Internet explorer trop trop lent

Bonjour,
étant un super novice en informatique veuillez s il vous plait m aider et si possible dans un langage "basique" :)

internet explorer est devenu tres tres lent depuis quelque jours, le lancement , les ouvertures donglet , les temps de chargement .....

HELPPPPP ME !!!!
Configuration: Windows Vista
Internet Explorer 7.0

7 réponses

Résumé de la discussion

Internet Explorer 7 est devenu très lent sur Windows Vista, affectant le lancement du navigateur, l'ouverture des onglets et les temps de chargement ces derniers jours. La meilleure réponse conseille fortement de remplacer Internet Explorer par Mozilla Firefox, considéré comme une alternative plus rapide et plus fiable pour naviguer et gérer les onglets, afin d'améliorer significativement les performances. D'autres réponses préconisent un nettoyage système pour supprimer des barres d'outils et malware, et présentent des outils comme HijackThis et RSIT pour analyser les infections et les éléments de démarrage. En cas de lenteurs persistantes, les solutions impliquent la suppression de barres d'outils indésirables et l'analyse des paramètres système et démarrage afin d'identifier des éléments responsables.

Bobot (l’IA à votre service)
  1. Bonjour,
    Si internet explorer est devenue trop lent je te conseil fortement : Mozilla Firefox

    ++
    1
    1. Contributeur sécurité
      Hello,

      Tu peux commencer par télécharger hijackthis et me poster un rapport dans ta prochaine réponse.
      Comment générer un rapport. (merci à Balltrap 34 pour la démo)
      Ne fixe aucune ligne pour l'instant.
      0
      1. une fois installé hijack et le fameux rapport réalisé je me permet de te l envoyer en esperant que tu puisse m aider au mieux !
        merci encore

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 00:54:39, on 13/04/2009
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\Explorer.EXE
        C:\Windows\System32\mobsync.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\hp\support\hpsysdrv.exe
        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
        C:\Windows\RtHDVCpl.exe
        C:\Windows\system32\schtasks.exe
        C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
        c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
        C:\Windows\system32\jusched.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Windows Media Player\WMPNSCFG.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
        C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
        C:\Windows\ehome\ehtray.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\hp\kbd\kbd.exe
        C:\Program Files\Internet Explorer\ieuser.exe
        C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        O1 - Hosts: ::1 localhost
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
        O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
        O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
        O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
        O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
        O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
        O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
        O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
        O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O13 - Gopher Prefix:
        O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
        O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
        O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro3.cce.hp.com/ChatEntry/downloads/sysinfo.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/VistaMSNPUpldfr-fr.cab
        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
        O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        0
    2. Contributeur sécurité
      Hello,

      Tu es infecté par une barre d'outil

      Désactive L'UAC:
      http://www.commentcamarche.net/faq/sujet 8343 vista desactiver l uac

      Redémarre ton pc.

      Télécharge Toolbar-S&D (Merci eric 71) sur ton Bureau:
      https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

      Lance l'installation du programme en double cliquant sur le fichier téléchargé.
      Double-clique sur le raccourci de Toolbar-S&D.
      Choisi la langue souhaitée en tapant la lettre "F" puis en validant avec la touche Entrée.
      Choisi maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
      Poste un copier/coller du rapport généré.

      @+
      0
      1. merci beaucoup davance pour toute ton aide !

        voila le rapport toolbar sd que tu m as demandé

        -----------\\ ToolBar S&D 1.2.8 XP/Vista

        Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
        X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz )
        BIOS : BIOS Date: 02/26/08 10:59:48 Ver: 5.21
        USER : DAVID' ( Administrator )
        BOOT : Normal boot
        Antivirus : Norton Internet Security 15.0.0.60 (Activated)
        Firewall : Norton Internet Security 15.0.0.60 (Activated)
        C:\ (Local Disk) - NTFS - Total:287 Go (Free:170 Go)
        D:\ (Local Disk) - NTFS - Total:10 Go (Free:1 Go)
        E:\ (CD or DVD)
        G:\ (USB)
        H:\ (USB)
        I:\ (USB)
        J:\ (USB)

        "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
        Option : [1] ( 13/04/2009|23:41 )

        [ UAC => 0 ]

        -----------\\ Recherche de Fichiers / Dossiers ...

        C:\Program Files\AskSBar
        C:\Program Files\AskSBar\bar
        C:\Program Files\AskSBar\bar\1.bin
        C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.JAR
        C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.MANIFEST
        C:\Program Files\AskSBar\bar\1.bin\A2HIGHIN.EXE
        C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.JAR
        C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.MANIFEST
        C:\Program Files\AskSBar\bar\1.bin\A2PLUGIN.DLL
        C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
        C:\Program Files\AskSBar\bar\1.bin\NPASKSBR.DLL
        C:\Program Files\AskSBar\bar\1.bin\V2RSSMNU.DLL

        -----------\\ [..\Internet Explorer\Main]

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
        "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
        "Local Page"="C:\\Windows\\system32\\blank.htm"
        "Search Page"="https://www.google.com/?gws_rd=ssl"
        "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
        "Url"="https://www.msn.com/fr-fr/actualite/"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
        "Start Page"="https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF"
        "Default_Page_URL"="https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF"
        "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

        --------------------\\ Recherche d'autres infections

        Aucune autre infection trouvée !

        [ UAC => 1 ]

        1 - "C:\ToolBar SD\TB_1.txt" - 13/04/2009|23:42 - Option : [1]

        -----------\\ Fin du rapport a 23:42:16,21
        0
      2. Contributeur sécurité
        @david1711Hello,

        Relance Toolbar-S&D. Choisis cette fois l'option 2 "suppression" puis valide avec "Entrée".
        Ne ferme pas la fenêtre lors de la suppression
        Poste ensuite le rapport.


        Au cas où :
        Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
        Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
        Tape explorer.exe puis valide.

