Malwarebytes' anti malware

Résolu
Bonjour,

voila hier j ai fais une analyse a mbam et il m a trouvé 2 infections je les ai supprimé et aujourd hui j en refais une et elles sont encore la si quelqu un peux m aider :)

merci :) :)

ci joint le rapport :

Malwarebytes' Anti-Malware 1.36
Version de la base de données: 2171
Windows 6.0.6001 Service Pack 1

24/05/2009 13:01:46
mbam-log-2009-05-24 (13-01-46).txt

Type de recherche: Examen rapide
Eléments examinés: 73541
Temps écoulé: 4 minute(s), 26 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
HKEY_CLASSES_ROOT\scrfile\shell\open\command\ (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\ (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
Configuration: Windows Vista Internet Explorer 7.0

71 réponses

Résumé de la discussion

Deux infections détectées par Malwarebytes lors d'un premier scan réapparaissent lors d'un second scan après suppression, indiquant une infection persistante et nécessitant une analyse plus approfondie et des outils complémentaires. Plusieurs intervenants recommandent d'effectuer un scan complet après mise à jour et d'analyser les rapports avec HijackThis pour repérer les éléments de démarrage et les extensions potentiellement malveillants. D'autres propositions évoquent d'augmenter la fiabilité des résultats par des analyses croisées avec plusieurs antivirus et des rapports (par exemple des fichiers identifiés comme suspects) avant d'appliquer des mesures de quarantaine ou de suppression. Si le problème persiste, démarrer en mode sans échec et réaliser des analyses croisées supplémentaires permet d'isoler les processus malveillants qui pourraient se masquer dans l’environnement système.

Bobot (l’IA à votre service)
  1. bonjour :

    ####### | Install & recherche | #########

    Telecharge et install UsbFix de C_XX & Chiquitine29

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectés sans les ouvrir

    # Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi éxécuter en tant qu'administrateur .

    # Choisi l option 1 ( Recherche )

    # Laisse travailler l outil.

    # Ensuite post le rapport UsbFix.txt qui apparaitra.

    # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
    1. merci pour ta reponse voici le rapport :

      ############################## [ UsbFix V3.025 | Scan ]

      # User : yiayia (Administrateurs) # PC-DE-YIAYIA
      # Update on 22/05/09 by Chiquitine29, C_XX & Chimay8
      # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
      # Start at: 13:19:35 | 24/05/2009

      # Intel(R) Celeron(R) CPU 550 @ 2.00GHz
      # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
      # Internet Explorer 8.0.6001.18702
      # Windows Firewall Status : Disabled
      # AV : Antivirus BitDefender 12.0 [ Enabled | Updated ]
      # FW : Pare-feu BitDefender [ Enabled ]12.0

      # C:\ # Disque fixe local # 111,69 Go (72,35 Go free) [ACER] # NTFS
      # D:\ # Disque fixe local # 111,43 Go (111,34 Go free) [DATA] # NTFS
      # E:\ # Disque CD-ROM # 681,28 Mo (0 Mo free) [1986] # CDFS

      ############################## [ Processus actifs ]

      C:\Windows\System32\smss.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
      C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\LEXBCES.EXE
      C:\Windows\System32\spoolsv.exe
      C:\Windows\System32\LEXPPS.EXE
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\Dwm.exe
      C:\Program Files\AGI\common\win32\PythonService.exe
      C:\Acer\ALaunch\ALaunchSvc.exe
      C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
      C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
      C:\Acer\Empowering Technology\eNet\eNet Service.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\iolo\common\lib\ioloServiceManager.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Acer\Mobility Center\MobilityService.exe
      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\IoctlSvc.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Windows\system32\DRIVERS\xaudio.exe
      C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
      C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
      C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Windows\RtHDVCpl.exe
      C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
      C:\Program Files\Launch Manager\LManager.exe
      C:\Windows\System32\igfxpers.exe
      C:\Program Files\Microsoft IntelliPoint\ipoint.exe
      C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Live\MessengerSearchAddon\msgrsrch.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
      C:\Windows\system32\igfxext.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
      C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
      C:\Windows\ehome\ehmsas.exe
      C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
      C:\Program Files\Windows Media Player\wmpnetwk.exe
      C:\Users\yiayia\AppData\Local\Temp\RtkBtMnt.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\SearchProtocolHost.exe
      C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil9g.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Windows\system32\conime.exe

      ################## [ Registre Startup ]

      HKCU_Main: "SEARCH PAGE"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
      HKCU_Main: "Start Page"="https://www.msn.com/fr-fr"
      HKCU_Main: "Start Page Redirect Cache"="https://www.msn.com/fr-fr?ocid=iehp"
      HKCU_Main: "Start Page Redirect Cache AcceptLangs"="fr"
      HKCU_Main: "Window Title"=""
      HKLM_logon: "Userinit"="C:\\Windows\\system32\\userinit.exe,"
      HKLM_logon: "DefaultUserName"="yiayia"
      HKLM_logon: "LegalNoticeCaption"=""
      HKLM_logon: "LegalNoticeText"=""
      HKLM_Run: RtHDVCpl=RtHDVCpl.exe
      HKLM_Run: eDataSecurity Loader=C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
      HKLM_Run: LManager=C:\PROGRA~1\LAUNCH~1\LManager.exe
      HKLM_Run: Apoint=C:\Program Files\Apoint2K\Apoint.exe
      HKLM_Run: IgfxTray=C:\Windows\system32\igfxtray.exe
      HKLM_Run: HotKeysCmds=C:\Windows\system32\hkcmd.exe
      HKLM_Run: Persistence=C:\Windows\system32\igfxpers.exe
      HKLM_Run: IntelliPoint="C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
      HKLM_Run: BDAgent="C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
      HKLM_Run: BitDefender Antiphishing Helper="C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
      HKLM_Run: WarReg_PopUp=C:\Acer\WR_PopUp\WarReg_PopUp.exe
      HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
      HKCU_Run: ehTray.exe=C:\Windows\ehome\ehTray.exe
      HKCU_Run: msnlivesearch=C:\Program Files\Windows Live\MessengerSearchAddon\msgrsrch.exe /Run
      HKCU_Run: ISUSPM Startup=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
      HKCU_Run: WMPNSCFG=C:\Program Files\Windows Media Player\WMPNSCFG.exe
      HKCU_Run: Uniblue RegistryBooster 2009=c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
      HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

      ################## [ Fichiers # Dossiers infectieux ]

      Found ! E:\autorun.ini
      Found ! E:\autorun.inf

      ################## [ Registre # Clés Run infectieuses ]

      Found ! HKLM\software\microsoft\security center\\ "UacDisableNotify"
      # -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 )

      ################## [ Registre # Mountpoints2 ]

      HKCU\...\Explorer\MountPoints2\{f008705e-e21a-11dc-94c3-806e6f6e6963}\Shell\AutoRun\Command

      ################## [ Informations # Fichier Suspect ]

      ################## [ Cracks # Keygens # Serials ]

      # -> Nothing found !

      ################## [ ! Fin du rapport # UsbFix V3.025 ! ]
      1. ######## | Suppression | ########

        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectés sans les ouvrir

        # Double clic sur le raccourci UsbFix présent sur ton bureau

        # choisi l option 2 ( Suppression )

        # Ton bureau disparaitra et le pc redémarrera .

        # Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

        # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

        # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        ######### | Désinstallation | #######

        # Double clic sur le raccourci UsbFix présent sur ton bureau

        # Choisi l option Désinstaller ....
        1. voici le rapport :

          ############################## [ UsbFix V3.025 | Cleaning ]

