Problème avec taquito.exe

Bonsoir,

Voila, j'avais installer Kaspersky security 2010 en version trial pour un essai de 30 jours. Aujourd'hui je l'es désinstallée et a chaque démmarrage du PC j'obtient une fenetre nommée "Propriété de Taquito" il me mets taille: 0 Octets et il y a un bouton restaurer et ok. j'ai fais OK et j'ai redémarrer pour voir et la fenetre revient tout le temps, que faire et que veux dire cette fenetre. MERCI
Configuration: Windows Vista / Internet Explorer 7.0

8 réponses

  1. Contributeur sécurité
    bonjour, regarde sur cette page et utilises l'utilitaire de désinstallation https://www.commentcamarche.net/faq/7367-desinstaller-proprement-liens-et-astuces#kaspersky
    et si cela ne règle pas le problème tu reviens et tu postes un RSIT et on verra si on trouve dessus le problème

    1) Télécharges et installes HijackThis :

    https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/

    Cliques sur le fichier hijackthis téléchargé pour lancer l'installation
    laisses toi guider et ne modifies pas les paramètres d'installation .
    A la fin de l’installation, le programme se lance automatiquement
    fermes le en cliquant sur la croix rouge.

    Ne lances pas ce programme pour l'instant et fais la suite

    2) Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    -> http://images.malwareremoval.com/random/RSIT.exe

    .Déconnectes toi et fermes toutes tes applications en cours

    Double-clique sur " RSIT.exe " pour le lancer.

    Clic droit sous VISTA (exécuter en tant que…)

    .Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    .Devant l'option "List files/folders created ..." , tu choisis : 1 months

    .cliques ensuite sur " Continuer " pour lancer l'analyse

    .laisses faire le scan et ne touches pas au PC

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront

    Postes le contenu de " log.txt " , ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante

    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum ??

    Note : les rapports seront en outre sauvegardés dans ce dossier C:\rsit

    0
    1. log.txt :

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Etienne at 2010-03-01 22:10:43
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
      System drive C: has 73 GB (36%) free of 205 GB
      Total RAM: 2046 MB (42% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 22:10:50, on 01/03/2010
      Platform: Windows Vista SP2 (WinNT 6.00.1906)
      MSIE: Internet Explorer v8.00 (8.00.6001.18882)
      Boot mode: Normal

      Running processes:
      c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\WINDOWS\RtHDVCpl.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
      C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
      C:\Program Files\Microsoft IntelliType Pro\itype.exe
      C:\Program Files\Microsoft IntelliPoint\ipoint.exe
      C:\Program Files\UsbBoost\TurboHddUsb.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Alwil Software\Avast5\AvastUI.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\Program Files\DAEMON Tools Lite\DTLite.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
      C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
      C:\Program Files\eMule\emule.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil10e.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
      C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Users\Etienne\Desktop\RSIT.exe
      C:\Program Files\Trend Micro\HijackThis\Etienne.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.durable.com/recherche
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.durable.com/recherche
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.durable.com/recherche
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.durable.com/recherche
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.durable.com/recherche
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.durable.com/recherche
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: iPhone OS 3 Toolbar - {74714d77-1695-4e73-a98e-25cb374f46b4} - C:\Program Files\iPhone_OS_3\tbiPho.dll
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: iPhone OS 3 Toolbar - {74714d77-1695-4e73-a98e-25cb374f46b4} - C:\Program Files\iPhone_OS_3\tbiPho.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: VeriSoft Access Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
      O3 - Toolbar: iPhone OS 3 Toolbar - {74714d77-1695-4e73-a98e-25cb374f46b4} - C:\Program Files\iPhone_OS_3\tbiPho.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
      O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
      O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll,RegisterModule
      O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
      O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
      O4 - HKLM\..\Run: [UsbBoost] C:\Program Files\UsbBoost\TurboHddUsb.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
      O4 - HKLM\..\Run: [PC Pitstop Optimize Reminder] C:\Program Files\PCPitstop\Optimize3\Reminder-Optimize3.exe
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
      O4 - HKCU\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
      O4 - HKCU\..\Run: [Internet Security Services] c:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Global Startup: BTTray.lnk = ?
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
      O4 - Global Startup: WDSmartWare.lnk = C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
      O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O13 - Gopher Prefix:
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (Ma-Config control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_4_0_1_3.cab
      O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
      O17 - HKLM\System\CCS\Services\Tcpip\..\{E0E2EBA3-503B-4AF0-91BE-6208F54BF662}: NameServer = 192.168.1.1
      O20 - AppInit_DLLs: APSHook.dll
      O23 - Service: Ashampoo CoreTuner Helper Service (acthelper) - Ashampoo Development GmbH & Co. KG - C:\Program Files\Ashampoo\Ashampoo Core Tuner\ACTHelperService.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
      O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
      O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
      O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
      O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
      O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
      0
      1. Pour la Premiere solution il em dit que Kaspersky n'est pas détecter.

