Rapport RSIT a analyser s'il vous plait

Bonjour,
j'ai depuis quelques semaines les pages "main.exoclick" et "https://fr.yahoo.com/?p=us" qui s'ouvrent a chaque fois que je clique sur un lien (recherches google par exemple) on m'a conseillé de faire une analyse avec RSIT et de la faire analyser par le forum.
Au passage si vous trouvez des choses pas normales signalez-le moi.
D'avance merci beaucoup, et excusez moi d'utiliser votre temps.

fichier "log" :

Logfile of random's system information tool 1.06 (written by random/random)
Run by Philippe at 2009-08-10 19:02:47
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 188 GB (79%) free of 238 GB
Total RAM: 2047 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:02:57, on 10/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ManyCam 2.3\ManyCam.exe
C:\Documents and Settings\Philippe\Mes documents\TrueTransparency\TrueTransparency\TrueTransparency.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Documents and Settings\Philippe\Bureau\RSIT.exe
C:\Program Files\trend micro\Philippe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Loader Class - {F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD} - C:\WINDOWS\BricoPacks\LeopardXP\FindeXer.dll (file missing)
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ManyCam] "C:\Program Files\ManyCam 2.3\ManyCam.exe"
O4 - HKCU\..\Run: [TrueTransparency] "C:\Documents and Settings\Philippe\Mes documents\TrueTransparency\TrueTransparency\TrueTransparency.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/2.0.2.3/cfweb_activex.camfrogweb.com-advanced-2.0.2.3_instmodule.exe
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game14.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{99F1FA63-F48F-49AE-899F-BD68498E40BA}: NameServer = 85.255.112.87,85.255.112.195
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.87,85.255.112.195
O17 - HKLM\System\CS1\Services\Tcpip\..\{99F1FA63-F48F-49AE-899F-BD68498E40BA}: NameServer = 85.255.112.87,85.255.112.195
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.87,85.255.112.195
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Service Google Update (gupdate1c9992f1d46729e) (gupdate1c9992f1d46729e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\LogiShrd\Bluetooth\LBTServ.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe

--
End of file - 13107 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Google Software Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-06-12 259696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll [2009-06-16 669168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-05-02 470512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll [2009-01-30 1114112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-09 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD}]
Loader Class - C:\WINDOWS\BricoPacks\LeopardXP\FindeXer.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-06-12 259696]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"Share-to-Web Namespace Daemon"=C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe [2002-04-17 69632]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2004-10-08 221184]
"LogitechCommunicationsManager"=C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe [2008-08-14 565008]
"LogitechQuickCamRibbon"=C:\Program Files\Logitech\QuickCam\Quickcam.exe [2008-08-14 2407184]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2008-02-29 76304]
"CTCheck"=C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe [2007-11-06 397312]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-01-05 413696]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-09-30 16864768]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2008-06-19 57344]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-11-06 39408]
"ManyCam"=C:\Program Files\ManyCam 2.3\ManyCam.exe [2008-10-14 1791272]
"TrueTransparency"=C:\Documents and Settings\Philippe\Mes documents\TrueTransparency\TrueTransparency\TrueTransparency.exe [2008-06-24 372224]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"CTSyncU.exe"=C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe [2007-07-17 868352]
"DriverUpdaterPro"=C:\Program Files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe -t []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CursorXP]
C:\Program Files\CursorXP\CursorXP.exe -s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files\pdfforge Toolbar\SearchSettings.exe [2009-01-30 992256]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrayServer]
C:\Program Files\MAGIX\Video_deluxe_15_Version_a_telecharger\TrayServer.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Philippe^Menu Démarrer^Programmes^Démarrage^Logitech . Enregistrement du produit.lnk]
C:\PROGRA~1\Logitech\QuickCam\eReg.exe [2008-02-13 493832]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Philippe^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2008-09-12 384000]

C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll [2008-05-02 72208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutorun"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\ma-config.com\maconfservice.exe"="C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe"="C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe:*:Enabled:Assistance à distance - Windows Messenger et voix"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Exécuter une DLL en tant qu'application"
"C:\Program Files\Project Looking Glass\LG3D Project 1.0.0_beta1\jre\bin\java.exe"="C:\Program Files\Project Looking Glass\LG3D Project 1.0.0_beta1\jre\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe"="C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\aMSN\bin\wish.exe"="C:\Program Files\aMSN\bin\wish.exe:*:Enabled:Wish Application"
"C:\Program Files\Fichiers communs\AOL\Loader\aolload.exe"="C:\Program Files\Fichiers communs\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\ManyCam 2.3\ManyCam.exe"="C:\Program Files\ManyCam 2.3\ManyCam.exe:*:Enabled:ManyCam 2.3"
"C:\Program Files\aMSN\amsn.exe"="C:\Program Files\aMSN\amsn.exe:*:Enabled:aMSN"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e299efbc-fd22-11dd-95bd-00e04cd02f65}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn

======List of files/folders created in the last 2 months======

2009-08-10 19:02:47 ----D---- C:\rsit
2009-08-10 19:02:47 ----D---- C:\Program Files\trend micro
2009-08-01 02:06:58 ----D---- C:\Program Files\EAGLE-5.6.0
2009-08-01 02:06:49 ----D---- C:\Documents and Settings\Philippe\Application Data\CadSoft
2009-07-31 18:09:49 ----D---- C:\Program Files\Avira
2009-07-31 18:09:49 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-07-29 23:43:54 ----D---- C:\Documents and Settings\Philippe\Application Data\Ulead Systems
2009-07-29 23:42:46 ----D---- C:\WINDOWS\system32\windows media
2009-07-29 23:42:41 ----D---- C:\WINDOWS\RegisteredPackages
2009-07-29 23:42:40 ----HD---- C:\WINDOWS\msdownld.tmp
2009-07-29 23:42:36 ----D---- C:\Program Files\Windows Media Components
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\uvsc.dll
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\uvAC3Enc.dll
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\pcmaout.dll
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\mpgvparse.dll
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\MPGVOUT.dll
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\mpgmux.dll
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\mpgcheck.dll
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\mpgcap32.dll
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\mpgaparse.dll
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\MPGAOUT.DLL
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\mpg_dlg.dll
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\MPEGIN.DLL
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\MCMpgDec.dll
2009-07-29 23:42:05 ----N---- C:\WINDOWS\system32\ac3aout.dll
2009-07-29 23:41:35 ----D---- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2009-07-26 19:31:08 ----D---- C:\Documents and Settings\Philippe\Application Data\dvdcss
2009-06-27 23:32:58 ----D---- C:\Program Files\KeepV Converter
2009-06-22 23:59:30 ----D---- C:\Program Files\FairUse Wizard 2
2009-06-22 20:22:53 ----A---- C:\WINDOWS\system32\javaws.exe
2009-06-22 20:22:53 ----A---- C:\WINDOWS\system32\javaw.exe
2009-06-22 20:22:53 ----A---- C:\WINDOWS\system32\java.exe
2009-06-21 15:11:48 ----D---- C:\Documents and Settings\Philippe\Application Data\vlc
2009-06-21 15:11:08 ----D---- C:\Program Files\VideoLAN
2009-06-20 21:26:25 ----D---- C:\Program Files\MSN Messenger
2009-06-20 20:31:56 ----D---- C:\Program Files\Windows Installer Clean Up