          # User : yiayia (Administrateurs) # PC-DE-YIAYIA
          # Update on 22/05/09 by Chiquitine29, C_XX & Chimay8
          # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
          # Start at: 13:34:17 | 24/05/2009

          # Intel(R) Celeron(R) CPU 550 @ 2.00GHz
          # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
          # Internet Explorer 8.0.6001.18702
          # Windows Firewall Status : Disabled
          # AV : Antivirus BitDefender 12.0 [ Enabled | Updated ]
          # FW : Pare-feu BitDefender [ Enabled ]12.0

          # C:\ # Disque fixe local # 111,69 Go (72,37 Go free) [ACER] # NTFS
          # D:\ # Disque fixe local # 111,43 Go (111,34 Go free) [DATA] # NTFS
          # E:\ # Disque CD-ROM # 681,28 Mo (0 Mo free) [1986] # CDFS

          ############################## [ Processus actifs ]

          C:\Windows\System32\smss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
          C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\LEXBCES.EXE
          C:\Windows\System32\spoolsv.exe
          C:\Windows\System32\LEXPPS.EXE
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\Explorer.EXE
          C:\Windows\system32\svchost.exe
          C:\Program Files\AGI\common\win32\PythonService.exe
          C:\Acer\ALaunch\ALaunchSvc.exe
          C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
          C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
          C:\Acer\Empowering Technology\eNet\eNet Service.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\iolo\common\lib\ioloServiceManager.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Acer\Mobility Center\MobilityService.exe
          C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\IoctlSvc.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Windows\system32\DRIVERS\xaudio.exe
          C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
          C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
          C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Windows\system32\runonce.exe
          C:\Windows\system32\conime.exe
          C:\Windows\system32\PresentationSettings.exe
          C:\Windows\system32\taskeng.exe

          ################## [ Fichiers # Dossiers infectieux ]

          (!) Not Deleted ! E:\autorun.ini
          (!) Not Deleted ! E:\autorun.inf

          ################## [ Registre # Clés Run infectieuses ]

          # HKLM\software\microsoft\security center\\ "UacDisableNotify"
          # -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 ) # -> Reset sucessfully !

          ################## [ Registre # Mountpoints2 ]

          Deleted ! HKCU\...\Explorer\MountPoints2\{f008705e-e21a-11dc-94c3-806e6f6e6963}\Shell\AutoRun\Command

          ################## [ Listing des fichiers présent ]

          [18/09/2006 23:43|--a------|24] - C:\autoexec.bat
          [19/01/2008 09:45|-rahs----|333203] - C:\bootmgr
          [18/09/2006 23:43|--a------|10] - C:\config.sys
          [22/07/2008 00:21|-rahs----|0] - C:\IO.SYS
          [22/07/2008 00:21|-rahs----|0] - C:\MSDOS.SYS
          [?|?|?] - C:\pagefile.sys
          [24/05/2009 13:41|--a------|3941] - C:\UsbFix.txt
          [19/12/2006 11:09|-r-------|120904] - E:\AUTORUN.EXE
          [19/06/2003 08:57|-r-------|45] - E:\AUTORUN.INF
          [24/10/2008 16:14|-r-------|123] - E:\AUTORUN.INI
          [29/08/2002 12:44|-r-------|1703936] - E:\GdiPlus.dll
          [17/09/2004 08:16|-r-------|13942] - E:\MICRO.ICO
          [09/07/2007 11:52|-r-------|522112] - E:\NavigMA.exe
          [01/12/2008 13:21|-r-------|17545] - E:\navigma.xml

          ################## [ Vaccination ]

          # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
          # D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

          ################## [ Informations # Fichier Suspect ]

          ################## [ Cracks # Keygens # Serials ]

          # -> Nothing found !

          ################## [ ! Fin du rapport # UsbFix V3.025 ! ]

          mon ordi s eteint comme ça et a l allumage me met un ecran noir avec un petit trait clignotant dans le coin en haut a gauche ça viendrait de ça a ton avis ? :)
          1. il peut y avoir un tas de raisons pourquoi le pc s'eteind :)

            pas forcement viral d'ailleurs , juste une surchauffe , un composant qui faiblit...etc...

            Salut,

            commences par ceci pour voir ce qu'il en est,avoir un diagnostic précis et donc repérer les infections possibles et les neutraliser:

            Télécharges et installes le logiciel de diagnostic :

            ici Hijackthis
            ou ici Hijackthis
            ou ici Hijackthis

            1- Cliques sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'installation .
            A la fin de l'installe , le prg ce lance automatiquement : fermes le en cliquant sur la croix rouge .
            Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
            "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

            tuto pour utilisation :(merci balltrap34)
            Regardes ici, c'est parfaitement expliqué en images ,

            2- !! Déconnectes toi et fermes toute tes applications en cours !!

            Cliques sur le raccourci du bureau pour lancer le prg :

            S'il ne se lance pas clique ici

            fais un scan HijackThis en cliquant sur : "Do a system scan and save a logfile"

            --->copies-colles le rapport généré pour analyse
            1. voila

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 14:11:06, on 24/05/2009
              Platform: Windows Vista SP1 (WinNT 6.00.1905)
              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Windows\RtHDVCpl.exe
              C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
              C:\Program Files\Launch Manager\LManager.exe
              C:\Windows\System32\hkcmd.exe
              C:\Windows\System32\igfxpers.exe
              C:\Program Files\Microsoft IntelliPoint\ipoint.exe
              C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Windows Live\MessengerSearchAddon\msgrsrch.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Users\yiayia\AppData\Local\Temp\RtkBtMnt.exe
              C:\Windows\system32\igfxext.exe
              C:\Windows\system32\igfxsrvc.exe
              C:\Windows\system32\igfxsrvc.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
              C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
              C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
              C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
              C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
              C:\Program Files\trend micro\HijackThis\HijackThis.exe

              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              R3 - URLSearchHook: (no name) - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
              O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: Iminent.SearchTheWeb.HelperObject - {0E896FCA-D07E-45FE-901F-6A26FCF59C02} - mscoree.dll (file missing)
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
              O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
              O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
              O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
              O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
              O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
              O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
              O4 - HKCU\..\Run: [msnlivesearch] C:\Program Files\Windows Live\MessengerSearchAddon\msgrsrch.exe /Run
              O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - Global Startup: Empowering Technology Launcher.lnk = ?
              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
              O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
              O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
              O13 - Gopher Prefix:
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{AA5F1747-800F-4F3F-B4FA-703DE1C18B6D}: NameServer = 208.67.222.222,208.67.220.220
              O20 - AppInit_DLLs: C:\Windows\System32\eNetHook.dll
              O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
              O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
              O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
              O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
              O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
              O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
              O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
              O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
              O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
              O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
              O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
              O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
              O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
              O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
              O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
              O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
              1. je dois y voir plus profond dans l'appareil :

                Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                ! Déconnecte toi et ferme toutes tes applications en cours !

                Double-clique sur " RSIT.exe " pour le lancer .

                -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                * Devant l'option "List files/folders created ..." , tu choisis : 2 months

                * clique ensuite sur " Continue " pour lancer l'analyse ...

                -> laisse faire le scan et ne touche pas au PC ...

                Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

                Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                Important : poste un rapport, puis l'autre dans la réponse suivante
                Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

                ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
                1. voici le log :

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by yiayia at 2009-05-24 14:37:18
                  Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                  System drive C: has 74 GB (65%) free of 114 GB
                  Total RAM: 2037 MB (43% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 14:37:21, on 24/05/2009
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\RtHDVCpl.exe
                  C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
                  C:\Program Files\Launch Manager\LManager.exe
                  C:\Windows\System32\hkcmd.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                  C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Windows Live\MessengerSearchAddon\msgrsrch.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Users\yiayia\AppData\Local\Temp\RtkBtMnt.exe
                  C:\Windows\system32\igfxext.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                  C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                  C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                  C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
                  C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
                  C:\Users\yiayia\Desktop\RSIT.exe
                  C:\Users\yiayia\Desktop\RSIT.exe
                  C:\Program Files\trend micro\HijackThis\yiayia.exe

                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: (no name) - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
                  O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Iminent.SearchTheWeb.HelperObject - {0E896FCA-D07E-45FE-901F-6A26FCF59C02} - mscoree.dll (file missing)
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                  O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                  O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                  O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
                  O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
                  O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [msnlivesearch] C:\Program Files\Windows Live\MessengerSearchAddon\msgrsrch.exe /Run
                  O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                  O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                  O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{AA5F1747-800F-4F3F-B4FA-703DE1C18B6D}: NameServer = 208.67.222.222,208.67.220.220
                  O20 - AppInit_DLLs: C:\Windows\System32\eNetHook.dll
                  O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
                  O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                  O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
                  O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                  O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                  O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                  O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                  O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
                  O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
                  O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                  O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                  O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                  O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
                  O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                  O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                  1. et info :

                    info.txt logfile of random's system information tool 1.06 2009-05-24 14:30:06

                    ======Uninstall list======

                    -->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
                    -->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
                    -->C:\Windows\UNNeroMediaHome.exe /UNINSTALL
                    -->C:\Windows\UNNeroShowTime.exe /UNINSTALL
                    -->C:\Windows\UNNeroVision.exe /UNINSTALL
                    -->C:\Windows\UNRecode.exe /UNINSTALL
                    -->MsiExec /X{A7E07C2B-2220-4415-87E3-784D5814BC93}
                    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{31403E22-2FDB-452F-AE9E-20854633226D}\Setup.EXE" -uninst
                    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A450831D-25F6-4F42-9662-D000B25E0D82}\setup.exe" -uninstall
                    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\setup.exe" -uninstall
                    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B145EC69-66F5-11D8-9D75-000129760D75}\setup.exe" -uninstall
                    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B804C424-B66D-447A-84BD-C6B88C392C3A}\setup.exe" -uninstall
                    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F79A208D-D929-11D9-9D77-000129760D75}\setup.exe" -uninstall
                    32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
                    Acer Arcade Deluxe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\setup.exe" -uninstall
                    Acer Crystal Eye webcam-->C:\Program Files\InstallShield Installation Information\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}\setup.exe -runfromtemp -l0x040c -removeonly -u
                    Acer Crystal Eye webcam-->C:\Program Files\InstallShield Installation Information\{AA047D7C-5E7C-4878-B75C-77589151B563}\setup.exe -runfromtemp -l0x0009 -removeonly
                    Acer eDataSecurity Management-->C:\Acer\Empowering Technology\eDataSecurity\eDSnstHelper.exe -Operation UNINSTALL
                    Acer eLock Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}\setup.exe" -l0x40c -removeonly
                    Acer Empowering Technology-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB6097D9-D722-4987-BD9E-A076E2848EE2}\setup.exe" -l0x40c -removeonly
                    Acer eNet Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C06554A1-2C1E-4D20-B613-EE62C79927CC}\setup.exe" -l0x40c -removeonly
                    Acer ePower Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{58E5844B-7CE2-413D-83D1-99294BF6C74F}\setup.exe" -l0x40c -removeonly
                    Acer ePresentation Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BF839132-BD43-4056-ACBF-4377F4A88E2A}\setup.exe" -l0x40c -removeonly
                    Acer eSettings Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CE65A9A0-9686-45C6-9098-3C9543A412F0}\setup.exe" -l0x40c -removeonly
                    Acer GridVista-->C:\Windows\UnInst32.exe GridV.UNI
                    Acer Mobility Center Plug-In-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{11316260-6666-467B-AC34-183FCB5D4335}\setup.exe" -l0x40c -removeonly
                    Acer ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
                    Acer Tour-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94389919-B0AA-4882-9BE8-9F0B004ECA35}\setup.exe" -l0x40c -removeonly
                    Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
                    Adobe Acrobat 5.0-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
                    Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                    Adobe Flash Player Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                    Adobe Reader 9.1.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
                    ALPS Touch Pad Driver-->C:\Program Files\Apoint2K\Uninstap.exe ADDREMOVE
                    AnyDVD-->"C:\Program Files\SlySoft\AnyDVD\AnyDVD-uninst.exe" /D="C:\Program Files\SlySoft\AnyDVD"
                    Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                    AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
                    BitDefender Total Security 2009-->MsiExec.exe /X{C731ACA8-EEE2-4B5A-9838-41D0AAD080C8}
                    CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                    Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                    CloneDVD2-->"C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
                    DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
                    Farm Frenzy 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E915304A-EDA2-4EDF-B92C-BA9356EB0C52}\Setup.exe" -l0x40c
                    Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
                    GOM Player-->"C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
                    HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118\UIU32m.exe -U -IAcrZUn32z.inf
                    HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                    HP Customer Participation Program 8.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
                    HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
                    HP OCR Software 8.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
                    HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
                    HP Photosmart.All-In-One Driver Software 8.0 .A-->C:\Program Files\HP\Digital Imaging\{282E5AB2-8E47-4571-B6FA-6B512555B557}\setup\hpzscr01.exe -datfile hposcr18.dat -onestop -showdisconnect -forcereboot
                    HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
                    HP Product Detection-->MsiExec.exe /X{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
                    HP Solution Center 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
                    HP Update-->MsiExec.exe /X{7059BDA7-E1DB-442C-B7A1-6144596720A4}
                    HPSSupply-->MsiExec.exe /X{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}
                    Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                    Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                    Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
                    iolo technologies' System Mechanic-->"C:\Program Files\iolo\System Mechanic\unins000.exe"
                    Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
                    Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
                    Launch Manager-->C:\Windows\UnInst32.exe LManager.UNI
                    Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                    Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                    Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                    Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                    Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                    Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                    Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
                    Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
                    Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
                    Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
                    Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                    Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                    Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                    Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                    Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                    Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                    Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                    Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                    Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                    Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                    Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
                    Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                    Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                    Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                    Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                    Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
                    Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                    Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
                    Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                    Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                    MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                    MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                    MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
                    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                    MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
                    Nero 8-->MsiExec.exe /X{9A5B876D-A900-4AAB-B557-DE827BE46E6C}
                    neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
                    NTI Backup NOW! 4.7-->"C:\Program Files\InstallShield Installation Information\{1598034D-7147-432C-8CA8-888E0632D124}\setup.exe" -removeonly
                    NTI Backup NOW! 4.7-->C:\Program Files\InstallShield Installation Information\{1598034D-7147-432C-8CA8-888E0632D124}\setup.exe -runfromtemp -l0x040c
                    NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
                    NVIDIA PhysX v8.09.04-->MsiExec.exe /X{A7E07C2B-2220-4415-87E3-784D5814BC93}
                    OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
                    Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                    PowerProducer 3.72-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.EXE" -uninstall
                    Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
                    Remue-méninges la saison des fruits-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F4F88D0-99D4-4D8F-8529-444BB169FB6B}\Setup.exe" -l0x40c
                    Revo Uninstaller 1.83-->C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
                    Search Settings 1.2-->MsiExec.exe /X{D0C73318-7B4A-4D16-A0C4-3B83F075EA88}
                    Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                    Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                    Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
                    Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
                    Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                    VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
                    VideoLAN VLC media player 0.8.6i-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                    Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
                    Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
                    Visual C++ 8.0 CRT (x86) WinSXS MSM-->MsiExec.exe /I{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}
                    Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                    Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                    Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
                    Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                    Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
                    Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                    Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
                    Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

