Ecran bleu analyse avec whocrashed

Bonjour, j'ai fait une analyse avec whocrashed et voila ce que j'ai obtenu quelqu'un c'est se que je dois faire ?

Crash dump directory: C:\Windows\Minidump

Crash dumps are enabled on your computer.

On Thu 29/10/2009 14:41:50 your computer crashed
This was likely caused by the following module: nvlddmkm.sys
Bugcheck code: 0x116 (0x882A4008, 0x8E4BBEB0, 0x0, 0x2)
Error: VIDEO_TDR_ERROR
file path: C:\Windows\system32\drivers\nvlddmkm.sys
product: NVIDIA Windows Kernel Mode Driver, Version 190.62
company: NVIDIA Corporation
description: NVIDIA Windows Kernel Mode Driver, Version 190.62

On Thu 29/10/2009 14:40:26 your computer crashed
This was likely caused by the following module: nvlddmkm.sys
Bugcheck code: 0x1000008E (0xC0000005, 0x8EB6000F, 0x8B3556BC, 0x0)
Error: KERNEL_MODE_EXCEPTION_NOT_HANDLED_M
file path: C:\Windows\system32\drivers\nvlddmkm.sys
product: NVIDIA Windows Kernel Mode Driver, Version 190.62
company: NVIDIA Corporation
description: NVIDIA Windows Kernel Mode Driver, Version 190.62

On Thu 29/10/2009 10:23:46 your computer crashed
This was likely caused by the following module: nvlddmkm.sys
Bugcheck code: 0x116 (0x87723008, 0x8EACB1A0, 0x0, 0x2)
Error: VIDEO_TDR_ERROR
file path: C:\Windows\system32\drivers\nvlddmkm.sys
product: NVIDIA Windows Kernel Mode Driver, Version 190.62
company: NVIDIA Corporation
description: NVIDIA Windows Kernel Mode Driver, Version 190.62

On Thu 29/10/2009 10:16:24 your computer crashed
This was likely caused by the following module: nvlddmkm.sys
Bugcheck code: 0x116 (0x875FC248, 0x8ECC91A0, 0x0, 0x2)
Error: VIDEO_TDR_ERROR
file path: C:\Windows\system32\drivers\nvlddmkm.sys
product: NVIDIA Windows Kernel Mode Driver, Version 190.62
company: NVIDIA Corporation
description: NVIDIA Windows Kernel Mode Driver, Version 190.62

--------------------------------------------------------------------------------
Conclusion
--------------------------------------------------------------------------------

4 crash dumps have been found and analyzed. Note that it's not always possible to state with certainty whether a reported driver is really responsible for crashing your system or that the root cause is in another module. Nonetheless it's suggested you look for updates for the products that these drivers belong to and regularly visit Windows update or enable automatic updates for Windows. In case a piece of malfunctioning hardware is causing trouble, a search with Google on the bug check errors together with the model name and brand of your computer may help you investigate this further.
Configuration: Windows Vista
Firefox 3.0.15

20 réponses

  1. poste le rapport del'option2
    0
    1. ceciest l'option1 fait la 2 comme ceci:
      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

      ▶ Double clic sur le raccourci UsbFix présent sur ton bureau

      ▶ choisi l'option 2 ( Suppression )

      ▶ Ton bureau disparaîtra et le pc redémarrera .

      ▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

      ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .

      ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

      ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

      ▶ /!\ UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.androidworld.fr/

      ▶ Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.

      ▶ Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

      ▶ Merci d'avance pour ta contribution !!
      0
      1. excuse moi j'avais mal lu le voila :

        ############################## | UsbFix V6.046 |

        User : ordi (Administrateurs) # PC-DE-ORDI
        Update on 29/10/2009 by Chiquitine29, C_XX & Chimay8
        Start at: 18:16:07 | 29/10/2009
        Website : http://pagesperso-orange.fr/NosTools/index.html
        Contact : FindyKill.Contact@gmail.com

        AMD Athlon(tm) 64 X2 Dual Core Processor 4000+
        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
        Internet Explorer 7.0.6001.18000
        Windows Firewall Status : Enabled

        C:\ -> Disque fixe local # 458,52 Go (22,13 Go free) [HP] # NTFS
        D:\ -> Disque fixe local # 7,24 Go (965,39 Mo free) [FACTORY_IMAGE] # NTFS
        E:\ -> Disque fixe local # 465,76 Go (284,48 Go free) [NEW_VOLUME] # NTFS
        F:\ -> Disque CD-ROM
        H:\ -> Disque amovible
        I:\ -> Disque amovible
        J:\ -> Disque amovible
        K:\ -> Disque CD-ROM
        L:\ -> Disque CD-ROM
        M:\ -> Disque CD-ROM
        N:\ -> Disque amovible

        ############################## | Processus actifs |

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\nvvsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\nvvsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\spoolsv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\hp\support\hpsysdrv.exe
        C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
        C:\WINDOWS\RtHDVCpl.exe
        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\WINDOWS\System32\rundll32.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
        C:\Program Files\DAEMON Tools Lite\daemon.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Windows\system32\schtasks.exe
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        C:\Windows\system32\ezNTSvc.exe
        C:\Windows\system32\svchost.exe
        c:\Program Files\Common Files\LightScribe\LSSrvc.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\PnkBstrA.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\WUDFHost.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Avira\AntiVir Desktop\update.exe
        C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
        C:\Windows\system32\conime.exe
        C:\hp\kbd\kbd.exe
        c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
        C:\Windows\system32\wuauclt.exe
        C:\Windows\system32\wbem\wmiprvse.exe

