Ecran bleu analyse avec whocrashed

Bonjour, j'ai fait une analyse avec whocrashed et voila ce que j'ai obtenu quelqu'un c'est se que je dois faire ?

Crash dump directory: C:\Windows\Minidump

Crash dumps are enabled on your computer.

On Thu 29/10/2009 14:41:50 your computer crashed
This was likely caused by the following module: nvlddmkm.sys
Bugcheck code: 0x116 (0x882A4008, 0x8E4BBEB0, 0x0, 0x2)
Error: VIDEO_TDR_ERROR
file path: C:\Windows\system32\drivers\nvlddmkm.sys
product: NVIDIA Windows Kernel Mode Driver, Version 190.62
company: NVIDIA Corporation
description: NVIDIA Windows Kernel Mode Driver, Version 190.62

On Thu 29/10/2009 14:40:26 your computer crashed
This was likely caused by the following module: nvlddmkm.sys
Bugcheck code: 0x1000008E (0xC0000005, 0x8EB6000F, 0x8B3556BC, 0x0)
Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M
file path: C:\Windows\system32\drivers\nvlddmkm.sys
product: NVIDIA Windows Kernel Mode Driver, Version 190.62
company: NVIDIA Corporation
description: NVIDIA Windows Kernel Mode Driver, Version 190.62

On Thu 29/10/2009 10:23:46 your computer crashed
This was likely caused by the following module: nvlddmkm.sys
Bugcheck code: 0x116 (0x87723008, 0x8EACB1A0, 0x0, 0x2)
Error: VIDEO_TDR_ERROR
file path: C:\Windows\system32\drivers\nvlddmkm.sys
product: NVIDIA Windows Kernel Mode Driver, Version 190.62
company: NVIDIA Corporation
description: NVIDIA Windows Kernel Mode Driver, Version 190.62

On Thu 29/10/2009 10:16:24 your computer crashed
This was likely caused by the following module: nvlddmkm.sys
Bugcheck code: 0x116 (0x875FC248, 0x8ECC91A0, 0x0, 0x2)
Error: VIDEO_TDR_ERROR
file path: C:\Windows\system32\drivers\nvlddmkm.sys
product: NVIDIA Windows Kernel Mode Driver, Version 190.62
company: NVIDIA Corporation
description: NVIDIA Windows Kernel Mode Driver, Version 190.62

--------------------------------------------------------------------------------
Conclusion
--------------------------------------------------------------------------------

4 crash dumps have been found and analyzed. Note that it's not always possible to state with certainty whether a reported driver is really responsible for crashing your system or that the root cause is in another module. Nonetheless it's suggested you look for updates for the products that these drivers belong to and regularly visit Windows update or enable automatic updates for Windows. In case a piece of malfunctioning hardware is causing trouble, a search with Google on the bug check errors together with the model name and brand of your computer may help you investigate this further.
Configuration: Windows Vista
Firefox 3.0.15

20 réponses

  1. bonjour le pc demarre t'il normalement ou il est impossible de faire qoique ce soit?
    0
    1. il démarre mais il y a l'écran bleu et après il redémarre et j'arrive a l'écran ou l'on doit choisir mode sans échec ,etc... .
      0
      1. oui j'y suis et je fais un memtest en ce moment
        0
        1. ok donc maintenant c'est l'heure de résoudre cela fais ceci:

          ▶ Télécharge Random's System Information Tool (RSIT).

          ▶ Un tutoriel sera à ta disposition pour l'installer et l'utiliser correctement.

          ▶ Double clique sur RSIT.exe pour lancer l'outil.

          ▶ Clique sur 'Continue' à l'écran Disclaimer.

          ▶ Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

          ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports.

          ( C:\RSIT\log.txt et C:\RSIT\info.txt )

          CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller

          Comment héberger les rapports trop longs de RSIT ??
          0
          1. c'est marquer listing event logs et sa ne bouge pas
            0
            1. info.txt logfile of random's system information tool 1.06 2009-10-29 16:49:24

