Virus?

Résolu
Bonjour,
voila en faite avant j'avais bitdeffender il mavait trouver un cheval de troie mais ne pouvait pas le supprimer du coup j'ai changer d'anti virus et j'ai pris kaspersky et lui me la effacer mais le probléme c'est que mon ordi beugu toujours autant qu'avant mais kaspersky ne détecte aucun autre virus aider moi svp
Configuration: Windows XP
Internet Explorer 7.0

23 réponses

  1. Contributeur
    si tu ne fini pas ta désinfection tu reviendra nous voir surement un de ces jours
    0
    1. merci a vous tous je n'ai plus de virus j'avais un magic controle et quelque cookie merci de m'avoir aider et bonne continuation
      0
      1. Contributeur
        re louise

        il faut commencer par faire une mise au point
        ne t'inquiéte pas tu auras toujours une réponse il faut parfois être patiente car nous avons un vie familiale et professionnel
        donc pas forcément dispo de suite;-)

        ensuite il faut impérativement que tu suive toutes les directives donnée
        que tu ne poste pas plusieurs fois le même rapport si cela ne t'ai pas demandé
        ne fais pas de scan ou autre sans l'accord cela pourrait perturber ta désinfection ;-)

        alors pour commencer je vois que tu es sous vista

        Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

        - Vas dans "Démarrer" puis Panneau de configuration.
        - Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
        - Clique sur Continuer.
        - Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
        - Valide par OK et redémarre.

        ensuite Télécharge sur le bureau : [url=http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe]navilog.exe[/url]

        = installe le
        = Double-Clic navilog1 qui est sur le bureau
        = Appuyer sur une touche jusqu' arriver aux options
        = Choisir option 1 ( = taper 1 )
        ne pas utiliser les autres sans avis , il peut y avoir des processus légitimes

        le rapport se trouve dans c: fixnavi.txt

        tu postes ce rapport.

        @+
        0
        1. voila mon scan est la mais il est exactement pareil que le nouveau pourtant j'ai fait tous que tu ma dit et impossible de copier coller le scan hijacthis
          0
          1. voyons-y plus clair.....pour ne pas s'y perdre

            télécharge HijackThis ici:
            http://telechargement.zebulon.fr/138-hijackthis-1991.html
            https://kerio.probb.fr/
            Dézippe le dans un dossier prévu à cet effet.
            Par exemple C:\hijackthis < Enregistre le bien dans c : !
            Démo : (Merci a Balltrap34 pour cette réalisation)
            http://pageperso.aol.fr/balltrap34/Hijenr.gif
            Lance le puis:
            clique sur "do a system scan and save logfile" (cf démo)
            faire un copier coller du log entier sur le forum

            0
            1. mon ordinateur beugue toujours je ne comprend pas
              0
              1. sa ma enlever 3 fichier infecter
                0
                1. bon ben finis les manuellement si tu peux..
                  0
                  1. j'ai désinstaller quelque truc mais il n ya pas tout les écriture es normal oui peu etre que sa s'enleve quand je désinstalle
                    0
                    1. impossibme de télécharger révo uninstaller il ne se passe rirn et j'ai mm été sur d'autre site toujours rien
                      0
                      1. Bon Alors deja tu avais un bon antivirus (BDTS2008).mais il etait je pense mal configure....un antivirus est un "ANTIVIRUS"....apres un cheval de troie n est pas un virus d'ou le fait que BD l'a juste mis en quarantaine....il n'est pas concu pour detruire les trojans.
                        il est concu pour detruire les VIRUS!!!(ou les mettre en quarantaine avec les trojans suivant la quantite d'infection et le niveau d'utilisation de ce qui a ete detecte dans un processus ou le degré de protection du programme dans lequel cela se trouve.......(fichiers systemes par exemple)).

                        si l'un est configure pour ne rien faire et l'autre pour detruire il est certains qu'il sera considere de meilleure qualite mais....sait-il vraiment ce qu'il detruit?car si c'est un fichier systeme et que l'ordi ne redemarre plus par exemple.....la faute du plantage sera renvoyee sur le virus alors que c est la propre protection du systeme qui l'aura plante.....c est pas parcequ'on a un virus qu'il faut faire n'importe quoi....!!!!!!!