        ################## | Fichiers # Dossiers infectieux |

        C:\Windows\system32\autorun.inf

        ################## | Registre # Clés Run infectieuses |

        ################## | Registre # Mountpoints2 |

        HKCU\..\..\Explorer\MountPoints2\{a07daef9-3706-11de-8c7e-001bb9bf6cf4}
        shell\AutoRun\command =K:\autorun.exe

        ################## | Suspect | https://www.virustotal.com/gui/ |

        ################## | Cracks / Keygens / Serials |

        "C:\Users\ordi\kevin\Cossack II\GSC Game World\Cossacks II\crack\C2_PATCH_V1_2.exe"
        20/06/2006 13:52 |Size 39301963 |Crc32 4721e24f |Md5 8c58c37acb6f515a7378378f1649b019

        "C:\Users\ordi\kevin\fallout3\CRACKfollout3\CRACK\FalloutLauncher.exe"
        28/10/2008 16:35 |Size 18552088 |Crc32 5c0691f9 |Md5 9bde0f461f037126db1b820ced98a8f2

        "E:\Medieval total war II\Crack\Medieval 2 Total War NOCD v1.0\medieval2.exe"
        17/12/2008 15:56 |Size 43319336 |Crc32 88f1449f |Md5 9b0ba7313de43a94aac93ffbc2f0b12f

        "E:\Men of war\Crack\mow.exe"
        04/05/2009 23:00 |Size 20844544 |Crc32 1c42e483 |Md5 55dd718cb40995b7422441dbd5354259

        "E:\Men of war\Crack\mow_editor.exe"
        04/05/2009 23:00 |Size 20045824 |Crc32 1809e6b2 |Md5 229a0cc5c5f7cca654040efa1044e9d0

        ################## | ! Fin du rapport # UsbFix V6.046 ! |
        0
        1. ceci est un rapport de smitfraudix et non de usbfix
          fait l'option2 de usbfix
          0
          1. SmitFraudFix v2.424

            Scan done at 17:41:51,71, 29/10/2009
            Run from C:\Users\ordi\Desktop\SmitfraudFix
            OS: Microsoft Windows [version 6.0.6001] - Windows_NT
            The filesystem type is NTFS
            Fix run in normal mode

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\nvvsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\nvvsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\spoolsv.exe
            C:\Program Files\Avira\AntiVir Desktop\sched.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\hp\support\hpsysdrv.exe
            C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
            C:\WINDOWS\RtHDVCpl.exe
            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\WINDOWS\System32\rundll32.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
            C:\Program Files\DAEMON Tools Lite\daemon.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Windows\system32\schtasks.exe
            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            C:\Windows\system32\ezNTSvc.exe
            C:\Windows\system32\svchost.exe
            c:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\PnkBstrA.exe
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\WUDFHost.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\Avira\AntiVir Desktop\update.exe
            C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
            C:\Windows\system32\conime.exe
            C:\hp\kbd\kbd.exe
            c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
            C:\Windows\system32\wuauclt.exe
            C:\Windows\system32\cmd.exe
            C:\Windows\system32\notepad.exe
            C:\Windows\explorer.exe
            C:\Windows\system32\cmd.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ordi

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ordi\AppData\Local\Temp

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ordi\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\ordi\FAVORI~1

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            C:\Program Files\Google\googletoolbar1.dll FOUND !

            »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

            »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
            !!!Attention, following keys are not inevitably infected!!!

            o4Patch
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
            !!!Attention, following keys are not inevitably infected!!!

            IEDFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
            !!!Attention, following keys are not inevitably infected!!!

            Agent.OMZ.Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
            !!!Attention, following keys are not inevitably infected!!!

            VACFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
            !!!Attention, following keys are not inevitably infected!!!

            404Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, following keys are not inevitably infected!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"=""
            "LoadAppInit_DLLs"=dword:00000000

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="C:\\Windows\\system32\\ezShellStart.exe"
            "Windows Shell (ezShellStart)"="C:\\Windows\\system32\\userinit.exe,"

            »»»»»»»»»»»»»»»»»»»»»»»» RK

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: NVIDIA nForce Networking Controller
            DNS Server Search Order: 192.168.1.1

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CCS\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: NameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: NameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: NameServer=192.168.1.1
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

            »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

            »»»»»»»»»»»»»»»»»»»»»»»» End
            0
            1. ▶ tutoriel nettoyage

              ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

              ▶ Double clic sur le raccourci UsbFix présent sur ton bureau

              ▶ choisi l'option 2 ( Suppression )

              ▶ Ton bureau disparaîtra et le pc redémarrera .

              ▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

              ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .

              ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

              ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

              ▶ /!\ UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.androidworld.fr/

              ▶ Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.