                    ======Security center information======

                    AV: Antivirus BitDefender
                    FW: Pare-feu BitDefender
                    AS: BitDefender AntiSpam
                    AS: Windows Defender

                    ======System event log======

                    Computer Name: PC-de-yiayia
                    Event Code: 1003
                    Message:
                    Record Number: 54870
                    Source Name: Microsoft-Windows-Dhcp-Client
                    Time Written: 20080729093840.000000-000
                    Event Type: Avertissement
                    User:

                    Computer Name: PC-de-yiayia
                    Event Code: 1002
                    Message: Le bail de l'adresse IP 192.168.2.19 pour la carte réseau dont l'adresse réseau est 001F3A3EB195 a été refusé par le serveur DHCP 192.168.1.1 (celui-ci a envoyé un message DHCPNACK).
                    Record Number: 54871
                    Source Name: Microsoft-Windows-Dhcp-Client
                    Time Written: 20080729093840.000000-000
                    Event Type: Erreur
                    User:

                    Computer Name: PC-de-yiayia
                    Event Code: 4226
                    Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
                    Record Number: 54888
                    Source Name: Tcpip
                    Time Written: 20080729101639.479208-000
                    Event Type: Avertissement
                    User:

                    Computer Name: PC-de-yiayia
                    Event Code: 6008
                    Message: L'arrêt système précédant à 20:54:23 le 29/07/2008 n'était pas prévu.
                    Record Number: 54892
                    Source Name: EventLog
                    Time Written: 20080729185656.000000-000
                    Event Type: Erreur
                    User:

                    Computer Name: PC-de-yiayia
                    Event Code: 4
                    Message: Broadcom NetLink (TM) Fast Ethernet: The network link is down. Check to make sure the network cable is properly connected.
                    Record Number: 54899
                    Source Name: b57nd60x
                    Time Written: 20080729185649.962886-000
                    Event Type: Avertissement
                    User:

                    =====Application event log=====

                    Computer Name: PC-de-yiayia
                    Event Code: 1530
                    Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                    DÉTAIL -
                    1 user registry handles leaked from \Registry\User\S-1-5-21-2042034648-109248656-1572164679-1000_Classes:
                    Process 908 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000_CLASSES

                    Record Number: 56852
                    Source Name: Microsoft-Windows-User Profiles Service
                    Time Written: 20090524110441.000000-000
                    Event Type: Avertissement
                    User: AUTORITE NT\SYSTEM

                    Computer Name: PC-de-yiayia
                    Event Code: 1530
                    Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                    DÉTAIL -
                    5 user registry handles leaked from \Registry\User\S-1-5-21-2042034648-109248656-1572164679-1000:
                    Process 904 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000
                    Process 1344 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\Microsoft\Internet Explorer\SearchUrl
                    Process 1344 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\AppDataLow\Software\Yahoo\Companion
                    Process 1344 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\Microsoft\Internet Explorer\URLSearchHooks
                    Process 1344 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\Microsoft\Internet Explorer\SearchScopes

                    Record Number: 56887
                    Source Name: Microsoft-Windows-User Profiles Service
                    Time Written: 20090524112952.000000-000
                    Event Type: Avertissement
                    User: AUTORITE NT\SYSTEM

                    Computer Name: PC-de-yiayia
                    Event Code: 1530
                    Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                    DÉTAIL -
                    2 user registry handles leaked from \Registry\User\S-1-5-21-2042034648-109248656-1572164679-1000_Classes:
                    Process 904 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000_CLASSES
                    Process 552 (\Device\HarddiskVolume2\Windows\System32\csrss.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000_CLASSES

                    Record Number: 56888
                    Source Name: Microsoft-Windows-User Profiles Service
                    Time Written: 20090524112953.000000-000
                    Event Type: Avertissement
                    User: AUTORITE NT\SYSTEM

                    Computer Name: PC-de-yiayia
                    Event Code: 1530
                    Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                    DÉTAIL -
                    5 user registry handles leaked from \Registry\User\S-1-5-21-2042034648-109248656-1572164679-1000:
                    Process 908 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000
                    Process 588 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\Microsoft\Internet Explorer\SearchUrl
                    Process 588 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\AppDataLow\Software\Yahoo\Companion
                    Process 588 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\Microsoft\Internet Explorer\URLSearchHooks
                    Process 588 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\Microsoft\Internet Explorer\SearchScopes

                    Record Number: 56924
                    Source Name: Microsoft-Windows-User Profiles Service
                    Time Written: 20090524115334.000000-000
                    Event Type: Avertissement
                    User: AUTORITE NT\SYSTEM

                    Computer Name: PC-de-yiayia
                    Event Code: 1530
                    Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                    DÉTAIL -
                    2 user registry handles leaked from \Registry\User\S-1-5-21-2042034648-109248656-1572164679-1000_Classes:
                    Process 908 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000_CLASSES
                    Process 552 (\Device\HarddiskVolume2\Windows\System32\csrss.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000_CLASSES

                    Record Number: 56925
                    Source Name: Microsoft-Windows-User Profiles Service
                    Time Written: 20090524115334.000000-000
                    Event Type: Avertissement
                    User: AUTORITE NT\SYSTEM

                    =====Security event log=====

                    Computer Name: PC-de-yiayia
                    Event Code: 4672
                    Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

                    Sujet :
                    ID de sécurité : S-1-5-18
                    Nom du compte : SYSTEM
                    Domaine du compte : AUTORITE NT
                    ID d’ouverture de session : 0x3e7

                    Privilèges : SeAssignPrimaryTokenPrivilege
                    SeTcbPrivilege
                    SeSecurityPrivilege
                    SeTakeOwnershipPrivilege
                    SeLoadDriverPrivilege
                    SeBackupPrivilege
                    SeRestorePrivilege
                    SeDebugPrivilege
                    SeAuditPrivilege
                    SeSystemEnvironmentPrivilege
                    SeImpersonatePrivilege
                    Record Number: 53352
                    Source Name: Microsoft-Windows-Security-Auditing
                    Time Written: 20090303105950.469721-000
                    Event Type: Succès de l'audit
                    User:

                    Computer Name: PC-de-yiayia
                    Event Code: 4624
                    Message: L’ouverture de session d’un compte s’est correctement déroulée.