        info.txt

        info.txt logfile of random's system information tool 1.06 2010-03-01 22:10:54

        ======Uninstall list======

        -->MsiExec /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}
        32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
        AC3Filter (remove only)-->C:\Program Files\AC3Filter\uninstall.exe
        Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
        Adobe Reader 8.2.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A82000000003}
        Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
        Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
        Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
        Ashampoo Core Tuner 1.20-->"C:\Program Files\Ashampoo\Ashampoo Core Tuner\unins000.exe"
        Ashampoo WinOptimizer 5.13-->"C:\Program Files\Ashampoo\Ashampoo WinOptimizer 5\unins000.exe"
        Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
        AuthenTec Fingerprint Sensor Minimum Install-->MsiExec.exe /I{B61B6668-A674-4A06-8405-51944D5CCDDD}
        avast! Free Antivirus-->C:\Program Files\Alwil Software\Avast5\aswRunDll.exe "C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll" RunSetup
        BackOff 1.02-->"C:\Program Files\DigiDNA\BackOff\unins000.exe"
        BitTorrent-->C:\Program Files\BitTorrent\uninst.exe
        Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
        CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
        DAEMON Tools Toolbar-->C:\Program Files\DAEMON Tools Toolbar\uninst.exe
        Defraggler-->"C:\Program Files\Defraggler\uninst.exe"
        Direct Show Ogg Vorbis Filter (remove only)-->"C:\Windows\system32\OggDSuninst.exe"
        DiskAid 3.11-->"C:\Program Files\DigiDNA\DiskAid\unins000.exe"
        Doom 3-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\Intel 32\IDriver.exe /M{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}
        DVD Decrypter (Remove Only)-->"C:\Program Files\DVD Decrypter\uninstall.exe"
        EBP Comptes Bancaires 2006-->"C:\Program Files\EBP\Comptes Bancaires\unins000.exe"
        eMule-->"C:\Program Files\eMule\Uninstall.exe"
        ESU for Microsoft Vista-->MsiExec.exe /X{DB3AE42A-AAED-49CC-9B87-55A181BCC868}
        FlatOut-->MsiExec.exe /I{A57D86AF-DE8E-4B26-972E-A1A28FFF7742}
        Genie Backup Assistant-->"C:\Program Files\LaCie\Genie Backup Assistant\unins000.exe"
        Glary Utilities 2.20.0.831-->"C:\Program Files\Glary Utilities\unins000.exe"
        Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
        Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
        GPL MPEG-1/2 DirectShow Decoder Filter-->MsiExec.exe /I{870815CA-6B60-47B6-88DD-A67F42D2F03E}
        GTAIII-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{92B94569-6683-4617-8C54-EB27A1B51B30}\Setup.exe" -l0x40c
        Hewlett-Packard Active Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
        Hewlett-Packard Asset Agent-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
        HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
        HP Active Support Library 32 bit components-->MsiExec.exe /I{FAB0C302-CB18-4A7A-BA03-C3DC23101A68}
        HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{290B83AA-093A-45BF-A917-D1C4A1E8D917}\setup.exe -runfromtemp -l0x0409
        HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}\setup.exe" -l0x9 -removeonly
        HP Customer Participation Program 8.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
        HP Doc Viewer-->MsiExec.exe /I{082702D5-5DD8-4600-BCE5-48B15174687F}
        HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40F7AED3-0C7D-4582-99F6-484A515C73F2}\setup.exe" -l0x9 -removeonly
        HP Help and Support-->MsiExec.exe /I{9061CEF2-51F5-42C9-8A70-9ED351C6597A}
        HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
        HP Integrated Module with Bluetooth wireless technology-->MsiExec.exe /X{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}
        HP OCR Software 8.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
        HP Photosmart Essential 2.0-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
        HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
        HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B-->C:\Program Files\HP\Digital Imaging\{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}\setup\hpzscr01.exe -datfile hposcr19.dat -onestop -showdisconnect -forcereboot
        HP Quick Launch Buttons 6.20 B1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x040c uninst
        HP QuickPlay 3.2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\setup.exe" -uninstall
        HP Solution Center 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
        HP Update-->MsiExec.exe /X{818ABC3C-635C-4651-8183-D0E9640B7DD1}
        HP User Guides 0057-->MsiExec.exe /I{DDFD9BA2-8E26-4E49-92AE-882424DAB1BC}
        HP Wireless Assistant-->MsiExec.exe /I{D32067CD-7409-4792-BFA0-1469BCD8F0C8}
        HPSSupply-->MsiExec.exe /X{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}
        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
        Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
        Intel Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
        iPhone_OS_3 Toolbar-->C:\PROGRA~1\iPhone_OS_3\UNWISE.EXE /U C:\PROGRA~1\iPhone_OS_3\INSTALL.LOG
        iTunes-->MsiExec.exe /I{81063354-9060-42B2-A000-1EBE96778AA9}
        Java(TM) 6 Update 18-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
        Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
        LaCie Backup Software v1.7.2893-->MsiExec.exe /I{5967A03E-3B74-4DF1-B591-2D89CA26BDC9}
        Logiciel d'archivage WinRAR-->C:\Program Files\WinRAR\uninstall.exe