======List of files/folders modified in the last 2 months======

2009-08-10 19:02:57 ----D---- C:\WINDOWS\Prefetch
2009-08-10 19:02:47 ----D---- C:\Program Files
2009-08-10 18:56:28 ----D---- C:\WINDOWS\Temp
2009-08-10 18:56:08 ----SD---- C:\WINDOWS\Tasks
2009-08-10 18:56:00 ----D---- C:\WINDOWS\system32\CatRoot2
2009-08-10 18:54:39 ----D---- C:\WINDOWS\system32\config
2009-08-10 18:54:22 ----D---- C:\WINDOWS\system32\wbem
2009-08-10 18:54:22 ----D---- C:\WINDOWS\Registration
2009-08-10 18:54:04 ----RSD---- C:\WINDOWS\Fonts
2009-08-10 18:53:46 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-08-10 18:37:23 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
2009-08-10 03:25:09 ----D---- C:\Documents and Settings
2009-08-09 20:22:41 ----A---- C:\WINDOWS\win.ini
2009-07-31 18:18:16 ----D---- C:\WINDOWS
2009-07-31 18:09:56 ----HD---- C:\WINDOWS\inf
2009-07-31 18:09:56 ----D---- C:\WINDOWS\system32\drivers
2009-07-31 18:08:15 ----D---- C:\Program Files\Fichiers communs
2009-07-31 18:07:31 ----SHD---- C:\WINDOWS\Installer
2009-07-31 18:06:33 ----D---- C:\Program Files\DivX
2009-07-31 18:04:10 ----D---- C:\Documents and Settings\All Users\Application Data\MAGIX
2009-07-31 18:04:03 ----D---- C:\Program Files\Alawar
2009-07-31 18:03:54 ----D---- C:\Program Files\LimeWire
2009-07-31 18:03:21 ----D---- C:\WINDOWS\WinSxS
2009-07-31 18:00:35 ----D---- C:\WINDOWS\system32
2009-07-29 23:42:47 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-07-29 23:41:39 ----HD---- C:\Program Files\InstallShield Installation Information
2009-07-29 00:47:21 ----D---- C:\Documents and Settings\Philippe\Application Data\LimeWire
2009-07-26 21:11:44 ----D---- C:\Program Files\Messenger Plus! Live
2009-07-26 19:22:13 ----D---- C:\Program Files\intaller- executeurs
2009-06-30 18:04:54 ----D---- C:\Program Files\Bridge Building Game
2009-06-28 14:41:57 ----A---- C:\WINDOWS\hpqcopy.INI
2009-06-28 07:40:33 ----AC---- C:\WINDOWS\OEWABLog.txt
2009-06-23 14:00:26 ----A---- C:\WINDOWS\avisplitter.ini
2009-06-22 20:22:51 ----D---- C:\Program Files\Java
2009-06-20 20:31:57 ----SD---- C:\Documents and Settings\Philippe\Application Data\Microsoft
2009-06-20 20:31:38 ----D---- C:\Program Files\MSECACHE
2009-06-20 18:31:15 ----D---- C:\Documents and Settings\All Users\Application Data\AlawarWrapper
2009-06-20 18:28:37 ----D---- C:\WINDOWS\system32\Restore
2009-06-19 19:11:43 ----D---- C:\Program Files\Opera

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2008-11-05 82380]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14720]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-07-31 28520]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-03-24 55640]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-10-02 4878336]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2008-02-29 35344]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2008-02-29 36880]
R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys [2008-07-26 25624]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2004-10-08 22016]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver; C:\WINDOWS\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-11-07 14604]
R3 QCMerced;Logitech QuickCam Communicate; C:\WINDOWS\system32\DRIVERS\LVCM.sys [2004-10-08 585824]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-02-26 81408]
R3 U2SP;USB to Serial Converter Driver(Philips); C:\WINDOWS\system32\DRIVERS\u2s2kxp.sys [2003-05-14 23948]
R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S1 gaopdxserv.sys;gaopdxserv.sys; C:\WINDOWS\system32\drivers\gaopdxserv.sys []
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS []
S3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2008-02-29 20240]
S3 L8042mou;SetPoint PS/2 Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\L8042mou.Sys [2008-02-29 63120]
S3 LMouKE;SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2008-02-29 79120]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-03-04 47360]
S3 SCREAMINGBDRIVER;Screaming Bee Audio; C:\WINDOWS\system32\drivers\ScreamingBAudio.sys [2008-11-22 23064]
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ssm_bus.sys [2007-05-02 83592]
S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys [2007-05-02 15112]
S3 ssm_mdm;SAMSUNG Mobile USB Modem II 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys [2007-05-02 109704]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbscan;Usbscan; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeActiveFileMonitor;Adobe Active File Monitor; C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [2004-10-12 98304]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-07-31 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-31 185089]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-12 44032]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-09 152984]
R2 LVCOMSer;LVCOMSer; C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe [2008-07-26 186904]
R2 LVPrcSrv;Process Monitor; C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe [2008-07-26 150040]
R2 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect; C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [2004-10-12 118784]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate1c9992f1d46729e;Service Google Update (gupdate1c9992f1d46729e); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-28 133104]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 183280]
S2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe []
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe []
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-03-27 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 1527900]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Fichiers communs\LogiShrd\Bluetooth\LBTServ.exe [2008-05-02 121360]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe [2009-05-20 79360]
S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

. est ce que vous avez besoin du fichier "info" aussi?
Configuration: Windows XP
Opera 9.64

47 réponses

Résumé de la discussion

Des redirections vers des pages publicitaires et intrusives s'affichent lors du clic sur des liens, ce qui suggère une infection par adware ou un programme indésirable agissant au niveau du navigateur. Le rapport RSIT et l'analyse souligne des barres d'outils et des modules BHO, de nombreux programmes au démarrage, et des modifications de page d'accueil ou de moteur de recherche. Des éléments typiques apparaissent aussi dans le registre et les tâches planifiées, avec des noms tels que pdfforge Toolbar, Google Toolbar, ManyCam et des entrées Run multiples. Par ailleurs, le rapport mentionne des serveurs DNS 85.255.112.87 et 85.255.112.195, ce qui peut indiquer une redirection réseau locale nécessitant correction et vérification des paramètres réseau.

Bobot (l’IA à votre service)
  1. bonsoir Phil.may

    Suis la procédure indiquée par neophyte*** .....Ton pc est redirigé....

    a+
    1
    1. est ce que vous avez besoin du fichier "info" aussi?

      Bonjour ,

      Oui ont en a besoins
      0
      1. slt

        tu n'as pas a t'excuser, tu as en effet plusieurs infections, entre autre un detournement de serveurs Dns et une infection de sources amovibles :

        Télécharge SmitfraudFix (de S!Ri) :

        Enregistre-le sur le Bureau

        Double-clique sur SmitfraudFix.exe et choisis l'option 5 puis Entrée

        Un rapport sera généré, poste-le dans ta prochaine réponse stp.

        Tutoriel illustré
        0
        1. fichier "info" :