                    Sujet :
                    ID de sécurité : S-1-5-18
                    Nom du compte : PC-DE-YIAYIA$
                    Domaine du compte : WORKGROUP
                    ID d’ouverture de session : 0x3e7

                    Type d’ouverture de session : 5

                    Nouvelle ouverture de session :
                    ID de sécurité : S-1-5-20
                    Nom du compte : SERVICE RÉSEAU
                    Domaine du compte : AUTORITE NT
                    ID d’ouverture de session : 0x3e4
                    GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                    Informations sur le processus :
                    ID du processus : 0x254
                    Nom du processus : C:\Windows\System32\services.exe

                    Informations sur le réseau :
                    Nom de la station de travail :
                    Adresse du réseau source : -
                    Port source : -

                    Informations détaillées sur l’authentification :
                    Processus d’ouverture de session : Advapi
                    Package d’authentification : Negotiate
                    Services en transit : -
                    Nom du package (NTLM uniquement) : -
                    Longueur de la clé : 0

                    Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

                    Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

                    Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

                    Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

                    Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

                    Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
                    - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
                    - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
                    - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
                    - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
                    Record Number: 53353
                    Source Name: Microsoft-Windows-Security-Auditing
                    Time Written: 20090303105950.797323-000
                    Event Type: Succès de l'audit
                    User:

                    Computer Name: PC-de-yiayia
                    Event Code: 4672
                    Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

                    Sujet :
                    ID de sécurité : S-1-5-20
                    Nom du compte : SERVICE RÉSEAU
                    Domaine du compte : AUTORITE NT
                    ID d’ouverture de session : 0x3e4

                    Privilèges : SeAssignPrimaryTokenPrivilege
                    SeAuditPrivilege
                    SeImpersonatePrivilege
                    Record Number: 53354
                    Source Name: Microsoft-Windows-Security-Auditing
                    Time Written: 20090303105950.797323-000
                    Event Type: Succès de l'audit
                    User:

                    Computer Name: PC-de-yiayia
                    Event Code: 4648
                    Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

                    Sujet :
                    ID de sécurité : S-1-5-18
                    Nom du compte : PC-DE-YIAYIA$
                    Domaine du compte : WORKGROUP
                    ID d’ouverture de session : 0x3e7
                    GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                    Compte dont les informations d’identification ont été utilisées :
                    Nom du compte : SYSTEM
                    Domaine du compte : AUTORITE NT
                    GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                    Serveur cible :
                    Nom du serveur cible : localhost
                    Informations supplémentaires : localhost

                    Informations sur le processus :
                    ID du processus : 0x254
                    Nom du processus : C:\Windows\System32\services.exe

                    Informations sur le réseau :
                    Adresse du réseau : -
                    Port : -

                    Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
                    Record Number: 53355
                    Source Name: Microsoft-Windows-Security-Auditing
                    Time Written: 20090303105950.922124-000
                    Event Type: Succès de l'audit
                    User:

                    Computer Name: PC-de-yiayia
                    Event Code: 4624
                    Message: L’ouverture de session d’un compte s’est correctement déroulée.

                    Sujet :
                    ID de sécurité : S-1-5-18
                    Nom du compte : PC-DE-YIAYIA$
                    Domaine du compte : WORKGROUP
                    ID d’ouverture de session : 0x3e7

                    Type d’ouverture de session : 5

                    Nouvelle ouverture de session :
                    ID de sécurité : S-1-5-18
                    Nom du compte : SYSTEM
                    Domaine du compte : AUTORITE NT
                    ID d’ouverture de session : 0x3e7
                    GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                    Informations sur le processus :
                    ID du processus : 0x254
                    Nom du processus : C:\Windows\System32\services.exe

                    Informations sur le réseau :
                    Nom de la station de travail :
                    Adresse du réseau source : -
                    Port source : -

                    Informations détaillées sur l’authentification :
                    Processus d’ouverture de session : Advapi
                    Package d’authentification : Negotiate
                    Services en transit : -
                    Nom du package (NTLM uniquement) : -
                    Longueur de la clé : 0

                    Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

                    Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

                    Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

                    Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

                    Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

                    Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
                    - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
                    - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
                    - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
                    - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
                    Record Number: 53356
                    Source Name: Microsoft-Windows-Security-Auditing
                    Time Written: 20090303105950.922124-000
                    Event Type: Succès de l'audit
                    User:

                    ======Environment variables======

                    "ComSpec"=%SystemRoot%\system32\cmd.exe
                    "FP_NO_HOST_CHECK"=NO
                    "OS"=Windows_NT
                    "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Windows\System32\WbemC:\Program Files\DMV\MaxTV4\plugins
                    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                    "PROCESSOR_ARCHITECTURE"=x86
                    "TEMP"=%SystemRoot%\TEMP
                    "TMP"=%SystemRoot%\TEMP
                    "USERNAME"=SYSTEM
                    "windir"=%SystemRoot%
                    "PROCESSOR_LEVEL"=6
                    "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 22 Stepping 1, GenuineIntel
                    "PROCESSOR_REVISION"=1601
                    "NUMBER_OF_PROCESSORS"=1

                    -----------------EOF-----------------
                    1. et info :

                      info.txt logfile of random's system information tool 1.06 2009-05-24 14:30:06

                      ======Uninstall list======

                      -->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
                      -->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
                      -->C:\Windows\UNNeroMediaHome.exe /UNINSTALL
                      -->C:\Windows\UNNeroShowTime.exe /UNINSTALL
                      -->C:\Windows\UNNeroVision.exe /UNINSTALL
                      -->C:\Windows\UNRecode.exe /UNINSTALL
                      -->MsiExec /X{A7E07C2B-2220-4415-87E3-784D5814BC93}
                      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{31403E22-2FDB-452F-AE9E-20854633226D}\Setup.EXE" -uninst
                      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A450831D-25F6-4F42-9662-D000B25E0D82}\setup.exe" -uninstall
                      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\setup.exe" -uninstall
                      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B145EC69-66F5-11D8-9D75-000129760D75}\setup.exe" -uninstall
                      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B804C424-B66D-447A-84BD-C6B88C392C3A}\setup.exe" -uninstall
                      -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F79A208D-D929-11D9-9D77-000129760D75}\setup.exe" -uninstall
                      32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
                      Acer Arcade Deluxe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\setup.exe" -uninstall
                      Acer Crystal Eye webcam-->C:\Program Files\InstallShield Installation Information\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}\setup.exe -runfromtemp -l0x040c -removeonly -u
                      Acer Crystal Eye webcam-->C:\Program Files\InstallShield Installation Information\{AA047D7C-5E7C-4878-B75C-77589151B563}\setup.exe -runfromtemp -l0x0009 -removeonly
                      Acer eDataSecurity Management-->C:\Acer\Empowering Technology\eDataSecurity\eDSnstHelper.exe -Operation UNINSTALL
                      Acer eLock Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}\setup.exe" -l0x40c -removeonly
                      Acer Empowering Technology-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB6097D9-D722-4987-BD9E-A076E2848EE2}\setup.exe" -l0x40c -removeonly
                      Acer eNet Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C06554A1-2C1E-4D20-B613-EE62C79927CC}\setup.exe" -l0x40c -removeonly
                      Acer ePower Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{58E5844B-7CE2-413D-83D1-99294BF6C74F}\setup.exe" -l0x40c -removeonly
                      Acer ePresentation Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BF839132-BD43-4056-ACBF-4377F4A88E2A}\setup.exe" -l0x40c -removeonly
                      Acer eSettings Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CE65A9A0-9686-45C6-9098-3C9543A412F0}\setup.exe" -l0x40c -removeonly
                      Acer GridVista-->C:\Windows\UnInst32.exe GridV.UNI
                      Acer Mobility Center Plug-In-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{11316260-6666-467B-AC34-183FCB5D4335}\setup.exe" -l0x40c -removeonly
                      Acer ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
                      Acer Tour-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94389919-B0AA-4882-9BE8-9F0B004ECA35}\setup.exe" -l0x40c -removeonly
                      Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
                      Adobe Acrobat 5.0-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
                      Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                      Adobe Flash Player Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                      Adobe Reader 9.1.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
                      ALPS Touch Pad Driver-->C:\Program Files\Apoint2K\Uninstap.exe ADDREMOVE
                      AnyDVD-->"C:\Program Files\SlySoft\AnyDVD\AnyDVD-uninst.exe" /D="C:\Program Files\SlySoft\AnyDVD"
                      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                      AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
                      BitDefender Total Security 2009-->MsiExec.exe /X{C731ACA8-EEE2-4B5A-9838-41D0AAD080C8}
                      CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                      Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                      CloneDVD2-->"C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
                      DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
                      Farm Frenzy 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E915304A-EDA2-4EDF-B92C-BA9356EB0C52}\Setup.exe" -l0x40c
                      Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
                      GOM Player-->"C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
                      HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118\UIU32m.exe -U -IAcrZUn32z.inf
                      HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                      HP Customer Participation Program 8.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
                      HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
                      HP OCR Software 8.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
                      HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
                      HP Photosmart.All-In-One Driver Software 8.0 .A-->C:\Program Files\HP\Digital Imaging\{282E5AB2-8E47-4571-B6FA-6B512555B557}\setup\hpzscr01.exe -datfile hposcr18.dat -onestop -showdisconnect -forcereboot
                      HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
                      HP Product Detection-->MsiExec.exe /X{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
                      HP Solution Center 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
                      HP Update-->MsiExec.exe /X{7059BDA7-E1DB-442C-B7A1-6144596720A4}
                      HPSSupply-->MsiExec.exe /X{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}
                      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                      Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                      Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
                      iolo technologies' System Mechanic-->"C:\Program Files\iolo\System Mechanic\unins000.exe"
                      Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
                      Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
                      Launch Manager-->C:\Windows\UnInst32.exe LManager.UNI
                      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                      Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                      Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                      Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
                      Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
                      Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
                      Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
                      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                      Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
                      Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                      Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                      Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                      Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                      Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
                      Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                      Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
                      Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                      Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                      MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
                      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                      MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
                      Nero 8-->MsiExec.exe /X{9A5B876D-A900-4AAB-B557-DE827BE46E6C}
                      neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
                      NTI Backup NOW! 4.7-->"C:\Program Files\InstallShield Installation Information\{1598034D-7147-432C-8CA8-888E0632D124}\setup.exe" -removeonly
                      NTI Backup NOW! 4.7-->C:\Program Files\InstallShield Installation Information\{1598034D-7147-432C-8CA8-888E0632D124}\setup.exe -runfromtemp -l0x040c
                      NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
                      NVIDIA PhysX v8.09.04-->MsiExec.exe /X{A7E07C2B-2220-4415-87E3-784D5814BC93}
                      OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
                      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                      PowerProducer 3.72-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.EXE" -uninstall
                      Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
                      Remue-méninges la saison des fruits-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F4F88D0-99D4-4D8F-8529-444BB169FB6B}\Setup.exe" -l0x40c
                      Revo Uninstaller 1.83-->C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
                      Search Settings 1.2-->MsiExec.exe /X{D0C73318-7B4A-4D16-A0C4-3B83F075EA88}
                      Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                      Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                      Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
                      Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
                      Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                      VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
                      VideoLAN VLC media player 0.8.6i-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                      Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
                      Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
                      Visual C++ 8.0 CRT (x86) WinSXS MSM-->MsiExec.exe /I{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}
                      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                      Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                      Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
                      Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                      Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
                      Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                      Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
                      Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

