Application.Claria

Bonjour,
depuis peu , mon log de messagerie et le navigateur mette plus de temps à ouvrir qu' habituellement ;l'unité centrale tourne très souvent à 100% notamment en navigation sur le net .
Jai parfois une fenetre qui s'ouvre pour me dire que la mémoire virtuelle est insuffisante.
(ma config :atlon 2.6 avec 2giga de ram)
J'ai fait un nettoyage en règle avec C cleaner et aussi de la base de registre .
Malwarebytes en mode sans échec et antivir n'ont rien trouvé, par contre bitdefender online à trouvé deux choses:
-Application.Claria.précision .time.A
-Application.Claria.AL
Est-ce vraiment un virus que doit -je faire pour la suite?
merci
Configuration: Windows XP  ,Atlon 2.6 ,2 giga de ram
Firefox 3.0.8

92 réponses

Résumé de la discussion

Problème de performance lié à un ralentissement du navigateur et du log de messagerie, l'unité centrale oscillant à 100% et des alertes de mémoire virtuelle insuffisante sur Athlon 2.6 avec 2 Go de RAM. Les analyses détectent deux éléments potentiellement indésirables via Bitdefender Online, nommément Application.Claria.precision.time.A et Application.Claria.AL, alors que Malwarebytes en mode sans échec et un antivirus en ligne n'ont rien signalé. La meilleure réponse suggère de relancer le scan en supprimant les anciens rapports et en recommençant, afin d'obtenir un relevé propre, tandis que d'autres précisent que HijackThis nécessite prudence et vérification ciblée.

Bobot (l’IA à votre service)
  1. N'y a t-il donc personne qui puisse me répondre ? car après avoir chercher sur plusieurs forum je suis un peu démunis
    1. Afin d'evaluer tes infections

      Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

      ! Déconnecte toi et ferme toutes tes applications en cours !

      Double-clique sur " RSIT.exe " pour le lancer .

      -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

      * Devant l'option "List files/folders created ..." , tu choisis : 2 months

      * clique ensuite sur " Continue " pour lancer l'analyse ...

      -> laisse faire le scan et ne touche pas au PC ...

      Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

      Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

      Important : poste un rapport, puis l'autre dans la réponse suivante
      Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

      ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
      1. Merci à toi ,de me donner un coup de main,
        voici donc le 1er rapport

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by M V at 2009-04-14 11:26:01
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 16 GB (13%) free of 117 GB
        Total RAM: 2048 MB (77% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 11:26:16, on 14/04/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\BufferZone\CLNTSVC.EXE
        C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
        C:\Program Files\BufferZone\BZRPCSS.EXE
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\WINDOWS\system32\LVCOMSX.EXE
        C:\Program Files\Logitech\Video\LogiTray.exe
        C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
        C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
        C:\Program Files\Windows Desktop Search\WindowsSearch.exe
        C:\Program Files\Logitech\Video\FxSvr2.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\system32\cisvc.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\Pen_Tablet.exe
        C:\WINDOWS\system32\SearchIndexer.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
        C:\WINDOWS\system32\Pen_Tablet.exe
        C:\WINDOWS\System32\alg.exe
        C:\WINDOWS\system32\cidaemon.exe
        C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
        C:\Documents and Settings\M V\Bureau\RSIT.exe
        C:\WINDOWS\System32\wbem\wmiprvse.exe
        C:\Program Files\trend micro\M V.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
        O3 - Toolbar: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
        O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
        O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
        O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
        O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
        O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
        O4 - HKCU\..\Run: [LDM] \Program\
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
        O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Startup: Anti-Autorun-inf.lnk = G:\Program Files\Prg Chris\Anti-Autorun.inf\Anti-Autorun.inf.exe
        O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
        O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
        O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
        O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
        O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
        O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
        O8 - Extra context menu item: View EXIF - C:\ViewEXIF\EXIF.htm
        O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O15 - Trusted Zone: https://www.msn.com/fr-fr
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
        O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab
        O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4}: NameServer = 208.67.220.220,208.67.222.222
        O17 - HKLM\System\CCS\Services\Tcpip\..\{F3CED271-D5C7-432C-BF6E-B7E600EEBA78}: NameServer = 208.67.220.220,208.67.222.222
        O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
        O23 - Service: BufferZone DCOM Helper (BZDcomLaunch) - Unknown owner - C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
        O23 - Service: BufferZone RPC Helper (BZRpcSs) - Unknown owner - C:\Program Files\BufferZone\BZRPCSS.EXE
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
        O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
        1. et puis le 2ième