          info.txt logfile of random's system information tool 1.06 2009-08-10 19:02:59

          ======Uninstall list======

          -->"C:\Program Files\Creative Installation Information\CD_RIPPER_UNICODE_2\Setup.exe" /remove /l0x040c
          -->"C:\Program Files\Creative Installation Information\CREATIVE_SYNC_MANAGER_U\Setup.exe" /remove /l0x040c
          -->"C:\Program Files\Creative Installation Information\CREATIVE_VIDEO_CONVERTER\Setup.exe" /remove /l0x040c
          -->"C:\Program Files\Creative Installation Information\ZEN_MTP_MEDIA_EXPLORER\Setup.exe" /remove /l0x040c
          -->C:\Program Files\MAGIX\Speed2_burnR_mxcdr\unwise.exe
          -->MsiExec /X{A7E07C2B-2220-4415-87E3-784D5814BC93}
          -->MsiExec.exe /I{5B782FFA-6A95-480D-8E0A-0954A14693D6}
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
          2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
          Acrobat.com-->C:\Program Files\Fichiers communs\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
          Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
          Adobe AIR-->C:\Program Files\Fichiers communs\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
          Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
          Adobe Bridge 1.0-->MsiExec.exe /I{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}
          Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5102}
          Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
          Adobe Help Center 2.0-->MsiExec.exe /I{8FFC924C-ED06-44CB-8867-3CA778ECE903}
          Adobe Photoshop Elements 3.0-->MsiExec.exe /I{851C67EF-068A-4060-9EF5-2E3DDCD68382}
          Adobe Premiere Pro 2.0-->msiexec /I {FA17A726-B229-4116-B793-A2AB1A4EAE2E}
          Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
          Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
          Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-1437-443D-B06E-79A00FE45110}
          Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
          Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
          Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
          Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
          AVS Video Converter 6-->"C:\Program Files\AVS4YOU\AVSVideoConverter6\unins000.exe"
          AVS4YOU Software Navigator 1.3-->"C:\Program Files\AVS4YOU\AVSSoftwareNavigator\unins000.exe"
          Bridge Building Game-->C:\Program Files\Bridge Building Game\uninstall.exe
          CamfrogWEB Advanced ActiveX Plugin (remove only)-->"C:\Program Files\CFWebAdvancedU\Uninstall.exe"
          CDDRV_Installer-->MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
          Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
          Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
          Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
          Coffret de pilotes Logitech QuickCam-->"C:\Program Files\Fichiers communs\LogiShrd\LogiDriverStore\lvdrivers\11.80.1048\LgDrvInst.exe" -remove -instdir"C:\Program Files\Fichiers communs\LogiShrd\LogiDriverStore\lvdrivers\" -enumdelay=2000 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -promptuninstall -arpregkey"lvdrivers_11.80" /clone_wait /hide_progress
          Correctif pour Windows XP (KB932716-v2)-->"C:\WINDOWS\$NtUninstallKB932716-v2$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
          Creative System Information-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c /remove
          Creative ZEN-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1B2DBF55-05D4-4072-87D8-689141E262BD}\SETUP.EXE" -l0x40c /remove
          CursorXP-->C:\Program Files\CursorXP\CurXPUtil.exe -u
          Disque de souvenirs HP-->MsiExec.exe /X{B376402D-58EA-45EA-BD50-DD924EB67A70}
          EAGLE 5.6.0-->cmd.exe /c start "EAGLE Uninstaller" /min "C:\Program Files\EAGLE-5.6.0\bin\uninstall.bat" C:\Program Files\EAGLE-5.6.0\bin
          enable Encore 4.0-->C:\Program Files\enable Encore\uninst.exe
          erLT-->MsiExec.exe /I{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}
          EVEREST Ultimate Edition v4.60-->"C:\Program Files\Lavalys\EVEREST Ultimate Edition\unins000.exe"
          FairUse Wizard 2-->"C:\Program Files\FairUse Wizard 2\un_FU-Setup_14333.exe"
          Firebird SQL Server - MAGIX Edition-->C:\Program Files\MAGIX\Common\Database\unwise.exe
          Fx-Interface 1.9.6-->"C:\Program Files\CASIO\Fx-Interface\unins000.exe"
          FX-INTERFACE PROFESSIONAL-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CD869122-24E1-11D4-A99B-204C4F4F5020}\setup.exe" AnyText
          Google SketchUp 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98736A65-3C79-49EC-B7E9-A3C77774B0E6}\setup.exe" -l0x40c -removeonly
          Google SketchUp 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}\setup.exe" -l0x40c -removeonly
          Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_9DE96A29E721D90A.exe" /uninstall
          Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
          Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
          Google Earth-->MsiExec.exe /X{CC016F21-3970-11DE-B878-005056806466}
          HDPlugin-->"C:\Program Files\HDPlugin\Uninstall.exe"
          HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
          hp deskjet 5100 series-->rundll32 hpzcon08.dll,VendorJettison hp deskjet 5100 series
          HP Photo and Imaging 2.2 - Scanjet 3970 Series-->MsiExec.exe /I{796ADAFF-7C5B-4CED-BA11-55A3644F1E0D}
          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
          Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
          Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
          Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
          KeepV Flash Converter-->"C:\Program Files\KeepV Converter\unins000.exe"
          KhalInstallWrapper-->MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
          K-Lite Codec Pack 4.2.5 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
          Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
          Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\SETUP.EXE" -l0x40c UNINSTALL
          Logitech QuickCam-->MsiExec.exe /X{3AF8FCCD-F51A-4014-9002-F195E1CBC876}
          Logitech SetPoint-->C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe -runfromtemp -l0x040c -removeonly
          Logitech Updater-->MsiExec.exe /I{53735ECE-E461-4FD0-B742-23A352436D3A}
          ManyCam 2.3 (remove only)-->"C:\Program Files\ManyCam 2.3\uninstall.exe"
          Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
          Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
          Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
          Microsoft .NET Framework 3.0-->MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
          Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
          Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
          Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
          Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
          Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
          Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
          Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
          Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
          Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
          Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
          Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
          Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
          Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
          Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
          Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
          Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
          Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
          Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
          Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
          Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
          Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
          Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
          Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)-->MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A}
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
          Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB953155)-->"C:\WINDOWS\$NtUninstallKB953155$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
          neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
          NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
          NVIDIA PhysX v8.09.04-->MsiExec.exe /X{A7E07C2B-2220-4415-87E3-784D5814BC93}
          OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
          Opera 9.64-->MsiExec.exe /X{E1BBBAC5-2857-4155-82A6-54492CE88620}
          Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
          pdfforge Toolbar v1.0-->MsiExec.exe /X{B8B0FC8B-E69B-4215-AF1A-4BDFF20D794B}
          Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
          QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
          Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
          SAMSUNG Mobile Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
          Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
          SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
          SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
          Samsung PC Studio 3 USB Driver Installer-->"C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -runfromtemp -l0x040c -removeonly
          Samsung PC Studio 3-->"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -runfromtemp -l0x040c -removeonly
          Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
          Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
          Security Update for 2007 Microsoft Office System (KB958439)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {6491B8AA-D11C-4648-A461-6234B31EB7E2}
          Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
          Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
          Security Update for Microsoft Office Excel 2007 (KB958437)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {648FC016-2D6B-4A16-8D87-404533642F4B}
          Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
          Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
          Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
          Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
          Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
          Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
          Sibelius Scorch (Firefox, Opera, Netscape only)-->MsiExec.exe /I{5F4B558D-8AEB-4DEE-AAB3-C00D1D9A86BA}
          SmartSound Quicktracks for Premiere Elements-->"C:\Program Files\InstallShield Installation Information\{F6234880-85BE-4DCB-8A45-1FF85A1A8552}\setup.exe" -runfromtemp -l0x0409 -removeonly
          SmartSound Quicktracks for Premiere Elements-->MsiExec.exe /I{F6234880-85BE-4DCB-8A45-1FF85A1A8552}
          SolidWorks Explorer 2009 sp03-->MsiExec.exe /I{030A97A0-8506-4ABD-98B1-183F8889EF8C}
          Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
          Update for Office 2007 (KB946691)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
          Update for Outlook 2007 Junk Email Filter (kb959634)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {50C77E2F-5C1C-467D-9BC8-3CA07D28C9F2}
          UxTheme Multipatcher Fr-->C:\Program Files\UxTheme Multipatcher Fr\uninstall.exe
          Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
          Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
          Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
          Windows Installer Clean Up-->MsiExec.exe /X{121634B0-2F4B-11D3-ADA3-00C04F52DD52}
          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
          Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
          Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
          Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
          Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
          Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
          Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
          WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
          ZENcast Organizer-->"C:\Program Files\Creative Installation Information\ZENCAST_ORGANIZER\Setup.exe" /remove /l0x040c
          Zune Desktop Theme-->MsiExec.exe /X{7E20EFE6-E604-48C6-8B39-BA4742F2CDB4}

          ======Security center information======

          AV: AntiVir Desktop

          ======System event log======

          Computer Name: GUYEZ-DG
          Event Code: 7036
          Message: Le service Carte de performance WMI est entré dans l'état : arrêté.

          Record Number: 24574
          Source Name: Service Control Manager
          Time Written: 20090627224931.000000+120
          Event Type: Informations
          User:

          Computer Name: GUYEZ-DG
          Event Code: 7036
          Message: Le service Carte de performance WMI est entré dans l'état : en cours d'exécution.

          Record Number: 24573
          Source Name: Service Control Manager
          Time Written: 20090627224931.000000+120
          Event Type: Informations
          User:

          Computer Name: GUYEZ-DG
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service Carte de performance WMI.

          Record Number: 24572
          Source Name: Service Control Manager
          Time Written: 20090627224931.000000+120
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: GUYEZ-DG
          Event Code: 7036
          Message: Le service Gestionnaire de connexions d'accès distant est entré dans l'état : en cours d'exécution.

          Record Number: 24571
          Source Name: Service Control Manager
          Time Written: 20090627224930.000000+120
          Event Type: Informations
          User:

          Computer Name: GUYEZ-DG
          Event Code: 7036
          Message: Le service Service de la passerelle de la couche Application est entré dans l'état : en cours d'exécution.

          Record Number: 24570
          Source Name: Service Control Manager
          Time Written: 20090627224930.000000+120
          Event Type: Informations
          User:

          =====Application event log=====

          Computer Name: GUYEZ-DG
          Event Code: 518
          Message: The Windows CardSpace service has been idle for some time. It has been shut down to make resources available for other programs.