              ======Uninstall list======

              -->MsiExec /X{74224F8D-4A17-4816-9EDB-7BB854DE532C}
              32 Bit HP CIO Components Installer-->MsiExec.exe /I{2614F54E-A828-49FA-93BA-45A3F756BFAA}
              Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
              Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
              ActiveCheck component for HP Active Support Library-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
              Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
              Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
              Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
              Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
              Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
              Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
              Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
              Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
              BumpTop-->MsiExec.exe /I{9FABFD28-000C-48AB-A0C7-82286B33EFA0}
              BumpTop-->MsiExec.exe /X{AC28B5E8-B5D6-4917-B686-DED2212926BB}
              Call of Duty(R) - World at War(TM)-->C:\Program Files\InstallShield Installation Information\{D80A6A73-E58A-4673-AFF5-F12D7110661F}\setup.exe -runfromtemp -l0x040c
              Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{3BD633E0-4BF8-4499-9149-88F0767D449C}\setup.exe -runfromtemp -l0x0409
              Call of Duty(R) 4 - Modern Warfare(TM)-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x040c
              Call of Juarez - Bound in Blood-->C:\Program Files\InstallShield Installation Information\{FEFAF112-4DA8-479C-89E2-7DE25091711A}\setup.exe -runfromtemp -l0x040c
              CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
              Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
              Combat Arms EU-->"C:\ProgramData\NexonEU\NGM\NGM.exe" -mode:uninstall -dll:ngm.nexoneu.com/cbangm/NGM/Bin/NGMDll.dll -game:50340359 -locale:EU
              Cossacks II-->C:\Users\ordi\kevin\Cossack II\GSC Game World\Cossacks II\uninstall.exe
              Counter-Strike: Source-->C:\Program Files\Counter-Strike Source\Uninst.exe
              Crysis(R)-->MsiExec.exe /I{000E79B7-E725-4F01-870A-C12942B7F8E4}
              EasyBits Magic Desktop-->C:\Windows\system32\ezMDUninstall.exe
              ESET Online Scanner v3-->C:\Program Files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
              Eufloria 2.00-->E:\eufloria\Eufloria\Uninstall.exe
              FallenEarth-->MsiExec.exe /X{82448C0D-FB2A-4E10-9F2C-F404F067A85B}
              Fallout 3 - The Garden of Eden Creation Kit-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B343B0E3-212A-40B9-8207-1BD299228F5D}\setup.exe" -l0x9 -removeonly
              Fallout 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{974C4B12-4D02-4879-85E0-61C95CC63E9E}\setup.exe" -l0x40c -removeonly
              Far Cry 2-->"C:\Program Files\InstallShield Installation Information\{F2835483-37F2-4123-B4FE-0E77D58447F2}\setup.exe" -runfromtemp -l0x040c -removeonly
              FEARCombat-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{75E607CF-7BAE-4B88-84B3-97F3DF44BA28}\setup.exe" -l0x9 /zU -removeonly
              FlatOut Ultimate Carnage-->E:\flatout 2\FlatOut Ultimate Carnage\Uninstall.exe
              Fraps-->"C:\Fraps\uninstall.exe"
              Free Download Manager 3.0-->"C:\Program Files\Free Download Manager\unins000.exe"
              Freelancer-->"C:\Program Files\Microsoft Games\Freelancer\UNINSTAL.EXE" /runtemp /addremove
              Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
              GameSpy Arcade-->C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG
              Glary Utilities 2.16.0.758-->"C:\Program Files\Glary Utilities\unins000.exe"
              Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
              Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
              Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
              Google Earth-->MsiExec.exe /X{3A05B900-A3E7-11DE-A9B7-005056806466}
              Hearts of Iron III-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D0106CC2-E34B-4FA3-B6B6-91F0ACEA2CC3}\setup.exe" -l0x9
              HijackThis 2.0.2-->"E:\hijackhis\HijackThis.exe" /uninstall
              Hitman Blood Money-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A804B134-F03D-4EFD-9BC0-DCD257AA1B22}\setup.exe" -l0xc0c -removeonly
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
              HP Active Support Library 32 bit components-->MsiExec.exe /I{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}
              HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{0A47BAFF-D4FF-4BD3-96CA-02A22EA62722}\setup.exe -runfromtemp -l0x0409
              HP Advisor-->MsiExec.exe /X{73A43E42-3658-4DD9-8551-FACDA3632538}
              HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}\setup.exe" -l0x9 -removeonly
              HP Customer Feedback-->MsiExec.exe /I{9DBA770F-BF73-4D39-B1DF-6035D95268FC}
              HP Customer Participation Program 9.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
              HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40F7AED3-0C7D-4582-99F6-484A515C73F2}\setup.exe" -l0x9 -removeonly
              HP Imaging Device Functions 9.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
              HP OCR Software 9.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
              HP On-Screen Cap/Num/Scroll Lock Indicator-->C:\Windows\system32\OsdRemove.exe
              HP Photosmart All-In-One Software 9.0-->C:\Program Files\HP\Digital Imaging\{D64BC2CF-0F12-47d7-B412-B4F3FD684253}\setup\hpzscr01.exe -datfile hposcr21.dat
              HP Photosmart Essential 2.01-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
              HP Picasso Media Center Add-In-->MsiExec.exe /I{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}
              HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
              HP Smart Web Printing-->MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7}
              HP Solution Center 9.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
              HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
              HPAsset component for HP Active Support Library-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
              HPSSupply-->MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
              Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
              Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
              Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216015FF}
              Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
              Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
              K-Lite Codec Pack 2.75 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
              Le Maître de l'Olympe - Zeus.-->C:\Windows\IsUn040c.exe -f"c:\users\ordi\kevin\Sierra\Le Maître de l' Olympe Zeus\Uninst.isu"
              Ma-Config.com-->MsiExec.exe /X{425FFD94-36BD-4933-881B-FE0B9DADF2B7}
              Medieval - Total War - Gold Edition-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A10F7877-4276-416C-9F22-CB56C0CB2700}\setup.exe" -l0x40c -removeonly
              Medieval II Total War Demo Gold-->C:\Program Files\InstallShield Installation Information\{4A665599-6771-4732-BE74-06B43B9F611B}\setup.exe -runfromtemp -l0x0009 -removeonly
              Medieval II Total War-->C:\Program Files\InstallShield Installation Information\{C0698BDA-0D29-40EE-8570-A31106DF9AB1}\Setup.exe -runfromtemp -l0x0009 -removeonly
              Mega Manager-->C:\Program Files\InstallShield Installation Information\{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}\setup.exe -runfromtemp -l0x0009 -removeonly