                      ======Security center information======

                      AV: Antivirus BitDefender
                      FW: Pare-feu BitDefender
                      AS: BitDefender AntiSpam
                      AS: Windows Defender

                      ======System event log======

                      Computer Name: PC-de-yiayia
                      Event Code: 1003
                      Message:
                      Record Number: 54870
                      Source Name: Microsoft-Windows-Dhcp-Client
                      Time Written: 20080729093840.000000-000
                      Event Type: Avertissement
                      User:

                      Computer Name: PC-de-yiayia
                      Event Code: 1002
                      Message: Le bail de l'adresse IP 192.168.2.19 pour la carte réseau dont l'adresse réseau est 001F3A3EB195 a été refusé par le serveur DHCP 192.168.1.1 (celui-ci a envoyé un message DHCPNACK).
                      Record Number: 54871
                      Source Name: Microsoft-Windows-Dhcp-Client
                      Time Written: 20080729093840.000000-000
                      Event Type: Erreur
                      User:

                      Computer Name: PC-de-yiayia
                      Event Code: 4226
                      Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
                      Record Number: 54888
                      Source Name: Tcpip
                      Time Written: 20080729101639.479208-000
                      Event Type: Avertissement
                      User:

                      Computer Name: PC-de-yiayia
                      Event Code: 6008
                      Message: L'arrêt système précédant à 20:54:23 le 29/07/2008 n'était pas prévu.
                      Record Number: 54892
                      Source Name: EventLog
                      Time Written: 20080729185656.000000-000
                      Event Type: Erreur
                      User:

                      Computer Name: PC-de-yiayia
                      Event Code: 4
                      Message: Broadcom NetLink (TM) Fast Ethernet: The network link is down. Check to make sure the network cable is properly connected.
                      Record Number: 54899
                      Source Name: b57nd60x
                      Time Written: 20080729185649.962886-000
                      Event Type: Avertissement
                      User:

                      =====Application event log=====

                      Computer Name: PC-de-yiayia
                      Event Code: 1530
                      Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                      DÉTAIL -
                      1 user registry handles leaked from \Registry\User\S-1-5-21-2042034648-109248656-1572164679-1000_Classes:
                      Process 908 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000_CLASSES

                      Record Number: 56852
                      Source Name: Microsoft-Windows-User Profiles Service
                      Time Written: 20090524110441.000000-000
                      Event Type: Avertissement
                      User: AUTORITE NT\SYSTEM

                      Computer Name: PC-de-yiayia
                      Event Code: 1530
                      Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                      DÉTAIL -
                      5 user registry handles leaked from \Registry\User\S-1-5-21-2042034648-109248656-1572164679-1000:
                      Process 904 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000
                      Process 1344 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\Microsoft\Internet Explorer\SearchUrl
                      Process 1344 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\AppDataLow\Software\Yahoo\Companion
                      Process 1344 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\Microsoft\Internet Explorer\URLSearchHooks
                      Process 1344 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\Microsoft\Internet Explorer\SearchScopes

                      Record Number: 56887
                      Source Name: Microsoft-Windows-User Profiles Service
                      Time Written: 20090524112952.000000-000
                      Event Type: Avertissement
                      User: AUTORITE NT\SYSTEM

                      Computer Name: PC-de-yiayia
                      Event Code: 1530
                      Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                      DÉTAIL -
                      2 user registry handles leaked from \Registry\User\S-1-5-21-2042034648-109248656-1572164679-1000_Classes:
                      Process 904 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000_CLASSES
                      Process 552 (\Device\HarddiskVolume2\Windows\System32\csrss.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000_CLASSES

                      Record Number: 56888
                      Source Name: Microsoft-Windows-User Profiles Service
                      Time Written: 20090524112953.000000-000
                      Event Type: Avertissement
                      User: AUTORITE NT\SYSTEM

                      Computer Name: PC-de-yiayia
                      Event Code: 1530
                      Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                      DÉTAIL -
                      5 user registry handles leaked from \Registry\User\S-1-5-21-2042034648-109248656-1572164679-1000:
                      Process 908 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000
                      Process 588 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\Microsoft\Internet Explorer\SearchUrl
                      Process 588 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\AppDataLow\Software\Yahoo\Companion
                      Process 588 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\Microsoft\Internet Explorer\URLSearchHooks
                      Process 588 (\Device\HarddiskVolume2\Program Files\AGI\common\win32\pythonservice.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000\Software\Microsoft\Internet Explorer\SearchScopes