                        et de surcroit ce n est pas parce qu'un antivirus ne detecte pas ou plus de virus QU'IL N'Y EN A PAS OU PLUS!!!!!!!!!!!!!!!

                        mieux vaut un A.V moyen bien configure qu'un bon A.V passoire.

                        une fois le choix fait,refais un scan par securite.

                        voila...esperant avoir ete assez clair....
                        ______________________________________________________________

                        la suite:

                        evite d'envoyer des rapports a tout va.... attends qu on te les demande ca evitera la perte de temps des deux parties,les heures de lectures,et la place prise...non est question qu'on la paie mais la roulette de ma souris est en train du fumer et mon index a des crampes pendant les comparatifs...

                        Telecharge le logiciel Revo Uninstaller ici:

                        https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/39960.html

                        clique droit sur le programme a desinstaller,oui et effacement avancé
                        tout supprimer apres le scan jusqu'a la fin(cles de registre et morcx de programmes restants dans program files si lieu il y a)
                        _______________________________________________________________
                        C:\Program Files\Kiwee Toolbar2\1.4.127\kwtbaim.exe =desinstaller
                        C:\Program Files\SweetIM\Messenger\SweetIM.exe =desinstaller

                        c est tres joli ces smileys mais ca devient tres vite un ramassis de trojans(j en ai fait l experience),ou autres voire pire

                        yahoo toolbar = desinstaller
                        ____________________________

                        C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                        C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe

                        la il va falloir choisir entre les deuxcar ca=tres mauvais.
                        l'effet d'un annihilant l'autre...a la rigueur mieux vaut ne pas en avaoir c est pareil sauf que tu auras pas des messages intempestifs a faire peur qui te diront n'importe quoi!

                        _____________________________
                        [Sidebar] %ProgramFiles%\Windows Sidebar=desinstalle(c est joli mais ca fait bugger les ordis et ca pompe beaucoup de ressources)

                        C:\Users\Raingeard\AppData\Local\arfvoshkbc.exe= kesako ?

                        ______________________________

                        R0 - Internet Explorer\Main,Start Page = https://home.sweetim.com/ = voila un ramassis de trojan supplementaire.....manoeuvre a effectuer > panneau de configuration,otpions internet,et tapes ceci dans l'adresse de page d'accueil:https://www.google.fr/?gws_rd=ssl
                        ______

                        R3 - URLSearchHook: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar2\1.4.127\KiweeIEToolbar.dll
                        ______

                        R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
                        O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
                        ______

                        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                        ______

                        O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Crux P2P\Plugins\RazaWebHook.dll (file missing)=

                        ce genre d'erreur n arrive pas en desinstallent comme il faut...un balai sans poils ne nettoie pas grans chose et bill n'a plus beaucoup de cheveux(moi non plus d'ailleurs)lol
                        _______

                        O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing) =

                        la dessus y a ecrit trojan en gros= a desisntller
                        _______

                        O2 - BHO: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar2\1.4.127\KiweeIEToolbar.dll
                        _______

                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) = commun a beaucoup de monde pas dangereux mais un pc propre ne l'a pas
                        _______

                        O2 - BHO: Easy Gif Animator Toolbar Helper - {96372AB6-15EB-4316-B497-71C741BC548C} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.1\EasyGifAnimator_Toolbar.dll (file missing)
                        O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (file missing)
                        O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                        ________

                        O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll
                        O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                        O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
                        O3 - Toolbar: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar2\1.4.127\KiweeIEToolbar.dll
                        O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BSMediaBar.dll (file missing)
                        O3 - Toolbar: Easy Gif Animator Toolbar - {35065594-9169-4A34-B167-FC4865038E53} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.1\EasyGifAnimator_Toolbar.dll (file missing)
                        O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                        O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                        ___________
                        une fois tout ca desinstalle on y verra plus clair
                        ___________

                        O4 - HKLM\..\Run: [KiweeHook] "C:\Program Files\Kiwee Toolbar2\1.4.127\kwtbaim.exe"

                        O4 - HKLM\..\Run: [FTP Server] C:\Users\RAINGE~1\AppData\Local\Temp\TEMP1_~2.ZIP\ftpserv.exe=?????