              Men of War (Retirer seulement)-->"C:\Program Files\505games\1C\Men of War\unins000.exe"
              Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
              Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
              Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
              Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
              Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}
              Microsoft Games for Windows - LIVE-->MsiExec.exe /X{F112F66E-25CA-42DD-983C-6118EB38F606}
              Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
              Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
              Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
              Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
              Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
              Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
              Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
              Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
              Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
              Microsoft Windows Media Video 9 VCM-->RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\wmv9vcm.inf, Uninstall
              Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
              Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
              Mount&Blade-->C:\Users\ordi\kevin\M&B 1.011 copie\Mount&Blade\uninstall.exe
              Mozilla Firefox (3.0.15)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
              MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
              MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
              MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
              muvee autoProducer 6.0-->C:\Program Files\InstallShield Installation Information\{14AF024E-2E3B-49D0-A175-D1C1A06B155A}\setup.exe -runfromtemp -l0x040c -removeonly
              Nation Red-->MsiExec.exe /I{43757761-174D-4835-AB38-0422F5F050C6}
              Need for Speed™ SHIFT-->MsiExec.exe /X{BBF0A67B-5DBA-452F-9D2E-6F168BC226E4}
              Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
              Neverwinter Nights 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F20C1251-1D0A-4944-B2AE-678581B33B19}\SETUP.exe" -l0x40c -removeonly
              NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
              NVIDIA PhysX v8.04.25-->MsiExec.exe /X{74224F8D-4A17-4816-9EDB-7BB854DE532C}
              NVIDIA PhysX-->MsiExec.exe /X{5DB65884-C963-4454-AABA-4CA3089281FA}
              NVIDIA Stereoscopic 3D Driver-->"C:\Program Files\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
              OpenAL-->"C:\Program Files\OpenAL\oalinst.exe" /U
              Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
              Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
              Outils de diagnostic du matériel-->C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
              Prototype(TM)-->C:\Program Files\InstallShield Installation Information\{9322A850-9091-4D0E-B252-3E82EDA3D94A}\setup.exe -runfromtemp -l0x040c
              PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
              Python 2.5-->MsiExec.exe /I{0A2C5854-557E-48C8-835A-3B9F074BDCAA}
              Python 2.6.1-->MsiExec.exe /I{9CC89170-000B-457D-91F1-53691F85B223}
              Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
              Red Faction Guerrilla-->"C:\Program Files\InstallShield Installation Information\{A357EF4C-2B6F-4980-ACA9-B1E42A74D7F3}\setup.exe" -runfromtemp -l0x040c -removeonly
              Red Faction Guerrilla-->MsiExec.exe /I{A357EF4C-2B6F-4980-ACA9-B1E42A74D7F3}
              Revo Uninstaller 1.83-->C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
              Roxio Activation Module-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
              Roxio Creator Audio-->MsiExec.exe /X{83FFCFC7-88C6-41c6-8752-958A45325C82}
              Roxio Creator Basic v9-->MsiExec.exe /X{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
              Roxio Creator Copy-->MsiExec.exe /X{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
              Roxio Creator Data-->MsiExec.exe /X{0D397393-9B50-4c52-84D5-77E344289F87}
              Roxio Creator EasyArchive-->MsiExec.exe /X{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}
              Roxio Creator Tools-->MsiExec.exe /X{0394CDC8-FABD-4ed8-B104-03393876DFDF}
              Roxio Express Labeler 3-->MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
              Roxio MyDVD Basic v9-->MsiExec.exe /X{938B1CD7-7C60-491E-AA90-1F1888168240}
              Saints Row 2-->"E:\steam\steam.exe" steam://uninstall/9480
              SAMSUNG Mobile Composite Device Software-->C:\Windows\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
              SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
              Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
              SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
              SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
              Samsung PC Studio 3 USB Driver Installer-->"C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -runfromtemp -l0x040c -removeonly
              Samsung PC Studio 3-->"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -runfromtemp -l0x040c -removeonly
              Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
              Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
              Sexy Beach 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{950174DD-FA73-448C-BDD3-A86B0F588EE8}\setup.exe" -l0x9 -removeonly
              Shareaza 2.4.0.0-->"C:\Program Files\Shareaza\Uninstall\unins000.exe"
              Software Informer 1.0 BETA-->"C:\Program Files\Software Informer\unins000.exe"
              Solution de clavier multimédia amélioré-->C:\HP\KBD\Install.exe /u
              Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
              Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
              System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
              TES Construction Set-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Bethesda Softworks\Morrowind\CSUninstall\Setup.exe" -l0x40c
              True Crime® New York City-->MsiExec.exe /I{C920EFB6-59DB-472D-B445-21821477AD17}
              Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
              Version de démonstration de Microsoft Office Home and Student 2007-->c:\hp\bin\MSOffice\uninst2.cmd
              Virtua Tennis 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9B63540D-D942-4C38-B42E-A48AE0145970}\setup.exe" -l0x40c -removeonly
              WhoCrashed 1.01-->"C:\Program Files\WhoCrashed\unins000.exe"
              Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
              Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
              Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
              Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
              Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
              Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
              Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
              Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
              Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
              Wings 3D 0.99.04a-->C:\Program Files\wings3d_0.99.04a\Uninstall.exe
              World of Battles-->"C:\Program Files\InstallShield Installation Information\{D7FD3F44-5AF4-441C-A476-1C514B69A20D}\setup.exe" -runfromtemp -l0x0009 -removeonly
              Xfire (remove only)-->"C:\Program Files\Xfire\uninst.exe"