              ▶ Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

              ▶ Merci d'avance pour ta contribution !!
              0
              1. voila,

                ############################## | UsbFix V6.046 |

                User : ordi (Administrateurs) # PC-DE-ORDI
                Update on 29/10/2009 by Chiquitine29, C_XX & Chimay8
                Start at: 17:29:16 | 29/10/2009
                Website : http://pagesperso-orange.fr/NosTools/index.html
                Contact : FindyKill.Contact@gmail.com

                AMD Athlon(tm) 64 X2 Dual Core Processor 4000+
                Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                Internet Explorer 7.0.6001.18000
                Windows Firewall Status : Enabled

                C:\ -> Disque fixe local # 458,52 Go (22,26 Go free) [HP] # NTFS
                D:\ -> Disque fixe local # 7,24 Go (965,39 Mo free) [FACTORY_IMAGE] # NTFS
                E:\ -> Disque fixe local # 465,76 Go (284,48 Go free) [NEW_VOLUME] # NTFS
                F:\ -> Disque CD-ROM
                H:\ -> Disque amovible
                I:\ -> Disque amovible
                J:\ -> Disque amovible
                K:\ -> Disque CD-ROM
                L:\ -> Disque CD-ROM
                M:\ -> Disque CD-ROM
                N:\ -> Disque amovible

                ############################## | Processus actifs |

                C:\Windows\System32\smss.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\wininit.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\services.exe
                C:\Windows\system32\lsass.exe
                C:\Windows\system32\lsm.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\nvvsvc.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\winlogon.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\SLsvc.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\nvvsvc.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\spoolsv.exe
                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\hp\support\hpsysdrv.exe
                C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                C:\WINDOWS\RtHDVCpl.exe
                C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                C:\Program Files\Java\jre6\bin\jusched.exe
                C:\WINDOWS\System32\rundll32.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
                C:\Program Files\DAEMON Tools Lite\daemon.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                C:\Windows\system32\schtasks.exe
                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                C:\Windows\system32\ezNTSvc.exe
                C:\Windows\system32\svchost.exe
                c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\PnkBstrA.exe
                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\WUDFHost.exe
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Program Files\Avira\AntiVir Desktop\update.exe
                C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                C:\Windows\system32\wbem\wmiprvse.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                C:\Windows\system32\conime.exe
                C:\hp\kbd\kbd.exe
                c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                C:\Windows\servicing\TrustedInstaller.exe
                C:\Windows\system32\vssvc.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\wbem\wmiprvse.exe
                C:\Windows\system32\wuauclt.exe

                ################## | Fichiers # Dossiers infectieux |

                C:\Windows\system32\autorun.inf

                ################## | Registre # Clés Run infectieuses |

                [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"

                ################## | Registre # Mountpoints2 |

                HKCU\..\..\Explorer\MountPoints2\{a07daef9-3706-11de-8c7e-001bb9bf6cf4}
                shell\AutoRun\command =K:\autorun.exe

                ################## | Suspect | https://www.virustotal.com/gui/ |

                ################## | Cracks / Keygens / Serials |

                "C:\Users\ordi\kevin\Cossack II\GSC Game World\Cossacks II\crack\C2_PATCH_V1_2.exe"
                20/06/2006 13:52 |Size 39301963 |Crc32 4721e24f |Md5 8c58c37acb6f515a7378378f1649b019

                "C:\Users\ordi\kevin\fallout3\CRACKfollout3\CRACK\FalloutLauncher.exe"
                28/10/2008 16:35 |Size 18552088 |Crc32 5c0691f9 |Md5 9bde0f461f037126db1b820ced98a8f2

                "E:\Medieval total war II\Crack\Medieval 2 Total War NOCD v1.0\medieval2.exe"
                17/12/2008 15:56 |Size 43319336 |Crc32 88f1449f |Md5 9b0ba7313de43a94aac93ffbc2f0b12f

                "E:\Men of war\Crack\mow.exe"
                04/05/2009 23:00 |Size 20844544 |Crc32 1c42e483 |Md5 55dd718cb40995b7422441dbd5354259

                "E:\Men of war\Crack\mow_editor.exe"
                04/05/2009 23:00 |Size 20045824 |Crc32 1809e6b2 |Md5 229a0cc5c5f7cca654040efa1044e9d0

                ################## | ! Fin du rapport # UsbFix V6.046 ! |
                0
                1. ▶ Rends-toi à cette adresse afin de télécharger UsbFix (créé par Chiquitine29 & C_XX) :

                  ▶ https://www.androidworld.fr/

                  ▶ Clique sur TÉLÉCHARGER et enregistre-le sur ton bureau.

                  ▶ tutoriel recherche

                  ▶ Double-clique sur UsbFix présent sur ton bureau, l'installation se fera automatiquement

                  ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                  ▶ Choisi l'option 1 (recherche)

                  ▶ Laisse travailler l'outil

                  ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra

                  * Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

                  * Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

                  * Note : "SniffC.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                  Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                  Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                  0
                  1. j'ai redémarrer mon ordinateur et ça marche mais j'ai peur que sa recommence donc je vais suivre tes consigne quand même voila le rapport je n'est pas 2 rapport comme tout a l'heure !

                    Logfile of random's system information tool 1.06 (written by random/random)
                    Run by ordi at 2009-10-29 17:22:27
                    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                    System drive C: has 23 GB (5%) free of 470 GB
                    Total RAM: 3070 MB (67% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 17:22:38, on 29/10/2009
                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                    MSIE: Internet Explorer v7.00 (7.00.6001.18319)
                    Boot mode: Normal