                      Record Number: 56924
                      Source Name: Microsoft-Windows-User Profiles Service
                      Time Written: 20090524115334.000000-000
                      Event Type: Avertissement
                      User: AUTORITE NT\SYSTEM

                      Computer Name: PC-de-yiayia
                      Event Code: 1530
                      Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

                      DÉTAIL -
                      2 user registry handles leaked from \Registry\User\S-1-5-21-2042034648-109248656-1572164679-1000_Classes:
                      Process 908 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000_CLASSES
                      Process 552 (\Device\HarddiskVolume2\Windows\System32\csrss.exe) has opened key \REGISTRY\USER\S-1-5-21-2042034648-109248656-1572164679-1000_CLASSES

                      Record Number: 56925
                      Source Name: Microsoft-Windows-User Profiles Service
                      Time Written: 20090524115334.000000-000
                      Event Type: Avertissement
                      User: AUTORITE NT\SYSTEM

                      =====Security event log=====

                      Computer Name: PC-de-yiayia
                      Event Code: 4672
                      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

                      Sujet :
                      ID de sécurité : S-1-5-18
                      Nom du compte : SYSTEM
                      Domaine du compte : AUTORITE NT
                      ID d’ouverture de session : 0x3e7

                      Privilèges : SeAssignPrimaryTokenPrivilege
                      SeTcbPrivilege
                      SeSecurityPrivilege
                      SeTakeOwnershipPrivilege
                      SeLoadDriverPrivilege
                      SeBackupPrivilege
                      SeRestorePrivilege
                      SeDebugPrivilege
                      SeAuditPrivilege
                      SeSystemEnvironmentPrivilege
                      SeImpersonatePrivilege
                      Record Number: 53352
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090303105950.469721-000
                      Event Type: Succès de l'audit
                      User:

                      Computer Name: PC-de-yiayia
                      Event Code: 4624
                      Message: L’ouverture de session d’un compte s’est correctement déroulée.

                      Sujet :
                      ID de sécurité : S-1-5-18
                      Nom du compte : PC-DE-YIAYIA$
                      Domaine du compte : WORKGROUP
                      ID d’ouverture de session : 0x3e7

                      Type d’ouverture de session : 5

                      Nouvelle ouverture de session :
                      ID de sécurité : S-1-5-20
                      Nom du compte : SERVICE RÉSEAU
                      Domaine du compte : AUTORITE NT
                      ID d’ouverture de session : 0x3e4
                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                      Informations sur le processus :
                      ID du processus : 0x254
                      Nom du processus : C:\Windows\System32\services.exe

                      Informations sur le réseau :
                      Nom de la station de travail :
                      Adresse du réseau source : -
                      Port source : -

                      Informations détaillées sur l’authentification :
                      Processus d’ouverture de session : Advapi
                      Package d’authentification : Negotiate
                      Services en transit : -
                      Nom du package (NTLM uniquement) : -
                      Longueur de la clé : 0

                      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

                      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

                      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

                      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

                      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

                      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
                      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
                      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
                      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
                      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
                      Record Number: 53353
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090303105950.797323-000
                      Event Type: Succès de l'audit
                      User:

                      Computer Name: PC-de-yiayia
                      Event Code: 4672
                      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

                      Sujet :
                      ID de sécurité : S-1-5-20
                      Nom du compte : SERVICE RÉSEAU
                      Domaine du compte : AUTORITE NT
                      ID d’ouverture de session : 0x3e4

                      Privilèges : SeAssignPrimaryTokenPrivilege
                      SeAuditPrivilege
                      SeImpersonatePrivilege
                      Record Number: 53354
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090303105950.797323-000
                      Event Type: Succès de l'audit
                      User:

                      Computer Name: PC-de-yiayia
                      Event Code: 4648
                      Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

                      Sujet :
                      ID de sécurité : S-1-5-18
                      Nom du compte : PC-DE-YIAYIA$
                      Domaine du compte : WORKGROUP
                      ID d’ouverture de session : 0x3e7
                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                      Compte dont les informations d’identification ont été utilisées :
                      Nom du compte : SYSTEM
                      Domaine du compte : AUTORITE NT
                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                      Serveur cible :
                      Nom du serveur cible : localhost
                      Informations supplémentaires : localhost

                      Informations sur le processus :
                      ID du processus : 0x254
                      Nom du processus : C:\Windows\System32\services.exe

                      Informations sur le réseau :
                      Adresse du réseau : -
                      Port : -

                      Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
                      Record Number: 53355
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090303105950.922124-000
                      Event Type: Succès de l'audit
                      User:

                      Computer Name: PC-de-yiayia
                      Event Code: 4624
                      Message: L’ouverture de session d’un compte s’est correctement déroulée.

                      Sujet :
                      ID de sécurité : S-1-5-18
                      Nom du compte : PC-DE-YIAYIA$
                      Domaine du compte : WORKGROUP
                      ID d’ouverture de session : 0x3e7

                      Type d’ouverture de session : 5

                      Nouvelle ouverture de session :
                      ID de sécurité : S-1-5-18
                      Nom du compte : SYSTEM
                      Domaine du compte : AUTORITE NT
                      ID d’ouverture de session : 0x3e7
                      GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                      Informations sur le processus :
                      ID du processus : 0x254
                      Nom du processus : C:\Windows\System32\services.exe

                      Informations sur le réseau :
                      Nom de la station de travail :
                      Adresse du réseau source : -
                      Port source : -

                      Informations détaillées sur l’authentification :
                      Processus d’ouverture de session : Advapi
                      Package d’authentification : Negotiate
                      Services en transit : -
                      Nom du package (NTLM uniquement) : -
                      Longueur de la clé : 0

                      Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

                      Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

                      Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

                      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

                      Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

                      Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
                      - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
                      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
                      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
                      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
                      Record Number: 53356
                      Source Name: Microsoft-Windows-Security-Auditing
                      Time Written: 20090303105950.922124-000
                      Event Type: Succès de l'audit
                      User:

                      ======Environment variables======

                      "ComSpec"=%SystemRoot%\system32\cmd.exe
                      "FP_NO_HOST_CHECK"=NO
                      "OS"=Windows_NT
                      "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Windows\System32\WbemC:\Program Files\DMV\MaxTV4\plugins
                      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                      "PROCESSOR_ARCHITECTURE"=x86
                      "TEMP"=%SystemRoot%\TEMP
                      "TMP"=%SystemRoot%\TEMP
                      "USERNAME"=SYSTEM
                      "windir"=%SystemRoot%
                      "PROCESSOR_LEVEL"=6
                      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 22 Stepping 1, GenuineIntel
                      "PROCESSOR_REVISION"=1601
                      "NUMBER_OF_PROCESSORS"=1

                      -----------------EOF-----------------
                      1. Désactivez le contrôle des comptes utilisateurs avant utilisation de cet outil:

                        * Allez dans "Démarrer" puis Panneau de configuration.
                        * Double Cliquez sur l'icône Comptes d'utilisateurs et sur "Activer ou désactiver le contrôle des comptes d'utilisateurs".
                        * Décochez la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
                        * Validez par OK et redémarrez .

                        Aides en images ( Uac )

                        ensuite

                        Télécharge Ad-remover ( de C_XX ) sur ton bureau :

                        ! Déconnecte toi et ferme toutes applications en cours !

                        clic droit sur "Ad-R.exe" en tant qu'administrateur pour lancer l'installation et laisse les paramètres d'installation par défaut .

                        clic droit sur le raccourci Ad-remover en tant qu'administrateur qui est sur ton bureau pour lancer l'outil .

                        Au menu principal choisis l'option "L" et tape sur [entrée] .