          info.txt logfile of random's system information tool 1.06 2009-04-14 11:26:18

          ======Uninstall list======

          -->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
          -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          150 000 Cliparts Volume 1-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{5CE69F36-35FD-4552-81EC-198F5A3F532B}
          Active GIF Creator 2.18-->"C:\Program Files\Active GIF Creator 2.18\uninstall.exe"
          Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
          Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
          Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
          Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
          Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
          Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
          Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
          Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
          Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
          Adobe Color EU Recommended Settings-->MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
          Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
          Adobe Color NA Extra Settings-->MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
          Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
          Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
          Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
          Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
          Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
          Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
          Adobe Illustrator 10-->"C:\Program Files\InstallShield Installation Information\{412033BC-44CF-48D9-B813-4B835101F4D3}\setup.exe"
          Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
          Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
          Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\32e9033392a51340b32fdc6ad893ab7\Setup.exe
          Adobe Photoshop CS3-->MsiExec.exe /I{BF794769-8875-4E01-B7BE-E00104604F4A}
          Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
          Adobe Setup-->MsiExec.exe /I{926DEB4E-2B0A-4C5C-AE4A-BF6C06949702}
          Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
          Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
          Adobe SVG Viewer 3.0-->C:\Program Files\Fichiers communs\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Fichiers communs\Adobe\SVG Viewer 3.0\Uninstall\Install.log
          Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
          Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
          Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
          Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
          Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
          AFPL Ghostscript 8.50-->C:\gs\uninstgs.exe "C:\gs\gs8.50\uninstal.txt"
          AFPL Ghostscript Fonts-->C:\gs\uninstgs.exe "C:\gs\fonts\uninstal.txt"
          ALCATEL PC Suite V6.2.8-->"C:\Program Files\ALCATEL PC Suite\unins000.exe"
          AMI-CW52 V.92 PCI Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F01&SUBSYS_900616EF\HXFSETUP.EXE -U -IVEN_14F1&DEV_2F01&SUBSYS_900616EF
          Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          ArtRage 2-->MsiExec.exe /X{19832654-3F86-48B8-9DA0-D3CF2D3AF000}
          Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
          AVIConverter 2.1-->C:\Program Files\AVIConverter\uninst.exe
          Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
          AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
          Bamboo Scribe Shared Files-->MsiExec.exe /X{08581E23-EC5B-4AEC-8DB9-F186D751129F}
          Bamboo Scribe-->"C:\Program Files\Bamboo Scribe\unins000.exe"
          Barre d'outils Outlook de Windows Live (Windows Live Toolbar)-->MsiExec.exe /X{6E15BEDF-7EB5-4010-998E-B430DB4EFE45}
          Bloqueur de fenêtres pop-up (Windows Live Toolbar)-->MsiExec.exe /X{A425C250-A0E1-4D78-B1C1-A5CBC7385E7C}
          BufferZone-->MsiExec.exe /X{793CFFC9-A72F-431D-9C74-2E9361E67D04}
          Canon Camera Window for ZoomBrowser EX-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A29EA741-24F7-4C07-9B2C-06CB6491BE4A}
          Canon EOS 20D Pilote WIA -->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{ED9775A0-383E-4EAA-8DA5-8CC6860D60A3}
          Canon Internet Library for ZoomBrowser EX-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6A0DBAA6-4FEC-41B7-858E-99EF59B9173C}
          Canon MP Navigator 2.0-->"C:\Program Files\Canon\MP Navigator 2.0\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator 2.0\uninst.ini
          Canon MP500-->"C:\WINDOWS\system32\CanonMP Uninstaller Information\{BA4DF4C3-196E-4128-969A-00996B5A46F8}\DelDrv.exe" /U:{BA4DF4C3-196E-4128-969A-00996B5A46F8} /L0x000c
          Canon PhotoRecord-->MsiExec.exe /X{BEF56F2D-56ED-4176-BF72-7B68D4A3B98D}
          Canon RAW Image Task for ZoomBrowser EX-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{D076E06B-F74B-454F-A56E-7510D7B6C9F0}
          Canon RemoteCapture Task for ZoomBrowser EX-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{822586CA-0B15-428C-859A-64B3728F28E7}
          Canon Utilities Digital Photo Professional 3.4-->"C:\Program Files\Fichiers communs\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\Digital Photo Professional\Uninst.ini"
          Canon Utilities Easy-PhotoPrint-->C:\Program Files\Canon\Easy-PhotoPrint\uninst.exe uninst.ini
          Canon Utilities EOS Capture 1.2-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{74BE7519-41A7-45A8-8AA6-78C7907A4808}
          Canon Utilities EOS Viewer Utility 1.2-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{73516B79-4518-4064-A328-28593D14E5A7}
          Canon Utilities RemoteCapture 2.7-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{14220DB1-DD96-4BCD-B3D5-03A4EA6631C4}
          Canon Utilities ZoomBrowser EX-->MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
          Cartoonist 1.2-->"C:\Program Files\Cartoonist\unins000.exe"
          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
          CDex 1.50 [Extraction Audio]-->"C:\Program Files\CDex\uninstall.exe"
          CD-LabelPrint-->"C:\Program Files\Canon\CD-LabelPrint\Uninstal.exe" Canon.CDLabelPrint.Application
          Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
          Classic PhoneTools-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3436EE2-D5CB-4249-840B-3A0140CC34C3}\setup.exe" -l0x40c ControlPanel
          Content Transfer-->MsiExec.exe /X{CFADE4AF-C0CF-4A04-A776-741318F1658F}
          Defraggler (remove only)-->"C:\Program Files\Defraggler\uninst.exe"
          Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{EFFCB0F1-CFEC-48D4-B793-EBFCAE852976}
          Disney Tarzan, Atelier de Jeux-->C:\WINDOWS\IsUn040c.exe -fC:\PROGRA~1\DISNEY~1\DISNEY~1\DeIsL1.isu
          DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
          DivX-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
          DreamSuite Series2-->C:\WINDOWS\unvise32.exe C:\DS2Uninstall.log
          DShot TWAIN Driver ver1.0-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{298B02FF-B4E7-460E-8BF6-95E8579C3EDC}\setup.exe"
          DVD to VCD AVI DivX Converter v3.2 (build 069)-->C:\PROGRA~1\MAGICD~1\UNWISE.EXE C:\PROGRA~1\MAGICD~1\INSTALL.LOG
          Easy-WebPrint-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Canon\Easy-WebPrint\Uninst.isu"
          EBP Comptes Bancaires 2004-->"C:\Program Files\EBP\Comptes Bancaires\unins000.exe"
          eMule-->"C:\Program Files\eMule\Uninstall.exe"
          Environnement d'exécution Java 2, Standard Edition v1.3.1_02-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\JavaSoft\JRE\1.3.1_02\Uninst.isu"
          Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{0CA6047C-D28B-4295-834A-07C52BA20C2D}
          Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP-->MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
          Free Video Converter V 2.0-->"C:\Program Files\Free Video Converter\unins000.exe"
          Garmin City Navigator Europe NT 2009.11 Update-->MsiExec.exe /X{EE2597D7-884D-48B1-8774-B89526A426C8}
          Garmin Communicator Plugin-->MsiExec.exe /X{86B879A5-927E-4536-B5FC-17CA96B60078}
          Garmin POI Loader-->MsiExec.exe /X{D9DA2DF6-8CB6-4E3C-A29E-FAECFBA3E9A7}
          Garmin USB Drivers-->MsiExec.exe /X{B1102A25-3AA3-446B-AA0F-A699B07A02FD}
          Google Earth-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonly
          HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
          Hollywood FX Pack 26 - Extra FX-->C:\WINDOWS\unvise32.exe C:\WINDOWS\unextrafx.log
          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
          Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
          InterActual Player-->C:\Program Files\InterActual\InterActual Player\inuninst.exe
          J2SE Runtime Environment 5.0 Update 10-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
          J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
          J2SE Runtime Environment 5.0 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150050}
          J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
          Japanese Fonts Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5760-0000-900000000003}
          Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
          jp2IE 1.0-->C:\WINDOWS\unins001.exe
          Lame ACM MP3 Codec-->C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_LameMP3 132 C:\WINDOWS\INF\LameACM.inf
          Le Fabuleux Voyage de l'Oncle Ernest-->C:\emme\Voyage\Desinst.exe
          Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
          LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
          Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x40c UNINSTALL
          Logitech Print Service-->C:\PROGRA~1\Logitech\PRINTS~1\UNWISE.EXE C:\PROGRA~1\Logitech\PRINTS~1\INSTALL.LOG
          Logitech QuickCam-->MsiExec.exe /I{0496D9E9-224B-4AFA-8F37-23B98D52F1EB}
          Make a Movie-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{70C002F0-5308-42D8-A65A-91436B90255C}
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
          Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
          Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
          Microsoft .NET Framework 3.0-->MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
          Microsoft ActiveSync 3.8-->"C:\WINDOWS\ISUN040C.EXE" -f"C:\Program Files\Microsoft ActiveSync\DeIsL1.isu" -c"C:\Program Files\Microsoft ActiveSync\ceuninst.dll"
          Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
          Microsoft Data Access Components KB870669-->C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
          Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
          Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
          Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
          Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
          Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
          Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
          Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
          Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
          Mozilla Firefox (3.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          Mozilla Thunderbird (2.0.0.21)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
          MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
          MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
          MSXML 6.0 Parser (KB925673)-->MsiExec.exe /I{FE9126DB-5F84-495A-BB46-3C724F1C2D08}
          Mulan FTH-->C:\WINDOWS\unin040c.exe -fC:\PROGRA~1\DISNEY~1\MULANF~1\DeIsL1.isu
          My DShot Camera Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5E54A963-5088-4C7E-8253-D06BCFFA8A46}\setup.exe"
          Nero Suite-->C:\Program Files\Fichiers communs\Nero\Uninstall\setupx.exe /uninstall ExtraUninstallID=""
          NeroVision Express Content-->C:\WINDOWS\UNNVEContent.exe /UNINSTALL
          OmniPage SE-->MsiExec.exe /I{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}
          OneCare Advisor (Windows Live Toolbar)-->MsiExec.exe /X{6D7F8D4B-D1A4-402A-973E-31E90940E585}
          OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
          Pen Tablet-->C:\Program Files\Tablet\Pen\Remove.exe /u
          Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
          Pinnacle Hollywood FX 5
          -->C:\WINDOWS\unvise32.exe C:\Program Files\Pinnacle\Hollywood FX 5\uninstal.log
          Pinnacle Hollywood FX Pack0 - Extra FX-->C:\WINDOWS\unvise32.exe C:\WINDOWS\unhfxpack0.log
          Pinnacle PCI Performance Enhancer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3E5A81BA-4702-490A-B729-0BFF6E7CBF96}\setup.exe" -l0x40c
          Pinnacle Systems PCI Performance Enhancer-->C:\PROGRA~1\Pinnacle\PPE\UNWISE.EXE C:\PROGRA~1\Pinnacle\PPE\INSTALL.LOG
          PRODUCT_NAME_REF PRODUCT_VERSION-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8A367C28-423C-48E2-8C76-EBA1171F932A}\apxp.ex_" -l0x40c
          Profound effect Generic Cam recorder-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{81BB044C-3CDD-441C-9A71-EDE87E4DA4C9}\setup.exe" -l0x40c
          Profound effect Hi end Cam recorder-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{48299665-C4D7-4A89-9AD8-2EE4A014F4C6}\setup.exe" -l0x40c
          Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
          Quick Zip 3.06.3-->"C:\Program Files\QuickZip\unins000.exe"
          QuickTime for Windows (32-bit)-->C:\WINDOWS\QTW32DEL.EXE
          QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
          RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          RescuePRO -->MsiExec.exe /X{B215D967-5524-4722-917D-A1457A57FF30}
          Ri4m v5.0.1d-->C:\Program Files\Ripp-it_AM\Ri4m_Uninstal.exe
          SAGEM F@st 800-840-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}\setup.exe" -l0x40c
          Secured eMule Toolbar-->C:\PROGRA~1\SECURE~2\UNWISE.EXE C:\PROGRA~1\SECURE~2\INSTALL.LOG
          Secured eMule-->C:\PROGRA~1\SECURE~1\UNWISE.EXE C:\PROGRA~1\SECURE~1\INSTALL.LOG
          Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
          Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
          Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
          SFR - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
          SoundMAX-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe"
          Studio 9.1 Patch-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{16E217EA-C3E0-402D-8D4F-6189DB74497A}\Setup.exe" -l0x40c UNINSTALL
          Studio 9-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E491AB7-4589-48CA-9CBB-874CB2788391}\Setup.exe" -l0x40c UNINSTALL
          Studio Content DVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B67624DE-75CE-4FAD-9F29-5C115773CE61}\Setup.exe" -l0x40c
          SyncBack-->"C:\Program Files\2BrightSparks\SyncBack\unins000.exe"
          torrent_search Toolbar-->C:\PROGRA~1\TORREN~1\UNWISE.EXE C:\PROGRA~1\TORREN~1\INSTALL.LOG
          Uninstall AutoEye-->C:\WINDOWS\unvise32.exe C:\Program Files\Adobe\Photoshop CS\Modules externes\AutoEye\AutoEye Uninstall.log
          Uninstall DreamSuite Bonus-->C:\WINDOWS\unvise32.exe C:\PROGRAM FILES\ADOBE\ADOBE PHOTOSHOP CS3\MODULES EXTERNES\DreamSuite Bonus\DreamSuite Bonus Uninstall.log
          Uninstall DreamSuite-->C:\WINDOWS\unvise32.exe C:\Program Files\Adobe\Photoshop CS\Modules externes\DreamSuite\DreamSuite Uninstall.log
          Uninstall Mystical-->C:\WINDOWS\unvise32.exe C:\Program Files\Adobe\Photoshop CS\Modules externes\Mystical\Mystical Uninstall.log
          Uninstall MysticalTTC-->C:\WINDOWS\unvise32.exe C:\Program Files\Adobe\Photoshop CS\Modules externes\MysticalTTC\MysticalTTC Uninstall.log
          ViaMichelin Navigation X-930-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{47FF921C-E834-47A6-8CE4-F0A99CDE347F}\setup.exe" -l0x40c
          VideoLAN VLC media player 0.8.6b-->C:\Program Files\VideoLAN\VLC\uninstall.exe
          Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
          Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)-->rundll32.exe C:\PROGRA~1\DIFX\15B7F172FC21855D\DIFxAppA.dll, DIFxARPUninstallDriverPackage C:\WINDOWS\system32\DRVSTORE\grmnusb_09F3E629557EBE4D2BA1A9469BDAE635AC0807AE\grmnusb.inf
          Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
          Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
          Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
          Windows Live Favorites pour Windows Live Toolbar-->MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
          Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
          Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
          Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
          Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
          Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
          Windows Search 4.0-->"C:\WINDOWS\$NtUninstallKB940157$\spuninst\spuninst.exe"
          Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
          Windows XP Service Pack 2-->C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
          Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
          WONswap-->C:\Program Files\WON\WONswap\WONswapUninstall.exe
          XnView 1.90.2-->"C:\Program Files\XnView\unins000.exe"
          Xvid 1.1.2 final uninstall-->"C:\Program Files\XviD\unins001.exe"

