Mon pc bloque sans cesse

Bonjour,
j'ai besoin d'aide car mon ordi bloque tres souvent malgré tous les netoyages au quotidien
merci de m'aider
Configuration: Windows Vista
Firefox 3.5.3

22 réponses

Résumé de la discussion

Blocage fréquent de l’ordinateur sous Windows Vista et Firefox 3.5.3 malgré des nettoyages quotidiens, ce qui peut indiquer une infection ou une maintenance inappropriée persistance. Parmi les réponses, il est conseillé d’arrêter l’outil OTM, puis de désactiver des comptes d’utilisateur et de relancer OTM en mode administrateur afin d’initier un diagnostic sur l’infection. En cas de persistance, des solutions complémentaires évoquent RSIT et ComboFix, puis Malwarebytes et une restauration système, avec vérification des rapports et réactivation de la protection en temps réel après le diagnostic. Des échanges ultérieurs signalent l’importance de disposer d’un antivirus et de nettoyer les rapports de scan, et montrent qu’un point de restauration ou l’absence d’antivirus peut influencer les résultats et la stabilité du système.

Bobot (l’IA à votre service)
  1. Essayes de le démmarrer en mode sans échec:

    ==> Comment aller en Mode sans échec
    1) Redémarre ton ordi
    2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
    3) Tu verras un écran avec options de démarrage apparaître
    4) Choisis l' option : Sans Échec avec prise en charge rèseau et valide avec "Entrée"

    a+
    1. je note quand mème que "relevantknowledje" est toujours visible dans__tous les programmes


      Supprime le manuellement (clc droit).

      a+
      1. bon,je crois que tout est clean
        je te suis reconnaissant pour le boulot éfectué
        je te souhaite de résoudre beaucoup d'énigmes(puisque c'est ta passion)
        et je te laisse le mot de la fin,à toi de mettre en résolue si tu penses que le travail est fini
        MERCI
      2. bonjour archet9,
        j'ai un gros soussis,alors que tout allé bien,haujourd'hui vers midi,le pc à planté completement
        j'ai éssayé de le faire partir mais je n'y arrive pas,je voudrais avoir accés à la restauration système que j'ai fait hier mais je ne sais pas faire puisque le seul moyen d'accés c'est en tapotant les touches f9,f12,supprime,etc
        as-tu une soluce
        merci
    2. Donc si tout va bien...

      Pour desinstaller les outils utilisés
      Telecharge ToolsCleaner2--> http://pc-system.fr/
      -Une fois téléchargé, installe-le et lance-le
      -Clique sur Recherche et laisse le scan se terminer
      -Clique sur SUPPRESSION
      -Clique sur Quitter pour que le rapport puisse se créer
      -Poste moi le rapport se trouvant ici--> C:\TCleaner.txt

      puis

      ---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
      https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

      * Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
      * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
      * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse(Sauvegarde la base de registre).
      * Décoche la case plus vieux que 48 h

      TRES IMPORTANT:

      ---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger :
      XP:
      https://www.tayo.fr/desactiver-restauration-systeme-sur-windows-xp-tutoriel.php
      VISTA:
      https://www.tayo.fr/desactiver-restauration-windows-vista-tutoriel.php

      ---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème :
      https://www.vulgarisation-informatique.com/creer-point-restauration.php

      a+

      1. j'ai fais ce que tu m'as demandé,mais Tcleaner me refuse le log text:
        (impossible de creer le fichier "c:\Tcleaner,txt"accés refusé) mais j'ai quand mème suprimé les outils
        je note quand mème que "relevantknowledje" est toujours visible dans__tous les programmes__
        sinon il ne me reste plus qu'a purger la restauration système
        voila,voila
    3. Voyons voir ce qu'en pense Genproc:

      Telecharge GENPROC

      http://www.genproc.com/GenProc.exe

      Copie et colle le rapport stp...

      a+
      1. voila chef

        Rapport GenProc 2.640 [1] - 26/10/2009 à 19:33:00
        @ Windows Vista Service Pack 2 - Mode normal
        @ Mozilla Firefox (3.5.3) [Navigateur par défaut]

        GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :

        Poste un rapport Nod32 https://www.eset.com/ (il faut utiliser Internet Explorer)
        - coche toutes les cases à chaque fois, et lorsque c'est terminé, colle le rapport :
        C:\Program Files\EsetOnlineScanner\log.txt

        ~~~~ INFORMATION COMPLEMENTAIRE ~~~~

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 19:33:49, on 26/10/2009
        Platform: Windows Vista SP2 (WinNT 6.00.1906)
        MSIE: Internet Explorer v8.00 (8.00.6001.18828)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Microsoft Security Essentials\msseces.exe
        C:\Windows\System32\mobsync.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Windows\system32\NOTEPAD.EXE
        C:\Windows\system32\cmd.exe
        C:\GenProc\outil\jc-joce_GenProc.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
        O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O13 - Gopher Prefix:
        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
        O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
        O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
        O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
        O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
        O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
        O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
        O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
        O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
        O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
        O23 - Service: RelevantKnowledge - Unknown owner - C:\Program Files\RelevantKnowledge\rlservice.exe (file missing)
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    4. j'ai oublié de te dire que une restauration systeme à été faite


      ==> Et RelevantKnowledge est revenu avec la restauration système....

      Relances malwarebytes
      mets le a jour...(onglet mise a jour)
      Click maintenant sur l´onglet recherche et coche la case : "executer un examen rapide".

      a+
      1. le voici
        et merci encore pour ta patience

        Malwarebytes' Anti-Malware 1.41
        Version de la base de données: 3036
        Windows 6.0.6002 Service Pack 2

        26/10/2009 19:15:49
        mbam-log-2009-10-26 (19-15-49).txt

        Type de recherche: Examen rapide
        Eléments examinés: 90874
        Temps écoulé: 2 minute(s), 9 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 0
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 0

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        (Aucun élément nuisible détecté)
    5. re,

      Relances à nouveau RSIT er si tout est ok, on finira!

      a+
      1. re
        j'ai oublié de te dire que une restauration systeme à été faite et qu'on à remis l'anti-virus de chez microsoft
        voici le log en deux parties
        Logfile of random's system information tool 1.06 (written by random/random)
        Run by jc-joce at 2009-10-26 18:12:50
        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
        System drive C: has 584 GB (96%) free of 610 GB
        Total RAM: 3326 MB (70% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:13:39, on 26/10/2009
        Platform: Windows Vista SP2 (WinNT 6.00.1906)
        MSIE: Internet Explorer v8.00 (8.00.6001.18828)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Microsoft Security Essentials\msseces.exe
        C:\Windows\System32\mobsync.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Users\jc-joce\Downloads\RSIT.exe
        C:\Program Files\trend micro\jc-joce.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
        O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
        O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O13 - Gopher Prefix:
        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
        O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
        O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
        O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
        O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
        O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
        O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
        O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
        O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
        O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
        O23 - Service: RelevantKnowledge - Unknown owner - C:\Program Files\RelevantKnowledge\rlservice.exe (file missing)
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      2. et le deux