        ______________________________________________________________________________________

        Ensuite:
        - Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

        - Double-clique sur RSIT.exe afin de lancer le programme.

        - Clique sur Continue à l'écran Disclaimer.

        -Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

        - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches) dans deux messages différents.

        NB : Les rapports sont sauvegardés dans le dossier C:\rsit.
        0
      3. @Trying2voila celui apres l etape supression
        -----------\\ ToolBar S&D 1.2.8 XP/Vista

        Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
        X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz )
        BIOS : BIOS Date: 02/26/08 10:59:48 Ver: 5.21
        USER : DAVID' ( Administrator )
        BOOT : Normal boot
        Antivirus : Norton Internet Security 15.0.0.60 (Activated)
        Firewall : Norton Internet Security 15.0.0.60 (Activated)
        C:\ (Local Disk) - NTFS - Total:287 Go (Free:170 Go)
        D:\ (Local Disk) - NTFS - Total:10 Go (Free:1 Go)
        E:\ (CD or DVD)
        G:\ (USB)
        H:\ (USB)
        I:\ (USB)
        J:\ (USB)

        "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
        Option : [2] ( 14/04/2009| 0:17 )

        [ UAC => 1 ]

        -----------\\ SUPPRESSION

        Supprime! - C:\Program Files\AskSBar\bar
        Supprime! - C:\Program Files\AskSBar

        -----------\\ Recherche de Fichiers / Dossiers ...

        -----------\\ [..\Internet Explorer\Main]

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
        "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
        "Local Page"="C:\\Windows\\system32\\blank.htm"
        "Search Page"="https://www.google.com/?gws_rd=ssl"
        "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
        "Url"="https://www.msn.com/fr-fr/actualite/"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
        "Start Page"="https://www.msn.com/fr-fr/"
        "Default_Page_URL"="https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF"
        "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

        --------------------\\ Recherche d'autres infections

        Aucune autre infection trouvée !

        [ UAC => 1 ]

        1 - "C:\ToolBar SD\TB_1.txt" - 13/04/2009|23:42 - Option : [1]
        2 - "C:\ToolBar SD\TB_2.txt" - 14/04/2009| 0:17 - Option : [2]

        -----------\\ Fin du rapport a 0:17:40,83

        voila le second rapport ( le troisieme je te l enverai juste en dessous)

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by DAVID' at 2009-04-14 00:24:05
        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
        System drive C: has 174 GB (59%) free of 295 GB
        Total RAM: 3071 MB (66% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 00:24:11, on 14/04/2009
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\hp\support\hpsysdrv.exe
        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
        C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
        C:\Windows\ehome\ehtray.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Windows\system32\schtasks.exe
        c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
        C:\Windows\System32\mobsync.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
        C:\hp\kbd\kbd.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\cmd.exe
        C:\Windows\System32\NOTEPAD.EXE
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Users\DAVID'\Desktop\RSIT.exe
        C:\Program Files\Trend Micro\HijackThis\DAVID'.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - Default URLSearchHook is missing
        O1 - Hosts: ::1 localhost
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
        O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
        O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
        O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
        O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
        O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
        O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O13 - Gopher Prefix:
        O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
        O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
        O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro3.cce.hp.com/ChatEntry/downloads/sysinfo.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/VistaMSNPUpldfr-fr.cab
        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
        O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        0
      4. @david1711et voila le dernier! merci encore !!!