          ======Security center information======

          AV: Avira AntiVir PersonalEdition

          ======System event log======

          Computer Name:
          Event Code: 17
          Message: AVGNTFLT successfully loaded

          Record Number: 21957
          Source Name: avgntflt
          Time Written: 20090222084931.000000+060
          Event Type: Informations
          User:

          Computer Name:
          Event Code: 26
          Message: Application popup :  : Machine Check: Regs

          Record Number: 21956
          Source Name: Application Popup
          Time Written: 20090222084931.000000+060
          Event Type: Informations
          User:

          Computer Name:
          Event Code: 26
          Message: Application popup :  : Machine Check:

          Record Number: 21955
          Source Name: Application Popup
          Time Written: 20090222084931.000000+060
          Event Type: Informations
          User:

          Computer Name:
          Event Code: 26
          Message: Application popup :  : Machine Check: Regs

          Record Number: 21954
          Source Name: Application Popup
          Time Written: 20090222084931.000000+060
          Event Type: Informations
          User:

          Computer Name:
          Event Code: 26
          Message: Application popup :  : Machine Check:

          Record Number: 21953
          Source Name: Application Popup
          Time Written: 20090222084931.000000+060
          Event Type: Informations
          User:

          =====Application event log=====

          Computer Name:
          Event Code: 1003
          Message: Le service Windows Search a été démarré.

          Record Number: 14295
          Source Name: Windows Search Service
          Time Written: 20090119060047.000000+060
          Event Type: Informations
          User:

          Computer Name:
          Event Code: 1800
          Message: Le service Centre de sécurité Windows a démarré.

          Record Number: 14294
          Source Name: SecurityCenter
          Time Written: 20090119060040.000000+060
          Event Type: Informations
          User:

          Computer Name:
          Event Code: 4096
          Message:
          Record Number: 14293
          Source Name: Avira AntiVir
          Time Written: 20090119060008.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name:
          Event Code: 1
          Message:
          Record Number: 14292
          Source Name: Bonjour Service
          Time Written: 20090119055959.000000+060
          Event Type: Informations
          User:

          Computer Name:
          Event Code: 1517
          Message: Windows a sauvegardé le Registre utilisateur VOILLET\M VOILLET alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.

          Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

          Record Number: 14291
          Source Name: Userenv
          Time Written: 20090118234455.000000+060
          Event Type: Avertissement
          User: AUTORITE NT\SYSTEM

          =====Security event log=====

          Computer Name:
          Event Code: 850
          Message: Un port générait une erreur d'exception lorsque le Pare-feu Windows a démarré.

          Origine de la stratégie : Stratégie locale

          Profil utilisé : Standard

          Interface : Toutes les interfaces

          Nom : Infrastructure UPnP sur TCP

          Numéro du port : 2869

          Protocole : TCP

          État : Désactivé

          Étendue : Sous-réseau local uniquement

          Record Number: 471921
          Source Name: Security
          Time Written: 20090331083218.000000+120
          Event Type: Succès de l'audit
          User: AUTORITE NT\SYSTEM

          Computer Name:
          Event Code: 850
          Message: Un port générait une erreur d'exception lorsque le Pare-feu Windows a démarré.

          Origine de la stratégie : Stratégie locale

          Profil utilisé : Standard

          Interface : Toutes les interfaces

          Nom : Composant SSDP de l'infrastructure UpnP

          Numéro du port : 1900

          Protocole : UDP

          État : Désactivé

          Étendue : Sous-réseau local uniquement

          Record Number: 471920
          Source Name: Security
          Time Written: 20090331083218.000000+120
          Event Type: Succès de l'audit
          User: AUTORITE NT\SYSTEM

          Computer Name:
          Event Code: 850
          Message: Un port générait une erreur d'exception lorsque le Pare-feu Windows a démarré.

