TrojanDownloader:Win32/

Bonjour,
Problème ce matin avec mon Windows Defender qui a détecté la présence du cheval de troie TrojanDownloader:Win32 mais qui ne parvient pas à le neutraliser - message d'erreur 0X80508021 et qui me demande de télécharger les dermières mises à jour (mais justement, depuis qq tps mon ordi ne parvient plus à télécharger les mises à jour de Vista...)-
Par ailleurs mon parefeu Comodo et mon Spywareblaster semblent complètement OUT puisqu'ils ne répondent plus à rien, ni lancement ni désinstallation (message d'erreur code 5)
Que faire?

Voici le rapport Hijackthis que je viens d'effectuer (en espérant qu'il soit complet):

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:21:17, on 27/11/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Users\Emma\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y722JFH9\HiJackThis[1].exe
C:\Users\Emma\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IXBYZDRV\HiJackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Emma\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.apexchange.com
O15 - Trusted Zone: https://www.rivesparis.banquepopulaire.fr/portailinternet/Pages/default.aspx
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_1_0.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9325 bytes

Help me if you can...

Jolem
Configuration: Windows Vista Internet Explorer 7.0

36 réponses

Résumé de la discussion

Le système signale la détection par Windows Defender d'un TrojanDownloader:Win32 et l'erreur 0x80508021, tandis que les mises à jour de Windows Vista échouent et que le pare-feu Comodo et SpywareBlaster ne répondent plus. Des liens de résolution évoquent des guides pour résoudre les échecs des mises à jour et recommander Windows Update manuel, avec Microsoft Support pour actualiser Internet Explorer. D'autres réponses suggèrent l'usage d'outils comme CCleaner et des vérifications basiques (nettoyage de la racine du disque C et élimination d'éléments soupçonnés), sans conclure à une solution immédiate. En complément utile, la discussion rappelle que l'échec des mises à jour peut laisser des composants de sécurité vulnérables et que le nettoyage doit être suivi d'une mise à jour des outils.

Bobot (l’IA à votre service)
  1. Bonjour,

    Fait ceci;

    ▶ Télécharge TOOLBAR S&D ( de Eric_71/Team IDN ) sur ton bureau :

    !! Déconnecte toi,desactive tes protections résidentes, et ferme toutes tes applications en cours le temps de la manip. !!

    ▶ Double-clique sur ToolBar SD.exe pour lancer l'outil et laisse toi guider ...

    ▶ option recherche puis [Entrée].

    Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse

    ( le rapport est en outre sauvegardé ici -> C:\TB.txt )

    Tutoriel
    0
    1. Bonjour Helper-Mask,

      Merci de ton aide mais après avoir téléchargé la toolbar que tu m'indiques, il m'est impossible de l'ouvrir: j'ai bien fermé toutes mes applications mais le message d'erreur suivant s'inscrit: " Windows ne trouve pas C:\Toolbar SD\ToolbarSD.cmd. Vérifiez que vous avez entré le nom correct puis réessayez'...
      Que dois-je faire?
      0
      1. => Désactive le « contrôle des comptes utilisateurs = UAC »

        (tu le réactiveras après ta désinfection): Ne pas oublier !!

        Désactiver l'UAC est nécessaire pour pouvoir faire fonctionner certains programmes sous Vista.

        - Vas dans Démarrer puis panneau de configuration
        - Double Clique sur l'icône "Comptes d'utilisateurs"
        - Clique ensuite sur désactiver et valide.

        ==>NOTE:

        => Avant tout emploi de logiciel, s’assurer que les protections de registres tel que le Tea Timer de spybot sont désactivées (notamment lors de l’emploi d’HijackThis)
        Spybot => mode avancé => outils => résident

        Décocher la case résident "tea timer"

        Refermer Spybot.

        Et ressaye la manip' ;))

        0
        1. Voilà:
          Ce matin j'ai donc réussi à lancer la toolbar, voici le rapport:

          -----------\\ ToolBar S&D 1.2.9 XP/Vista

          Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
          X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz )
          BIOS : Default System BIOS
          USER : Emma ( Administrator )
          BOOT : Normal boot
          Firewall : COMODO Firewall 3.5 (Activated)
          C:\ (Local Disk) - NTFS - Total:137 Go (Free:74 Go)
          D:\ (Local Disk) - NTFS - Total:11 Go (Free:1 Go)
          E:\ (CD or DVD)

          "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
          Option : [1] ( 28/11/2009|11:22 )

          [ UAC => 0 ]

          -----------\\ Recherche de Fichiers / Dossiers ...

          C:\Program Files\AskSBar
          C:\Program Files\AskSBar\bar
          C:\Program Files\AskSBar\bar\1.bin
          C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.JAR
          C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.MANIFEST
          C:\Program Files\AskSBar\bar\1.bin\A2HIGHIN.EXE
          C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.JAR
          C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.MANIFEST
          C:\Program Files\AskSBar\bar\1.bin\A2PLUGIN.DLL
          C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
          C:\Program Files\AskSBar\bar\1.bin\NPASKSBR.DLL

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Start Page"="https://www.google.com/?gws_rd=ssl"
          "Local Page"="C:\\Windows\\system32\\blank.htm"
          "Search Page"="https://www.google.com/?gws_rd=ssl"
          "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
          "Start Page Redirect Cache"="https://www.msn.com/fr-fr?ocid=iehp"
          "Url"="https://www.msn.com/fr-fr/actualite/"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Start Page"="https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF"
          "Default_Page_URL"="https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF"
          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
          "Local Page"="C:\\Windows\\System32\\blank.htm"

          --------------------\\ Recherche d'autres infections

          Aucune autre infection trouvée !

          [ UAC => 1 ]

          1 - "C:\ToolBar SD\TB_1.txt" - 28/11/2009|10:51 - Option : [1]
          2 - "C:\ToolBar SD\TB_2.txt" - 28/11/2009|10:52 - Option : [1]
          3 - "C:\ToolBar SD\TB_3.txt" - 28/11/2009|11:23 - Option : [1]

          -----------\\ Fin du rapport a 11:23:16,08

          C'est grave, docteur? ;-)
          0
          1. ▶ Relance Toolbar-S&D en double-cliquant sur le raccourci

            ▶ Tape sur "2" puis valide en appuyant sur "Entrée".

            ! Ne ferme pas la fenêtre lors de la suppression !

            Un rapport sera généré,

            ▶ poste son contenu ici.

            NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
            Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
            Tape explorer puis valide.

            0
            1. Mission accomplie. Rapport:

              -----------\\ ToolBar S&D 1.2.9 XP/Vista

              Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
              X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz )
              BIOS : Default System BIOS
              USER : Emma ( Administrator )
              BOOT : Normal boot
              Firewall : COMODO Firewall 3.5 (Activated)
              C:\ (Local Disk) - NTFS - Total:137 Go (Free:74 Go)
              D:\ (Local Disk) - NTFS - Total:11 Go (Free:1 Go)
              E:\ (CD or DVD)

              "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
              Option : [2] ( 28/11/2009|13:25 )

              [ UAC => 1 ]

              -----------\\ SUPPRESSION

              Supprime! - C:\Program Files\AskSBar\bar
              Supprime! - C:\Program Files\AskSBar

              -----------\\ Recherche de Fichiers / Dossiers ...