                    Running processes:
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\Explorer.EXE
                    C:\Windows\system32\taskeng.exe
                    C:\Program Files\Windows Defender\MSASCui.exe
                    C:\hp\support\hpsysdrv.exe
                    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                    C:\WINDOWS\RtHDVCpl.exe
                    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                    C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\WINDOWS\System32\rundll32.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
                    C:\Program Files\DAEMON Tools Lite\daemon.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    C:\Windows\system32\schtasks.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                    C:\Windows\system32\conime.exe
                    C:\hp\kbd\kbd.exe
                    C:\Users\ordi\Desktop\antiV.exe
                    E:\hijackhis\ordi.exe
                    C:\Windows\system32\DllHost.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    R3 - Default URLSearchHook is missing
                    F2 - REG:system.ini: UserInit=C:\Windows\system32\ezShellStart.exe
                    O1 - Hosts: ::1 localhost
                    O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                    O2 - BHO: (no name) - {7418E5F5-0E48-4144-8F92-5CA791C82396} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
                    O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
                    O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O2 - BHO: (no name) - {DE713078-8012-4B75-92BA-398D4642A64B} - (no file)
                    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                    O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                    O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
                    O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
                    O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
                    O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
                    O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                    O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                    O9 - Extra button: (no name) - {A573D71B-951B-4BAD-B8CC-708AE84769C9} - (no file)
                    O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                    O13 - Gopher Prefix:
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: NameServer = 192.168.1.1
                    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                    O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\Windows\system32\ezNTSvc.exe
                    O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                    O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                    O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
                    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                    0
                    1. renomme le en ce que tu veux parce que de nos jours les pirates connaisse les moyen de desinfection
                      0
                      1. quand tu dit renomme RSIT c'est a dire ? renommer en quoi ?
                        0
                        1. info.txt logfile of random's system information tool 1.06 2009-10-29 16:49:24

