Spyware'Trj/Agent-LVG

Résolu
pascale -  
 pascale -
Bonjour,



Ce virus a infecté mon PC portable il y a plusieurs mois.
Y a t il un moyen de s'en débarrasser ?
Merci bcp
Pascale

18 réponses

  1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Le premier c'est un installeur d'un faux plugging VLC proposé sur les sites de streaming => https://forum.malekal.com/viewtopic.php?t=29633&start=
    C'est VLC avec plein de PUPs/Adwares.
    A mettre en quarantaine.

    Le second, ce sont des fichiers dans la restauraton du système.
    Donc rien de bien grave.

    Eventuellement faire ça :

    Télécharge AdwCleaner ( d'Xplode ) sur ton bureau.
    Lance le, clique sur [Suppression] puis patiente le temps du scan.
    Une fois le scan fini, un rapport s'ouvrira. Poste moi son contenu dans ta prochaine réponse.

    Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt

    puis :

    - Télécharge http://www.trendsecure.com/portal/fr/_download/HJTInstall.exe ton bureau.
    - Double-clic sur HijackThis
    - Génère un rapport en suivant ces indications :
    - Exécute le et clique sur Do a scan and save log file.
    - Le rapport s'ouvre sur le Bloc-Note
    - Enregistre le sur ton bureau
    - Envoie le sur http://pjjoint.malekal.com
    - Donne le lien pjjoint ici.
    1
  2. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Salut,

    Quels sont les fichiers infectés?
    Tu peux poster le rapport de ton antivirus ?
    0
    1. pascale
       
      Bonjour,
      merci bcp de me répondre .
      compte rendu du , : scan minutieux : (avast)
      fichier infecté : C:\...\VLCSetup.exe

      menace : Win32 :Zango-B (adw)

      Lancé scan au redémarrage : suppression de C: \System volume information\restore
      je vais tester pour voir ce qui va ou pas
      merci de me donner des pistes
      Pascale
      0
  3. pascale
     
    Bien j'ai effectué les procédures indiquées et posté le rapport HijackThis sur pjjiont.malekal.com
    Je ne peux pas copier coller le rapport de AvwCleaner fonction copier coller inopérante, j'ai tenté le le mettre en PJ avec l'autre ?

    Merci encore de cette aide précieuse
    0
    1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
       
      faut donner les liens pjjoint ici.
      0
  4. pascale
     
    Je ne trouve pas comment poster les rapports (désolée) sur le présent forum, j'ai posté sur le site malekal .com ça fonctionne ou pas ?
    Impasse !
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Envoie les rapports sur pjjoint.
    Donne les liens pjjoint ici.
    0
  7. pascale
     
    rapport HIJackThis :
    lien :
    http: //pjjioint.malakal.com/files.php?id=HijackThis_20120130_b5i15h9k9c5

    Merci de me dire ce que je peux faire maintenant
    0
  8. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Désinstalle Windows Live Toolbar.

    Relance HijackThis et coche ces lignes :

    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
    O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [ADMTray.exe] C:\Acer\Empowering Technology\admtray.exe
    O4 - HKLM\..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe -atboottime
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    O4 - HKLM\..\Run: [Expl0rer] Systim32.exe

    ==> clic sur fix checked

    Télécharge et installe Malwarebyte : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
    Mets le à jour, fais un scan rapide, supprime tout et poste le rapport ici.
    !!! Malwarebyte doit être à jour avant de faire le scan !!!
    Supprime bien ce qui est détecté : bouton supprimer sélection.

    ensuite :

    Tu peux suivre les indications de cette page pour t'aider : https://www.malekal.com/tutorial-otl/

    * Télécharge http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/ sur ton bureau.
    (Sous Vista/Win7, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)

    * Lance OTL
    * Sur OTL, sous Personnalisation, copie-colle le script ci-dessous :
    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    drivers32
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %temp%\.exe /s
    %SYSTEMDRIVE%\*.exe
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    wininit.exe
    /md5stop
    HKEY_LOCAL_MACHINE\SYSTEM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters /s
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems /s
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls /s
    CREATERESTOREPOINT
    nslookup www.google.fr /c
    SAVEMBR:0
    hklm\software\clients\startmenuinternet|command /rs
    hklm\software\clients\startmenuinternet|command /64 /rs

    * Clique sur le bouton Analyse.
    * Quand le scan est fini, utilise le site http://pjjoint.malekal.com/ pour envoyer le rapport OTL.txt (et Extra.txt si présent), donne le ou les liens pjjoint qui pointent vers ces rapports ici dans un nouveau message.

    Like the angel you are, you laugh creating a lightness in my chest,
    Your eyes they penetrate me,
    (Your answer's always 'maybe')
    That's when I got up and left
    0
  9. pascale
     
    Merci bcp je ferai ça ce soir ( enfin j'essaierai) et je posterai le rapport
    bonne journée
    Pascale
    0
    1. Pascale
       
      Voici le rapport OTL EXTRA
      OTL Extras logfile created on: 01/02/2012 22:20:30 - Run 1
      OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Pascale Tison\Mes documents\Téléchargements
      Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
      Internet Explorer (Version = 6.0.2900.2180)
      Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

      1022,04 Mb Total Physical Memory | 371,10 Mb Available Physical Memory | 36,31% Memory free
      2,40 Gb Paging File | 1,91 Gb Available in Paging File | 79,65% Paging File free
      Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

      %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
      Drive C: | 44,37 Gb Total Space | 9,74 Gb Free Space | 21,96% Space Free | Partition Type: FAT32
      Drive D: | 44,86 Gb Total Space | 37,51 Gb Free Space | 83,62% Space Free | Partition Type: FAT32

      Computer Name: ACER-6C0BC44289 | User Name: Pascale Tison | Logged in as Administrator.
      Boot Mode: Normal | Scan Mode: Current user
      Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

      [color=#E56717]========== Extra Registry (SafeList) ==========/color


      [color=#E56717]========== File Associations ==========/color

      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
      .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
      .html [@ = ChromeHTML] -- Reg Error: Key error. File not found
      .url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

      [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
      .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