              -----------\\ [..\Internet Explorer\Main]

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
              "Start Page"="https://www.google.com/?gws_rd=ssl"
              "Local Page"="C:\\Windows\\system32\\blank.htm"
              "Search Page"="https://www.google.com/?gws_rd=ssl"
              "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
              "Start Page Redirect Cache"="https://www.msn.com/fr-fr?ocid=iehp"
              "Url"="https://www.msn.com/fr-fr/actualite/"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
              "Start Page"="https://www.msn.com/fr-fr/"
              "Default_Page_URL"="https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF"
              "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
              "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
              "Local Page"="C:\\Windows\\System32\\blank.htm"

              --------------------\\ Recherche d'autres infections

              Aucune autre infection trouvée !

              [ UAC => 1 ]

              1 - "C:\ToolBar SD\TB_1.txt" - 28/11/2009|10:51 - Option : [1]
              2 - "C:\ToolBar SD\TB_2.txt" - 28/11/2009|10:52 - Option : [1]
              3 - "C:\ToolBar SD\TB_3.txt" - 28/11/2009|11:23 - Option : [1]
              4 - "C:\ToolBar SD\TB_4.txt" - 28/11/2009|13:27 - Option : [2]

              -----------\\ Fin du rapport a 13:27:12,38
              0
              1. Ok,

                Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                ▶ Télécharge :

                Malwarebytes

                ou :

                Malwarebytes

                ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                ▶ Potasses le Tuto pour te familiariser avec le prg :

                ( cela dit, il est très simple d'utilisation ).

                relance malwarebytes en suivant scrupuleusement ces consignes :

                ! Déconnecte toi et ferme toutes applications en cours !

                ▶ Lance Malwarebyte's .

                Fais un examen dit "Complet" .

                ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                ▶ à la fin tu cliques sur "résultat" .
                ▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                ▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                ▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                0
                1. Voici donc le rapport:

                  Malwarebytes' Anti-Malware 1.41
                  Version de la base de données: 3250
                  Windows 6.0.6002 Service Pack 2

                  28/11/2009 16:34:09
                  mbam-log-2009-11-28 (16-34-09).txt

                  Type de recherche: Examen complet (C:\|D:\|E:\|)
                  Eléments examinés: 297920
                  Temps écoulé: 1 hour(s), 20 minute(s), 10 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 0
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 0

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Tout a donc l'air ok de ce côté-là à mes yeux de néophyte... Mais aurais-tu une idée sur le fait que je n'arrive toujours pas à installer les dernières mises à jour de Vista?

                  Merci pour tout.
                  0
                  1. Fait ceci :

                    Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                    ! Déconnecte toi et FERME TOUTES TES APPLICATIONS EN COURS !

                    Double-clique sur " RSIT.exe " pour le lancer .

                    ▶ Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                    ▶ Devant l'option "List files/folders created ..." , tu choisis : 2 months

                    ▶ clique ensuite sur " Continue " pour lancer l'analyse ...

                    ▶ laisse faire le scan et ne touche pas au PC ...

                    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

                    Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                    Important : poste un rapport, puis l'autre dans la réponse suivante
                    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

                    ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
                    0
                    1. Bonjour,

                      Voici le premier rapport:

                      oLogfile of random's system information tool 1.06 (written by random/random)
                      Run by Emma at 2009-11-29 11:00:48
                      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                      System drive C: has 77 GB (55%) free of 141 GB
                      Total RAM: 2037 MB (48% free)

                      HijackThis download failed

                      ======Scheduled tasks folder======

                      C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-594348230-2693977953-2740101455-1000Core.job
                      C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-594348230-2693977953-2740101455-1000UA.job
                      C:\Windows\tasks\User_Feed_Synchronization-{3647CAFB-1DA7-48DD-BE27-30E5CFF39EA2}.job

                      ======Registry dump======

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                      Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
                      RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-11-25 329312]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
                      Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll []

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                      Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-25 41760]

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                      "Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2007-12-21 217088]
                      "IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2007-10-03 178712]
                      "QPService"=C:\Program Files\HP\QuickPlay\QPService.exe [2007-09-30 181544]
                      "QlbCtrl"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2007-09-27 202032]
                      "UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2007-09-13 222504]
                      "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
                      "HP Health Check Scheduler"=[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe []
                      "HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
                      "COMODO Firewall Pro"=C:\Program Files\COMODO\Firewall\cfp.exe [2009-11-28 1800464]
                      "avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
                      "IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-11 141848]
                      "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-02-11 166424]
                      "Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-11 133656]
                      "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-25 149280]
                      "COMODO Internet Security"=C:\Program Files\COMODO\Firewall\cfp.exe [2009-11-28 1800464]
                      "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
                      "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
                      "TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-11-25 198160]
                      "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
                      "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]

                      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                      "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
                      "HPAdvisor"=C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [2007-10-01 1783136]
                      "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
                      "Google Update"=C:\Users\Emma\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-26 133104]
                      "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]

                      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
                      Lancement rapide de Microsoft Office OneNote 2003.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE

                      C:\Users\Emma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
                      OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                      "AppInit_DLLS"=" C:\Windows\system32\guard32.dll"

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
                      C:\Windows\system32\igfxdev.dll [2008-02-11 204800]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                      "{4F07DA45-8170-4859-9B5F-037EF2970034}"=C:\PROGRA~1\TALLEM~1\ONLINE~1\oaevent.dll []

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                      "dontdisplaylastusername"=0
                      "legalnoticecaption"=
                      "legalnoticetext"=
                      "shutdownwithoutlogon"=1
                      "undockwithoutlogon"=1
                      "FilterAdministratorToken"=1
                      "EnableUIADesktopToggle"=0

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                      "BindDirectlyToPropertySetStorage"=

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                      ======File associations======

                      .js - edit - C:\Windows\System32\Notepad.exe %1
                      .js - open - C:\Windows\System32\WScript.exe "%1" %*