                        O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe

                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

                        O4 - HKCU\..\Run: [arfvoshkbc] c:\users\raingeard\appdata\local\arfvoshkbc.exe arfvoshkbc
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

                        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll

                        O9 - Extra button: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - (file missing)
                        O9 - Extra 'Tools' menuitem: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - (file missing)
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)

                        une fois que tout ce qui est inscrit est désinstallé fixe toutes ces lignes apres avoir effectué un scan avec ceci :

                        Hijackthis - Outil de diagnostic et réparation
                        télécharge HijackThis ici:
                        http://telechargement.zebulon.fr/138-hijackthis-1991.html
                        https://kerio.probb.fr/
                        Dézippe le dans un dossier prévu à cet effet.
                        Par exemple C:\hijackthis < Enregistre le bien dans c : !
                        Démo : (Merci a Balltrap34 pour cette réalisation)
                        http://pageperso.aol.fr/balltrap34/Hijenr.gif
                        Lance le puis:
                        clique sur "do a system scan and save logfile" (cf démo)
                        faire un copier coller du log entier sur le forum

                        ensuite utilise ceci:

                        1) Télécharge et installe Malwarebyte's Anti-Malware:

                        http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                        A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée. >>> clique sur OK

                        Lance Malwarebyte's Anti-Malware en double-cliquant sur l'icône sur ton Bureau.

                        Au premier lancement, une fenêtre t'annonce que la version est Free >>> clique sur OK

                        Laisse les Mises à jour se télécharger

                        *** Referme le programme ***

                        2) Redémarre en "Mode sans échec"

                        Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
                        Sélectionner "Mode sans échec" et appuie sur [Entrée]
                        Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
                        Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm

                        Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.

                        3) Scan avec Malwarebyte's Anti-Malware

                        Lance Malwarebyte's Anti-Malware
                        Onglet "Recherche" >>> coche Executer un exame complet >>> Rechercher sélectionne tes disques durs puis clique sur Lancer l’examen
                        A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
                        Suppression des éléments détectés >>>> clique sur Supprimer la sélection
                        S'il t'es demandé de redémarrer >>> clique sur "Yes"

                        --> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.

                        quand tu demande une analyse, demande en mode sans échec.

                        Pourquoi en mode sans échec:

                        *Car déjà l'analyse cherche plus de fichiers en mode sans échec que en mode normal.
                        *Et aussi en mode normal les virus ( trojans, cheval de troie, vers, spywares , malwares et autres ... sont actif) donc ne se supprimes pas donc ils faut le faire en mode sans échec voila.

                        _______________________________________________

                        et refais un scan avec hijackthis et poste le

                        voila bon travail a toi.......................................;
                        0
                        1. es que c'est bon se que j'ai fait si se n'est pas le cas je suis vraiment désoler je suis pas trop douer en informatique
                          0
                          1. Deckard's System Scanner v20071014.68
                            Run by Raingeard on 2008-05-06 04:12:10
                            Computer is in Normal Mode.
                            --------------------------------------------------------------------------------

                            -- HijackThis (run as Raingeard.exe) -------------------------------------------

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 04:12:16, on 06/05/2008
                            Platform: Windows Vista (WinNT 6.00.1904)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16643)
                            Boot mode: Normal

