VIRTUMONDE === SPYBOT === VIRUS

Résolu
Bonjour, j'ai un problème avec mon ordinateur ...
j'ai lancé SPYBOT pour voir s'il n'y avais pas d'infection
ou de virus sur mon ordi et à la fin du SCAN, il
m'a mis qu'il avait trouvé 3 virus VIRTUMONDE alors
j'ai tenté de le supprimer mais l'ordinateur en a supprimer
que 1 des 3 et en plus celui-là revient après chaques scan.
Pour les 2 autres il me disait que pour les supprimer
il faut être administrateur de l'ordinateur alors que je
le suis déjà et qu'aucune autres session ne l'est...

j'èspère que vs aller surement pouvoir m'aider

MERCI :)
Configuration: Windows Vista
Safari 530.5

64 réponses

Résumé de la discussion

Un utilisateur constate qu’un scan Spybot signale trois éléments Virtumonde sur un PC Windows Vista et que seules certaines menaces peuvent être supprimées, les autres demandant des droits d’administrateur malgré son statut. Des recommandations privilégient l’emploi d’outils complémentaires et un diagnostic du système, car Spybot seul peut ne pas supprimer Virtumonde et certains éléments nécessitent des privilèges d’administrateur. En cas d’infection persistante, l’analyse des journaux et l’utilisation d’outils comme HijackThis ou Malwarebytes, puis une vérification des clés de démarrage et des paramètres réseau, peuvent être envisagées sans conclure sur l’état du fil.

Bobot (l’IA à votre service)
  1. Si tu as vista tu vas dans démarré et dans recherche tu marque spybot quand tu le trouve tu fait un clic dessus et tu fait exécuter en tant quadministrateur
    0
    1. Bonjour,
      il faut lui faire faire un diagnostic complet du PC avec l'outil RSIT pour repérer les infections présentes
      0
  2. oui tu refait un scan complet avec spybot et normalement tu pourra les suprimé sinon fait un scan avec ton anti virus ou ad-aware
    0
    1. Il faut un outil pour supprimer Virtumonde, mais il faut faire un diagnostic du PC, je ne pense pas que Spybot va le supprimer
      0
  3. et comment on fait un diagnostic ??
    0
    1. Désactive le controle de compte d'utilisateurs:
      Démarrer, panneau de configuration, compte d'utilisateurs
      Décoches la case utiliser le controle de compte d'utilisateur....
      Puis OK et redémarre le PC

      Ensuite:

      Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

      -> http://images.malwareremoval.com/random/RSIT.exe

      ! Déconnecte toi et ferme toutes tes applications en cours !

      Double-clique sur " RSIT.exe " pour le lancer .

      -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

      * Devant l'option "List files/folders created ..." , tu choisis : 2 months

      * clique ensuite sur " Continue " pour lancer l'analyse ...

      -> laisse faire le scan et ne touche pas au PC ...

      Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

      Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

      Important : poste un rapport, puis l'autre dans la réponse suivante
      Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

      ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )-
      0
  4. Logfile of random's system information tool 1.06 (written by random/random)
    Run by Benoît at 2009-06-30 15:09:02
    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
    System drive C: has 54 GB (47%) free of 114 GB
    Total RAM: 3070 MB (53% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:09:18, on 30/06/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18248)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Windows\explorer.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\RtHDVCpl.exe
    C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
    C:\Acer\Empowering Technology\eAudio\eAudio.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Launch Manager\LManager.exe
    C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
    C:\Windows\PLFSetI.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HiYo\Bin\HiYo.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Users\Benoît\AppData\Local\Google\Update\GoogleUpdate.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Convesoft\Orion\Messenger.exe
    C:\Program Files\Apoint2K\ApMsgFwd.exe
    C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
    C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
    C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
    C:\PROGRA~1\Magentic\bin\MgApp.exe
    C:\Users\BENOT~1\AppData\Local\Temp\RtkBtMnt.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Benoît\Documents\Downloads\RSIT.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\Benoît\Documents\Downloads\RSIT (1).exe
    C:\Program Files\trend micro\Benoît.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=0409&m=aspire_7520
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.hiyo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=0409&m=aspire_7520
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe
    O1 - Hosts: ::1 localhost
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
    O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SetPanel] C:\Acer\APanel\APanel.cmd
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
    O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
    O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
    O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
    O4 - HKLM\..\Run: [PLFSetL] C:\Windows\\PLFSetL.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [reader_s] C:\Windows\System32\reader_s.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [Google Update] "C:\Users\Benoît\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKLM\..\Policies\Explorer\Run: [Clouds] C:\Windows\msiexec.exe
    O4 - HKLM\..\Policies\Explorer\Run: [csrcs] C:\Windows\system32\csrcs.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Startup: Orion.lnk = C:\Convesoft\Orion\Messenger.exe
    O4 - Global Startup: Empowering Technology Launcher.lnk = ?
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-BE/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
    O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
    O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
    O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
    O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
    O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
    0
    1. info.txt logfile of random's system information tool 1.06 2009-06-30 15:06:59