                      ======List of files/folders created in the last 2 months======

                      2009-11-29 11:00:49 ----D---- C:\Program Files\trend micro
                      2009-11-29 11:00:48 ----D---- C:\rsit
                      2009-11-28 14:04:31 ----D---- C:\Users\Emma\AppData\Roaming\Malwarebytes
                      2009-11-28 14:04:24 ----D---- C:\ProgramData\Malwarebytes
                      2009-11-28 14:04:24 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
                      2009-11-28 10:50:13 ----A---- C:\TB.txt
                      2009-11-27 15:29:21 ----D---- C:\ToolBar SD
                      2009-11-25 15:33:54 ----D---- C:\Users\Emma\AppData\Roaming\Apple Computer
                      2009-11-25 15:33:12 ----A---- C:\Windows\system32\GEARAspi.dll
                      2009-11-25 15:33:11 ----DC---- C:\Windows\system32\DRVSTORE
                      2009-11-25 15:27:56 ----D---- C:\Program Files\iPod
                      2009-11-25 15:27:54 ----D---- C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
                      2009-11-25 15:27:54 ----D---- C:\Program Files\iTunes
                      2009-11-25 15:27:22 ----D---- C:\Program Files\Bonjour
                      2009-11-25 15:19:56 ----D---- C:\ProgramData\Apple Computer
                      2009-11-25 15:19:56 ----D---- C:\Program Files\QuickTime
                      2009-11-25 14:49:14 ----A---- C:\Windows\system32\rmoc3260.dll
                      2009-11-25 14:49:04 ----A---- C:\Windows\system32\pndx5032.dll
                      2009-11-25 14:49:04 ----A---- C:\Windows\system32\pndx5016.dll
                      2009-11-25 14:49:02 ----D---- C:\Program Files\Common Files\xing shared
                      2009-11-25 14:48:46 ----A---- C:\Windows\system32\pncrt.dll
                      2009-11-25 14:48:33 ----D---- C:\Program Files\Real
                      2009-11-25 14:48:31 ----D---- C:\ProgramData\Real
                      2009-11-25 14:48:31 ----D---- C:\Program Files\Common Files\Real
                      2009-11-25 14:48:29 ----D---- C:\Users\Emma\AppData\Roaming\Real
                      2009-11-06 21:34:21 ----D---- C:\Users\Emma\AppData\Roaming\vlc
                      2009-11-04 12:59:20 ----D---- C:\Program Files\Windows Portable Devices
                      2009-11-04 10:22:29 ----D---- C:\Windows\CheckSur
                      2009-11-04 09:54:19 ----A---- C:\Windows\system32\wups2.dll
                      2009-11-04 09:54:19 ----A---- C:\Windows\system32\wucltux.dll
                      2009-11-04 09:54:19 ----A---- C:\Windows\system32\wuaueng.dll
                      2009-11-04 09:54:19 ----A---- C:\Windows\system32\wuauclt.exe
                      2009-11-04 09:53:26 ----A---- C:\Windows\system32\wups.dll
                      2009-11-04 09:53:26 ----A---- C:\Windows\system32\wudriver.dll
                      2009-11-04 09:53:25 ----A---- C:\Windows\system32\wuapi.dll
                      2009-11-04 09:52:39 ----A---- C:\Windows\system32\wuwebv.dll
                      2009-11-04 09:52:39 ----A---- C:\Windows\system32\wuapp.exe
                      2009-11-03 10:46:58 ----A---- C:\Windows\system32\mshtml.dll
                      2009-11-02 11:04:22 ----A---- C:\Windows\system32\UIAnimation.dll
                      2009-11-02 11:04:21 ----A---- C:\Windows\system32\UIRibbonRes.dll
                      2009-11-02 11:04:20 ----A---- C:\Windows\system32\UIRibbon.dll
                      2009-11-02 11:03:40 ----A---- C:\Windows\system32\WMPhoto.dll
                      2009-11-02 11:03:37 ----A---- C:\Windows\system32\cdd.dll
                      2009-11-02 11:03:36 ----A---- C:\Windows\system32\XpsRasterService.dll
                      2009-11-02 11:03:36 ----A---- C:\Windows\system32\XpsGdiConverter.dll
                      2009-11-02 11:03:36 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
                      2009-11-02 11:03:36 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
                      2009-11-02 11:03:36 ----A---- C:\Windows\system32\d3d10warp.dll
                      2009-11-02 11:03:36 ----A---- C:\Windows\system32\d2d1.dll
                      2009-11-02 11:03:35 ----A---- C:\Windows\system32\xpsservices.dll
                      2009-11-02 11:03:35 ----A---- C:\Windows\system32\XpsPrint.dll
                      2009-11-02 11:03:35 ----A---- C:\Windows\system32\WindowsCodecs.dll
                      2009-11-02 11:03:35 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
                      2009-11-02 11:03:35 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
                      2009-11-02 11:03:35 ----A---- C:\Windows\system32\OpcServices.dll
                      2009-11-02 11:03:35 ----A---- C:\Windows\system32\FntCache.dll
                      2009-11-02 11:03:35 ----A---- C:\Windows\system32\dxdiagn.dll
                      2009-11-02 11:03:35 ----A---- C:\Windows\system32\dxdiag.exe
                      2009-11-02 11:03:35 ----A---- C:\Windows\system32\DWrite.dll
                      2009-11-02 11:03:35 ----A---- C:\Windows\system32\d3d10level9.dll
                      2009-11-02 11:03:35 ----A---- C:\Windows\system32\d3d10core.dll
                      2009-11-02 11:03:34 ----A---- C:\Windows\system32\dxgi.dll
                      2009-11-02 11:03:34 ----A---- C:\Windows\system32\d3d11.dll
                      2009-11-02 11:03:34 ----A---- C:\Windows\system32\d3d10_1core.dll
                      2009-11-02 11:03:34 ----A---- C:\Windows\system32\d3d10_1.dll
                      2009-11-02 11:03:34 ----A---- C:\Windows\system32\d3d10.dll
                      2009-11-02 11:02:58 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
                      2009-11-02 11:02:58 ----A---- C:\Windows\system32\wpdbusenum.dll
                      2009-11-02 11:02:58 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
                      2009-11-02 11:02:47 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
                      2009-11-02 11:02:40 ----A---- C:\Windows\system32\WPDShServiceObj.dll
                      2009-11-02 11:02:40 ----A---- C:\Windows\system32\wpdshext.dll
                      2009-11-02 11:02:40 ----A---- C:\Windows\system32\WpdMtpUS.dll
                      2009-11-02 11:02:40 ----A---- C:\Windows\system32\WpdMtp.dll
                      2009-11-02 11:02:40 ----A---- C:\Windows\system32\WpdConns.dll
                      2009-11-02 11:02:40 ----A---- C:\Windows\system32\wpd_ci.dll
                      2009-11-02 11:02:39 ----A---- C:\Windows\system32\WPDSp.dll
                      2009-11-02 11:02:39 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
                      2009-11-02 11:02:39 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
                      2009-11-02 11:02:39 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
                      2009-11-02 11:02:39 ----A---- C:\Windows\system32\PortableDeviceApi.dll
                      2009-11-02 11:01:36 ----A---- C:\Windows\system32\oleaccrc.dll
                      2009-11-02 11:01:29 ----A---- C:\Windows\system32\UIAutomationCore.dll
                      2009-11-02 11:01:29 ----A---- C:\Windows\system32\oleacc.dll
                      2009-10-14 18:04:26 ----A---- C:\Windows\system32\msv1_0.dll
                      2009-10-14 18:04:18 ----A---- C:\Windows\system32\ntoskrnl.exe
                      2009-10-14 18:04:18 ----A---- C:\Windows\system32\ntkrnlpa.exe
                      2009-10-14 18:03:41 ----A---- C:\Windows\system32\ieframe.dll
                      2009-10-14 18:03:40 ----A---- C:\Windows\system32\iertutil.dll
                      2009-10-14 18:03:39 ----A---- C:\Windows\system32\wininet.dll
                      2009-10-14 18:03:39 ----A---- C:\Windows\system32\urlmon.dll
                      2009-10-14 18:03:39 ----A---- C:\Windows\system32\occache.dll
                      2009-10-14 18:03:39 ----A---- C:\Windows\system32\msfeeds.dll
                      2009-10-14 18:03:39 ----A---- C:\Windows\system32\iedkcs32.dll
                      2009-10-14 18:03:38 ----A---- C:\Windows\system32\msfeedsbs.dll
                      2009-10-14 18:03:38 ----A---- C:\Windows\system32\ieUnatt.exe
                      2009-10-14 18:03:38 ----A---- C:\Windows\system32\ieui.dll
                      2009-10-14 18:03:38 ----A---- C:\Windows\system32\iesysprep.dll
                      2009-10-14 18:03:38 ----A---- C:\Windows\system32\iepeers.dll
                      2009-10-14 18:03:37 ----A---- C:\Windows\system32\msfeedssync.exe
                      2009-10-14 18:03:37 ----A---- C:\Windows\system32\jsproxy.dll
                      2009-10-14 18:03:37 ----A---- C:\Windows\system32\iesetup.dll
                      2009-10-14 18:03:37 ----A---- C:\Windows\system32\iernonce.dll
                      2009-10-14 18:03:37 ----A---- C:\Windows\system32\ie4uinit.exe
                      2009-10-14 18:03:28 ----A---- C:\Windows\system32\msasn1.dll
                      2009-10-14 18:03:23 ----A---- C:\Windows\system32\WMSPDMOD.DLL
                      2009-10-07 15:22:49 ----A---- C:\Windows\_MSRSTRT.EXE
                      2009-10-03 11:43:50 ----N---- C:\Windows\system32\MpSigStub.exe