              ======Security center information======

              AS: Windows Defender (disabled)

              ======System event log======

              Computer Name: PC-de-ordi
              Event Code: 7001
              Message: Le service Service Liste des réseaux dépend du service Connaissance des emplacements réseau qui n'a pas pu démarrer en raison de l'erreur :
              Le service n'a pas été démarré.
              Record Number: 330370
              Source Name: Service Control Manager
              Time Written: 20091029151532.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-ordi
              Event Code: 7001
              Message: Le service Service Liste des réseaux dépend du service Connaissance des emplacements réseau qui n'a pas pu démarrer en raison de l'erreur :
              Le service n'a pas été démarré.
              Record Number: 330371
              Source Name: Service Control Manager
              Time Written: 20091029151532.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-ordi
              Event Code: 7024
              Message: Le service Connaissance des emplacements réseau s'est arrêté avec l'erreur service particulière 3221226008 (0xC0000218).
              Record Number: 330373
              Source Name: Service Control Manager
              Time Written: 20091029151532.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-ordi
              Event Code: 7001
              Message: Le service Service Liste des réseaux dépend du service Connaissance des emplacements réseau qui n'a pas pu démarrer en raison de l'erreur :
              Opération réussie.
              Record Number: 330374
              Source Name: Service Control Manager
              Time Written: 20091029151532.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-ordi
              Event Code: 7024
              Message: Le service Connaissance des emplacements réseau s'est arrêté avec l'erreur service particulière 3221226008 (0xC0000218).
              Record Number: 330376
              Source Name: Service Control Manager
              Time Written: 20091029151532.000000-000
              Event Type: Erreur
              User:

              =====Application event log=====

              Computer Name: PC-de-ordi
              Event Code: 8193
              Message: Échec de la création d’un point de restauration sur le volume (Processus = C:\Windows\system32\msiexec.exe /V ; Description = Removed 32 Bit HP CIO Components Installer ; Hr = 0x8007043c).
              Record Number: 202615
              Source Name: System Restore
              Time Written: 20091029145240.000000-000
              Event Type: Erreur
              User:

              Computer Name: PC-de-ordi
              Event Code: 6000
              Message: L’abonné aux notifications Winlogon <GPClient> n’était pas disponible pour traiter un événement de notification.
              Record Number: 202620
              Source Name: Microsoft-Windows-Winlogon
              Time Written: 20091029151050.000000-000
              Event Type: Avertissement
              User:

              Computer Name: PC-de-ordi
              Event Code: 6000
              Message: L’abonné aux notifications Winlogon <GPClient> n’était pas disponible pour traiter un événement de notification.
              Record Number: 202623
              Source Name: Microsoft-Windows-Winlogon
              Time Written: 20091029151051.000000-000
              Event Type: Avertissement
              User:

              Computer Name: PC-de-ordi
              Event Code: 6000
              Message: L’abonné aux notifications Winlogon <GPClient> n’était pas disponible pour traiter un événement de notification.
              Record Number: 202627
              Source Name: Microsoft-Windows-Winlogon
              Time Written: 20091029151410.000000-000
              Event Type: Avertissement
              User:

              Computer Name: PC-de-ordi
              Event Code: 4609
              Message: Le système d'événements de COM+ a détecté un code de renvoi erroné lors de son traitement interne. Le HRESULT est 8007043c à partir de la ligne 45 de d:\vistasp1_gdr\com\complus\src\events\tier1\eventsystemobj.cpp. Contactez les services de support technique Microsoft pour signaler cette erreur.
              Record Number: 202630
              Source Name: Microsoft-Windows-EventSystem
              Time Written: 20091029151442.000000-000
              Event Type: Erreur
              User:

              =====Security event log=====

              Computer Name: PC-de-ordi
              Event Code: 4907
              Message: Les paramètres d’audit sur l’objet ont changé.

              Sujet :
              ID de sécurité : S-1-5-18
              Nom du compte : PC-DE-ORDI$
              Domaine du compte : WORKGROUP
              ID d’ouverture de session : 0x3e7

              Objet :
              Serveur de l’objet : Security
              Type d’objet : File
              Nom de l’objet : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallMembership.sql
              ID du handle : 0x14

              Informations sur le processus :
              ID du processus : 0x1690
              Nom du processus : C:\WINDOWS\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

              Paramètres d’audit :
              Descripteur de sécurité d’origine : S:AI
              Nouveau descripteur de sécurité :
              Record Number: 42729
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090802074230.915640-000
              Event Type: Succès de l'audit
              User:

              Computer Name: PC-de-ordi
              Event Code: 4907
              Message: Les paramètres d’audit sur l’objet ont changé.

              Sujet :
              ID de sécurité : S-1-5-18
              Nom du compte : PC-DE-ORDI$
              Domaine du compte : WORKGROUP
              ID d’ouverture de session : 0x3e7

              Objet :
              Serveur de l’objet : Security
              Type d’objet : File
              Nom de l’objet : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state_perf.h
              ID du handle : 0x14

              Informations sur le processus :
              ID du processus : 0x1690
              Nom du processus : C:\WINDOWS\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

              Paramètres d’audit :
              Descripteur de sécurité d’origine :
              Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
              Record Number: 42730
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090802074230.931240-000
              Event Type: Succès de l'audit
              User:

              Computer Name: PC-de-ordi
              Event Code: 4907
              Message: Les paramètres d’audit sur l’objet ont changé.