      ======Uninstall list======

      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{31403E22-2FDB-452F-AE9E-20854633226D}\SetXX.exe" -uninst
      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A450831D-25F6-4F42-9662-D000B25E0D82}\setup.exe" -uninstall
      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\setup.exe" -uninstall
      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B145EC69-66F5-11D8-9D75-000129760D75}\setup.exe" -uninstall
      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B804C424-B66D-447A-84BD-C6B88C392C3A}\setup.exe" -uninstall
      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F79A208D-D929-11D9-9D77-000129760D75}\setup.exe" -uninstall
      Acer Arcade Deluxe-->C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\Setup.exe -uninstall
      Acer Crystal Eye Webcam Video Class Camera -->C:\Program Files\InstallShield Installation Information\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}\setup.exe -runfromtemp -l0x040c -removeonly -u
      Acer Crystal Eye Webcam-->C:\Program Files\InstallShield Installation Information\{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}\setup.exe -runfromtemp -l0x040c -removeonly
      Acer eAudio Management-->"C:\Program Files\InstallShield Installation Information\{57265292-228A-41FA-9AEC-4620CBCC2739}\Setup.exe" -uninstall
      Acer eDataSecurity Management-->C:\Acer\Empowering Technology\eDataSecurity\x86\eDSnstHelper.exe -Operation UNINSTALL
      Acer eLock Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}\setup.exe" -l0x40c -removeonly
      Acer Empowering Technology-->"C:\Program Files\InstallShield Installation Information\{AB6097D9-D722-4987-BD9E-A076E2848EE2}\setup.exe" -runfromtemp -l0x040c -removeonly
      Acer eNet Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C06554A1-2C1E-4D20-B613-EE62C79927CC}\setup.exe" -l0x40c -removeonly
      Acer ePower Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{58E5844B-7CE2-413D-83D1-99294BF6C74F}\setup.exe" -l0x40c -removeonly
      Acer ePresentation Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BF839132-BD43-4056-ACBF-4377F4A88E2A}\setup.exe" -l0x40c -removeonly
      Acer eSettings Management-->"C:\Program Files\InstallShield Installation Information\{CE65A9A0-9686-45C6-9098-3C9543A412F0}\setup.exe" -runfromtemp -l0x040c -removeonly
      Acer GameZone Console 2.0.1.1-->"C:\Program Files\Acer GameZone\GameConsole\unins000.exe"
      Acer GridVista-->C:\Windows\UnInst32.exe GridV.UNI
      Acer Mobility Center Plug-In-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{11316260-6666-467B-AC34-183FCB5D4335}\setup.exe" -l0x40c -removeonly
      Acer ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
      Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
      Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
      Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
      Agatha Christie Death on the Nile-->"C:\Program Files\Acer GameZone\Agatha Christie Death on the Nile\Uninstall.exe" "C:\Program Files\Acer GameZone\Agatha Christie Death on the Nile\install.log"
      Alice Greenfingers-->"C:\Program Files\Acer GameZone\Alice Greenfingers\Uninstall.exe" "C:\Program Files\Acer GameZone\Alice Greenfingers\install.log"
      ALPS Touch Pad Driver-->C:\Program Files\Apoint2K\Uninstap.exe ADDREMOVE
      AnmanieSMP 2.4 i-->"C:\Program Files\AnmSMP\unins000.exe"
      Apple Mobile Device Support-->MsiExec.exe /I{659B48CD-0608-4ED5-94C0-0B6C87114F10}
      avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
      AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
      Azada-->"C:\Program Files\Acer GameZone\Azada\Uninstall.exe" "C:\Program Files\Acer GameZone\Azada\install.log"
      Backspin Billiards-->"C:\Program Files\Acer GameZone\Backspin Billiards\Uninstall.exe" "C:\Program Files\Acer GameZone\Backspin Billiards\install.log"
      Big Kahuna Reef-->"C:\Program Files\Acer GameZone\Big Kahuna Reef\Uninstall.exe" "C:\Program Files\Acer GameZone\Big Kahuna Reef\install.log"
      Bricks of Egypt-->"C:\Program Files\Acer GameZone\Bricks of Egypt\Uninstall.exe" "C:\Program Files\Acer GameZone\Bricks of Egypt\install.log"
      Cake Mania-->"C:\Program Files\Acer GameZone\Cake Mania\Uninstall.exe" "C:\Program Files\Acer GameZone\Cake Mania\install.log"
      CAMagic Mobile for Bluetooth-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A047546B-1FC0-42AB-972E-EC689D9CF08D}\setup.exe" -l0x40c
      CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
      Chicken Invaders 3-->"C:\Program Files\Acer GameZone\Chicken Invaders 3\Uninstall.exe" "C:\Program Files\Acer GameZone\Chicken Invaders 3\install.log"
      DeepBurner v1.9.0.228-->"C:\Program Files\Astonsoft\DeepBurner\Uninstall.exe" "C:\Program Files\Astonsoft\DeepBurner\install.log" -u
      Diner Dash Flo on the Go-->"C:\Program Files\Acer GameZone\Diner Dash Flo on the Go\Uninstall.exe" "C:\Program Files\Acer GameZone\Diner Dash Flo on the Go\install.log"
      eMule-->"C:\Program Files\eMule\Uninstall.exe"
      Firebird SQL Server - MAGIX Edition-->C:\Program Files\MAGIX\Common\Database\unwise.exe
      GIF Movie Gear 4.2-->"C:\Program Files\GIF Movie Gear\unins000.exe"
      Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
      Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_9DE96A29E721D90A.exe" /uninstall
      Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
      HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118\UIU32m.exe -U -IAcrZUn32z.inf
      HiYo -->MsiExec.exe /X{8F3A13FC-DFDA-4001-A6C3-030495A1E66E} ARPVAL="UnInst" /qf /L*V "%temp%\HiYoUninstallLog.log"
      HiYo-->MsiExec.exe /X{8F3A13FC-DFDA-4001-A6C3-030495A1E66E}
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
      iTunes-->MsiExec.exe /I{CC5702D7-86E2-45A8-99D7-E8B976ADCC56}
      Jewel Quest Solitaire-->"C:\Program Files\Acer GameZone\Jewel Quest Solitaire\Uninstall.exe" "C:\Program Files\Acer GameZone\Jewel Quest Solitaire\install.log"
      Kick N Rush-->"C:\Program Files\Acer GameZone\Kick N Rush\Uninstall.exe" "C:\Program Files\Acer GameZone\Kick N Rush\install.log"
      K-Lite Codec Pack 4.7.5 (Standard)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
      Launch Manager-->C:\Windows\UnInst32.exe LManager.UNI
      Magentic-->C:\PROGRA~1\Magentic\bin\mgsetup.exe /remove /addon:Magentic
      MAGIX Music Maker 2008 Producer Edition Trial 13.0.2.1 (F)-->C:\Program Files\MAGIX\MusicMaker2008PE_Version_a_telecharger\unwise.exe
      MAGIX Screenshare 4.3.6.1987 (F)-->C:\Program Files\MAGIX\PCVisit\unwise.exe
      Mahjong Escape Ancient China-->"C:\Program Files\Acer GameZone\Mahjong Escape Ancient China\Uninstall.exe" "C:\Program Files\Acer GameZone\Mahjong Escape Ancient China\install.log"
      Mahjongg Artifacts-->"C:\Program Files\Acer GameZone\Mahjongg Artifacts\Uninstall.exe" "C:\Program Files\Acer GameZone\Mahjongg Artifacts\install.log"
      Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
      Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
      Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
      Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
      Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
      Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
      Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
      Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
      Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
      MobileMe Control Panel-->MsiExec.exe /I{CADBCBBA-6CDD-4119-B5ED-4AE075B153E7}
      Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
      Mozilla Firefox (3.0.9)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      Mystery Case Files - Huntsville-->"C:\Program Files\Acer GameZone\Mystery Case Files - Huntsville\Uninstall.exe" "C:\Program Files\Acer GameZone\Mystery Case Files - Huntsville\install.log"
      Mystery Solitaire - Secret Island-->"C:\Program Files\Acer GameZone\Mystery Solitaire - Secret Island\Uninstall.exe" "C:\Program Files\Acer GameZone\Mystery Solitaire - Secret Island\install.log"
      NTI Backup NOW! 4.7-->C:\Program Files\InstallShield Installation Information\{1598034D-7147-432C-8CA8-888E0632D124}\setup.exe -runfromtemp -l0x040c
      NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
      NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
      OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
      PowerProducer-->"C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" -uninstall
      QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x40c -removeonly
      RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x40c anything
      Safari-->MsiExec.exe /I{C5C649A8-1D21-4C83-9B08-7B3752E580F4}
      Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
      Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
      Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
      Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
      Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
      Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
      Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
      Turbo Pizza-->"C:\Program Files\Acer GameZone\Turbo Pizza\Uninstall.exe" "C:\Program Files\Acer GameZone\Turbo Pizza\install.log"
      Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
      VLC media player 0.9.9-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      VSO CopyToDVD 4-->"C:\Program Files\VSO\unins000.exe"
      Zuma Deluxe-->"C:\Program Files\Acer GameZone\Zuma Deluxe\Uninstall.exe" "C:\Program Files\Acer GameZone\Zuma Deluxe\install.log"