                      ======List of files/folders modified in the last 2 months======

                      2009-11-29 11:00:49 ----RD---- C:\Program Files
                      2009-11-29 11:00:49 ----D---- C:\Windows\Prefetch
                      2009-11-29 11:00:38 ----D---- C:\Windows\Temp
                      2009-11-29 10:59:44 ----SHD---- C:\System Volume Information
                      2009-11-29 10:56:38 ----D---- C:\Users\Emma\AppData\Roaming\OpenOffice.org2
                      2009-11-28 17:12:53 ----D---- C:\Windows\system32\catroot2
                      2009-11-28 17:12:19 ----D---- C:\Windows\System32
                      2009-11-28 17:08:55 ----A---- C:\Windows\system32\guard32.dll
                      2009-11-28 16:47:06 ----D---- C:\Windows\winsxs
                      2009-11-28 14:04:26 ----D---- C:\Windows\system32\drivers
                      2009-11-28 14:04:24 ----HD---- C:\ProgramData
                      2009-11-28 13:57:30 ----AD---- C:\ProgramData\TEMP
                      2009-11-28 10:50:24 ----D---- C:\Program Files\SpywareBlaster
                      2009-11-27 17:58:34 ----D---- C:\Windows
                      2009-11-27 15:33:49 ----D---- C:\Windows\system32\Tasks
                      2009-11-27 12:07:22 ----D---- C:\Windows\Debug
                      2009-11-26 16:39:03 ----D---- C:\Windows\system32\catroot
                      2009-11-26 16:35:43 ----SHD---- C:\Windows\Installer
                      2009-11-25 15:27:55 ----D---- C:\Program Files\Common Files\Apple
                      2009-11-25 15:26:58 ----D---- C:\Windows\inf
                      2009-11-25 14:49:02 ----D---- C:\Program Files\Common Files
                      2009-11-22 00:26:07 ----D---- C:\Program Files\Mozilla Firefox
                      2009-11-12 22:06:09 ----D---- C:\Program Files\Windows Mail
                      2009-11-12 21:55:07 ----D---- C:\ProgramData\Microsoft Help
                      2009-11-09 23:49:00 ----D---- C:\Windows\system32\Macromed
                      2009-11-09 23:26:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
                      2009-11-07 15:11:16 ----D---- C:\Users\Emma\AppData\Roaming\CyberLink
                      2009-11-06 23:11:06 ----RSD---- C:\Windows\Fonts
                      2009-11-05 18:36:21 ----A---- C:\Windows\system32\mrt.exe
                      2009-11-04 13:17:57 ----D---- C:\Windows\rescache
                      2009-11-04 12:59:26 ----D---- C:\Windows\system32\fr-FR
                      2009-11-04 12:59:19 ----D---- C:\Windows\system32\wbem
                      2009-11-04 12:59:16 ----D---- C:\Windows\system32\pt-BR
                      2009-11-04 12:59:15 ----D---- C:\Windows\system32\uk-UA
                      2009-11-04 12:59:15 ----D---- C:\Windows\system32\sl-SI
                      2009-11-04 12:59:15 ----D---- C:\Windows\system32\pt-PT
                      2009-11-04 12:59:15 ----D---- C:\Windows\system32\pl-PL
                      2009-11-04 12:59:15 ----D---- C:\Windows\system32\ko-KR
                      2009-11-04 12:59:15 ----D---- C:\Windows\system32\it-IT
                      2009-11-04 12:59:15 ----D---- C:\Windows\system32\hu-HU
                      2009-11-04 12:59:15 ----D---- C:\Windows\system32\hr-HR
                      2009-11-04 12:59:15 ----D---- C:\Windows\system32\he-IL
                      2009-11-04 12:59:15 ----D---- C:\Windows\system32\bg-BG
                      2009-11-04 12:59:14 ----D---- C:\Windows\system32\zh-HK
                      2009-11-04 12:59:14 ----D---- C:\Windows\system32\tr-TR
                      2009-11-04 12:59:14 ----D---- C:\Windows\system32\th-TH
                      2009-11-04 12:59:14 ----D---- C:\Windows\system32\sv-SE
                      2009-11-04 12:59:14 ----D---- C:\Windows\system32\sr-Latn-CS
                      2009-11-04 12:59:14 ----D---- C:\Windows\system32\nl-NL
                      2009-11-04 12:59:14 ----D---- C:\Windows\system32\fi-FI
                      2009-11-04 12:59:14 ----D---- C:\Windows\system32\el-GR
                      2009-11-04 12:59:13 ----D---- C:\Windows\system32\zh-TW
                      2009-11-04 12:59:13 ----D---- C:\Windows\system32\sk-SK
                      2009-11-04 12:59:13 ----D---- C:\Windows\system32\lv-LV
                      2009-11-04 12:59:13 ----D---- C:\Windows\system32\lt-LT
                      2009-11-04 12:59:13 ----D---- C:\Windows\system32\et-EE
                      2009-11-04 12:59:13 ----D---- C:\Windows\system32\es-ES
                      2009-11-04 12:59:13 ----D---- C:\Windows\system32\de-DE
                      2009-11-04 12:59:13 ----D---- C:\Windows\system32\cs-CZ
                      2009-11-04 12:59:12 ----D---- C:\Windows\system32\zh-CN
                      2009-11-04 12:59:12 ----D---- C:\Windows\system32\ru-RU
                      2009-11-04 12:59:12 ----D---- C:\Windows\system32\ro-RO
                      2009-11-04 12:59:12 ----D---- C:\Windows\system32\ja-JP
                      2009-11-04 12:59:12 ----D---- C:\Windows\system32\ar-SA
                      2009-11-04 12:59:11 ----D---- C:\Windows\system32\nb-NO
                      2009-11-04 12:59:11 ----D---- C:\Windows\system32\en-US
                      2009-11-04 12:59:11 ----D---- C:\Windows\system32\da-DK
                      2009-11-04 12:52:24 ----D---- C:\Program Files\Internet Explorer
                      2009-11-04 12:42:08 ----D---- C:\Windows\Tasks
                      2009-11-04 12:42:07 ----D---- C:\Windows\system32\spool
                      2009-11-04 12:42:04 ----D---- C:\Windows\registration
                      2009-11-04 12:42:04 ----D---- C:\Program Files\CCleaner
                      2009-11-04 10:00:34 ----SD---- C:\Windows\Downloaded Program Files
                      2009-10-20 15:27:18 ----D---- C:\ProgramData\NOS
                      2009-10-19 17:05:51 ----D---- C:\ProgramData\Adobe
                      2009-10-18 22:20:32 ----D---- C:\Program Files\Common Files\Adobe
                      2009-10-15 18:34:42 ----D---- C:\Windows\Microsoft.NET
                      2009-10-15 18:34:30 ----RSD---- C:\Windows\assembly
                      2009-10-15 17:43:11 ----D---- C:\Windows\ehome
                      2009-10-15 17:43:10 ----D---- C:\Windows\system32\migration