      [color=#E56717]========== Shell Spawning ==========/color

      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
      batfile [open] -- "%1" %*
      cmdfile [open] -- "%1" %*
      comfile [open] -- "%1" %*
      cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
      exefile [open] -- "%1" %*
      http [open] -- Reg Error: Key error.
      https [open] -- Reg Error: Key error.
      InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
      piffile [open] -- "%1" %*
      regfile [merge] -- Reg Error: Key error.
      scrfile [config] -- "%1"
      scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
      scrfile [open] -- "%1" /S
      txtfile [edit] -- Reg Error: Key error.
      Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
      Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
      Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
      Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

      [color=#E56717]========== Security Center Settings ==========/color

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
      "FirstRunDisabled" = 1
      "AntiVirusDisableNotify" = 0
      "FirewallDisableNotify" = 0
      "UpdatesDisableNotify" = 0
      "AntiVirusOverride" = 0
      "FirewallOverride" = 0

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
      "DisableMonitoring" = 1

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
      "DisableMonitoring" = 1

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
      "DisableMonitoring" = 1

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

      [color=#E56717]========== System Restore Settings ==========/color

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
      "DisableSR" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
      "Start" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
      "Start" = 2

      [color=#E56717]========== Firewall Settings ==========/color

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
      "EnableFirewall" = 1
      "DoNotAllowExceptions" = 0
      "DisableNotifications" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
      "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
      "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
      "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
      "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
      "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
      "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

      [color=#E56717]========== Authorized Applications List ==========/color

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe -- (Hewlett-Packard)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\HP Software Update\hpwucli.exe" = C:\Program Files\Hewlett-Packard\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe -- (Hewlett-Packard)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe -- (Hewlett-Packard Co.)

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
      "C:\Program Files\Acer\Acer Arcade\PCMService.exe" = C:\Program Files\Acer\Acer Arcade\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program
      "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" = C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client -- (Veoh Networks)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe -- (Hewlett-Packard)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\HP Software Update\hpwucli.exe" = C:\Program Files\Hewlett-Packard\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe -- (Hewlett-Packard)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager


      [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========/color

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA
      "{05653DE1-6567-40C6-B930-39D399B64369}" = OpenOffice.org 3.3
      "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
      "{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
      "{0CA6047C-D28B-4295-834A-07C52BA20C2D}" = Extension de Windows Live Toolbar (Windows Live Toolbar)
      "{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}" = Menus intelligents (Windows Live Toolbar)
      "{133742BA-6F46-4D3E-85AF-78631D9AD8B8}" = Installation Windows Live
      "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
      "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
      "{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
      "{15B70821-7893-4607-805A-BB80F3EA8279}" = Acer Empowering Technology framework
      "{1EE04769-91C4-4A06-92B7-FCAFE6BABDD9}" = Galerie de photos Windows Live
      "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
      "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Outil de téléchargement Windows Live
      "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
      "{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
      "{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 22
      "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
      "{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
      "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
      "{350C940c-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
      "{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}" = QuickTime
      "{445B183D-F4F1-45C8-B9DB-F11355CA657B}" = Windows Live Messenger
      "{4634B21A-CC07-4396-890C-2B8168661FEA}" = Windows Live Writer
      "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
      "{5546F4E9-B0F4-4F54-B949-2AB006C9284F}" = DJ_AIO_06_F2400_SW_Min
      "{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
      "{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
      "{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
      "{5DD76286-9BE7-4894-A990-E905E91AC818}" = Windows Live Mail
      "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
      "{5EFDFC8B-D438-4792-A298-E87AA9ADA816}" = Acer eDataSecurity Management
      "{60FFB3E0-6D5B-4D73-AE5B-07E58B83AF0C}" = 32 Bit HP CIO Components Installer
      "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
      "{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}" = Acer eLock Management
      "{6DBB66CD-38C7-472C-BBB9-06BFDA182A29}" = F2400
      "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
      "{74DC0593-6BC6-4001-AD5F-D810AFB68D86}" = HP Update
      "{76810709-A7D3-468D-9167-A1780C1E766C}" = Windows Live FolderShare
      "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
      "{819CA3BC-2FF8-4811-B42F-421F7BFD3559}" = HP Deskjet F2400 All-in-One Driver Software 14.0 Rel. 6
      "{81B5F83F-2291-48B0-8375-36B63A9BF5B0}" = Surligneur (Windows Live Toolbar)
      "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
      "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
      "{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
      "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
      "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
      "{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
      "{9028040C-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional avec FrontPage
      "{92636B62-9423-4246-82FE-69E2F4158350}" = LG SyncManager
      "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
      "{9A394342-4A68-4EBA-85A6-55B559F4E700}" = Microsoft .NET Framework 1.1 French Language Pack
      "{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}" = Copy
      "{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
      "{9D6524E6-15CF-4852-BF70-04FE973A3DE1}" = Windows Live Toolbar
      "{9FF9FDF7-F84A-4F99-B4BB-066B6F95F33D}" = Windows Live Contrôle parental
      "{A059DE09-1B49-4450-B340-7AE097EC3F04}" = Microsoft Works
      "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
      "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
      "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype(TM) 5.5
      "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply
      "{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
      "{B3B487E7-6171-4376-9074-B28082CEB504}" = Windows Live Call
      "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
      "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
      "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
      "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
      "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
      "{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management
      "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
      "{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
      "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
      "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
      "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
      "{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}" = Assistant de connexion Windows Live
      "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
      "{D458BBDC-0363-42E0-8FF9-4736E3CB3CA2}" = Acer Screensaver
      "{DEE08946-40F0-4890-853E-60A6C3306041}" = Acer ePerformance Management
      "{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}" = Acer eSettings Management
      "{E431C518-2EE2-471E-9234-BE995C36D513}" = Acer eDataSecurity Management 1.00.23
      "{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
      "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
      "{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
      "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
      "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
      "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
      "{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
      "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
      "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
      "avast" = avast! Free Antivirus
      "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_1025007F" = HDAUDIO Soft Data Fax Modem with SmartCP
      "Defraggler" = Defraggler
      "DivX Setup.divx.com" = Configuration DivX
      "ePresentation" = Acer ePresentation Management
      "GridVista" = Acer GridVista
      "HijackThis" = HijackThis 2.0.2
      "HP Imaging Device Functions" = HP Imaging Device Functions 14.0
      "HP Smart Web Printing" = HP Smart Web Printing 4.60
      "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
      "HPExtendedCapabilities" = HP Customer Participation Program 14.0
      "InstallShield_{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA
      "InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
      "InstallShield_{15B70821-7893-4607-805A-BB80F3EA8279}" = Acer Empowering Technology framework
      "InstallShield_{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}" = QuickTime
      "InstallShield_{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}" = Acer eLock Management
      "InstallShield_{DEE08946-40F0-4890-853E-60A6C3306041}" = Acer ePerformance Management
      "InstallShield_{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}" = Acer eSettings Management
      "LManager" = Launch Manager
      "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
      "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
      "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
      "Mozilla Firefox 9.0.1 (x86 fr)" = Mozilla Firefox 9.0.1 (x86 fr)
      "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
      "Neuf_Kit" = Neuf - Kit de connexion
      "NVIDIA Drivers" = NVIDIA Drivers
      "ProInst" = Logiciel Intel(R) PROSet/Wireless
      "Shop for HP Supplies" = Shop for HP Supplies
      "SynTPDeinstKey" = Synaptics Pointing Device Driver
      "VLC media player" = VideoLAN VLC media player 0.8.6h
      "WIC" = Windows Imaging Component
      "Windows Media Format Runtime" = Windows Media Format 11 runtime
      "Windows Media Player" = Lecteur Windows Media 11
      "WinLiveSuite_Wave3" = Installation Windows Live
      "WMFDist11" = Windows Media Format 11 runtime
      "wmp11" = Windows Media Player 11
      "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