        Ma-Config.com-->MsiExec.exe /X{18754BA4-4F0C-4E6E-888B-9496AFA05F43}
        Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
        Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
        Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
        Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
        Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{59E4543A-D49D-4489-B445-473D763C79AF}
        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
        Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
        Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
        Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
        Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
        Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
        Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
        Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
        Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
        Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
        Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
        Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
        Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
        Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
        Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
        Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
        Microsoft Windows Media Video 9 VCM-->RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\wmv9vcm.inf, Uninstall
        Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
        Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
        Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
        Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
        Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
        Motorola SM56 Data Fax Modem-->rundll32.exe sm56co6a.dll,SM56UnInstaller
        MSCU for Microsoft Vista-->MsiExec.exe /X{336A609A-6ECC-4E05-B320-CCC085BF7EA7}
        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
        Need for Speed™ ProStreet-->MsiExec.exe /X{2E1A71D5-7897-4F3F-B0E3-B412C86A646D}
        neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
        NVIDIA Display Control Panel-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe DisplayControlPanel
        NVIDIA Drivers-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe UninstallGUI
        NVIDIA PhysX-->MsiExec.exe /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}
        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
        PC Pitstop Optimize3 3.0-->"C:\Program Files\PCPitstop\Optimize3\unins000.exe"
        PixiePack Codec Pack-->MsiExec.exe /I{9C450606-ED24-4958-92BA-B8940C99D441}
        Quake 4(TM)-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\Intel 32\IDriver.exe /M{152B782A-05F3-48EC-9AAC-4D3EB68D9E20} /l1036
        QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
        RadLight PVA DirectShow filter (remove only)-->"C:\Windows\system32\RadLightPVAUninstall.exe"
        Real Alternative 1.8.0-->"C:\Program Files\Real Alternative\unins000.exe"
        Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
        Roxio Activation Module-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
        Roxio Creator Audio-->MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82}
        Roxio Creator Basic v9-->MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
        Roxio Creator Copy-->MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
        Roxio Creator Data-->MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87}
        Roxio Creator EasyArchive-->MsiExec.exe /I{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}
        Roxio Creator Tools-->MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF}
        Roxio Express Labeler 3-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
        Roxio MyDVD Basic v9-->MsiExec.exe /I{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}
        Safari-->MsiExec.exe /I{46A5D1D1-8956-497C-92FB-59C44EFA6214}
        Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
        Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
        Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
        Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
        Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
        Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
        Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
        SUPER © Version 2010.bld.37 (Jan 2, 2010)-->C:\PROGRA~1\eRightSoft\SUPER\Setup.exe /remove /q0
        Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
        Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
        Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
        Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
        Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
        UsbBoost-->C:\Program Files\UsbBoost\Uninstall.exe
        VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
        VeriSoft Access Manager-->rundll32.exe "c:\Program Files\Bioscrypt\VeriSoft\Bin\SetupHelper.dll",ExecMain /Uninstall {0ABA40AF-288D-41F1-B735-C5155692CD7D}
        Virtual DJ - Atomix Productions-->C:\PROGRA~1\VIRTUA~1\UNWISE.EXE C:\PROGRA~1\VIRTUA~1\INSTALL.LOG
        VLC media player 1.0.5-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        WD SmartWare-->MsiExec.exe /X{CD0DC280-2489-4464-A2FC-16104676394A}
        WhiteCap-->C:\Program Files\SoundSpectrum\WhiteCap\Uninstall.exe
        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
        Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
        Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
        Zattoo 3.3.4 Beta-->C:\Program Files\Zattoo\uninst.exe