        2009-10-19 07:08:41 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
        2009-10-19 07:08:41 ----A---- C:\Windows\system32\scecli.dll
        2009-10-19 07:08:41 ----A---- C:\Windows\system32\rasplap.dll
        2009-10-19 07:08:41 ----A---- C:\Windows\system32\rasgcw.dll
        2009-10-19 07:08:41 ----A---- C:\Windows\system32\PnPUnattend.exe
        2009-10-19 07:08:41 ----A---- C:\Windows\system32\FWPUCLNT.DLL
        2009-10-19 07:08:41 ----A---- C:\Windows\system32\fdWSD.dll
        2009-10-19 07:08:41 ----A---- C:\Windows\system32\cmmon32.exe
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\wiaaut.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\whealogr.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\srcore.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\SCardSvr.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\raschap.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\MSVidCtl.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\fontext.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\conime.exe
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\cmdial32.dll
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\WMVXENCD.DLL
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\wlanui.dll
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\shwebsvc.dll
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\rasppp.dll
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\PnPutil.exe
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\oobefldr.dll
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\dsprop.dll
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\dimsroam.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\wmdrmsdk.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\wlgpclnt.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\shsetup.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\rasmontr.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\mscandui.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\modemui.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\dataclen.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\chtbrkr.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\blackbox.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\WSDMon.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\wmpeffects.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\smss.exe
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\rdpwsx.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\networkexplorer.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\netplwiz.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\ifmon.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\credui.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\certprop.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\wscapi.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\wpcsvc.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\thawbrkr.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\softkbd.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\sendmail.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\msscp.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\msimtf.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\logagent.exe
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\InkEd.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\gpresult.exe
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\cipher.exe
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\puiapi.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\olepro32.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\msctfui.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\input.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\ExplorerFrame.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\drmmgrtn.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\dmsynth.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\cdd.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\wshbth.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\version.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\SLLUA.exe
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\msisip.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\MsCtfMonitor.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\mprapi.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\fdSSDP.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\fc.exe
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\dmusic.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\cscapi.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\wsdchngr.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\Storprop.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\SMBHelperClass.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\rasdial.exe
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\rasdiag.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\msjint40.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\l2nacp.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\ftp.exe
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\fdWCN.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\eapp3hst.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\dot3cfg.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\cscdll.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\bthudtask.exe
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\bthci.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\tscupgrd.exe
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\slcinst.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\ocsetup.exe
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\nslookup.exe
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\networkitemfactory.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\ipconfig.exe
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\hbaapi.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\FwRemoteSvr.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\fdeploy.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\eappgnui.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\eappcfg.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
        2009-10-19 07:08:31 ----A---- C:\Windows\system32\PNPXAssoc.dll
        2009-10-19 07:08:31 ----A---- C:\Windows\system32\mmcico.dll
        2009-10-19 07:08:31 ----A---- C:\Windows\system32\gpupdate.exe
        2009-10-19 07:08:31 ----A---- C:\Windows\system32\cbsra.exe
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\winrnr.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\vdmdbg.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\slwga.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\odbcconf.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\NcdProp.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\iscsilog.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\inetppui.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\csrstub.exe
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\bitsigd.dll
        2009-10-19 07:08:29 ----A---- C:\Windows\system32\midimap.dll
        2009-10-19 07:08:28 ----A---- C:\Windows\system32\msimsg.dll
        2009-10-19 07:08:28 ----A---- C:\Windows\system32\f3ahvoas.dll
        2009-10-19 07:08:19 ----A---- C:\Windows\system32\SmiEngine.dll
        2009-10-19 07:08:18 ----A---- C:\Windows\system32\wdscore.dll
        2009-10-19 07:08:18 ----A---- C:\Windows\system32\PkgMgr.exe
        2009-10-19 07:08:17 ----A---- C:\Windows\system32\drvstore.dll
        2009-10-19 04:27:16 ----A---- C:\Windows\system32\Oemdspif.dll
        2009-10-19 04:27:15 ----A---- C:\Windows\system32\atiumdva.dll
        2009-10-19 04:27:15 ----A---- C:\Windows\system32\atiumdag.dll
        2009-10-19 04:27:15 ----A---- C:\Windows\system32\atitmmxx.dll
        2009-10-19 04:27:15 ----A---- C:\Windows\system32\atipdlxx.dll
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\atioglxx.dll
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODE.exe.manifest
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODE.exe
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODCLI.exe.manifest
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODCLI.exe
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\atidxx32.dll
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIDEMGX.dll
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\atibrtmon.exe
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\atiadlxx.dll
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\Ati2evxx.exe
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\Ati2evxx.dll
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\ati2edxx.dll
        2009-10-19 04:27:13 ----A---- C:\Windows\system32\amdpcom32.dll
        2009-10-18 21:51:41 ----A---- C:\Windows\system32\jscript.dll
        2009-10-18 21:48:52 ----D---- C:\Users\jc-joce\AppData\Roaming\WinRAR
        2009-10-18 21:47:09 ----A---- C:\Windows\system32\d3dx9_32.dll
        2009-10-18 21:46:46 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
        2009-10-18 21:45:27 ----D---- C:\Program Files\CCleaner
        2009-10-18 21:43:15 ----D---- C:\Program Files\WinRAR
        2009-10-18 21:40:10 ----D---- C:\Program Files\Microsoft
        2009-10-18 21:39:54 ----D---- C:\Program Files\Windows Live SkyDrive
        2009-10-18 21:39:38 ----D---- C:\Program Files\Windows Live
        2009-10-18 21:33:20 ----N---- C:\Windows\system32\MpSigStub.exe
        2009-10-18 21:32:37 ----D---- C:\Program Files\Common Files\Windows Live
        2009-10-18 21:29:57 ----D---- C:\Program Files\Microsoft Security Essentials
        2009-10-18 21:18:39 ----A---- C:\Windows\Acer(Wide).ini
        2009-10-18 21:18:39 ----A---- C:\Windows\Acer(Normal).ini
        2009-10-18 21:18:38 ----D---- C:\Windows\Acer_Wide
        2009-10-18 21:18:38 ----D---- C:\Program Files\Acer Incorporated
        2009-10-18 21:18:36 ----D---- C:\Windows\Acer_Normal
        2009-10-18 21:17:59 ----D---- C:\Users\jc-joce\AppData\Roaming\Mozilla
        2009-10-18 21:17:53 ----D---- C:\Program Files\Mozilla Firefox
        2009-10-18 21:17:29 ----D---- C:\Users\jc-joce\AppData\Roaming\InstallShield
        2009-10-18 21:17:14 ----D---- C:\Program Files\Northstar
        2009-10-18 21:13:23 ----A---- C:\Windows\system32\occache.dll
        2009-10-18 21:13:22 ----A---- C:\Windows\system32\msfeedsbs.dll
        2009-10-18 21:13:22 ----A---- C:\Windows\system32\msfeeds.dll
        2009-10-18 21:13:22 ----A---- C:\Windows\system32\jsproxy.dll
        2009-10-18 21:13:22 ----A---- C:\Windows\system32\ieui.dll
        2009-10-18 21:13:22 ----A---- C:\Windows\system32\iepeers.dll
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\wininet.dll
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\msfeedssync.exe
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\iesetup.dll
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\iertutil.dll
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\iernonce.dll
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\iedkcs32.dll
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\ie4uinit.exe
        2009-10-18 21:13:20 ----A---- C:\Windows\system32\urlmon.dll
        2009-10-18 21:13:20 ----A---- C:\Windows\system32\ieUnatt.exe
        2009-10-18 21:13:20 ----A---- C:\Windows\system32\iesysprep.dll
        2009-10-18 21:13:20 ----A---- C:\Windows\system32\ieframe.dll
        2009-10-18 21:13:19 ----A---- C:\Windows\system32\mshtml.dll
        2009-10-18 21:11:43 ----A---- C:\Windows\system32\mshtmled.dll
        2009-10-18 21:11:43 ----A---- C:\Windows\system32\icardie.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\msls31.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\mshtmler.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\imgutil.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\ieakeng.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\dxtmsft.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\corpol.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\admparse.dll
        2009-10-18 21:11:41 ----A---- C:\Windows\system32\webcheck.dll
        2009-10-18 21:11:41 ----A---- C:\Windows\system32\msrating.dll
        2009-10-18 21:11:41 ----A---- C:\Windows\system32\licmgr10.dll
        2009-10-18 21:11:41 ----A---- C:\Windows\system32\inseng.dll
        2009-10-18 21:11:41 ----A---- C:\Windows\system32\ieaksie.dll
        2009-10-18 21:11:41 ----A---- C:\Windows\system32\dxtrans.dll
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\WinFXDocObj.exe
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\wextract.exe
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\pngfilt.dll
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\mstime.dll
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\ieapfltr.dll
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\ieakui.dll
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\advpack.dll
        2009-10-18 21:11:39 ----A---- C:\Windows\system32\vbscript.dll
        2009-10-18 21:11:39 ----A---- C:\Windows\system32\url.dll
        2009-10-18 21:11:38 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
        2009-10-18 21:11:38 ----A---- C:\Windows\system32\SetDepNx.exe
        2009-10-18 21:11:38 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
        2009-10-18 21:11:38 ----A---- C:\Windows\system32\PDMSetup.exe
        2009-10-18 21:11:38 ----A---- C:\Windows\system32\mshta.exe
        2009-10-18 21:11:38 ----A---- C:\Windows\system32\iexpress.exe
        2009-10-18 21:10:04 ----D---- C:\Users\jc-joce\AppData\Roaming\Macromedia
        2009-10-18 21:07:27 ----D---- C:\Users\jc-joce\AppData\Roaming\Adobe
        2009-10-18 21:07:21 ----D---- C:\Users\jc-joce\AppData\Roaming\Google
        2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwutl32_priv.dll
        2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwutl32.dll
        2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwpnp32_priv.dll
        2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwpnp32.dll
        2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwi2c32.dll
        2009-10-18 21:01:38 ----A---- C:\Windows\system32\tzres.dll
        2009-10-18 20:16:37 ----A---- C:\Windows\system32\netfxperf.dll
        2009-10-18 20:15:15 ----D---- C:\Program Files\MSXML 4.0
        2009-10-18 20:02:30 ----A---- C:\Windows\system32\netiohlp.dll
        2009-10-18 20:02:27 ----A---- C:\Windows\system32\NETSTAT.EXE
        2009-10-18 20:02:27 ----A---- C:\Windows\system32\ARP.EXE
        2009-10-18 20:02:26 ----A---- C:\Windows\system32\TCPSVCS.EXE
        2009-10-18 20:02:25 ----A---- C:\Windows\system32\HOSTNAME.EXE
        2009-10-18 20:02:25 ----A---- C:\Windows\system32\finger.exe
        2009-10-18 20:02:24 ----A---- C:\Windows\system32\ROUTE.EXE
        2009-10-18 20:02:24 ----A---- C:\Windows\system32\MRINFO.EXE
        2009-10-18 20:02:21 ----A---- C:\Windows\system32\netevent.dll
        2009-10-18 20:01:21 ----A---- C:\Windows\system32\gameux.dll
        2009-10-18 20:01:18 ----A---- C:\Windows\system32\Apphlpdm.dll
        2009-10-18 20:01:15 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
        2009-10-18 20:01:12 ----A---- C:\Windows\system32\WMVCORE.DLL
        2009-10-18 20:01:12 ----A---- C:\Windows\system32\mf.dll
        2009-10-18 20:01:10 ----A---- C:\Windows\system32\rrinstaller.exe
        2009-10-18 20:01:10 ----A---- C:\Windows\system32\mfps.dll
        2009-10-18 20:01:10 ----A---- C:\Windows\system32\mfpmp.exe
        2009-10-18 20:01:09 ----A---- C:\Windows\system32\mferror.dll
        2009-10-18 20:00:43 ----A---- C:\Windows\system32\rpcrt4.dll
        2009-10-18 20:00:36 ----A---- C:\Windows\system32\lsasrv.dll
        2009-10-18 20:00:36 ----A---- C:\Windows\system32\kerberos.dll
        2009-10-18 20:00:35 ----A---- C:\Windows\system32\wdigest.dll
        2009-10-18 20:00:35 ----A---- C:\Windows\system32\schannel.dll
        2009-10-18 20:00:32 ----A---- C:\Windows\system32\secur32.dll
        2009-10-18 20:00:30 ----A---- C:\Windows\system32\lsass.exe
        2009-10-18 20:00:24 ----A---- C:\Windows\system32\ntoskrnl.exe
        2009-10-18 20:00:24 ----A---- C:\Windows\system32\ntkrnlpa.exe
        2009-10-18 20:00:20 ----A---- C:\Windows\system32\wmp.dll
        2009-10-18 20:00:18 ----A---- C:\Windows\system32\wmpdxm.dll
        2009-10-18 20:00:15 ----A---- C:\Windows\system32\spwmp.dll
        2009-10-18 20:00:13 ----A---- C:\Windows\system32\dxmasf.dll
        2009-10-18 20:00:12 ----A---- C:\Windows\system32\wmploc.DLL
        2009-10-18 20:00:05 ----A---- C:\Windows\system32\localspl.dll
        2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlansvc.dll
        2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlansec.dll
        2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlanmsm.dll
        2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlanhlp.dll
        2009-10-18 20:00:01 ----A---- C:\Windows\system32\L2SecHC.dll
        2009-10-18 19:59:59 ----A---- C:\Windows\system32\wlanapi.dll
        2009-10-18 19:59:54 ----A---- C:\Windows\system32\tsgqec.dll
        2009-10-18 19:59:54 ----A---- C:\Windows\system32\mstscax.dll
        2009-10-18 19:59:54 ----A---- C:\Windows\system32\aaclient.dll
        2009-10-18 19:59:50 ----A---- C:\Windows\system32\t2embed.dll
        2009-10-18 19:59:50 ----A---- C:\Windows\system32\fontsub.dll
        2009-10-18 19:59:50 ----A---- C:\Windows\system32\atmfd.dll
        2009-10-18 19:59:49 ----A---- C:\Windows\system32\lpk.dll
        2009-10-18 19:59:49 ----A---- C:\Windows\system32\atmlib.dll
        2009-10-18 19:59:47 ----A---- C:\Windows\system32\dciman32.dll
        2009-10-18 19:59:44 ----A---- C:\Windows\system32\msv1_0.dll
        2009-10-18 19:59:20 ----A---- C:\Windows\system32\wkssvc.dll
        2009-10-18 19:59:03 ----A---- C:\Windows\system32\avifil32.dll
        2009-10-18 19:58:56 ----A---- C:\Windows\system32\atl.dll
        2009-10-18 19:55:01 ----A---- C:\Windows\system32\msasn1.dll
        2009-10-18 19:49:22 ----D---- C:\ProgramData\ATI
        2009-10-18 19:49:21 ----D---- C:\Users\jc-joce\AppData\Roaming\ATI
        2009-10-18 19:49:13 ----SHD---- C:\$RECYCLE.BIN
        2009-10-18 19:48:56 ----D---- C:\Users\jc-joce\AppData\Roaming\Identities
        2009-10-18 19:48:49 ----A---- C:\Windows\system32\WMSPDMOD.DLL
        2009-10-18 19:48:19 ----D---- C:\ProgramData\Partner
        2009-10-18 19:47:42 ----D---- C:\ProgramData\Google
        2009-10-18 19:47:39 ----D---- C:\Program Files\Google
        2009-10-18 19:45:00 ----SD---- C:\Users\jc-joce\AppData\Roaming\Microsoft
        2009-10-18 19:45:00 ----D---- C:\Users\jc-joce\AppData\Roaming\Media Center Programs
        2009-10-18 19:45:00 ----D---- C:\Users\jc-joce\AppData\Roaming\Acer GameZone Console
        2009-10-18 19:42:14 ----A---- C:\Windows\system32\wups2.dll
        2009-10-18 19:42:14 ----A---- C:\Windows\system32\wucltux.dll
        2009-10-18 19:42:14 ----A---- C:\Windows\system32\wuauclt.exe
        2009-10-18 19:42:13 ----A---- C:\Windows\system32\wuaueng.dll
        2009-10-18 19:42:06 ----A---- C:\Windows\system32\wups.dll
        2009-10-18 19:42:06 ----A---- C:\Windows\system32\wudriver.dll
        2009-10-18 19:42:05 ----A---- C:\Windows\system32\wuapi.dll
        2009-10-18 19:42:03 ----A---- C:\Windows\system32\wuwebv.dll
        2009-10-18 19:42:03 ----A---- C:\Windows\system32\wuapp.exe
        2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Modèles
        2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Menu Démarrer
        2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Favoris
        2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Bureau
        2009-10-18 19:41:29 ----SHD---- C:\Program Files\Fichiers communs
        2009-10-18 19:35:33 ----D---- C:\Program Files\ATI Technologies
        2009-10-18 19:32:38 ----D---- C:\Program Files\ATI
        2009-10-18 19:32:28 ----A---- C:\Windows\ATIDetect.txt
        2009-10-18 19:30:35 ----A---- C:\Windows\system32\nvraiins.dll
        2009-10-18 19:30:32 ----D---- C:\Windows\SoftwareDistribution

        ======List of files/folders modified in the last 1 months======

        2009-10-26 17:01:43 ----D---- C:\Windows\System32
        2009-10-26 17:01:43 ----D---- C:\Windows\inf
        2009-10-26 17:01:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
        2009-10-26 16:57:24 ----D---- C:\Windows
        2009-10-26 16:13:36 ----D---- C:\Windows\system32\LogFiles
        2009-10-26 14:41:55 ----HD---- C:\Windows\system32\GroupPolicy
        2009-10-26 14:41:55 ----HD---- C:\ProgramData
        2009-10-26 14:08:35 ----RD---- C:\Program Files
        2009-10-26 13:48:56 ----SHD---- C:\System Volume Information
        2009-10-26 13:15:48 ----D---- C:\Windows\rescache
        2009-10-26 13:12:25 ----SHD---- C:\Windows\Installer
        2009-10-26 12:39:28 ----D---- C:\Windows\winsxs
        2009-10-26 12:39:26 ----D---- C:\Windows\system32\migration
        2009-10-26 12:39:26 ----D---- C:\Windows\system32\fr-FR
        2009-10-26 12:39:25 ----D---- C:\Windows\system32\inetsrv
        2009-10-26 07:13:37 ----D---- C:\Windows\system32\config
        2009-10-26 07:13:32 ----D---- C:\Windows\Tasks
        2009-10-26 07:13:32 ----D---- C:\Windows\system32\spool
        2009-10-26 07:13:31 ----SD---- C:\ProgramData\Microsoft
        2009-10-26 07:13:31 ----D---- C:\Windows\system32\drivers
        2009-10-26 07:13:31 ----D---- C:\Windows\system32\CodeIntegrity
        2009-10-26 07:13:30 ----D---- C:\Windows\registration
        2009-10-26 06:16:06 ----D---- C:\Windows\system32\catroot2
        2009-10-26 06:14:19 ----D---- C:\Windows\system32\Msdtc
        2009-10-26 06:14:18 ----D---- C:\Windows\system32\wbem
        2009-10-25 15:14:25 ----D---- C:\Windows\AppPatch
        2009-10-25 15:14:25 ----D---- C:\Program Files\Common Files
        2009-10-25 14:08:07 ----D---- C:\Windows\Prefetch
        2009-10-24 19:37:01 ----HD---- C:\Program Files\InstallShield Installation Information
        2009-10-24 19:29:42 ----RSD---- C:\Windows\Fonts
        2009-10-24 19:29:41 ----SD---- C:\Windows\Downloaded Program Files
        2009-10-24 19:29:41 ----D---- C:\Program Files\Common Files\InstallShield
        2009-10-24 16:33:30 ----D---- C:\PerfLogs
        2009-10-23 15:06:04 ----D---- C:\Windows\ShellNew
        2009-10-23 07:25:11 ----D---- C:\Windows\Logs
        2009-10-22 06:39:42 ----D---- C:\Windows\system32\Tasks
        2009-10-21 08:13:28 ----D---- C:\Windows\system32\NDF
        2009-10-19 19:50:37 ----D---- C:\Windows\twain_32
        2009-10-19 19:50:17 ----A---- C:\Windows\win.ini
        2009-10-19 15:24:11 ----D---- C:\Windows\Microsoft.NET
        2009-10-19 15:24:04 ----RSD---- C:\Windows\assembly
        2009-10-19 15:14:27 ----D---- C:\Windows\system32\catroot
        2009-10-19 14:41:10 ----D---- C:\ProgramData\CyberLink
        2009-10-19 09:13:32 ----D---- C:\Program Files\Common Files\Adobe
        2009-10-19 09:13:28 ----D---- C:\ProgramData\Adobe
        2009-10-19 07:24:45 ----D---- C:\Boot
        2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Sidebar
        2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Media Player
        2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Mail
        2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Collaboration
        2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Calendar
        2009-10-19 07:20:50 ----D---- C:\Program Files\Movie Maker
        2009-10-19 07:20:50 ----D---- C:\Program Files\Internet Explorer
        2009-10-19 07:20:49 ----D---- C:\Program Files\Windows Photo Gallery
        2009-10-19 07:20:49 ----D---- C:\Program Files\Common Files\System
        2009-10-19 07:20:48 ----D---- C:\Windows\servicing
        2009-10-19 07:20:48 ----D---- C:\Windows\ehome
        2009-10-19 07:20:48 ----D---- C:\Program Files\Windows Defender
        2009-10-19 07:20:46 ----D---- C:\Windows\system32\lv-LV
        2009-10-19 07:20:46 ----D---- C:\Windows\IME
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\XPSViewer
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\sk-SK
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\ru-RU
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\oobe
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\ko-KR
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\it-IT
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\hr-HR
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\fr
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\et-EE
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\en-US
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\el-GR
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\de-DE
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\da-DK
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\AdvancedInstallers
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\zh-TW
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\zh-CN
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\uk-UA
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\th-TH
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\sv-SE
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\sr-Latn-CS
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\SLUI
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\sl-SI
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\setup
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\ro-RO
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\pt-PT
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\pl-PL
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\manifeststore
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\ja-JP
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\hu-HU
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\he-IL
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\fi-FI
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\es-ES
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\cs-CZ
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\bg-BG
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\tr-TR
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\pt-BR
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\nl-NL
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\nb-NO
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\migwiz
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\lt-LT
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\ar-SA
        2009-10-19 07:20:35 ----D---- C:\Windows\system32\Boot
        2009-10-19 07:19:30 ----D---- C:\Windows\system32\RTCOM
        2009-10-18 22:26:52 ----D---- C:\Windows\Debug
        2009-10-18 22:06:49 ----D---- C:\Windows\system32\WDI
        2009-10-18 21:50:23 ----D---- C:\ProgramData\Microsoft Help
        2009-10-18 21:47:38 ----D---- C:\Program Files\Common Files\microsoft shared
        2009-10-18 21:47:31 ----D---- C:\Program Files\Microsoft Works
        2009-10-18 21:26:37 ----D---- C:\ACER
        2009-10-18 21:21:11 ----D---- C:\Windows\PolicyDefinitions
        2009-10-18 21:20:43 ----D---- C:\Windows\system32\OEM
        2009-10-18 21:17:31 ----D---- C:\Windows\system
        2009-10-18 19:51:46 ----D---- C:\ProgramData\SiteAdvisor
        2009-10-18 19:48:11 ----D---- C:\Program Files\Acer
        2009-10-18 19:44:49 ----RD---- C:\Users
        2009-10-18 19:41:53 ----D---- C:\Windows\system32\restore
        2009-10-18 19:41:29 ----D---- C:\Program Files\Windows NT
        2009-10-18 19:36:17 ----D---- C:\Windows\Panther
        2009-10-02 10:01:58 ----A---- C:\Windows\system32\mrt.exe

        ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

        R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2009-06-18 142832]
        R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2008-08-19 15392]
        R2 irda;Protocole IrDA; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
        R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-07-29 16944]
        R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-07-29 60464]
        R2 RMCAST;Pilote du protocole RMCAT PGMP; C:\Windows\system32\DRIVERS\RMCAST.sys [2009-04-11 113664]
        R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-10-03 3977728]
        R3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
        R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-04 2161496]
        R3 irsir;Pilote série infrarouge Microsoft; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-21 20992]
        R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2009-06-18 42480]
        R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-30 14848]
        R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-07-07 1050656]
        R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-08-24 15872]
        R3 snpstd2;Trek 310; C:\Windows\system32\DRIVERS\snpstd2.sys [2007-06-26 343808]
        R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
        R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
        R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
        S3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
        S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
        S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
        S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
        S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
        S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
        S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
        S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
        S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
        S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
        S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
        S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

        ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

        R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service; C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448]
        R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2008-01-21 21504]
        R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-10-03 704512]
        R2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
        R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-07-29 500784]
        R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576]
        R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2008-09-08 450560]
        R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
        R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
        R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
        R2 MsMpSvc;@c:\Program Files\Microsoft Security Essentials\MpAsDesc.dll,-241; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2009-07-02 17904]
        R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
        R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2008-09-08 184320]
        R2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
        R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
        R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
        R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2008-05-29 241734]
        R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-08-14 9728]
        R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
        S2 gupdate;Service Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-10-19 133104]
        S2 RelevantKnowledge;RelevantKnowledge; C:\Program Files\RelevantKnowledge\rlservice.exe /service []
        S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-18 24064]
        S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-10-18 182768]
        S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
        S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
        S3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2008-01-21 21504]

        -----------------EOF-----------------
    6. est ce qu'il-y-a encore moyen de ratraper mes co....? 


      Nok...tu n'as pas fais de conneries....
      C''était a moi de le voir !!!
      ==> Nous sommes là pour ça....</gras

      >Mais la j'ai toit de même un gros doute ....
      Car l'infection a bien éré identififiée...et le premier MBAM ne l'a pas vue !!!!!

      ==> je vais vérifier les<gras> MAJ


      En attendant...Comment se comporte le pc ?
      a+
      1. bonjour archet9,
        je viens d'arriver,j'ai demandé à ma femme pour le pc,elle a travaillée toute la journée dessus,et
        c'est RAS; elle a fait du nétoyage dessus, et la pour le moment il tourne impec
        ma femme à également scané avec malwarebytes anti-malware +anti-virus et les logs sont sains
        cordialement
    7. Excuses moi mich,

      Mais là tu me poses un sérieux pronblème:
      Excuses moi mich,

      Je t'avais demandé MBAM:

      Je l'avais déja à jour, et c'est le quatrième scan que je fais depuis se matin avec voici le log
      Malwarebytes' Anti-Malware 1.41
      Version de la base de données: 3028
      Windows 6.0.6002 Service Pack 2

      25/10/2009 12:12:45
      mbam-log-2009-10-25 (12-12-45).txt

      ==> Result :

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 0


      ENSUITE:

      ==> je te demannde ceci:(avec OTM)

      :processes
      explorer.exe

      :services
      relevantknowledge

      :files
      c:\program files\relevantknowledge\rlservice.exe

      :reg
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RelevantKnowledge

      :commands
      [purity]
      [emptytemp]
      [start explorer]
      [Reboot]

      Et enfin:
      Tu me colles un rapport MBAM:
      avec ttes les suppressionns !

      Processus mémoire infecté(s):
      C:\Program Files\RelevantKnowledge\rlservice.exe (Spyware.MarketScore) -> Unloaded process successfully. C:\Program Files\RelevantKnowledge\rlvknlg.exe (Spyware.MarketScore) -> Unloaded process successfully.

      Module(s) mémoire infecté(s):
      C:\Program Files\RelevantKnowledge\rlls.dll (Spyware.MarketScore) -> Delete on reboot.

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.

      AS-TU UNE EXPLICATON ?
      a+
      1. je suis vraiment désolé,les rapports que j'ai posté ce sont les plus recents,franchement j'ettais à mille lieux de
        savoir qu'un log d'hier était utile, cette pièce je la gardais pour mémoire au cas ou je serais de nouveau infecté
        par ces memes virus, ça porte peutètre à sourire mais mes connaissances en informatique est assez limité, et il est vrai que j'aurais put ne pas l'avoir
        je suis vraiment confus
        est ce qu'il-y-a encore moyen de ratraper mes co....?
        A+
    8. post le...

      a+
      1. le voila et encore merci pour ton aide

        Malwarebytes' Anti-Malware 1.41
        Version de la base de données: 3023
        Windows 6.0.6002 Service Pack 2

        24/10/2009 08:43:14
        mbam-log-2009-10-24 (08-43-14).txt

        Type de recherche: Examen complet (C:\|)
        Eléments examinés: 220292
        Temps écoulé: 30 minute(s), 37 second(s)

        Processus mémoire infecté(s): 2
        Module(s) mémoire infecté(s): 1
        Clé(s) du Registre infectée(s): 1
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 1
        Fichier(s) infecté(s): 4

        Processus mémoire infecté(s):
        C:\Program Files\RelevantKnowledge\rlservice.exe (Spyware.MarketScore) -> Unloaded process successfully.
        C:\Program Files\RelevantKnowledge\rlvknlg.exe (Spyware.MarketScore) -> Unloaded process successfully.

        Module(s) mémoire infecté(s):
        C:\Program Files\RelevantKnowledge\rlls.dll (Spyware.MarketScore) -> Delete on reboot.

        Clé(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)
    9. As tu beaucuop de choses à sauvegarder ?

      ==> Sinon fais une restauration complète et remmets ton pc comme au premier jour ....

      a+
      1. Si ça peut aider j'ai un rapport d'hier de malwarebytes anti-malware
    10. A tout hasard....
      aurais-tu un point de restauration antérieur a ton problème?

      a+
      1. ça devient compliqué(surtout pour moi lol)
        en fait, ce pc n'est pas vieux, il date du mois de mai 2009
        mais j'ai toujours été emm....le dernier point, date d'hier,puisque je n'arrete pas de faire des points, des restau.
        et des reenstal à l'aide de recovery
      2. @michsi ça peut aider j'ai un rapport d'hier de malwarebytes anti-malware
    11. la fin stp
      1. 3eme tentative de remise
        il à encore bloqué
        le voici