      [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========/color

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "Game Organizer" = EasyBits GO

      [color=#E56717]========== Last 10 Event Log Errors ==========/color

      [ Antivirus Events ]
      Error - 06/11/2009 08:34:37 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 06/11/2009 11:08:17 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 06/11/2009 11:08:20 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 09/11/2009 10:36:34 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 09/11/2009 10:36:34 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 10/11/2009 03:40:04 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 10/11/2009 11:26:58 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 11/12/2009 14:07:06 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 11/12/2009 14:07:06 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 11/12/2009 14:07:25 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      [ Application Events ]
      Error - 10/11/2011 17:32:57 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 10005
      Description = Produit : Windows Live Communications Platform -- Windows Installer
      a rencontré une erreur inattendue lors de l'installation de ce package. Il s'agit
      peut-être d'un problème lié au package. Le code d'erreur est 2762. Les arguments
      sont : , ,

      Error - 11/11/2011 10:23:57 | Computer Name = ACER-6C0BC44289 | Source = Application Error | ID = 1000
      Description = Application défaillante plugin-container.exe, version 8.0.0.4325,
      module défaillant wininet.dll, version 6.0.2900.3698, adresse de défaillance 0x0000c479.

      Error - 13/11/2011 07:30:51 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 11706
      Description = Produit : Microsoft Office XP Professional avec FrontPage -- Erreur
      1706. Le programme d'installation ne peut pas trouver les fichiers requis. Vérifiez
      votre connexion au réseau ou votre lecteur de CD-ROM. Pour des solutions éventuelles
      à ce problème, consultez C:\Program Files\Microsoft Office\Office10\1036\SETUP.HLP.

      Error - 13/11/2011 07:30:57 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 1024
      Description = Produit : Microsoft Office XP Professional avec FrontPage - La mise
      à jour '{10864676-F019-4492-91BC-6A5F68C72840}' n'a pas pu être installée. Code
      d'erreur 1603. Windows Installer peut créer des journaux pour faciliter la résolution
      des éventuelles erreurs d'installation des packages logiciels. Utilisez le lien
      suivant pour afficher des instructions concernant l'activation des journaux : http://go.microsoft.com/fwlink/?LinkId=23127

      Error - 13/11/2011 09:40:09 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 11706
      Description = Produit : Microsoft Office XP Professional avec FrontPage -- Erreur
      1706. Le programme d'installation ne peut pas trouver les fichiers requis. Vérifiez
      votre connexion au réseau ou votre lecteur de CD-ROM. Pour des solutions éventuelles
      à ce problème, consultez C:\Program Files\Microsoft Office\Office10\1036\SETUP.HLP.

      Error - 13/11/2011 09:40:11 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 1024
      Description = Produit : Microsoft Office XP Professional avec FrontPage - La mise
      à jour '{10864676-F019-4492-91BC-6A5F68C72840}' n'a pas pu être installée. Code
      d'erreur 1603. Windows Installer peut créer des journaux pour faciliter la résolution
      des éventuelles erreurs d'installation des packages logiciels. Utilisez le lien
      suivant pour afficher des instructions concernant l'activation des journaux : http://go.microsoft.com/fwlink/?LinkId=23127

      Error - 21/12/2011 04:14:03 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 11905
      Description = Product: NTI Backup NOW! 4 -- Error 1905.Module C:\Program Files\NewTech
      Infosystems\NTI Backup NOW! 4\resSchdlrFr.dll failed to unregister. HRESULT .
      Contact your support personnel.

      Error - 21/12/2011 04:14:05 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 11905
      Description = Product: NTI Backup NOW! 4 -- Error 1905.Module C:\Program Files\NewTech
      Infosystems\NTI Backup NOW! 4\resBunFr.dll failed to unregister. HRESULT . Contact
      your support personnel.

      Error - 30/01/2012 04:10:10 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 11706
      Description = Produit : Microsoft Office XP Professional avec FrontPage -- Erreur
      1706. Le programme d'installation ne peut pas trouver les fichiers requis. Vérifiez
      votre connexion au réseau ou votre lecteur de CD-ROM. Pour des solutions éventuelles
      à ce problème, consultez C:\Program Files\Microsoft Office\Office10\1036\SETUP.HLP.

      Error - 30/01/2012 04:10:23 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 1024
      Description = Produit : Microsoft Office XP Professional avec FrontPage - La mise
      à jour '{10864676-F019-4492-91BC-6A5F68C72840}' n'a pas pu être installée. Code
      d'erreur 1603. Windows Installer peut créer des journaux pour faciliter la résolution
      des éventuelles erreurs d'installation des packages logiciels. Utilisez le lien
      suivant pour afficher des instructions concernant l'activation des journaux : http://go.microsoft.com/fwlink/?LinkId=23127

      [ System Events ]
      Error - 30/01/2012 22:42:32 | Computer Name = ACER-6C0BC44289 | Source = Service Control Manager | ID = 7023
      Description = Le service Gestion d'applications s'est arrêté avec l'erreur : %%126

      Error - 30/01/2012 22:42:32 | Computer Name = ACER-6C0BC44289 | Source = Service Control Manager | ID = 7023
      Description = Le service Gestion d'applications s'est arrêté avec l'erreur : %%126

      Error - 31/01/2012 00:21:27 | Computer Name = ACER-6C0BC44289 | Source = ACPIEC | ID = 327681
      Description = \Device\ACPIEC : Le contrôleur intégré du matériel n'a pas répondu
      dans les délais impartis. Ceci pourrait indiquer une erreur dans le contrôleur
      intégré du matériel ou des logiciels, ou probablement un BIOS mal conçu accédant
      au contrôleur intégré d'une manière non sécurisée. Le pilote du contrôleur intégré
      va tenter à nouveau la transaction non réussie.