        ======Hosts File======

        127.0.0.1 update.bitdefender.com127.0.0.1 update.bitdefender.com

        ======Security center information======

        AV: Bitdefender Antivirus (disabled)
        FW: Bitdefender Firewall (disabled)
        AS: BitDefender AntiSpam (disabled)
        AS: Windows Defender

        ======System event log======

        Computer Name: PC-de-Etienne
        Event Code: 4374
        Message: Windows Servicing a déterminé que ce package KB936330(Service Pack) n’est pas applicable à ce système.
        Record Number: 26738
        Source Name: Microsoft-Windows-Servicing
        Time Written: 20100104112147.000000-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: PC-de-Etienne
        Event Code: 4374
        Message: Windows Servicing a déterminé que ce package KB936330(Service Pack) n’est pas applicable à ce système.
        Record Number: 26733
        Source Name: Microsoft-Windows-Servicing
        Time Written: 20100104112146.000000-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: PC-de-Etienne
        Event Code: 4374
        Message: Windows Servicing a déterminé que ce package KB936330(Service Pack) n’est pas applicable à ce système.
        Record Number: 26731
        Source Name: Microsoft-Windows-Servicing
        Time Written: 20100104112146.000000-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: PC-de-Etienne
        Event Code: 4374
        Message: Windows Servicing a déterminé que ce package KB936330(Service Pack) n’est pas applicable à ce système.
        Record Number: 26724
        Source Name: Microsoft-Windows-Servicing
        Time Written: 20100104112145.000000-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        Computer Name: PC-de-Etienne
        Event Code: 4374
        Message: Windows Servicing a déterminé que ce package KB936330(Service Pack) n’est pas applicable à ce système.
        Record Number: 26723
        Source Name: Microsoft-Windows-Servicing
        Time Written: 20100104112145.000000-000
        Event Type: Avertissement
        User: AUTORITE NT\SYSTEM

        =====Application event log=====

        Computer Name: PC-de-Etienne
        Event Code: 1015
        Message: La connexion au serveur est impossible. Erreur : 0x800401F0
        Record Number: 98
        Source Name: MsiInstaller
        Time Written: 20100103152036.000000-000
        Event Type: Avertissement
        User: PC-de-Etienne\Etienne

        Computer Name: PC-de-Etienne
        Event Code: 1015
        Message: La connexion au serveur est impossible. Erreur : 0x800401F0
        Record Number: 94
        Source Name: MsiInstaller
        Time Written: 20100103152035.000000-000
        Event Type: Avertissement
        User: PC-de-Etienne\Etienne

        Computer Name: PC-de-Etienne
        Event Code: 1015
        Message: La connexion au serveur est impossible. Erreur : 0x800401F0
        Record Number: 89
        Source Name: MsiInstaller
        Time Written: 20100103152026.000000-000
        Event Type: Avertissement
        User: PC-de-Etienne\Etienne

        Computer Name: PC-de-Etienne
        Event Code: 1015
        Message: La connexion au serveur est impossible. Erreur : 0x800401F0
        Record Number: 85
        Source Name: MsiInstaller
        Time Written: 20100103151930.000000-000
        Event Type: Avertissement
        User: PC-de-Etienne\Etienne

        Computer Name: PC-de-Etienne
        Event Code: 101
        Message:
        Record Number: 69
        Source Name: Automatic LiveUpdate Scheduler
        Time Written: 20100103151150.000000-000
        Event Type: Erreur
        User: PC-de-Etienne\Etienne

        =====Security event log=====

        Computer Name: PC-de-Etienne
        Event Code: 4616
        Message: L’heure du système a été modifiée.

