Portable hp infecté Help - Page 2

  1. Comme le portable ne démarre plus en mode normal, je repasse Antivir en mode sans echec et en ayant restauré tous les fichiers et en ayant changé le la config de l'antivirus.
    3.3%, il aurait dé"jà trouvé un Adware/adware.gen et un avertissement.
    A 11.8%, il bloque sur le même fichier HPBC.EXE. Ce qui est etonnant, c'est que ce n'est pas seulement le scan qui s'arrête mais tout le systeme qui se plante....
    Je vais arrêté le scan et refaire un ZHPDIAG en mode sans Echec + un Rsit. On verra bien.
    A mon avis, il a des fichiers endommagés pour réagir comme ça, et surtout pour planter maintenant en mode normal.
    Je vois pas d'autres solutions que d'utiliser la console de récup HP.
    0
    1. Voilou une floppée de rapports :

      Avira AntiVir Personal
      Date de création du fichier de rapport : lundi 21 décembre 2009 11:34

      La recherche porte sur 1265407 souches de virus.

      Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
      Numéro de série : 0000149996-ADJIE-0000001
      Plateforme : Windows Vista
      Version de Windows : (Service Pack 2) [6.0.6002]
      Mode Boot : Mode sans échec avec assistance réseau
      Identifiant : sandrine
      Nom de l'ordinateur : PC-DE-SANDRINE

      Informations de version :
      BUILD.DAT : 9.0.0.74 21698 Bytes 04/12/2009 13:56:00
      AVSCAN.EXE : 9.0.3.10 466689 Bytes 13/10/2009 10:25:46
      AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 09:21:02
      LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:11
      LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 09:21:31
      VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 06:35:52
      VBASE001.VDF : 7.10.0.1 2048 Bytes 06/11/2009 06:35:56
      VBASE002.VDF : 7.10.0.2 2048 Bytes 06/11/2009 06:35:58
      VBASE003.VDF : 7.10.0.3 2048 Bytes 06/11/2009 06:36:02
      VBASE004.VDF : 7.10.0.4 2048 Bytes 06/11/2009 06:36:04
      VBASE005.VDF : 7.10.0.5 2048 Bytes 06/11/2009 06:36:08
      VBASE006.VDF : 7.10.0.6 2048 Bytes 06/11/2009 06:36:12
      VBASE007.VDF : 7.10.0.7 2048 Bytes 06/11/2009 06:36:16
      VBASE008.VDF : 7.10.0.8 2048 Bytes 06/11/2009 06:36:18
      VBASE009.VDF : 7.10.0.9 2048 Bytes 06/11/2009 06:36:22
      VBASE010.VDF : 7.10.0.10 2048 Bytes 06/11/2009 06:36:30
      VBASE011.VDF : 7.10.0.11 2048 Bytes 06/11/2009 06:36:34
      VBASE012.VDF : 7.10.0.12 2048 Bytes 06/11/2009 06:36:38
      VBASE013.VDF : 7.10.0.13 2048 Bytes 06/11/2009 06:36:40
      VBASE014.VDF : 7.10.0.14 2048 Bytes 06/11/2009 06:36:44
      VBASE015.VDF : 7.10.0.15 2048 Bytes 06/11/2009 06:36:46
      VBASE016.VDF : 7.10.0.16 2048 Bytes 06/11/2009 06:36:48
      VBASE017.VDF : 7.10.0.17 2048 Bytes 06/11/2009 06:36:50
      VBASE018.VDF : 7.10.0.18 2048 Bytes 06/11/2009 06:36:54
      VBASE019.VDF : 7.10.0.19 2048 Bytes 06/11/2009 06:36:56
      VBASE020.VDF : 7.10.0.20 2048 Bytes 06/11/2009 06:36:58
      VBASE021.VDF : 7.10.0.21 2048 Bytes 06/11/2009 06:37:00
      VBASE022.VDF : 7.10.0.22 2048 Bytes 06/11/2009 06:37:04
      VBASE023.VDF : 7.10.0.23 2048 Bytes 06/11/2009 06:37:06
      VBASE024.VDF : 7.10.0.24 2048 Bytes 06/11/2009 06:37:10
      VBASE025.VDF : 7.10.0.25 2048 Bytes 06/11/2009 06:37:12
      VBASE026.VDF : 7.10.0.26 2048 Bytes 06/11/2009 06:37:14
      VBASE027.VDF : 7.10.0.27 2048 Bytes 06/11/2009 06:37:16
      VBASE028.VDF : 7.10.0.28 2048 Bytes 06/11/2009 06:37:18
      VBASE029.VDF : 7.10.0.29 2048 Bytes 06/11/2009 06:37:20
      VBASE030.VDF : 7.10.0.30 2048 Bytes 06/11/2009 06:37:22
      VBASE031.VDF : 7.10.0.33 2048 Bytes 06/11/2009 06:37:24
      Version du moteur : 8.2.1.59
      AEVDF.DLL : 8.1.1.2 106867 Bytes 08/11/2009 06:38:52
      AESCRIPT.DLL : 8.1.2.43 528764 Bytes 08/11/2009 06:38:48
      AESCN.DLL : 8.1.2.5 127346 Bytes 08/11/2009 06:38:46
      AESBX.DLL : 8.1.1.1 246132 Bytes 08/11/2009 06:38:44
      AERDL.DLL : 8.1.3.2 479604 Bytes 08/11/2009 06:38:42
      AEPACK.DLL : 8.2.0.3 422261 Bytes 08/11/2009 06:38:40
      AEOFFICE.DLL : 8.1.0.38 196987 Bytes 08/11/2009 06:38:38
      AEHEUR.DLL : 8.1.0.178 2093431 Bytes 08/11/2009 06:38:34
      AEHELP.DLL : 8.1.7.0 237940 Bytes 08/11/2009 06:38:30
      AEGEN.DLL : 8.1.1.71 364916 Bytes 08/11/2009 06:38:28
      AEEMU.DLL : 8.1.1.0 393587 Bytes 08/11/2009 06:38:26
      AECORE.DLL : 8.1.8.2 184694 Bytes 08/11/2009 06:38:24
      AEBB.DLL : 8.1.0.3 53618 Bytes 08/11/2009 06:38:20
      AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:30
      AVPREF.DLL : 9.0.3.0 44289 Bytes 26/08/2009 14:13:31
      AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
      AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 14:24:42
      AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:22
      AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:36:37
      SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
      SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:20:57
      NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 14:40:59
      RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 17/06/2009 12:44:26
      RCTEXT.DLL : 9.0.73.0 88321 Bytes 02/11/2009 15:58:32

      Configuration pour la recherche actuelle :
      Nom de la tâche...............................: ShlExt
      Fichier de configuration......................: C:\Users\sandrine\AppData\Local\Temp\3ecac802.avp
      Documentation.................................: bas
      Action principale.............................: interactif
      Action secondaire.............................: ignorer
      Recherche sur les secteurs d'amorçage maître..: marche
      Recherche sur les secteurs d'amorçage.........: marche
      Secteurs d'amorçage...........................: C:,
      Recherche dans les programmes actifs..........: arrêt
      Recherche en cours sur l'enregistrement.......: arrêt
      Recherche de Rootkits.........................: arrêt
      Contrôle d'intégrité de fichiers système......: arrêt
      Fichier mode de recherche.....................: Tous les fichiers
      Recherche sur les archives....................: marche
      Limiter la profondeur de récursivité..........: arrêt
      Archive Smart Extensions......................: arrêt
      Types d'archives divergents...................: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox,
      Heuristique de macrovirus.....................: marche
      Heuristique fichier...........................: moyen
      Catégories de dangers divergentes.............: +GAME,+JOKE,+PCK,+PFS,+SPR,

      Début de la recherche : lundi 21 décembre 2009 11:34

      La recherche sur les fichiers sélectionnés commence :

      Recherche débutant dans 'C:\Users\sandrine\Documents\LimeWire\Incomplete'
      C:\Users\sandrine\Documents\LimeWire\Incomplete\T-5122201-embargo.snd
      [RESULTAT] Contient le modèle de détection de l'exploit EXP/ASF.GetCodec.Gen

      Début de la désinfection :
      C:\Users\sandrine\Documents\LimeWire\Incomplete\T-5122201-embargo.snd
      [RESULTAT] Contient le modèle de détection de l'exploit EXP/ASF.GetCodec.Gen
      [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b644f6c.qua' !

      Fin de la recherche : lundi 21 décembre 2009 11:34
      Temps nécessaire: 00:00 Minute(s)

      La recherche a été effectuée intégralement

      1 Les répertoires ont été contrôlés
      16 Des fichiers ont été contrôlés
      1 Des virus ou programmes indésirables ont été trouvés
      0 Des fichiers ont été classés comme suspects
      0 Des fichiers ont été supprimés
      0 Des virus ou programmes indésirables ont été réparés
      1 Les fichiers ont été déplacés dans la quarantaine
      0 Les fichiers ont été renommés
      0 Impossible de contrôler des fichiers
      15 Fichiers non infectés
      0 Les archives ont été contrôlées
      0 Avertissements
      1 Consignes
      0
      1. Rapport de ZHPDiag v1.24.39 par Nicolas Coolman
        Run by sandrine at 21/12/2009 11:52:39
        Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
        Platform : Windows Vista (TM) Home Premium (6.0.6002) Service Pack 2
        MSIE: Internet Explorer v8.0.6001.18865

        Boot mode:
        Total RAM: 2045 MB (77% free)
        System drive C: has 85 GB (38%) free of 221 GB

        ---\\ Processus lancés
        [MD5.FBC211A75FE4C2DEAA10B130728D376D] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
        [MD5.CF41C54529021D0E393BD149FEE4F03E] - C:\Program Files\HP\QuickPlay\QPService.exe
        [MD5.AEF50C71530B415AFA40E1D478BEFCCC] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
        [MD5.2CF59B201A59D0FF5534089F76297559] - C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
        [MD5.523D786AB9BFC3C228B8C851D402F502] - c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
        [MD5.CB4EE42EE2D33A58EFD48C276B683663] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
        [MD5.B8AF02700299CD308046BB9339165813] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
        [MD5.B98FFA8288EFAABC436C30D198608345] - C:\Program Files\Java\jre6\bin\jusched.exe
        [MD5.21293443961A4E2597453EE7A9347F22] - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        [MD5.29680A793F690EEF4AAA68479D2A6DF8] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        [MD5.9E35FF7F943AE0FB89192BFE058B7FD4] - C:\Program Files\Windows Sidebar\Sidebar.exe
        [MD5.3794B461C45882E06856F282EEF025AF] - C:\Windows\system32\svchost.exe
        [MD5.9015BC03F62940527EC92D45EE89E46F] - C:\Program Files\Avira\AntiVir Desktop\sched.exe
        [MD5.B8720A787C1223492E6F319465E996CE] - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        [MD5.89F9E1984C1CD9E5F4FE39642D886E11] - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
        [MD5.04C1DCBB226C6AE647B794833CE3CEB6] - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
        [MD5.68431DB6633ED4C9D18226384498310A] - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
        [MD5.2F237AAB91497AAA03AF48EAE68758FC] - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        [MD5.7B525BC857F88B5068A51B5B4D225A95] - C:\Windows\system32\nvvsvc.exe
        [MD5.599FF0B96561CA4F0899FE7F1C4CCE9A] - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
        [MD5.8FF5CAD74C3C5E692E1610E861609A3B] - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
        [MD5.17E0BEF5CA5C9CE52CC8082AC6EBC449] - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        [MD5.3978F3540329E16C0AC3BCF677E5669F] - C:\Windows\system32\lsass.exe
        [MD5.A275FBB7C99458C12E088DFF3E58EB4D] - C:\Windows\System32\tcpsvcs.exe
        [MD5.862BB4CBC05D80C5B45BE430E5EF872F] - C:\Windows\system32\SLsvc.exe
        [MD5.524BFBEA40E6E404737CCBC754647A2E] - C:\Windows\System32\spoolsv.exe
        [MD5.41335396339DD3C1B74527B187F6AE79] - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
        [MD5.AED0DFF80C6B3914769407E78D7AB21A] - C:\Windows\system32\SearchIndexer.exe

        ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
        F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
        F2 - REG:system.ini: Shell=explorer.exe

        ---\\ Pages de démarrage d'Internet Explorer (R0)
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr

        ---\\ Pages de recherche d'Internet Explorer (R1)
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

        ---\\ Internet Explorer URLSearchHook (R3)
        R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\system32\ieframe.dll

        ---\\ Browser Helper Objects de navigateur (O2)
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

        ---\\ Internet Explorer Toolbars (O3)
        O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -

        ---\\ Applications démarrées automatiquement par le registre (O4)
        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
        O4 - HKLM\..\Run: [QPService] C:\Program Files\HP\QuickPlay\QPService.exe
        O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
        O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
        O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
        O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
        O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
        O4 - HKLM\..\policies\Explorer: [BindDirectlyToPropertySetStorage] Data=0
        O4 - HKLM\..\policies\Explorer: [NoDriveAutoRun] Data=128
        O4 - HKLM\..\policies\Explorer: [NoDriveTypeAutoRun] Data=128
        O4 - HKLM\..\policies\Explorer: [HonorAutoRunSetting] Data=0
        O4 - HKCU\..\policies\Explorer: [NoDriveAutoRun] Data=128
        O4 - HKCU\..\policies\Explorer: [NoDriveTypeAutoRun] Data=128
        O4 - HKCU\..\policies\Explorer: [HonorAutoRunSetting] Data=0
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
        O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter

        ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
        O9 - Extra button: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll,103
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFBARH.ICO

        ---\\ Winsock hijacker (Layered Service Provider) (O10)
        O10 - WLSP:\000000000001\Winsock LSP File - C:\Windows\system32\NLAapi.dll
        O10 - WLSP:\000000000002\Winsock LSP File - C:\Windows\system32\napinsp.dll
        O10 - WLSP:\000000000003\Winsock LSP File - C:\Windows\system32\pnrpnsp.dll
        O10 - WLSP:\000000000004\Winsock LSP File - C:\Windows\system32\pnrpnsp.dll
        O10 - WLSP:\000000000005\Winsock LSP File - C:\Windows\system32\mswsock.dll
        O10 - WLSP:\000000000006\Winsock LSP File - C:\Windows\system32\winrnr.dll

        ---\\ Protocole additionnel et piratage de protocole (O18)
        O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\system32\urlmon.dll
        O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\msvidctl.dll
        O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\system32\inetcomm.dll
        O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
        O18 - Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
        O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\msvidctl.dll
        O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

        ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSODL) (O21)
        O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll

        ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
        O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll

        ---\\ Liste des services NT non Microsoft et non désactivés (O23)
        O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - C:\Program Files\Avira\AntiVir Desktop\sched.exe
        O23 - Service: Avira AntiVir Guard (AntiVirService) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        O23 - Service: HP Health Check Service (HP Health Check Service) - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
        O23 - Service: hpqwmiex (hpqwmiex) - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
        O23 - Service: LiveUpdate Notice (LiveUpdate Notice) - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
        O23 - Service: NVIDIA Display Driver Service (nvsvc) - C:\Windows\system32\nvvsvc.exe
        O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
        O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        O23 - Service: @%SystemRoot%\system32\simptcp.dll,-200 (simptcp) - C:\Windows\System32\tcpsvcs.exe
        O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - C:\Windows\system32\SLsvc.exe
        O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - C:\Windows\System32\spoolsv.exe
        O23 - Service: Vodafone Mobile Connect Service (VMCService) - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
        O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - C:\Windows\system32\SearchIndexer.exe /Embedding
        O23 - Service: {22D78859-9CE9-4B77-BF18-AC83E81A9263} ({22D78859-9CE9-4B77-BF18-AC83E81A9263}) - C:\WindowsC:\Program Files\HP\QuickPlay\000.fcl

        ---\\ Tâches planifiées en automatique (O39)
        O39 - APT:Automatic Planified Task - C:\Windows\Tasks\User_Feed_Synchronization-{29E851C7-A003-4FD2-A142-4083CFA9441E}.job

        ---\\ Composants installés (ActiveSetup Installed Components) (O40)
        O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
        O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
        O40 - ASIC: Browser Customizations - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
        O40 - ASIC: Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - (not file)
        O40 - ASIC: Macromedia Shockwave Director 10.1 - {166B1BCA-3F9C-11CF-8075-444553540000} - (not file)
        O40 - ASIC: Microsoft Windows Media Player 11.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\System32\wmpdxm.dll
        O40 - ASIC: Macromedia Shockwave Director 10.1 - {2A202491-F00D-11cf-87CC-0020AFEECF20} - (not file)
        O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - C:\Windows\system32\regsvr32.exe /s /n /i:/UserInstall C:\Windows\system32\themeui.dll
        O40 - ASIC: Offline Browsing Pack - {3af36230-a269-11d1-b5bf-0000f8051515} - (not file)
        O40 - ASIC: Microsoft Windows Mail 7 - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
        O40 - ASIC: DirectDrawEx - {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - (not file)
        O40 - ASIC: Internet Explorer Help - {45ea75a0-a269-11d1-b5bf-0000f8051515} - (not file)
        O40 - ASIC: Microsoft Windows Script 5.7 - {4f645220-306d-11d2-995d-00c04f98bbc9} - (not file)
        O40 - ASIC: Internet Explorer Setup Tools - {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - (not file)
        O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} - (not file)
        O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} - C:\Windows\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
        O40 - ASIC: MSN Site Access - {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - (not file)
        O40 - ASIC: Address Book 7 - {7790769C-0471-11d2-AF11-00C04FA35D02} - (not file)
        O40 - ASIC: .NET Framework - {7C028AF8-F614-47B3-82DA-BA94E41B1089} - (not file)
        O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
        O40 - ASIC: Internet Explorer - {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
        O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
        O40 - ASIC: Dynamic HTML Data Binding - {9381D8F2-0288-11D0-9501-00AA00B911A5} - (not file)
        O40 - ASIC: .NET Framework - {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - (not file)
        O40 - ASIC: Internet Explorer Core Fonts - {C9E9A340-D1F1-11D0-821E-444553540600} - (not file)
        O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} - C:\Windows\system32\Macromed\Flash\Flash10b.ocx
        O40 - ASIC: HTML Help - {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - (not file)
        O40 - ASIC: Active Directory Service Interface - {E92B03AB-B707-11d2-9CBD-0000F87A369E} - (not file)

        ---\\ Pilotes lancés au démarrage (O41)
        O41 - Driver: Ancilliary Function Driver for Winsock (AFD) - C:\Windows\system32\drivers\afd.sys
        O41 - Driver: avgio (avgio) - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
        O41 - Driver: avipbb (avipbb) - C:\WINDOWS\system32\DRIVERS\avipbb.sys
        O41 - Driver: Pilote de CD-ROM (cdrom) - C:\WINDOWS\system32\DRIVERS\cdrom.sys
        O41 - Driver: @%systemroot%\system32\drivers\dfsc.sys,-101 (DfsC) - C:\WINDOWS\System32\Drivers\dfsc.sys
        O41 - Driver: Symantec Eraser Control driver (eeCtrl) - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
        O41 - Driver: Pilote pour clavier i8042 et souris sur port PS/2 (i8042prt) - C:\WINDOWS\system32\DRIVERS\i8042prt.sys
        O41 - Driver: Symantec Intrusion Prevention Driver (IDSvix86) - C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20081104.005\IDSvix86.sys
        O41 - Driver: Pilote de la classe Clavier (kbdclass) - C:\WINDOWS\system32\DRIVERS\kbdclass.sys
        O41 - Driver: Pilote HID de clavier (kbdhid) - C:\WINDOWS\system32\DRIVERS\kbdhid.sys
        O41 - Driver: Pilote de la classe Souris (mouclass) - C:\WINDOWS\system32\DRIVERS\mouclass.sys
        O41 - Driver: NetBIOS Interface (NetBIOS) - C:\WINDOWS\system32\DRIVERS\netbios.sys
        O41 - Driver: NETBT (netbt) - C:\WINDOWS\System32\DRIVERS\netbt.sys
        O41 - Driver: NSI proxy service (nsiproxy) - C:\WINDOWS\system32\drivers\nsiproxy.sys
        O41 - Driver: @%SystemRoot%\System32\drivers\pacer.sys,-101 (PSched) - C:\WINDOWS\system32\DRIVERS\pacer.sys
        O41 - Driver: Remote Access Auto Connection Driver (RasAcd) - C:\WINDOWS\System32\DRIVERS\rasacd.sys
        O41 - Driver: Redirected Buffering Sub Sysytem (rdbss) - C:\WINDOWS\system32\DRIVERS\rdbss.sys
        O41 - Driver: RDPCDD (RDPCDD) - C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
        O41 - Driver: RDP Encoder Mirror Driver (RDPENCDD) - C:\WINDOWS\system32\drivers\rdpencdd.sys
        O41 - Driver: @%SystemRoot%\system32\tcpipcfg.dll,-50005 (Smb) - C:\WINDOWS\system32\DRIVERS\smb.sys
        O41 - Driver: ssmdrv (ssmdrv) - C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
        O41 - Driver: @%SystemRoot%\system32\tcpipcfg.dll,-50004 (tdx) - C:\WINDOWS\system32\DRIVERS\tdx.sys
        O41 - Driver: Pilote de périphérique terminal (TermDD) - C:\WINDOWS\system32\DRIVERS\termdd.sys
        O41 - Driver: (no object) (VgaSave) - C:\Windows\System32\drivers\vga.sys
        O41 - Driver: Remote Access IPv6 ARP Driver (Wanarpv6) - C:\WINDOWS\system32\DRIVERS\wanarp.sys