        2009-10-19 07:08:41 ----A---- C:\Windows\system32\rasplap.dll
        2009-10-19 07:08:41 ----A---- C:\Windows\system32\rasgcw.dll
        2009-10-19 07:08:41 ----A---- C:\Windows\system32\PnPUnattend.exe
        2009-10-19 07:08:41 ----A---- C:\Windows\system32\FWPUCLNT.DLL
        2009-10-19 07:08:41 ----A---- C:\Windows\system32\fdWSD.dll
        2009-10-19 07:08:41 ----A---- C:\Windows\system32\cmmon32.exe
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\wiaaut.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\whealogr.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\srcore.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\SCardSvr.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\raschap.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\MSVidCtl.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\fontext.dll
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\conime.exe
        2009-10-19 07:08:40 ----A---- C:\Windows\system32\cmdial32.dll
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\WMVXENCD.DLL
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\wlanui.dll
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\shwebsvc.dll
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\rasppp.dll
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\PnPutil.exe
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\oobefldr.dll
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\dsprop.dll
        2009-10-19 07:08:39 ----A---- C:\Windows\system32\dimsroam.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\wmdrmsdk.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\wlgpclnt.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\shsetup.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\rasmontr.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\mscandui.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\modemui.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\dataclen.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\chtbrkr.dll
        2009-10-19 07:08:38 ----A---- C:\Windows\system32\blackbox.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\WSDMon.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\wmpeffects.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\smss.exe
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\rdpwsx.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\networkexplorer.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\netplwiz.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\ifmon.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\credui.dll
        2009-10-19 07:08:37 ----A---- C:\Windows\system32\certprop.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\wscapi.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\wpcsvc.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\thawbrkr.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\softkbd.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\sendmail.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\msscp.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\msimtf.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\logagent.exe
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\InkEd.dll
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\gpresult.exe
        2009-10-19 07:08:36 ----A---- C:\Windows\system32\cipher.exe
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\puiapi.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\olepro32.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\msctfui.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\input.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\ExplorerFrame.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\drmmgrtn.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\dmsynth.dll
        2009-10-19 07:08:35 ----A---- C:\Windows\system32\cdd.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\wshbth.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\version.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\SLLUA.exe
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\msisip.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\MsCtfMonitor.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\mprapi.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\fdSSDP.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\fc.exe
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\dmusic.dll
        2009-10-19 07:08:34 ----A---- C:\Windows\system32\cscapi.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\wsdchngr.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\Storprop.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\SMBHelperClass.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\rasdial.exe
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\rasdiag.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\msjint40.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\l2nacp.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\ftp.exe
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\fdWCN.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\eapp3hst.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\dot3cfg.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\cscdll.dll
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\bthudtask.exe
        2009-10-19 07:08:33 ----A---- C:\Windows\system32\bthci.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\tscupgrd.exe
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\slcinst.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\ocsetup.exe
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\nslookup.exe
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\networkitemfactory.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\ipconfig.exe
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\hbaapi.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\FwRemoteSvr.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\fdeploy.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\eappgnui.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\eappcfg.dll
        2009-10-19 07:08:32 ----A---- C:\Windows\system32\CHxReadingStringIME.dll
        2009-10-19 07:08:31 ----A---- C:\Windows\system32\PNPXAssoc.dll
        2009-10-19 07:08:31 ----A---- C:\Windows\system32\mmcico.dll
        2009-10-19 07:08:31 ----A---- C:\Windows\system32\gpupdate.exe
        2009-10-19 07:08:31 ----A---- C:\Windows\system32\cbsra.exe
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\winrnr.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\vdmdbg.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\slwga.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\odbcconf.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\NcdProp.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\iscsilog.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\inetppui.dll
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\csrstub.exe
        2009-10-19 07:08:30 ----A---- C:\Windows\system32\bitsigd.dll
        2009-10-19 07:08:29 ----A---- C:\Windows\system32\midimap.dll
        2009-10-19 07:08:28 ----A---- C:\Windows\system32\msimsg.dll
        2009-10-19 07:08:28 ----A---- C:\Windows\system32\f3ahvoas.dll
        2009-10-19 07:08:19 ----A---- C:\Windows\system32\SmiEngine.dll
        2009-10-19 07:08:18 ----A---- C:\Windows\system32\wdscore.dll
        2009-10-19 07:08:18 ----A---- C:\Windows\system32\PkgMgr.exe
        2009-10-19 07:08:17 ----A---- C:\Windows\system32\drvstore.dll
        2009-10-19 04:27:16 ----A---- C:\Windows\system32\Oemdspif.dll
        2009-10-19 04:27:15 ----A---- C:\Windows\system32\atiumdva.dll
        2009-10-19 04:27:15 ----A---- C:\Windows\system32\atiumdag.dll
        2009-10-19 04:27:15 ----A---- C:\Windows\system32\atitmmxx.dll
        2009-10-19 04:27:15 ----A---- C:\Windows\system32\atipdlxx.dll
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\atioglxx.dll
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODE.exe.manifest
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODE.exe
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODCLI.exe.manifest
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIODCLI.exe
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\atidxx32.dll
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\ATIDEMGX.dll
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\atibrtmon.exe
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\atiadlxx.dll
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\Ati2evxx.exe
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\Ati2evxx.dll
        2009-10-19 04:27:14 ----A---- C:\Windows\system32\ati2edxx.dll
        2009-10-19 04:27:13 ----A---- C:\Windows\system32\amdpcom32.dll
        2009-10-18 21:51:41 ----A---- C:\Windows\system32\jscript.dll
        2009-10-18 21:48:52 ----D---- C:\Users\jc-joce\AppData\Roaming\WinRAR
        2009-10-18 21:47:09 ----A---- C:\Windows\system32\d3dx9_32.dll
        2009-10-18 21:46:46 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
        2009-10-18 21:45:27 ----D---- C:\Program Files\CCleaner
        2009-10-18 21:43:15 ----D---- C:\Program Files\WinRAR
        2009-10-18 21:40:10 ----D---- C:\Program Files\Microsoft
        2009-10-18 21:39:54 ----D---- C:\Program Files\Windows Live SkyDrive
        2009-10-18 21:39:38 ----D---- C:\Program Files\Windows Live
        2009-10-18 21:33:20 ----N---- C:\Windows\system32\MpSigStub.exe
        2009-10-18 21:32:37 ----D---- C:\Program Files\Common Files\Windows Live
        2009-10-18 21:18:39 ----A---- C:\Windows\Acer(Wide).ini
        2009-10-18 21:18:39 ----A---- C:\Windows\Acer(Normal).ini
        2009-10-18 21:18:38 ----D---- C:\Windows\Acer_Wide
        2009-10-18 21:18:38 ----D---- C:\Program Files\Acer Incorporated
        2009-10-18 21:18:36 ----D---- C:\Windows\Acer_Normal
        2009-10-18 21:17:59 ----D---- C:\Users\jc-joce\AppData\Roaming\Mozilla
        2009-10-18 21:17:53 ----D---- C:\Program Files\Mozilla Firefox
        2009-10-18 21:17:29 ----D---- C:\Users\jc-joce\AppData\Roaming\InstallShield
        2009-10-18 21:17:14 ----D---- C:\Program Files\Northstar
        2009-10-18 21:13:23 ----A---- C:\Windows\system32\occache.dll
        2009-10-18 21:13:22 ----A---- C:\Windows\system32\msfeedsbs.dll
        2009-10-18 21:13:22 ----A---- C:\Windows\system32\msfeeds.dll
        2009-10-18 21:13:22 ----A---- C:\Windows\system32\jsproxy.dll
        2009-10-18 21:13:22 ----A---- C:\Windows\system32\ieui.dll
        2009-10-18 21:13:22 ----A---- C:\Windows\system32\iepeers.dll
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\wininet.dll
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\msfeedssync.exe
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\iesetup.dll
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\iertutil.dll
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\iernonce.dll
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\iedkcs32.dll
        2009-10-18 21:13:21 ----A---- C:\Windows\system32\ie4uinit.exe
        2009-10-18 21:13:20 ----A---- C:\Windows\system32\urlmon.dll
        2009-10-18 21:13:20 ----A---- C:\Windows\system32\ieUnatt.exe
        2009-10-18 21:13:20 ----A---- C:\Windows\system32\iesysprep.dll
        2009-10-18 21:13:20 ----A---- C:\Windows\system32\ieframe.dll
        2009-10-18 21:13:19 ----A---- C:\Windows\system32\mshtml.dll
        2009-10-18 21:11:43 ----A---- C:\Windows\system32\mshtmled.dll
        2009-10-18 21:11:43 ----A---- C:\Windows\system32\icardie.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\msls31.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\mshtmler.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\imgutil.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\ieakeng.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\dxtmsft.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\corpol.dll
        2009-10-18 21:11:42 ----A---- C:\Windows\system32\admparse.dll
        2009-10-18 21:11:41 ----A---- C:\Windows\system32\webcheck.dll
        2009-10-18 21:11:41 ----A---- C:\Windows\system32\msrating.dll
        2009-10-18 21:11:41 ----A---- C:\Windows\system32\licmgr10.dll
        2009-10-18 21:11:41 ----A---- C:\Windows\system32\inseng.dll
        2009-10-18 21:11:41 ----A---- C:\Windows\system32\ieaksie.dll
        2009-10-18 21:11:41 ----A---- C:\Windows\system32\dxtrans.dll
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\WinFXDocObj.exe
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\wextract.exe
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\pngfilt.dll
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\mstime.dll
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\ieapfltr.dll
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\ieakui.dll
        2009-10-18 21:11:40 ----A---- C:\Windows\system32\advpack.dll
        2009-10-18 21:11:39 ----A---- C:\Windows\system32\vbscript.dll
        2009-10-18 21:11:39 ----A---- C:\Windows\system32\url.dll
        2009-10-18 21:11:38 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
        2009-10-18 21:11:38 ----A---- C:\Windows\system32\SetDepNx.exe
        2009-10-18 21:11:38 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
        2009-10-18 21:11:38 ----A---- C:\Windows\system32\PDMSetup.exe
        2009-10-18 21:11:38 ----A---- C:\Windows\system32\mshta.exe
        2009-10-18 21:11:38 ----A---- C:\Windows\system32\iexpress.exe
        2009-10-18 21:10:04 ----D---- C:\Users\jc-joce\AppData\Roaming\Macromedia
        2009-10-18 21:07:27 ----D---- C:\Users\jc-joce\AppData\Roaming\Adobe
        2009-10-18 21:07:21 ----D---- C:\Users\jc-joce\AppData\Roaming\Google
        2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwutl32_priv.dll
        2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwutl32.dll
        2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwpnp32_priv.dll
        2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwpnp32.dll
        2009-10-18 21:07:06 ----A---- C:\Windows\system32\hcwi2c32.dll
        2009-10-18 21:01:38 ----A---- C:\Windows\system32\tzres.dll
        2009-10-18 20:16:37 ----A---- C:\Windows\system32\netfxperf.dll
        2009-10-18 20:15:15 ----D---- C:\Program Files\MSXML 4.0
        2009-10-18 20:02:30 ----A---- C:\Windows\system32\netiohlp.dll
        2009-10-18 20:02:27 ----A---- C:\Windows\system32\NETSTAT.EXE
        2009-10-18 20:02:27 ----A---- C:\Windows\system32\ARP.EXE
        2009-10-18 20:02:26 ----A---- C:\Windows\system32\TCPSVCS.EXE
        2009-10-18 20:02:25 ----A---- C:\Windows\system32\HOSTNAME.EXE
        2009-10-18 20:02:25 ----A---- C:\Windows\system32\finger.exe
        2009-10-18 20:02:24 ----A---- C:\Windows\system32\ROUTE.EXE
        2009-10-18 20:02:24 ----A---- C:\Windows\system32\MRINFO.EXE
        2009-10-18 20:02:21 ----A---- C:\Windows\system32\netevent.dll
        2009-10-18 20:01:21 ----A---- C:\Windows\system32\gameux.dll
        2009-10-18 20:01:18 ----A---- C:\Windows\system32\Apphlpdm.dll
        2009-10-18 20:01:15 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
        2009-10-18 20:01:12 ----A---- C:\Windows\system32\WMVCORE.DLL
        2009-10-18 20:01:12 ----A---- C:\Windows\system32\mf.dll
        2009-10-18 20:01:10 ----A---- C:\Windows\system32\rrinstaller.exe
        2009-10-18 20:01:10 ----A---- C:\Windows\system32\mfps.dll
        2009-10-18 20:01:10 ----A---- C:\Windows\system32\mfpmp.exe
        2009-10-18 20:01:09 ----A---- C:\Windows\system32\mferror.dll
        2009-10-18 20:00:43 ----A---- C:\Windows\system32\rpcrt4.dll
        2009-10-18 20:00:36 ----A---- C:\Windows\system32\lsasrv.dll
        2009-10-18 20:00:36 ----A---- C:\Windows\system32\kerberos.dll
        2009-10-18 20:00:35 ----A---- C:\Windows\system32\wdigest.dll
        2009-10-18 20:00:35 ----A---- C:\Windows\system32\schannel.dll
        2009-10-18 20:00:32 ----A---- C:\Windows\system32\secur32.dll
        2009-10-18 20:00:30 ----A---- C:\Windows\system32\lsass.exe
        2009-10-18 20:00:24 ----A---- C:\Windows\system32\ntoskrnl.exe
        2009-10-18 20:00:24 ----A---- C:\Windows\system32\ntkrnlpa.exe
        2009-10-18 20:00:20 ----A---- C:\Windows\system32\wmp.dll
        2009-10-18 20:00:18 ----A---- C:\Windows\system32\wmpdxm.dll
        2009-10-18 20:00:15 ----A---- C:\Windows\system32\spwmp.dll
        2009-10-18 20:00:13 ----A---- C:\Windows\system32\dxmasf.dll
        2009-10-18 20:00:12 ----A---- C:\Windows\system32\wmploc.DLL
        2009-10-18 20:00:05 ----A---- C:\Windows\system32\localspl.dll
        2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlansvc.dll
        2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlansec.dll
        2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlanmsm.dll
        2009-10-18 20:00:01 ----A---- C:\Windows\system32\wlanhlp.dll
        2009-10-18 20:00:01 ----A---- C:\Windows\system32\L2SecHC.dll
        2009-10-18 19:59:59 ----A---- C:\Windows\system32\wlanapi.dll
        2009-10-18 19:59:54 ----A---- C:\Windows\system32\tsgqec.dll
        2009-10-18 19:59:54 ----A---- C:\Windows\system32\mstscax.dll
        2009-10-18 19:59:54 ----A---- C:\Windows\system32\aaclient.dll
        2009-10-18 19:59:50 ----A---- C:\Windows\system32\t2embed.dll
        2009-10-18 19:59:50 ----A---- C:\Windows\system32\fontsub.dll
        2009-10-18 19:59:50 ----A---- C:\Windows\system32\atmfd.dll
        2009-10-18 19:59:49 ----A---- C:\Windows\system32\lpk.dll
        2009-10-18 19:59:49 ----A---- C:\Windows\system32\atmlib.dll
        2009-10-18 19:59:47 ----A---- C:\Windows\system32\dciman32.dll
        2009-10-18 19:59:44 ----A---- C:\Windows\system32\msv1_0.dll
        2009-10-18 19:59:20 ----A---- C:\Windows\system32\wkssvc.dll
        2009-10-18 19:59:03 ----A---- C:\Windows\system32\avifil32.dll
        2009-10-18 19:58:56 ----A---- C:\Windows\system32\atl.dll
        2009-10-18 19:55:01 ----A---- C:\Windows\system32\msasn1.dll
        2009-10-18 19:49:22 ----D---- C:\ProgramData\ATI
        2009-10-18 19:49:21 ----D---- C:\Users\jc-joce\AppData\Roaming\ATI
        2009-10-18 19:49:13 ----D---- C:\$RECYCLE.BIN
        2009-10-18 19:48:56 ----D---- C:\Users\jc-joce\AppData\Roaming\Identities
        2009-10-18 19:48:49 ----A---- C:\Windows\system32\WMSPDMOD.DLL
        2009-10-18 19:48:19 ----D---- C:\ProgramData\Partner
        2009-10-18 19:47:42 ----D---- C:\ProgramData\Google
        2009-10-18 19:47:39 ----D---- C:\Program Files\Google
        2009-10-18 19:45:00 ----SD---- C:\Users\jc-joce\AppData\Roaming\Microsoft
        2009-10-18 19:45:00 ----D---- C:\Users\jc-joce\AppData\Roaming\Media Center Programs
        2009-10-18 19:45:00 ----D---- C:\Users\jc-joce\AppData\Roaming\Acer GameZone Console
        2009-10-18 19:42:14 ----A---- C:\Windows\system32\wups2.dll
        2009-10-18 19:42:14 ----A---- C:\Windows\system32\wucltux.dll
        2009-10-18 19:42:14 ----A---- C:\Windows\system32\wuauclt.exe
        2009-10-18 19:42:13 ----A---- C:\Windows\system32\wuaueng.dll
        2009-10-18 19:42:06 ----A---- C:\Windows\system32\wups.dll
        2009-10-18 19:42:06 ----A---- C:\Windows\system32\wudriver.dll
        2009-10-18 19:42:05 ----A---- C:\Windows\system32\wuapi.dll
        2009-10-18 19:42:03 ----A---- C:\Windows\system32\wuwebv.dll
        2009-10-18 19:42:03 ----A---- C:\Windows\system32\wuapp.exe
        2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Modèles
        2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Menu Démarrer
        2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Favoris
        2009-10-18 19:41:29 ----SHD---- C:\ProgramData\Bureau
        2009-10-18 19:41:29 ----SHD---- C:\Program Files\Fichiers communs
        2009-10-18 19:35:33 ----D---- C:\Program Files\ATI Technologies
        2009-10-18 19:32:38 ----D---- C:\Program Files\ATI
        2009-10-18 19:32:28 ----A---- C:\Windows\ATIDetect.txt
        2009-10-18 19:30:35 ----A---- C:\Windows\system32\nvraiins.dll
        2009-10-18 19:30:32 ----D---- C:\Windows\SoftwareDistribution