                      ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                      R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [2009-02-13 11608]
                      R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
                      R1 cmdGuard;COMODO Firewall Pro Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2009-11-28 128376]
                      R1 cmdHlp;COMODO Firewall Pro Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2009-11-28 29520]
                      R1 Inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2009-11-28 74328]
                      R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-07-13 28520]
                      R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2009-08-24 55656]
                      R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
                      R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-07-10 8704]
                      R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2008-01-08 165424]
                      R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2007-05-30 735232]
                      R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-19 14208]
                      R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2008-02-27 201728]
                      R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
                      R3 HBtnKey;HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [2006-06-28 9472]
                      R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
                      R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-06-20 984064]
                      R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-06-20 208896]
                      R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
                      R3 KMWDFILTER;HIDUASDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys [2008-10-09 17408]
                      R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2009-09-04 47360]
                      R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2007-04-23 50176]
                      R3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-19 134016]
                      R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-06-20 660480]
                      R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-19 11264]
                      S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 464384]
                      S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys [2009-05-29 14336]
                      S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
                      S3 E100B;Intel(R) PRO Adapter Driver; C:\Windows\system32\DRIVERS\e100b325.sys [2006-11-02 163328]
                      S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDART.sys [2007-10-11 176640]
                      S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
                      S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
                      S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
                      S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
                      S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
                      S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
                      S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\Windows\system32\DRIVERS\SymIM.sys []
                      S3 SymIMMP;SymIMMP; C:\Windows\system32\DRIVERS\SymIM.sys []
                      S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
                      S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]

                      ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                      R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-07-13 108289]
                      R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-24 185089]
                      R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
                      R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
                      R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\Firewall\cmdagent.exe [2009-11-28 723632]
                      R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2007-09-19 65536]
                      R2 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2006-05-02 135168]
                      R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2007-10-03 358936]
                      R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-01-09 272024]
                      R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-07-10 386560]
                      R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
                      S3 Com4Qlb;Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [2007-03-05 110592]
                      S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
                      S3 GameConsoleService;GameConsoleService; C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe [2007-07-24 181800]
                      S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
                      S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2009-05-29 234864]
                      S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
                      S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

                      -----------------EOF-----------------

                      A bientôt pour la suite...
                      0
                  2. Je t'envoie le 2° rapport en deux parties car ça ne passe pas en une seule...:

                    info.txt logfile of random's system information tool 1.06 2009-11-29 11:00:55

                    ======Uninstall list======

                    -->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Blasterball 2 Revolution\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Bricks of Egypt\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Chicken Invaders 3 - Revenge of the Yolk\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Crystal Maze\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
                    -->"C:\Program Files\HP Games\FATE\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Fish Tycoon\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Jewel Quest\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Magic Academy\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
                    -->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Polar Golfer Pineapple Cup\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Shooting Stars Pool\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Super Granny\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Virtual Villagers - A New Home\Uninstall.exe"
                    -->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
                    -->C:\Program Files\Conexant\SmartAudio\SETUP.EXE -U -ISmartAudio -SM=SMAUDIO.EXE,1801
                    Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
                    Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
                    Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
                    Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
                    Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
                    Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                    Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                    Adobe Reader 9.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A92000000001}
                    Adobe Reader 9.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A92000000001}
                    Adobe Shockwave Player 11-->C:\Windows\system32\adobe\SHOCKW~1\UNWISE.EXE C:\Windows\system32\Adobe\SHOCKW~1\Install.log
                    Adobe Shockwave Player-->MsiExec.exe /X{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}
                    Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
                    Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
                    Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                    Atheros Driver Installation Program-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{28006915-2739-4EBE-B5E8-49B25D32EB33}\setup.exe" -l0x40c -removeonly
                    Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
                    Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                    Canon Camera Support Core Library-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{91F1A0D6-23AD-49FE-8D4E-379485652214} /l1036
                    Canon Camera Window DS for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{91203BD3-6C3E-472F-ADBD-F60FDC7C4010}
                    Canon Camera Window DVC for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{4C96958A-6562-4143-B820-FF4890D3B734}
                    Canon Camera Window for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{C7281207-4AA4-425E-B57A-0E9EF8445635}
                    Canon Internet Library for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2F81FBFC-9A37-431F-9050-14B55485DF5A}
                    Canon MovieEdit Task for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{8AF1E098-1A5C-4336-BBE2-D047ABB401ED}
                    Canon PhotoRecord-->MsiExec.exe /X{0878E100-C0BB-41E8-B4C6-C486B61FDA7B}
                    Canon RAW Image Task for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{45EF4EE3-F591-4B74-A477-0CAE12934CE7}
                    Canon RemoteCapture Task for ZoomBrowser EX-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{28291BD5-92D2-4685-82DC-CCA925C53CCA}
                    Canon Utilities PhotoStitch 3.1-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{218BBBE3-FE63-4BB2-81A8-7435575A84FA}
                    Canon ZoomBrowser EX-->MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
                    CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
                    CloneDVD 4.3.0.3-->"C:\Program Files\CloneDVD\unins000.exe"
                    COMODO Firewall Pro-->C:\Program Files\COMODO\Firewall\cfpconfg.exe -u
                    Conexant HD Audio-->C:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU32a.exe -U -ILEOHERza.INF
                    CyberLink YouCam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
                    DVD Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
                    EA Link-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{F5577101-33CC-4711-8235-3A95BCD49DB0} /l1036
                    ESU for Microsoft Vista-->MsiExec.exe /I{AD3FDC40-BCF4-476D-A2D6-C4B154DD9DF5}
                    HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDA_HSF\UIU32m.exe -U -I*.INF
                    Hewlett-Packard Active Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
                    Hewlett-Packard Asset Agent for Health Check-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
                    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                    HP Doc Viewer-->MsiExec.exe /I{082702D5-5DD8-4600-BCE5-48B15174687F}
                    HP DVD Play 3.6-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
                    HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9885A11E-60E4-417C-B58B-8B31B21C0B8A}\setup.exe" -l0x9 -removeonly
                    HP Help and Support-->MsiExec.exe /I{28EDCE9C-3304-4331-8AB3-F3EBE94C35B4}
                    HP Quick Launch Buttons 6.30 E2-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x040c uninst
                    HP Total Care Advisor-->MsiExec.exe /X{b02df929-29a7-4fd2-9a70-81a644b635f7}
                    HP Update-->MsiExec.exe /X{7059BDA7-E1DB-442C-B7A1-6144596720A4}
                    HP User Guides 0093-->MsiExec.exe /I{D7358B07-4F10-4014-9869-7999578BE8ED}
                    Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
                    Intel(R) Matrix Storage Manager-->C:\Windows\System32\Imsmudlg.exe
                    Intel(R) TV Wizard-->C:\Windows\system32\TVWizudlg.exe -uninstall
                    iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
                    Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
                    Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
                    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                    LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" -uninstall
                    Les Sims™ Histoires de vie-->MsiExec.exe /I{2284D904-C138-4B58-93EC-5C362AB5130A}
                    Ma-Config.com-->MsiExec.exe /X{6C4D4FC0-467B-4BD7-8D11-50E49B2770D2}
                    Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                    Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                    Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                    Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                    Microsoft Keyboard Layout Creator 1.4-->MsiExec.exe /X{99E66BC9-E4B6-485F-ABFC-31EFCE36DFDF}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                    Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
                    Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                    Microsoft Office FrontPage 2003-->MsiExec.exe /I{9017040C-6000-11D3-8CFE-0150048383C9}
                    Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
                    Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
                    Microsoft Office OneNote 2003-->MsiExec.exe /I{90A1040C-6000-11D3-8CFE-0150048383C9}
                    Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
                    Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
                    Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                    Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
                    Microsoft Office Professional 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROR /dll OSETUP.DLL
                    Microsoft Office Professional 2007-->MsiExec.exe /X{91120000-0014-0000-0000-0000000FF1CE}
                    Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
                    Microsoft Office Project Professional 2003-->MsiExec.exe /I{903B040C-6000-11D3-8CFE-0150048383C9}
                    Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                    Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                    Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                    Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                    Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                    Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                    Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                    Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
                    Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                    Microsoft Office Visio Professional 2003-->MsiExec.exe /I{9051040C-6000-11D3-8CFE-0150048383C9}
                    Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
                    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                    Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
                    Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                    Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                    Mise à jour Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {51EFB347-1F3D-4BAC-8B79-F056B904FE21}
                    Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
                    Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
                    Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                    Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                    Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
                    Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                    Mozilla Firefox (3.0.15)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                    MSCU for Microsoft Vista-->MsiExec.exe /I{E87F5651-CE15-493F-AE99-3B670E25A54E}
                    MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                    MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
                    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                    MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
                    My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
                    NetWaiting-->C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x040c -removeonly
                    OpenOffice.org 2.4-->MsiExec.exe /I{B6694BAA-7604-46AA-A41F-B5F1E6DADE7A}
                    Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
                    PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
                    QuickPlay SlingPlayer 0.4.4-->"C:\Program Files\HP\QuickPlay\unins000.exe"
                    QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
                    RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|12.0
                    Realtek 8139 and 8139C+ Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{AE46ABD3-D625-467F-B5A7-8D3FFF077F0D}\setup.exe -runfromtemp -l0x040c -removeonly
                    Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                    Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                    Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
                    Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
                    Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
                    Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
                    Security Update for Microsoft Office Outlook 2007 (KB972363)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {120BE9A0-9B09-4855-9E0C-7DEE45CB03C0}
                    Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
                    Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
                    Security Update for Microsoft Office Publisher 2007 (KB969693)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
                    Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
                    Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
                    Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
                    Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
                    Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                    Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                    Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
                    SpywareBlaster 4.2-->"C:\Program Files\SpywareBlaster\unins000.exe"
                    Touch Pad Driver-->C:\Program Files\Apoint2K\Uninstap.exe ADDREMOVE
                    Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                    Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                    Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
                    Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
                    Update for Outlook 2007 Junk Email Filter (kb975960)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {F1AB1BED-7477-4D5A-BD0C-04C2109459A5}
                    Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
                    VLC media player 1.0.0-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                    Windows Resource Kit Tools-->MsiExec.exe /I{FA237125-51FF-408C-8BB8-30C2B3DFFF9C}