      ======Security center information======

      AS: Spybot - Search and Destroy
      AS: Windows Defender

      ======System event log======

      Computer Name: Administrator
      Event Code: 19
      Message: Une erreur matérielle corrigée s’est produite.

      Source de l’erreur : vérification d’ordinateur corrigée

      Type d’erreur : Erreur de bus/d’interconnexion

      ID du processeur valide : Oui
      ID du processeur : 0x0
      Numéro de banque : 2
      Type de transaction : N/A
      Participation du processeur : Générique
      Type de demande : 13
      Mémoire-E/S : E/S
      Niveau de hiérarchie mémoire : Générique
      Délai d’attente : Oui
      Record Number: 42646
      Source Name: Microsoft-Windows-WHEA-Logger
      Time Written: 20090630114356.872200-000
      Event Type: Avertissement
      User: AUTORITE NT\SERVICE LOCAL

      Computer Name: Administrator
      Event Code: 19
      Message: Une erreur matérielle corrigée s’est produite.

      Source de l’erreur : vérification d’ordinateur corrigée

      Type d’erreur : Erreur de hiérarchie mémoire

      ID du processeur valide : Oui
      ID du processeur : 0x1
      Numéro de banque : 3
      Type de transaction : N/A
      Participation du processeur : N/A
      Type de demande : N/A
      Mémoire-E/S : N/A
      Niveau de hiérarchie mémoire : Niveau 0
      Délai d’attente : N/A
      Record Number: 42648
      Source Name: Microsoft-Windows-WHEA-Logger
      Time Written: 20090630114456.688600-000
      Event Type: Avertissement
      User: AUTORITE NT\SERVICE LOCAL

      Computer Name: Administrator
      Event Code: 19
      Message: Une erreur matérielle corrigée s’est produite.