        ---\\ Logiciels installés (O42)
        O42 - Logiciel: Activation Assistant for the 2007 Microsoft Office suites
        O42 - Logiciel: Adobe Flash Player 10 ActiveX
        O42 - Logiciel: Adobe Flash Player 10 Plugin
        O42 - Logiciel: Adobe Reader 8.1.0 - Français
        O42 - Logiciel: Adobe Shockwave Player
        O42 - Logiciel: AppCore
        O42 - Logiciel: Avira AntiVir Personal - Free Antivirus
        O42 - Logiciel: CCleaner
        O42 - Logiciel: Card Detector for Option Icon 225
        O42 - Logiciel: Combined Community Codec Pack BETA 2008-12-29 01:28
        O42 - Logiciel: Component Framework
        O42 - Logiciel: CyberLink YouCam
        O42 - Logiciel: DVD Suite
        O42 - Logiciel: DivX Codec
        O42 - Logiciel: DivX Converter
        O42 - Logiciel: DivX Player
        O42 - Logiciel: DivX Web Player
        O42 - Logiciel: EA Link
        O42 - Logiciel: ESU for Microsoft Vista
        O42 - Logiciel: Google Toolbar for Internet Explorer
        O42 - Logiciel: HP Active Support Library
        O42 - Logiciel: HP Customer Experience Enhancements
        O42 - Logiciel: HP Doc Viewer
        O42 - Logiciel: HP Easy Setup - Frontend
        O42 - Logiciel: HP Help and Support
        O42 - Logiciel: HP Quick Launch Buttons 6.30 E1
        O42 - Logiciel: HP QuickPlay 3.6
        O42 - Logiciel: HP QuickTouch 1.00 C4
        O42 - Logiciel: HP Total Care Advisor
        O42 - Logiciel: HP Update
        O42 - Logiciel: HP User Guides 0088
        O42 - Logiciel: HP Wireless Assistant
        O42 - Logiciel: HPNetworkAssistant
        O42 - Logiciel: Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
        O42 - Logiciel: Hewlett-Packard Active Check for Health Check
        O42 - Logiciel: Hewlett-Packard Asset Agent for Health Check
        O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
        O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
        O42 - Logiciel: Intel® Matrix Storage Manager
        O42 - Logiciel: Java(TM) 6 Update 11
        O42 - Logiciel: Java(TM) 6 Update 2
        O42 - Logiciel: Java(TM) 6 Update 7
        O42 - Logiciel: LabelPrint
        O42 - Logiciel: Les Sims™ Histoires de vie
        O42 - Logiciel: MSCU for Microsoft Vista
        O42 - Logiciel: MSXML 4.0 SP2 (KB936181)
        O42 - Logiciel: MSXML 4.0 SP2 (KB941833)
        O42 - Logiciel: MSXML 4.0 SP2 (KB954430)
        O42 - Logiciel: MSXML 4.0 SP2 (KB973688)
        O42 - Logiciel: Malwarebytes' Anti-Malware
        O42 - Logiciel: Microsoft .NET Framework 3.5 Language Pack SP1 - fra
        O42 - Logiciel: Microsoft .NET Framework 3.5 SP1
        O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2)
        O42 - Logiciel: Microsoft Office Excel MUI (French) 2007
        O42 - Logiciel: Microsoft Office Home and Student 2007
        O42 - Logiciel: Microsoft Office OneNote MUI (French) 2007
        O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007
        O42 - Logiciel: Microsoft Office PowerPoint Viewer 2007 (French)
        O42 - Logiciel: Microsoft Office Proof (Arabic) 2007
        O42 - Logiciel: Microsoft Office Proof (Dutch) 2007
        O42 - Logiciel: Microsoft Office Proof (English) 2007
        O42 - Logiciel: Microsoft Office Proof (French) 2007
        O42 - Logiciel: Microsoft Office Proof (German) 2007
        O42 - Logiciel: Microsoft Office Proof (Spanish) 2007
        O42 - Logiciel: Microsoft Office Proofing (French) 2007
        O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
        O42 - Logiciel: Microsoft Office Shared MUI (French) 2007
        O42 - Logiciel: Microsoft Office Word MUI (French) 2007
        O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
        O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable
        O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
        O42 - Logiciel: Microsoft Works
        O42 - Logiciel: Module de compatibilité pour Microsoft Office System 2007
        O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra
        O42 - Logiciel: Motorola SM56 Data Fax Modem
        O42 - Logiciel: My HP Games
        O42 - Logiciel: NVIDIA Drivers
        O42 - Logiciel: Norton Internet Security (Symantec Corporation)
        O42 - Logiciel: PhotoNow!
        O42 - Logiciel: Power2Go
        O42 - Logiciel: PowerDirector
        O42 - Logiciel: QuickPlay SlingPlayer 0.4.4
        O42 - Logiciel: RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
        O42 - Logiciel: Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
        O42 - Logiciel: Realtek High Definition Audio Driver
        O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559)
        O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB973704)
        O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB973593)
        O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB957789)
        O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
        O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581)
        O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB969613)
        O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234)
        O42 - Logiciel: Synaptics Pointing Device Driver
        O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642)
        O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
        O42 - Logiciel: Update for Microsoft Office InfoPath 2007 (KB976416)
        O42 - Logiciel: Update for Microsoft Office Word 2007 (KB974561)
        O42 - Logiciel: Visual C++ 2008 x86 Runtime - (v9.0.30729)
        O42 - Logiciel: Visual C++ 2008 x86 Runtime - v9.0.30729.01
        O42 - Logiciel: Vodafone Mobile Connect Lite
        O42 - Logiciel: ccCommon
        O42 - Logiciel: muvee autoProducer 6.1
        0
        1. Rapport de ZHPDiag v1.24.39 par Nicolas Coolman

          SUITE

          ---\\ Contenu des dossiers Fichiers Communs (O43)
          O43 - CFD:Common File Directory ----D- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
          O43 - CFD:Common File Directory ----D- C:\Program Files\Ad-Remover
          O43 - CFD:Common File Directory ----D- C:\Program Files\Adobe
          O43 - CFD:Common File Directory ----D- C:\Program Files\Alwil Software
          O43 - CFD:Common File Directory ----D- C:\Program Files\Avira
          O43 - CFD:Common File Directory ----D- C:\Program Files\CardDetector
          O43 - CFD:Common File Directory ----D- C:\Program Files\CCleaner
          O43 - CFD:Common File Directory ----D- C:\Program Files\Combined Community Codec Pack
          O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files
          O43 - CFD:Common File Directory ----D- C:\Program Files\CyberLink
          O43 - CFD:Common File Directory ----D- C:\Program Files\DivX
          O43 - CFD:Common File Directory ----D- C:\Program Files\Electronic Arts
          O43 - CFD:Common File Directory ----D- C:\Program Files\EMCO
          O43 - CFD:Common File Directory ----D- C:\Program Files\eMule
          O43 - CFD:Common File Directory -SH-D- C:\Program Files\Fichiers communs
          O43 - CFD:Common File Directory ----D- C:\Program Files\Free Download Manager
          O43 - CFD:Common File Directory ----D- C:\Program Files\Hewlett-Packard
          O43 - CFD:Common File Directory ----D- C:\Program Files\Hp
          O43 - CFD:Common File Directory ----D- C:\Program Files\HP Games
          O43 - CFD:Common File Directory ----D- C:\Program Files\HPQ
          O43 - CFD:Common File Directory --H-D- C:\Program Files\InstallShield Installation Information
          O43 - CFD:Common File Directory ----D- C:\Program Files\Intel
          O43 - CFD:Common File Directory ----D- C:\Program Files\Internet Explorer
          O43 - CFD:Common File Directory ----D- C:\Program Files\Java
          O43 - CFD:Common File Directory ----D- C:\Program Files\Malwarebytes' Anti-Malware
          O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft
          O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Games
          O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Office
          O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Silverlight
          O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Works
          O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft.NET
          O43 - CFD:Common File Directory ----D- C:\Program Files\Motorola
          O43 - CFD:Common File Directory ----D- C:\Program Files\Movie Maker
          O43 - CFD:Common File Directory ----D- C:\Program Files\MSBuild
          O43 - CFD:Common File Directory ----D- C:\Program Files\MSXML 4.0
          O43 - CFD:Common File Directory ----D- C:\Program Files\muvee Technologies
          O43 - CFD:Common File Directory ----D- C:\Program Files\Navilog1
          O43 - CFD:Common File Directory ----D- C:\Program Files\Norton Internet Security
          O43 - CFD:Common File Directory ----D- C:\Program Files\Pack Securite
          O43 - CFD:Common File Directory ----D- C:\Program Files\Realtek
          O43 - CFD:Common File Directory ----D- C:\Program Files\Reference Assemblies
          O43 - CFD:Common File Directory ----D- C:\Program Files\Services en ligne
          O43 - CFD:Common File Directory ----D- C:\Program Files\Symantec
          O43 - CFD:Common File Directory ----D- C:\Program Files\Synaptics
          O43 - CFD:Common File Directory ----D- C:\Program Files\Trend Micro
          O43 - CFD:Common File Directory --H-D- C:\Program Files\Uninstall Information
          O43 - CFD:Common File Directory ----D- C:\Program Files\Vodafone
          O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Calendar
          O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Collaboration
          O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Defender
          O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Journal
          O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Mail
          O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Media Player
          O43 - CFD:Common File Directory ----D- C:\Program Files\Windows NT
          O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Photo Gallery
          O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Portable Devices
          O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Sidebar
          O43 - CFD:Common File Directory ----D- C:\Program Files\WinTV
          O43 - CFD:Common File Directory ----D- C:\Program Files\ZHPDiag
          O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\Adobe
          O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\DESIGNER
          O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\InstallShield
          O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\Java
          O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\microsoft shared
          O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\muvee Technologies
          O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\PX Storage Engine
          O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\Services
          O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\SpeechEngines
          O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\Symantec Shared
          O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\System

          ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
          O44 - LFC:Last File Created 21/12/2009 - 11:37:19 ---A- C:\Windows\System32\PerfStringBackup.INI
          O44 - LFC:Last File Created 21/12/2009 - 11:37:19 ---A- C:\Windows\System32\perfc009.dat
          O44 - LFC:Last File Created 21/12/2009 - 11:37:19 ---A- C:\Windows\System32\perfc00C.dat
          O44 - LFC:Last File Created 21/12/2009 - 11:37:19 ---A- C:\Windows\System32\perfh009.dat
          O44 - LFC:Last File Created 21/12/2009 - 11:37:19 ---A- C:\Windows\System32\perfh00C.dat
          O44 - LFC:Last File Created 21/12/2009 - 11:33:00 ---A- C:\Windows\ntbtlog.txt
          O44 - LFC:Last File Created 21/12/2009 - 11:32:34 -S-A- C:\Windows\bootstat.dat
          O44 - LFC:Last File Created 21/12/2009 - 10:54:31 --HA- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
          O44 - LFC:Last File Created 21/12/2009 - 10:54:31 --HA- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
          O44 - LFC:Last File Created 20/12/2009 - 22:33:12 ---A- C:\Windows\System32\FNTCACHE.DAT
          O44 - LFC:Last File Created 20/12/2009 - 17:50:35 ---A- C:\Windows\WindowsUpdate.log
          O44 - LFC:Last File Created 20/12/2009 - 16:00:07 ---A- C:\Windows\setupact.log
          O44 - LFC:Last File Created 20/12/2009 - 16:00:07 ---A- C:\Windows\setuperr.log
          O44 - LFC:Last File Created 20/12/2009 - 14:20:07 ---A- C:\Windows\System32\config.nt
          O44 - LFC:Last File Created 20/12/2009 - 14:00:10 ---A- C:\ZHPExportRegistry-20-12-2009-14-00-10.txt
          O44 - LFC:Last File Created 19/12/2009 - 21:11:08 ---A- C:\UsbFix.txt
          O44 - LFC:Last File Created 19/12/2009 - 20:56:17 ---A- C:\Ad-Report-CLEAN[1].log
          O44 - LFC:Last File Created 19/12/2009 - 20:45:34 ---A- C:\Ad-Report-SCAN[1].log
          O44 - LFC:Last File Created 19/12/2009 - 14:45:59 ---A- C:\cleannavi.txt
          O44 - LFC:Last File Created 18/12/2009 - 20:06:51 ---A- C:\FindyKill.txt
          O44 - LFC:Last File Created 18/12/2009 - 13:36:42 --HA- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
          O44 - LFC:Last File Created 18/12/2009 - 13:36:24 --HA- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
          O44 - LFC:Last File Created 01/12/2009 - 12:06:20 ---A- C:\Windows\System32\mrt.exe
          O44 - LFC:Last File Created 25/11/2009 - 11:19:02 ---A- C:\Windows\System32\drivers\avgntflt.sys
          O44 - LFC:Last File Created 21/11/2009 - 07:40:20 ---A- C:\Windows\System32\wininet.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:40:03 ---A- C:\Windows\System32\urlmon.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:38:17 ---A- C:\Windows\System32\occache.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:35:43 ---A- C:\Windows\System32\mshtml.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:35:38 ---A- C:\Windows\System32\msfeeds.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:35:38 ---A- C:\Windows\System32\msfeedsbs.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:34:58 ---A- C:\Windows\System32\jsproxy.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:34:52 ---A- C:\Windows\System32\inetcpl.cpl
          O44 - LFC:Last File Created 21/11/2009 - 07:34:39 ---A- C:\Windows\System32\iertutil.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:34:39 ---A- C:\Windows\System32\iesetup.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:34:39 ---A- C:\Windows\System32\iesysprep.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:34:39 ---A- C:\Windows\System32\ieui.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:34:38 ---A- C:\Windows\System32\ieframe.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:34:38 ---A- C:\Windows\System32\iepeers.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:34:38 ---A- C:\Windows\System32\iernonce.dll
          O44 - LFC:Last File Created 21/11/2009 - 07:34:33 ---A- C:\Windows\System32\iedkcs32.dll
          O44 - LFC:Last File Created 21/11/2009 - 05:59:58 ---A- C:\Windows\System32\ieUnatt.exe
          O44 - LFC:Last File Created 21/11/2009 - 05:59:52 ---A- C:\Windows\System32\ie4uinit.exe
          O44 - LFC:Last File Created 21/11/2009 - 05:59:14 ---A- C:\Windows\System32\msfeedssync.exe
          O44 - LFC:Last File Created 21/11/2009 - 05:58:54 ---A- C:\Windows\System32\mshtml.tlb
          O44 - LFC:Last File Created 21/11/2009 - 04:21:16 ---A- C:\Windows\System32\ieuinit.inf

          ---\\ Contrôle du Safe Boot (CSB) (O49)
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys
          O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Minimal\sermouse.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Minimal\vga.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Minimal\vgasave.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Minimal\volmgr.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Minimal\volmgrx.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Network\ipnat.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Network\nsiproxy.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Network\rdpencdd.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Network\sermouse.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Network\vga.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Network\vgasave.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Network\volmgr.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS1\Network\volmgrx.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Minimal\sermouse.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Minimal\vga.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Minimal\vgasave.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Minimal\volmgr.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Minimal\volmgrx.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Network\ipnat.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Network\nsiproxy.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Network\rdpencdd.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Network\sermouse.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Network\vga.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Network\vgasave.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Network\volmgr.sys
          O49 - CSB:Control Safe Boot HKLM\...\CS3\Network\volmgrx.sys

          ---\\ Trojan Driver Search Data (TDSD) (O52)
          O52 - TDSD:HKLM\...\Drivers\"timer"="timer.drv"
          O52 - TDSD:HKLM\...\Drivers32\"vidc.mrle"="msrle32.dll"
          O52 - TDSD:HKLM\...\Drivers32\"vidc.msvc"="msvidc32.dll"
          O52 - TDSD:HKLM\...\Drivers32\"msacm.imaadpcm"="imaadp32.acm"
          O52 - TDSD:HKLM\...\Drivers32\"msacm.msg711"="msg711.acm"
          O52 - TDSD:HKLM\...\Drivers32\"msacm.msgsm610"="msgsm32.acm"
          O52 - TDSD:HKLM\...\Drivers32\"msacm.msadpcm"="msadp32.acm"
          O52 - TDSD:HKLM\...\Drivers32\"midimapper"="midimap.dll"
          O52 - TDSD:HKLM\...\Drivers32\"wavemapper"="msacm32.drv"
          O52 - TDSD:HKLM\...\Drivers32\"VIDC.UYVY"="msyuv.dll"
          O52 - TDSD:HKLM\...\Drivers32\"VIDC.YUY2"="msyuv.dll"
          O52 - TDSD:HKLM\...\Drivers32\"VIDC.YVYU"="msyuv.dll"
          O52 - TDSD:HKLM\...\Drivers32\"VIDC.IYUV"="iyuv_32.dll"
          O52 - TDSD:HKLM\...\Drivers32\"vidc.i420"="iyuv_32.dll"
          O52 - TDSD:HKLM\...\Drivers32\"VIDC.YVU9"="tsbyuv.dll"
          O52 - TDSD:HKLM\...\Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm"
          O52 - TDSD:HKLM\...\Drivers32\"vidc.cvid"="iccvid.dll"
          O52 - TDSD:HKLM\...\Drivers32\"MSVideo8"="VfWWDM32.dll"
          O52 - TDSD:HKLM\...\Drivers32\"msacm.l3codecp"="l3codecp.acm"
          O52 - TDSD:HKLM\...\Drivers32\"vidc.DIVX"="DivX.dll"
          O52 - TDSD:HKLM\...\Drivers32\"vidc.yv12"="DivX.dll"
          O52 - TDSD:HKLM\...\Drivers32\"vidc.ffds"="C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll"
          O52 - TDSD:HKLM\...\Drivers32\"wave"="wdmaud.drv"
          O52 - TDSD:HKLM\...\Drivers32\"midi"="wdmaud.drv"
          O52 - TDSD:HKLM\...\Drivers32\"mixer"="wdmaud.drv"
          O52 - TDSD:HKLM\...\Drivers32\"aux"="wdmaud.drv"
          O52 - TDSD:HKLM\...\drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec"
          O52 - TDSD:HKLM\...\drivers.desc\"wdmaud.drv"="Realtek High Definition Audio"
          O52 - TDSD:HKLM\...\drivers.desc\"vfwwdm32.dll"="WDM Video For Windows Capture Driver (Win32)"
          O52 - TDSD:HKLM\...\drivers.desc\"l3codecp.acm"=""
          O52 - TDSD:HKLM\...\drivers.desc\"DivX.dll"="DivX 6.8.5 Codec"
          O52 - TDSD:HKLM\...\drivers.desc\"C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll"="ffdshow Video Codec"

          ---\\ Microsoft Control Security Providers (MCSP) (O54)
          O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - "SecurityProviders"=credssp.dll
          O54 - MCSP:[HKLM\...\ControlSet001\Control] - "SecurityProviders"=credssp.dll

          ---\\ Microsoft Windows Policies System (MWPS) (O55)
          O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=2
          O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=1
          O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
          O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
          O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
          O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
          O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
          O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
          O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
          O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
          O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
          O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
          O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
          O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
          O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
          O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0

          ---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
          O56 - MWPE:[HKCU\...\Policies\Explorer] - "NoDriveAutoRun"=128
          O56 - MWPE:[HKCU\...\Policies\Explorer] - "NoDriveTypeAutoRun"=128
          O56 - MWPE:[HKCU\...\Policies\Explorer] - "HonorAutoRunSetting"=0
          O56 - MWPE:[HKLM\...\Policies\Explorer] - "BindDirectlyToPropertySetStorage"=0
          O56 - MWPE:[HKLM\...\Policies\Explorer] - "NoDriveAutoRun"=128
          O56 - MWPE:[HKLM\...\Policies\Explorer] - "NoDriveTypeAutoRun"=128
          O56 - MWPE:[HKLM\...\Policies\Explorer] - "HonorAutoRunSetting"=0
          0
          1. Rapport de ZHPDiag v1.24.39 par Nicolas Coolman