          Origine de la stratégie : Stratégie locale

          Profil utilisé : Standard

          Interface : Toutes les interfaces

          Nom : SMB sur TCP

          Numéro du port : 445

          Protocole : TCP

          État : Désactivé

          Étendue : Sous-réseau local uniquement

          Record Number: 471919
          Source Name: Security
          Time Written: 20090331083218.000000+120
          Event Type: Succès de l'audit
          User: AUTORITE NT\SYSTEM

          Computer Name:
          Event Code: 850
          Message: Un port générait une erreur d'exception lorsque le Pare-feu Windows a démarré.

          Origine de la stratégie : Stratégie locale

          Profil utilisé : Standard

          Interface : Toutes les interfaces

          Nom : Service de session NetBIOS

          Numéro du port : 139

          Protocole : TCP

          État : Désactivé

          Étendue : Sous-réseau local uniquement

          Record Number: 471918
          Source Name: Security
          Time Written: 20090331083218.000000+120
          Event Type: Succès de l'audit
          User: AUTORITE NT\SYSTEM

          Computer Name:
          Event Code: 850
          Message: Un port générait une erreur d'exception lorsque le Pare-feu Windows a démarré.

          Origine de la stratégie : Stratégie locale

          Profil utilisé : Standard

          Interface : Toutes les interfaces

          Nom : Service de datagramme NetBIOS

          Numéro du port : 138

          Protocole : UDP

          État : Désactivé

          Étendue : Sous-réseau local uniquement

          Record Number: 471917
          Source Name: Security
          Time Written: 20090331083218.000000+120
          Event Type: Succès de l'audit
          User: AUTORITE NT\SYSTEM

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\QuickTime\QTSystem\
          "windir"=%SystemRoot%
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
          "PROCESSOR_REVISION"=0a00
          "NUMBER_OF_PROCESSORS"=1
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "FP_NO_HOST_CHECK"=NO
          "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
          "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

          -----------------EOF-----------------
          1. 1/Télécharge TOOLBAR S&D( de Eric_71/Team IDN ) sur ton bureau :

            ( Tuto : https://sites.google.com/site/toolbarsd/aideenimages )

            !! Déconnecte toi et ferme toutes tes applications en cours le temps de la manipe !!

            * Double-clique sur ToolBar SD.exe pour lancer l'outil et laisse toi guider ...
            --> Tapes ( option " recherche " ) puis tape sur [Entrée].

            Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse

            ( le rapport est en outre sauvegardé ici -> C:\TB.txt )

            2/
            Relance Toolbar-S&D en double-cliquant sur le raccourci
            .
            Ø Tape sur "2" puis valide en appuyant sur "Entrée".

            ! Ne ferme pas la fenêtre lors de la suppression !

            Un rapport sera généré, poste son contenu ici.

            NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
            Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
            Tape explorer puis valide.
            1. voici donc le 1er rappotr et je continue

              Option : [1] ( 14/04/2009|12:04 )

              -----------\\ Recherche de Fichiers / Dossiers ...

              C:\Program Files\AskBarDis
              C:\Program Files\AskBarDis\bar
              C:\Program Files\AskBarDis\unins000.dat
              C:\Program Files\AskBarDis\bar\Settings
              C:\Program Files\AskBarDis\bar\Settings\config.dat
              C:\Program Files\AskBarDis\bar\Settings\config.dat.bak

              -----------\\ Extensions

              (M V) - {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} => forecastfox
              (M V) - {4BBDD651-70CF-4821-84F8-2B918CF89CA3} => febe
              (M V) - {73a6fe31-595d-460b-a920-fcc0f8843232} => noscript
              (M V) - {73a6fe31-595d-460b-a920-fcc0f8843232} => noscript
              (M V) - {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} => wot
              (M V) - {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} => wot
              (M V) - {EF522540-89F5-46b9-B6FE-1829E2B572C6} => googlepreview
              (M V) - {e8cba685-930c-1283-6314-a6ae605cc7be} => outlook_2003_bluetb-2.0-tb
              (M V) - {e8cba685-930c-1283-6314-a6ae605cc7be} => outlook_2003_bluetb-2.0-tb
              (M V) - {e8cba685-930c-1283-6314-a6ae605cc7be} => outlook_2003_bluetb__45_2.0__45_tb

              -----------\\ [..\Internet Explorer\Main]

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
              "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
              "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
              "SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
              "Search Bar"="https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5"
              "Start Page"="https://www.google.com/webhp?hl=fr&gws_rd=ssl"
              "First Home Page"="http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
              "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
              "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
              "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"

              --------------------\\ Recherche d'autres infections

              --------------------\\ Cracks & Keygens ..

              C:\DOCUME~1\MV~1\Application Data\Microsoft\Office\Récents\Auto FX Software DreamSuite Gel Series 1.18 CRACK.lnk

              1 - "C:\ToolBar SD\TB_1.txt" - 14/04/2009|12:05 - Option : [1]

              -----------\\ Fin du rapport a 12:05:52,75
              1. le rapport de l'option 2

                -----------\\ ToolBar S&D 1.2.8 XP/Vista

                Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                X86-based PC ( Uniprocessor Free : AMD Athlon(TM) XP 2600+ )
                BIOS : Award Modular BIOS v6.0
                USER : M V ( Administrator )
                BOOT : Normal boot
                Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
                A:\ (USB)
                C:\ (Local Disk) - NTFS - Total:114 Go (Free:15 Go)
                D:\ (CD or DVD)
                E:\ (CD or DVD)

                "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                Option : [2] ( 14/04/2009|12:11 )

                -----------\\ SUPPRESSION

                Supprime! - C:\Program Files\AskBarDis\bar
                Supprime! - C:\Program Files\AskBarDis\unins000.dat
                Supprime! - C:\Program Files\AskBarDis

                -----------\\ Recherche de Fichiers / Dossiers ...