          Record Number: 5820
          Source Name: CardSpace 3.0.0.0
          Time Written: 20090330203721.000000+120
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: GUYEZ-DG
          Event Code: 0
          Message: Service started successfully.

          Record Number: 5819
          Source Name: idsvc
          Time Written: 20090330193721.000000+120
          Event Type: Informations
          User:

          Computer Name: GUYEZ-DG
          Event Code: 0
          Message:
          Record Number: 5818
          Source Name: gusvc
          Time Written: 20090330193129.000000+120
          Event Type: Informations
          User:

          Computer Name: GUYEZ-DG
          Event Code: 0
          Message:
          Record Number: 5817
          Source Name: gupdate1c9992f1d46729e
          Time Written: 20090330193056.000000+120
          Event Type: Informations
          User:

          Computer Name: GUYEZ-DG
          Event Code: 19011
          Message:
          Record Number: 5816
          Source Name: MSSQL$SONY_MEDIAMGR
          Time Written: 20090330193040.000000+120
          Event Type: Avertissement
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\WBEM;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Samsung\Samsung PC Studio 3\;C:\Program Files\ESTsoft\ALZip\;C:\Program Files\Fichiers communs\Adobe\AGL;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Fichiers communs\Ulead Systems\MPEG
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=15
          "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 2, AuthenticAMD
          "PROCESSOR_REVISION"=6b02
          "NUMBER_OF_PROCESSORS"=2
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
          "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

          -----------------EOF-----------------
          0
          1. fichier "info" :

            info.txt logfile of random's system information tool 1.06 2009-08-10 19:02:59

            ======Uninstall list======

            -->"C:\Program Files\Creative Installation Information\CD_RIPPER_UNICODE_2\Setup.exe" /remove /l0x040c
            -->"C:\Program Files\Creative Installation Information\CREATIVE_SYNC_MANAGER_U\Setup.exe" /remove /l0x040c
            -->"C:\Program Files\Creative Installation Information\CREATIVE_VIDEO_CONVERTER\Setup.exe" /remove /l0x040c
            -->"C:\Program Files\Creative Installation Information\ZEN_MTP_MEDIA_EXPLORER\Setup.exe" /remove /l0x040c
            -->C:\Program Files\MAGIX\Speed2_burnR_mxcdr\unwise.exe
            -->MsiExec /X{A7E07C2B-2220-4415-87E3-784D5814BC93}
            -->MsiExec.exe /I{5B782FFA-6A95-480D-8E0A-0954A14693D6}
            -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c
            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
            2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
            Acrobat.com-->C:\Program Files\Fichiers communs\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
            Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
            Adobe AIR-->C:\Program Files\Fichiers communs\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
            Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
            Adobe Bridge 1.0-->MsiExec.exe /I{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}
            Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5102}
            Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
            Adobe Help Center 2.0-->MsiExec.exe /I{8FFC924C-ED06-44CB-8867-3CA778ECE903}
            Adobe Photoshop Elements 3.0-->MsiExec.exe /I{851C67EF-068A-4060-9EF5-2E3DDCD68382}
            Adobe Premiere Pro 2.0-->msiexec /I {FA17A726-B229-4116-B793-A2AB1A4EAE2E}
            Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
            Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
            Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-1437-443D-B06E-79A00FE45110}
            Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
            Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
            Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
            Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
            AVS Video Converter 6-->"C:\Program Files\AVS4YOU\AVSVideoConverter6\unins000.exe"
            AVS4YOU Software Navigator 1.3-->"C:\Program Files\AVS4YOU\AVSSoftwareNavigator\unins000.exe"
            Bridge Building Game-->C:\Program Files\Bridge Building Game\uninstall.exe
            CamfrogWEB Advanced ActiveX Plugin (remove only)-->"C:\Program Files\CFWebAdvancedU\Uninstall.exe"
            CDDRV_Installer-->MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
            Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
            Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
            Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
            Coffret de pilotes Logitech QuickCam-->"C:\Program Files\Fichiers communs\LogiShrd\LogiDriverStore\lvdrivers\11.80.1048\LgDrvInst.exe" -remove -instdir"C:\Program Files\Fichiers communs\LogiShrd\LogiDriverStore\lvdrivers\" -enumdelay=2000 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -promptuninstall -arpregkey"lvdrivers_11.80" /clone_wait /hide_progress
            Correctif pour Windows XP (KB932716-v2)-->"C:\WINDOWS\$NtUninstallKB932716-v2$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
            Creative System Information-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c /remove
            Creative ZEN-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1B2DBF55-05D4-4072-87D8-689141E262BD}\SETUP.EXE" -l0x40c /remove
            CursorXP-->C:\Program Files\CursorXP\CurXPUtil.exe -u
            Disque de souvenirs HP-->MsiExec.exe /X{B376402D-58EA-45EA-BD50-DD924EB67A70}
            EAGLE 5.6.0-->cmd.exe /c start "EAGLE Uninstaller" /min "C:\Program Files\EAGLE-5.6.0\bin\uninstall.bat" C:\Program Files\EAGLE-5.6.0\bin
            enable Encore 4.0-->C:\Program Files\enable Encore\uninst.exe
            erLT-->MsiExec.exe /I{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}
            EVEREST Ultimate Edition v4.60-->"C:\Program Files\Lavalys\EVEREST Ultimate Edition\unins000.exe"
            FairUse Wizard 2-->"C:\Program Files\FairUse Wizard 2\un_FU-Setup_14333.exe"
            Firebird SQL Server - MAGIX Edition-->C:\Program Files\MAGIX\Common\Database\unwise.exe
            Fx-Interface 1.9.6-->"C:\Program Files\CASIO\Fx-Interface\unins000.exe"
            FX-INTERFACE PROFESSIONAL-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CD869122-24E1-11D4-A99B-204C4F4F5020}\setup.exe" AnyText
            Google SketchUp 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98736A65-3C79-49EC-B7E9-A3C77774B0E6}\setup.exe" -l0x40c -removeonly
            Google SketchUp 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}\setup.exe" -l0x40c -removeonly
            Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_9DE96A29E721D90A.exe" /uninstall
            Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
            Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
            Google Earth-->MsiExec.exe /X{CC016F21-3970-11DE-B878-005056806466}
            HDPlugin-->"C:\Program Files\HDPlugin\Uninstall.exe"
            HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
            hp deskjet 5100 series-->rundll32 hpzcon08.dll,VendorJettison hp deskjet 5100 series
            HP Photo and Imaging 2.2 - Scanjet 3970 Series-->MsiExec.exe /I{796ADAFF-7C5B-4CED-BA11-55A3644F1E0D}
            Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
            Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
            Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
            Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
            KeepV Flash Converter-->"C:\Program Files\KeepV Converter\unins000.exe"
            KhalInstallWrapper-->MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
            K-Lite Codec Pack 4.2.5 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
            Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
            Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\SETUP.EXE" -l0x40c UNINSTALL
            Logitech QuickCam-->MsiExec.exe /X{3AF8FCCD-F51A-4014-9002-F195E1CBC876}
            Logitech SetPoint-->C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe -runfromtemp -l0x040c -removeonly
            Logitech Updater-->MsiExec.exe /I{53735ECE-E461-4FD0-B742-23A352436D3A}
            ManyCam 2.3 (remove only)-->"C:\Program Files\ManyCam 2.3\uninstall.exe"
            Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
            Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
            Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
            Microsoft .NET Framework 3.0-->MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
            Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
            Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
            Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
            Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
            Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
            Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
            Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
            Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
            Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
            Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
            Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
            Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
            Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
            Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
            Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
            Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
            Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
            Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
            Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
            Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
            Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
            Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
            Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)-->MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
            Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB953155)-->"C:\WINDOWS\$NtUninstallKB953155$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
            MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
            MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
            MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
            neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
            NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
            NVIDIA PhysX v8.09.04-->MsiExec.exe /X{A7E07C2B-2220-4415-87E3-784D5814BC93}
            OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
            Opera 9.64-->MsiExec.exe /X{E1BBBAC5-2857-4155-82A6-54492CE88620}
            Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
            Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
            PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
            pdfforge Toolbar v1.0-->MsiExec.exe /X{B8B0FC8B-E69B-4215-AF1A-4BDFF20D794B}
            Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
            QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
            Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
            SAMSUNG Mobile Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
            Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
            SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
            SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
            Samsung PC Studio 3 USB Driver Installer-->"C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -runfromtemp -l0x040c -removeonly
            Samsung PC Studio 3-->"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -runfromtemp -l0x040c -removeonly
            Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
            Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
            Security Update for 2007 Microsoft Office System (KB958439)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {6491B8AA-D11C-4648-A461-6234B31EB7E2}
            Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
            Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
            Security Update for Microsoft Office Excel 2007 (KB958437)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {648FC016-2D6B-4A16-8D87-404533642F4B}
            Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
            Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
            Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
            Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
            Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
            Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
            Sibelius Scorch (Firefox, Opera, Netscape only)-->MsiExec.exe /I{5F4B558D-8AEB-4DEE-AAB3-C00D1D9A86BA}
            SmartSound Quicktracks for Premiere Elements-->"C:\Program Files\InstallShield Installation Information\{F6234880-85BE-4DCB-8A45-1FF85A1A8552}\setup.exe" -runfromtemp -l0x0409 -removeonly
            SmartSound Quicktracks for Premiere Elements-->MsiExec.exe /I{F6234880-85BE-4DCB-8A45-1FF85A1A8552}
            SolidWorks Explorer 2009 sp03-->MsiExec.exe /I{030A97A0-8506-4ABD-98B1-183F8889EF8C}
            Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
            Update for Office 2007 (KB946691)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
            Update for Outlook 2007 Junk Email Filter (kb959634)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {50C77E2F-5C1C-467D-9BC8-3CA07D28C9F2}
            UxTheme Multipatcher Fr-->C:\Program Files\UxTheme Multipatcher Fr\uninstall.exe
            Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
            Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
            Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
            Windows Installer Clean Up-->MsiExec.exe /X{121634B0-2F4B-11D3-ADA3-00C04F52DD52}
            Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
            Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
            Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
            Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
            Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
            Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
            Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
            Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
            Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
            WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
            ZENcast Organizer-->"C:\Program Files\Creative Installation Information\ZENCAST_ORGANIZER\Setup.exe" /remove /l0x040c
            Zune Desktop Theme-->MsiExec.exe /X{7E20EFE6-E604-48C6-8B39-BA4742F2CDB4}