      Error - 31/01/2012 00:38:33 | Computer Name = ACER-6C0BC44289 | Source = ACPIEC | ID = 327681
      Description = \Device\ACPIEC : Le contrôleur intégré du matériel n'a pas répondu
      dans les délais impartis. Ceci pourrait indiquer une erreur dans le contrôleur
      intégré du matériel ou des logiciels, ou probablement un BIOS mal conçu accédant
      au contrôleur intégré d'une manière non sécurisée. Le pilote du contrôleur intégré
      va tenter à nouveau la transaction non réussie.

      Error - 31/01/2012 00:41:06 | Computer Name = ACER-6C0BC44289 | Source = ACPIEC | ID = 327681
      Description = \Device\ACPIEC : Le contrôleur intégré du matériel n'a pas répondu
      dans les délais impartis. Ceci pourrait indiquer une erreur dans le contrôleur
      intégré du matériel ou des logiciels, ou probablement un BIOS mal conçu accédant
      au contrôleur intégré d'une manière non sécurisée. Le pilote du contrôleur intégré
      va tenter à nouveau la transaction non réussie.

      Error - 31/01/2012 03:09:29 | Computer Name = ACER-6C0BC44289 | Source = Service Control Manager | ID = 7000
      Description = Le service Cyberlink RichVideo Service(CRVS) n'a pas pu démarrer en
      raison de l'erreur : %%2

      Error - 01/02/2012 13:59:12 | Computer Name = ACER-6C0BC44289 | Source = ACPIEC | ID = 327681
      Description = \Device\ACPIEC : Le contrôleur intégré du matériel n'a pas répondu
      dans les délais impartis. Ceci pourrait indiquer une erreur dans le contrôleur
      intégré du matériel ou des logiciels, ou probablement un BIOS mal conçu accédant
      au contrôleur intégré d'une manière non sécurisée. Le pilote du contrôleur intégré
      va tenter à nouveau la transaction non réussie.

      Error - 01/02/2012 16:43:55 | Computer Name = ACER-6C0BC44289 | Source = sr | ID = 1
      Description = Le filtre de restauration du système à rencontré l'erreur inattendue
      '0xC0000001' pendant le traitement du fichier '' sur le volume 'HarddiskVolume2'.
      Ceci a entraîné l'arrêt de la surveillance du volume.

      Error - 01/02/2012 16:44:24 | Computer Name = ACER-6C0BC44289 | Source = Service Control Manager | ID = 7000
      Description = Le service Cyberlink RichVideo Service(CRVS) n'a pas pu démarrer en
      raison de l'erreur : %%2

      Error - 01/02/2012 16:44:24 | Computer Name = ACER-6C0BC44289 | Source = Service Control Manager | ID = 7026
      Description = Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se
      charger : abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp
      amsint
      asc
      asc3350p
      asc3550
      cbidf
      cd20xrnt
      CmdIde
      Cpqarray
      dac2w2k
      dac960nt
      dpti2o
      hpn
      i2omp
      ini910u
      IntelIde
      mraid35x
      perc2
      perc2hib
      ql1080
      Ql10wnt
      ql12160
      ql1240
      ql1280
      sisagp
      Sparrow
      symc810
      symc8xx
      sym_hi
      sym_u3
      TosIde
      ultra
      viaagp
      ViaIde


      < End of report >
      0
    2. Pascale
       
      Voici le rapport OTL
      OTL Extras logfile created on: 01/02/2012 22:36:46 - Run 1
      OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Pascale Tison\Mes documents\Téléchargements
      Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
      Internet Explorer (Version = 6.0.2900.2180)
      Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

      1022,04 Mb Total Physical Memory | 323,58 Mb Available Physical Memory | 31,66% Memory free
      2,40 Gb Paging File | 1,83 Gb Available in Paging File | 76,26% Paging File free
      Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

      %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
      Drive C: | 44,37 Gb Total Space | 9,74 Gb Free Space | 21,95% Space Free | Partition Type: FAT32
      Drive D: | 44,86 Gb Total Space | 37,51 Gb Free Space | 83,62% Space Free | Partition Type: FAT32

      Computer Name: ACER-6C0BC44289 | User Name: Pascale Tison | Logged in as Administrator.
      Boot Mode: Normal | Scan Mode: Current user
      Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

      [color=#E56717]========== Extra Registry (SafeList) ==========/color


      [color=#E56717]========== File Associations ==========/color

      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
      .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
      .html [@ = ChromeHTML] -- Reg Error: Key error. File not found
      .url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

      [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
      .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

      [color=#E56717]========== Shell Spawning ==========/color

      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
      batfile [open] -- "%1" %*
      cmdfile [open] -- "%1" %*
      comfile [open] -- "%1" %*
      cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
      exefile [open] -- "%1" %*
      http [open] -- Reg Error: Key error.
      https [open] -- Reg Error: Key error.
      InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
      piffile [open] -- "%1" %*
      regfile [merge] -- Reg Error: Key error.
      scrfile [config] -- "%1"
      scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
      scrfile [open] -- "%1" /S
      txtfile [edit] -- Reg Error: Key error.
      Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
      Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
      Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
      Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

      [color=#E56717]========== Security Center Settings ==========/color

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
      "FirstRunDisabled" = 1
      "AntiVirusDisableNotify" = 0
      "FirewallDisableNotify" = 0
      "UpdatesDisableNotify" = 0
      "AntiVirusOverride" = 0
      "FirewallOverride" = 0

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
      "DisableMonitoring" = 1

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
      "DisableMonitoring" = 1

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
      "DisableMonitoring" = 1

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

      [color=#E56717]========== System Restore Settings ==========/color

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
      "DisableSR" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
      "Start" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
      "Start" = 2

      [color=#E56717]========== Firewall Settings ==========/color

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
      "EnableFirewall" = 1
      "DoNotAllowExceptions" = 0
      "DisableNotifications" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
      "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
      "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
      "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
      "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
      "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
      "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

      [color=#E56717]========== Authorized Applications List ==========/color

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe -- (Hewlett-Packard)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\HP Software Update\hpwucli.exe" = C:\Program Files\Hewlett-Packard\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe -- (Hewlett-Packard)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe -- (Hewlett-Packard Co.)