                    ======Security center information======

                    FW: COMODO Firewall
                    AS: COMODO Defense+
                    AS: Windows Defender (disabled)

                    ======System event log======

                    Computer Name: PC-de-Emma
                    Event Code: 4001
                    Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

                    Record Number: 117325
                    Source Name: Microsoft-Windows-WLAN-AutoConfig
                    Time Written: 20091011224638.809000-000
                    Event Type: Avertissement
                    User: AUTORITE NT\SYSTEM

                    Computer Name: PC-de-Emma
                    Event Code: 4001
                    Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

                    Record Number: 117029
                    Source Name: Microsoft-Windows-WLAN-AutoConfig
                    Time Written: 20091010000424.609984-000
                    Event Type: Avertissement
                    User: AUTORITE NT\SYSTEM

                    Computer Name: PC-de-Emma
                    Event Code: 4001
                    Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

                    Record Number: 116712
                    Source Name: Microsoft-Windows-WLAN-AutoConfig
                    Time Written: 20091007142321.160587-000
                    Event Type: Avertissement
                    User: AUTORITE NT\SYSTEM

                    Computer Name: PC-de-Emma
                    Event Code: 3004
                    Message: L’agent de protection en temps réel Windows Defender a détecté des modifications. Microsoft vous recommande d’analyser les logiciels responsables de ces modifications, à la recherche de risques potentiels. Vous pouvez vous servir des informations relatives au fonctionnement de ces programmes pour autoriser ou non leur exécution, ou pour les supprimer de l’ordinateur. N’autorisez les modifications que si vous faites confiance au programme ou à l’éditeur de logiciel. Windows Defender ne peut pas annuler les modifications que vous autorisez.
                    Pour plus d’informations, consultez les données suivantes :
                    Non applicable
                    ID d’analyse : {56372DA0-9A30-4011-8020-9B86C0923E7D}
                    Utilisateur : PC-de-Emma\Emma
                    Nom : Unknown
                    ID :
                    ID de gravité :
                    ID de catégorie :
                    Chemin d’accès trouvé : ieurlsearchhook:HKCU@S-1-5-21-594348230-2693977953-2740101455-1000\Software\Microsoft\Internet Explorer\UrlSearchHooks\\{d1e06b91-60e6-4492-af9f-53043fa32716}
                    Type d’alerte : Logiciel non classifié
                    Type de détection :
                    Record Number: 116703
                    Source Name: Microsoft-Windows-Windows Defender
                    Time Written: 20091007142049.000000-000
                    Event Type: Avertissement
                    User:
                    0
                    1. Computer Name: PC-de-Emma
                      Event Code: 4001
                      Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

                      Record Number: 116295
                      Source Name: Microsoft-Windows-WLAN-AutoConfig
                      Time Written: 20091004230545.938570-000
                      Event Type: Avertissement
                      User: AUTORITE NT\SYSTEM

                      =====Application event log=====

                      Computer Name: PC-de-Emma
                      Event Code: 63
                      Message: Le fournisseur OffProv12 a été inscrit dans l’espace de noms Windows Management Instrumentation Root\MSAPPS12, afin d’utiliser le compte LocalSystem. Ce compte bénéficie de privilèges et le fournisseur peut provoquer une violation de sécurité s’il ne représente pas correctement les demandes utilisateur.
                      Record Number: 229
                      Source Name: Microsoft-Windows-WMI
                      Time Written: 20080706131411.000000-000
                      Event Type: Avertissement
                      User: AUTORITE NT\SYSTEM

                      Computer Name: PC-de-Emma
                      Event Code: 5007
                      Message: Impossible d’analyser le fichier cible de la plateforme de signalement de problèmes Windows (fichier DLL contenant la liste des problèmes de l’ordinateur et nécessitant la collecte de données supplémentaires à des fins de diagnostic). Le code d’erreur était : 8014FFF9.
                      Record Number: 140
                      Source Name: WerSvc
                      Time Written: 20080706115057.000000-000
                      Event Type: Erreur
                      User:

                      Computer Name: PC-de-Emma
                      Event Code: 1530
                      Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                      DÉTAIL -
                      1 user registry handles leaked from \Registry\User\S-1-5-21-594348230-2693977953-2740101455-1000:
                      Process 536 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-594348230-2693977953-2740101455-1000

                      Record Number: 97
                      Source Name: Microsoft-Windows-User Profiles Service
                      Time Written: 20080705142352.000000-000
                      Event Type: Avertissement
                      User: AUTORITE NT\SYSTEM