            SUITE ET FIN

            ---\\ Liste des Drivers Système (SDL) (O58)
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\1394bus.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\acpi.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\adp94xx.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\adpahci.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\adpu160m.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\adpu320.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\afd.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\AGP440.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\aliide.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\AMDAGP.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\amdide.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\amdk7.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\amdk8.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\arc.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\arcsas.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\asyncmac.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\atapi.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ataport.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\avgntflt.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\avipbb.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\battc.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BCMWL6.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\bdasup.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\beep.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\bowser.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BrFiltLo.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BrFiltUp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\bridge.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BrSerId.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BrSerWdm.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BrUsbMdm.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\BrUsbSer.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\bthmodem.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\cdfs.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\cdrom.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\circlass.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Classpnp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\CmBatt.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\cmdide.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\compbatt.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\crashdmp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\crcdisk.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\crusoe.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\dfsc.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\disk.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Diskdump.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\djsvs.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\drmk.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\drmkaud.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Dumpata.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\dxapi.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\dxg.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\dxgkrnl.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\e100b325.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\E1G60I32.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ecache.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\elxstor.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\exfat.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\fastfat.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\fdc.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\fileinfo.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\filetrace.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\flpydisk.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\fltMgr.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\fs_rec.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\FWPKCLNT.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\GAGP30KX.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\hdaudbus.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\HdAudio.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\hidbth.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\hidclass.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\hidir.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\hidparse.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\hidusb.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\HpCISSs.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\HpqKbFiltr.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\HpqRemHid.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\http.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\i2omgmt.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\i2omp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\i8042prt.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\iaStor.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\iaStorV.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\igdkmd32.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\iirsp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\intelide.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\intelppm.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ipfltdrv.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\IPMIDrv.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ipnat.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\irda.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\irenum.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\isapnp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\iteatapi.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\iteraid.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\kbdclass.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\kbdhid.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ks.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ksecdd.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lltdio.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lsi_fc.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lsi_sas.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\lsi_scsi.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\luafv.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\massfilter.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mbam.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mbamswissarmy.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mcd.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\megasas.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\modem.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\monitor.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mouclass.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mouhid.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mountmgr.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mpio.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mpsdrv.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Mraid35x.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mrxdav.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mrxsmb.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mrxsmb10.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mrxsmb20.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\msahci.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\msdsm.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\msfs.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\msisadrv.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\msiscsi.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mskssrv.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mspclock.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mspqm.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\msrpc.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mssmbios.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mstee.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\mup.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ndis.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ndistapi.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ndisuio.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ndiswan.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ndproxy.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\netbios.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\netbt.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\netio.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\NETw3v32.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\NETw4v32.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\nfrd960.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\npfs.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\nsiproxy.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ntfs.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ntrigdigi.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\null.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\nvlddmkm.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\nvraid.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\nvstor.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\NV_AGP.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\nwifi.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ohci1394.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\pacer.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\parport.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\partmgr.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\parvdm.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\pci.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\pciide.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\pciidex.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\pcmcia.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\PEAuth.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\portcls.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\processr.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ql2300.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ql40xx.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\qwavedrv.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rasacd.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rasl2tp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\raspppoe.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\raspptp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rassstp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rdbss.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\RDPCDD.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rdpdr.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\RDPENCDD.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rdpwd.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rimmptsk.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rimsptsk.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rixdptsk.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rmcast.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\RNDISMP.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rootmdm.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\rspndr.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\RTKVHDA.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Rtlh86.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sbp2port.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\scsiport.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sdbus.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\secdrv.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\serenum.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\serial.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sermouse.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sffdisk.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sffp_mmc.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sffp_sd.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sfloppy.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\SISAGP.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sisraid2.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sisraid4.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\smb.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\smclib.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\smserial.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\spldr.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\spsys.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\srv.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\srv2.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\srvnet.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ssmdrv.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Storport.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\stream.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\swenum.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\symc8xx.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\SYMEVENT.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\symndisv.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sym_hi.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\sym_u3.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\SynTP.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tape.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tcpip.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tcpipreg.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tdi.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tdpipe.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tdtcp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tdx.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\termdd.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tssecsrv.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\TUNMP.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\tunnel.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\UAGP35.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\udfs.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ULIAGPKX.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\uliahci.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ulsata.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ulsata2.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\umbus.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\umpass.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usb8023.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\USBCAMD.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\USBCAMD2.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbccgp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbcir.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbd.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbehci.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbhub.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbohci.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbport.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbprint.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\USBSTOR.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbuhci.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\usbvideo.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\vga.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\vgapnp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\VIAAGP.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\viac7.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\viaide.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\videoprt.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\volmgr.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\volmgrx.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\volsnap.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\vsmraid.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\VSTAZL3.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\VSTCNXT3.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\VSTDPV3.SYS
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\wacompen.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\wanarp.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\watchdog.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\wd.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\Wdf01000.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\WdfLdr.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\wmiacpi.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\wmilib.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\WpdUsb.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ws2ifsl.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\WUDFPf.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\WUDFRd.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ZTEusbmdm6k.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ZTEusbnet.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ZTEusbnmea.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\ZTEusbser6k.sys
            O58 - SDL:System Drivers List - C:\Windows\system32\drivers\zteusbvoice.sys

            ---\\ Liste des outils de nettoyage (LATC) (O63)
            O63 - Logiciel: HijackThis 2.0.2
            O63 - Logiciel: ZHPDiag 1.24
            O63 - Logiciel: AD-Remover
            O63 - Logiciel: UsbFix

            ---\\ Liste des services Legacy (LALS) (O64)
            O64 - Services: CurCS - Ancilliary Function Driver for Winsock (AFD) - LEGACY_AFD
            O64 - Services: CurCS - aswFsBlk (aswFsBlk) - LEGACY_ASWFSBLK
            O64 - Services: CurCS - aswMonFlt (aswMonFlt) - LEGACY_ASWMONFLT
            O64 - Services: CurCS - aswRdr (aswRdr) - LEGACY_ASWRDR
            O64 - Services: CurCS - avast! Self Protection (aswSP) - LEGACY_ASWSP
            O64 - Services: CurCS - avast! Network Shield Support (aswTdi) - LEGACY_ASWTDI
            O64 - Services: CurCS - avgio (avgio) - LEGACY_AVGIO
            O64 - Services: CurCS - avgntflt (avgntflt) - LEGACY_AVGNTFLT
            O64 - Services: CurCS - avipbb (avipbb) - LEGACY_AVIPBB
            O64 - Services: CurCS - Beep (Beep) - LEGACY_BEEP
            O64 - Services: CurCS - Bowser (bowser) - LEGACY_BOWSER
            O64 - Services: CurCS - CD/DVD File System Reader (cdfs) - LEGACY_CDFS
            O64 - Services: CurCS - Common Log (CLFS) (CLFS) - LEGACY_CLFS
            O64 - Services: CurCS - comHost (comHost) - LEGACY_COMHOST
            O64 - Services: CurCS - CO_Mon (CO_Mon) - LEGACY_CO_MON
            O64 - Services: CurCS - Crcdisk Filter Driver (crcdisk) - LEGACY_CRCDISK
            O64 - Services: CurCS - Dfs Client Driver (DfsC) - LEGACY_DFSC
            O64 - Services: CurCS - LDDM Graphics Subsystem (DXGKrnl) - LEGACY_DXGKRNL
            O64 - Services: CurCS - ReadyBoost Caching Driver (Ecache) - LEGACY_ECACHE
            O64 - Services: CurCS - Symantec Eraser Control driver (eeCtrl) - LEGACY_EECTRL
            O64 - Services: CurCS - EraserUtilDrvI7 (EraserUtilDrvI7) - LEGACY_ERASERUTILDRVI7
            O64 - Services: CurCS - EraserUtilRebootDrv (EraserUtilRebootDrv) - LEGACY_ERASERUTILREBOOTDRV
            O64 - Services: CurCS - F-Secure HIPS (F-Secure HIPS) - LEGACY_F-SECURE_HIPS
            O64 - Services: CurCS - FAT12/16/32 File System Driver (fastfat) - LEGACY_FASTFAT
            O64 - Services: CurCS - File Information FS MiniFilter (FileInfo) - LEGACY_FILEINFO
            O64 - Services: CurCS - FltMgr (FltMgr) - LEGACY_FLTMGR
            O64 - Services: CurCS - Fs_Rec (Fs_Rec) - LEGACY_FS_REC
            O64 - Services: CurCS - HTTP (HTTP) - LEGACY_HTTP
            O64 - Services: CurCS - Symantec Intrusion Prevention Driver (IDSvix86) - LEGACY_IDSVIX86
            O64 - Services: CurCS - KSecDD (KSecDD) - LEGACY_KSECDD
            O64 - Services: CurCS - Link-Layer Topology Discovery Mapper I/O Driver (lltdio) - LEGACY_LLTDIO
            O64 - Services: CurCS - UAC File Virtualization (luafv) - LEGACY_LUAFV
            O64 - Services: CurCS - Mount Point Manager (MountMgr) - LEGACY_MOUNTMGR
            O64 - Services: CurCS - @%SystemRoot%\system32\FirewallAPI.dll,-23092 (mpsdrv) - LEGACY_MPSDRV
            O64 - Services: CurCS - WebDav Client Redirector Driver (MRxDAV) - LEGACY_MRXDAV
            O64 - Services: CurCS - SMB MiniRedirector Wrapper and Engine (mrxsmb) - LEGACY_MRXSMB
            O64 - Services: CurCS - SMB 1.x MiniRedirector (mrxsmb10) - LEGACY_MRXSMB10
            O64 - Services: CurCS - SMB 2.0 MiniRedirector (mrxsmb20) - LEGACY_MRXSMB20
            O64 - Services: CurCS - msahci (msahci) - LEGACY_MSAHCI
            O64 - Services: CurCS - Msfs (Msfs) - LEGACY_MSFS
            O64 - Services: CurCS - ISA/EISA Class Driver (msisadrv) - LEGACY_MSISADRV
            O64 - Services: CurCS - Mup (Mup) - LEGACY_MUP
            O64 - Services: CurCS - NativeWiFi Filter (NativeWifiP) - LEGACY_NATIVEWIFIP
            O64 - Services: CurCS - NDIS System Driver (NDIS) - LEGACY_NDIS
            O64 - Services: CurCS - NDIS Usermode I/O Protocol (Ndisuio) - LEGACY_NDISUIO
            O64 - Services: CurCS - NDProxy (NDProxy) - LEGACY_NDPROXY
            O64 - Services: CurCS - NetBIOS Interface (NetBIOS) - LEGACY_NETBIOS
            O64 - Services: CurCS - NETBT (netbt) - LEGACY_NETBT
            O64 - Services: CurCS - Npfs (Npfs) - LEGACY_NPFS
            O64 - Services: CurCS - NSI proxy service (nsiproxy) - LEGACY_NSIPROXY
            O64 - Services: CurCS - Ntfs (Ntfs) - LEGACY_NTFS
            O64 - Services: CurCS - Null (Null) - LEGACY_NULL
            O64 - Services: CurCS - PEAUTH (PEAUTH) - LEGACY_PEAUTH
            O64 - Services: CurCS - @%SystemRoot%\System32\drivers\pacer.sys,-101 (PSched) - LEGACY_PSCHED
            O64 - Services: CurCS - Remote Access Auto Connection Driver (RasAcd) - LEGACY_RASACD
            O64 - Services: CurCS - Redirected Buffering Sub Sysytem (rdbss) - LEGACY_RDBSS
            O64 - Services: CurCS - RDPCDD (RDPCDD) - LEGACY_RDPCDD
            O64 - Services: CurCS - RDP Encoder Mirror Driver (RDPENCDD) - LEGACY_RDPENCDD
            O64 - Services: CurCS - Link-Layer Topology Discovery Responder (rspndr) - LEGACY_RSPNDR
            O64 - Services: CurCS - Security Driver (secdrv) - LEGACY_SECDRV
            O64 - Services: CurCS - @%SystemRoot%\system32\tcpipcfg.dll,-50005 (Smb) - LEGACY_SMB
            O64 - Services: CurCS - Security Processor Loader Driver (spldr) - LEGACY_SPLDR
            O64 - Services: CurCS - srv (srv) - LEGACY_SRV
            O64 - Services: CurCS - srv2 (srv2) - LEGACY_SRV2
            O64 - Services: CurCS - srvnet (srvnet) - LEGACY_SRVNET
            O64 - Services: CurCS - ssmdrv (ssmdrv) - LEGACY_SSMDRV
            O64 - Services: CurCS - SYMDNS (SYMDNS) - LEGACY_SYMDNS
            O64 - Services: CurCS - SymEvent (SymEvent) - LEGACY_SYMEVENT
            O64 - Services: CurCS - SYMFW (SYMFW) - LEGACY_SYMFW
            O64 - Services: CurCS - SYMNDISV (SYMNDISV) - LEGACY_SYMNDISV
            O64 - Services: CurCS - SYMREDRV (SYMREDRV) - LEGACY_SYMREDRV
            O64 - Services: CurCS - SYMTDI (SYMTDI) - LEGACY_SYMTDI
            O64 - Services: CurCS - @%SystemRoot%\system32\tcpipcfg.dll,-50003 (Tcpip) - LEGACY_TCPIP
            O64 - Services: CurCS - TCP/IP Registry Compatibility (tcpipreg) - LEGACY_TCPIPREG
            O64 - Services: CurCS - @%SystemRoot%\system32\tcpipcfg.dll,-50004 (tdx) - LEGACY_TDX
            O64 - Services: CurCS - udfs (udfs) - LEGACY_UDFS
            O64 - Services: CurCS - VgaSave (VgaSave) - LEGACY_VGASAVE
            O64 - Services: CurCS - Dynamic Volume Manager (volmgrx) - LEGACY_VOLMGRX
            O64 - Services: CurCS - Volumes de stockage (volsnap) - LEGACY_VOLSNAP
            O64 - Services: CurCS - Remote Access IPv6 ARP Driver (Wanarpv6) - LEGACY_WANARPV6
            O64 - Services: CurCS - Kernel Mode Driver Frameworks service (Wdf01000) - LEGACY_WDF01000
            O64 - Services: CurCS - Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0 (ws2ifsl) - LEGACY_WS2IFSL
            O64 - Services: CurCS - {22D78859-9CE9-4B77-BF18-AC83E81A9263} ({22D78859-9CE9-4B77-BF18-AC83E81A9263}) - LEGACY_{22D78859-9CE9-4B77-BF18-AC83E81A9263}