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
      "C:\Program Files\Acer\Acer Arcade\PCMService.exe" = C:\Program Files\Acer\Acer Arcade\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program
      "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" = C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client -- (Veoh Networks)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe -- (Hewlett-Packard)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Hewlett-Packard\HP Software Update\hpwucli.exe" = C:\Program Files\Hewlett-Packard\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe -- (Hewlett-Packard)
      "C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe -- (Hewlett-Packard Co.)
      "C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager


      [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========/color

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA
      "{05653DE1-6567-40C6-B930-39D399B64369}" = OpenOffice.org 3.3
      "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
      "{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
      "{0CA6047C-D28B-4295-834A-07C52BA20C2D}" = Extension de Windows Live Toolbar (Windows Live Toolbar)
      "{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}" = Menus intelligents (Windows Live Toolbar)
      "{133742BA-6F46-4D3E-85AF-78631D9AD8B8}" = Installation Windows Live
      "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
      "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
      "{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
      "{15B70821-7893-4607-805A-BB80F3EA8279}" = Acer Empowering Technology framework
      "{1EE04769-91C4-4A06-92B7-FCAFE6BABDD9}" = Galerie de photos Windows Live
      "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
      "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Outil de téléchargement Windows Live
      "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
      "{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
      "{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java(TM) 6 Update 22
      "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
      "{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
      "{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
      "{350C940c-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
      "{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}" = QuickTime
      "{445B183D-F4F1-45C8-B9DB-F11355CA657B}" = Windows Live Messenger
      "{4634B21A-CC07-4396-890C-2B8168661FEA}" = Windows Live Writer
      "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
      "{5546F4E9-B0F4-4F54-B949-2AB006C9284F}" = DJ_AIO_06_F2400_SW_Min
      "{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
      "{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
      "{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
      "{5DD76286-9BE7-4894-A990-E905E91AC818}" = Windows Live Mail
      "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
      "{5EFDFC8B-D438-4792-A298-E87AA9ADA816}" = Acer eDataSecurity Management
      "{60FFB3E0-6D5B-4D73-AE5B-07E58B83AF0C}" = 32 Bit HP CIO Components Installer
      "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
      "{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}" = Acer eLock Management
      "{6DBB66CD-38C7-472C-BBB9-06BFDA182A29}" = F2400
      "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
      "{74DC0593-6BC6-4001-AD5F-D810AFB68D86}" = HP Update
      "{76810709-A7D3-468D-9167-A1780C1E766C}" = Windows Live FolderShare
      "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
      "{819CA3BC-2FF8-4811-B42F-421F7BFD3559}" = HP Deskjet F2400 All-in-One Driver Software 14.0 Rel. 6
      "{81B5F83F-2291-48B0-8375-36B63A9BF5B0}" = Surligneur (Windows Live Toolbar)
      "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
      "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
      "{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
      "{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
      "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
      "{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
      "{9028040C-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional avec FrontPage
      "{92636B62-9423-4246-82FE-69E2F4158350}" = LG SyncManager
      "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
      "{9A394342-4A68-4EBA-85A6-55B559F4E700}" = Microsoft .NET Framework 1.1 French Language Pack
      "{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}" = Copy
      "{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
      "{9D6524E6-15CF-4852-BF70-04FE973A3DE1}" = Windows Live Toolbar
      "{9FF9FDF7-F84A-4F99-B4BB-066B6F95F33D}" = Windows Live Contrôle parental
      "{A059DE09-1B49-4450-B340-7AE097EC3F04}" = Microsoft Works
      "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
      "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
      "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype(TM) 5.5
      "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply
      "{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
      "{B3B487E7-6171-4376-9074-B28082CEB504}" = Windows Live Call
      "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Click to Call with Skype
      "{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
      "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
      "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
      "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
      "{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management
      "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
      "{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
      "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
      "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
      "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
      "{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}" = Assistant de connexion Windows Live
      "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
      "{D458BBDC-0363-42E0-8FF9-4736E3CB3CA2}" = Acer Screensaver
      "{DEE08946-40F0-4890-853E-60A6C3306041}" = Acer ePerformance Management
      "{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}" = Acer eSettings Management
      "{E431C518-2EE2-471E-9234-BE995C36D513}" = Acer eDataSecurity Management 1.00.23
      "{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
      "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
      "{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
      "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
      "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
      "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
      "{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
      "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
      "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
      "avast" = avast! Free Antivirus
      "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_1025007F" = HDAUDIO Soft Data Fax Modem with SmartCP
      "Defraggler" = Defraggler
      "DivX Setup.divx.com" = Configuration DivX
      "ePresentation" = Acer ePresentation Management
      "GridVista" = Acer GridVista
      "HijackThis" = HijackThis 2.0.2
      "HP Imaging Device Functions" = HP Imaging Device Functions 14.0
      "HP Smart Web Printing" = HP Smart Web Printing 4.60
      "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
      "HPExtendedCapabilities" = HP Customer Participation Program 14.0
      "InstallShield_{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA
      "InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
      "InstallShield_{15B70821-7893-4607-805A-BB80F3EA8279}" = Acer Empowering Technology framework
      "InstallShield_{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}" = QuickTime
      "InstallShield_{6CA897D0-67F5-4F75-8261-DC8BFCA6DA42}" = Acer eLock Management
      "InstallShield_{DEE08946-40F0-4890-853E-60A6C3306041}" = Acer ePerformance Management
      "InstallShield_{E38BC648-883B-4EE5-966C-94C4B7AB3E0B}" = Acer eSettings Management
      "LManager" = Launch Manager
      "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
      "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
      "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
      "Mozilla Firefox 9.0.1 (x86 fr)" = Mozilla Firefox 9.0.1 (x86 fr)
      "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
      "Neuf_Kit" = Neuf - Kit de connexion
      "NVIDIA Drivers" = NVIDIA Drivers
      "ProInst" = Logiciel Intel(R) PROSet/Wireless
      "Shop for HP Supplies" = Shop for HP Supplies
      "SynTPDeinstKey" = Synaptics Pointing Device Driver
      "VLC media player" = VideoLAN VLC media player 0.8.6h
      "WIC" = Windows Imaging Component
      "Windows Media Format Runtime" = Windows Media Format 11 runtime
      "Windows Media Player" = Lecteur Windows Media 11
      "WinLiveSuite_Wave3" = Installation Windows Live
      "WMFDist11" = Windows Media Format 11 runtime
      "wmp11" = Windows Media Player 11
      "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