        ======List of files/folders modified in the last 1 months======

        2009-10-25 17:08:39 ----D---- C:\Windows\System32
        2009-10-25 17:08:39 ----D---- C:\Windows\inf
        2009-10-25 17:08:39 ----A---- C:\Windows\system32\PerfStringBackup.INI
        2009-10-25 15:17:05 ----D---- C:\Windows
        2009-10-25 15:16:13 ----N---- C:\Windows\system.ini
        2009-10-25 15:14:25 ----D---- C:\Windows\system32\drivers
        2009-10-25 15:14:25 ----D---- C:\Windows\AppPatch
        2009-10-25 15:14:25 ----D---- C:\Program Files\Common Files
        2009-10-25 14:08:07 ----D---- C:\Windows\Prefetch
        2009-10-25 13:56:59 ----D---- C:\Windows\system32\catroot2
        2009-10-25 10:34:48 ----RD---- C:\Program Files
        2009-10-24 23:47:55 ----SHD---- C:\Windows\Installer
        2009-10-24 23:47:48 ----SD---- C:\ProgramData\Microsoft
        2009-10-24 22:25:39 ----D---- C:\Windows\system32\wbem
        2009-10-24 22:24:59 ----D---- C:\Windows\system32\config
        2009-10-24 22:24:54 ----D---- C:\Windows\Tasks
        2009-10-24 22:24:54 ----D---- C:\Windows\system32\spool
        2009-10-24 22:24:54 ----D---- C:\Windows\system32\Msdtc
        2009-10-24 22:24:54 ----D---- C:\Windows\system32\CodeIntegrity
        2009-10-24 22:24:53 ----D---- C:\Windows\registration
        2009-10-24 22:24:09 ----SHD---- C:\System Volume Information
        2009-10-24 19:37:01 ----HD---- C:\Program Files\InstallShield Installation Information
        2009-10-24 19:29:42 ----RSD---- C:\Windows\Fonts
        2009-10-24 19:29:41 ----SD---- C:\Windows\Downloaded Program Files
        2009-10-24 19:29:41 ----D---- C:\Program Files\Common Files\InstallShield
        2009-10-24 19:29:29 ----D---- C:\ProgramData
        2009-10-24 16:33:30 ----D---- C:\PerfLogs
        2009-10-23 15:22:49 ----D---- C:\Windows\rescache
        2009-10-23 15:06:04 ----D---- C:\Windows\ShellNew
        2009-10-23 15:05:20 ----D---- C:\Windows\winsxs
        2009-10-23 07:25:11 ----D---- C:\Windows\Logs
        2009-10-22 17:28:32 ----D---- C:\Windows\system32\LogFiles
        2009-10-22 06:39:42 ----D---- C:\Windows\system32\Tasks
        2009-10-21 08:13:28 ----D---- C:\Windows\system32\NDF
        2009-10-19 19:50:37 ----D---- C:\Windows\twain_32
        2009-10-19 19:50:17 ----A---- C:\Windows\win.ini
        2009-10-19 15:24:11 ----D---- C:\Windows\Microsoft.NET
        2009-10-19 15:24:04 ----RSD---- C:\Windows\assembly
        2009-10-19 15:14:27 ----D---- C:\Windows\system32\catroot
        2009-10-19 14:41:10 ----D---- C:\ProgramData\CyberLink
        2009-10-19 09:13:32 ----D---- C:\Program Files\Common Files\Adobe
        2009-10-19 09:13:28 ----D---- C:\ProgramData\Adobe
        2009-10-19 07:24:45 ----D---- C:\Boot
        2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Sidebar
        2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Media Player
        2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Mail
        2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Collaboration
        2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Calendar
        2009-10-19 07:20:50 ----D---- C:\Program Files\Movie Maker
        2009-10-19 07:20:50 ----D---- C:\Program Files\Internet Explorer
        2009-10-19 07:20:49 ----D---- C:\Program Files\Windows Photo Gallery
        2009-10-19 07:20:49 ----D---- C:\Program Files\Common Files\System
        2009-10-19 07:20:48 ----D---- C:\Windows\servicing
        2009-10-19 07:20:48 ----D---- C:\Windows\ehome
        2009-10-19 07:20:48 ----D---- C:\Program Files\Windows Defender
        2009-10-19 07:20:46 ----D---- C:\Windows\system32\lv-LV
        2009-10-19 07:20:46 ----D---- C:\Windows\IME
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\XPSViewer
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\sk-SK
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\ru-RU
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\oobe
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\migration
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\ko-KR
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\it-IT
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\hr-HR
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\fr-FR
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\fr
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\et-EE
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\en-US
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\el-GR
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\de-DE
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\da-DK
        2009-10-19 07:20:45 ----D---- C:\Windows\system32\AdvancedInstallers
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\zh-TW
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\zh-CN
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\uk-UA
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\th-TH
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\sv-SE
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\sr-Latn-CS
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\SLUI
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\sl-SI
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\setup
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\ro-RO
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\pt-PT
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\pl-PL
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\manifeststore
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\ja-JP
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\hu-HU
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\he-IL
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\fi-FI
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\es-ES
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\cs-CZ
        2009-10-19 07:20:44 ----D---- C:\Windows\system32\bg-BG
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\tr-TR
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\pt-BR
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\nl-NL
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\nb-NO
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\migwiz
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\lt-LT
        2009-10-19 07:20:43 ----D---- C:\Windows\system32\ar-SA
        2009-10-19 07:20:35 ----D---- C:\Windows\system32\Boot
        2009-10-19 07:19:30 ----D---- C:\Windows\system32\RTCOM
        2009-10-18 22:26:52 ----D---- C:\Windows\Debug
        2009-10-18 22:06:49 ----D---- C:\Windows\system32\WDI
        2009-10-18 21:50:23 ----D---- C:\ProgramData\Microsoft Help
        2009-10-18 21:47:38 ----D---- C:\Program Files\Common Files\microsoft shared
        2009-10-18 21:47:31 ----D---- C:\Program Files\Microsoft Works
        2009-10-18 21:26:37 ----D---- C:\ACER
        2009-10-18 21:21:11 ----D---- C:\Windows\PolicyDefinitions
        2009-10-18 21:20:43 ----D---- C:\Windows\system32\OEM
        2009-10-18 21:17:31 ----D---- C:\Windows\system
        2009-10-18 19:51:46 ----D---- C:\ProgramData\SiteAdvisor
        2009-10-18 19:48:11 ----D---- C:\Program Files\Acer
        2009-10-18 19:44:49 ----RD---- C:\Users
        2009-10-18 19:41:53 ----D---- C:\Windows\system32\restore
        2009-10-18 19:41:29 ----D---- C:\Program Files\Windows NT
        2009-10-18 19:36:17 ----D---- C:\Windows\Panther
        2009-10-02 10:01:58 ----A---- C:\Windows\system32\mrt.exe

        ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

        R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2008-08-19 15392]
        R2 irda;Protocole IrDA; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
        R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-07-29 16944]
        R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-07-29 60464]
        R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-10-03 3977728]
        R3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
        R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-04 2161496]
        R3 irsir;Pilote série infrarouge Microsoft; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-21 20992]
        R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-30 14848]
        R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-07-07 1050656]
        R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-08-24 15872]
        R3 snpstd2;Trek 310; C:\Windows\system32\DRIVERS\snpstd2.sys [2007-06-26 343808]
        R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
        R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
        R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
        S3 catchme;catchme; \??\C:\Users\jc-joce\AppData\Local\Temp\catchme.sys []
        S3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
        S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
        S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
        S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
        S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
        S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
        S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
        S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
        S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
        S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
        S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
        S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

        ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

        R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service; C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448]
        R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-10-03 704512]
        R2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
        R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-07-29 500784]
        R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576]
        R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2008-09-08 450560]
        R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
        R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
        R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
        R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
        R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2008-09-08 184320]
        R2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
        R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
        R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
        R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2008-05-29 241734]
        R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
        S2 gupdate;Service Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-10-19 133104]
        S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-18 24064]
        S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-10-18 182768]
        S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
        S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

        -----------------EOF-----------------
    12. ok
      le voici posté en deux fois

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by jc-joce at 2009-10-25 16:43:27
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
      System drive C: has 579 GB (95%) free of 610 GB
      Total RAM: 3326 MB (75% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 16:43:41, on 25/10/2009
      Platform: Windows Vista SP2 (WinNT 6.00.1906)
      MSIE: Internet Explorer v8.00 (8.00.6001.18828)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
      c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Windows\System32\mobsync.exe
      C:\Users\jc-joce\Downloads\RSIT.exe
      C:\Program Files\trend micro\jc-joce.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
      O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O4 - HKLM\..\Run: [VirusKeeper] C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
      O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
      O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
      O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
      O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
      O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
      O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
      O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
      O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
      O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
      O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      1. Non ...pas télécharger mais relancer puisque l'icone se trouve normalement sur ton burau...
        a+
        1. Refais un RSIT stp...
          Tu n'auras que le logtxt cette fois...
          c'est normal

          a+
          1. re
            excuse mon ignorance,mais pour ne pas mourir con,
            dit moi stp ce que veut dire rsit
            et infin,si c'est le logtxt que tu veux,le voici puisque combofix ma donné les deux

            ComboFix 09-10-24.01 - jc-joce 25/10/2009 15:11.1.4 - NTFSx86
            Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3326.2493 [GMT 1:00]
            Lancé depuis: c:\users\jc-joce\Downloads\ComboFix.exe
            AV: VirusKeeper 2007 Pro *On-access scanning disabled* (Updated) {165EE528-D666-4745-B14E-AA998BBEC191}
            SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
            .

            ((((((((((((((((((((((((((((( Fichiers créés du 2009-09-25 au 2009-10-25 ))))))))))))))))))))))))))))))))))))
            .

            2009-10-25 11:41 . 2009-10-25 11:41 -------- d-----w- C:\_OTM
            2009-10-25 09:34 . 2009-10-25 14:08 -------- d-----w- c:\program files\trend micro
            2009-10-25 09:34 . 2009-10-25 09:35 -------- d-----w- C:\rsit
            2009-10-24 22:45 . 2009-10-24 22:45 -------- d-----w- c:\program files\AxBx
            2009-10-23 19:01 . 2009-10-23 19:01 -------- d-----w- c:\users\jc-joce\AppData\Roaming\KC Softwares
            2009-10-22 18:35 . 2009-10-22 18:35 -------- d-----w- c:\programdata\Messenger Plus!
            2009-10-22 18:31 . 2009-10-22 18:31 -------- d-----w- c:\program files\Messenger Plus! Live
            2009-10-20 18:44 . 2009-10-20 18:44 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Malwarebytes
            2009-10-20 18:44 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
            2009-10-20 18:44 . 2009-10-20 19:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
            2009-10-20 18:44 . 2009-10-20 18:44 -------- d-----w- c:\programdata\Malwarebytes
            2009-10-20 18:44 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
            2009-10-20 10:20 . 2009-10-20 10:20 -------- d-----w- c:\users\jc-joce\AppData\Local\Acer HomeMedia Trial Creator
            2009-10-20 10:19 . 2009-10-20 10:19 -------- d-----w- c:\users\Public\MediaServer
            2009-10-20 10:19 . 2009-10-20 10:19 -------- d-----w- c:\users\jc-joce\AppData\Local\Acer HomeMedia Connect
            2009-10-19 19:01 . 2009-10-19 19:01 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Auslogics
            2009-10-19 19:01 . 2009-10-19 19:01 -------- d-----w- c:\program files\Auslogics
            2009-10-19 18:50 . 2005-11-23 11:55 53248 ----a-w- c:\windows\system32\csnpstd2.dll
            2009-10-19 18:50 . 2009-10-19 18:50 -------- d-----w- c:\program files\Common Files\Trek310
            2009-10-19 18:50 . 2007-06-26 08:06 343808 ----a-w- c:\windows\system32\drivers\snpstd2.sys
            2009-10-19 18:50 . 2007-04-13 11:52 307200 ----a-w- c:\windows\vsnpstd2.exe
            2009-10-19 18:50 . 2007-03-29 12:52 36864 ----a-w- c:\windows\system32\vsnpstd2.dll
            2009-10-19 18:50 . 2004-09-24 14:24 57344 ----a-w- c:\windows\system32\rsnpstd2.dll
            2009-10-19 18:50 . 2003-08-05 11:48 65536 ----a-w- c:\windows\amcap.exe
            2009-10-19 18:50 . 2009-10-19 18:50 -------- d-----w- c:\program files\Trek 310
            2009-10-19 15:00 . 2009-10-19 15:00 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Template
            2009-10-19 14:58 . 2009-10-19 14:58 -------- d-----w- c:\users\jc-joce\Option
            2009-10-19 13:39 . 2009-10-19 13:39 -------- d-----w- c:\users\jc-joce\AppData\Local\Acer Arcade Live
            2009-10-19 13:39 . 2009-10-19 13:39 -------- d-----w- c:\users\jc-joce\AppData\Roaming\CyberLink
            2009-10-19 09:17 . 1999-05-05 20:22 73728 ----a-w- c:\windows\system32\drivers\vfwwdm32.dll
            2009-10-19 09:17 . 1999-05-05 20:22 65536 ----a-w- c:\windows\system32\drivers\IYUV_32.DLL
            2009-10-19 09:17 . 1999-05-05 20:22 257808 ----a-w- c:\windows\system32\drivers\MSH263.DRV
            2009-10-19 09:17 . 1999-05-05 20:22 15664 ----a-w- c:\windows\system32\drivers\vfwwdm.drv
            2009-10-19 09:15 . 2009-10-19 09:15 -------- d-----w- c:\program files\Managed DirectX (0900)
            2009-10-19 09:14 . 2009-10-19 09:14 -------- d-----w- c:\windows\Cache
            2009-10-19 08:21 . 2009-10-19 08:21 -------- d-----w- c:\users\jc-joce\AppData\Roaming\igraal
            2009-10-19 07:39 . 2009-10-19 07:40 160168 ----a-w- c:\windows\hpqins00.dat
            2009-10-19 07:38 . 2009-10-19 07:38 -------- d-----w- c:\programdata\HP Product Assistant
            2009-10-19 07:36 . 2009-10-22 08:25 -------- d-----w- c:\users\jc-joce\AppData\Roaming\HpUpdate
            2009-10-19 07:36 . 2009-10-19 07:36 -------- d-----w- c:\windows\Hewlett-Packard
            2009-10-19 07:28 . 2009-10-22 16:45 -------- d-----w- c:\users\jc-joce\AppData\Roaming\HP
            2009-10-19 07:27 . 2009-10-19 07:27 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Printer Info Cache
            2009-10-19 07:27 . 2009-10-23 18:19 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Image Zone Express
            2009-10-19 07:25 . 2009-10-19 07:25 -------- d-----w- c:\programdata\HPSSUPPLY
            2009-10-19 07:24 . 2009-10-19 07:24 -------- d-----w- c:\program files\Hewlett-Packard
            2009-10-19 07:24 . 2009-10-19 07:24 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
            2009-10-19 07:24 . 2009-10-19 07:25 -------- d-----w- c:\program files\Common Files\HP
            2009-10-19 07:22 . 2009-10-19 07:25 -------- d-----w- c:\program files\HP
            2009-10-19 07:21 . 2009-10-19 07:28 164276 ----a-w- c:\windows\hpoins19.dat
            2009-10-19 07:20 . 2009-10-22 16:48 -------- d-----w- c:\programdata\HP
            2009-10-19 07:20 . 2006-11-20 21:36 258048 ----a-w- c:\windows\system32\hpzids01.dll
            2009-10-19 07:20 . 2006-12-16 06:19 303104 ----a-w- c:\windows\system32\hpovst01.dll
            2009-10-19 07:20 . 2006-12-16 06:19 573440 ----a-w- c:\windows\system32\hpotscl1.dll
            2009-10-19 07:20 . 2007-03-13 19:55 26952 ----a-w- c:\windows\hpomdl19.dat
            2009-10-19 06:54 . 2009-10-19 06:54 -------- d-----w- c:\windows\Album
            2009-10-19 06:20 . 2009-10-19 06:20 -------- d-----w- c:\windows\system32\ca-ES
            2009-10-19 06:20 . 2009-10-19 06:20 -------- d-----w- c:\windows\system32\eu-ES
            2009-10-19 06:20 . 2009-10-19 06:20 -------- d-----w- c:\windows\system32\vi-VN
            2009-10-19 06:10 . 2009-10-19 06:10 -------- d-----w- c:\windows\system32\EventProviders
            2009-10-19 06:08 . 2009-04-11 06:32 122344 ----a-w- c:\windows\system32\drivers\Storport.sys
            2009-10-19 03:27 . 2008-10-03 17:39 262144 ----a-w- c:\windows\system32\Oemdspif.dll
            2009-10-18 21:01 . 2009-10-19 08:05 -------- d-----w- c:\users\jc-joce\AppData\Local\Adobe
            2009-10-18 20:48 . 2009-10-25 07:53 -------- d-----w- c:\users\jc-joce\Tracing
            2009-10-18 20:47 . 2009-10-18 20:47 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
            2009-10-18 20:47 . 2006-11-29 11:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
            2009-10-18 20:46 . 2009-10-18 20:46 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
            2009-10-18 20:45 . 2009-10-18 20:45 -------- d-----w- c:\program files\CCleaner
            2009-10-18 20:40 . 2009-10-18 20:40 -------- d-----w- c:\program files\Microsoft
            2009-10-18 20:39 . 2009-10-18 20:39 -------- d-----w- c:\program files\Windows Live SkyDrive
            2009-10-18 20:39 . 2009-10-18 20:47 -------- d-----w- c:\program files\Windows Live
            2009-10-18 20:33 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
            2009-10-18 20:32 . 2009-10-18 20:32 -------- d-----w- c:\program files\Common Files\Windows Live
            2009-10-18 20:18 . 2006-10-19 08:00 187392 ----a-w- c:\windows\Acer(Wide).scr
            2009-10-18 20:18 . 2006-10-19 08:00 187392 ----a-w- c:\windows\Acer(Normal).scr
            2009-10-18 20:18 . 2009-10-18 20:18 -------- d-----w- c:\windows\Acer_Wide
            2009-10-18 20:18 . 2009-10-18 20:18 -------- d-----w- c:\program files\Acer Incorporated
            2009-10-18 20:18 . 2009-10-18 20:23 -------- d-----w- c:\windows\Acer_Normal
            2009-10-18 20:18 . 2009-10-18 20:18 0 ----a-w- c:\windows\nsreg.dat
            2009-10-18 20:17 . 2009-10-18 20:17 -------- d-----w- c:\users\jc-joce\AppData\Local\Mozilla
            2009-10-18 20:17 . 2008-06-05 17:01 62464 ----a-w- c:\windows\system32\drivers\RTSTOR.sys
            2009-10-18 20:17 . 2008-05-06 15:41 6416928 ----a-w- c:\windows\system\DriveIcon.dll
            2009-10-18 20:17 . 2009-10-18 20:17 -------- d-----w- c:\users\jc-joce\AppData\Roaming\InstallShield
            2009-10-18 20:17 . 2009-10-18 21:36 -------- d-----w- c:\program files\Northstar
            2009-10-18 20:07 . 2009-10-19 19:31 -------- d-----w- c:\users\jc-joce\AppData\Local\Google
            2009-10-18 20:07 . 2007-06-26 18:06 262200 ----a-w- c:\windows\system32\hcwpnp32_priv.dll
            2009-10-18 20:07 . 2007-06-26 18:06 262200 ----a-w- c:\windows\system32\hcwpnp32.dll
            2009-10-18 20:07 . 2007-05-15 14:46 98360 ----a-w- c:\windows\system32\hcwi2c32.dll
            2009-10-18 20:07 . 2006-10-10 16:47 36921 ----a-w- c:\windows\system32\hcwutl32_priv.dll
            2009-10-18 20:07 . 2006-10-10 16:47 36921 ----a-w- c:\windows\system32\hcwutl32.dll
            2009-10-18 20:01 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
            2009-10-18 19:16 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
            2009-10-18 19:15 . 2009-10-18 19:15 -------- d-----w- c:\program files\MSXML 4.0
            2009-10-18 19:02 . 2009-08-14 16:27 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
            2009-10-18 19:02 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
            2009-10-18 19:02 . 2009-08-14 13:48 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
            2009-10-18 19:02 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
            2009-10-18 19:02 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
            2009-10-18 19:02 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
            2009-10-18 19:02 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
            2009-10-18 19:02 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
            2009-10-18 19:02 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
            2009-10-18 19:02 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
            2009-10-18 19:02 . 2009-08-14 15:53 17920 ----a-w- c:\windows\system32\netevent.dll
            2009-10-18 19:01 . 2009-04-11 06:28 1696768 ----a-w- c:\windows\system32\gameux.dll
            2009-10-18 19:01 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
            2009-10-18 19:01 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
            2009-10-18 19:01 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
            2009-10-18 19:01 . 2009-04-11 06:28 98816 ----a-w- c:\windows\system32\mfps.dll
            2009-10-18 19:01 . 2009-04-11 06:27 53248 ----a-w- c:\windows\system32\rrinstaller.exe
            2009-10-18 19:01 . 2009-04-11 06:27 24576 ----a-w- c:\windows\system32\mfpmp.exe
            2009-10-18 19:01 . 2009-04-11 04:54 2048 ----a-w- c:\windows\system32\mferror.dll
            2009-10-18 18:59 . 2009-07-11 19:01 65024 ----a-w- c:\windows\system32\wlanapi.dll
            2009-10-18 18:58 . 2009-07-17 13:54 71680 ----a-w- c:\windows\system32\atl.dll
            2009-10-18 18:55 . 2009-09-04 11:41 60928 ----a-w- c:\windows\system32\msasn1.dll
            2009-10-18 18:50 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
            2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\programdata\ATI
            2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\users\jc-joce\AppData\Roaming\ATI
            2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\users\jc-joce\AppData\Local\ATI
            2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\users\jc-joce\AppData\Local\PowerCinema
            2009-10-18 18:48 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
            2009-10-18 18:48 . 2009-10-20 20:10 -------- d-----w- c:\programdata\Partner
            2009-10-18 18:48 . 2009-10-24 21:27 70104 ----a-w- c:\users\jc-joce\AppData\Local\GDIPFONTCACHEV1.DAT
            2009-10-18 18:47 . 2009-10-19 15:24 -------- d-----w- c:\program files\Google
            2009-10-18 18:44 . 2009-10-24 23:39 -------- d-----w- c:\users\jc-joce
            2009-10-18 18:42 . 2008-10-16 21:09 51224 ----a-w- c:\windows\system32\wuauclt.exe

