone et de bar de tache est regler (redemarrer lordi...XD)
                                  0
                                  1. Okay... jai choisi nettoyage desoler jai mal lue en se moment je nai plus de toolbar ni dicone sur mon bureau....
                                    mais bon jai quand meme pu faire recherche et voici ce que sa ma donner SmitFraudFix v2.423

                                    Rapport fait à 10:05:14,37, 2009-08-28
                                    Executé à partir de C:\Documents and Settings\Vincent\Bureau\SmitfraudFix
                                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                                    Le type du système de fichiers est NTFS
                                    Fix executé en mode normal

                                    »»»»»»»»»»»»»»»»»»»»»»»» Process

                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\csrss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                    C:\Program Files\Bonjour\mDNSResponder.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Java\jre6\bin\jqs.exe
                                    C:\WINDOWS\system32\PnkBstrA.exe
                                    C:\WINDOWS\system32\PnkBstrB.exe
                                    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                                    C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                    C:\Program Files\Spyware Doctor\pctsSvc.exe
                                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\TUProgSt.exe
                                    C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                    C:\Program Files\Canon\CAL\CALMAIN.exe
                                    C:\Program Files\AVG\AVG8\avgcsrvx.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                    C:\WINDOWS\System32\alg.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Internet Explorer\Iexplore.exe
                                    C:\Program Files\Internet Explorer\Iexplore.exe
                                    C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
                                    C:\Documents and Settings\Vincent\Bureau\SmitfraudFix\Policies.exe
                                    C:\WINDOWS\system32\cmd.exe
                                    C:\WINDOWS\system32\wbem\wmiprvse.exe

                                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Vincent

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Vincent\LOCALS~1\Temp

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Vincent\Application Data

                                    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Vincent\Favoris

                                    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                                    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                                    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                                    "Source"="About:Home"
                                    "SubscribedURL"="About:Home"
                                    "FriendlyName"="Ma page d'accueil"

                                    »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    o4Patch
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    IEDFix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    Agent.OMZ.Fix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    VACFix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    404Fix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    SrchSTS.exe by S!Ri
                                    Search SharedTaskScheduler's .dll

                                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

                                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                                    »»»»»»»»»»»»»»»»»»»»»»»» RK

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                    Description: NVIDIA nForce Networking Controller - Miniport d'ordonnancement de paquets
                                    DNS Server Search Order: 192.168.2.1

                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{82D9356A-1D20-43FF-806F-2E52612C314F}: DhcpNameServer=192.168.2.1
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{82D9356A-1D20-43FF-806F-2E52612C314F}: DhcpNameServer=192.168.2.1
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{82D9356A-1D20-43FF-806F-2E52612C314F}: DhcpNameServer=192.168.2.1
                                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
                                    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

                                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                                    »»»»»»»»»»»»»»»»»»»»»»»» Fin

                                    0
                                    1. Eeeeh oui jai nai pas ▶ Clique ensuite sur désactiver et valide. desoler pour le retard de la reponse je pensai que je revcevrai un courriel me disant que quelqun ma ecrit

                                      en se momant je suis entrain dessayer les options que tum ma donner
                                      0
                                      • 1
                                      • 2