                            Running processes:
                            C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\Explorer.EXE
                            C:\Acer\Empowering Technology\SysMonitor.exe
                            C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Program Files\Lexmark 2500 Series\lxddmon.exe
                            C:\Program Files\Lexmark 2500 Series\lxddamon.exe
                            C:\Program Files\QuickTime\qttask.exe
                            C:\Program Files\Orange\Systray\SystrayApp.exe
                            C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                            C:\Program Files\Kiwee Toolbar2\1.4.127\kwtbaim.exe
                            C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
                            C:\Program Files\Logitech\QuickCam\Quickcam.exe
                            C:\Users\Raingeard\AppData\Local\Temp\Temp1_ftpserv-111.zip\ftpserv.exe
                            C:\Program Files\SweetIM\Messenger\SweetIM.exe
                            C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                            C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                            C:\Program Files\Windows Sidebar\sidebar.exe
                            C:\Windows\ehome\ehtray.exe
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                            C:\Program Files\Internet Download Manager\IDMan.exe
                            C:\Program Files\Windows Media Player\wmpnscfg.exe
                            C:\Users\Raingeard\AppData\Local\arfvoshkbc.exe
                            C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                            C:\Program Files\Orange\Launcher\Launcher.exe
                            C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                            C:\Windows\System32\mobsync.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Windows\ehome\ehmsas.exe
                            C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                            C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                            C:\Program Files\Internet Download Manager\IEMonitor.exe
                            C:\Program Files\Orange\Deskboard\deskboard.exe
                            C:\Program Files\Orange\connectivity\connectivitymanager.exe
                            C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
                            C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
                            C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
                            C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                            C:\Windows\system32\conime.exe
                            C:\Program Files\Orange\browser\browser.exe
                            C:\Program Files\Ares\Ares.exe
                            C:\Program Files\WinRAR\WinRAR.exe
                            C:\Windows\notepad.exe
                            C:\Users\Raingeard\Documents\Downloads\dss.exe
                            C:\PROGRA~1\TRENDM~1\HIJACK~1\RAINGE~1.EXE

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                            R3 - URLSearchHook: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar2\1.4.127\KiweeIEToolbar.dll
                            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
                            R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
                            O1 - Hosts: ::1 localhost
                            O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
                            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                            O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Crux P2P\Plugins\RazaWebHook.dll (file missing)
                            O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
                            O2 - BHO: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar2\1.4.127\KiweeIEToolbar.dll
                            O2 - BHO: UrlHelper Class - {6D023EBF-70B8-45A6-9ED5-556515FA0FE4} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll (file missing)
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Easy Gif Animator Toolbar Helper - {96372AB6-15EB-4316-B497-71C741BC548C} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.1\EasyGifAnimator_Toolbar.dll (file missing)
                            O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (file missing)
                            O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                            O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                            O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
                            O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
                            O3 - Toolbar: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar2\1.4.127\KiweeIEToolbar.dll
                            O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BSMediaBar.dll (file missing)
                            O3 - Toolbar: Easy Gif Animator Toolbar - {35065594-9169-4A34-B167-FC4865038E53} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.1\EasyGifAnimator_Toolbar.dll (file missing)
                            O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                            O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
                            O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                            O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                            O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                            O4 - HKLM\..\Run: [Apanel] c:\windows\system32\oem\audit\newsetapanel.cmd
                            O4 - HKLM\..\Run: [lxddmon.exe] "C:\Program Files\Lexmark 2500 Series\lxddmon.exe"
                            O4 - HKLM\..\Run: [lxddamon] "C:\Program Files\Lexmark 2500 Series\lxddamon.exe"
                            O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
                            O4 - HKLM\..\Run: [LXDDCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXDDtime.dll,_RunDLLEntry@16
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                            O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
                            O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                            O4 - HKLM\..\Run: [KiweeHook] "C:\Program Files\Kiwee Toolbar2\1.4.127\kwtbaim.exe"
                            O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
                            O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
                            O4 - HKLM\..\Run: [FTP Server] C:\Users\RAINGE~1\AppData\Local\Temp\TEMP1_~2.ZIP\ftpserv.exe
                            O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
                            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
                            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
                            O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
                            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                            O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                            O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
                            O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
                            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                            O4 - HKCU\..\Run: [arfvoshkbc] c:\users\raingeard\appdata\local\arfvoshkbc.exe arfvoshkbc
                            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                            O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                            O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                            O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
                            O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
                            O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                            O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
                            O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                            O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                            O9 - Extra button: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - (no file)
                            O9 - Extra 'Tools' menuitem: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - (no file)
                            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                            O13 - Gopher Prefix:
                            O15 - Trusted Zone: https://www.orange.fr/portail
                            O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                            O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                            O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll
                            O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                            O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
                            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                            O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                            O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                            O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - C:\Program Files\FileZilla Server\FileZilla Server.exe (file missing)
                            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                            O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                            O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                            O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                            O23 - Service: lxdd_device - - C:\Windows\system32\lxddcoms.exe
                            O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
                            O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
                            0
                            1. http://djlizard.net/software/Dial-a-fix-v0.60.0.24.zip
                              0
                              1. escuse moi encore et ou télécharger sdfix stp?
                                0
                                1. Deckard's System Scanner v20071014.68
                                  Extra logfile - please post this as an attachment with your post.
                                  --------------------------------------------------------------------------------