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2009-10-25 13:11 . 2008-01-21 08:40 669328 ----a-w- c:\windows\system32\perfh00C.dat
            2009-10-25 13:11 . 2008-01-21 08:40 123350 ----a-w- c:\windows\system32\perfc00C.dat
            2009-10-24 18:37 . 2008-10-31 04:27 -------- d--h--w- c:\program files\InstallShield Installation Information
            2009-10-24 18:29 . 2008-10-31 04:30 -------- d-----w- c:\program files\Common Files\InstallShield
            2009-10-23 22:48 . 2009-10-19 15:00 170 ----a-w- c:\users\jc-joce\AppData\Roaming\wklnhst.dat
            2009-10-21 15:10 . 2009-10-21 15:10 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
            2009-10-19 13:41 . 2008-10-31 04:41 -------- d-----w- c:\programdata\CyberLink
            2009-10-19 08:13 . 2008-10-31 04:46 -------- d-----w- c:\program files\Common Files\Adobe
            2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
            2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
            2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
            2009-10-19 06:20 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
            2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
            2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
            2009-10-18 20:50 . 2008-10-31 05:01 -------- d-----w- c:\programdata\Microsoft Help
            2009-10-18 20:47 . 2008-10-31 05:03 -------- d-----w- c:\program files\Microsoft Works
            2009-10-18 18:51 . 2008-10-31 04:38 -------- d-----w- c:\programdata\SiteAdvisor
            2009-10-18 18:48 . 2008-10-31 04:34 -------- d-----w- c:\program files\Acer
            2009-10-18 18:41 . 2009-10-18 18:41 -------- d-sh--we c:\programdata\Modèles
            2009-10-18 18:41 . 2009-10-18 18:41 -------- d-sh--we c:\programdata\Menu Démarrer
            2009-10-18 18:31 . 2009-10-18 18:31 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
            2009-09-14 09:29 . 2009-10-18 18:59 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
            2009-09-10 16:48 . 2009-10-18 18:59 218624 ----a-w- c:\windows\system32\msv1_0.dll
            2009-08-27 05:22 . 2009-10-18 20:13 916480 ----a-w- c:\windows\system32\wininet.dll
            2009-08-27 05:17 . 2009-10-18 20:13 71680 ----a-w- c:\windows\system32\iesetup.dll
            2009-08-27 05:17 . 2009-10-18 20:13 109056 ----a-w- c:\windows\system32\iesysprep.dll
            2009-08-27 03:42 . 2009-10-18 20:13 133632 ----a-w- c:\windows\system32\ieUnatt.exe
            2009-08-17 21:33 . 2009-08-17 21:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
            2009-08-04 12:34 . 2009-10-18 19:00 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
            2009-08-04 12:34 . 2009-10-18 19:00 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
            .

            ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
            REGEDIT4

            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
            @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
            [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
            2008-07-29 16:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "VirusKeeper"="c:\program files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe" [2009-09-23 2609008]
            "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
            "EnableLUA"= 0 (0x0)
            "EnableUIADesktopToggle"= 0 (0x0)

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
            "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
            @="Service"

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
            "DisableMonitoring"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
            "VistaSp2"=hex(b):a1,b5,94,fc,84,50,ca,01

            R0 nvamacpi;Nvidia Away Mode System;c:\windows\System32\drivers\nvamacpi.sys [31/10/2008 13:56 24608]
            R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [31/10/2008 05:34 24576]
            S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [31/10/2008 05:43 269448]
            S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [03/03/2008 13:11 16384]
            S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [19/10/2009 16:23 133104]
            S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [25/04/2008 21:36 45056]
            S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [25/04/2008 21:36 131072]
            S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [18/10/2009 21:13 24064]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
            HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
            hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
            .
            Contenu du dossier 'Tâches planifiées'

            2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
            - c:\program files\Google\Update\GoogleUpdate.exe [2009-10-19 15:23]

            2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
            - c:\program files\Google\Update\GoogleUpdate.exe [2009-10-19 15:23]
            .
            .
            ------- Examen supplémentaire -------
            .
            mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
            IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
            LSP: %SYSTEMROOT%\system32\nvLsp.dll
            FF - ProfilePath - c:\users\jc-joce\AppData\Roaming\Mozilla\Firefox\Profiles\4029skmd.default\
            FF - prefs.js: browser.startup.homepage - hxxp://fr.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
            FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
            FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
            FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
            FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
            .

            **************************************************************************

            catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2009-10-25 15:16
            Windows 6.0.6002 Service Pack 2 NTFS

            Recherche de processus cachés ...

            Recherche d'éléments en démarrage automatique cachés ...

            Recherche de fichiers cachés ...

            Scan terminé avec succès
            Fichiers cachés: 0

            **************************************************************************
            .
            --------------------- DLLs chargées dans les processus actifs ---------------------

            - - - - - - - > 'Explorer.exe'(2276)
            c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
            c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
            .
            Heure de fin: 2009-10-25 15:17
            ComboFix-quarantined-files.txt 2009-10-25 14:17

            Avant-CF: 607 100 076 032 octets libres
            Après-CF: 607 120 744 448 octets libres

            - - End Of File - - E4FCDEAD90E2A97F66D5BEB8A8DF7E4F
          2. @michdoi je teledharger ça?
            Random's system information tool
            désolé!
        2. Ok laisse tomber....

          ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
          http://download.bleepingcomputer.com/sUBs/ComboFix.exe

          /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\
          ---> Double-clique sur Combofix.exe
          Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
          Accepte en cliquant sur "Oui"

          ---> Mets-le en langue française F
          Tape sur la touche 1 (Yes) pour démarrer le scan.

          /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\
          En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

          Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

          /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

          Note : Le rapport se trouve également là : C:\ComboFix.txt

          a+
          1. désolé pour ma lenteur
            voici le log combofix

            ComboFix 09-10-24.01 - jc-joce 25/10/2009 15:11.1.4 - NTFSx86
            Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3326.2493 [GMT 1:00]
            Lancé depuis: c:\users\jc-joce\Downloads\ComboFix.exe
            AV: VirusKeeper 2007 Pro *On-access scanning disabled* (Updated) {165EE528-D666-4745-B14E-AA998BBEC191}
            SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
            .

            ((((((((((((((((((((((((((((( Fichiers créés du 2009-09-25 au 2009-10-25 ))))))))))))))))))))))))))))))))))))
            .