                -----------\\ Extensions

                (M V) - {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} => forecastfox
                (M V) - {4BBDD651-70CF-4821-84F8-2B918CF89CA3} => febe
                (M V) - {73a6fe31-595d-460b-a920-fcc0f8843232} => noscript
                (M V) - {73a6fe31-595d-460b-a920-fcc0f8843232} => noscript
                (M V) - {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} => wot
                (M V) - {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} => wot
                (M V) - {EF522540-89F5-46b9-B6FE-1829E2B572C6} => googlepreview
                (M V) - {e8cba685-930c-1283-6314-a6ae605cc7be} => outlook_2003_bluetb-2.0-tb
                (M V) - {e8cba685-930c-1283-6314-a6ae605cc7be} => outlook_2003_bluetb-2.0-tb
                (M V) - {e8cba685-930c-1283-6314-a6ae605cc7be} => outlook_2003_bluetb__45_2.0__45_tb

                -----------\\ [..\Internet Explorer\Main]

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                "SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
                "Search Bar"="https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5"
                "Start Page"="https://www.google.com/webhp?hl=fr&gws_rd=ssl"
                "First Home Page"="http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1"

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                "Start Page"="https://www.msn.com/fr-fr/"

                --------------------\\ Recherche d'autres infections

                --------------------\\ Cracks & Keygens ..

                C:\DOCUME~1\MV~1\Application Data\Microsoft\Office\Récents\Auto FX Software DreamSuite Gel Series 1.18 CRACK.lnk

                1 - "C:\ToolBar SD\TB_1.txt" - 14/04/2009|12:05 - Option : [1]
                2 - "C:\ToolBar SD\TB_2.txt" - 14/04/2009|12:13 - Option : [2]

                -----------\\ Fin du rapport a 12:13:34,12
                1. Télécharge Superantispyware (SAS)

                  Choisis "enregistrer" et enregistre-le sur ton bureau.

                  Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

                  Créé une icône sur le bureau.

                  Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

                  - Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
                  - Sous Configuration and Preferences, clique sur le bouton "Preferences"
                  - Clique sur l'onglet "Scanning Control "
                  - Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

                  Close browsers before scanning
                  Scan for tracking cookies
                  Terminate memory threats before quarantining
                  - Laisse les autres lignes décochées.

                  - Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

                  - Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

                  Dans la colonne de gauche, coche C:\Fixed Drive.

                  Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

                  Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

                  A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

                  Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

                  Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

                  Pour recopier les informations sur le forum, fais ceci :

                  - après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
                  - Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
                  - Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

                  - Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

                  - Copie son contenu dans ta réponse.

                  Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
                  1. voici le rapport sas ,rien n'a été detecté

                    SUPERAntiSpyware journal de bord
                    https://www.superantispyware.com/

                    Généré 04/14/2009 at 02:54 PM

                    Version du Logiciel : 4.26.1000

                    Core Rules Database Version : 3842
                    Trace Rules Database Version: 1797

                    Genre de Scan : Scan Complète
                    Temps total du Scan : 01:18:19

                    Articles du Mémoire analysés : 559
                    Risques de dommage de Mémoire détectés : 0
                    Articles du Registre analysés : 6543
                    Risques de dommage de Registre détectés : 0
                    Articles de fichier scannés : 39676
                    Risques du Dommage de Fichier Détectés : 0
                    1. Sais tu ce qu'est ce programme?

                      2009-04-11 18:59:23 ----D---- C:\Documents and Settings\All Users\Application Data\iolo
                      1. Suis allez voir , vraiment aucune idée.
                    2. 1- Télécharge Rooter de l'équipe IDN sur ton bureau :
                      https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/Rooter.exe?attachauth=ANoY7cpzQksLcJt-e1z30LGu7t4JjUhh8amzWs_oSPSJpXbXp8ythGbW2WF8ysioh5NNlarrn7zMnYCRfsT5rCwNrfw5_CZYELApylTiY_MGu0G6uKzWpLEF2YXM3tF7nKZZAWj0JSAajXlZhd8dIyI3MrZ-lAIT5ZrAdcrct9_7bshwVpaZRPizuMTv9SDvmvY31BX4Vvvh2F2Brp1cy_K0jtTTfjttEA%3D%3D&attredirects=2

                      ! Déconnecte toi d'internet et ferme toutes applications en cours !

                      * Exécute Rooter et laisse travailler l'outil .

                      * Une fois terminé, poste le rapport obtenu pour analyse ...
                      1. le rapport rooter

                        Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3

                        A:\ [Removable] (Total:0 Mo/Free:0 Mo)
                        C:\ [Fixed] - NTFS - (Total:117232 Mo/Free:3178 Mo)
                        D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
                        E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)

                        14/04/2009|15:50

                        ----------------------\\ Processes..

                        --Locked-- [System Process]
                        ---------- System
                        ---------- \SystemRoot\System32\smss.exe
                        ---------- \??\C:\WINDOWS\system32\csrss.exe
                        ---------- \??\C:\WINDOWS\system32\winlogon.exe
                        ---------- C:\WINDOWS\system32\services.exe
                        ---------- C:\WINDOWS\system32\lsass.exe
                        ---------- C:\WINDOWS\system32\svchost.exe
                        ---------- C:\WINDOWS\system32\svchost.exe
                        --Locked-- ClntSvc.exe
                        ---------- C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
                        ---------- C:\Program Files\BufferZone\BZRPCSS.EXE
                        ---------- C:\WINDOWS\System32\svchost.exe
                        ---------- C:\WINDOWS\system32\svchost.exe
                        ---------- C:\WINDOWS\System32\svchost.exe
                        ---------- C:\WINDOWS\System32\svchost.exe
                        ---------- C:\WINDOWS\Explorer.EXE
                        ---------- C:\WINDOWS\system32\spoolsv.exe
                        ---------- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        ---------- C:\WINDOWS\system32\LVCOMSX.EXE
                        ---------- C:\Program Files\Logitech\Video\LogiTray.exe
                        ---------- C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
                        ---------- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        ---------- C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
                        ---------- C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
                        ---------- C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                        ---------- C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                        ---------- C:\Program Files\Logitech\Video\FxSvr2.exe
                        ---------- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        ---------- C:\Program Files\Bonjour\mDNSResponder.exe
                        ---------- C:\WINDOWS\system32\cisvc.exe
                        ---------- C:\Program Files\Java\jre6\bin\jqs.exe
                        ---------- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        ---------- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                        ---------- C:\WINDOWS\System32\svchost.exe
                        ---------- C:\WINDOWS\system32\Pen_Tablet.exe
                        ---------- C:\WINDOWS\system32\SearchIndexer.exe
                        ---------- C:\WINDOWS\system32\wscntfy.exe
                        ---------- C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
                        ---------- C:\WINDOWS\system32\Pen_Tablet.exe
                        ---------- C:\WINDOWS\System32\alg.exe
                        ---------- C:\WINDOWS\system32\cidaemon.exe
                        ---------- C:\Program Files\XnView\xnview.exe
                        ---------- C:\Program Files\Adobe\Adobe Bridge CS3\Bridge.exe
                        ---------- C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                        ---------- C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe
                        ---------- C:\WINDOWS\system32\SearchProtocolHost.exe
                        ---------- C:\WINDOWS\system32\SearchFilterHost.exe
                        ---------- C:\WINDOWS\system32\cmd.exe
                        ---------- C:\Rooter$\RK.exe