        Sujet :
        ID de sécurité : S-1-5-19
        Nom du compte : SERVICE LOCAL
        Domaine du compte : AUTORITE NT
        ID d’ouverture de session : 0x3e5

        Informations sur le processus :
        ID du processus : 0x500
        Nom : C:\WINDOWS\System32\svchost.exe

        Heure précédente : 15:07:11 03/01/2010
        Nouvelle heure : 16:07:16 03/01/2010

        Cet événement est généré lorsque l’heure du système est modifiée. Le changement régulier de l’heure du système est une opération normale de la part du service de temps Windows qui s’exécute avec des privilèges système. Mais, d’autres modifications de l’heure du système peuvent indiquer des tentatives de falsification de l’ordinateur.
        Record Number: 5
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20100103150716.767552-000
        Event Type: Succès de l'audit
        User:

        Computer Name: PC-de-Etienne
        Event Code: 5032
        Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

        Code d’erreur : 2
        Record Number: 4
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20100103140709.884000-000
        Event Type: Échec de l'audit
        User:

        Computer Name: PC-de-Etienne
        Event Code: 5032
        Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

        Code d’erreur : 2
        Record Number: 3
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20100103140709.884000-000
        Event Type: Échec de l'audit
        User:

        Computer Name: PC-de-Etienne
        Event Code: 5032
        Message: Le Pare-feu Windows n’a pas pu notifier l’utilisateur qu’il a empêché une application d’accepter des connexions entrantes sur le réseau.

        Code d’erreur : 2
        Record Number: 2
        Source Name: Microsoft-Windows-Security-Auditing
        Time Written: 20100103140709.884000-000
        Event Type: Échec de l'audit
        User:

        Computer Name: PC-de-Etienne
        Event Code: 1102
        Message: Le journal d’audit a été effacé.
        Objet :
        ID de sécurité : S-1-5-21-4191828767-1039924487-4214550897-1000
        Nom de compte : Etienne
        Nom de domaine : PC-de-Etienne
        ID de connexion : 0xdffb7
        Record Number: 1
        Source Name: Microsoft-Windows-Eventlog
        Time Written: 20100103140548.741800-000
        Event Type: Succès de l'audit
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;c:\Program Files\Bioscrypt\VeriSoft\bin;C:\Program Files\QuickTime\QTSystem\
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
        "PROCESSOR_ARCHITECTURE"=x86
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "USERNAME"=SYSTEM
        "windir"=%SystemRoot%
        "PROCESSOR_LEVEL"=6
        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
        "PROCESSOR_REVISION"=0f0b
        "NUMBER_OF_PROCESSORS"=2
        "PLATFORM"=MCD
        "PCBRAND"=Pavilion
        "OnlineServices"=Services en ligne
        "RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
        "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
        "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

        -----------------EOF-----------------
        0
        1. Contributeur sécurité
          bon il est ici O4 - HKCU\..\Run: [Internet Security Services] c:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
          je vais te donner des lignes que tu vas fixer avec hijackthis, et puis tu passeras les outils que je vais te donner car il y a des choses pas très bonne sur le pc !!

          1) Fixer les lignes

          .Tu fermes tout les programmes ouverts y compris le navigateur. sauf ton anti-virus et pare-feux
          .Lances HijackThis
          .Cliques sur "Do a system scan only"
          .Tu coches les lignes suivantes :
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKCU\..\Run: [Internet Security Services] c:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe


          .Tu cliques sur "Fix Checked"
          .Tu fermes HijackThis

          des expliquations en images : http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm

          2) passes AD-Remover option L

          • Télécharge Ad-remover ( de C_XX ) sur ton bureau :

          https://www.androidworld.fr/

          ! Déconnecte toi et ferme toutes applications en cours !

          • Double clique sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

          • Double-clique sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

          • Au menu principal choisis l'option "L" et tape sur [entrée] .

          • Laisse travailler l'outil et ne touche à rien ...

          --> Poste le rapport qui apparait à la fin , sur le forum ...

          ( Le rapport est sauvegardé sous C:\Ad-report-clean.log )

          ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

          Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

          3) passes usbfix option 2

          • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

          • Telecharges et installes: http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe

          (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

          • Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "éxécuter en tant qu'administrateur" .

          • choisi l'option 2 ( Suppression )

          • Ton bureau disparaitra et le pc redémarrera .

          • Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

          • Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

          • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          Pendant son nettoyage, l'outil a récolté certains fichiers infectieux.
          Nous vous demandons de nous les faire parvenir pour des futures mises à jour, ainsi que pour un meilleur traitement des infections.
          Nous vous remercions pour votre contribution.


          .UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

          Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.

          Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

          Merci d'avance pour ta contribution !!

          0
          1. .
            ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
            .
            Mis à jour par C_XX le 05.02.2010 à 17:34
            Contact: AdRemover.contact@gmail.com
            Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
            .
            Lancé à: 23:10:20, 01/03/2010 | Mode Normal | Option: CLEAN
            Exécuté de: C:\Ad-Remover\
            Système d'exploitation: Microsoft® Windows Vista™ HomePremium Service Pack 2 v6.0.6002
            Nom du PC: PC-DE-ETIENNE | Utilisateur actuel: Etienne
            .
            ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
            .

            (!) -- Fichiers temporaires supprimés.

            .
            HKCU\software\microsoft\internet explorer\searchscopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
            HKLM\Software\Classes\Interface\{DB885111-F39F-4D88-9EE5-C88460B6DF7B}
            .
            ============== Scan additionnel ==============
            .
            .
            * Internet Explorer Version 8.0.6001.18882 *
            .
            [HKEY_CURRENT_USER\..\Internet Explorer\Main]
            .
            Start Page: hxxp://fr.msn.com/
            Do404Search: 01000000
            Local Page: C:\Windows\system32\blank.htm
            Show_ToolBar: yes
            Enable Browser Extensions: yes
            Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            Use Search Asst: no
            Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
            Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
            .
            [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
            .
            Start Page: hxxp://fr.msn.com/
            Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
            Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            Delete_Temp_Files_On_Exit: yes
            Local Page: C:\Windows\System32\blank.htm
            Enable Browser Extensions: yes
            Use Search Asst: no
            Search bar: hxxp://search.msn.com/spbasic.htm
            .
            [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
            .
            Tabs: res://ieframe.dll/tabswelcome.htm
            .
            ============== Suspect (Cracks, Serials, ...) ==============
            .
            C:\Users\Etienne\AppData\Roaming\BitTorrent\Kaspersky 2010 - Crack and Setup Included. No keys needed !.rar.torrent
            C:\Users\Etienne\AppData\Roaming\BitTorrent\Kaspersky IS 2010 v9.0 CRACKED.rar.1.torrent
            C:\Users\Etienne\AppData\Roaming\BitTorrent\Kaspersky IS 2010 v9.0 CRACKED.rar.torrent
            C:\Users\Etienne\AppData\Roaming\BitTorrent\Kaspersky KIS-KAV 2010 Incl-Crack.KeygenMaker.zip.torrent
            C:\Users\Etienne\Desktop\GTA3\GTA 3 game crack noCD.exe
            C:\Users\Etienne\Documents\jeux\doom3\Doom.3.KEYGEN-RELOADED.by.rar
            C:\Users\Etienne\Documents\jeux\doom3\Doom.3.Resurrection.Of.Evil.CRACKFiX-MiNT.infiniti.par.rar
            C:\Users\Etienne\Documents\jeux\doom3\DooM.3.v1.0.NoCD.Crack.by.zip
            C:\Users\Etienne\Documents\jeux\flat out\Flat.Out.NOCD.Crack.(Multi.ITA.ENG.FR.ESP).Finalmente.by.zip
            C:\Users\Etienne\Documents\jeux\gta3\.GTA.3.game.crack.noCD.by.zip
            C:\Users\Etienne\Documents\jeux\quake4\Quake.4.KEYGEN-RELOADED.ShadowCast.rar
            .
            ===================================
            .
            2941 Octet(s) - C:\Ad-Report-CLEAN[1].log
            .
            5 Fichier(s) - C:\Users\Etienne\AppData\Local\Temp
            2 Fichier(s) - C:\Windows\Temp
            0 Fichier(s) - C:\Windows\Prefetch
            .
            18 Fichier(s) - C:\Ad-Remover\BACKUP
            0 Fichier(s) - C:\Ad-Remover\QUARANTINE
            .
            Fin à: 23:13:33 | 01/03/2010 - CLEAN[1]
            .
            ============== E.O.F ==============
            .
            0
            1. ############################## | UsbFix V6.097 |