        info.txt logfile of random's system information tool 1.06 2009-04-14 00:24:12

        ======Uninstall list======

        -->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
        -->"C:\Program Files\HP Games\Blasterball 2 Revolution\Uninstall.exe"
        -->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
        -->"C:\Program Files\HP Games\Bricks of Egypt\Uninstall.exe"
        -->"C:\Program Files\HP Games\Chicken Invaders 3 - Revenge of the Yolk\Uninstall.exe"
        -->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
        -->"C:\Program Files\HP Games\Crystal Maze\Uninstall.exe"
        -->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
        -->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
        -->"C:\Program Files\HP Games\FATE\Uninstall.exe"
        -->"C:\Program Files\HP Games\Fish Tycoon\Uninstall.exe"
        -->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
        -->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
        -->"C:\Program Files\HP Games\Jewel Quest\Uninstall.exe"
        -->"C:\Program Files\HP Games\Magic Academy\Uninstall.exe"
        -->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
        -->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
        -->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
        -->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
        -->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
        -->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
        -->"C:\Program Files\HP Games\Polar Golfer Pineapple Cup\Uninstall.exe"
        -->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
        -->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
        -->"C:\Program Files\HP Games\Shooting Stars Pool\Uninstall.exe"
        -->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
        -->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
        -->"C:\Program Files\HP Games\Super Granny\Uninstall.exe"
        -->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
        -->"C:\Program Files\HP Games\Virtual Villagers - A New Home\Uninstall.exe"
        -->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
        -->"c:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
        -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
        -->MsiExec.exe /I{48A669A9-76FA-4CA8-BFD5-00C125AC4166}
        Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Reader 8.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
        AirPlus G-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2B7E4354-0492-460A-BDB1-1F59EE141025}\setup.exe" -l0x40c -removeonly
        AppCore-->MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
        Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
        Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
        Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
        Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
        Avanquest update-->C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe -runfromtemp -l0x0009 -removeonly
        AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
        BlackBerry Desktop Software 4.6-->MsiExec.exe /i{14AD69CE-B59F-4EC2-BC3A-DB56105F3D62}
        BlackBerry Desktop Software 4.6-->MsiExec.exe /I{14AD69CE-B59F-4EC2-BC3A-DB56105F3D62}
        Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
        Catalyst Control Center - Branding-->MsiExec.exe /I{2E4609A3-F5AF-4408-B0C4-B8B84BC753DF}
        ccCommon-->MsiExec.exe /I{B24E05CC-46FF-4787-BBB8-5CD516AFB118}
        Compel Adaptec WinASPI-->"C:\Program Files\WinASPI\unins000.exe"
        Component Framework-->MsiExec.exe /I{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}
        CyberLink DVD Suite Deluxe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\Setup.exe" -uninstall
        DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
        DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
        DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
        DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
        DVD2Pod-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A72D1D05-1145-4BDB-AC26-DA88AB4B7B65}\setup.exe" -l0x40c -removeonly
        Free FLV Converter V 5.3-->"C:\Program Files\Free FLV Converter conversion video du net\unins000.exe"
        Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
        Google Earth-->MsiExec.exe /X{548EAC70-EE00-11DD-908C-005056806466}
        Hewlett-Packard Active Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
        Hewlett-Packard Asset Agent for Health Check-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
        HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
        HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C8D47273-7A1A-4614-A3D8-263632D8A5ED}\setup.exe" -l0x9 -removeonly
        HP Customer Feedback-->MsiExec.exe /I{9DBA770F-BF73-4D39-B1DF-6035D95268FC}
        HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1BCE2581-B7CA-4BB4-BDFB-D113506AA38B}\setup.exe" -l0x9 -removeonly
        HP On-Screen Cap/Num/Scroll Lock Indicator-->C:\Windows\system32\OsdRemove.exe
        HP Photosmart Essential 2.5-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
        HP Picasso Media Center Add-In-->MsiExec.exe /I{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}
        HP Total Care Advisor-->MsiExec.exe /X{fef8097e-662d-49b3-aa77-2919db3746d7}
        HP Update-->MsiExec.exe /X{7059BDA7-E1DB-442C-B7A1-6144596720A4}
        Intel(R) Matrix Storage Manager-->C:\Windows\System32\Imsmudlg.exe
        iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
        Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
        Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
        LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" -uninstall
        LightScribe System Software 1.10.23.1-->MsiExec.exe /X{0E19A83E-F53B-40CF-8C91-96F32D955E6A}
        LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
        LiveUpdate (Symantec Corporation)-->MsiExec.exe /x {E80F62FF-5D3C-4A19-8409-9721F2928206} /l*v "c:\ProgramData\LuUninstall.LiveUpdate"
        LiveUpdate (Symantec Corporation)-->MsiExec.exe /X{E80F62FF-5D3C-4A19-8409-9721F2928206}
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1 Hotfix (KB929729)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M929729\M929729Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
        Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
        Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
        Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
        Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
        Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
        Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
        Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
        Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
        MSVC80_x86-->MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
        muvee autoProducer 6.1-->C:\Program Files\InstallShield Installation Information\{5115C036-C0D5-4E1B-81C9-542CA967478A}\muveesetup.exe -removeonly -runfromtemp
        My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
        Nokia Connectivity Cable Driver-->MsiExec.exe /X{15AC0C5D-A6FB-4CE2-8CD0-28179EEB5625}
        Nokia PC Suite-->C:\ProgramData\Installations\{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}\Nokia_PC_Suite_7_1_18_0_fre.exe
        Nokia PC Suite-->MsiExec.exe /I{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}
        Norton AntiVirus Help-->MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
        Norton AntiVirus-->MsiExec.exe /X{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}
        Norton Confidential Core-->MsiExec.exe /I{55A6283C-638A-4EE0-B491-51118554BDA2}
        Norton Internet Security (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\SymSetup\{C1C185CA-C531-49F5-A6FA-B838405A049D}_15_0_0_60\Setup.exe" /X
        Norton Internet Security-->MsiExec.exe /I{3672B097-EA69-4BFE-B92F-29AE6D9D2B34}
        Norton Internet Security-->MsiExec.exe /I{C1C185CA-C531-49F5-A6FA-B838405A049D}
        Norton Protection Center-->MsiExec.exe /I{62120008-8E1E-4807-860D-A8B48F8552DB}
        Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
        Outils de diagnostic du matériel-->C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
        Package de pilotes Windows - Nokia Modem (03/05/2008 3.7)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\nokia_bluetooth.inf_ce5ad925\nokia_bluetooth.inf
        Package de pilotes Windows - Nokia Modem (03/13/2008 6.86.0.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\nokbtmdm.inf_674398ba\nokbtmdm.inf
        Package de pilotes Windows - Nokia Modem (10/27/2008 3.9)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\nokia_bluetooth.inf_544c8e16\nokia_bluetooth.inf
        Package de pilotes Windows - Nokia Modem (10/27/2008 7.01.0.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\nokbtmdm.inf_0e4dd4bb\nokbtmdm.inf
        Package de pilotes Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\Windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf
        Panneau de configuration MobileMe-->MsiExec.exe /I{6DA9102E-199F-43A0-A36B-6EF48081A658}
        PC Connectivity Solution-->MsiExec.exe /I{D848D140-41C3-4A53-86D8-E866A100B4CD}
        Pinnacle TVCenter Pro-->"C:\Program Files\InstallShield Installation Information\{F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA}\Setup.exe"UNINSTALL /l0x040c -removeonly
        Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" -uninstall
        PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
        PSPWare-->"C:\Program Files\PSPWare\uninstall.exe"
        Python 2.5-->MsiExec.exe /I{0A2C5854-557E-48C8-835A-3B9F074BDCAA}
        QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
        RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
        Roxio Media Manager-->MsiExec.exe /X{F6377647-81AF-41C0-BC7E-06CF37E204AB}
        Safari-->MsiExec.exe /I{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}
        Solution de clavier multimédia amélioré-->C:\HP\KBD\Install.exe /u
        SPBBC 32bit-->MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
        Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
        VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
        VeohTV BETA-->C:\Program Files\InstallShield Installation Information\{0405E51E-9582-4207-8F38-AC44201D3808}\setup.exe -runfromtemp -l0x0409
        Version de démonstration de Microsoft Office Home and Student 2007-->c:\hp\bin\MSOffice\uninst2.cmd
        VideoLAN VLC media player 0.8.6h-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        Vuze-->C:\Program Files\Vuze azureus\uninstall.exe
        Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
        Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
        Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}