                        ----------------------\\ Search..

                        ----------------------\\ ROOTKIT !!

                        1 - "C:\Rooter$\Rooter_1.txt" - 14/04/2009|15:51

                        ----------------------\\ Scan completed at 15:51
                        1. > Télécharge Dr Web CureIt sur ton Bureau :

                          - Double clique <drweb-cureit.exe> et ensuite clique sur <Analyse>;

                          - Clique <Ok> à l'invite de l'analyse rapide. S'il trouve des processus infectés alors clique le bouton <Oui>.
                          Note : une fenêtre s'ouvrira avec options pour "Commander" ou "50% de réduction" : Quitte en cliquant le "X".
                          - Lorsque le scan rapide est terminé, clique sur le menu <Options> puis <Changer la configuration> ; Choisis l'onglet <Scanner>, et décoche <Analyse heuristique>. Clique ensuite sur <Ok>.
                          - De retour à la fenêtre principale : clique pour activer <Analyse complète>
                          - Clique le bouton avec flèche verte sur la droite, et le scan débutera.
                          - Clique <Oui> pour tout à l'invite "Désinfecter ?" lorsqu'un fichier est détecté, et ensuite clique "Désinfecter".
                          - Lorsque le scan sera complété, regarde si tu peux cliquer sur l' icône, adjacente aux fichiers détectés (plusieurs feuilles l'une sur l'autre). Si oui, alors clique dessus et ensuite clique sur l'icône <Suivant>, au dessous, et choisis <Déplacer en quarantaine l'objet indésirable>.
                          - Du menu principal de l'outil, au haut à gauche, clique sur le menu <Fichier> et choisis <Enregistrer le rapport>. Sauvegarde le rapport sur ton Bureau. Ce dernier se nommera DrWeb.csv
                          - Ferme Dr.Web Cureit
                          - Redémarre ton ordi (important car certains fichiers peuvent être déplacés/réparés au redémarrage).
                          - Suite au redémarrage, poste (Copie/Colle) le contenu du rapport de Dr.Web dans ta prochaine réponse.
                          1. Ok, aprés plusieurs heures de scan voici le rapport

                            InstallPrecisionTime.exe\data010 C:\unzipped\precisiontime2102\InstallPrecisionTime.exe Adware.Gator
                            InstallPrecisionTime.exe C:\unzipped\precisiontime2102 L'archive contient des éléments infectés Quarantaine.
                            Process.exe C:\WINDOWS\system32 Tool.Prockill Quarantaine.
                            restart.exe C:\WINDOWS\system32 Tool.ShutDown.14 Quarantaine.
                        2. C'est toi qui a installé ce logiciel?

                          InstallPrecisionTime.exe\data010 C:\unzipped\precisiontime21­02\InstallPrecisionTime.exe Adware.Gator
                          1. Non ,je n'ai pas le souvenir d'avoir installé ça ,mais on retrouve là ,ce que bitdefender avais trouvé
                            puisque j'avais " Application.claria.précision. time. A"
                        3. Supprimes les logiciels de desinfeciton inutiles avec tool cleaner.Supprimes tout ce qui est en quarantaine dans ton antivirus et dans tes antispywares.

                          Repostes moi un Rsit (supprimes les anciens rapports avant de relancer le scan)
                          1. pour supprimer ce qui est en quarantaine doit- je reprendre un scan avec dr web? ou est ce que je vais les retrouver avec antivir?
                        4. Tu supprimes tout ce qui est en quanrantaine dans ton antivirus et tes antisywares (on verra pour dr web plus tard)
                          1. le dernier rapport Rsi ,reste qq outils que tools cleaner n' a pu supprimer. On verra la suite demain et encore merci de ton aide.

                            Logfile of random's system information tool 1.06 (written by random/random)
                            Run by M V at 2009-04-15 00:32:45
                            Microsoft Windows XP Édition familiale Service Pack 3
                            System drive C: has 15 GB (13%) free of 117 GB
                            Total RAM: 2048 MB (70% free)

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 00:32:51, on 15/04/2009
                            Platform: Windows XP SP3 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\csrss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\BufferZone\CLNTSVC.EXE
                            C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
                            C:\Program Files\BufferZone\BZRPCSS.EXE
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                            C:\WINDOWS\system32\LVCOMSX.EXE
                            C:\Program Files\Logitech\Video\LogiTray.exe
                            C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                            C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
                            C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
                            C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                            C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                            C:\Program Files\Logitech\Video\FxSvr2.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                            C:\Program Files\Bonjour\mDNSResponder.exe
                            C:\WINDOWS\system32\cisvc.exe
                            C:\Program Files\Java\jre6\bin\jqs.exe
                            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                            C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\Pen_Tablet.exe
                            C:\WINDOWS\system32\SearchIndexer.exe
                            C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
                            C:\WINDOWS\system32\Pen_Tablet.exe
                            C:\WINDOWS\system32\wscntfy.exe
                            C:\WINDOWS\System32\alg.exe
                            C:\WINDOWS\system32\cidaemon.exe
                            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                            C:\WINDOWS\system32\SearchProtocolHost.exe
                            C:\WINDOWS\system32\SearchFilterHost.exe
                            C:\Documents and Settings\M VT\Bureau\RSIT.exe
                            C:\WINDOWS\System32\wbem\wmiprvse.exe
                            C:\Program Files\trend micro\M V.exe