      Source de l’erreur : vérification d’ordinateur corrigée

      Type d’erreur : Erreur de hiérarchie mémoire

      ID du processeur valide : Oui
      ID du processeur : 0x0
      Numéro de banque : 0
      Type de transaction : N/A
      Participation du processeur : N/A
      Type de demande : N/A
      Mémoire-E/S : N/A
      Niveau de hiérarchie mémoire : Générique
      Délai d’attente : N/A
      Record Number: 42652
      Source Name: Microsoft-Windows-WHEA-Logger
      Time Written: 20090630122255.542000-000
      Event Type: Avertissement
      User: AUTORITE NT\SERVICE LOCAL

      Computer Name: Administrator
      Event Code: 19
      Message: Une erreur matérielle corrigée s’est produite.

      Source de l’erreur : vérification d’ordinateur corrigée

      Type d’erreur : Erreur de bus/d’interconnexion

      ID du processeur valide : Oui
      ID du processeur : 0x0
      Numéro de banque : 1
      Type de transaction : N/A
      Participation du processeur : Générique
      Type de demande : 15
      Mémoire-E/S : Générique
      Niveau de hiérarchie mémoire : Niveau 2
      Délai d’attente : Oui
      Record Number: 42654
      Source Name: Microsoft-Windows-WHEA-Logger
      Time Written: 20090630122354.299600-000
      Event Type: Avertissement
      User: AUTORITE NT\SERVICE LOCAL

      Computer Name: Administrator
      Event Code: 19
      Message: Une erreur matérielle corrigée s’est produite.

      Source de l’erreur : vérification d’ordinateur corrigée

      Type d’erreur : Erreur de hiérarchie mémoire

      ID du processeur valide : Oui
      ID du processeur : 0x1
      Numéro de banque : 3
      Type de transaction : N/A
      Participation du processeur : N/A
      Type de demande : N/A
      Mémoire-E/S : N/A
      Niveau de hiérarchie mémoire : Niveau 0
      Délai d’attente : N/A
      Record Number: 42655
      Source Name: Microsoft-Windows-WHEA-Logger
      Time Written: 20090630122454.125600-000
      Event Type: Avertissement
      User: AUTORITE NT\SERVICE LOCAL

      =====Application event log=====

      Computer Name: Administrator
      Event Code: 1530
      Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

      DÉTAIL -
      1 user registry handles leaked from \Registry\User\S-1-5-21-3520710125-3187046526-3509169689-1000:
      Process 1004 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3520710125-3187046526-3509169689-1000

      Record Number: 7582
      Source Name: Microsoft-Windows-User Profiles Service
      Time Written: 20090630110248.000000-000
      Event Type: Avertissement
      User: AUTORITE NT\SYSTEM

      Computer Name: Administrator
      Event Code: 1530
      Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

      DÉTAIL -
      2 user registry handles leaked from \Registry\User\S-1-5-21-3520710125-3187046526-3509169689-1000_Classes:
      Process 1004 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3520710125-3187046526-3509169689-1000_CLASSES
      Process 2040 (\Device\HarddiskVolume2\Windows\System32\spoolsv.exe) has opened key \REGISTRY\USER\S-1-5-21-3520710125-3187046526-3509169689-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache

      Record Number: 7583
      Source Name: Microsoft-Windows-User Profiles Service
      Time Written: 20090630110249.000000-000
      Event Type: Avertissement
      User: AUTORITE NT\SYSTEM

      Computer Name: Administrator
      Event Code: 10
      Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 7605
      Source Name: Microsoft-Windows-WMI
      Time Written: 20090630110859.000000-000
      Event Type: Erreur
      User:

      Computer Name: Administrator
      Event Code: 3013
      Message: Impossible de mettre à jour l'entrée <C:\USERS\BENOÎT\MUSIC\ITUNES\ITUNES LIBRARY EXTRAS.ITDB-JOURNAL> dans la configuration de hachage.

      Contexte : Application , Catalogue SystemIndex

      Détails :
      Un périphérique attaché au système ne fonctionne pas correctement. (0x8007001f)

      Record Number: 7619
      Source Name: Microsoft-Windows-Search
      Time Written: 20090630114503.000000-000
      Event Type: Erreur
      User:

      Computer Name: Administrator
      Event Code: 3013
      Message: Impossible de mettre à jour l'entrée <C:\USERS\BENOÎT\MUSIC\ITUNES\ITUNES LIBRARY EXTRAS.ITDB-JOURNAL> dans la configuration de hachage.