            ======Security center information======

            AV: AntiVir Desktop

            ======System event log======

            Computer Name: GUYEZ-DG
            Event Code: 7036
            Message: Le service Carte de performance WMI est entré dans l'état : arrêté.

            Record Number: 24574
            Source Name: Service Control Manager
            Time Written: 20090627224931.000000+120
            Event Type: Informations
            User:

            Computer Name: GUYEZ-DG
            Event Code: 7036
            Message: Le service Carte de performance WMI est entré dans l'état : en cours d'exécution.

            Record Number: 24573
            Source Name: Service Control Manager
            Time Written: 20090627224931.000000+120
            Event Type: Informations
            User:

            Computer Name: GUYEZ-DG
            Event Code: 7035
            Message: Un contrôle Démarrer a correctement été envoyé au service Carte de performance WMI.

            Record Number: 24572
            Source Name: Service Control Manager
            Time Written: 20090627224931.000000+120
            Event Type: Informations
            User: AUTORITE NT\SYSTEM

            Computer Name: GUYEZ-DG
            Event Code: 7036
            Message: Le service Gestionnaire de connexions d'accès distant est entré dans l'état : en cours d'exécution.

            Record Number: 24571
            Source Name: Service Control Manager
            Time Written: 20090627224930.000000+120
            Event Type: Informations
            User:

            Computer Name: GUYEZ-DG
            Event Code: 7036
            Message: Le service Service de la passerelle de la couche Application est entré dans l'état : en cours d'exécution.

            Record Number: 24570
            Source Name: Service Control Manager
            Time Written: 20090627224930.000000+120
            Event Type: Informations
            User:

            =====Application event log=====

            Computer Name: GUYEZ-DG
            Event Code: 518
            Message: The Windows CardSpace service has been idle for some time. It has been shut down to make resources available for other programs.

            Record Number: 5820
            Source Name: CardSpace 3.0.0.0
            Time Written: 20090330203721.000000+120
            Event Type: Informations
            User: AUTORITE NT\SYSTEM

            Computer Name: GUYEZ-DG
            Event Code: 0
            Message: Service started successfully.

            Record Number: 5819
            Source Name: idsvc
            Time Written: 20090330193721.000000+120
            Event Type: Informations
            User:

            Computer Name: GUYEZ-DG
            Event Code: 0
            Message:
            Record Number: 5818
            Source Name: gusvc
            Time Written: 20090330193129.000000+120
            Event Type: Informations
            User:

            Computer Name: GUYEZ-DG
            Event Code: 0
            Message:
            Record Number: 5817
            Source Name: gupdate1c9992f1d46729e
            Time Written: 20090330193056.000000+120
            Event Type: Informations
            User:

            Computer Name: GUYEZ-DG
            Event Code: 19011
            Message:
            Record Number: 5816
            Source Name: MSSQL$SONY_MEDIAMGR
            Time Written: 20090330193040.000000+120
            Event Type: Avertissement
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\WBEM;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Samsung\Samsung PC Studio 3\;C:\Program Files\ESTsoft\ALZip\;C:\Program Files\Fichiers communs\Adobe\AGL;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Fichiers communs\Ulead Systems\MPEG
            "windir"=%SystemRoot%
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "PROCESSOR_ARCHITECTURE"=x86
            "PROCESSOR_LEVEL"=15
            "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 2, AuthenticAMD
            "PROCESSOR_REVISION"=6b02
            "NUMBER_OF_PROCESSORS"=2
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
            "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

            -----------------EOF-----------------
            0
            1. désolé pour le double post du rapport info ce n'étais pas voulu
              Voici le rapport de SmitfraudFix :
              SmitFraudFix v2.423

              Rapport fait à 19:33:56,59, 10/08/2009
              Executé à partir de C:\Documents and Settings\Philippe\Bureau\SmitfraudFix
              OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
              Le type du système de fichiers est NTFS
              Fix executé en mode normal

              »»»»»»»»»»»»»»»»»»»»»»»» DNS Avant Fix

              Votre ordinateur est certainement victime d'un détournement de DNS: 85.255.x.x détecté !

              Description: Realtek RTL8169/8110 Family Gigabit Ethernet NIC - Miniport d'ordonnancement de paquets
              DNS Server Search Order: 85.255.112.87
              DNS Server Search Order: 85.255.112.195

              HKLM\SYSTEM\CCS\Services\Tcpip\..\{99F1FA63-F48F-49AE-899F-BD68498E40BA}: DhcpNameServer=192.168.1.254
              HKLM\SYSTEM\CCS\Services\Tcpip\..\{99F1FA63-F48F-49AE-899F-BD68498E40BA}: NameServer=85.255.112.87,85.255.112.195
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{99F1FA63-F48F-49AE-899F-BD68498E40BA}: DhcpNameServer=192.168.1.254
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{99F1FA63-F48F-49AE-899F-BD68498E40BA}: NameServer=85.255.112.87,85.255.112.195
              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.112.87,85.255.112.195
              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.112.87,85.255.112.195

              »»»»»»»»»»»»»»»»»»»»»»»» DNS Après Fix
              0
              1. Bien !

                Suis la procédure :

                ~~~~~~~~~~~~~~~> Lop S&D <~~~~~~~~~~~~~~~~~~

                Téléchargez Lop S&D d'Eric 71 & Angeldark à partir de ce lien

                > https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2

                - Cliquez sur Enregistrer et placez le sur le Bureau

                - Une fois le Téléchargement terminé, cliquez sur Fermer
                - Double-cliquez sur l'icône pour lancer l'installation

                - Acceptez les termes d'utilisation et cliquez sur Suivant
                - Cliquez sur Oui pour créer un répertoire

                - Double-cliquez sur le nouvel icône placé sur votre bureau pour lancer l'outil

                - Choisissez votre langue : dans notre cas, ce sera Français, tapez F et pressez la touche Entrée de votre clavier
                - Un rapport apparait automatiquement, Poste le dans ton prochain message
                0
                1. Bonjour xaton,

                  sauf si j'ai loupé quelquechose, peux tu m'expliquer ce qui motive Lopsd ?
                  0
                  1. Ceci :

                    "main.exoclick" et "https://fr.yahoo.com/?p=us" qui s'ouvrent a chaque fois que je clique sur un lien

                    Et ceci :

                    O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"

                    ???
                    0
                    1. Impossible de suivre ta procédure car LopSD me demande directement quelle langue je veux, j'ai pris Français, et il m'affiche un nouveau choix a faire : " 1-recherche / 2-suppression+hosts / 3-suppression-hosts / 4- lopscript / quitter / whitelist.