                      Computer Name: PC-de-Emma
                      Event Code: 1000
                      Message: Application défaillante Explorer.EXE, version 6.0.6000.16386, horodatage 0x4549b091, module défaillant ShellvRTF.dll, version 1.1.0.8, horodatage 0x46d83e7c, code d’exception 0xc0000005, décalage d’erreur 0x000057ab, ID du processus 0xd08, heure de début de l’application 0x01c8de9d7d69dcb1.
                      Record Number: 89
                      Source Name: Application Error
                      Time Written: 20080705141350.000000-000
                      Event Type: Erreur
                      User:

                      Computer Name: PC-de-Emma
                      Event Code: 1000
                      Message: Application défaillante Apoint.exe, version 7.0.202.266, horodatage 0x470c4b94, module défaillant Apoint.DLL, version 7.0.202.268, horodatage 0x470b1bf5, code d’exception 0xc0000005, décalage d’erreur 0x00010000, ID du processus 0x4d0, heure de début de l’application 0x01c8dea4e8e3a3c1.
                      Record Number: 87
                      Source Name: Application Error
                      Time Written: 20080705134708.000000-000
                      Event Type: Erreur
                      User:

                      =====Security event log=====

                      Computer Name: PC-de-Emma
                      Event Code: 4624
                      Message: L’ouverture de session d’un compte s’est correctement déroulée.

                      Sujet :
                      ID de sécurité : S-1-5-18
                      Nom du compte : PC-DE-EMMA$
                      Domaine du compte : WORKGROUP
                      ID d’ouverture de session : 0x3e7

                      Type d’ouverture de session : 5

                      Nouvelle ouverture de session :
                      ID de sécurité : S-1-5-18
                      Nom du compte : SYSTEM
                      Domaine du compte : AUTORITE NT
                      ID d’ouverture de session : 0x3e7
                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                      Informations sur le processus :
                      ID du processus : 0x2a0
                      Nom du processus : C:\Windows\System32\services.exe

                      Informations sur le réseau :
                      Nom de la station de travail :
                      Adresse du réseau source : -
                      Port source : -

                      Informations détaillées sur l’authentification :
                      Processus d’ouverture de session : Advapi
                      Package d’authentification : Negotiate
                      Services en transit : -
                      Nom du package (NTLM uniquement) : -
                      Longueur de la clé : 0

                      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

                      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

                      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

                      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

                      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

                      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
                      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
                      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
                      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
                      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
                      Record Number: 32206
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090714114736.863161-000
                      Event Type: Succès de l'audit
                      User:

                      Computer Name: PC-de-Emma
                      Event Code: 4648
                      Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

                      Sujet :
                      ID de sécurité : S-1-5-18
                      Nom du compte : PC-DE-EMMA$
                      Domaine du compte : WORKGROUP
                      ID d’ouverture de session : 0x3e7
                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                      Compte dont les informations d’identification ont été utilisées :
                      Nom du compte : SYSTEM
                      Domaine du compte : AUTORITE NT
                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                      Serveur cible :
                      Nom du serveur cible : localhost
                      Informations supplémentaires : localhost

                      Informations sur le processus :
                      ID du processus : 0x2a0
                      Nom du processus : C:\Windows\System32\services.exe

                      Informations sur le réseau :
                      Adresse du réseau : -
                      Port : -

                      Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
                      Record Number: 32205
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090714114736.863161-000
                      Event Type: Succès de l'audit
                      User:

                      Computer Name: PC-de-Emma
                      Event Code: 4672
                      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

                      Sujet :
                      ID de sécurité : S-1-5-18
                      Nom du compte : SYSTEM
                      Domaine du compte : AUTORITE NT
                      ID d’ouverture de session : 0x3e7

                      Privilèges : SeAssignPrimaryTokenPrivilege
                      SeTcbPrivilege
                      SeSecurityPrivilege
                      SeTakeOwnershipPrivilege
                      SeLoadDriverPrivilege
                      SeBackupPrivilege
                      SeRestorePrivilege
                      SeDebugPrivilege
                      SeAuditPrivilege
                      SeSystemEnvironmentPrivilege
                      SeImpersonatePrivilege
                      Record Number: 32204
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090714114736.691560-000
                      Event Type: Succès de l'audit
                      User:

                      Computer Name: PC-de-Emma
                      Event Code: 4624
                      Message: L’ouverture de session d’un compte s’est correctement déroulée.

                      Sujet :
                      ID de sécurité : S-1-5-18
                      Nom du compte : PC-DE-EMMA$
                      Domaine du compte : WORKGROUP
                      ID d’ouverture de session : 0x3e7

                      Type d’ouverture de session : 5

                      Nouvelle ouverture de session :
                      ID de sécurité : S-1-5-18
                      Nom du compte : SYSTEM
                      Domaine du compte : AUTORITE NT
                      ID d’ouverture de session : 0x3e7
                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                      Informations sur le processus :
                      ID du processus : 0x2a0
                      Nom du processus : C:\Windows\System32\services.exe

                      Informations sur le réseau :
                      Nom de la station de travail :
                      Adresse du réseau source : -
                      Port source : -

                      Informations détaillées sur l’authentification :
                      Processus d’ouverture de session : Advapi
                      Package d’authentification : Negotiate
                      Services en transit : -
                      Nom du package (NTLM uniquement) : -
                      Longueur de la clé : 0

                      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

                      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

                      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

                      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

                      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

                      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
                      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
                      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
                      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
                      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
                      Record Number: 32203
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090714114736.691560-000
                      Event Type: Succès de l'audit
                      User:

                      Computer Name: PC-de-Emma
                      Event Code: 4648
                      Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

                      Sujet :
                      ID de sécurité : S-1-5-18
                      Nom du compte : PC-DE-EMMA$
                      Domaine du compte : WORKGROUP
                      ID d’ouverture de session : 0x3e7
                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                      Compte dont les informations d’identification ont été utilisées :
                      Nom du compte : SYSTEM
                      Domaine du compte : AUTORITE NT
                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                      Serveur cible :
                      Nom du serveur cible : localhost
                      Informations supplémentaires : localhost

                      Informations sur le processus :
                      ID du processus : 0x2a0
                      Nom du processus : C:\Windows\System32\services.exe

                      Informations sur le réseau :
                      Adresse du réseau : -
                      Port : -

                      Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
                      Record Number: 32202
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090714114736.691560-000
                      Event Type: Succès de l'audit
                      User:

                      ======Environment variables======

                      "ComSpec"=%SystemRoot%\system32\cmd.exe
                      "FP_NO_HOST_CHECK"=NO
                      "OS"=Windows_NT
                      "Path"=C:\Program Files\Windows Resource Kits\Tools\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\CyberLink\Power2Go\;C:\Program Files\QuickTime\QTSystem\
                      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                      "PROCESSOR_ARCHITECTURE"=x86
                      "TEMP"=%SystemRoot%\TEMP
                      "TMP"=%SystemRoot%\TEMP
                      "USERNAME"=SYSTEM
                      "windir"=%SystemRoot%
                      "PROCESSOR_LEVEL"=6
                      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
                      "PROCESSOR_REVISION"=0f0d
                      "NUMBER_OF_PROCESSORS"=2
                      "PLATFORM"=MCD
                      "PCBRAND"=Presario
                      "OnlineServices"=Online Services
                      "USERPART"=E:
                      "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                      "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

                      -----------------EOF-----------------

                      Merci encore!
                      0
                      1. Fait moi un rapport hijackthis pour le nettoyage ...
                        0
                        1. Et voilà:

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 14:06:19, on 29/11/2009
                          Platform: Windows Vista SP2 (WinNT 6.00.1906)
                          MSIE: Internet Explorer v8.00 (8.00.6001.18828)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Windows\system32\taskeng.exe
                          C:\Program Files\Apoint2K\Apoint.exe
                          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                          C:\Program Files\Hp\QuickPlay\QPService.exe
                          C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
                          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                          C:\Windows\System32\hkcmd.exe
                          C:\Windows\System32\igfxpers.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Windows\ehome\ehtray.exe
                          C:\Program Files\Windows Media Player\wmpnscfg.exe
                          C:\Windows\system32\igfxsrvc.exe
                          C:\Windows\ehome\ehmsas.exe
                          C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                          C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                          C:\Program Files\Apoint2K\Apntex.exe
                          C:\Windows\system32\conime.exe
                          C:\Windows\system32\wuauclt.exe
                          C:\Users\Emma\Downloads\HiJackThis.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                          O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                          O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                          O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                          O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                          O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                          O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
                          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                          O4 - HKCU\..\Run: [Google Update] "C:\Users\Emma\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                          O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                          O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                          O13 - Gopher Prefix:
                          O15 - Trusted Zone: http://www.apexchange.com
                          O15 - Trusted Zone: https://www.rivesparis.banquepopulaire.fr/portailinternet/Pages/default.aspx
                          O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
                          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
                          O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_1_0.cab
                          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                          O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
                          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
                          O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
                          O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                          O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                          O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                          0
                          1. > Rélance Hijackthis
                            > Fais scan only
                            > Coches ces lignes sur leur gauche:

                            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe    
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"    
                            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot    
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime    
                            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe


                            > Tu les coches et tu clic sur "fix checked"
                            > Et tu fermes le programme.

                            --> Et envoie moi le rapport

                            0
                            1. Voici le rapport après nettpyage:

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 14:28:31, on 29/11/2009
                              Platform: Windows Vista SP2 (WinNT 6.00.1906)
                              MSIE: Internet Explorer v8.00 (8.00.6001.18828)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\Windows\system32\taskeng.exe
                              C:\Program Files\Apoint2K\Apoint.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                              C:\Program Files\Hp\QuickPlay\QPService.exe
                              C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                              C:\Program Files\Windows Defender\MSASCui.exe
                              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                              C:\Windows\System32\hkcmd.exe
                              C:\Windows\System32\igfxpers.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Windows\ehome\ehtray.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Windows\system32\igfxsrvc.exe
                              C:\Windows\ehome\ehmsas.exe
                              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                              C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                              C:\Program Files\Apoint2K\Apntex.exe
                              C:\Windows\system32\conime.exe
                              C:\Windows\system32\wuauclt.exe
                              C:\Windows\system32\SearchProtocolHost.exe
                              C:\Users\Emma\Downloads\HiJackThis.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                              O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                              O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                              O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                              O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                              O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
                              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
                              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
                              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                              O4 - HKCU\..\Run: [Google Update] "C:\Users\Emma\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                              O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                              O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                              O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                              O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                              O13 - Gopher Prefix:
                              O15 - Trusted Zone: http://www.apexchange.com
                              O15 - Trusted Zone: https://www.rivesparis.banquepopulaire.fr/portailinternet/Pages/default.aspx
                              O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
                              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
                              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_1_0.cab
                              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                              O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
                              O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                              O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
                              O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
                              O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                              O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                              O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                              O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                              0
                              1. Tu peux refaire la manip stp ? Rien n'a changer tu t'est peut être trompé lis bien ce que j'ai écrit ...
                                0
                                1. Je ne comprends pas: j'ai beau recommencer la manoeuvre, seule la première ligne que tu m'as indiquée (celle qui commence par R3) s'est effacée, les autres restent obstinément présentes malgré le fait que je les aie cochées et 'fixed/checked', en outre, je n'arrive maintenant plus à lancer HijackThis (une fenêtre me dit qu'il est 'already running' alors que j'ai fermé le programme, et de nouveau mon pare-feu COMODO qui ne veut plus se lancer...).
                                  0
                                  1. Bon,

                                    Enlève les programmes de démarrage manuellement.

                                    Désactive les programmes inutiles au démarrage pour gagner en performance et un démarrage plus rapide :

                                    - Menu Démarrer puis executer
                                    - Tape msconfig dans le champs et clic sur OK
                                    - Dans la nouvelle fenetre clic sur l'onglet démarrage en haut à droite
                                    - Décoche tous les programmes qui te semblent inutiles (selon l'utilisation que tu fais de l'ordinateur)
                                    - Clic sur OK

                                    Plus d'informations sur msconfig : Se rendre ici
                                    0
                                    1. Après plusieurs tâtonnements, j'ai réussi à enlever 5 des 6 programmes que tu me demandais de cocher, il reste juste le 'Bonjour service' .
                                      Voici le dernier rapport:

                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 15:38:09, on 29/11/2009
                                      Platform: Windows Vista SP2 (WinNT 6.00.1906)
                                      MSIE: Internet Explorer v8.00 (8.00.6001.18828)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\Windows\system32\Dwm.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\Explorer.EXE
                                      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                      C:\Windows\System32\igfxpers.exe
                                      C:\Program Files\COMODO\Firewall\cfp.exe
                                      C:\Program Files\Windows Sidebar\sidebar.exe
                                      C:\Windows\ehome\ehtray.exe
                                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                                      C:\Program Files\Internet Explorer\iexplore.exe
                                      C:\Windows\ehome\ehmsas.exe
                                      C:\Windows\system32\igfxsrvc.exe
                                      C:\Program Files\Internet Explorer\iexplore.exe
                                      C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
                                      C:\Program Files\Internet Explorer\iexplore.exe
                                      C:\Windows\system32\wuauclt.exe
                                      C:\Users\Emma\Downloads\HiJackThis.exe

                                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                      O1 - Hosts: ::1 localhost
                                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                      O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll (file missing)
                                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                      O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
                                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                      O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
                                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                      O4 - HKCU\..\Run: [Google Update] "C:\Users\Emma\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                                      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                                      O13 - Gopher Prefix:
                                      O15 - Trusted Zone: http://www.apexchange.com
                                      O15 - Trusted Zone: https://www.rivesparis.banquepopulaire.fr/portailinternet/Pages/default.aspx
                                      O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
                                      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
                                      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_1_0.cab
                                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                      O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
                                      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                      O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
                                      O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
                                      O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                                      O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                                      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                      0
                                      1. 1- Télécharges Ccleaner :

                                        Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corriger ton registre .
                                        Lors de l'installation:
                                        -choisis bien "francais" en langue .
                                        -avant de cliquer sur le bouton "installer", décoches toutes les "options supplémentaires" sauf les 2 premières.

                                        Tuto

                                        ---> Utilisation:
                                        ! déconnectes toi et fermes toutes applications en cours !
                                        * vas dans "nettoyeur" : fait analyse puis nettoyage
                                        * vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

                                        ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )

                                        ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

                                        https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/

                                        ---> Télécharge ToolsCleaner2 sur ton Bureau.

                                        * Double-clique sur ToolsCleaner2.exe pour le lancer.
                                        * Clique sur Recherche et laisse le scan agir.

                                        * Clique sur Suppression pour finaliser.
                                        * Tu peux, si tu le souhaites, te servir des Options Facultatives.

                                        * Clique sur Quitter pour obtenir le rapport.
                                        * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
                                        _________________________________________________
                                        1
                                        • 1
                                        • 2