      [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========/color

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "Game Organizer" = EasyBits GO

      [color=#E56717]========== Last 10 Event Log Errors ==========/color

      [ Antivirus Events ]
      Error - 06/11/2009 08:34:37 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 06/11/2009 11:08:17 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 06/11/2009 11:08:20 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 09/11/2009 10:36:34 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 09/11/2009 10:36:34 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 10/11/2009 03:40:04 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 10/11/2009 11:26:58 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 11/12/2009 14:07:06 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 11/12/2009 14:07:06 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      Error - 11/12/2009 14:07:25 | Computer Name = ACER-6C0BC44289 | Source = avast! | ID = 33554522
      Description =

      [ Application Events ]
      Error - 10/11/2011 17:32:57 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 10005
      Description = Produit : Windows Live Communications Platform -- Windows Installer
      a rencontré une erreur inattendue lors de l'installation de ce package. Il s'agit
      peut-être d'un problème lié au package. Le code d'erreur est 2762. Les arguments
      sont : , ,

      Error - 11/11/2011 10:23:57 | Computer Name = ACER-6C0BC44289 | Source = Application Error | ID = 1000
      Description = Application défaillante plugin-container.exe, version 8.0.0.4325,
      module défaillant wininet.dll, version 6.0.2900.3698, adresse de défaillance 0x0000c479.

      Error - 13/11/2011 07:30:51 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 11706
      Description = Produit : Microsoft Office XP Professional avec FrontPage -- Erreur
      1706. Le programme d'installation ne peut pas trouver les fichiers requis. Vérifiez
      votre connexion au réseau ou votre lecteur de CD-ROM. Pour des solutions éventuelles
      à ce problème, consultez C:\Program Files\Microsoft Office\Office10\1036\SETUP.HLP.

      Error - 13/11/2011 07:30:57 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 1024
      Description = Produit : Microsoft Office XP Professional avec FrontPage - La mise
      à jour '{10864676-F019-4492-91BC-6A5F68C72840}' n'a pas pu être installée. Code
      d'erreur 1603. Windows Installer peut créer des journaux pour faciliter la résolution
      des éventuelles erreurs d'installation des packages logiciels. Utilisez le lien
      suivant pour afficher des instructions concernant l'activation des journaux : http://go.microsoft.com/fwlink/?LinkId=23127

      Error - 13/11/2011 09:40:09 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 11706
      Description = Produit : Microsoft Office XP Professional avec FrontPage -- Erreur
      1706. Le programme d'installation ne peut pas trouver les fichiers requis. Vérifiez
      votre connexion au réseau ou votre lecteur de CD-ROM. Pour des solutions éventuelles
      à ce problème, consultez C:\Program Files\Microsoft Office\Office10\1036\SETUP.HLP.

      Error - 13/11/2011 09:40:11 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 1024
      Description = Produit : Microsoft Office XP Professional avec FrontPage - La mise
      à jour '{10864676-F019-4492-91BC-6A5F68C72840}' n'a pas pu être installée. Code
      d'erreur 1603. Windows Installer peut créer des journaux pour faciliter la résolution
      des éventuelles erreurs d'installation des packages logiciels. Utilisez le lien
      suivant pour afficher des instructions concernant l'activation des journaux : http://go.microsoft.com/fwlink/?LinkId=23127

      Error - 21/12/2011 04:14:03 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 11905
      Description = Product: NTI Backup NOW! 4 -- Error 1905.Module C:\Program Files\NewTech
      Infosystems\NTI Backup NOW! 4\resSchdlrFr.dll failed to unregister. HRESULT .
      Contact your support personnel.

      Error - 21/12/2011 04:14:05 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 11905
      Description = Product: NTI Backup NOW! 4 -- Error 1905.Module C:\Program Files\NewTech
      Infosystems\NTI Backup NOW! 4\resBunFr.dll failed to unregister. HRESULT . Contact
      your support personnel.

      Error - 30/01/2012 04:10:10 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 11706
      Description = Produit : Microsoft Office XP Professional avec FrontPage -- Erreur
      1706. Le programme d'installation ne peut pas trouver les fichiers requis. Vérifiez
      votre connexion au réseau ou votre lecteur de CD-ROM. Pour des solutions éventuelles
      à ce problème, consultez C:\Program Files\Microsoft Office\Office10\1036\SETUP.HLP.

      Error - 30/01/2012 04:10:23 | Computer Name = ACER-6C0BC44289 | Source = MsiInstaller | ID = 1024
      Description = Produit : Microsoft Office XP Professional avec FrontPage - La mise
      à jour '{10864676-F019-4492-91BC-6A5F68C72840}' n'a pas pu être installée. Code
      d'erreur 1603. Windows Installer peut créer des journaux pour faciliter la résolution
      des éventuelles erreurs d'installation des packages logiciels. Utilisez le lien
      suivant pour afficher des instructions concernant l'activation des journaux : http://go.microsoft.com/fwlink/?LinkId=23127

      [ System Events ]
      Error - 30/01/2012 22:42:32 | Computer Name = ACER-6C0BC44289 | Source = Service Control Manager | ID = 7023
      Description = Le service Gestion d'applications s'est arrêté avec l'erreur : %%126

      Error - 30/01/2012 22:42:32 | Computer Name = ACER-6C0BC44289 | Source = Service Control Manager | ID = 7023
      Description = Le service Gestion d'applications s'est arrêté avec l'erreur : %%126

      Error - 31/01/2012 00:21:27 | Computer Name = ACER-6C0BC44289 | Source = ACPIEC | ID = 327681
      Description = \Device\ACPIEC : Le contrôleur intégré du matériel n'a pas répondu
      dans les délais impartis. Ceci pourrait indiquer une erreur dans le contrôleur
      intégré du matériel ou des logiciels, ou probablement un BIOS mal conçu accédant
      au contrôleur intégré d'une manière non sécurisée. Le pilote du contrôleur intégré
      va tenter à nouveau la transaction non réussie.