        ======Security center information======

        AV: Norton Internet Security (outdated)
        FW: Norton Internet Security
        AS: Windows Defender
        AS: Norton Internet Security (outdated)

        ======System event log======

        Computer Name: PC-de-DAVID
        Event Code: 4226
        Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
        Record Number: 122442
        Source Name: Tcpip
        Time Written: 20090413174639.267000-000
        Event Type: Avertissement
        User:

        Computer Name: PC-de-DAVID
        Event Code: 4226
        Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
        Record Number: 122443
        Source Name: Tcpip
        Time Written: 20090413192051.655000-000
        Event Type: Avertissement
        User:

        Computer Name: PC-de-DAVID
        Event Code: 4226
        Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
        Record Number: 122444
        Source Name: Tcpip
        Time Written: 20090413200344.734000-000
        Event Type: Avertissement
        User:

        Computer Name: PC-de-DAVID
        Event Code: 4001
        Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

        Record Number: 122452
        Source Name: Microsoft-Windows-WLAN-AutoConfig
        Time Written: 20090413213341.526800-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: PC-de-DAVID
        Event Code: 15016
        Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
        Record Number: 122468
        Source Name: Microsoft-Windows-HttpEvent
        Time Written: 20090413213431.832121-000
        Event Type: Erreur
        User:

        =====Application event log=====

        Computer Name: PC-de-DAVID
        Event Code: 4621
        Message: Le système d'événements de COM+ n'a pas pu supprimer l'objet EventSystem.EventSubscription {CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. HRESULT : 80070005.
        Record Number: 50298
        Source Name: Microsoft-Windows-EventSystem
        Time Written: 20090413115221.000000-000
        Event Type: Erreur
        User:

        Computer Name: PC-de-DAVID
        Event Code: 1530
        Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

        DÉTAIL -
        1 user registry handles leaked from \Registry\User\S-1-5-21-2654767095-991143059-3734150245-1000:
        Process 992 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2654767095-991143059-3734150245-1000

        Record Number: 50301
        Source Name: Microsoft-Windows-User Profiles Service
        Time Written: 20090413115224.000000-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: PC-de-DAVID
        Event Code: 1530
        Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

        DÉTAIL -
        1 user registry handles leaked from \Registry\User\S-1-5-21-2654767095-991143059-3734150245-1000_Classes:
        Process 992 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2654767095-991143059-3734150245-1000_CLASSES

        Record Number: 50302
        Source Name: Microsoft-Windows-User Profiles Service
        Time Written: 20090413115224.000000-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: PC-de-DAVID
        Event Code: 1530
        Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

        DÉTAIL -
        1 user registry handles leaked from \Registry\User\S-1-5-21-2654767095-991143059-3734150245-1000:
        Process 988 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2654767095-991143059-3734150245-1000

        Record Number: 50344
        Source Name: Microsoft-Windows-User Profiles Service
        Time Written: 20090413213339.000000-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: PC-de-DAVID
        Event Code: 1530
        Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

        DÉTAIL -
        1 user registry handles leaked from \Registry\User\S-1-5-21-2654767095-991143059-3734150245-1000_Classes:
        Process 988 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2654767095-991143059-3734150245-1000_CLASSES

        Record Number: 50345
        Source Name: Microsoft-Windows-User Profiles Service
        Time Written: 20090413213339.000000-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        =====Security event log=====

        Computer Name: PC-de-DAVID
        Event Code: 5024
        Message: Le démarrage du service Pare-feu Windows s’est correctement déroulé.
        Record Number: 20589
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20081225113750.232362-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-DAVID
        Event Code: 4624
        Message: L’ouverture de session d’un compte s’est correctement déroulée.

        Sujet :
        ID de sécurité : S-1-0-0
        Nom du compte : -
        Domaine du compte : -
        ID d’ouverture de session : 0x0

        Type d’ouverture de session : 3

        Nouvelle ouverture de session :
        ID de sécurité : S-1-5-7
        Nom du compte : ANONYMOUS LOGON
        Domaine du compte : AUTORITE NT
        ID d’ouverture de session : 0x4122b
        GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

        Informations sur le processus :
        ID du processus : 0x0
        Nom du processus : -

        Informations sur le réseau :
        Nom de la station de travail :
        Adresse du réseau source : -
        Port source : -

        Informations détaillées sur l’authentification :
        Processus d’ouverture de session : NtLmSsp
        Package d’authentification : NTLM
        Services en transit : -
        Nom du package (NTLM uniquement) : NTLM V1
        Longueur de la clé : 0

        Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

        Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

        Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

        Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

        Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

        Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
        - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
        - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
        - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
        - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
        Record Number: 20590
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20081225113750.264362-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-DAVID
        Event Code: 5038
        Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

        Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\Aspi32.sys
        Record Number: 20591
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20081225113750.529362-000
        Event Type: Échec de l'audit
        User:

        Computer Name: PC-de-DAVID
        Event Code: 4648
        Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

        Sujet :
        ID de sécurité : S-1-5-18
        Nom du compte : PC-DE-DAVID$
        Domaine du compte : WORKGROUP
        ID d’ouverture de session : 0x3e7
        GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

        Compte dont les informations d’identification ont été utilisées :
        Nom du compte : SYSTEM
        Domaine du compte : AUTORITE NT
        GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

        Serveur cible :
        Nom du serveur cible : localhost
        Informations supplémentaires : localhost

        Informations sur le processus :
        ID du processus : 0x2a0
        Nom du processus : C:\Windows\System32\services.exe

        Informations sur le réseau :
        Adresse du réseau : -
        Port : -

        Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
        Record Number: 20592
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20081225113756.078562-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-DAVID
        Event Code: 4624
        Message: L’ouverture de session d’un compte s’est correctement déroulée.