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
                            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            R3 - URLSearchHook: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
                            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                            O2 - BHO: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
                            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                            O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                            O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                            O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
                            O3 - Toolbar: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
                            O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                            O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
                            O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                            O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                            O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                            O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
                            O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
                            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                            O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
                            O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                            O4 - HKCU\..\Run: [LDM] \Program\
                            O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
                            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                            O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                            O4 - Startup: Anti-Autorun-inf.lnk = G:\Program Files\Prg Chris\Anti-Autorun.inf\Anti-Autorun.inf.exe
                            O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                            O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                            O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                            O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
                            O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                            O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
                            O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
                            O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
                            O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
                            O8 - Extra context menu item: View EXIF - C:\ViewEXIF\EXIF.htm
                            O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
                            O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
                            O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
                            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O15 - Trusted Zone: https://www.msn.com/fr-fr
                            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                            O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab
                            O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
                            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                            O17 - HKLM\System\CCS\Services\Tcpip\..\{EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4}: NameServer = 208.67.220.220,208.67.222.222
                            O17 - HKLM\System\CCS\Services\Tcpip\..\{F3CED271-D5C7-432C-BF6E-B7E600EEBA78}: NameServer = 208.67.220.220,208.67.222.222
                            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                            O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                            O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                            O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                            O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
                            O23 - Service: BufferZone DCOM Helper (BZDcomLaunch) - Unknown owner - C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
                            O23 - Service: BufferZone RPC Helper (BZRpcSs) - Unknown owner - C:\Program Files\BufferZone\BZRPCSS.EXE
                            O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                            O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                            O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                            O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
                            1. oK A DEMAIN
                              1. Salut ,loloetseb je ne sais pas si tu est disponible mais on peu reprendre quand tu veux ,@+
                            2. Tu dois avoir hijack this sur le bureau,sinon telecharges le ici

                              écharges et installes le logiciel de diagnostic :

                              ici Hijackthis
                              ou ici Hijackthis
                              ou ici Hijackthis

                              ou renommé

                              réouvre hijackthis
                              fais scan only
                              coches ces lignes sur leur gauche:

                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                              O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                              O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                              O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                              O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab
                              O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

                              tu les coches et tu clic sur "fix checked"

                              et tu fermes le programme.

                              Ensuite relances hijack this,tu cliques sur do a scan and save a log.Un rapport va s'editer,postes moi le
                              1. Salut, voici le rapport hijacjack
                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 20:28:43, on 15/04/2009
                                Platform: Windows XP SP3 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\csrss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\BufferZone\CLNTSVC.EXE
                                C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
                                C:\Program Files\BufferZone\BZRPCSS.EXE
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                C:\Program Files\Logitech\Video\LogiTray.exe
                                C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
                                C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
                                C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                                C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                C:\Program Files\Logitech\Video\FxSvr2.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                C:\Program Files\Bonjour\mDNSResponder.exe
                                C:\WINDOWS\system32\cisvc.exe
                                C:\Program Files\Java\jre6\bin\jqs.exe
                                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\Pen_Tablet.exe
                                C:\WINDOWS\system32\SearchIndexer.exe
                                C:\WINDOWS\system32\wscntfy.exe
                                C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
                                C:\WINDOWS\system32\Pen_Tablet.exe
                                C:\WINDOWS\System32\alg.exe
                                C:\WINDOWS\system32\cidaemon.exe
                                C:\Program Files\Adobe\Adobe Bridge CS3\Bridge.exe
                                C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                                C:\Program Files\XnView\xnview.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\Program Files\Windows Live\Contacts\wlcomm.exe
                                C:\Program Files\Windows Live\Messenger\wlcsdk.exe
                                C:\Program Files\XnView\xnview.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                C:\WINDOWS\System32\wbem\wmiprvse.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
                                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                R3 - URLSearchHook: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
                                O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                O2 - BHO: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
                                O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
                                O3 - Toolbar: Secured_eMule Toolbar - {1d1b60fd-b21f-4b9a-8a5f-64e8544828d7} - C:\Program Files\Secured_eMule\tbSec1.dll
                                O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\PINNAC~1\PPE\PPE.EXE
                                O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                                O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                                O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
                                O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
                                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
                                O4 - HKCU\..\Run: [LDM] \Program\
                                O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
                                O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                O4 - Startup: Anti-Autorun-inf.lnk = G:\Program Files\Prg Chris\Anti-Autorun.inf\Anti-Autorun.inf.exe
                                O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                                O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                                O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
                                O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                                O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
                                O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
                                O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
                                O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
                                O8 - Extra context menu item: View EXIF - C:\ViewEXIF\EXIF.htm
                                O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
                                O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
                                O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
                                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O15 - Trusted Zone: https://www.msn.com/fr-fr
                                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab
                                O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
                                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{EBEF871C-A2D7-417F-9DE6-F96A04EFF1A4}: NameServer = 208.67.220.220,208.67.222.222
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{F3CED271-D5C7-432C-BF6E-B7E600EEBA78}: NameServer = 208.67.220.220,208.67.222.222
                                O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                O23 - Service: BufferZone Service (BufferZoneSvc) - Unknown owner - C:\Program Files\BufferZone\CLNTSVC.EXE
                                O23 - Service: BufferZone DCOM Helper (BZDcomLaunch) - Unknown owner - C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE
                                O23 - Service: BufferZone RPC Helper (BZRpcSs) - Unknown owner - C:\Program Files\BufferZone\BZRPCSS.EXE
                                O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                                O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                                O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
                            • 1
                            • 2
                            • 3
                            • 4
                            • 5