                      Je n'ai eu aucun reglement a accepter ni de nouvelle icone. .
                      0
                      1. pour la procédure de neophyte*** j'ai deja mis le rapport de smithfraudfix.

                        j'ai aussi fais la recherche de lopR, mais là j'avoue que vous n'avez pas l'air d'accord alors je voudrais savoir ce dont vous avez besoin.
                        0
                        1. bjr archet ;)

                          phil, desole, parti mangé ;)

                          xatron
                          O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" :

                          https://www.systemlookup.com/Startup/2469-CTSyncU_exe.html

                          qu'a t'elle de nefaste, sous xp (comme vista) une infection lop est située dans app data avec des appellations entre crochets avec des mots anglais aleatoires :)

                          phil :

                          ton rapport Smit n'est pas complet, peux tu verifier stp ensuite on va s'ocupper de ton infection de sources amovibles et en profiter pour les vacciner pour le futur :

                          * Telecharge UsbFix de C_XX & Chiquitine29
                          * tutoriel d'installation
                          * tutoriel recherche
                          * Lance l installation avec les parametres par default
                          * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d'avoir été infectés sans les ouvrir
                          * Double clic sur le raccourci UsbFix sur ton bureau
                          * Choisi l'option 1 (recherche)
                          * Laisse travailler l'outil
                          * Ensuite post le rapport UsbFix.txt qui apparaîtra
                          * Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

                          * Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus

                          0
                          1. c'est ça que tu voulais plutot?

                            SmitFraudFix v2.423

                            Rapport fait à 20:36:38,67, 10/08/2009
                            Executé à partir de C:\Documents and Settings\Philippe\Bureau\SmitfraudFix
                            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                            Le type du système de fichiers est NTFS
                            Fix executé en mode normal

                            »»»»»»»»»»»»»»»»»»»»»»»» Process

                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Avira\AntiVir Desktop\sched.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
                            C:\WINDOWS\system32\RUNDLL32.EXE
                            C:\WINDOWS\system32\LVCOMSX.EXE
                            C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                            C:\Program Files\Logitech\QuickCam\Quickcam.exe
                            C:\WINDOWS\system32\rundll32.exe
                            C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
                            C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
                            C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                            C:\WINDOWS\system32\CTsvcCDA.exe
                            C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
                            C:\Program Files\Java\jre6\bin\jqs.exe
                            C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                            C:\WINDOWS\RTHDCPL.EXE
                            C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                            C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
                            C:\Program Files\Java\jre6\bin\jusched.exe
                            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\Program Files\ManyCam 2.3\ManyCam.exe
                            C:\Documents and Settings\Philippe\Mes documents\TrueTransparency\TrueTransparency\TrueTransparency.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
                            C:\WINDOWS\system32\nvsvc32.exe
                            C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                            C:\Program Files\Logitech\SetPoint\SetPoint.exe
                            C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                            C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
                            C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Program Files\Opera\opera.exe
                            C:\WINDOWS\system32\cmd.exe

                            »»»»»»»»»»»»»»»»»»»»»»»» hosts

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Philippe

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Philippe\LOCALS~1\Temp

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Philippe\Application Data

                            C:\Documents and Settings\Philippe\Application Data\Skinux PRESENT !

                            »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Philippe\Favoris

                            »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                            »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                            »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                            "Source"="About:Home"
                            "SubscribedURL"="About:Home"
                            "FriendlyName"="Ma page d'accueil"

                            »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            o4Patch
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            IEDFix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            Agent.OMZ.Fix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            VACFix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            404Fix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            SrchSTS.exe by S!Ri
                            Search SharedTaskScheduler's .dll

                            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                            "AppInit_DLLs"=""

                            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                            "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

                            »»»»»»»»»»»»»»»»»»»»»»»» RK

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                            "System"=""

                            »»»»»»»»»»»»»»»»»»»»»»»» DNS

                            Description: Realtek RTL8169/8110 Family Gigabit Ethernet NIC - Miniport d'ordonnancement de paquets
                            DNS Server Search Order: 192.168.1.254

                            HKLM\SYSTEM\CCS\Services\Tcpip\..\{99F1FA63-F48F-49AE-899F-BD68498E40BA}: DhcpNameServer=192.168.1.254

                            »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                            »»»»»»»»»»»»»»»»»»»»»»»» Fin
                            0
                            1. euhh non , ca c'est l'opt1 , bon maintenant que tu l'as fais, :

                              Nettoyage :
                              Démarre en mode sans échec :
                              Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
                              Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                              Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                              (Si F8 ne marche pas utilise la touche F5).

                              tuto
                              tuto

                              Relance le programme Smitfraud,
                              Cette fois choisit l’option 2, répond oui a tous ;
                              Sauvegarde le rapport, Redémarre en mode normal,
                              copie/colle le rapport sauvegardé sur le forum

                              process.exe
                              est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                              http://www.beyondlogic.org/consulting/processutil/processutil.htm

                              ENSUITE

                              Tu peux faire la procedure USBFIX que je t'ai donné plus haut ;)
                              0
                              1. rapport obtenu après le nettoyage smithfraud :

                                SmitFraudFix v2.423

                                Rapport fait à 20:36:38,67, 10/08/2009
                                Executé à partir de C:\Documents and Settings\Philippe\Bureau\SmitfraudFix
                                OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                                Le type du système de fichiers est NTFS
                                Fix executé en mode normal

                                »»»»»»»»»»»»»»»»»»»»»»»» Process

                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
                                C:\WINDOWS\system32\RUNDLL32.EXE
                                C:\WINDOWS\system32\LVCOMSX.EXE
                                C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                                C:\Program Files\Logitech\QuickCam\Quickcam.exe
                                C:\WINDOWS\system32\rundll32.exe
                                C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
                                C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
                                C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                C:\WINDOWS\system32\CTsvcCDA.exe
                                C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
                                C:\Program Files\Java\jre6\bin\jqs.exe
                                C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                C:\WINDOWS\RTHDCPL.EXE
                                C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                                C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
                                C:\Program Files\Java\jre6\bin\jusched.exe
                                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                C:\Program Files\ManyCam 2.3\ManyCam.exe
                                C:\Documents and Settings\Philippe\Mes documents\TrueTransparency\TrueTransparency\TrueTransparency.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                C:\Program Files\Logitech\SetPoint\SetPoint.exe
                                C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
                                C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\wuauclt.exe
                                C:\Program Files\Opera\opera.exe
                                C:\WINDOWS\system32\cmd.exe

                                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Philippe

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Philippe\LOCALS~1\Temp

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Philippe\Application Data

                                C:\Documents and Settings\Philippe\Application Data\Skinux PRESENT !

                                »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Philippe\Favoris

                                »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                                »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                                »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                                "Source"="About:Home"
                                "SubscribedURL"="About:Home"
                                "FriendlyName"="Ma page d'accueil"

                                »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                o4Patch
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                IEDFix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                Agent.OMZ.Fix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                VACFix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                404Fix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                SrchSTS.exe by S!Ri
                                Search SharedTaskScheduler's .dll

                                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                "AppInit_DLLs"=""

                                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

                                »»»»»»»»»»»»»»»»»»»»»»»» RK

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                "System"=""

                                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                Description: Realtek RTL8169/8110 Family Gigabit Ethernet NIC - Miniport d'ordonnancement de paquets
                                DNS Server Search Order: 192.168.1.254

                                HKLM\SYSTEM\CCS\Services\Tcpip\..\{99F1FA63-F48F-49AE-899F-BD68498E40BA}: DhcpNameServer=192.168.1.254

                                »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                                »»»»»»»»»»»»»»»»»»»»»»»» Fin

                                . rapport usbfix (que j'avais fais avant l'autre)

                                ############################## | UsbFix V6.014 |

                                User : Philippe (Administrateurs) # GZ-DG
                                Update on 04/08/09 by Chiquitine29 & C_XX
                                Start at: 20:41:03 | 10/08/2009
                                Website : http://pagesperso-orange.fr/NosTools/index.html