                          ======Uninstall list======

                          -->MsiExec /X{74224F8D-4A17-4816-9EDB-7BB854DE532C}
                          32 Bit HP CIO Components Installer-->MsiExec.exe /I{2614F54E-A828-49FA-93BA-45A3F756BFAA}
                          Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
                          Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
                          ActiveCheck component for HP Active Support Library-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
                          Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
                          Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
                          Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                          Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                          Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
                          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                          Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                          Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
                          BumpTop-->MsiExec.exe /I{9FABFD28-000C-48AB-A0C7-82286B33EFA0}
                          BumpTop-->MsiExec.exe /X{AC28B5E8-B5D6-4917-B686-DED2212926BB}
                          Call of Duty(R) - World at War(TM)-->C:\Program Files\InstallShield Installation Information\{D80A6A73-E58A-4673-AFF5-F12D7110661F}\setup.exe -runfromtemp -l0x040c
                          Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{3BD633E0-4BF8-4499-9149-88F0767D449C}\setup.exe -runfromtemp -l0x0409
                          Call of Duty(R) 4 - Modern Warfare(TM)-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x040c
                          Call of Juarez - Bound in Blood-->C:\Program Files\InstallShield Installation Information\{FEFAF112-4DA8-479C-89E2-7DE25091711A}\setup.exe -runfromtemp -l0x040c
                          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                          Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                          Combat Arms EU-->"C:\ProgramData\NexonEU\NGM\NGM.exe" -mode:uninstall -dll:ngm.nexoneu.com/cbangm/NGM/Bin/NGMDll.dll -game:50340359 -locale:EU
                          Cossacks II-->C:\Users\ordi\kevin\Cossack II\GSC Game World\Cossacks II\uninstall.exe
                          Counter-Strike: Source-->C:\Program Files\Counter-Strike Source\Uninst.exe
                          Crysis(R)-->MsiExec.exe /I{000E79B7-E725-4F01-870A-C12942B7F8E4}
                          EasyBits Magic Desktop-->C:\Windows\system32\ezMDUninstall.exe
                          ESET Online Scanner v3-->C:\Program Files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
                          Eufloria 2.00-->E:\eufloria\Eufloria\Uninstall.exe
                          FallenEarth-->MsiExec.exe /X{82448C0D-FB2A-4E10-9F2C-F404F067A85B}
                          Fallout 3 - The Garden of Eden Creation Kit-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B343B0E3-212A-40B9-8207-1BD299228F5D}\setup.exe" -l0x9 -removeonly
                          Fallout 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{974C4B12-4D02-4879-85E0-61C95CC63E9E}\setup.exe" -l0x40c -removeonly
                          Far Cry 2-->"C:\Program Files\InstallShield Installation Information\{F2835483-37F2-4123-B4FE-0E77D58447F2}\setup.exe" -runfromtemp -l0x040c -removeonly
                          FEARCombat-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{75E607CF-7BAE-4B88-84B3-97F3DF44BA28}\setup.exe" -l0x9 /zU -removeonly
                          FlatOut Ultimate Carnage-->E:\flatout 2\FlatOut Ultimate Carnage\Uninstall.exe
                          Fraps-->"C:\Fraps\uninstall.exe"
                          Free Download Manager 3.0-->"C:\Program Files\Free Download Manager\unins000.exe"
                          Freelancer-->"C:\Program Files\Microsoft Games\Freelancer\UNINSTAL.EXE" /runtemp /addremove
                          Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
                          GameSpy Arcade-->C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG
                          Glary Utilities 2.16.0.758-->"C:\Program Files\Glary Utilities\unins000.exe"
                          Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
                          Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
                          Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
                          Google Earth-->MsiExec.exe /X{3A05B900-A3E7-11DE-A9B7-005056806466}
                          Hearts of Iron III-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D0106CC2-E34B-4FA3-B6B6-91F0ACEA2CC3}\setup.exe" -l0x9
                          HijackThis 2.0.2-->"E:\hijackhis\HijackThis.exe" /uninstall
                          Hitman Blood Money-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A804B134-F03D-4EFD-9BC0-DCD257AA1B22}\setup.exe" -l0xc0c -removeonly
                          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                          HP Active Support Library 32 bit components-->MsiExec.exe /I{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}
                          HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{0A47BAFF-D4FF-4BD3-96CA-02A22EA62722}\setup.exe -runfromtemp -l0x0409
                          HP Advisor-->MsiExec.exe /X{73A43E42-3658-4DD9-8551-FACDA3632538}
                          HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}\setup.exe" -l0x9 -removeonly
                          HP Customer Feedback-->MsiExec.exe /I{9DBA770F-BF73-4D39-B1DF-6035D95268FC}
                          HP Customer Participation Program 9.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
                          HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40F7AED3-0C7D-4582-99F6-484A515C73F2}\setup.exe" -l0x9 -removeonly
                          HP Imaging Device Functions 9.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
                          HP OCR Software 9.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
                          HP On-Screen Cap/Num/Scroll Lock Indicator-->C:\Windows\system32\OsdRemove.exe
                          HP Photosmart All-In-One Software 9.0-->C:\Program Files\HP\Digital Imaging\{D64BC2CF-0F12-47d7-B412-B4F3FD684253}\setup\hpzscr01.exe -datfile hposcr21.dat
                          HP Photosmart Essential 2.01-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
                          HP Picasso Media Center Add-In-->MsiExec.exe /I{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}
                          HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
                          HP Smart Web Printing-->MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7}
                          HP Solution Center 9.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
                          HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
                          HPAsset component for HP Active Support Library-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
                          HPSSupply-->MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
                          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                          Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                          Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216015FF}
                          Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
                          Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
                          K-Lite Codec Pack 2.75 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
                          Le Maître de l'Olympe - Zeus.-->C:\Windows\IsUn040c.exe -f"c:\users\ordi\kevin\Sierra\Le Maître de l' Olympe Zeus\Uninst.isu"
                          Ma-Config.com-->MsiExec.exe /X{425FFD94-36BD-4933-881B-FE0B9DADF2B7}
                          Medieval - Total War - Gold Edition-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A10F7877-4276-416C-9F22-CB56C0CB2700}\setup.exe" -l0x40c -removeonly
                          Medieval II Total War Demo Gold-->C:\Program Files\InstallShield Installation Information\{4A665599-6771-4732-BE74-06B43B9F611B}\setup.exe -runfromtemp -l0x0009 -removeonly
                          Medieval II Total War-->C:\Program Files\InstallShield Installation Information\{C0698BDA-0D29-40EE-8570-A31106DF9AB1}\Setup.exe -runfromtemp -l0x0009 -removeonly
                          Mega Manager-->C:\Program Files\InstallShield Installation Information\{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}\setup.exe -runfromtemp -l0x0009 -removeonly
                          Men of War (Retirer seulement)-->"C:\Program Files\505games\1C\Men of War\unins000.exe"
                          Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
                          Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                          Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                          Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                          Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                          Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                          Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}
                          Microsoft Games for Windows - LIVE-->MsiExec.exe /X{F112F66E-25CA-42DD-983C-6118EB38F606}
                          Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
                          Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                          Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                          Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                          Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                          Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
                          Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
                          Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
                          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                          Microsoft Windows Media Video 9 VCM-->RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\wmv9vcm.inf, Uninstall
                          Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
                          Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                          Mount&Blade-->C:\Users\ordi\kevin\M&B 1.011 copie\Mount&Blade\uninstall.exe
                          Mozilla Firefox (3.0.15)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                          MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
                          muvee autoProducer 6.0-->C:\Program Files\InstallShield Installation Information\{14AF024E-2E3B-49D0-A175-D1C1A06B155A}\setup.exe -runfromtemp -l0x040c -removeonly
                          Nation Red-->MsiExec.exe /I{43757761-174D-4835-AB38-0422F5F050C6}
                          Need for Speed™ SHIFT-->MsiExec.exe /X{BBF0A67B-5DBA-452F-9D2E-6F168BC226E4}
                          Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
                          Neverwinter Nights 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F20C1251-1D0A-4944-B2AE-678581B33B19}\SETUP.exe" -l0x40c -removeonly
                          NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
                          NVIDIA PhysX v8.04.25-->MsiExec.exe /X{74224F8D-4A17-4816-9EDB-7BB854DE532C}
                          NVIDIA PhysX-->MsiExec.exe /X{5DB65884-C963-4454-AABA-4CA3089281FA}
                          NVIDIA Stereoscopic 3D Driver-->"C:\Program Files\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
                          OpenAL-->"C:\Program Files\OpenAL\oalinst.exe" /U
                          Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
                          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                          Outils de diagnostic du matériel-->C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
                          Prototype(TM)-->C:\Program Files\InstallShield Installation Information\{9322A850-9091-4D0E-B252-3E82EDA3D94A}\setup.exe -runfromtemp -l0x040c
                          PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
                          Python 2.5-->MsiExec.exe /I{0A2C5854-557E-48C8-835A-3B9F074BDCAA}
                          Python 2.6.1-->MsiExec.exe /I{9CC89170-000B-457D-91F1-53691F85B223}
                          Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
                          Red Faction Guerrilla-->"C:\Program Files\InstallShield Installation Information\{A357EF4C-2B6F-4980-ACA9-B1E42A74D7F3}\setup.exe" -runfromtemp -l0x040c -removeonly
                          Red Faction Guerrilla-->MsiExec.exe /I{A357EF4C-2B6F-4980-ACA9-B1E42A74D7F3}
                          Revo Uninstaller 1.83-->C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
                          Roxio Activation Module-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
                          Roxio Creator Audio-->MsiExec.exe /X{83FFCFC7-88C6-41c6-8752-958A45325C82}
                          Roxio Creator Basic v9-->MsiExec.exe /X{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
                          Roxio Creator Copy-->MsiExec.exe /X{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
                          Roxio Creator Data-->MsiExec.exe /X{0D397393-9B50-4c52-84D5-77E344289F87}
                          Roxio Creator EasyArchive-->MsiExec.exe /X{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}
                          Roxio Creator Tools-->MsiExec.exe /X{0394CDC8-FABD-4ed8-B104-03393876DFDF}
                          Roxio Express Labeler 3-->MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
                          Roxio MyDVD Basic v9-->MsiExec.exe /X{938B1CD7-7C60-491E-AA90-1F1888168240}
                          Saints Row 2-->"E:\steam\steam.exe" steam://uninstall/9480
                          SAMSUNG Mobile Composite Device Software-->C:\Windows\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
                          SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
                          Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
                          SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
                          SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
                          Samsung PC Studio 3 USB Driver Installer-->"C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -runfromtemp -l0x040c -removeonly
                          Samsung PC Studio 3-->"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -runfromtemp -l0x040c -removeonly
                          Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                          Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                          Sexy Beach 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{950174DD-FA73-448C-BDD3-A86B0F588EE8}\setup.exe" -l0x9 -removeonly
                          Shareaza 2.4.0.0-->"C:\Program Files\Shareaza\Uninstall\unins000.exe"
                          Software Informer 1.0 BETA-->"C:\Program Files\Software Informer\unins000.exe"
                          Solution de clavier multimédia amélioré-->C:\HP\KBD\Install.exe /u
                          Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
                          Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
                          System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
                          TES Construction Set-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Bethesda Softworks\Morrowind\CSUninstall\Setup.exe" -l0x40c
                          True Crime® New York City-->MsiExec.exe /I{C920EFB6-59DB-472D-B445-21821477AD17}
                          Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                          Version de démonstration de Microsoft Office Home and Student 2007-->c:\hp\bin\MSOffice\uninst2.cmd
                          Virtua Tennis 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9B63540D-D942-4C38-B42E-A48AE0145970}\setup.exe" -l0x40c -removeonly
                          WhoCrashed 1.01-->"C:\Program Files\WhoCrashed\unins000.exe"
                          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                          Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                          Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
                          Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                          Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
                          Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
                          Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
                          Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                          Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
                          Wings 3D 0.99.04a-->C:\Program Files\wings3d_0.99.04a\Uninstall.exe
                          World of Battles-->"C:\Program Files\InstallShield Installation Information\{D7FD3F44-5AF4-441C-A476-1C514B69A20D}\setup.exe" -runfromtemp -l0x0009 -removeonly
                          Xfire (remove only)-->"C:\Program Files\Xfire\uninst.exe"