      Contexte : Application , Catalogue SystemIndex

      Détails :
      Un périphérique attaché au système ne fonctionne pas correctement. (0x8007001f)

      Record Number: 7620
      Source Name: Microsoft-Windows-Search
      Time Written: 20090630114503.000000-000
      Event Type: Erreur
      User:

      =====Security event log=====

      Computer Name: Administrator
      Event Code: 4624
      Message: L’ouverture de session d’un compte s’est correctement déroulée.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : ADMINISTRATOR$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7

      Type d’ouverture de session : 7

      Nouvelle ouverture de session :
      ID de sécurité : S-1-5-21-3520710125-3187046526-3509169689-1000
      Nom du compte : Benoît
      Domaine du compte : Administrator
      ID d’ouverture de session : 0x1d027a
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Informations sur le processus :
      ID du processus : 0x340
      Nom du processus : C:\Windows\System32\winlogon.exe

      Informations sur le réseau :
      Nom de la station de travail : ADMINISTRATOR
      Adresse du réseau source : 127.0.0.1
      Port source : 0

      Informations détaillées sur l’authentification :
      Processus d’ouverture de session : User32
      Package d’authentification : Negotiate
      Services en transit : -
      Nom du package (NTLM uniquement) : -
      Longueur de la clé : 0

      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
      Record Number: 9884
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090630122323.578400-000
      Event Type: Succès de l'audit
      User:

      Computer Name: Administrator
      Event Code: 4624
      Message: L’ouverture de session d’un compte s’est correctement déroulée.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : ADMINISTRATOR$
      Domaine du compte : WORKGROUP
      ID d’ouverture de session : 0x3e7

      Type d’ouverture de session : 7

      Nouvelle ouverture de session :
      ID de sécurité : S-1-5-21-3520710125-3187046526-3509169689-1000
      Nom du compte : Benoît
      Domaine du compte : Administrator
      ID d’ouverture de session : 0x1d0287
      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

      Informations sur le processus :
      ID du processus : 0x340
      Nom du processus : C:\Windows\System32\winlogon.exe

      Informations sur le réseau :
      Nom de la station de travail : ADMINISTRATOR
      Adresse du réseau source : 127.0.0.1
      Port source : 0

      Informations détaillées sur l’authentification :
      Processus d’ouverture de session : User32
      Package d’authentification : Negotiate
      Services en transit : -
      Nom du package (NTLM uniquement) : -
      Longueur de la clé : 0

      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
      Record Number: 9885
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090630122323.578400-000
      Event Type: Succès de l'audit
      User:

      Computer Name: Administrator
      Event Code: 4672
      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

      Sujet :
      ID de sécurité : S-1-5-21-3520710125-3187046526-3509169689-1000
      Nom du compte : Benoît
      Domaine du compte : Administrator
      ID d’ouverture de session : 0x1d027a

      Privilèges : SeSecurityPrivilege
      SeTakeOwnershipPrivilege
      SeLoadDriverPrivilege
      SeBackupPrivilege
      SeRestorePrivilege
      SeDebugPrivilege
      SeSystemEnvironmentPrivilege
      SeImpersonatePrivilege
      Record Number: 9886
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090630122323.578400-000
      Event Type: Succès de l'audit
      User:

      Computer Name: Administrator
      Event Code: 4634
      Message: Fermeture de session d’un compte.

      Sujet :
      ID de sécurité : S-1-5-21-3520710125-3187046526-3509169689-1000
      Nom du compte : Benoît
      Domaine du compte : Administrator
      ID du compte : 0x1d0287

      Type d’ouverture de session : 7

      Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.
      Record Number: 9887
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090630122323.578400-000
      Event Type: Succès de l'audit
      User:

      Computer Name: Administrator
      Event Code: 4634
      Message: Fermeture de session d’un compte.

      Sujet :
      ID de sécurité : S-1-5-21-3520710125-3187046526-3509169689-1000
      Nom du compte : Benoît
      Domaine du compte : Administrator
      ID du compte : 0x1d027a

      Type d’ouverture de session : 7

      Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.
      Record Number: 9888
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20090630122323.578400-000
      Event Type: Succès de l'audit
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Acer\Empowering Technology\eDataSecurity\;C:\Acer\Empowering Technology\eDataSecurity\x86;C:\Acer\Empowering Technology\eDataSecurity\x64;C:\Program Files\QuickTime\QTSystem\
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
      "PROCESSOR_ARCHITECTURE"=x86
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "USERNAME"=SYSTEM
      "windir"=%SystemRoot%
      "PROCESSOR_LEVEL"=15
      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 104 Stepping 2, AuthenticAMD
      "PROCESSOR_REVISION"=6802
      "NUMBER_OF_PROCESSORS"=2
      "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
      "DFSTRACINGON"=FALSE
      "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
      "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

      -----------------EOF-----------------
      0
      1. Modérateur
        Bonjour,

        --> Désactive l'UAC le temps de la désinfection.

        --> Télécharge UsbFix (de C_XX & Chiquitine29) sur ton Bureau.

        --> Lance l'installation avec les paramètres par défaut.

        --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.

        --> Clique droit sur le raccourci UsbFix sur ton Bureau et choisis Exécuter en tant qu'administrateur.

        --> Choisis l'option 1 (Recherche).

        --> Laisse travailler l'outil.

        --> Poste le rapport UsbFix.txt.

        Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).