                                AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
                                Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                Internet Explorer 7.0.5730.13
                                Windows Firewall Status : Enabled
                                AV : AntiVir Desktop 9.0.1.30 [ Enabled | Updated ]

                                A:\ -> Lecteur de disquettes 3 ½ pouces
                                C:\ -> Disque fixe local # 232,88 Go (183,86 Go free) # NTFS
                                D:\ -> Disque fixe local # 29,29 Go (12,99 Go free) [Partagé (photos, docs)] # NTFS
                                E:\ -> Disque fixe local # 45,23 Go (37,04 Go free) [S2] # NTFS
                                F:\ -> Disque CD-ROM
                                G:\ -> Disque amovible
                                H:\ -> Disque amovible # 3,73 Go (2,98 Go free) [KEY P G] # FAT32
                                I:\ -> Disque amovible
                                J:\ -> Disque amovible
                                K:\ -> Disque amovible
                                L:\ -> Disque fixe local # 335,35 Go (34,82 Go free) [Externe] # NTFS

                                ############################## | Processus actifs |

                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\csrss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
                                C:\WINDOWS\system32\RUNDLL32.EXE
                                C:\WINDOWS\system32\LVCOMSX.EXE
                                C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                                C:\Program Files\Logitech\QuickCam\Quickcam.exe
                                C:\WINDOWS\system32\rundll32.exe
                                C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
                                C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                C:\WINDOWS\system32\CTsvcCDA.exe
                                C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
                                C:\Program Files\Java\jre6\bin\jqs.exe
                                C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                C:\WINDOWS\RTHDCPL.EXE
                                C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                                C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
                                C:\Program Files\Java\jre6\bin\jusched.exe
                                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                C:\Program Files\ManyCam 2.3\ManyCam.exe
                                C:\Documents and Settings\Philippe\Mes documents\TrueTransparency\TrueTransparency\TrueTransparency.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                C:\Program Files\Logitech\SetPoint\SetPoint.exe
                                C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                C:\WINDOWS\System32\alg.exe
                                C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
                                C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Opera\opera.exe
                                C:\Program Files\Java\jre6\bin\jucheck.exe
                                C:\WINDOWS\system32\wbem\wmiprvse.exe

                                ################## | Fichiers # Dossiers infectieux |

                                ################## | Other | https://www.virustotal.com/gui/ |

                                ################## | Registre # Clés Run infectieuses |

                                ################## | Registre # Mountpoints2 |

                                HKCU\..\..\Explorer\MountPoints2\{e299efbc-fd22-11dd-95bd-00e04cd02f65}
                                Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn

                                ################## | Cracks / Keygens / Serials |

                                ################## | ! Fin du rapport # UsbFix V6.014 ! |
                                0
                                1. * tutoriel nettoyage

                                  * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectés sans les ouvrir
                                  * Double clic sur le raccourci UsbFix présent sur ton bureau
                                  * choisi l'option 2 ( Suppression )
                                  * Ton bureau disparaîtra et le pc redémarrera .
                                  * Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.
                                  * Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .
                                  * Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                                  ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                  ENSUITE

                                  Imprime ces instructions ou sauvegarde les sur ton Bureau car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                                  Télécharge Malwarebytes’ Anti-Malware

                                  (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX)

                                  - Sur la page cliques sur Télécharger Malwarebyte’s Anti-Malware
                                  - Enregistres le sur le bureau
                                  - Double cliques sur le fichier téléchargé pour lancer le processus d’installation
                                  - Lorsqu’il te le sera demandé, met à jour Malwarebytes anti malware
                                  - Si le pare-feu demande l’autorisation de se connecter pour malwarebytes, acceptes
                                  - Une fois la mise à jour terminée, ferme Malwarebytes
                                  - Double-cliques sur l’icône de malwarebytes pour le relancer
                                  - Dans l’onglet, Recherche, probablement ouvert par défaut,
                                  - Sélectionne Exécuter un examen complet
                                  - Clique sur Rechercher
                                  - Le scan démarre
                                  - A la fin de l’analyse, un message s’affiche : L’examen s’est terminé normalement. Cliquez sur ‘Afficher les résultats’ pour afficher tous les objets trouvés.
                                  - Cliques sur Ok pour poursuivre.
                                  - Si des malwares ont été détectés, cliques sur Afficher les résultats
                                  - Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                                  - Malwarebytes va ouvrir le bloc-notes et y copier le rapport d’analyse.
                                  - Rends toi dans l’onglet rapport/log
                                  - Tu cliques dessus pour l’afficher une fois affiché
                                  - Tu cliques sur édition en haut du bloc notes, et puis sur sélectionner tout
                                  - Tu recliques sur édition et puis sur copier et tu reviens sur le forum et dans ta réponse
                                  - Tu cliques droit dans le cadre de la réponse et coller

                                  Si tu as besoin d’aide regarde ce tutorial

                                  https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                                  ps: s'il te demande de redemarrer : fais le !

                                  0
                                  1. Alors , Usbfix :
                                    ############################## | UsbFix V6.014 |

                                    User : Philippe (Administrateurs) # GZ-DG
                                    Update on 04/08/09 by Chiquitine29 & C_XX
                                    Start at: 23:08:47 | 10/08/2009
                                    Website : http://pagesperso-orange.fr/NosTools/index.html

                                    AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
                                    Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                    Internet Explorer 7.0.5730.13
                                    Windows Firewall Status : Enabled
                                    AV : AntiVir Desktop 9.0.1.30 [ Enabled | Updated ]

                                    A:\ -> Lecteur de disquettes 3 ½ pouces
                                    C:\ -> Disque fixe local # 232,88 Go (183,93 Go free) # NTFS
                                    D:\ -> Disque fixe local # 29,29 Go (12,99 Go free) [Partagé (photos, docs)] # NTFS
                                    E:\ -> Disque fixe local # 45,23 Go (37,04 Go free) [S2] # NTFS
                                    F:\ -> Disque CD-ROM
                                    G:\ -> Disque amovible
                                    H:\ -> Disque amovible # 3,73 Go (2,98 Go free) [KEY P Z] # FAT32
                                    I:\ -> Disque amovible
                                    J:\ -> Disque amovible
                                    K:\ -> Disque amovible
                                    L:\ -> Disque fixe local # 335,35 Go (35,02 Go free) [Externe] # NTFS

                                    ############################## | Processus actifs |

                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\csrss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\LogonUI.EXE
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                    C:\WINDOWS\system32\userinit.exe
                                    C:\Program Files\Google\Update\GoogleUpdate.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                                    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                    C:\WINDOWS\system32\CTsvcCDA.exe
                                    C:\Program Files\Google\Update\GoogleUpdate.exe
                                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    C:\Program Files\Java\jre6\bin\jqs.exe
                                    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                    C:\Program Files\Google\Update\GoogleUpdate.exe
                                    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                                    C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                                    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                    C:\WINDOWS\System32\alg.exe

                                    ################## | Fichiers # Dossiers infectieux |

                                    ################## | Other |

                                    ################## | Suspect ... | https://www.virustotal.com/gui/ |

                                    ################## | Registre # Clés Run infectieuses |

                                    ################## | Registre # Mountpoints2 |

                                    Supprimé ! HKCU\...\Explorer\MountPoints2\{e299efbc-fd22-11dd-95bd-00e04cd02f65}\Shell\AutoRun\Command