                        Laisse travailler l'outil et ne touche à rien ...

                        --> Poste le rapport qui apparait à la fin , sur le forum ...

                        ( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
                        ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                        Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                        Aides en images (Installation)
                        Aides en images (Recherche)
                        1. desolée du retard :)
                          voici :

                          ------- RAPPORT D'AD-REMOVER 1.1.4.2 | UNIQUEMENT XP/VISTA -------

                          Mit à jour part C_XX le 23/05/2009 à 13:40
                          Contact: AdRemover.contact@gmail.com
                          Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html

                          Lancé à: 14:59:48, 24/05/2009 | Normal
                          Exécuté de: C:\Program Files\Ad-remover\
                          Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 1 v6.0.6001
                          Nom du PC: PC-DE-YIAYIA
                          Utilisateur actuel: yiayia - Administrator

                          .
                          ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                          .
                          .
                          HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
                          HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
                          HKCU\Software\SweetIM
                          HKLM\Software\SweetIM
                          HKLM\Software\Trymedia Systems

                          alors la je sais pas si c'est entier ou pas j ai que ça j etais parti revenu ordi eteint :( (il a encore deconné)
                          1. ça y est desolée :)

                            ------- RAPPORT D'AD-REMOVER 1.1.4.2 | UNIQUEMENT XP/VISTA -------

                            Mit à jour part C_XX le 23/05/2009 à 13:40
                            Contact: AdRemover.contact@gmail.com
                            Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html

                            Lancé à: 18:26:27, 24/05/2009 | Mode sans echec
                            Exécuté de: C:\Program Files\Ad-remover\
                            Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 1 v6.0.6001
                            Nom du PC: PC-DE-YIAYIA
                            Utilisateur actuel: yiayia - Administrator

                            .
                            ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                            .
                            .
                            .
                            C:\ProgramData\Trymedia\data
                            C:\ProgramData\Trymedia\licenses
                            C:\ProgramData\Trymedia\data\{46E99196-9543-F902-CAD4-C135B7CCADF4}
                            C:\ProgramData\Trymedia\data\{8F77FD78-F430-55A2-00F9-A86544DCFD7C}
                            C:\ProgramData\Trymedia\data\{9A22B074-FA4A-642D-672B-3FAF21C2B0F0}
                            C:\ProgramData\Trymedia\data\{B580E7DE-9DEB-A47A-1725-C6395C6F637B}
                            C:\ProgramData\Trymedia
                            C:\Users\yiayia\Appdata\LocalLow\Search Settings\kb127
                            C:\Users\yiayia\Appdata\LocalLow\Search Settings\kb127\res
                            C:\Users\yiayia\Appdata\LocalLow\Search Settings\kb127\temp
                            C:\Users\yiayia\Appdata\LocalLow\Search Settings\kb127\temp\ws-14377.log
                            C:\Users\yiayia\Appdata\LocalLow\Search Settings\kb127\temp\ws-14378.log
                            C:\Users\yiayia\Appdata\LocalLow\Search Settings\kb127\temp\ws-14379.log
                            C:\Users\yiayia\Appdata\LocalLow\Search Settings\kb127\temp\ws-14380.log
                            C:\Users\yiayia\Appdata\LocalLow\Search Settings
                            C:\Users\yiayia\Appdata\LocalLow\SweetIM\Toolbars
                            C:\Users\yiayia\Appdata\LocalLow\SweetIM\Toolbars\Internet Explorer
                            C:\Users\yiayia\Appdata\LocalLow\SweetIM\Toolbars\Internet Explorer\cache
                            C:\Users\yiayia\Appdata\LocalLow\SweetIM\Toolbars\Internet Explorer\cache\f64a71f602d078aa84829e36b8992194.toolbar31.xml
                            C:\Users\yiayia\Appdata\LocalLow\SweetIM
                            C:\Windows\Installer\df393a.msi

                            (!) -- Fichiers temporaires supprimés.

                            .
                            +-----------------| Scan additionnel:
                            .

                            ---- Mozilla FireFox Version 3.0.10 ----

                            Nom du profil: 46syev50.default (yiayia)
                            .
                            (Prefs.js) user_pref("browser.startup.homepage", "hxxp://msn.fr");
                            (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.10");
                            .
                            .

                            ---- Internet Explorer Version 8.0.6001.18702 ----

                            [HKEY_CURRENT_USER\..\Internet Explorer\Main]

                            Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                            Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                            Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                            Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                            Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                            Start Page: hxxp://fr.msn.com/?ocid=iehp

                            [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

                            Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                            Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                            Search bar: hxxp://search.msn.com/spbasic.htm
                            Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                            Start Page: hxxp://fr.msn.com/

                            [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

                            Tabs: res://ieframe.dll/tabswelcome.htm

                            =========== Suspect (Cracks, Serials ... ) ==========

                            .
                            C:\Users\yiayia\Documents\logiciels\kEYGEN.exe
                            [70365 Octet(s)|--a------|23/11/2008 21:42|HashMD5: 346c7974ccae52221f492b721f6b6428 |CRC32: a80bb437]

                            +---------------------------------------------------------------------------+

                            3474 Octet(s) - C:\Ad-Report-24.05.2009.log

                            20 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
                            5 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE

                            Fin à: 18:32:48 | 24/05/2009
                            .
                            +-----------------| E.O.F
                            .
                            1. j ai eu que le log :

                              Logfile of random's system information tool 1.06 (written by random/random)
                              Run by yiayia at 2009-05-24 18:47:30
                              Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                              System drive C: has 74 GB (65%) free of 114 GB
                              Total RAM: 2037 MB (52% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 18:47:58, on 24/05/2009
                              Platform: Windows Vista SP1 (WinNT 6.00.1905)
                              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\Windows\RtHDVCpl.exe
                              C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
                              C:\Program Files\Launch Manager\LManager.exe
                              C:\Windows\System32\hkcmd.exe
                              C:\Windows\System32\igfxpers.exe
                              C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                              C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
                              C:\Windows\ehome\ehtray.exe
                              C:\Program Files\Windows Live\MessengerSearchAddon\msgrsrch.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                              C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                              C:\Windows\system32\igfxsrvc.exe
                              C:\Windows\ehome\ehmsas.exe
                              C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
                              C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                              C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
                              C:\Users\yiayia\AppData\Local\Temp\RtkBtMnt.exe
                              C:\Windows\system32\igfxext.exe
                              C:\Windows\system32\SearchFilterHost.exe
                              C:\Users\yiayia\Desktop\RSIT.exe
                              C:\Program Files\trend micro\HijackThis\yiayia.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              R3 - URLSearchHook: (no name) - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
                              O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: Iminent.SearchTheWeb.HelperObject - {0E896FCA-D07E-45FE-901F-6A26FCF59C02} - mscoree.dll (file missing)
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                              O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                              O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                              O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                              O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
                              O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
                              O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                              O4 - HKCU\..\Run: [msnlivesearch] C:\Program Files\Windows Live\MessengerSearchAddon\msgrsrch.exe /Run
                              O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                              O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                              O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                              O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                              O13 - Gopher Prefix:
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{AA5F1747-800F-4F3F-B4FA-703DE1C18B6D}: NameServer = 208.67.222.222,208.67.220.220
                              O20 - AppInit_DLLs: C:\Windows\System32\eNetHook.dll
                              O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
                              O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                              O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
                              O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                              O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                              O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                              O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                              O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
                              O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
                              O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                              O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                              O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                              O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
                              O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                              O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                              O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                              • 1
                              • 2
                              • 3
                              • 4