        "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        0
        1. est ben tu vas t 'amusé
          0
          1. ############################## | UsbFix V3.034 |

            # User : Benoît (Administrateurs) # ADMINISTRATOR
            # Update on 29/06/09 by Chiquitine29 & C_XX
            # Start at: 15:45:16 | 30/06/2009
            # Website : http://pagesperso-orange.fr/NosTools/usbfix.html

            # AMD Turion(tm) 64 X2 Mobile Technology TL-62
            # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
            # Internet Explorer 7.0.6001.18000
            # Windows Firewall Status : Enabled

            # C:\ # Disque fixe local # 111,69 Go (52,75 Go free) [ACER] # NTFS
            # D:\ # Disque fixe local # 111,43 Go (111,34 Go free) [DATA] # NTFS
            # E:\ # Disque CD-ROM

            ############################## | Processus actifs |

            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\Windows\system32\WLANExt.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\System32\spoolsv.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Windows\system32\svchost.exe
            C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
            C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
            C:\Acer\Empowering Technology\eNet\eNet Service.exe
            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Acer\Mobility Center\MobilityService.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\SearchIndexer.exe
            C:\Windows\system32\DRIVERS\xaudio.exe
            C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
            C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
            C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
            C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Windows\system32\wbem\wmiprvse.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Windows\explorer.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Windows\RtHDVCpl.exe
            C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
            C:\Acer\Empowering Technology\eAudio\eAudio.exe
            C:\Windows\System32\rundll32.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Launch Manager\LManager.exe
            C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
            C:\Windows\PLFSetI.exe
            C:\Program Files\Apoint2K\Apoint.exe
            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\HiYo\Bin\HiYo.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Users\Benoît\AppData\Local\Google\Update\GoogleUpdate.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\Convesoft\Orion\Messenger.exe
            C:\Program Files\Apoint2K\ApMsgFwd.exe
            C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
            C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
            C:\Program Files\Apoint2K\Apntex.exe
            C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
            C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
            C:\PROGRA~1\Magentic\bin\MgApp.exe
            C:\Users\BENOT~1\AppData\Local\Temp\RtkBtMnt.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
            C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
            C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
            C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
            C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
            C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
            C:\Windows\system32\conime.exe

            ################## | Registre Startup |

            HKCU_Main: "Local Page"="C:\\Windows\\system32\\blank.htm"
            HKCU_Main: "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            HKCU_Main: "Start Page"="http://mystart.hiyo.com/"
            HKLM_logon: "Userinit"="C:\\Windows\\system32\\userinit.exe,"
            HKLM_logon: "LegalNoticeCaption"=""
            HKLM_logon: "LegalNoticeText"=""
            HKLM_Run: Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
            HKLM_Run: RtHDVCpl=RtHDVCpl.exe
            HKLM_Run: eDataSecurity Loader=C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
            HKLM_Run: eAudio="C:\Acer\Empowering Technology\eAudio\eAudio.exe"
            HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            HKLM_Run: NvSvc=RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
            HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            HKLM_Run: SetPanel=C:\Acer\APanel\APanel.cmd
            HKLM_Run: Google Desktop Search="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
            HKLM_Run: LManager=C:\PROGRA~1\LAUNCH~1\LManager.exe
            HKLM_Run: PlayMovie="C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
            HKLM_Run: WarReg_PopUp=C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
            HKLM_Run: PLFSetI=C:\Windows\PLFSetI.exe
            HKLM_Run: PLFSetL=C:\Windows\\PLFSetL.exe
            HKLM_Run: Apoint=C:\Program Files\Apoint2K\Apoint.exe
            HKLM_Run: eRecoveryService=
            HKLM_Run: Acer Tour Reminder=C:\Acer\AcerTour\Reminder.exe
            HKLM_Run: avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
            HKLM_Run: reader_s=C:\Windows\System32\reader_s.exe
            HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
            HKLM_Run: iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
            HKLM_Run: AppleSyncNotifier=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
            HKLM_Run: Hiyo=C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
            HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
            HKCU_Run: WindowsWelcomeCenter=rundll32.exe oobefldr.dll,ShowWelcomeCenter
            HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            HKCU_Run: Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            HKCU_Run: Google Update="C:\Users\Benoît\AppData\Local\Google\Update\GoogleUpdate.exe" /c
            HKCU_Run: Magentic=C:\PROGRA~1\Magentic\bin\Magentic.exe /c
            HKCU_Run: SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

            ################## | Fichiers # Dossiers infectieux |

            Présent ! C:\Windows\system32\autorun.inf
            Présent ! C:\Users\BENOT~1\AppData\Local\Temp\ImInstaller\HiYo_Install.exe
            Présent ! C:\Users\BENOT~1\AppData\Local\Temp\ImInstaller\magentic_install.exe

            ################## | Registre # Clés Run infectieuses |

            Présent ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "reader_s"

            ################## | Registre # Mountpoints2 |

            HKCU\...\Explorer\MountPoints2\{809349e3-2147-11de-bb45-00235a5c87f8}\Shell\AutoRun\Command
            HKCU\...\Explorer\MountPoints2\{809349e3-2147-11de-bb45-00235a5c87f8}\Shell\explore\Command
            HKCU\...\Explorer\MountPoints2\{809349e3-2147-11de-bb45-00235a5c87f8}\Shell\open\Command
            HKCU\...\Explorer\MountPoints2\{80d40135-2d18-11de-a20e-00235a5c87f8}\Shell\AutoRun\Command
            HKCU\...\Explorer\MountPoints2\{80d40135-2d18-11de-a20e-00235a5c87f8}\Shell\explore\Command
            HKCU\...\Explorer\MountPoints2\{80d40135-2d18-11de-a20e-00235a5c87f8}\Shell\open\Command

            ################## | Etat / Services / Informations |

            # Affichage des fichiers cachés : OK

            # Mode sans echec : OK

            # Uac : OK

            # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
            # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
            # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
            # (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
            # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
            # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
            # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

            ################## | Cracks / Keygens / Serials |

            ################## | ! Fin du rapport # UsbFix V3.034 ! |
            0
            1. Modérateur
              --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.