        Sujet :
        ID de sécurité : S-1-5-18
        Nom du compte : PC-DE-DAVID$
        Domaine du compte : WORKGROUP
        ID d’ouverture de session : 0x3e7

        Type d’ouverture de session : 5

        Nouvelle ouverture de session :
        ID de sécurité : S-1-5-18
        Nom du compte : SYSTEM
        Domaine du compte : AUTORITE NT
        ID d’ouverture de session : 0x3e7
        GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

        Informations sur le processus :
        ID du processus : 0x2a0
        Nom du processus : C:\Windows\System32\services.exe

        Informations sur le réseau :
        Nom de la station de travail :
        Adresse du réseau source : -
        Port source : -

        Informations détaillées sur l’authentification :
        Processus d’ouverture de session : Advapi
        Package d’authentification : Negotiate
        Services en transit : -
        Nom du package (NTLM uniquement) : -
        Longueur de la clé : 0

        Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

        Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

        Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

        Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

        Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

        Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
        - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
        - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
        - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
        - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
        Record Number: 20593
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20081225113756.078562-000
        Event Type: Succès de l'audit
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\hp\bin\Python;c:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
        "PROCESSOR_ARCHITECTURE"=x86
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "USERNAME"=SYSTEM
        "windir"=%SystemRoot%
        "PROCESSOR_LEVEL"=6
        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
        "PROCESSOR_REVISION"=0f0b
        "NUMBER_OF_PROCESSORS"=4
        "PLATFORM"=HPD
        "PCBRAND"=Pavilion
        "OnlineServices"=Online Services
        "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
        "QTJAVA"=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip

        -----------------EOF-----------------
        0
      5. @Trying2Voila celui apres l etape supression
        -----------\\ ToolBar S&D 1.2.8 XP/Vista

        Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
        X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz )
        BIOS : BIOS Date: 02/26/08 10:59:48 Ver: 5.21
        USER : DAVID' ( Administrator )
        BOOT : Normal boot
        Antivirus : Norton Internet Security 15.0.0.60 (Activated)
        Firewall : Norton Internet Security 15.0.0.60 (Activated)
        C:\ (Local Disk) - NTFS - Total:287 Go (Free:170 Go)
        D:\ (Local Disk) - NTFS - Total:10 Go (Free:1 Go)
        E:\ (CD or DVD)
        G:\ (USB)
        H:\ (USB)
        I:\ (USB)
        J:\ (USB)

        "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
        Option : [2] ( 14/04/2009| 0:17 )

        [ UAC => 1 ]

        -----------\\ SUPPRESSION

        Supprime! - C:\Program Files\AskSBar\bar
        Supprime! - C:\Program Files\AskSBar

        -----------\\ Recherche de Fichiers / Dossiers ...

        -----------\\ [..\Internet Explorer\Main]

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
        "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
        "Local Page"="C:\\Windows\\system32\\blank.htm"
        "Search Page"="https://www.google.com/?gws_rd=ssl"
        "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
        "Url"="https://www.msn.com/fr-fr/actualite/"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
        "Start Page"="https://www.msn.com/fr-fr/"
        "Default_Page_URL"="http://ie.redirect.hp.com/"
        "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

        --------------------\\ Recherche d'autres infections

        Aucune autre infection trouvée !

        [ UAC => 1 ]

        1 - "C:\ToolBar SD\TB_1.txt" - 13/04/2009|23:42 - Option : [1]
        2 - "C:\ToolBar SD\TB_2.txt" - 14/04/2009| 0:17 - Option : [2]

        -----------\\ Fin du rapport a 0:17:40,83

        voila le second rapport ( le troisieme je te l enverai juste en dessous)

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by DAVID' at 2009-04-14 00:24:05
        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
        System drive C: has 174 GB (59%) free of 295 GB
        Total RAM: 3071 MB (66% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 00:24:11, on 14/04/2009
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\hp\support\hpsysdrv.exe
        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
        C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
        C:\Windows\ehome\ehtray.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Windows\system32\schtasks.exe
        c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
        C:\Windows\System32\mobsync.exe
        C:\Windows\system32\wbem\unsecapp.exe
        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
        C:\hp\kbd\kbd.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\cmd.exe
        C:\Windows\System32\NOTEPAD.EXE
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Users\DAVID'\Desktop\RSIT.exe
        C:\Program Files\Trend Micro\HijackThis\DAVID'.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - Default URLSearchHook is missing
        O1 - Hosts: ::1 localhost
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
        O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
        O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
        O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
        O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
        O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
        O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O13 - Gopher Prefix:
        O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
        O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
        O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro3.cce.hp.com/ChatEntry/downloads/sysinfo.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/VistaMSNPUpldfr-fr.cab
        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
        O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

        End of file - 7876 bytes

        ======Scheduled tasks folder======

        C:\Windows\tasks\Google Software Updater.job
        C:\Windows\tasks\GoogleUpdateTaskMachine.job
        C:\Windows\tasks\Norton Internet Security - Effectuer une analyse complète du système - DAVID'.job
        C:\Windows\tasks\User_Feed_Synchronization-{28B504AF-9560-408E-B0E8-900933E20EEB}.job

        ======Registry dump======

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
        Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
        RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-07-30 308856]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
        c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll [2007-08-24 316784]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
        Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll [2008-06-10 116088]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
        Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
        Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-03-25 668656]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
        Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-04-09 35840]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
        {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Show Norton Toolbar - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 316784]
        {D0943516-5076-4020-A3B5-AEFAF26AB263} - Veoh Browser Plug-in - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [2008-08-28 352256]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
        ""= []
        "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
        "IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2007-07-12 178712]
        "hpsysdrv"=c:\hp\support\hpsysdrv.exe [2007-04-18 65536]
        "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
        "HP Health Check Scheduler"=[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe []
        "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-07-03 6266880]
        "SunJavaUpdateReg"=C:\Windows\system32\jureg.exe [2007-04-07 54936]
        "RoxWatchTray"=C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2008-06-08 236016]
        "OsdMaestro"=C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [2007-02-15 118784]
        "StartCCC"=c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
        "KBD"=C:\HP\KBD\KbdStub.EXE [2006-12-08 65536]
        "TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-07-30 185896]
        "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-04-09 148888]