              Sujet :
              ID de sécurité : S-1-5-18
              Nom du compte : PC-DE-ORDI$
              Domaine du compte : WORKGROUP
              ID d’ouverture de session : 0x3e7

              Objet :
              Serveur de l’objet : Security
              Type d’objet : File
              Nom de l’objet : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
              ID du handle : 0x14

              Informations sur le processus :
              ID du processus : 0x1690
              Nom du processus : C:\WINDOWS\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

              Paramètres d’audit :
              Descripteur de sécurité d’origine :
              Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
              Record Number: 42731
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090802074230.978040-000
              Event Type: Succès de l'audit
              User:

              Computer Name: PC-de-ordi
              Event Code: 4907
              Message: Les paramètres d’audit sur l’objet ont changé.

              Sujet :
              ID de sécurité : S-1-5-18
              Nom du compte : PC-DE-ORDI$
              Domaine du compte : WORKGROUP
              ID d’ouverture de session : 0x3e7

              Objet :
              Serveur de l’objet : Security
              Type d’objet : File
              Nom de l’objet : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
              ID du handle : 0x14

              Informations sur le processus :
              ID du processus : 0x1690
              Nom du processus : C:\WINDOWS\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

              Paramètres d’audit :
              Descripteur de sécurité d’origine :
              Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
              Record Number: 42732
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090802074231.024840-000
              Event Type: Succès de l'audit
              User:

              Computer Name: PC-de-ordi
              Event Code: 4907
              Message: Les paramètres d’audit sur l’objet ont changé.

              Sujet :
              ID de sécurité : S-1-5-18
              Nom du compte : PC-DE-ORDI$
              Domaine du compte : WORKGROUP
              ID d’ouverture de session : 0x3e7

              Objet :
              Serveur de l’objet : Security
              Type d’objet : File
              Nom de l’objet : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe
              ID du handle : 0x14

              Informations sur le processus :
              ID du processus : 0x1690
              Nom du processus : C:\WINDOWS\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

              Paramètres d’audit :
              Descripteur de sécurité d’origine :
              Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
              Record Number: 42733
              Source Name: Microsoft-Windows-Security-Auditing
              Time Written: 20090802074231.071640-000
              Event Type: Succès de l'audit
              User:

              ======Environment variables======

              "ComSpec"=%SystemRoot%\system32\cmd.exe
              "FP_NO_HOST_CHECK"=NO
              "NUMBER_OF_PROCESSORS"=2
              "OnlineServices"=Services en ligne
              "OS"=Windows_NT
              "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\hp\bin\python;C:\Program Files\Common Files\Roxio Shared\DLLShared\;c:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\"C:\Python26"\C:\Program Files\Common Files\Autodesk Shared\;C:\Program Files\backburner 2\;C:Games;C:\Program Files\Samsung\Samsung PC Studio 3\
              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
              "PCBRAND"=Pavilion
              "PLATFORM"=HPD
              "PROCESSOR_ARCHITECTURE"=x86
              "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
              "PROCESSOR_LEVEL"=15
              "PROCESSOR_REVISION"=6b01
              "RoxioCentral"=c:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
              "TEMP"=%SystemRoot%\TEMP
              "TMP"=%SystemRoot%\TEMP
              "USERNAME"=SYSTEM
              "windir"=%SystemRoot%
              "SAFEBOOT_OPTION"=NETWORK

              -----------------EOF-----------------

              Logfile of random's system information tool 1.06 (written by random/random)
              Run by ordi at 2009-10-29 16:49:08
              Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
              System drive C: has 26 GB (6%) free of 470 GB
              Total RAM: 3070 MB (76% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 16:49:21, on 29/10/2009
              Platform: Windows Vista SP1 (WinNT 6.00.1905)
              MSIE: Internet Explorer v7.00 (7.00.6001.18319)
              Boot mode: Safe mode with network support

              Running processes:
              C:\Windows\Explorer.EXE
              C:\WINDOWS\System32\WerFault.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              E:\memtest\memtest.exe
              C:\Program Files\WhoCrashed\whocrashed.exe
              C:\Users\ordi\Desktop\RSIT.exe
              E:\hijackhis\ordi.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              R3 - Default URLSearchHook is missing
              F2 - REG:system.ini: UserInit=C:\Windows\system32\ezShellStart.exe
              O1 - Hosts: ::1 localhost
              O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
              O2 - BHO: (no name) - {7418E5F5-0E48-4144-8F92-5CA791C82396} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
              O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
              O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: (no name) - {DE713078-8012-4B75-92BA-398D4642A64B} - (no file)
              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
              O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
              O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
              O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
              O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
              O4 - HKLM\..\RunOnce: [NVStereoReg] "C:\Program Files\NVIDIA Corporation\3D Vision\nvstreg.exe" "C:\Program Files\NVIDIA Corporation\3D Vision\nvstdef.reg" "C:\Program Files\NVIDIA Corporation\3D Vision\oglstreg.reg"
              O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
              O4 - HKLM\..\RunOnce: [NvExportOEMDefaults] RUNDLL32.EXE C:\Windows\system32\NVCPL.DLL,ExportOEMDefaults
              O4 - HKLM\..\RunOnce: [NvRegisterMCTray] RUNDLL32.EXE C:\Windows\system32\NVMCTRAY.DLL,NvMCRegisterApp C:\Windows\system32\NvCpl.dll
              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
              O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
              O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
              O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
              O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
              O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
              O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
              O9 - Extra button: (no name) - {A573D71B-951B-4BAD-B8CC-708AE84769C9} - (no file)
              O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
              O13 - Gopher Prefix:
              O17 - HKLM\System\CCS\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: NameServer = 192.168.1.1
              O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
              O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\Windows\system32\ezNTSvc.exe
              O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
              O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
              O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
              O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
              O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
              O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
              O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
              O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
              0
              1. quand tu dit renomme RSIT c'est a dire ? renommer en quoi ?
                0
                1. renomme le en ce que tu veux parce que de nos jours les pirates connaisse les moyen de desinfection
                  0
                  1. j'ai redémarrer mon ordinateur et ça marche mais j'ai peur que sa recommence donc je vais suivre tes consigne quand même voila le rapport je n'est pas 2 rapport comme tout a l'heure !