      Error - 31/01/2012 00:38:33 | Computer Name = ACER-6C0BC44289 | Source = ACPIEC | ID = 327681
      Description = \Device\ACPIEC : Le contrôleur intégré du matériel n'a pas répondu
      dans les délais impartis. Ceci pourrait indiquer une erreur dans le contrôleur
      intégré du matériel ou des logiciels, ou probablement un BIOS mal conçu accédant
      au contrôleur intégré d'une manière non sécurisée. Le pilote du contrôleur intégré
      va tenter à nouveau la transaction non réussie.

      Error - 31/01/2012 00:41:06 | Computer Name = ACER-6C0BC44289 | Source = ACPIEC | ID = 327681
      Description = \Device\ACPIEC : Le contrôleur intégré du matériel n'a pas répondu
      dans les délais impartis. Ceci pourrait indiquer une erreur dans le contrôleur
      intégré du matériel ou des logiciels, ou probablement un BIOS mal conçu accédant
      au contrôleur intégré d'une manière non sécurisée. Le pilote du contrôleur intégré
      va tenter à nouveau la transaction non réussie.

      Error - 31/01/2012 03:09:29 | Computer Name = ACER-6C0BC44289 | Source = Service Control Manager | ID = 7000
      Description = Le service Cyberlink RichVideo Service(CRVS) n'a pas pu démarrer en
      raison de l'erreur : %%2

      Error - 01/02/2012 13:59:12 | Computer Name = ACER-6C0BC44289 | Source = ACPIEC | ID = 327681
      Description = \Device\ACPIEC : Le contrôleur intégré du matériel n'a pas répondu
      dans les délais impartis. Ceci pourrait indiquer une erreur dans le contrôleur
      intégré du matériel ou des logiciels, ou probablement un BIOS mal conçu accédant
      au contrôleur intégré d'une manière non sécurisée. Le pilote du contrôleur intégré
      va tenter à nouveau la transaction non réussie.

      Error - 01/02/2012 16:43:55 | Computer Name = ACER-6C0BC44289 | Source = sr | ID = 1
      Description = Le filtre de restauration du système à rencontré l'erreur inattendue
      '0xC0000001' pendant le traitement du fichier '' sur le volume 'HarddiskVolume2'.
      Ceci a entraîné l'arrêt de la surveillance du volume.

      Error - 01/02/2012 16:44:24 | Computer Name = ACER-6C0BC44289 | Source = Service Control Manager | ID = 7000
      Description = Le service Cyberlink RichVideo Service(CRVS) n'a pas pu démarrer en
      raison de l'erreur : %%2

      Error - 01/02/2012 16:44:24 | Computer Name = ACER-6C0BC44289 | Source = Service Control Manager | ID = 7026
      Description = Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se
      charger : abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp
      amsint
      asc
      asc3350p
      asc3550
      cbidf
      cd20xrnt
      CmdIde
      Cpqarray
      dac2w2k
      dac960nt
      dpti2o
      hpn
      i2omp
      ini910u
      IntelIde
      mraid35x
      perc2
      perc2hib
      ql1080
      Ql10wnt
      ql12160
      ql1240
      ql1280
      sisagp
      Sparrow
      symc810
      symc8xx
      sym_hi
      sym_u3
      TosIde
      ultra
      viaagp
      ViaIde


      < End of report >
      0
    3. Pascale
       
      voici le rapport Malwarebytes
      Malwarebytes Anti-Malware 1.60.1.1000
      www.malwarebytes.org

      Version de la base de données: v2012.02.01.05

      Windows XP Service Pack 2 x86 FAT32
      Internet Explorer 6.0.2900.2180
      Pascale Tison :: ACER-6C0BC44289 [administrateur]

      01/02/2012 21:01:42
      mbam-log-2012-02-01 (21-01-42).txt

      Type d'examen: Examen rapide
      Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
      Options d'examen désactivées: P2P
      Elément(s) analysé(s): 192741
      Temps écoulé: 29 minute(s), 22 seconde(s)

      Processus mémoire détecté(s): 0
      (Aucun élément nuisible détecté)

      Module(s) mémoire détecté(s): 0
      (Aucun élément nuisible détecté)

      Clé(s) du Registre détectée(s): 1
      HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} (Rogue.WinAntiVirus) -> Mis en quarantaine et supprimé avec succès.

      Valeur(s) du Registre détectée(s): 0
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre détecté(s): 2
      HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Mauvais: (1) Bon: (0) -> Mis en quarantaine et réparé avec succès
      HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Mauvais: (1) Bon: (0) -> Mis en quarantaine et réparé avec succès

      Dossier(s) détecté(s): 0
      (Aucun élément nuisible détecté)

      Fichier(s) détecté(s): 2
      C:\WINDOWS\system32\SYSTIM32.EXE (Trojan.Agent) -> Mis en quarantaine et supprimé avec succès.
      C:\WINDOWS\TWAIN_32.EXE (Trojan.Agent) -> Mis en quarantaine et supprimé avec succès.

      (fin)
      0
    4. Pascale
       
      Malekal,
      j'ai donc éffectué ttte la procédure, je te remercie infiniment de me dire si il y a autre chose à faire, pour l'insatnt j'ai consaté que le copié coller fonctionne , pour le reste je verrai demain.
      Merci encore cette aide est infiniment précieuse.
      0
  10. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    le rapport OTL est à mettre sur pjjoint (sinon ils vont être tronqué).
    Là en plus t'as mis que extra.
    0
  11. pascale
     
    D'accord merci je ferai ça ce soir
    bonne journée
    Pascale
    0
  12. pascale
     
    Voici le lien pour le rapport OTL

    http://pjjoint.malekal.com/files.php?id=20120203_z5u6t13c6m12

    Merci encore
    0
    1. pascale
       
      je ne trouve plus le rapport OTL extra ?
      Merci
      0
  13. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Refais le scan..
    0
  14. pascale
     
    Lequel stp ?
    0
    1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
       
      otl..
      0
  15. pascale
     
    Voici le lien du rapport :

    http://pjjoint.malekal.com/files.php?id=20120203_v13i10o13c13e11

    merci
    0
  16. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Relance OTL.
    o sous Personnalisation, copie_colle le contenu du cadre ci dessous (bien prendre :OTL en début).
    Clic Correction, un rapport apparraitra, copie/colle le contenu ici:

    :OTL
    [2012/01/30 11:49:18 | 006,883,584 | ---- | C] () -- C:\WINDOWS\SYSTIM32.EXE
    [2012/01/30 09:04:54 | 006,883,584 | ---- | C] () -- C:\WINDOWS\TEMP.003
    [2012/01/29 17:25:53 | 006,914,048 | ---- | C] () -- C:\WINDOWS\TEMP.002
    [2012/01/23 17:25:19 | 005,275,648 | ---- | C] () -- C:\WINDOWS\TEMP.001
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\WLAN.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\WINSXS.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\TEMP.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\SUN.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\SRCHASST.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\SOFTWA~1.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\SHELLNEW.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\SERVIC~1.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\SECURITY.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\RESOUR~1.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\REPAIR.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\REGIST~1.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\PSS.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\PROVIS~1.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\PREFETCH.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\PEERNET.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\PCHEALTH.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\NVIEW.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\MUI.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\MSAPPS.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\MSAGENT.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\MODEM.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\MINIDUMP.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\MICROS~1.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\MEDIA.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\M115.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\M104.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\M103.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\LHSP.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\LANGIGA.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\LAN.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\JAVA.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\INTEL.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\IME.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\HEWLET~1.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\HELP.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\FIR.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\DRIVER~1.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\DOWNLO~2.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\DEBUG.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\CURSORS.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\CONNEC~1.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\CONFIG.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\CARDREAD.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\CARDBUS.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\APPPATCH.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\ADDINS.EXE
    [2011/09/20 17:29:34 | 006,883,584 | ---- | C] () -- C:\WINDOWS\ACER.EXE


    * redemarre le pc sous windows et poste le rapport ici

    Like the angel you are, you laugh creating a lightness in my chest,
    Your eyes they penetrate me,
    (Your answer's always 'maybe')
    That's when I got up and left
    0
  17. pascale
     
    ======== OTL ==========
    C:\WINDOWS\SYSTIM32.EXE moved successfully.
    C:\WINDOWS\TEMP.003 moved successfully.
    C:\WINDOWS\TEMP.002 moved successfully.
    C:\WINDOWS\TEMP.001 moved successfully.
    C:\WINDOWS\WLAN.EXE moved successfully.
    C:\WINDOWS\WINSXS.EXE moved successfully.
    C:\WINDOWS\TEMP.EXE moved successfully.
    C:\WINDOWS\SUN.EXE moved successfully.
    C:\WINDOWS\SRCHASST.EXE moved successfully.
    C:\WINDOWS\SOFTWA~1.EXE moved successfully.
    C:\WINDOWS\SHELLNEW.EXE moved successfully.
    C:\WINDOWS\SERVIC~1.EXE moved successfully.
    C:\WINDOWS\SECURITY.EXE moved successfully.
    C:\WINDOWS\RESOUR~1.EXE moved successfully.
    C:\WINDOWS\REPAIR.EXE moved successfully.
    C:\WINDOWS\REGIST~1.EXE moved successfully.
    C:\WINDOWS\PSS.EXE moved successfully.
    C:\WINDOWS\PROVIS~1.EXE moved successfully.
    C:\WINDOWS\PREFETCH.EXE moved successfully.
    C:\WINDOWS\PEERNET.EXE moved successfully.
    C:\WINDOWS\PCHEALTH.EXE moved successfully.
    C:\WINDOWS\NVIEW.EXE moved successfully.
    C:\WINDOWS\MUI.EXE moved successfully.
    C:\WINDOWS\MSAPPS.EXE moved successfully.
    C:\WINDOWS\MSAGENT.EXE moved successfully.
    C:\WINDOWS\MODEM.EXE moved successfully.
    C:\WINDOWS\MINIDUMP.EXE moved successfully.
    C:\WINDOWS\MICROS~1.EXE moved successfully.
    C:\WINDOWS\MEDIA.EXE moved successfully.
    C:\WINDOWS\M115.EXE moved successfully.
    C:\WINDOWS\M104.EXE moved successfully.
    C:\WINDOWS\M103.EXE moved successfully.
    C:\WINDOWS\LHSP.EXE moved successfully.
    C:\WINDOWS\LANGIGA.EXE moved successfully.
    C:\WINDOWS\LAN.EXE moved successfully.
    C:\WINDOWS\JAVA.EXE moved successfully.
    C:\WINDOWS\INTEL.EXE moved successfully.
    C:\WINDOWS\IME.EXE moved successfully.
    C:\WINDOWS\HEWLET~1.EXE moved successfully.
    C:\WINDOWS\HELP.EXE moved successfully.
    C:\WINDOWS\FIR.EXE moved successfully.
    C:\WINDOWS\DRIVER~1.EXE moved successfully.
    C:\WINDOWS\DOWNLO~2.EXE moved successfully.
    C:\WINDOWS\DEBUG.EXE moved successfully.
    C:\WINDOWS\CURSORS.EXE moved successfully.
    C:\WINDOWS\CONNEC~1.EXE moved successfully.
    C:\WINDOWS\CONFIG.EXE moved successfully.
    C:\WINDOWS\CARDREAD.EXE moved successfully.
    C:\WINDOWS\CARDBUS.EXE moved successfully.
    C:\WINDOWS\APPPATCH.EXE moved successfully.
    C:\WINDOWS\ADDINS.EXE moved successfully.
    C:\WINDOWS\ACER.EXE moved successfully.

    OTL by OldTimer - Version 3.2.31.0 log created on 02032012_235010
    0
  18. pascale
     
    ci dessus le rapport OTL, ça parait plutot encourageant !!
    merci encore de toute cette aide
    Ya t il encore des manipulations à effectuer ?
    0
  19. pascale
     
    Merci beaucoup tout semble fonctionner désormais.J'ai maintenant le pb de la clé ( 32 GO) sur laquelle j'avais fait des sauvegardes et que je voudrais réutiliser : comment la désinfecter ?
    tout cette aide m'est précieuse autant qu'efficace je tines à t'en remercier chaleureusement
    0
    1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
       
      Faire un scan de la clef avant de l'ouvrir.

      ou utiliser USBFix : https://www.malekal.com/tutoriels-logiciels/
      0
    2. pascale
       
      Merci pour ce conseil je ferai ça demain
      0