              User : Etienne (Administrateurs) # PC-DE-ETIENNE
              Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
              Start at: 23:19:31 | 01/03/2010
              Website : http://pagesperso-orange.fr/NosTools/index.html
              Contact : FindyKill.Contact@gmail.com

              Intel(R) Core(TM)2 Duo CPU T7500 @ 2.20GHz
              Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
              Internet Explorer 8.0.6001.18882
              Windows Firewall Status : Enabled
              AV : Bitdefender Antivirus 8.0 [ (!) Disabled | Updated ]
              FW : Bitdefender Firewall[ (!) Disabled ]8.0

              C:\ -> Disque fixe local # 200,49 Go (70,94 Go free) # NTFS
              D:\ -> Disque CD-ROM
              G:\ -> Disque CD-ROM
              H:\ -> Disque fixe local # 931,26 Go (64,91 Go free) [LaCie] # NTFS
              I:\ -> Disque CD-ROM
              J:\ -> Disque CD-ROM
              K:\ -> Disque CD-ROM

              ############################## | Processus actifs |

              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\nvvsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
              C:\Windows\system32\LogonUI.exe
              C:\Windows\system32\nvvsvc.exe
              C:\Windows\System32\spoolsv.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Ashampoo\Ashampoo Core Tuner\ACTHelperService.exe
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\PnkBstrA.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
              C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
              c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe
              C:\Windows\system32\userinit.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Windows\system32\runonce.exe
              C:\Windows\system32\wbem\wmiprvse.exe

              ################## | Elements infectieux |

              Supprimé ! C:\Restore\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
              Supprimé ! C:\Restore\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
              Supprimé ! C:\Restore\S-1-5-21-1482476501-1644491937-682003330-1013
              Supprimé ! C:\$Recycle.Bin\S-1-5-21-1794683373-2906535831-3130477172-500
              Supprimé ! C:\$Recycle.Bin\S-1-5-21-4191828767-1039924487-4214550897-1000
              Supprimé ! H:\autorun.inf
              Supprimé ! H:\._autorun.inf
              Supprimé ! H:\$Recycle.Bin\S-1-5-21-4191828767-1039924487-4214550897-1000

              ################## | Registre |

              Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoClose"
              Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFind"
              Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoRecentDocsHistory"
              Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoRun"
              Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoViewContextMenu"

              ################## | Mountpoints2 |

              Supprimé ! HKCU\...\Explorer\MountPoints2\{53724e8a-f924-11de-b4d1-001a6bf7243f}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{a8a993f4-0628-11df-badd-001a6bf7243f}\Shell\AutoRun\Command

              ################## | Listing des fichiers présent |

              [01/03/2010 23:13|--a------|3280] C:\Ad-Report-CLEAN[1].log
              [11/04/2009 07:36|-rahs----|333257] C:\bootmgr
              [03/01/2010 15:36|--a------|0] C:\DRECOVERY
              [04/01/2010 22:33|--ahs----|16] C:\HPCD.sys
              [04/01/2010 20:07|-rahs----|0] C:\IO.SYS
              [04/01/2010 20:07|-rahs----|0] C:\MSDOS.SYS
              [29/02/2004 16:44|--a------|52576] C:\orange.bmp
              [?|?|?] C:\pagefile.sys
              [04/01/2010 22:33|-r-hs----|20] C:\RCBoot.sys
              [01/03/2010 23:23|--a------|4594] C:\UsbFix.txt
              [04/01/2010 22:28|--a------|43] C:\Writer.ini
              [07/01/2010 14:14|--ahs----|29018] H:\.VolumeIcon.icns
              [07/01/2010 14:14|--ahs----|25214] H:\.VolumeIcon.ico
              [31/01/2010 23:38|--a------|18677726] H:\vlc-1.0.5-win32.exe

              ################## | Vaccination |

              # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
              # H:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

              ################## | Upload |

              Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_PC-de-Etienne.zip : https://www.ionos.fr/?affiliate_id=77097
              Merci pour votre contribution .

              ################## | ! Fin du rapport # UsbFix V6.097 ! |
              0
              1. voici les deux rapport demandés
                0
                1. Contributeur sécurité
                  bonjour, qu'est ce que <tu fais avec une collection de cracks sur ton pc je vois dans le lot kaspersky , et bien si tu télécharges des choses de sécurité cracké ne soit pas trop surpris d'être infecté !!!

                  postes un hijackthis de controle !!

                  0