                                  -- System Information ----------------------------------------------------------

                                  Microsoft® Windows Vista™ Édition Familiale Premium (build 6000)
                                  Architecture: X86; Language: French

                                  CPU 0: AMD Athlon(tm) 64 X2 Dual Core Processor 4000+
                                  Percentage of Memory in Use: 52%
                                  Physical Memory (total/avail): 1790.94 MiB / 857.84 MiB
                                  Pagefile Memory (total/avail): 3807.71 MiB / 2514.51 MiB
                                  Virtual Memory (total/avail): 2047.88 MiB / 1931.2 MiB

                                  C: is Fixed (NTFS) - 69.78 GiB total, 24.47 GiB free.
                                  D: is Fixed (NTFS) - 69.51 GiB total, 55.53 GiB free.
                                  E: is CDROM (No Media)
                                  G: is Removable (No Media)
                                  H: is Removable (No Media)
                                  I: is Removable (No Media)
                                  J: is Removable (No Media)

                                  \\.\PHYSICALDRIVE0 - Hitachi HDS721616PLA SCSI Disk Device - 153.38 GiB - 3 partitions
                                  \PARTITION0 - Unknown - 9.76 GiB
                                  \PARTITION1 (bootable) - MS-DOS V4 Huge - 69.78 GiB - C:
                                  \PARTITION2 - Système de fichiers installable - 69.51 GiB - D:

                                  \\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device

                                  \\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device

                                  \\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device

                                  \\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device

                                  -- Security Center -------------------------------------------------------------

                                  AUOptions is scheduled to auto-install.
                                  Windows Internal Firewall is enabled.

                                  AV: Kaspersky Anti-Virus v7.0.1.325 (Kaspersky Lab)
                                  AS: Windows Defender v1.1.1505.0 (Microsoft Corporation) [COLOR=RED]Disabled/COLOR
                                  AS: Kaspersky Anti-Virus v7.0.1.325 (Kaspersky Lab)

                                  [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

                                  [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
                                  "C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"="C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe:*:enabled:CSS"
                                  "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"

                                  -- Environment Variables -------------------------------------------------------

                                  ALLUSERSPROFILE=C:\ProgramData
                                  APPDATA=C:\Users\Raingeard\AppData\Roaming
                                  CommonProgramFiles=C:\Program Files\Common Files
                                  COMPUTERNAME=PC-DE-RAINGEARD
                                  ComSpec=C:\Windows\system32\cmd.exe
                                  FP_NO_HOST_CHECK=NO
                                  HOMEDRIVE=C:
                                  HOMEPATH=\Users\Raingeard
                                  LOCALAPPDATA=C:\Users\Raingeard\AppData\Local
                                  LOGONSERVER=\\PC-DE-RAINGEARD
                                  NUMBER_OF_PROCESSORS=2
                                  OS=Windows_NT
                                  Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem
                                  PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                                  PROCESSOR_ARCHITECTURE=x86
                                  PROCESSOR_IDENTIFIER=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
                                  PROCESSOR_LEVEL=15
                                  PROCESSOR_REVISION=6b01
                                  ProgramData=C:\ProgramData
                                  ProgramFiles=C:\Program Files
                                  PROMPT=$P$G
                                  PUBLIC=C:\Users\Public
                                  SystemDrive=C:
                                  SystemRoot=C:\Windows
                                  TEMP=C:\Users\RAINGE~1\AppData\Local\Temp
                                  TMP=C:\Users\RAINGE~1\AppData\Local\Temp
                                  USERDOMAIN=PC-de-Raingeard
                                  USERNAME=Raingeard
                                  USERPROFILE=C:\Users\Raingeard
                                  windir=C:\Windows