        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
        ""= []
        "PMCRemote"= []
        "msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2007-10-18 5724184]
        "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-19 1233920]
        "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-01-26 39408]
        "ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-11 218032]
        "Veoh"=C:\Program Files\Veoh Networks\Veoh\VeohClient.exe [2008-08-28 3660848]
        "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
        C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-09-03 111936]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
        c:\Program Files\Common Files\Symantec Shared\ccApp.exe [2008-10-17 51048]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
        C:\Program Files\eMule\emule.exe -AutoStart []

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
        C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [2008-01-18 942080]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
        C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
        C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia FastStart]
        C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe /command:faststart []

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
        C:\Program Files\QuickTime\QTTask.exe [2008-11-04 413696]

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-01-26 39408]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
        "dontdisplaylastusername"=0
        "legalnoticecaption"=
        "legalnoticetext"=
        "shutdownwithoutlogon"=1
        "undockwithoutlogon"=1
        "FilterAdministratorToken"=1
        "EnableUIADesktopToggle"=0
        "DisableStatusMessages"=0

        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
        "NoViewContextMenu"=0
        "NoRun"=0
        "NoFind"=0
        "NoDesktop"=0
        "HideClock"=0
        "NoFolderOptions"=0
        "NoDriveTypeAutoRun"=149

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be6634d7-4dae-11dd-ae2b-001fc62b603e}]
        shell\Setup\command - F:\setup.exe

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e45f6808-f05f-11dd-bb5b-001fc62b603e}]
        shell\AutoRun\command - F:\start.exe
        shell\iledefrance\command - F:\start.exe

        ======File associations======

        .bat - edit - %SystemRoot%\System32\NOTEPAD.EXE %1"
        .ini - open - %SystemRoot%\System32\NOTEPAD.EXE %1"

        ======List of files/folders created in the last 1 months======

        2009-04-14 00:24:05 ----D---- C:\rsit
        2009-04-13 23:41:54 ----A---- C:\TB.txt
        2009-04-13 23:41:18 ----D---- C:\ToolBar SD
        2009-04-13 00:54:20 ----D---- C:\Program Files\Trend Micro
        2009-04-09 19:07:11 ----A---- C:\Windows\system32\javaws.exe
        2009-04-09 19:07:11 ----A---- C:\Windows\system32\javaw.exe
        2009-04-09 19:07:11 ----A---- C:\Windows\system32\java.exe
        2009-04-09 19:07:11 ----A---- C:\Windows\system32\deploytk.dll
        2009-04-04 17:11:56 ----D---- C:\Program Files\Microsoft
        2009-04-04 14:00:12 ----A---- C:\Windows\system32\PresentationHostProxy.dll
        2009-04-04 14:00:12 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
        2009-04-04 14:00:12 ----A---- C:\Windows\system32\infocardapi.dll
        2009-04-04 14:00:12 ----A---- C:\Windows\system32\icardres.dll
        2009-04-04 14:00:12 ----A---- C:\Windows\system32\icardagt.exe
        2009-04-04 14:00:11 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
        2009-04-04 14:00:09 ----A---- C:\Windows\system32\PresentationHost.exe
        2009-04-04 13:55:58 ----A---- C:\Windows\system32\dfshim.dll
        2009-04-04 13:55:53 ----A---- C:\Windows\system32\mscoree.dll
        2009-04-04 13:55:52 ----A---- C:\Windows\system32\netfxperf.dll
        2009-04-04 13:55:42 ----A---- C:\Windows\system32\mscorier.dll
        2009-04-04 13:55:38 ----A---- C:\Windows\system32\mscories.dll

        ======List of files/folders modified in the last 1 months======

        2009-04-14 00:24:11 ----D---- C:\Windows\Prefetch
        2009-04-14 00:24:07 ----D---- C:\Windows\Temp
        2009-04-14 00:17:29 ----RD---- C:\Program Files
        2009-04-13 23:39:00 ----D---- C:\Windows\System32
        2009-04-13 23:39:00 ----D---- C:\Windows\inf
        2009-04-13 23:39:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
        2009-04-13 23:36:58 ----D---- C:\Windows\Tasks
        2009-04-13 18:50:13 ----D---- C:\ProgramData\Google Updater
        2009-04-12 18:14:19 ----SHD---- C:\System Volume Information
        2009-04-11 23:05:21 ----D---- C:\Windows\system32\Tasks
        2009-04-09 19:49:59 ----HD---- C:\ProgramData
        2009-04-09 19:49:59 ----D---- C:\Windows\system32\drivers
        2009-04-09 19:07:14 ----SHD---- C:\Windows\Installer
        2009-04-09 19:06:50 ----D---- C:\Program Files\Java
        2009-04-09 14:19:58 ----D---- C:\ProgramData\Google
        2009-04-09 14:19:58 ----D---- C:\Program Files\Google
        2009-04-08 20:22:28 ----RSD---- C:\Windows\assembly
        2009-04-08 17:50:03 ----D---- C:\Program Files\AOL
        2009-04-08 15:42:54 ----SD---- C:\Windows\Downloaded Program Files
        2009-04-07 16:58:18 ----D---- C:\Windows\system32\catroot2
        2009-04-05 03:06:32 ----D---- C:\Windows\Microsoft.NET
        2009-04-04 21:22:25 ----D---- C:\Windows\system32\wbem
        2009-04-04 21:22:25 ----D---- C:\Windows
        2009-04-04 21:11:45 ----D---- C:\Windows\winsxs
        2009-04-04 21:11:43 ----D---- C:\Windows\system32\XPSViewer
        2009-04-04 21:11:43 ----D---- C:\Windows\system32\spool
        2009-04-04 21:11:43 ----D---- C:\Windows\system32\fr-FR
        2009-04-04 21:11:43 ----D---- C:\Windows\system32\en-US
        2009-04-04 21:11:43 ----D---- C:\Windows\SMINST
        2009-04-04 21:11:43 ----D---- C:\Windows\rescache
        2009-04-04 21:11:40 ----D---- C:\Program Files\Windows Mail
        2009-04-04 21:11:39 ----D---- C:\Windows\registration
        2009-04-04 18:18:23 ----SD---- C:\Users\DAVID'\AppData\Roaming\Microsoft
        2009-04-04 18:08:57 ----HD---- C:\hp
        2009-04-04 17:11:48 ----D---- C:\Windows\system32\catroot
        2009-04-04 13:51:11 ----D---- C:\Users\DAVID'\AppData\Roaming\InstallShield
        2009-04-03 22:38:58 ----D---- C:\Windows\Minidump
        2009-03-30 20:52:43 ----D---- C:\Users\DAVID'\AppData\Roaming\LimeWire
        2009-03-26 21:04:21 ----D---- C:\Windows\system32\WDI

        ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

        R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2008-08-23 371248]
        R1 IDSvix86;Symantec Intrusion Prevention Driver; \??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080818.001\IDSvix86.sys [2008-03-20 261680]
        R1 SRTSP;SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [2007-11-30 279088]
        R1 SRTSPX;SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [2007-11-30 43696]
        R1 SymIM;Symantec Network Security Intermediate Filter Driver; C:\Windows\system32\DRIVERS\SymIMv.sys [2009-02-19 24112]
        R1 SYMTDI;SYMTDI; C:\Windows\System32\Drivers\SYMTDI.SYS [2009-02-19 184496]
        R2 Aspi32;Aspi32; C:\Windows\system32\drivers\Aspi32.sys [1999-09-10 25244]
        R2 CO_Mon;CO_Mon; \??\C:\Windows\system32\drivers\CO_Mon.sys [2007-08-08 36056]
        R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-02-04 3483136]
        R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-08-23 99376]
        R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
        R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-07-03 2152088]
        R3 Ltn_stk7070P;PCTV based TV tuner device; C:\Windows\system32\DRIVERS\Ltn_stk7070P.sys [2007-06-14 466048]
        R3 Ltn_stkrc;PCTV Infrared Receiver; C:\Windows\system32\DRIVERS\Ltn_stkrc.sys [2007-06-13 13440]
        R3 NAVENG;NAVENG; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080823.019\NAVENG.SYS [2008-08-23 89104]
        R3 NAVEX15;NAVEX15; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20080823.019\NAVEX15.SYS [2008-08-23 873552]
        R3 Ps2;PS2; C:\Windows\system32\DRIVERS\PS2.sys [2005-12-12 19072]
        R3 RimVSerPort;RIM Virtual Serial Port v2; C:\Windows\system32\DRIVERS\RimSerial.sys [2007-01-18 26496]
        R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2008-01-19 8192]
        R3 RT73;D-Link USB Wireless LAN Card Driver; C:\Windows\system32\DRIVERS\Dr71WU.sys [2007-05-11 329728]
        R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-10-03 99840]
        R3 SYMDNS;SYMDNS; C:\Windows\System32\Drivers\SYMDNS.SYS [2009-02-19 13616]
        R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2009-01-12 124464]
        R3 SYMFW;SYMFW; C:\Windows\System32\Drivers\SYMFW.SYS [2009-02-19 96560]
        R3 SYMNDISV;SYMNDISV; C:\Windows\System32\Drivers\SYMNDISV.SYS [2009-02-19 41008]
        R3 SYMREDRV;SYMREDRV; C:\Windows\System32\Drivers\SYMREDRV.SYS [2009-02-19 22320]
        R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
        S3 COH_Mon;COH_Mon; \??\C:\Windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
        S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
        S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
        S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
        S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
        S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
        S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2008-09-15 17664]
        S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2008-09-15 22016]
        S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
        S3 RimUsb;Téléphone intelligent BlackBerry ; C:\Windows\System32\Drivers\RimUsb.sys [2007-05-31 22656]
        S3 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [2008-09-05 447024]
        S3 SRTSPL;SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [2007-11-30 317616]
        S3 SymIMMP;SymIMMP; C:\Windows\system32\DRIVERS\SymIM.sys []
        S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2008-09-15 8064]
        S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2008-10-01 32000]
        S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2008-01-19 28160]
        S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

        ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

        R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-02-04 643072]
        R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2007-07-12 354840]
        R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
        S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-25 183280]
        S3 GameConsoleService;GameConsoleService; C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe [2007-07-24 181800]
        S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
        S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
        S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
        S4 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
        S4 Automatic LiveUpdate Scheduler;Planificateur LiveUpdate automatique; c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2007-08-31 243064]
        S4 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
        S4 ccEvtMgr;Symantec Event Manager; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
        S4 ccSetMgr;Symantec Settings Manager; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
        S4 CLTNetCnService;Symantec Lic NetConnect service; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
        S4 comHost;COM Host; c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [2007-08-21 55640]
        S4 gupdate1c988a3d6791068;Google Update Service (gupdate1c988a3d6791068); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-06 133104]
        S4 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2007-09-19 65536]
        S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
        S4 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-11-19 79136]
        S4 LiveUpdate Notice;LiveUpdate Notice; c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
        S4 LiveUpdate;LiveUpdate; c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE [2007-08-23 3192184]
        S4 Roxio UPnP Renderer 9;Roxio UPnP Renderer 9; C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe [2007-12-07 88560]
        S4 Roxio Upnp Server 9;Roxio Upnp Server 9; C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe [2007-12-07 362992]
        S4 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe [2008-06-08 313840]
        S4 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2008-06-08 1108464]
        S4 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2008-06-08 170480]
        S4 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-11-11 620544]
        S4 Symantec Core LC;Symantec Core LC; C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe [2008-06-10 1251720]

        -----------------EOF-----------------
        0
    3. Contributeur sécurité
      Tu payes pour Norton ou c'est une version fournie avec le pc?

      Ton installation de Vista est d'origine ou tu l'as déjà réinstallé? (si oui, de quelle manière?)