              --> Clique droit sur le raccourci UsbFix présent sur ton Bureau et choisis Exécuter en tant qu'administrateur.

              --> Choisis l'option 2 (Suppression).

              --> Ton Bureau disparaîtra et le PC redémarrera.

              --> Au redémarrage, UsbFix scannera ton PC, laisse travailler l'outil.

              --> Ensuite, poste le rapport UsbFix.txt qui apparaîtra avec le Bureau.

              Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
              0
              1. T'ES SUR QUE IL Y A AUCUN RISQUE ??
                0
                1. Modérateur
                  Oui.
                  0
                  1. bench003 tu es entre bonnes mains
                    0
                2. Si tu utilise le windows xp ouvre en mode sans etache tu vas etre administrateur automatiquement
                  0
                  1. Modérateur
                    Je viens de modifier la procédure pour l'option 2 d'UsbFix sinon tu risques d'avoir le message Accès refusé.
                    0
                    1. bonjour tout le monde, destrio 05 et nathandre ; )
                      Message pour bench-003 : fais l'option 2, tu as les meilleurs avec toi
                      0
                      1. voilà j'ai fais ce que tu as dit
                        et puis il a redémarrer
                        et g ouvert "C:\UsbFix.txt"

                        =>

                        ############################## | UsbFix V3.034 |

                        # User : Benoît (Administrateurs) # ADMINISTRATOR
                        # Update on 29/06/09 by Chiquitine29 & C_XX
                        # Start at: 15:45:16 | 30/06/2009
                        # Website : http://pagesperso-orange.fr/NosTools/usbfix.html

                        # AMD Turion(tm) 64 X2 Mobile Technology TL-62
                        # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                        # Internet Explorer 7.0.6001.18000
                        # Windows Firewall Status : Enabled

                        # C:\ # Disque fixe local # 111,69 Go (52,75 Go free) [ACER] # NTFS
                        # D:\ # Disque fixe local # 111,43 Go (111,34 Go free) [DATA] # NTFS
                        # E:\ # Disque CD-ROM

                        ############################## | Processus actifs |

                        C:\Windows\System32\smss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\Windows\system32\WLANExt.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        C:\Windows\system32\svchost.exe
                        C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
                        C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                        C:\Acer\Empowering Technology\eNet\eNet Service.exe
                        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        C:\Acer\Mobility Center\MobilityService.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\SearchIndexer.exe
                        C:\Windows\system32\DRIVERS\xaudio.exe
                        C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                        C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                        C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                        C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Windows\system32\wbem\unsecapp.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\Windows\explorer.exe
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Windows\RtHDVCpl.exe
                        C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
                        C:\Acer\Empowering Technology\eAudio\eAudio.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\Launch Manager\LManager.exe
                        C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
                        C:\Windows\PLFSetI.exe
                        C:\Program Files\Apoint2K\Apoint.exe
                        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\HiYo\Bin\HiYo.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Users\Benoît\AppData\Local\Google\Update\GoogleUpdate.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\Convesoft\Orion\Messenger.exe
                        C:\Program Files\Apoint2K\ApMsgFwd.exe
                        C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
                        C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                        C:\Program Files\Apoint2K\Apntex.exe
                        C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                        C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                        C:\PROGRA~1\Magentic\bin\MgApp.exe
                        C:\Users\BENOT~1\AppData\Local\Temp\RtkBtMnt.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\Windows Live\Contacts\wlcomm.exe
                        C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
                        C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
                        C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
                        C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
                        C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
                        C:\Users\Benoît\AppData\Local\Google\Chrome\Application\chrome.exe
                        C:\Windows\system32\conime.exe