                                  -- User Profiles ---------------------------------------------------------------

                                  Raingeard
                                  [I](new local, net ready)/I
                                  vincent et louise
                                  Invité [I](new local, guest, net ready)/I

                                  -- Add/Remove Programs ---------------------------------------------------------

                                  --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                                  ABBYY FineReader 6.0 Sprint --> MsiExec.exe /X{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
                                  Acer eDataSecurity Management --> C:\Acer\Empowering Technology\eDataSecurity\eDSnstHelper.exe -Operation UNINSTALL
                                  Acer Empowering Technology --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB6097D9-D722-4987-BD9E-A076E2848EE2}\setup.exe" -l0x40c -removeonly
                                  Acer ePerformance Management --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D462BF9E-0C35-4705-BF9B-3DF9F3816643}\setup.exe" -l0x40c -removeonly
                                  Acer Picture Slide DVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{41581EF5-45A7-11DA-9D78-000129760D75}\Setup.exe" -uninstall
                                  Acer Plug and Record --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6EFFB76-4A07-11DA-9D78-000129760D75}\Setup.exe" -uninstall
                                  Acer ScreenSaver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
                                  Acer Tour --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94389919-B0AA-4882-9BE8-9F0B004ECA35}\setup.exe" -l0x40c -removeonly
                                  Acer Zone Main Page --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\Setup.exe" -uninstall
                                  Activation Assistant for the 2007 Microsoft Office suites --> "C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
                                  Adobe Acrobat 5.0 --> C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
                                  Adobe Flash Player 9 ActiveX --> C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
                                  Adobe Reader 7.0 - Français --> MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70000000000}
                                  Archiveur WinRAR --> C:\Program Files\WinRAR\uninstall.exe
                                  ArcSoft PhotoImpression --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{19234D4B-AA7A-4165-8ECB-0247B420C515}\Setup.exe" -l0x40c -uninst
                                  ArcSoft PhotoImpression 4 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{68D5CEF9-0DA8-47FE-B0EB-4CBFB5AAF662}\setup.exe" -l0x40c
                                  ArcSoft VideoImpression 2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{643DDB7A-E108-40B2-BE77-5FFD50F83CA5}\setup.exe" -l0x40c
                                  Assistant de connexion Windows Live --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
                                  Barre d'outils MSN --> C:\Program Files\MSN Toolbar\01.01.2607.0\fr\mtbs.exe c
                                  BitDefender Total Security 2008 --> MsiExec.exe /I{F4F09997-F426-4019-B29B-6F1FE74852AC}
                                  DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
                                  DivX Converter --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                                  DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
                                  DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
                                  eSobi v2 --> C:\Program Files\InstallShield Installation Information\{15D967B5-A4BE-42AE-9E84-64CD062B25AA}\setup.exe -runfromtemp -l0x040c
                                  Extension de Windows Live Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{0CA6047C-D28B-4295-834A-07C52BA20C2D}
                                  FaceLift --> C:\Windows\IsUninst.exe -f"C:\Program Files\Maxis\FaceLift\Uninst.isu"
                                  Favorit --> c:\users\raingeard\appdata\local\chdzd.bat
                                  Galerie de photos Windows Live --> MsiExec.exe /X{A70FA218-6598-4AC9-813D-63597C5DD068}
                                  Internet Download Manager --> C:\Program Files\Internet Download Manager\Uninstall.exe
                                  Java(TM) 6 Update 4 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
                                  Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
                                  Kaspersky Anti-Virus 7.0 --> MsiExec.exe /I{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}
                                  Kaspersky Anti-Virus 7.0 --> MsiExec.exe /I{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}
                                  Kiwee Toolbar --> MsiExec.exe /X{DD3D19E6-466A-4D4C-887B-AD68F58AE619}
                                  Les Sims™ 2 Deluxe --> C:\Program Files\EA GAMES\Les Sims 2 Deluxe\EAUninstall.exe
                                  Les Sims™ 2 Kit Glamour --> C:\Program Files\EA GAMES\Les Sims 2 Kit Glamour\EAUninstall.exe
                                  Lexmark 2500 Series --> C:\Program Files\Lexmark 2500 Series\Install\x86\Uninst.exe
                                  livebox --> C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly
                                  Logitech Desktop Messenger --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x40c UNINSTALL
                                  Logitech QuickCam --> MsiExec.exe /X{364EC092-93CF-4DDC-9D7A-7278452028E0}
                                  Mega Manager --> C:\Program Files\InstallShield Installation Information\{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}\setup.exe -runfromtemp -l0x0009 -removeonly