      Fais en sorte que l'UAC soit encore désactivé.

      *Télécharge et installe UsbFix de C_XX & Chiquitine29.

      *Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectés sans les ouvrir.
      Notamment ce qui correspond à ton périphérique F/

      *Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "exécuter en tant qu'administrateur" .

      *Choisi l'option 1 ( Recherche )

      *Laisse travailler l'outil.

      *Ensuite poste le rapport UsbFix.txt qui apparaîtra dans ton prochain message.

      Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
      "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
      0
      1. je ne paye pas pour norton , non et non je n ai jamais reinstallé vista !
        quat aux autre procedure j attackerais demain , il se fait trop tard ! merci encore meme si je ne comprend rien a ce que je fais ... ;)
        0
      2. Contributeur sécurité
        @david1711merci encore meme si je ne comprend rien a ce que je fais ... ;)

        Je t'en prie, n'hésite pas à poser des questions si tu le souhaites.

        Pour Norton, je te le ferai désinstaller pour, un plus efficace, plus léger et bien sûr gratuit.

        Pour l'instant: hijackthis et RSIT sont des outils de diagnostics.
        Au travers de ces rapports, on cherche la petite bête qui ne devrait pas y être et on utilise le logiciel adapté à son éradication.

        La toolbar ask était présente --> on a utilisé toolbar sd.

        Tu as un fichier que j'espère shooter avec usbFix, sachant qu'usbfix se chargera d'éliminer les clé de registre correspondants à cette bestiole.

        Je te poste un peu plus tard de quoi virer Norton proprement et de quoi télécharger Antivir.

        Voilou.
        Bonne nuit.
        0
    4. Contributeur sécurité
      Pour l'antivirus:

      Télécharge Antivir, mais ne l'installe pas tout de suite.

      Suis l'étape 2 de cette page pour désinstaller Norton.
      Redémarre ton pc.

      Tu peux maintenant double cliquer sur Antivir pour l'installer.

      Mets le à jour, effectue un scan complet et poste le moi dans ta prochaine réponse.
      0
      1. ayant eu quelque exam je n ai toujours pas réaliser ce que tu m à demander , mais à la grande surprise général !!!! Mon pc à décider ( comme un grand ) se ne plus aller sur internet !! Il est connecter à internet , msn marche , les mises à jour se font , mais internet explorer non ! Rien à faire !! Je ne peux donc plus télécharger les logiciels ect .. Pour dégager le pb de mon ordi ! que faire ??????? Le reinitialiser ?
        0
      2. Contributeur sécurité
        @david1711Hello David,

        Avant toute chose:

        As tu essayé de télécharger ce que je te demande et de passer le tout par clé USB , d'un pc à l'autre?
        0
      3. @Trying2non je n ai pas eu le tps de télécharger les logiciel demandes , mais j attend un amis qui va me prêter un ordinateur portable ... Peux tu stp me renvoyer les démarche à faire ... Sachant que je dois tt télécharger avant de transférer le tt sur mon pc malade , c bien sa ?
        0
      4. Contributeur sécurité
        @david1711Ok, commence par télécharger et installer Antivir après avoir viré Norton.
        Comme tu n'a pas d'accès au net, fais une mise à jour manuelle d'antivir de cette manière.

        En suite poste moi le rapport d 'Usbfix.

        Essaye d'utiliser firefox, pour surfer.

        Toute la suite se fera par étape: un rapport-->une consigne.

        Voilou @+
        0
      5. @Trying2étant donné que firefoxx ne marchait pas non plus , et que personne n a pu se libérer pour me préter un pc , jai fait une restauration de systeme d il y a a peu pret 5 jours !
        a ma grande suprise, internet fonctionne parfaitement , enfin je pense . que dois je maintenant faire ?
        si je savais comment (je ne connais pas le terme excat) reinitialiser mon pc de maniere a ce qu il soit pareil qu a sa sortie des cartons je le ferais sans hésiter!!!
        0
    5. Contributeur sécurité
      On recommence:

      - Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

      - Double-clique sur RSIT.exe afin de lancer le programme.

      - Clique sur Continue à l'écran Disclaimer.

      -Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

      - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches) dans deux messages différents.
      0
      1. Contributeur sécurité
        David,

        Si tu souhaites réellement réinitialiser ton pc, clique http://h10025.www1.hp.com/ewfrf/wc/fastFaqLiteDocument?lc=fr&dlc=fr&cc=fr&docname=c00846469&product=12455.

        Tiens moi au courant.@+
        0
        1. merci de tte ton aide , mais j ai fini par reinitialiser mon pc ! et d.ieu sait qu il va mieu !! lol
          j ai fait un copie de mes données sur un disc dur , mais peut etre yy a t il dans mes données le fameux virus qui ma tt explosé ? nan ...
          bref je vai suivre les indications afin de viré norton et mettre celui que tu m a dit a la place
          0
        2. Contributeur sécurité
          @david1711Hello,

          Ca fait plaisir d'avoir des nouvelles :)

          Effectivement avant de réinjecter tes données dans ton pc, ou même brancher ton DD externe, installe Antivir et scan ce DD externe.

          Si tu souhaites qu'on fasse ensuite un diagnostic ensemble, pour éventuellement nettoyer ou optimiser ta machine, tu sais où me trouver...
          0
        3. @Trying2j ai fait le scan du disc dur , et ooooo grande suprise jai trouvé quelque virus et chevaux de troye....suprimer par ton antivirus
          merci encore

          sinon que faire pour augmenter les performances de mon pc ?
          0
        4. Contributeur sécurité
          @david1711Hello,


          que faire pour augmenter les performances de mon pc ?


          Tu peux télécharger hijackthis et me poster un rapport dans ta prochaine réponse.
          Comment générer un rapport. (merci à Balltrap 34 pour la démo)
          Ne fixe aucune ligne pour l'instant.

          Ensuite je te guiderai pour faire quelques manips.
          0