            2009-10-25 11:41 . 2009-10-25 11:41 -------- d-----w- C:\_OTM
            2009-10-25 09:34 . 2009-10-25 14:08 -------- d-----w- c:\program files\trend micro
            2009-10-25 09:34 . 2009-10-25 09:35 -------- d-----w- C:\rsit
            2009-10-24 22:45 . 2009-10-24 22:45 -------- d-----w- c:\program files\AxBx
            2009-10-23 19:01 . 2009-10-23 19:01 -------- d-----w- c:\users\jc-joce\AppData\Roaming\KC Softwares
            2009-10-22 18:35 . 2009-10-22 18:35 -------- d-----w- c:\programdata\Messenger Plus!
            2009-10-22 18:31 . 2009-10-22 18:31 -------- d-----w- c:\program files\Messenger Plus! Live
            2009-10-20 18:44 . 2009-10-20 18:44 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Malwarebytes
            2009-10-20 18:44 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
            2009-10-20 18:44 . 2009-10-20 19:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
            2009-10-20 18:44 . 2009-10-20 18:44 -------- d-----w- c:\programdata\Malwarebytes
            2009-10-20 18:44 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
            2009-10-20 10:20 . 2009-10-20 10:20 -------- d-----w- c:\users\jc-joce\AppData\Local\Acer HomeMedia Trial Creator
            2009-10-20 10:19 . 2009-10-20 10:19 -------- d-----w- c:\users\Public\MediaServer
            2009-10-20 10:19 . 2009-10-20 10:19 -------- d-----w- c:\users\jc-joce\AppData\Local\Acer HomeMedia Connect
            2009-10-19 19:01 . 2009-10-19 19:01 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Auslogics
            2009-10-19 19:01 . 2009-10-19 19:01 -------- d-----w- c:\program files\Auslogics
            2009-10-19 18:50 . 2005-11-23 11:55 53248 ----a-w- c:\windows\system32\csnpstd2.dll
            2009-10-19 18:50 . 2009-10-19 18:50 -------- d-----w- c:\program files\Common Files\Trek310
            2009-10-19 18:50 . 2007-06-26 08:06 343808 ----a-w- c:\windows\system32\drivers\snpstd2.sys
            2009-10-19 18:50 . 2007-04-13 11:52 307200 ----a-w- c:\windows\vsnpstd2.exe
            2009-10-19 18:50 . 2007-03-29 12:52 36864 ----a-w- c:\windows\system32\vsnpstd2.dll
            2009-10-19 18:50 . 2004-09-24 14:24 57344 ----a-w- c:\windows\system32\rsnpstd2.dll
            2009-10-19 18:50 . 2003-08-05 11:48 65536 ----a-w- c:\windows\amcap.exe
            2009-10-19 18:50 . 2009-10-19 18:50 -------- d-----w- c:\program files\Trek 310
            2009-10-19 15:00 . 2009-10-19 15:00 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Template
            2009-10-19 14:58 . 2009-10-19 14:58 -------- d-----w- c:\users\jc-joce\Option
            2009-10-19 13:39 . 2009-10-19 13:39 -------- d-----w- c:\users\jc-joce\AppData\Local\Acer Arcade Live
            2009-10-19 13:39 . 2009-10-19 13:39 -------- d-----w- c:\users\jc-joce\AppData\Roaming\CyberLink
            2009-10-19 09:17 . 1999-05-05 20:22 73728 ----a-w- c:\windows\system32\drivers\vfwwdm32.dll
            2009-10-19 09:17 . 1999-05-05 20:22 65536 ----a-w- c:\windows\system32\drivers\IYUV_32.DLL
            2009-10-19 09:17 . 1999-05-05 20:22 257808 ----a-w- c:\windows\system32\drivers\MSH263.DRV
            2009-10-19 09:17 . 1999-05-05 20:22 15664 ----a-w- c:\windows\system32\drivers\vfwwdm.drv
            2009-10-19 09:15 . 2009-10-19 09:15 -------- d-----w- c:\program files\Managed DirectX (0900)
            2009-10-19 09:14 . 2009-10-19 09:14 -------- d-----w- c:\windows\Cache
            2009-10-19 08:21 . 2009-10-19 08:21 -------- d-----w- c:\users\jc-joce\AppData\Roaming\igraal
            2009-10-19 07:39 . 2009-10-19 07:40 160168 ----a-w- c:\windows\hpqins00.dat
            2009-10-19 07:38 . 2009-10-19 07:38 -------- d-----w- c:\programdata\HP Product Assistant
            2009-10-19 07:36 . 2009-10-22 08:25 -------- d-----w- c:\users\jc-joce\AppData\Roaming\HpUpdate
            2009-10-19 07:36 . 2009-10-19 07:36 -------- d-----w- c:\windows\Hewlett-Packard
            2009-10-19 07:28 . 2009-10-22 16:45 -------- d-----w- c:\users\jc-joce\AppData\Roaming\HP
            2009-10-19 07:27 . 2009-10-19 07:27 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Printer Info Cache
            2009-10-19 07:27 . 2009-10-23 18:19 -------- d-----w- c:\users\jc-joce\AppData\Roaming\Image Zone Express
            2009-10-19 07:25 . 2009-10-19 07:25 -------- d-----w- c:\programdata\HPSSUPPLY
            2009-10-19 07:24 . 2009-10-19 07:24 -------- d-----w- c:\program files\Hewlett-Packard
            2009-10-19 07:24 . 2009-10-19 07:24 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
            2009-10-19 07:24 . 2009-10-19 07:25 -------- d-----w- c:\program files\Common Files\HP
            2009-10-19 07:22 . 2009-10-19 07:25 -------- d-----w- c:\program files\HP
            2009-10-19 07:21 . 2009-10-19 07:28 164276 ----a-w- c:\windows\hpoins19.dat
            2009-10-19 07:20 . 2009-10-22 16:48 -------- d-----w- c:\programdata\HP
            2009-10-19 07:20 . 2006-11-20 21:36 258048 ----a-w- c:\windows\system32\hpzids01.dll
            2009-10-19 07:20 . 2006-12-16 06:19 303104 ----a-w- c:\windows\system32\hpovst01.dll
            2009-10-19 07:20 . 2006-12-16 06:19 573440 ----a-w- c:\windows\system32\hpotscl1.dll
            2009-10-19 07:20 . 2007-03-13 19:55 26952 ----a-w- c:\windows\hpomdl19.dat
            2009-10-19 06:54 . 2009-10-19 06:54 -------- d-----w- c:\windows\Album
            2009-10-19 06:20 . 2009-10-19 06:20 -------- d-----w- c:\windows\system32\ca-ES
            2009-10-19 06:20 . 2009-10-19 06:20 -------- d-----w- c:\windows\system32\eu-ES
            2009-10-19 06:20 . 2009-10-19 06:20 -------- d-----w- c:\windows\system32\vi-VN
            2009-10-19 06:10 . 2009-10-19 06:10 -------- d-----w- c:\windows\system32\EventProviders
            2009-10-19 06:08 . 2009-04-11 06:32 122344 ----a-w- c:\windows\system32\drivers\Storport.sys
            2009-10-19 03:27 . 2008-10-03 17:39 262144 ----a-w- c:\windows\system32\Oemdspif.dll
            2009-10-18 21:01 . 2009-10-19 08:05 -------- d-----w- c:\users\jc-joce\AppData\Local\Adobe
            2009-10-18 20:48 . 2009-10-25 07:53 -------- d-----w- c:\users\jc-joce\Tracing
            2009-10-18 20:47 . 2009-10-18 20:47 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
            2009-10-18 20:47 . 2006-11-29 11:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
            2009-10-18 20:46 . 2009-10-18 20:46 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
            2009-10-18 20:45 . 2009-10-18 20:45 -------- d-----w- c:\program files\CCleaner
            2009-10-18 20:40 . 2009-10-18 20:40 -------- d-----w- c:\program files\Microsoft
            2009-10-18 20:39 . 2009-10-18 20:39 -------- d-----w- c:\program files\Windows Live SkyDrive
            2009-10-18 20:39 . 2009-10-18 20:47 -------- d-----w- c:\program files\Windows Live
            2009-10-18 20:33 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
            2009-10-18 20:32 . 2009-10-18 20:32 -------- d-----w- c:\program files\Common Files\Windows Live
            2009-10-18 20:18 . 2006-10-19 08:00 187392 ----a-w- c:\windows\Acer(Wide).scr
            2009-10-18 20:18 . 2006-10-19 08:00 187392 ----a-w- c:\windows\Acer(Normal).scr
            2009-10-18 20:18 . 2009-10-18 20:18 -------- d-----w- c:\windows\Acer_Wide
            2009-10-18 20:18 . 2009-10-18 20:18 -------- d-----w- c:\program files\Acer Incorporated
            2009-10-18 20:18 . 2009-10-18 20:23 -------- d-----w- c:\windows\Acer_Normal
            2009-10-18 20:18 . 2009-10-18 20:18 0 ----a-w- c:\windows\nsreg.dat
            2009-10-18 20:17 . 2009-10-18 20:17 -------- d-----w- c:\users\jc-joce\AppData\Local\Mozilla
            2009-10-18 20:17 . 2008-06-05 17:01 62464 ----a-w- c:\windows\system32\drivers\RTSTOR.sys
            2009-10-18 20:17 . 2008-05-06 15:41 6416928 ----a-w- c:\windows\system\DriveIcon.dll
            2009-10-18 20:17 . 2009-10-18 20:17 -------- d-----w- c:\users\jc-joce\AppData\Roaming\InstallShield
            2009-10-18 20:17 . 2009-10-18 21:36 -------- d-----w- c:\program files\Northstar
            2009-10-18 20:07 . 2009-10-19 19:31 -------- d-----w- c:\users\jc-joce\AppData\Local\Google
            2009-10-18 20:07 . 2007-06-26 18:06 262200 ----a-w- c:\windows\system32\hcwpnp32_priv.dll
            2009-10-18 20:07 . 2007-06-26 18:06 262200 ----a-w- c:\windows\system32\hcwpnp32.dll
            2009-10-18 20:07 . 2007-05-15 14:46 98360 ----a-w- c:\windows\system32\hcwi2c32.dll
            2009-10-18 20:07 . 2006-10-10 16:47 36921 ----a-w- c:\windows\system32\hcwutl32_priv.dll
            2009-10-18 20:07 . 2006-10-10 16:47 36921 ----a-w- c:\windows\system32\hcwutl32.dll
            2009-10-18 20:01 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
            2009-10-18 19:16 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
            2009-10-18 19:15 . 2009-10-18 19:15 -------- d-----w- c:\program files\MSXML 4.0
            2009-10-18 19:02 . 2009-08-14 16:27 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
            2009-10-18 19:02 . 2009-08-14 13:48 105984 ----a-w- c:\windows\system32\netiohlp.dll
            2009-10-18 19:02 . 2009-08-14 13:48 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
            2009-10-18 19:02 . 2009-08-14 13:49 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
            2009-10-18 19:02 . 2009-08-14 13:49 19968 ----a-w- c:\windows\system32\ARP.EXE
            2009-10-18 19:02 . 2009-08-14 13:49 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
            2009-10-18 19:02 . 2009-08-14 13:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
            2009-10-18 19:02 . 2009-08-14 13:49 10240 ----a-w- c:\windows\system32\finger.exe
            2009-10-18 19:02 . 2009-08-14 13:49 17920 ----a-w- c:\windows\system32\ROUTE.EXE
            2009-10-18 19:02 . 2009-08-14 13:49 11264 ----a-w- c:\windows\system32\MRINFO.EXE
            2009-10-18 19:02 . 2009-08-14 15:53 17920 ----a-w- c:\windows\system32\netevent.dll
            2009-10-18 19:01 . 2009-04-11 06:28 1696768 ----a-w- c:\windows\system32\gameux.dll
            2009-10-18 19:01 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
            2009-10-18 19:01 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
            2009-10-18 19:01 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\system32\mf.dll
            2009-10-18 19:01 . 2009-04-11 06:28 98816 ----a-w- c:\windows\system32\mfps.dll
            2009-10-18 19:01 . 2009-04-11 06:27 53248 ----a-w- c:\windows\system32\rrinstaller.exe
            2009-10-18 19:01 . 2009-04-11 06:27 24576 ----a-w- c:\windows\system32\mfpmp.exe
            2009-10-18 19:01 . 2009-04-11 04:54 2048 ----a-w- c:\windows\system32\mferror.dll
            2009-10-18 18:59 . 2009-07-11 19:01 65024 ----a-w- c:\windows\system32\wlanapi.dll
            2009-10-18 18:58 . 2009-07-17 13:54 71680 ----a-w- c:\windows\system32\atl.dll
            2009-10-18 18:55 . 2009-09-04 11:41 60928 ----a-w- c:\windows\system32\msasn1.dll
            2009-10-18 18:50 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
            2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\programdata\ATI
            2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\users\jc-joce\AppData\Roaming\ATI
            2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\users\jc-joce\AppData\Local\ATI
            2009-10-18 18:49 . 2009-10-18 18:49 -------- d-----w- c:\users\jc-joce\AppData\Local\PowerCinema
            2009-10-18 18:48 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
            2009-10-18 18:48 . 2009-10-20 20:10 -------- d-----w- c:\programdata\Partner
            2009-10-18 18:48 . 2009-10-24 21:27 70104 ----a-w- c:\users\jc-joce\AppData\Local\GDIPFONTCACHEV1.DAT
            2009-10-18 18:47 . 2009-10-19 15:24 -------- d-----w- c:\program files\Google
            2009-10-18 18:44 . 2009-10-24 23:39 -------- d-----w- c:\users\jc-joce
            2009-10-18 18:42 . 2008-10-16 21:09 51224 ----a-w- c:\windows\system32\wuauclt.exe

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2009-10-25 13:11 . 2008-01-21 08:40 669328 ----a-w- c:\windows\system32\perfh00C.dat
            2009-10-25 13:11 . 2008-01-21 08:40 123350 ----a-w- c:\windows\system32\perfc00C.dat
            2009-10-24 18:37 . 2008-10-31 04:27 -------- d--h--w- c:\program files\InstallShield Installation Information
            2009-10-24 18:29 . 2008-10-31 04:30 -------- d-----w- c:\program files\Common Files\InstallShield
            2009-10-23 22:48 . 2009-10-19 15:00 170 ----a-w- c:\users\jc-joce\AppData\Roaming\wklnhst.dat
            2009-10-21 15:10 . 2009-10-21 15:10 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
            2009-10-19 13:41 . 2008-10-31 04:41 -------- d-----w- c:\programdata\CyberLink
            2009-10-19 08:13 . 2008-10-31 04:46 -------- d-----w- c:\program files\Common Files\Adobe
            2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
            2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
            2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
            2009-10-19 06:20 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
            2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
            2009-10-19 06:20 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
            2009-10-18 20:50 . 2008-10-31 05:01 -------- d-----w- c:\programdata\Microsoft Help
            2009-10-18 20:47 . 2008-10-31 05:03 -------- d-----w- c:\program files\Microsoft Works
            2009-10-18 18:51 . 2008-10-31 04:38 -------- d-----w- c:\programdata\SiteAdvisor
            2009-10-18 18:48 . 2008-10-31 04:34 -------- d-----w- c:\program files\Acer
            2009-10-18 18:41 . 2009-10-18 18:41 -------- d-sh--we c:\programdata\Modèles
            2009-10-18 18:41 . 2009-10-18 18:41 -------- d-sh--we c:\programdata\Menu Démarrer
            2009-10-18 18:31 . 2009-10-18 18:31 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
            2009-09-14 09:29 . 2009-10-18 18:59 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
            2009-09-10 16:48 . 2009-10-18 18:59 218624 ----a-w- c:\windows\system32\msv1_0.dll
            2009-08-27 05:22 . 2009-10-18 20:13 916480 ----a-w- c:\windows\system32\wininet.dll
            2009-08-27 05:17 . 2009-10-18 20:13 71680 ----a-w- c:\windows\system32\iesetup.dll
            2009-08-27 05:17 . 2009-10-18 20:13 109056 ----a-w- c:\windows\system32\iesysprep.dll
            2009-08-27 03:42 . 2009-10-18 20:13 133632 ----a-w- c:\windows\system32\ieUnatt.exe
            2009-08-17 21:33 . 2009-08-17 21:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
            2009-08-04 12:34 . 2009-10-18 19:00 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
            2009-08-04 12:34 . 2009-10-18 19:00 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
            .

            ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
            REGEDIT4

            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
            @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
            [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
            2008-07-29 16:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "VirusKeeper"="c:\program files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe" [2009-09-23 2609008]
            "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
            "EnableLUA"= 0 (0x0)
            "EnableUIADesktopToggle"= 0 (0x0)

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
            "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
            @="Service"

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
            "DisableMonitoring"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
            "VistaSp2"=hex(b):a1,b5,94,fc,84,50,ca,01

            R0 nvamacpi;Nvidia Away Mode System;c:\windows\System32\drivers\nvamacpi.sys [31/10/2008 13:56 24608]
            R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [31/10/2008 05:34 24576]
            S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [31/10/2008 05:43 269448]
            S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [03/03/2008 13:11 16384]
            S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [19/10/2009 16:23 133104]
            S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [25/04/2008 21:36 45056]
            S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [25/04/2008 21:36 131072]
            S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [18/10/2009 21:13 24064]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
            HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
            hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
            .
            Contenu du dossier 'Tâches planifiées'

            2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
            - c:\program files\Google\Update\GoogleUpdate.exe [2009-10-19 15:23]

            2009-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
            - c:\program files\Google\Update\GoogleUpdate.exe [2009-10-19 15:23]
            .
            .
            ------- Examen supplémentaire -------
            .
            mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
            IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
            LSP: %SYSTEMROOT%\system32\nvLsp.dll
            FF - ProfilePath - c:\users\jc-joce\AppData\Roaming\Mozilla\Firefox\Profiles\4029skmd.default\
            FF - prefs.js: browser.startup.homepage - hxxp://fr.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
            FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
            FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
            FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
            FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
            .

            **************************************************************************

            catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2009-10-25 15:16
            Windows 6.0.6002 Service Pack 2 NTFS

            Recherche de processus cachés ...

            Recherche d'éléments en démarrage automatique cachés ...

            Recherche de fichiers cachés ...

            Scan terminé avec succès
            Fichiers cachés: 0

            **************************************************************************
            .
            --------------------- DLLs chargées dans les processus actifs ---------------------

            - - - - - - - > 'Explorer.exe'(2276)
            c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
            c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
            .
            Heure de fin: 2009-10-25 15:17
            ComboFix-quarantined-files.txt 2009-10-25 14:17

            Avant-CF: 607 100 076 032 octets libres
            Après-CF: 607 120 744 448 octets libres

            - - End Of File - - E4FCDEAD90E2A97F66D5BEB8A8DF7E4F
        3. Greeee ==> VISTA.....

          Non cela n'est pas normal....

          ==> Stop OTM....

          Ensuite:
          desactives tes comptes d'utilisateur:
          https://www.zebulon.fr/astuces/pratique/220-desactiver-l-uac-dans-vista.html

          Puis relances OTM en faisant un clic droit (sur l'icone OTM) et choisis:
          "Exécuter en tant qu'administrateur"

          a+
          1. c'est embarassant,mais apres avoir desactivé le compte utilisateur OTM ne réponds toujours pas
            j'ai essayé à plusieurs reprises sans resultat
            à+
        4. ---> Télécharge OTM (OldTimer) sur ton Bureau :
          http: http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/

          ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

          ---> Copie (Ctrl+C) le texte suivant en gras ci-dessous :

          :processes
          explorer.exe

          :services
          relevantknowledge

          :files
          c:\program files\relevantknowledge\rlservice.exe

          :reg
          HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RelevantKnowledge

          :commands
          [purity]
          [emptytemp]
          [start explorer]
          [Reboot]


          ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre : Paste Instructions for Items to be Moved.
          ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

          Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
          Accepte en cliquant sur YES.

          ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
          Le nom du rapport correspond au moment de sa création : date_heure.log

          a+
          1. j'ai colé les textes en gras comme tu m'as dit,seulement j'ai pas de reponse de otmovelt par ailleurs à part
            l'écran d'accueil et le volet de otm je n'ais rien d'autre: démarrer,barre des taches,racourcis,etc je n'ais plus rien sur l'écran, le petit sablier tourne en permanance
            c'est normal?
            la je suis sur le pc de mon fils
            a+
        5. Fais un scan avec cet antispyware :
          Telecharges Malwarebytes + tutoriel

          Tu l´installes; mets le a jour...(onglet mise a jour)
          Click maintenant sur l´onglet recherche et coche la case : "executer un examen rapide".
          Puis click sur "rechercher".
          Laisses le scanner le pc...Si des elements on ete trouvés > click sur supprimer la selection.
          si il t´es demandé de redemarrer > click sur "oui".
          A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vue de le poster sur le forum.
          Copies et colles le rapport stp.

          a+

          1. je l'avais déja à jour, et c'est le quatrième scan que je fais depuis se matin avec
            voici le log
            Malwarebytes' Anti-Malware 1.41
            Version de la base de données: 3028
            Windows 6.0.6002 Service Pack 2

            25/10/2009 12:12:45
            mbam-log-2009-10-25 (12-12-45).txt

            Type de recherche: Examen rapide
            Eléments examinés: 89061
            Temps écoulé: 2 minute(s), 0 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 0
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 0
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 0

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            (Aucun élément nuisible détecté)

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            (Aucun élément nuisible détecté)
        6. Pour l'AV laisse tomber...j'avais zappé ceci:
          C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
          Postes ton logtxt en deux fois si tu veux....

          a+
          1. re
            voici la première partie

            Logfile of random's system information tool 1.06 (written by random/random)
            Run by jc-joce at 2009-10-25 10:34:48
            Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
            System drive C: has 579 GB (95%) free of 610 GB
            Total RAM: 3326 MB (73% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:35:03, on 25/10/2009
            Platform: Windows Vista SP2 (WinNT 6.00.1906)
            MSIE: Internet Explorer v8.00 (8.00.6001.18828)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
            c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Users\jc-joce\Downloads\RSIT.exe
            C:\Program Files\trend micro\jc-joce.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1009&m=aspire_m7711
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
            O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O4 - HKLM\..\Run: [VirusKeeper] C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
            O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
            O13 - Gopher Prefix:
            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
            O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
            O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
            O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
            O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
            O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
            O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
            O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
            O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
            O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
            O23 - Service: RelevantKnowledge - Unknown owner - C:\Program Files\RelevantKnowledge\rlservice.exe (file missing)
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          2. @michet la deuxième
            et il m'a encore bloqué j'ai du réinicialiser de nouveau
            2009-10-18 19:41:29 ----SHD---- C:\Program Files\Fichiers communs
            2009-10-18 19:35:33 ----D---- C:\Program Files\ATI Technologies
            2009-10-18 19:32:38 ----D---- C:\Program Files\ATI
            2009-10-18 19:32:28 ----A---- C:\Windows\ATIDetect.txt
            2009-10-18 19:30:35 ----A---- C:\Windows\system32\nvraiins.dll
            2009-10-18 19:30:32 ----D---- C:\Windows\SoftwareDistribution

            ======List of files/folders modified in the last 1 months======

            2009-10-25 11:50:42 ----D---- C:\Windows\Temp
            2009-10-25 10:34:48 ----RD---- C:\Program Files
            2009-10-25 10:34:23 ----D---- C:\Windows\System32
            2009-10-25 10:34:23 ----D---- C:\Windows\inf
            2009-10-25 10:34:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
            2009-10-25 08:32:59 ----D---- C:\Windows
            2009-10-24 23:47:55 ----SHD---- C:\Windows\Installer
            2009-10-24 23:47:48 ----SD---- C:\ProgramData\Microsoft
            2009-10-24 23:47:48 ----D---- C:\Windows\system32\drivers
            2009-10-24 22:25:39 ----D---- C:\Windows\system32\wbem
            2009-10-24 22:24:59 ----D---- C:\Windows\system32\config
            2009-10-24 22:24:54 ----D---- C:\Windows\Tasks
            2009-10-24 22:24:54 ----D---- C:\Windows\system32\spool
            2009-10-24 22:24:54 ----D---- C:\Windows\system32\Msdtc
            2009-10-24 22:24:54 ----D---- C:\Windows\system32\CodeIntegrity
            2009-10-24 22:24:54 ----D---- C:\Windows\system32\catroot2
            2009-10-24 22:24:53 ----D---- C:\Windows\registration
            2009-10-24 22:24:09 ----SHD---- C:\System Volume Information
            2009-10-24 19:37:01 ----HD---- C:\Program Files\InstallShield Installation Information
            2009-10-24 19:37:01 ----D---- C:\Program Files\Common Files
            2009-10-24 19:29:42 ----RSD---- C:\Windows\Fonts
            2009-10-24 19:29:41 ----SD---- C:\Windows\Downloaded Program Files
            2009-10-24 19:29:41 ----D---- C:\Program Files\Common Files\InstallShield
            2009-10-24 19:29:29 ----HD---- C:\ProgramData
            2009-10-24 18:13:34 ----D---- C:\Windows\Prefetch
            2009-10-24 16:33:30 ----D---- C:\PerfLogs
            2009-10-23 15:22:49 ----D---- C:\Windows\rescache
            2009-10-23 15:06:04 ----D---- C:\Windows\ShellNew
            2009-10-23 15:05:20 ----D---- C:\Windows\winsxs
            2009-10-23 07:25:11 ----D---- C:\Windows\Logs
            2009-10-22 17:28:32 ----D---- C:\Windows\system32\LogFiles
            2009-10-22 06:39:42 ----D---- C:\Windows\system32\Tasks
            2009-10-21 08:13:28 ----D---- C:\Windows\system32\NDF
            2009-10-19 19:50:37 ----D---- C:\Windows\twain_32
            2009-10-19 19:50:17 ----A---- C:\Windows\win.ini
            2009-10-19 15:24:11 ----D---- C:\Windows\Microsoft.NET
            2009-10-19 15:24:04 ----RSD---- C:\Windows\assembly
            2009-10-19 15:14:27 ----D---- C:\Windows\system32\catroot
            2009-10-19 14:41:10 ----D---- C:\ProgramData\CyberLink
            2009-10-19 09:13:32 ----D---- C:\Program Files\Common Files\Adobe
            2009-10-19 09:13:28 ----D---- C:\ProgramData\Adobe
            2009-10-19 07:24:45 ----SHD---- C:\Boot
            2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Sidebar
            2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Media Player
            2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Mail
            2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Collaboration
            2009-10-19 07:20:50 ----D---- C:\Program Files\Windows Calendar
            2009-10-19 07:20:50 ----D---- C:\Program Files\Movie Maker
            2009-10-19 07:20:50 ----D---- C:\Program Files\Internet Explorer
            2009-10-19 07:20:49 ----D---- C:\Program Files\Windows Photo Gallery
            2009-10-19 07:20:49 ----D---- C:\Program Files\Common Files\System
            2009-10-19 07:20:48 ----D---- C:\Windows\servicing
            2009-10-19 07:20:48 ----D---- C:\Windows\ehome
            2009-10-19 07:20:48 ----D---- C:\Program Files\Windows Defender
            2009-10-19 07:20:46 ----D---- C:\Windows\system32\lv-LV
            2009-10-19 07:20:46 ----D---- C:\Windows\IME
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\XPSViewer
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\sk-SK
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\ru-RU
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\oobe
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\migration
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\ko-KR
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\it-IT
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\hr-HR
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\fr-FR
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\fr
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\et-EE
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\en-US
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\el-GR
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\de-DE
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\da-DK
            2009-10-19 07:20:45 ----D---- C:\Windows\system32\AdvancedInstallers
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\zh-TW
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\zh-CN
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\uk-UA
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\th-TH
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\sv-SE
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\sr-Latn-CS
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\SLUI
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\sl-SI
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\setup
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\ro-RO
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\pt-PT
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\pl-PL
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\manifeststore
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\ja-JP
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\hu-HU
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\he-IL
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\fi-FI
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\es-ES
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\cs-CZ
            2009-10-19 07:20:44 ----D---- C:\Windows\system32\bg-BG
            2009-10-19 07:20:43 ----D---- C:\Windows\system32\tr-TR
            2009-10-19 07:20:43 ----D---- C:\Windows\system32\pt-BR
            2009-10-19 07:20:43 ----D---- C:\Windows\system32\nl-NL
            2009-10-19 07:20:43 ----D---- C:\Windows\system32\nb-NO
            2009-10-19 07:20:43 ----D---- C:\Windows\system32\migwiz
            2009-10-19 07:20:43 ----D---- C:\Windows\system32\lt-LT
            2009-10-19 07:20:43 ----D---- C:\Windows\system32\ar-SA
            2009-10-19 07:20:37 ----D---- C:\Windows\AppPatch
            2009-10-19 07:20:35 ----D---- C:\Windows\system32\Boot
            2009-10-19 07:19:30 ----D---- C:\Windows\system32\RTCOM
            2009-10-18 22:26:52 ----D---- C:\Windows\Debug
            2009-10-18 22:06:49 ----D---- C:\Windows\system32\WDI
            2009-10-18 21:50:23 ----D---- C:\ProgramData\Microsoft Help
            2009-10-18 21:47:38 ----D---- C:\Program Files\Common Files\microsoft shared
            2009-10-18 21:47:31 ----D---- C:\Program Files\Microsoft Works
            2009-10-18 21:26:37 ----D---- C:\ACER
            2009-10-18 21:21:11 ----D---- C:\Windows\PolicyDefinitions
            2009-10-18 21:20:43 ----D---- C:\Windows\system32\OEM
            2009-10-18 21:17:31 ----D---- C:\Windows\system
            2009-10-18 19:51:46 ----D---- C:\ProgramData\SiteAdvisor
            2009-10-18 19:48:11 ----D---- C:\Program Files\Acer
            2009-10-18 19:44:49 ----RD---- C:\Users
            2009-10-18 19:41:53 ----D---- C:\Windows\system32\restore
            2009-10-18 19:41:29 ----D---- C:\Program Files\Windows NT
            2009-10-18 19:36:17 ----D---- C:\Windows\Panther
            2009-10-02 10:01:58 ----A---- C:\Windows\system32\mrt.exe

            ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2008-08-19 15392]
            R2 irda;Protocole IrDA; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
            R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-07-29 16944]
            R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-07-29 60464]
            R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-10-03 3977728]
            R3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
            R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-04 2161496]
            R3 irsir;Pilote série infrarouge Microsoft; C:\Windows\system32\DRIVERS\irsir.sys [2008-01-21 20992]
            R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-30 14848]
            R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-07-07 1050656]
            R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-08-24 15872]
            R3 snpstd2;Trek 310; C:\Windows\system32\DRIVERS\snpstd2.sys [2007-06-26 343808]
            R3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
            R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
            R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
            S3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
            S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
            S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
            S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
            S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
            S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
            S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
            S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
            S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
            S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
            S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
            S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

            ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service; C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448]
            R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-10-03 704512]
            R2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
            R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-07-29 500784]
            R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-08-19 24576]
            R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2008-09-08 450560]
            R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
            R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
            R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
            R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
            R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2008-09-08 184320]
            R2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
            R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
            R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
            R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2008-05-29 241734]
            R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
            S2 gupdate;Service Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-10-19 133104]
            S2 RelevantKnowledge;RelevantKnowledge; C:\Program Files\RelevantKnowledge\rlservice.exe /service []
            S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-18 24064]
            S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-10-18 182768]
            S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
            S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

            -----------------EOF-----------------
        • 1
        • 2