                                  Menus intelligents (Windows Live Toolbar) --> MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
                                  Microsoft Office Excel MUI (French) 2007 --> MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                                  Microsoft Office Home and Student 2007 --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
                                  Microsoft Office Home and Student 2007 --> MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
                                  Microsoft Office OneNote MUI (French) 2007 --> MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
                                  Microsoft Office PowerPoint MUI (French) 2007 --> MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                                  Microsoft Office Proof (Arabic) 2007 --> MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                                  Microsoft Office Proof (Dutch) 2007 --> MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                                  Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                                  Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                                  Microsoft Office Proof (German) 2007 --> MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                                  Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                                  Microsoft Office Proofing (French) 2007 --> MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                                  Microsoft Office Shared MUI (French) 2007 --> MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                                  Microsoft Office Word MUI (French) 2007 --> MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                                  Microsoft SQL Server 2005 Compact Edition [ENU] --> MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                                  Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                                  Microsoft Works --> MsiExec.exe /I{6B1CB38D-E2E4-4a30-933D-EFDEBA76AD9C}
                                  MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                                  MSXML 4.0 SP2 (KB941833) --> MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
                                  MVision --> MsiExec.exe /I{35725FBC-A136-4A46-9F29-091759D9BB93}
                                  Navigateur Orange --> C:\Program Files\Orange\Uninstall\Browser\Shell.exe MainUninstall.shl
                                  NTI Backup NOW! 4.7 --> "C:\Program Files\InstallShield Installation Information\{67ADE9AF-5CD9-4089-8825-55DE4B366799}\setup.exe" -removeonly
                                  NTI CD & DVD-Maker --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
                                  NVIDIA Drivers --> C:\Windows\system32\NVUNINST.EXE UninstallGUI
                                  OpenOffice.org Installer 1.0 --> MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
                                  Orange - Logiciels Internet --> C:\Program Files\Orange\installation\core\Installgui.exe -u
                                  Programme de gestion Camera de Logitech® --> "C:\Program Files\Common Files\LogiShrd\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
                                  QuickTime --> C:\Windows\unvise32qt.exe C:\Windows\system32\QuickTime\Uninstall.log
                                  RegSupreme --> "C:\Program Files\RegSupreme\unins000.exe"
                                  Security Update for Excel 2007 (KB946974) --> msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}
                                  Security Update for Office 2007 (KB947801) --> msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}
                                  Security Update for Visio 2007 (KB947590) --> msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
                                  Solutions de télécopie Lexmark --> C:\Program Files\Lexmark Fax Solutions\Install\x86\Uninst.exe /R:faxunst
                                  SPCA533 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F83390D5-EA4D-4C7B-A216-789CF1E751AA}\setup.exe" -l0x9 -removeonly
                                  Surligneur (Windows Live Toolbar) --> MsiExec.exe /X{81B5F83F-2291-48B0-8375-36B63A9BF5B0}
                                  SweetIM for Messenger 2.5 --> MsiExec.exe /X{EC6BD2CC-2DCF-4AD8-A8DD-DF89D29EEF3F}
                                  SweetIM Toolbar for Internet Explorer 3.1 --> MsiExec.exe /X{59971D79-8111-42C2-9E40-883A0C277E78}
                                  TuneUp Utilities 2008 --> MsiExec.exe /I{5888428E-699C-4E71-BF71-94EE06B497DA}
                                  Update for Office 2007 (KB934528) --> msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {2B939677-2FFD-48F6-9075-7BF48CB87C80}
                                  Update for Office 2007 (KB946691) --> msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
                                  Update for Office System 2007 Setup (KB929722) --> msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {D8E9BEBD-655F-467D-8176-CA9959C140A3}
                                  VideoLAN VLC media player 0.8.6f --> C:\Program Files\VideoLAN\VLC\uninstall.exe
                                  Windows Live Favorites pour Windows Live Toolbar --> MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
                                  Windows Live installer --> MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                                  Windows Live Mail --> MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
                                  Windows Live Messenger --> MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}