                    Logfile of random's system information tool 1.06 (written by random/random)
                    Run by ordi at 2009-10-29 17:22:27
                    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                    System drive C: has 23 GB (5%) free of 470 GB
                    Total RAM: 3070 MB (67% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 17:22:38, on 29/10/2009
                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                    MSIE: Internet Explorer v7.00 (7.00.6001.18319)
                    Boot mode: Normal

                    Running processes:
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\Explorer.EXE
                    C:\Windows\system32\taskeng.exe
                    C:\Program Files\Windows Defender\MSASCui.exe
                    C:\hp\support\hpsysdrv.exe
                    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                    C:\WINDOWS\RtHDVCpl.exe
                    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                    C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\WINDOWS\System32\rundll32.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
                    C:\Program Files\DAEMON Tools Lite\daemon.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    C:\Windows\system32\schtasks.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                    C:\Windows\system32\conime.exe
                    C:\hp\kbd\kbd.exe
                    C:\Users\ordi\Desktop\antiV.exe
                    E:\hijackhis\ordi.exe
                    C:\Windows\system32\DllHost.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    R3 - Default URLSearchHook is missing
                    F2 - REG:system.ini: UserInit=C:\Windows\system32\ezShellStart.exe
                    O1 - Hosts: ::1 localhost
                    O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                    O2 - BHO: (no name) - {7418E5F5-0E48-4144-8F92-5CA791C82396} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
                    O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
                    O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O2 - BHO: (no name) - {DE713078-8012-4B75-92BA-398D4642A64B} - (no file)
                    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                    O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                    O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
                    O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
                    O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
                    O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
                    O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                    O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                    O9 - Extra button: (no name) - {A573D71B-951B-4BAD-B8CC-708AE84769C9} - (no file)
                    O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                    O13 - Gopher Prefix:
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: NameServer = 192.168.1.1
                    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                    O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\Windows\system32\ezNTSvc.exe
                    O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                    O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                    O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
                    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                    0
                    1. ▶ Rends-toi à cette adresse afin de télécharger UsbFix (créé par Chiquitine29 & C_XX) :

                      ▶ https://www.androidworld.fr/

                      ▶ Clique sur TÉLÉCHARGER et enregistre-le sur ton bureau.

                      ▶ tutoriel recherche

                      ▶ Double-clique sur UsbFix présent sur ton bureau, l'installation se fera automatiquement

                      ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                      ▶ Choisi l'option 1 (recherche)

                      ▶ Laisse travailler l'outil

                      ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra

                      * Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

                      * Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

                      * Note : "SniffC.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                      0
                      1. voila,

                        ############################## | UsbFix V6.046 |

                        User : ordi (Administrateurs) # PC-DE-ORDI
                        Update on 29/10/2009 by Chiquitine29, C_XX & Chimay8
                        Start at: 17:29:16 | 29/10/2009
                        Website : http://pagesperso-orange.fr/NosTools/index.html
                        Contact : FindyKill.Contact@gmail.com

                        AMD Athlon(tm) 64 X2 Dual Core Processor 4000+
                        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                        Internet Explorer 7.0.6001.18000
                        Windows Firewall Status : Enabled

                        C:\ -> Disque fixe local # 458,52 Go (22,26 Go free) [HP] # NTFS
                        D:\ -> Disque fixe local # 7,24 Go (965,39 Mo free) [FACTORY_IMAGE] # NTFS
                        E:\ -> Disque fixe local # 465,76 Go (284,48 Go free) [NEW_VOLUME] # NTFS
                        F:\ -> Disque CD-ROM
                        H:\ -> Disque amovible
                        I:\ -> Disque amovible
                        J:\ -> Disque amovible
                        K:\ -> Disque CD-ROM
                        L:\ -> Disque CD-ROM
                        M:\ -> Disque CD-ROM
                        N:\ -> Disque amovible

                        ############################## | Processus actifs |

                        C:\Windows\System32\smss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\nvvsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\nvvsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Program Files\Avira\AntiVir Desktop\sched.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Windows\system32\taskeng.exe
                        C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\hp\support\hpsysdrv.exe
                        C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                        C:\WINDOWS\RtHDVCpl.exe
                        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\WINDOWS\System32\rundll32.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
                        C:\Program Files\DAEMON Tools Lite\daemon.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        C:\Windows\system32\schtasks.exe
                        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                        C:\Windows\system32\ezNTSvc.exe
                        C:\Windows\system32\svchost.exe
                        c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\PnkBstrA.exe
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\WUDFHost.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\Program Files\Avira\AntiVir Desktop\update.exe
                        C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                        C:\Windows\system32\conime.exe
                        C:\hp\kbd\kbd.exe
                        c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                        C:\Windows\servicing\TrustedInstaller.exe
                        C:\Windows\system32\vssvc.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Windows\system32\wuauclt.exe

                        ################## | Fichiers # Dossiers infectieux |

                        C:\Windows\system32\autorun.inf

                        ################## | Registre # Clés Run infectieuses |

                        [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"