                        ################## | Registre Startup |

                        HKCU_Main: "Local Page"="C:\\Windows\\system32\\blank.htm"
                        HKCU_Main: "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                        HKCU_Main: "Start Page"="http://mystart.hiyo.com/"
                        HKLM_logon: "Userinit"="C:\\Windows\\system32\\userinit.exe,"
                        HKLM_logon: "LegalNoticeCaption"=""
                        HKLM_logon: "LegalNoticeText"=""
                        HKLM_Run: Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        HKLM_Run: RtHDVCpl=RtHDVCpl.exe
                        HKLM_Run: eDataSecurity Loader=C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
                        HKLM_Run: eAudio="C:\Acer\Empowering Technology\eAudio\eAudio.exe"
                        HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        HKLM_Run: NvSvc=RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        HKLM_Run: SetPanel=C:\Acer\APanel\APanel.cmd
                        HKLM_Run: Google Desktop Search="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                        HKLM_Run: LManager=C:\PROGRA~1\LAUNCH~1\LManager.exe
                        HKLM_Run: PlayMovie="C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
                        HKLM_Run: WarReg_PopUp=C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
                        HKLM_Run: PLFSetI=C:\Windows\PLFSetI.exe
                        HKLM_Run: PLFSetL=C:\Windows\\PLFSetL.exe
                        HKLM_Run: Apoint=C:\Program Files\Apoint2K\Apoint.exe
                        HKLM_Run: eRecoveryService=
                        HKLM_Run: Acer Tour Reminder=C:\Acer\AcerTour\Reminder.exe
                        HKLM_Run: avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
                        HKLM_Run: reader_s=C:\Windows\System32\reader_s.exe
                        HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
                        HKLM_Run: iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
                        HKLM_Run: AppleSyncNotifier=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                        HKLM_Run: Hiyo=C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
                        HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                        HKCU_Run: WindowsWelcomeCenter=rundll32.exe oobefldr.dll,ShowWelcomeCenter
                        HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        HKCU_Run: Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        HKCU_Run: Google Update="C:\Users\Benoît\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                        HKCU_Run: Magentic=C:\PROGRA~1\Magentic\bin\Magentic.exe /c
                        HKCU_Run: SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

                        ################## | Fichiers # Dossiers infectieux |

                        Présent ! C:\Windows\system32\autorun.inf
                        Présent ! C:\Users\BENOT~1\AppData\Local\Temp\ImInstaller\HiYo_Install.exe
                        Présent ! C:\Users\BENOT~1\AppData\Local\Temp\ImInstaller\magentic_install.exe

                        ################## | Registre # Clés Run infectieuses |

                        Présent ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "reader_s"

                        ################## | Registre # Mountpoints2 |

                        HKCU\...\Explorer\MountPoints2\{809349e3-2147-11de-bb45-00235a5c87f8}\Shell\AutoRun\Command
                        HKCU\...\Explorer\MountPoints2\{809349e3-2147-11de-bb45-00235a5c87f8}\Shell\explore\Command
                        HKCU\...\Explorer\MountPoints2\{809349e3-2147-11de-bb45-00235a5c87f8}\Shell\open\Command
                        HKCU\...\Explorer\MountPoints2\{80d40135-2d18-11de-a20e-00235a5c87f8}\Shell\AutoRun\Command
                        HKCU\...\Explorer\MountPoints2\{80d40135-2d18-11de-a20e-00235a5c87f8}\Shell\explore\Command
                        HKCU\...\Explorer\MountPoints2\{80d40135-2d18-11de-a20e-00235a5c87f8}\Shell\open\Command

                        ################## | Etat / Services / Informations |

                        # Affichage des fichiers cachés : OK

                        # Mode sans echec : OK

                        # Uac : OK

                        # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                        # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
                        # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
                        # (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
                        # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
                        # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                        # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                        ################## | Cracks / Keygens / Serials |

                        ################## | ! Fin du rapport # UsbFix V3.034 ! |
                        0
                        1. Modérateur
                          1/

                          ---> Cherche ce fichier : C:\Program Files\trend micro\Benoît.exe

                          ---> Clique droit dessus et choisis Exécuter en tant qu'administrateur.

                          ---> Choisis Do a system scan only.

                          ---> Coche les cases qui sont devant les lignes suivantes :

                          F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe

                          O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

                          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

                          O4 - HKLM\..\Run: [reader_s] C:\Windows\System32\reader_s.exe

                          O4 - HKLM\..\Policies\Explorer\Run: [Clouds] C:\Windows\msiexec.exe

                          O4 - HKLM\..\Policies\Explorer\Run: [csrcs] C:\Windows\system32\csrcs.exe

                          ---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.

                          ---> Ferme HijackThis.

                          2/

                          ---> Désactive ton antivirus le temps de la manipulation car OTM est détecté comme une infection à tort.

                          ---> Télécharge OTM (OldTimer) sur ton Bureau.

                          ---> Clique droit sur OTM.exe et choisis Exécuter en tant qu'administrateur.

                          ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                          :processes
                          explorer.exe

                          :services
                          glaide32

                          :files
                          C:\Users\Benoît\AppData\Roaming\inst.exe
                          C:\Windows\system32\drivers\glaide32.sys
                          C:\ikax.exe
                          C:\Windows\system32\xpsvc32.exe
                          C:\Windows\system32\korn.exe
                          C:\Windows\msiexec.exe

                          :commands
                          [purity]
                          [emptytemp]
                          [reboot]

                          ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                          ---> Clique maintenant sur le bouton MoveIt! puis ferme OTM.

                          Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                          Accepte en cliquant sur YES.

                          ---> Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
                          Le nom du rapport correspond au moment de sa création : date_heure.log
                          0
                          1. je ne vois pas les fichiers supprimés ou desactivés, tu es sûr d'avoir fait l'option 2 ?
                            0
                            1. Modérateur
                              Non, il n'a pas fait l'option 2.
                              0
                              1. c'est bien ce qui me semablait aussi ; )
                                je te laisse faire mon copin, à + destio 05
                                0
                                1. j'ai un problème...
                                  quand j'ouvre "C:\_OTM\MovedFiles"

                                  il n'y a pas de fichier " .log "
                                  il n'y a que des sous-dossiers ....
                                  0
                                  • 1
                                  • 2
                                  • 3
                                  • 4