            End of the scan: 900 lines
            0
            1. info.txt logfile of random's system information tool 1.06 2009-12-21 12:00:55

              ======Uninstall list======

              -->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
              -->"C:\Program Files\HP Games\Blasterball 2 Revolution\Uninstall.exe"
              -->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
              -->"C:\Program Files\HP Games\Bricks of Egypt\Uninstall.exe"
              -->"C:\Program Files\HP Games\Chicken Invaders 3 - Revenge of the Yolk\Uninstall.exe"
              -->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
              -->"C:\Program Files\HP Games\Crystal Maze\Uninstall.exe"
              -->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
              -->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
              -->"C:\Program Files\HP Games\FATE\Uninstall.exe"
              -->"C:\Program Files\HP Games\Fish Tycoon\Uninstall.exe"
              -->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
              -->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
              -->"C:\Program Files\HP Games\Jewel Quest\Uninstall.exe"
              -->"C:\Program Files\HP Games\Magic Academy\Uninstall.exe"
              -->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
              -->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
              -->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
              -->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
              -->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
              -->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
              -->"C:\Program Files\HP Games\Polar Golfer Pineapple Cup\Uninstall.exe"
              -->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
              -->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
              -->"C:\Program Files\HP Games\Shooting Stars Pool\Uninstall.exe"
              -->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
              -->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
              -->"C:\Program Files\HP Games\Super Granny\Uninstall.exe"
              -->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
              -->"C:\Program Files\HP Games\Virtual Villagers - A New Home\Uninstall.exe"
              -->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
              -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
              Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
              Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
              Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
              Adobe Reader 8.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81000000003}
              Adobe Shockwave Player-->MsiExec.exe /X{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}
              AppCore-->MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
              Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
              Card Detector for Option Icon 225-->C:\Program Files\CardDetector\ICON225\CardDetectorSetup.exe -u
              ccCommon-->MsiExec.exe /I{B24E05CC-46FF-4787-BBB8-5CD516AFB118}
              CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
              Combined Community Codec Pack BETA 2008-12-29 01:28-->"C:\Program Files\Combined Community Codec Pack\unins000.exe"
              Component Framework-->MsiExec.exe /I{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}
              CyberLink YouCam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
              DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
              DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
              DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
              DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
              DVD Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
              EA Link-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{F5577101-33CC-4711-8235-3A95BCD49DB0} /l1036
              ESU for Microsoft Vista-->MsiExec.exe /I{AD3FDC40-BCF4-476D-A2D6-C4B154DD9DF5}
              Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
              Hauppauge MCE XP/Vista Software Encoder (2.0.25149)-->C:\PROGRA~1\WinTV\UNSftMCE.EXE C:\PROGRA~1\WinTV\softMCE.LOG
              Hewlett-Packard Active Check for Health Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
              Hewlett-Packard Asset Agent for Health Check-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
              HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
              Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
              HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}\setup.exe -runfromtemp -l0x0409
              HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD0E2B92-3814-46F0-893B-4612EA010C7E}\setup.exe" -l0x9 -removeonly
              HP Doc Viewer-->MsiExec.exe /I{082702D5-5DD8-4600-BCE5-48B15174687F}
              HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9885A11E-60E4-417C-B58B-8B31B21C0B8A}\setup.exe" -l0x9 -removeonly
              HP Help and Support-->MsiExec.exe /X{31216452-5540-4C96-B754-94890A63D5AB}
              HP Quick Launch Buttons 6.30 E1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x040c uninst
              HP QuickPlay 3.6-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
              HP QuickTouch 1.00 C4-->MsiExec.exe /I{7DC4A410-9986-4329-9E5D-687B2C42CA39}
              HP Total Care Advisor-->MsiExec.exe /X{b02df929-29a7-4fd2-9a70-81a644b635f7}
              HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
              HP User Guides 0088-->MsiExec.exe /I{8347A7A5-4AB8-433F-82AA-496B0D189A9B}
              HP Wireless Assistant-->MsiExec.exe /I{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}
              HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
              Intel® Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
              Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
              Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
              Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
              LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" -uninstall
              Les Sims™ Histoires de vie-->MsiExec.exe /I{2284D904-C138-4B58-93EC-5C362AB5130A}
              Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
              Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
              Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
              Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
              Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
              Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
              Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
              Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
              Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
              Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
              Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
              Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
              Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
              Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
              Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
              Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
              Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
              Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
              Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
              Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
              Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
              Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
              Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
              Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
              Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
              Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
              Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
              Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
              Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
              Motorola SM56 Data Fax Modem-->rundll32.exe sm56co6a.dll,SM56UnInstaller
              MSCU for Microsoft Vista-->MsiExec.exe /I{E87F5651-CE15-493F-AE99-3B670E25A54E}
              MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
              MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
              MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
              MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
              muvee autoProducer 6.1-->C:\Program Files\InstallShield Installation Information\{250E9609-E830-43EB-B379-DAB7546A2422}\muveesetup.exe -removeonly -runfromtemp
              My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
              Norton Internet Security (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\SymSetup\{C1C185CA-C531-49F5-A6FA-B838405A049D}_15_0_0_60\Setup.exe" /X
              NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
              PhotoNow!-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\setup.exe" -uninstall
              Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
              PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
              QuickPlay SlingPlayer 0.4.4-->"C:\Program Files\HP\QuickPlay\unins000.exe"
              Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
              Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
              RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x40c anything
              Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
              Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
              Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
              Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
              Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
              Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
              Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
              Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
              Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
              Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
              Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
              Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
              Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
              Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
              Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
              Vodafone Mobile Connect Lite-->MsiExec.exe /X{C656142F-EFE1-44CD-BFAD-6CBC6DCB9860}
              ZHPDiag 1.24-->"C:\Program Files\ZHPDiag\unins000.exe"
              0
              1. info.txt logfile of random's system information tool 1.06 2009-12-21 12:00:55

                SUITE ET FIN

                =====HijackThis Backups=====

                O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll [2009-12-19]
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/... [2009-12-19]
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/... [2009-12-19]

                ======Security center information======

                AV: Norton Internet Security
                FW: Norton Internet Security (disabled)
                AS: Windows Defender
                AS: Norton Internet Security (disabled) (outdated)

                ======System event log======

                Computer Name: PC-de-sandrine
                Event Code: 10005
                Message: DCOM a reçu l'erreur "1084" lors de la mise en route du service WSearch avec les arguments "" pour démarrer le serveur :
                {9E175B6D-F52A-11D8-B9A5-505054503030}
                Record Number: 293359
                Source Name: Microsoft-Windows-DistributedCOM
                Time Written: 20091220192008.000000-000
                Event Type: Erreur
                User:

                Computer Name: PC-de-sandrine
                Event Code: 10005
                Message: DCOM a reçu l'erreur "1084" lors de la mise en route du service EventSystem avec les arguments "" pour démarrer le serveur :
                {1BE1F766-5536-11D1-B726-00C04FB926AF}
                Record Number: 293357
                Source Name: Microsoft-Windows-DistributedCOM
                Time Written: 20091220192002.000000-000
                Event Type: Erreur
                User:

                Computer Name: PC-de-sandrine
                Event Code: 10005
                Message: DCOM a reçu l'erreur "1084" lors de la mise en route du service ShellHWDetection avec les arguments "" pour démarrer le serveur :
                {DD522ACC-F821-461A-A407-50B198B896DC}
                Record Number: 293356
                Source Name: Microsoft-Windows-DistributedCOM
                Time Written: 20091220191954.000000-000
                Event Type: Erreur
                User:

                Computer Name: PC-DE-SANDRINE
                Event Code: 263
                Message: Le service ‘TabletInputService’ n'a peut-être pas annulé son inscription aux notifications d’événements de périphériques avant d’être arrêté.
                Record Number: 293352
                Source Name: PlugPlayManager
                Time Written: 20091220191945.000000-000
                Event Type: Avertissement
                User:

                Computer Name: PC-de-sandrine
                Event Code: 6008
                Message: L'arrêt système précédant à 20:16:27 le 20/12/2009 n'était pas prévu.
                Record Number: 293348
                Source Name: EventLog
                Time Written: 20091220191945.000000-000
                Event Type: Erreur
                User:

                =====Application event log=====

                Computer Name: PC-de-sandrine
                Event Code: 103
                Message:
                Record Number: 24844
                Source Name: F-Secure Anti-Virus
                Time Written: 20090420161434.000000-000
                Event Type: Erreur
                User:

                Computer Name: PC-de-sandrine
                Event Code: 103
                Message:
                Record Number: 24843
                Source Name: F-Secure Anti-Virus
                Time Written: 20090420161242.000000-000
                Event Type: Erreur
                User:

                Computer Name: PC-de-sandrine
                Event Code: 103
                Message:
                Record Number: 23732
                Source Name: F-Secure Anti-Virus
                Time Written: 20090416121417.000000-000
                Event Type: Erreur
                User:

                Computer Name: PC-de-sandrine
                Event Code: 103
                Message:
                Record Number: 23426
                Source Name: F-Secure Anti-Virus
                Time Written: 20090415111816.000000-000
                Event Type: Erreur
                User:

                Computer Name: PC-de-sandrine
                Event Code: 103
                Message:
                Record Number: 23064
                Source Name: F-Secure Anti-Virus
                Time Written: 20090414103219.000000-000
                Event Type: Erreur
                User:

                =====Security event log=====

                Computer Name: PC-de-sandrine
                Event Code: 1100
                Message: Le service d’enregistrement des événements a été arrêté.
                Record Number: 961
                Source Name: Microsoft-Windows-Eventlog
                Time Written: 20080908053333.138200-000
                Event Type: Succès de l'audit
                User:

                Computer Name: PC-de-sandrine
                Event Code: 4647
                Message: Fermeture de session initiée par l’utilisateur :

                Sujet :
                ID de sécurité : S-1-5-21-879023170-2910880756-1729088331-1000
                Nom du compte : sandrine
                Domaine du compte : PC-de-sandrine
                ID d’ouverture de session : 0x29d489

                Cet événement est généré lorsqu’une fermeture de session est initiée, mais que le nombre de références du jeton n’étant pas zéro, la session ouverte ne peut pas être supprimée. Aucune autre activité initiée par l’utilisateur ne peut se produire. Cet événement peut être interprété comme un événement de fermeture de session.
                Record Number: 960
                Source Name: Microsoft-Windows-Security-Auditing
                Time Written: 20080908053331.531400-000
                Event Type: Succès de l'audit
                User:

                Computer Name: PC-de-sandrine
                Event Code: 4616
                Message: L’heure du système a été modifiée.

                Sujet :
                ID de sécurité : S-1-5-21-879023170-2910880756-1729088331-1000
                Nom du compte : sandrine
                Domaine du compte : PC-de-sandrine
                ID d’ouverture de session : 0x29d3aa

                Informations sur le processus :
                ID du processus : 0x9f0
                Nom : C:\Windows\System32\dllhost.exe

                Heure précédente : 02:31:05 08/09/2008
                Nouvelle heure : 07:30:42 08/09/2008

                Cet événement est généré lorsque l’heure du système est modifiée. Le changement régulier de l’heure du système est une opération normale de la part du service de temps Windows qui s’exécute avec des privilèges système. Mais, d’autres modifications de l’heure du système peuvent indiquer des tentatives de falsification de l’ordinateur.
                Record Number: 959
                Source Name: Microsoft-Windows-Security-Auditing
                Time Written: 20080908053042.029000-000
                Event Type: Succès de l'audit
                User:

                Computer Name: PC-de-sandrine
                Event Code: 4616
                Message: L’heure du système a été modifiée.

                Sujet :
                ID de sécurité : S-1-5-21-879023170-2910880756-1729088331-1000
                Nom du compte : sandrine
                Domaine du compte : PC-de-sandrine
                ID d’ouverture de session : 0x29d3aa

                Informations sur le processus :
                ID du processus : 0x9f0
                Nom : C:\Windows\System32\dllhost.exe

                Heure précédente : 07:30:42 08/09/2008
                Nouvelle heure : 07:30:42 08/09/2008

                Cet événement est généré lorsque l’heure du système est modifiée. Le changement régulier de l’heure du système est une opération normale de la part du service de temps Windows qui s’exécute avec des privilèges système. Mais, d’autres modifications de l’heure du système peuvent indiquer des tentatives de falsification de l’ordinateur.
                Record Number: 958
                Source Name: Microsoft-Windows-Security-Auditing
                Time Written: 20080908053042.029000-000
                Event Type: Succès de l'audit
                User:

                Computer Name: PC-de-sandrine
                Event Code: 1102
                Message: Le journal d’audit a été effacé.
                Objet :
                ID de sécurité : S-1-5-21-879023170-2910880756-1729088331-1000
                Nom de compte : sandrine
                Nom de domaine : PC-de-sandrine
                ID de connexion : 0x29d3aa
                Record Number: 957
                Source Name: Microsoft-Windows-Eventlog
                Time Written: 20080907233823.992800-000
                Event Type: Succès de l'audit
                User:

                ======Environment variables======

                "ComSpec"=%SystemRoot%\system32\cmd.exe
                "FP_NO_HOST_CHECK"=NO
                "OS"=Windows_NT
                "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\CyberLink\Power2Go\
                "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                "PROCESSOR_ARCHITECTURE"=x86
                "TEMP"=%SystemRoot%\TEMP
                "TMP"=%SystemRoot%\TEMP
                "USERNAME"=SYSTEM
                "windir"=%SystemRoot%
                "PROCESSOR_LEVEL"=6
                "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
                "PROCESSOR_REVISION"=0f0d
                "NUMBER_OF_PROCESSORS"=2
                "PLATFORM"=MCD
                "PCBRAND"=Pavilion
                "OnlineServices"=Services en ligne
                "USERPART"=E:
                "SAFEBOOT_OPTION"=NETWORK

                -----------------EOF-----------------
                0
                1. CA C LE LOG RSIT... Mais ca fait peut etre double emploi avec l'autre ?

                  info.txt logfile of random's system information tool 1.06 2009-12-21 12:00:55

                  ======Uninstall list======

                  -->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Blasterball 2 Revolution\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Bricks of Egypt\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Chicken Invaders 3 - Revenge of the Yolk\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Crystal Maze\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
                  -->"C:\Program Files\HP Games\FATE\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Fish Tycoon\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Jewel Quest\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Magic Academy\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
                  -->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Polar Golfer Pineapple Cup\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Shooting Stars Pool\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Super Granny\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Virtual Villagers - A New Home\Uninstall.exe"
                  -->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
                  -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                  Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
                  Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                  Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                  Adobe Reader 8.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81000000003}
                  Adobe Shockwave Player-->MsiExec.exe /X{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}
                  AppCore-->MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
                  Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
                  Card Detector for Option Icon 225-->C:\Program Files\CardDetector\ICON225\CardDetectorSetup.exe -u
                  ccCommon-->MsiExec.exe /I{B24E05CC-46FF-4787-BBB8-5CD516AFB118}
                  CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
                  Combined Community Codec Pack BETA 2008-12-29 01:28-->"C:\Program Files\Combined Community Codec Pack\unins000.exe"
                  Component Framework-->MsiExec.exe /I{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}
                  CyberLink YouCam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
                  DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
                  DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                  DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
                  DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
                  DVD Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
                  EA Link-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{F5577101-33CC-4711-8235-3A95BCD49DB0} /l1036
                  ESU for Microsoft Vista-->MsiExec.exe /I{AD3FDC40-BCF4-476D-A2D6-C4B154DD9DF5}
                  Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
                  Hauppauge MCE XP/Vista Software Encoder (2.0.25149)-->C:\PROGRA~1\WinTV\UNSftMCE.EXE C:\PROGRA~1\WinTV\softMCE.LOG
                  Hewlett-Packard Active Check for Health Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
                  Hewlett-Packard Asset Agent for Health Check-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
                  HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                  Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                  Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                  HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}\setup.exe -runfromtemp -l0x0409
                  HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD0E2B92-3814-46F0-893B-4612EA010C7E}\setup.exe" -l0x9 -removeonly
                  HP Doc Viewer-->MsiExec.exe /I{082702D5-5DD8-4600-BCE5-48B15174687F}
                  HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9885A11E-60E4-417C-B58B-8B31B21C0B8A}\setup.exe" -l0x9 -removeonly
                  HP Help and Support-->MsiExec.exe /X{31216452-5540-4C96-B754-94890A63D5AB}
                  HP Quick Launch Buttons 6.30 E1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x040c uninst
                  HP QuickPlay 3.6-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
                  HP QuickTouch 1.00 C4-->MsiExec.exe /I{7DC4A410-9986-4329-9E5D-687B2C42CA39}
                  HP Total Care Advisor-->MsiExec.exe /X{b02df929-29a7-4fd2-9a70-81a644b635f7}
                  HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
                  HP User Guides 0088-->MsiExec.exe /I{8347A7A5-4AB8-433F-82AA-496B0D189A9B}
                  HP Wireless Assistant-->MsiExec.exe /I{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}
                  HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
                  Intel® Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
                  Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
                  Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
                  Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                  LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" -uninstall
                  Les Sims™ Histoires de vie-->MsiExec.exe /I{2284D904-C138-4B58-93EC-5C362AB5130A}
                  Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                  Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                  Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                  Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                  Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                  Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
                  Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
                  Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
                  Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                  Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
                  Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                  Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                  Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                  Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                  Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                  Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                  Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                  Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                  Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                  Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                  Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                  Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                  Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                  Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                  Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                  Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                  Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                  Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                  Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
                  Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                  Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
                  Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                  Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
                  Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                  Motorola SM56 Data Fax Modem-->rundll32.exe sm56co6a.dll,SM56UnInstaller
                  MSCU for Microsoft Vista-->MsiExec.exe /I{E87F5651-CE15-493F-AE99-3B670E25A54E}
                  MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                  MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
                  MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                  MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
                  muvee autoProducer 6.1-->C:\Program Files\InstallShield Installation Information\{250E9609-E830-43EB-B379-DAB7546A2422}\muveesetup.exe -removeonly -runfromtemp
                  My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
                  Norton Internet Security (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\SymSetup\{C1C185CA-C531-49F5-A6FA-B838405A049D}_15_0_0_60\Setup.exe" /X
                  NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
                  PhotoNow!-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\setup.exe" -uninstall
                  Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
                  PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
                  QuickPlay SlingPlayer 0.4.4-->"C:\Program Files\HP\QuickPlay\unins000.exe"
                  Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
                  Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
                  RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x40c anything
                  Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                  Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
                  Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
                  Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
                  Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
                  Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
                  Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                  Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                  Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                  Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                  Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                  Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
                  Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
                  Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
                  Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
                  Vodafone Mobile Connect Lite-->MsiExec.exe /X{C656142F-EFE1-44CD-BFAD-6CBC6DCB9860}
                  ZHPDiag 1.24-->"C:\Program Files\ZHPDiag\unins000.exe"

                  =====HijackThis Backups=====

                  O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll [2009-12-19]
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF [2009-12-19]
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF [2009-12-19]
                  0
                  1. info.txt logfile of random's system information tool 1.06 2009-12-21 12:00:55

                    suite et fin

                    ======Security center information======

                    AV: Norton Internet Security
                    FW: Norton Internet Security (disabled)
                    AS: Windows Defender
                    AS: Norton Internet Security (disabled) (outdated)

                    ======System event log======

                    Computer Name: PC-de-sandrine
                    Event Code: 10005
                    Message: DCOM a reçu l'erreur "1084" lors de la mise en route du service WSearch avec les arguments "" pour démarrer le serveur :
                    {9E175B6D-F52A-11D8-B9A5-505054503030}
                    Record Number: 293359
                    Source Name: Microsoft-Windows-DistributedCOM
                    Time Written: 20091220192008.000000-000
                    Event Type: Erreur
                    User:

                    Computer Name: PC-de-sandrine
                    Event Code: 10005
                    Message: DCOM a reçu l'erreur "1084" lors de la mise en route du service EventSystem avec les arguments "" pour démarrer le serveur :
                    {1BE1F766-5536-11D1-B726-00C04FB926AF}
                    Record Number: 293357
                    Source Name: Microsoft-Windows-DistributedCOM
                    Time Written: 20091220192002.000000-000
                    Event Type: Erreur
                    User:

                    Computer Name: PC-de-sandrine
                    Event Code: 10005
                    Message: DCOM a reçu l'erreur "1084" lors de la mise en route du service ShellHWDetection avec les arguments "" pour démarrer le serveur :
                    {DD522ACC-F821-461A-A407-50B198B896DC}
                    Record Number: 293356
                    Source Name: Microsoft-Windows-DistributedCOM
                    Time Written: 20091220191954.000000-000
                    Event Type: Erreur
                    User:

                    Computer Name: PC-DE-SANDRINE
                    Event Code: 263
                    Message: Le service ‘TabletInputService’ n'a peut-être pas annulé son inscription aux notifications d’événements de périphériques avant d’être arrêté.
                    Record Number: 293352
                    Source Name: PlugPlayManager
                    Time Written: 20091220191945.000000-000
                    Event Type: Avertissement
                    User:

                    Computer Name: PC-de-sandrine
                    Event Code: 6008
                    Message: L'arrêt système précédant à 20:16:27 le 20/12/2009 n'était pas prévu.
                    Record Number: 293348
                    Source Name: EventLog
                    Time Written: 20091220191945.000000-000
                    Event Type: Erreur
                    User:

                    =====Application event log=====

                    Computer Name: PC-de-sandrine
                    Event Code: 103
                    Message:
                    Record Number: 24844
                    Source Name: F-Secure Anti-Virus
                    Time Written: 20090420161434.000000-000
                    Event Type: Erreur
                    User:

                    Computer Name: PC-de-sandrine
                    Event Code: 103
                    Message:
                    Record Number: 24843
                    Source Name: F-Secure Anti-Virus
                    Time Written: 20090420161242.000000-000
                    Event Type: Erreur
                    User:

                    Computer Name: PC-de-sandrine
                    Event Code: 103
                    Message:
                    Record Number: 23732
                    Source Name: F-Secure Anti-Virus
                    Time Written: 20090416121417.000000-000
                    Event Type: Erreur
                    User:

                    Computer Name: PC-de-sandrine
                    Event Code: 103
                    Message:
                    Record Number: 23426
                    Source Name: F-Secure Anti-Virus
                    Time Written: 20090415111816.000000-000
                    Event Type: Erreur
                    User:

                    Computer Name: PC-de-sandrine
                    Event Code: 103
                    Message:
                    Record Number: 23064
                    Source Name: F-Secure Anti-Virus
                    Time Written: 20090414103219.000000-000
                    Event Type: Erreur
                    User:

                    =====Security event log=====

                    Computer Name: PC-de-sandrine
                    Event Code: 1100
                    Message: Le service d’enregistrement des événements a été arrêté.
                    Record Number: 961
                    Source Name: Microsoft-Windows-Eventlog
                    Time Written: 20080908053333.138200-000
                    Event Type: Succès de l'audit
                    User:

                    Computer Name: PC-de-sandrine
                    Event Code: 4647
                    Message: Fermeture de session initiée par l’utilisateur :

                    Sujet :
                    ID de sécurité : S-1-5-21-879023170-2910880756-1729088331-1000
                    Nom du compte : sandrine
                    Domaine du compte : PC-de-sandrine
                    ID d’ouverture de session : 0x29d489

                    Cet événement est généré lorsqu’une fermeture de session est initiée, mais que le nombre de références du jeton n’étant pas zéro, la session ouverte ne peut pas être supprimée. Aucune autre activité initiée par l’utilisateur ne peut se produire. Cet événement peut être interprété comme un événement de fermeture de session.
                    Record Number: 960
                    Source Name: Microsoft-Windows-Security-Auditing
                    Time Written: 20080908053331.531400-000
                    Event Type: Succès de l'audit
                    User:

                    Computer Name: PC-de-sandrine
                    Event Code: 4616
                    Message: L’heure du système a été modifiée.

                    Sujet :
                    ID de sécurité : S-1-5-21-879023170-2910880756-1729088331-1000
                    Nom du compte : sandrine
                    Domaine du compte : PC-de-sandrine
                    ID d’ouverture de session : 0x29d3aa

                    Informations sur le processus :
                    ID du processus : 0x9f0
                    Nom : C:\Windows\System32\dllhost.exe

                    Heure précédente : 02:31:05 08/09/2008
                    Nouvelle heure : 07:30:42 08/09/2008

                    Cet événement est généré lorsque l’heure du système est modifiée. Le changement régulier de l’heure du système est une opération normale de la part du service de temps Windows qui s’exécute avec des privilèges système. Mais, d’autres modifications de l’heure du système peuvent indiquer des tentatives de falsification de l’ordinateur.
                    Record Number: 959
                    Source Name: Microsoft-Windows-Security-Auditing
                    Time Written: 20080908053042.029000-000
                    Event Type: Succès de l'audit
                    User:

                    Computer Name: PC-de-sandrine
                    Event Code: 4616
                    Message: L’heure du système a été modifiée.

                    Sujet :
                    ID de sécurité : S-1-5-21-879023170-2910880756-1729088331-1000
                    Nom du compte : sandrine
                    Domaine du compte : PC-de-sandrine
                    ID d’ouverture de session : 0x29d3aa

                    Informations sur le processus :
                    ID du processus : 0x9f0
                    Nom : C:\Windows\System32\dllhost.exe

                    Heure précédente : 07:30:42 08/09/2008
                    Nouvelle heure : 07:30:42 08/09/2008

                    Cet événement est généré lorsque l’heure du système est modifiée. Le changement régulier de l’heure du système est une opération normale de la part du service de temps Windows qui s’exécute avec des privilèges système. Mais, d’autres modifications de l’heure du système peuvent indiquer des tentatives de falsification de l’ordinateur.
                    Record Number: 958
                    Source Name: Microsoft-Windows-Security-Auditing
                    Time Written: 20080908053042.029000-000
                    Event Type: Succès de l'audit
                    User:

                    Computer Name: PC-de-sandrine
                    Event Code: 1102
                    Message: Le journal d’audit a été effacé.
                    Objet :
                    ID de sécurité : S-1-5-21-879023170-2910880756-1729088331-1000
                    Nom de compte : sandrine
                    Nom de domaine : PC-de-sandrine
                    ID de connexion : 0x29d3aa
                    Record Number: 957
                    Source Name: Microsoft-Windows-Eventlog
                    Time Written: 20080907233823.992800-000
                    Event Type: Succès de l'audit
                    User:

                    ======Environment variables======

                    "ComSpec"=%SystemRoot%\system32\cmd.exe
                    "FP_NO_HOST_CHECK"=NO
                    "OS"=Windows_NT
                    "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\CyberLink\Power2Go\
                    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                    "PROCESSOR_ARCHITECTURE"=x86
                    "TEMP"=%SystemRoot%\TEMP
                    "TMP"=%SystemRoot%\TEMP
                    "USERNAME"=SYSTEM
                    "windir"=%SystemRoot%
                    "PROCESSOR_LEVEL"=6
                    "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
                    "PROCESSOR_REVISION"=0f0d
                    "NUMBER_OF_PROCESSORS"=2
                    "PLATFORM"=MCD
                    "PCBRAND"=Pavilion
                    "OnlineServices"=Services en ligne
                    "USERPART"=E:
                    "SAFEBOOT_OPTION"=NETWORK

                    -----------------EOF-----------------
                    0
                    1. L'ouverture du portable en mode normal semble bloquer au démarrage de Avira.
                      Je vais donc le desinstaller et le reinstaller.
                      0
                      1. Bon, j'ai beau faire et refaire... on dirait qu'une partie du disque n'est pas accessible. Je pense qu'il y a un problème matériel, ou si c'est un virus... il est puissant le type!
                        Il a fallu que je reparte sur une sauvegarde... il plantait au démarrage en mode normal... Pour l'instant, aucun anti-virus, anti malware, ne peut scanner le disque dans sa totalité. Il plante systématiquement au bout d'un moment. J'ai essayé un chkdsk au démarrage. Plantage idem à 13% de l'examen de la surface.
                        Pour moi, je ne vois qu'un problème matériel et donc une réinstall paramètres usine. Je vais conseiller à ma copine de faire une sauvegarde de ses fichiers avant.
                        Pour Internet (il n'affiche aucune page Web), je pense que cela peut venir de Vodafone Lite. Son copain doit brancher une clé 3 G dessus. Je ne vois pas ce qui peut bloquer le changement des paramètres et de l'adresse IP sinon.
                        Affaire à suivre... Si on ne peut faire de scan avec aucun outil, il va être difficile de trouver les raisons de l'infection.
                        Qu'en penses-tu ?
                        Merci beaucoup pour ton aide en tout cas.
                        0
                        1. Contributeur sécurité
                          Pour moi, je ne vois qu'un problème matériel et donc une réinstall paramètres usine


                          bonjour , si c'est vraiment un problème matériel "disque dur" qui lacherait , perso je pense pas que la réinstallation usine règlera le problème , mais bon en réinstallant tu seras fixer si cela réparrer c'est que tu avais une salopperie de planquer sur le pc et que le formatage à supprimé !! sinon il te faudra voir à changer le dd !!!
                          0
                          1. Bonjour,

                            Pour l'instant, j'ai rendu le portable à sa proprietaire qui en avait besoin pour finir un projet écrit. Logiquement, elle me le ramène la semaine prochaine.

                            Je pense qu'il y a plusieurs problèmes avec ce portable :

                            - des logiciels et non des moindre qui ont été mal installés ou desinstallés,
                            - des virus car il a été mal protégés depuis deux ans, d'ailleurs, certains ont été neutralisés grâce au forum, notamment (merci à Xplode)
                            - Et peut être des problèmes matériels sur le disque.

                            De toute façon, pour qu'on n'arrive pas à faire un chk sur un disque, c'est soit parce qu'il a un problème physique, soit parce qu'il y a des virus qui empêchent qu'on vienne les chatouiller (lol... je ne suis pas encore schizo en pensant que les virus informatiques me parlent...mdr).

                            Toutes les idées sont bonnes à prendre. Les log sont sur le forum pour ça et c'est avec le partage de toutes nos petites connaissances, qu'on arrive à bout de ses virus, toujours plus nombreux, toujours plus vicieux.... mais toujours aussi passionnants.
                            Alors merci d'avance pour ton aide et celle des autres. Et à la semaine prochaine peut-être.
                            0
                            Précédent
                            • 1
                            • 2