                        ################## | Registre # Mountpoints2 |

                        HKCU\..\..\Explorer\MountPoints2\{a07daef9-3706-11de-8c7e-001bb9bf6cf4}
                        shell\AutoRun\command =K:\autorun.exe

                        ################## | Suspect | https://www.virustotal.com/gui/ |

                        ################## | Cracks / Keygens / Serials |

                        "C:\Users\ordi\kevin\Cossack II\GSC Game World\Cossacks II\crack\C2_PATCH_V1_2.exe"
                        20/06/2006 13:52 |Size 39301963 |Crc32 4721e24f |Md5 8c58c37acb6f515a7378378f1649b019

                        "C:\Users\ordi\kevin\fallout3\CRACKfollout3\CRACK\FalloutLauncher.exe"
                        28/10/2008 16:35 |Size 18552088 |Crc32 5c0691f9 |Md5 9bde0f461f037126db1b820ced98a8f2

                        "E:\Medieval total war II\Crack\Medieval 2 Total War NOCD v1.0\medieval2.exe"
                        17/12/2008 15:56 |Size 43319336 |Crc32 88f1449f |Md5 9b0ba7313de43a94aac93ffbc2f0b12f

                        "E:\Men of war\Crack\mow.exe"
                        04/05/2009 23:00 |Size 20844544 |Crc32 1c42e483 |Md5 55dd718cb40995b7422441dbd5354259

                        "E:\Men of war\Crack\mow_editor.exe"
                        04/05/2009 23:00 |Size 20045824 |Crc32 1809e6b2 |Md5 229a0cc5c5f7cca654040efa1044e9d0

                        ################## | ! Fin du rapport # UsbFix V6.046 ! |
                        0
                        1. ▶ tutoriel nettoyage

                          ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

                          ▶ Double clic sur le raccourci UsbFix présent sur ton bureau

                          ▶ choisi l'option 2 ( Suppression )

                          ▶ Ton bureau disparaîtra et le pc redémarrera .

                          ▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

                          ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .

                          ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                          ▶ /!\ UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.androidworld.fr/

                          ▶ Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.

                          ▶ Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

                          ▶ Merci d'avance pour ta contribution !!
                          0
                          1. SmitFraudFix v2.424

                            Scan done at 17:41:51,71, 29/10/2009
                            Run from C:\Users\ordi\Desktop\SmitfraudFix
                            OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                            The filesystem type is NTFS
                            Fix run in normal mode

                            »»»»»»»»»»»»»»»»»»»»»»»» Process

                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\wininit.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\services.exe
                            C:\Windows\system32\lsass.exe
                            C:\Windows\system32\lsm.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\nvvsvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\winlogon.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\SLsvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\nvvsvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\spoolsv.exe
                            C:\Program Files\Avira\AntiVir Desktop\sched.exe
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\Explorer.EXE
                            C:\Windows\system32\taskeng.exe
                            C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\hp\support\hpsysdrv.exe
                            C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                            C:\WINDOWS\RtHDVCpl.exe
                            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                            C:\Program Files\Java\jre6\bin\jusched.exe
                            C:\WINDOWS\System32\rundll32.exe
                            C:\Program Files\Windows Sidebar\sidebar.exe
                            C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
                            C:\Program Files\DAEMON Tools Lite\daemon.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                            C:\Windows\system32\schtasks.exe
                            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                            C:\Windows\system32\ezNTSvc.exe
                            C:\Windows\system32\svchost.exe
                            c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\PnkBstrA.exe
                            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                            C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\WUDFHost.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\Program Files\Avira\AntiVir Desktop\update.exe
                            C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                            C:\Windows\system32\conime.exe
                            C:\hp\kbd\kbd.exe
                            c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                            C:\Windows\system32\wuauclt.exe
                            C:\Windows\system32\cmd.exe
                            C:\Windows\system32\notepad.exe
                            C:\Windows\explorer.exe
                            C:\Windows\system32\cmd.exe
                            C:\Windows\system32\wbem\wmiprvse.exe

                            »»»»»»»»»»»»»»»»»»»»»»»» hosts

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ordi

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ordi\AppData\Local\Temp

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ordi\Application Data

                            »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ordi\FAVORI~1

                            »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                            C:\Program Files\Google\googletoolbar1.dll FOUND !

                            »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                            »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                            »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                            !!!Attention, following keys are not inevitably infected!!!

                            o4Patch
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                            !!!Attention, following keys are not inevitably infected!!!

                            IEDFix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                            !!!Attention, following keys are not inevitably infected!!!

                            Agent.OMZ.Fix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                            !!!Attention, following keys are not inevitably infected!!!

                            VACFix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                            !!!Attention, following keys are not inevitably infected!!!

                            404Fix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                            !!!Attention, following keys are not inevitably infected!!!

                            SrchSTS.exe by S!Ri
                            Search SharedTaskScheduler's .dll

                            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                            !!!Attention, following keys are not inevitably infected!!!

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                            "AppInit_DLLs"=""
                            "LoadAppInit_DLLs"=dword:00000000

                            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                            !!!Attention, following keys are not inevitably infected!!!