                          ======Security center information======

                          AS: Windows Defender (disabled)

                          ======System event log======

                          Computer Name: PC-de-ordi
                          Event Code: 7001
                          Message: Le service Service Liste des réseaux dépend du service Connaissance des emplacements réseau qui n'a pas pu démarrer en raison de l'erreur :
                          Le service n'a pas été démarré.
                          Record Number: 330370
                          Source Name: Service Control Manager
                          Time Written: 20091029151532.000000-000
                          Event Type: Erreur
                          User:

                          Computer Name: PC-de-ordi
                          Event Code: 7001
                          Message: Le service Service Liste des réseaux dépend du service Connaissance des emplacements réseau qui n'a pas pu démarrer en raison de l'erreur :
                          Le service n'a pas été démarré.
                          Record Number: 330371
                          Source Name: Service Control Manager
                          Time Written: 20091029151532.000000-000
                          Event Type: Erreur
                          User:

                          Computer Name: PC-de-ordi
                          Event Code: 7024
                          Message: Le service Connaissance des emplacements réseau s'est arrêté avec l'erreur service particulière 3221226008 (0xC0000218).
                          Record Number: 330373
                          Source Name: Service Control Manager
                          Time Written: 20091029151532.000000-000
                          Event Type: Erreur
                          User:

                          Computer Name: PC-de-ordi
                          Event Code: 7001
                          Message: Le service Service Liste des réseaux dépend du service Connaissance des emplacements réseau qui n'a pas pu démarrer en raison de l'erreur :
                          Opération réussie.
                          Record Number: 330374
                          Source Name: Service Control Manager
                          Time Written: 20091029151532.000000-000
                          Event Type: Erreur
                          User:

                          Computer Name: PC-de-ordi
                          Event Code: 7024
                          Message: Le service Connaissance des emplacements réseau s'est arrêté avec l'erreur service particulière 3221226008 (0xC0000218).
                          Record Number: 330376
                          Source Name: Service Control Manager
                          Time Written: 20091029151532.000000-000
                          Event Type: Erreur
                          User:

                          =====Application event log=====

                          Computer Name: PC-de-ordi
                          Event Code: 8193
                          Message: Échec de la création d’un point de restauration sur le volume (Processus = C:\Windows\system32\msiexec.exe /V ; Description = Removed 32 Bit HP CIO Components Installer ; Hr = 0x8007043c).
                          Record Number: 202615
                          Source Name: System Restore
                          Time Written: 20091029145240.000000-000
                          Event Type: Erreur
                          User:

                          Computer Name: PC-de-ordi
                          Event Code: 6000
                          Message: L’abonné aux notifications Winlogon <GPClient> n’était pas disponible pour traiter un événement de notification.
                          Record Number: 202620
                          Source Name: Microsoft-Windows-Winlogon
                          Time Written: 20091029151050.000000-000
                          Event Type: Avertissement
                          User:

                          Computer Name: PC-de-ordi
                          Event Code: 6000
                          Message: L’abonné aux notifications Winlogon <GPClient> n’était pas disponible pour traiter un événement de notification.
                          Record Number: 202623
                          Source Name: Microsoft-Windows-Winlogon
                          Time Written: 20091029151051.000000-000
                          Event Type: Avertissement
                          User:

                          Computer Name: PC-de-ordi
                          Event Code: 6000
                          Message: L’abonné aux notifications Winlogon <GPClient> n’était pas disponible pour traiter un événement de notification.
                          Record Number: 202627
                          Source Name: Microsoft-Windows-Winlogon
                          Time Written: 20091029151410.000000-000
                          Event Type: Avertissement
                          User:

                          Computer Name: PC-de-ordi
                          Event Code: 4609
                          Message: Le système d'événements de COM+ a détecté un code de renvoi erroné lors de son traitement interne. Le HRESULT est 8007043c à partir de la ligne 45 de d:\vistasp1_gdr\com\complus\src\events\tier1\eventsystemobj.cpp. Contactez les services de support technique Microsoft pour signaler cette erreur.
                          Record Number: 202630
                          Source Name: Microsoft-Windows-EventSystem
                          Time Written: 20091029151442.000000-000
                          Event Type: Erreur
                          User:

                          =====Security event log=====

                          Computer Name: PC-de-ordi
                          Event Code: 4907
                          Message: Les paramètres d’audit sur l’objet ont changé.

                          Sujet :
                          ID de sécurité : S-1-5-18
                          Nom du compte : PC-DE-ORDI$
                          Domaine du compte : WORKGROUP
                          ID d’ouverture de session : 0x3e7

                          Objet :
                          Serveur de l’objet : Security
                          Type d’objet : File
                          Nom de l’objet : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\UninstallMembership.sql
                          ID du handle : 0x14

                          Informations sur le processus :
                          ID du processus : 0x1690
                          Nom du processus : C:\WINDOWS\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

                          Paramètres d’audit :
                          Descripteur de sécurité d’origine : S:AI
                          Nouveau descripteur de sécurité :
                          Record Number: 42729
                          Source Name: Microsoft-Windows-Security-Auditing
                          Time Written: 20090802074230.915640-000
                          Event Type: Succès de l'audit
                          User:

                          Computer Name: PC-de-ordi
                          Event Code: 4907
                          Message: Les paramètres d’audit sur l’objet ont changé.

                          Sujet :
                          ID de sécurité : S-1-5-18
                          Nom du compte : PC-DE-ORDI$
                          Domaine du compte : WORKGROUP
                          ID d’ouverture de session : 0x3e7

                          Objet :
                          Serveur de l’objet : Security
                          Type d’objet : File
                          Nom de l’objet : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state_perf.h
                          ID du handle : 0x14

                          Informations sur le processus :
                          ID du processus : 0x1690
                          Nom du processus : C:\WINDOWS\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

                          Paramètres d’audit :
                          Descripteur de sécurité d’origine :
                          Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
                          Record Number: 42730
                          Source Name: Microsoft-Windows-Security-Auditing
                          Time Written: 20090802074230.931240-000
                          Event Type: Succès de l'audit
                          User:

                          Computer Name: PC-de-ordi
                          Event Code: 4907
                          Message: Les paramètres d’audit sur l’objet ont changé.

                          Sujet :
                          ID de sécurité : S-1-5-18
                          Nom du compte : PC-DE-ORDI$
                          Domaine du compte : WORKGROUP
                          ID d’ouverture de session : 0x3e7

                          Objet :
                          Serveur de l’objet : Security
                          Type d’objet : File
                          Nom de l’objet : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll
                          ID du handle : 0x14

                          Informations sur le processus :
                          ID du processus : 0x1690
                          Nom du processus : C:\WINDOWS\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

                          Paramètres d’audit :
                          Descripteur de sécurité d’origine :
                          Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
                          Record Number: 42731
                          Source Name: Microsoft-Windows-Security-Auditing
                          Time Written: 20090802074230.978040-000
                          Event Type: Succès de l'audit
                          User:

                          Computer Name: PC-de-ordi
                          Event Code: 4907
                          Message: Les paramètres d’audit sur l’objet ont changé.

                          Sujet :
                          ID de sécurité : S-1-5-18
                          Nom du compte : PC-DE-ORDI$
                          Domaine du compte : WORKGROUP
                          ID d’ouverture de session : 0x3e7

                          Objet :
                          Serveur de l’objet : Security
                          Type d’objet : File
                          Nom de l’objet : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll
                          ID du handle : 0x14

                          Informations sur le processus :
                          ID du processus : 0x1690
                          Nom du processus : C:\WINDOWS\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

                          Paramètres d’audit :
                          Descripteur de sécurité d’origine :
                          Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
                          Record Number: 42732
                          Source Name: Microsoft-Windows-Security-Auditing
                          Time Written: 20090802074231.024840-000
                          Event Type: Succès de l'audit
                          User:

                          Computer Name: PC-de-ordi
                          Event Code: 4907
                          Message: Les paramètres d’audit sur l’objet ont changé.