                                  -- Application Event Log -------------------------------------------------------

                                  Event Record #/Type13501 / Success
                                  Event Submitted/Written: 05/06/2008 03:12:14 AM
                                  Event ID/Source: 12001 / usnjsvc
                                  Event Description:
                                  The Messenger Sharing USN Journal Reader service started successfully.

                                  Event Record #/Type13499 / Error
                                  Event Submitted/Written: 05/06/2008 03:10:59 AM
                                  Event ID/Source: 1000 / Application Error
                                  Event Description:
                                  Application défaillante SystrayApp.exe, version 1.0.39.739, horodatage 0x46f94eba, module défaillant SystrayApp.exe, version 1.0.39.739, horodatage 0x46f94eba, code d’exception 0xc0000005, décalage d’erreur 0x00001c1c,
                                  ID du processus 0xcec, heure de début de l’application 0xSystrayApp.exe0.

                                  Event Record #/Type13495 / Warning
                                  Event Submitted/Written: 05/06/2008 03:10:25 AM
                                  Event ID/Source: 1 / Microsoft-Windows-ApplicationExperienceInfrastructure
                                  Event Description:
                                  421StarForce Protection10StarForce207?1

                                  Event Record #/Type13492 / Success
                                  Event Submitted/Written: 05/06/2008 03:10:23 AM
                                  Event ID/Source: 5617 / WinMgmt
                                  Event Description:

                                  Event Record #/Type13490 / Success
                                  Event Submitted/Written: 05/06/2008 03:10:22 AM
                                  Event ID/Source: 5615 / WinMgmt
                                  Event Description:

                                  -- Security Event Log ----------------------------------------------------------

                                  No Errors/Warnings found.

                                  -- System Event Log ------------------------------------------------------------

                                  Event Record #/Type39660 / Error
                                  Event Submitted/Written: 05/06/2008 03:11:57 AM
                                  Event ID/Source: 7026 / Service Control Manager
                                  Event Description:
                                  BTHidMgr
                                  sfdrv01

                                  Event Record #/Type39627 / Error
                                  Event Submitted/Written: 05/06/2008 03:11:57 AM
                                  Event ID/Source: 7000 / Service Control Manager
                                  Event Description:
                                  FileZilla Server FTP server%%2

                                  Event Record #/Type39578 / Error
                                  Event Submitted/Written: 05/06/2008 03:09:57 AM
                                  Event ID/Source: 875 / Application Popup
                                  Event Description:
                                  Le chargement du pilote sfdrv01.sys a été bloqué.

                                  Event Record #/Type39576 / Error
                                  Event Submitted/Written: 05/06/2008 03:09:56 AM
                                  Event ID/Source: 6 / ACPI
                                  Event Description:
                                  IRQARB : le BIOS ACP ne contient pas un IRQ pour le périphérique dans le connecteur PCI 12, fonction 0.
                                  Contactez le fabricant de votre ordinateur pour une assistance technique.

                                  Event Record #/Type39575 / Error
                                  Event Submitted/Written: 05/06/2008 03:09:56 AM
                                  Event ID/Source: 6 / ACPI
                                  Event Description:
                                  IRQARB : le BIOS ACP ne contient pas un IRQ pour le périphérique dans le connecteur PCI 11, fonction 0.
                                  Contactez le fabricant de votre ordinateur pour une assistance technique.

                                  -- End of Deckard's System Scanner: finished at 2008-05-06 03:22:50 ------------
                                  0
                                  1. je sais pas exactement si j'ai bien fait le copier coller
                                    0
                                    • 1
                                    • 2