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                            "Userinit"="C:\\Windows\\system32\\ezShellStart.exe"
                            "Windows Shell (ezShellStart)"="C:\\Windows\\system32\\userinit.exe,"

                            »»»»»»»»»»»»»»»»»»»»»»»» RK

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                            »»»»»»»»»»»»»»»»»»»»»»»» DNS

                            Description: NVIDIA nForce Networking Controller
                            DNS Server Search Order: 192.168.1.1

                            HKLM\SYSTEM\CCS\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CCS\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: NameServer=192.168.1.1
                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: NameServer=192.168.1.1
                            HKLM\SYSTEM\CS2\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS2\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: NameServer=192.168.1.1
                            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                            »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                            »»»»»»»»»»»»»»»»»»»»»»»» End
                            0
                            1. ceci est un rapport de smitfraudix et non de usbfix
                              fait l'option2 de usbfix
                              0
                              1. excuse moi j'avais mal lu le voila :

                                ############################## | UsbFix V6.046 |

                                User : ordi (Administrateurs) # PC-DE-ORDI
                                Update on 29/10/2009 by Chiquitine29, C_XX & Chimay8
                                Start at: 18:16:07 | 29/10/2009
                                Website : http://pagesperso-orange.fr/NosTools/index.html
                                Contact : FindyKill.Contact@gmail.com

                                AMD Athlon(tm) 64 X2 Dual Core Processor 4000+
                                Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                                Internet Explorer 7.0.6001.18000
                                Windows Firewall Status : Enabled

                                C:\ -> Disque fixe local # 458,52 Go (22,13 Go free) [HP] # NTFS
                                D:\ -> Disque fixe local # 7,24 Go (965,39 Mo free) [FACTORY_IMAGE] # NTFS
                                E:\ -> Disque fixe local # 465,76 Go (284,48 Go free) [NEW_VOLUME] # NTFS
                                F:\ -> Disque CD-ROM
                                H:\ -> Disque amovible
                                I:\ -> Disque amovible
                                J:\ -> Disque amovible
                                K:\ -> Disque CD-ROM
                                L:\ -> Disque CD-ROM
                                M:\ -> Disque CD-ROM
                                N:\ -> Disque amovible

                                ############################## | Processus actifs |

                                C:\Windows\System32\smss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\wininit.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\services.exe
                                C:\Windows\system32\lsass.exe
                                C:\Windows\system32\lsm.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\nvvsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\winlogon.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\SLsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\nvvsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\spoolsv.exe
                                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\Explorer.EXE
                                C:\Windows\system32\taskeng.exe
                                C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
                                C:\Program Files\Windows Defender\MSASCui.exe
                                C:\hp\support\hpsysdrv.exe
                                C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                                C:\WINDOWS\RtHDVCpl.exe
                                C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                C:\Program Files\Java\jre6\bin\jusched.exe
                                C:\WINDOWS\System32\rundll32.exe
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
                                C:\Program Files\DAEMON Tools Lite\daemon.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                C:\Windows\system32\schtasks.exe
                                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                C:\Windows\system32\ezNTSvc.exe
                                C:\Windows\system32\svchost.exe
                                c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\PnkBstrA.exe
                                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\WUDFHost.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Program Files\Avira\AntiVir Desktop\update.exe
                                C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                                C:\Windows\system32\conime.exe
                                C:\hp\kbd\kbd.exe
                                c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                C:\Windows\system32\wuauclt.exe
                                C:\Windows\system32\wbem\wmiprvse.exe

                                ################## | Fichiers # Dossiers infectieux |

                                C:\Windows\system32\autorun.inf

                                ################## | Registre # Clés Run infectieuses |

                                ################## | Registre # Mountpoints2 |

                                HKCU\..\..\Explorer\MountPoints2\{a07daef9-3706-11de-8c7e-001bb9bf6cf4}
                                shell\AutoRun\command =K:\autorun.exe

                                ################## | Suspect | https://www.virustotal.com/gui/ |

                                ################## | Cracks / Keygens / Serials |

                                "C:\Users\ordi\kevin\Cossack II\GSC Game World\Cossacks II\crack\C2_PATCH_V1_2.exe"
                                20/06/2006 13:52 |Size 39301963 |Crc32 4721e24f |Md5 8c58c37acb6f515a7378378f1649b019

                                "C:\Users\ordi\kevin\fallout3\CRACKfollout3\CRACK\FalloutLauncher.exe"
                                28/10/2008 16:35 |Size 18552088 |Crc32 5c0691f9 |Md5 9bde0f461f037126db1b820ced98a8f2

                                "E:\Medieval total war II\Crack\Medieval 2 Total War NOCD v1.0\medieval2.exe"
                                17/12/2008 15:56 |Size 43319336 |Crc32 88f1449f |Md5 9b0ba7313de43a94aac93ffbc2f0b12f

                                "E:\Men of war\Crack\mow.exe"
                                04/05/2009 23:00 |Size 20844544 |Crc32 1c42e483 |Md5 55dd718cb40995b7422441dbd5354259

                                "E:\Men of war\Crack\mow_editor.exe"
                                04/05/2009 23:00 |Size 20045824 |Crc32 1809e6b2 |Md5 229a0cc5c5f7cca654040efa1044e9d0

                                ################## | ! Fin du rapport # UsbFix V6.046 ! |
                                0
                                1. ceciest l'option1 fait la 2 comme ceci:
                                  Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

                                  ▶ Double clic sur le raccourci UsbFix présent sur ton bureau

                                  ▶ choisi l'option 2 ( Suppression )

                                  ▶ Ton bureau disparaîtra et le pc redémarrera .

                                  ▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

                                  ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .

                                  ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                                  ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                  ▶ /!\ UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.androidworld.fr/

                                  ▶ Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.

                                  ▶ Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

                                  ▶ Merci d'avance pour ta contribution !!
                                  0