                          Sujet :
                          ID de sécurité : S-1-5-18
                          Nom du compte : PC-DE-ORDI$
                          Domaine du compte : WORKGROUP
                          ID d’ouverture de session : 0x3e7

                          Objet :
                          Serveur de l’objet : Security
                          Type d’objet : File
                          Nom de l’objet : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen.exe
                          ID du handle : 0x14

                          Informations sur le processus :
                          ID du processus : 0x1690
                          Nom du processus : C:\WINDOWS\winsxs\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.0.6002.18005_none_0b4ada54c46c45b0\poqexec.exe

                          Paramètres d’audit :
                          Descripteur de sécurité d’origine :
                          Nouveau descripteur de sécurité : S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
                          Record Number: 42733
                          Source Name: Microsoft-Windows-Security-Auditing
                          Time Written: 20090802074231.071640-000
                          Event Type: Succès de l'audit
                          User:

                          ======Environment variables======

                          "ComSpec"=%SystemRoot%\system32\cmd.exe
                          "FP_NO_HOST_CHECK"=NO
                          "NUMBER_OF_PROCESSORS"=2
                          "OnlineServices"=Services en ligne
                          "OS"=Windows_NT
                          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\hp\bin\python;C:\Program Files\Common Files\Roxio Shared\DLLShared\;c:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\"C:\Python26"\C:\Program Files\Common Files\Autodesk Shared\;C:\Program Files\backburner 2\;C:Games;C:\Program Files\Samsung\Samsung PC Studio 3\
                          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                          "PCBRAND"=Pavilion
                          "PLATFORM"=HPD
                          "PROCESSOR_ARCHITECTURE"=x86
                          "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
                          "PROCESSOR_LEVEL"=15
                          "PROCESSOR_REVISION"=6b01
                          "RoxioCentral"=c:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
                          "TEMP"=%SystemRoot%\TEMP
                          "TMP"=%SystemRoot%\TEMP
                          "USERNAME"=SYSTEM
                          "windir"=%SystemRoot%
                          "SAFEBOOT_OPTION"=NETWORK

                          -----------------EOF-----------------

                          Logfile of random's system information tool 1.06 (written by random/random)
                          Run by ordi at 2009-10-29 16:49:08
                          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                          System drive C: has 26 GB (6%) free of 470 GB
                          Total RAM: 3070 MB (76% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 16:49:21, on 29/10/2009
                          Platform: Windows Vista SP1 (WinNT 6.00.1905)
                          MSIE: Internet Explorer v7.00 (7.00.6001.18319)
                          Boot mode: Safe mode with network support

                          Running processes:
                          C:\Windows\Explorer.EXE
                          C:\WINDOWS\System32\WerFault.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          E:\memtest\memtest.exe
                          C:\Program Files\WhoCrashed\whocrashed.exe
                          C:\Users\ordi\Desktop\RSIT.exe
                          E:\hijackhis\ordi.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          R3 - Default URLSearchHook is missing
                          F2 - REG:system.ini: UserInit=C:\Windows\system32\ezShellStart.exe
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                          O2 - BHO: (no name) - {7418E5F5-0E48-4144-8F92-5CA791C82396} - (no file)
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
                          O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
                          O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                          O2 - BHO: (no name) - {DE713078-8012-4B75-92BA-398D4642A64B} - (no file)
                          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                          O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                          O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                          O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                          O4 - HKLM\..\RunOnce: [NVStereoReg] "C:\Program Files\NVIDIA Corporation\3D Vision\nvstreg.exe" "C:\Program Files\NVIDIA Corporation\3D Vision\nvstdef.reg" "C:\Program Files\NVIDIA Corporation\3D Vision\oglstreg.reg"
                          O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
                          O4 - HKLM\..\RunOnce: [NvExportOEMDefaults] RUNDLL32.EXE C:\Windows\system32\NVCPL.DLL,ExportOEMDefaults
                          O4 - HKLM\..\RunOnce: [NvRegisterMCTray] RUNDLL32.EXE C:\Windows\system32\NVMCTRAY.DLL,NvMCRegisterApp C:\Windows\system32\NvCpl.dll
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
                          O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
                          O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
                          O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
                          O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
                          O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                          O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                          O9 - Extra button: (no name) - {A573D71B-951B-4BAD-B8CC-708AE84769C9} - (no file)
                          O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                          O13 - Gopher Prefix:
                          O17 - HKLM\System\CCS\Services\Tcpip\..\{552352EB-B208-4767-AE7A-7D0E4550D8CE}: NameServer = 192.168.1.1
                          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\Windows\system32\ezNTSvc.exe
                          O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                          O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                          O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                          O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                          O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                          O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                          O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
                          O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                          0
                          1. c'est marquer listing event logs et sa ne bouge pas
                            0
                            1. ok donc maintenant c'est l'heure de résoudre cela fais ceci:

                              ▶ Télécharge Random's System Information Tool (RSIT).

                              ▶ Un tutoriel sera à ta disposition pour l'installer et l'utiliser correctement.

                              ▶ Double clique sur RSIT.exe pour lancer l'outil.

                              ▶ Clique sur 'Continue' à l'écran Disclaimer.

                              ▶ Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

                              ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports.

                              ( C:\RSIT\log.txt et C:\RSIT\info.txt )

                              CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller

                              Comment héberger les rapports trop longs de RSIT ??
                              0
                              1. oui j'y suis et je fais un memtest en ce moment
                                0
                                1. il démarre mais il y a l'écran bleu et après il redémarre et j'arrive a l'écran ou l'on doit choisir mode sans échec ,etc... .
                                  0
                                  1. bonjour le pc demarre t'il normalement ou il est impossible de faire qoique ce soit?
                                    0