                                    ################## | Listing des fichiers présent |

                                    [18/06/2004 14:07|--a------|656542] -> C:\271_icol.dll
                                    [04/11/2008 20:14|--a------|0] -> C:\AUTOEXEC.BAT
                                    [27/03/2009 23:25|--ahs----|216] -> C:\boot.ini
                                    [02/03/2006 14:00|-rahs----|4952] -> C:\Bootfont.bin
                                    [07/03/2009 12:50|--a------|74] -> C:\CMLoader.log
                                    [04/11/2008 20:14|--a------|0] -> C:\CONFIG.SYS
                                    [22/01/2009 22:16|--a------|0] -> C:\fftoutput.txt
                                    [09/08/2009 22:49|--a------|180852] -> C:\hpfr5100.log
                                    [04/11/2008 20:14|-rahs----|0] -> C:\IO.SYS
                                    [24/05/2009 01:21|--ah-----|1082] -> C:\IPH.PH
                                    [04/12/2008 20:50|--a------|90] -> C:\LogiSetup.log
                                    [10/08/2009 19:58|--a------|24429] -> C:\lopR.txt
                                    [04/11/2008 20:14|-rahs----|0] -> C:\MSDOS.SYS
                                    [02/03/2006 14:00|-rahs----|47564] -> C:\NTDETECT.COM
                                    [17/05/2009 11:02|-rahs----|252240] -> C:\ntldr
                                    [?|?|?] -> C:\pagefile.sys
                                    [10/11/2008 20:22|--a------|48155] -> C:\playground.log
                                    [10/08/2009 22:35|--a------|2004] -> C:\rapport.txt
                                    [18/04/2009 14:57|--a------|270] -> C:\RecorderSDKLog.txt
                                    [06/12/2008 19:45|--ah-----|292] -> C:\sqmdata00.sqm
                                    [29/12/2008 18:44|--ah-----|268] -> C:\sqmdata01.sqm
                                    [25/12/2008 13:58|--ah-----|268] -> C:\sqmdata02.sqm
                                    [06/12/2008 19:45|--ah-----|244] -> C:\sqmnoopt00.sqm
                                    [29/12/2008 18:44|--ah-----|244] -> C:\sqmnoopt01.sqm
                                    [25/12/2008 13:58|--ah-----|244] -> C:\sqmnoopt02.sqm
                                    [11/08/2009 00:00|--a------|4261] -> C:\UsbFix.txt
                                    [02/01/2009 18:19|--ahs----|10240] -> D:\Thumbs.db
                                    [07/08/2009 01:27|--a------|27938] -> H:\291637_T1R7WZOFRAMND2SR8TN15CPJYZFETJ_dessin_3_H010720_L.jpg
                                    [25/11/2008 16:09|---hs----|16384] -> H:\Thumbs.db
                                    [14/06/2009 17:22|--a------|60667] -> H:\654654654879879879873413213212313212315465465468784546876543432132135654326546548754487654654646546543432132131346574876543432131313135465987.jpg
                                    [02/06/2009 21:49|--a------|29769] -> H:\2316602973_small_4.jpg
                                    [09/05/2009 19:06|--a------|259992] -> H:\FreeBoxUSB_1301.EXE
                                    [08/06/2009 21:48|--a------|6535] -> H:\1456647024570626352.jpg
                                    [20/06/2009 21:18|--a------|1161576] -> H:\wlsetup-web.exe
                                    [20/06/2009 21:20|--a------|1161576] -> H:\wlsetup-custom.exe
                                    [23/06/2009 02:07|--a------|733743104] -> H:\Muse-Haarp.avi
                                    [07/08/2009 23:37|--a------|40630] -> H:\2508543655_small_1.jpg
                                    [31/07/2009 03:06|--a------|416426] -> H:\essaifuzzz.jpg
                                    [07/08/2009 23:38|--a------|130702] -> H:\Viva-la-resistance.jpg
                                    [24/03/2009 23:28|--ahs----|63488] -> L:\Thumbs.db

                                    ################## | Vaccination |

                                    # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                                    # D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                                    # E:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                                    # H:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                                    # L:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

                                    ################## | Cracks / Keygens / Serials |

                                    ################## | ! Fin du rapport # UsbFix V6.014 ! |

                                    ______________________________________________________________________________________
                                    Malwarebytes' :

                                    Malwarebytes' Anti-Malware 1.40
                                    Version de la base de données: 2594
                                    Windows 5.1.2600 Service Pack 3

                                    11/08/2009 03:47:29
                                    mbam-log-2009-08-11 (03-47-29).txt

                                    Type de recherche: Examen complet (C:\|D:\|E:\|L:\|)
                                    Eléments examinés: 314580
                                    Temps écoulé: 2 hour(s), 25 minute(s), 34 second(s)

                                    Processus mémoire infecté(s): 0
                                    Module(s) mémoire infecté(s): 0
                                    Clé(s) du Registre infectée(s): 4
                                    Valeur(s) du Registre infectée(s): 0
                                    Elément(s) de données du Registre infecté(s): 0
                                    Dossier(s) infecté(s): 2
                                    Fichier(s) infecté(s): 3

                                    Processus mémoire infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Module(s) mémoire infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Clé(s) du Registre infectée(s):
                                    HKEY_CURRENT_USER\SOFTWARE\{NSINAME} (Trojan.Agent) -> Quarantined and deleted successfully.
                                    HKEY_CURRENT_USER\SOFTWARE\HDPlugin (Trojan.DNSChanger) -> Quarantined and deleted successfully.
                                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HDPlugin (Trojan.DNSChanger) -> Quarantined and deleted successfully.
                                    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gaopdxserv.sys (Trojan.Agent) -> Quarantined and deleted successfully.

                                    Valeur(s) du Registre infectée(s):
                                    (Aucun élément nuisible détecté)

                                    Elément(s) de données du Registre infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Dossier(s) infecté(s):
                                    C:\Program Files\HDPlugin (Trojan.DNSChanger) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\Philippe\Menu Démarrer\Programmes\HDPlugin (Trojan.DNSChanger) -> Quarantined and deleted successfully.

                                    Fichier(s) infecté(s):
                                    C:\Program Files\HDPlugin\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
                                    C:\System Volume Information\_restore{9E3517E3-B2AB-4C79-9949-C9F305198A02}\RP285\A0086605.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\Philippe\Menu Démarrer\Programmes\HDPlugin\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.
                                    0
                                    1. Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 15:35:14, on 11/08/2009
                                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v7.00 (7.00.6000.16876)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                      C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                                      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                      C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
                                      C:\WINDOWS\system32\CTsvcCDA.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\Java\jre6\bin\jqs.exe
                                      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                      C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                                      C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\WINDOWS\system32\nvsvc32.exe
                                      C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
                                      C:\WINDOWS\system32\RUNDLL32.EXE
                                      C:\WINDOWS\system32\rundll32.exe
                                      C:\WINDOWS\system32\LVCOMSX.EXE
                                      C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                                      C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
                                      C:\Program Files\Logitech\QuickCam\Quickcam.exe
                                      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                      C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
                                      C:\WINDOWS\RTHDCPL.EXE
                                      C:\Program Files\Java\jre6\bin\jusched.exe
                                      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                      C:\Program Files\ManyCam 2.3\ManyCam.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Documents and Settings\Philippe\Mes documents\TrueTransparency\TrueTransparency\TrueTransparency.exe
                                      C:\WINDOWS\system32\ctfmon.exe
                                      C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
                                      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                      C:\Program Files\Logitech\SetPoint\SetPoint.exe
                                      C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
                                      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                                      C:\Program Files\Opera\opera.exe
                                      C:\Program Files\Java\jre6\bin\jucheck.exe
                                      C:\Program Files\trend micro\Philippe.exe

                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                      R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
                                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
                                      O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
                                      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                      O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
                                      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                      O2 - BHO: Loader Class - {F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD} - C:\WINDOWS\BricoPacks\LeopardXP\FindeXer.dll (file missing)
                                      O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
                                      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                      O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
                                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                                      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                                      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
                                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                      O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                                      O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
                                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                      O4 - HKCU\..\Run: [ManyCam] "C:\Program Files\ManyCam 2.3\ManyCam.exe"
                                      O4 - HKCU\..\Run: [TrueTransparency] "C:\Documents and Settings\Philippe\Mes documents\TrueTransparency\TrueTransparency\TrueTransparency.exe"
                                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                      O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
                                      O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
                                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                      O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                      O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
                                      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                      O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/2.0.2.3/cfweb_activex.camfrogweb.com-advanced-2.0.2.3_instmodule.exe
                                      O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
                                      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
                                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                                      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                                      O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
                                      O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game14.zylom.com/activex/zylomgamesplayer.cab
                                      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                                      O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                                      O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
                                      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                      O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                                      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                                      O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
                                      O23 - Service: Service Google Update (gupdate1c9992f1d46729e) (gupdate1c9992f1d46729e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                      O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\LogiShrd\Bluetooth\LBTServ.exe
                                      O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                                      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                                      O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe (file missing)
                                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                      O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                                      O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe
                                      0
                                      • 1
                                      • 2
                                      • 3