Comment supprimer trojan win32 renos.jm

Bonjour, mon pc portable a été infécter par un trojan win 32 renos.jm que je n'arrive pas à enlever comment faire je suis sous windows vista et j'ai en antivirus bitdefender voila merci d'avance pour l'aide que vous m'apporterez
Configuration: Windows Vista
Safari 532.0

35 réponses

Résumé de la discussion

Une infection par trojan Win32 Renos.jm sur un PC Windows Vista est signalée, avec une difficulté à l’éliminer malgré l’antivirus Bitdefender. La réponse principale recommande Malwarebytes Anti-Malware : téléchargement, mise à jour, analyse complète et suppression des éléments détectés avant un redémarrage. Des solutions secondaires évoquent l’utilisation d’outils comme SuperAntiSpyware et des vérifications de processus, de journaux et des rapports d’analyse pour guider l’éradication. Des rapports d’analyse générés par les outils permettent de suivre les éléments supprimés et les actions recommandées, facilitant la poursuite du nettoyage.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonsoir,

    ▶ Télécharge Random's System Information Tool (RSIT).

    ▶ Un tutoriel est à ta disposition pour l'installer et l'utiliser correctement ici

    ▶ Double clique sur RSIT.exe pour lancer l'outil.

    ▶ Clique sur 'Continue' à l'écran Disclaimer.

    ▶ Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

    ▶ Une fois le scan fini , 2 rapports vont apparaitre. ▶ copie le contenu des 2 rapports.

    ( C:\RSIT\log.txt et C:\RSIT\info.txt )

    CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller

    ▶ Ensuite viens coller dans ta prochaine réponse le rapport log.txt et dans une autre réponse la rapport info.txt afin qu'ils soient complet tout les 2.
    0
    1. voila les deux rapports

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by user at 2009-12-27 22:31:49
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
      System drive C: has 57 GB (32%) free of 181 GB
      Total RAM: 2046 MB (32% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 22:33:07, on 27/12/2009
      Platform: Windows Vista SP2 (WinNT 6.00.1906)
      MSIE: Internet Explorer v7.00 (7.00.6002.18005)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Apoint\Apoint.exe
      C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
      C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
      C:\Program Files\sony\VAIO Camera Utility\VCUServe.exe
      C:\Program Files\sony\ISB Utility\ISBMgr.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Search Settings\SearchSettings.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
      C:\Users\user\Program Files\DNA\btdna.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
      C:\Windows\System32\mobsync.exe
      C:\Program Files\Apoint\ApMsgFwd.exe
      C:\Program Files\Apoint\Apntex.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe
      C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe
      C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe
      C:\Users\user\Documents\Downloads\RSIT.exe
      C:\Program Files\trend micro\user.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://recherche.neuf.fr/ie/default.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://recherche.neuf.fr/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O1 - Hosts: ::1 localhost
      O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
      O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
      O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
      O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
      O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
      O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\user\Program Files\DNA\btdna.exe"
      O4 - HKCU\..\Run: [Google Update] "C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe" /c
      O4 - HKCU\..\Run: [J8RPLTROBQ] C:\Users\user\AppData\Local\Temp\c.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\user\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
      O4 - Global Startup: Bluetooth Manager.lnk = ?
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
      O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\MSCSPTISRV.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AvLib\PACSPTISVR.exe
      O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
      O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SsBeSvc.exe
      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SPTISRV.exe
      O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SSScsiSV.exe
      O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\stacsv.exe
      O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
      O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
      O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\sony\VAIO Event Service\VESMgr.exe
      O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\VMISrv.exe
      O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
      O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
      O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\VmGateway.exe
      O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\UCLS.exe
      O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
      O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
      O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
      O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
      0
      1. Contributeur sécurité
        le rapport info.txt n'est pas complet, tu peux me le reposter. merci.
        0
        1. comment fait tu pour revoir le info.txt
          0
          1. info.txt logfile of random's system information tool 1.06 2009-12-27 22:33:22

            ======Uninstall list======

            -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
            -->C:\Program Files\InstallShield Installation Information\{69333A04-5134-40A5-A055-9166A7AA1EC8}\setup.exe -runfromtemp -l0x0009 -removeonly
            -->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
            -->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
            -->C:\Windows\UNRecode.exe /UNINSTALL
            -->Dummy
            -->MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF}
            -->MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87}
            -->MsiExec.exe /I{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}
            -->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
            -->MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
            -->MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82}
            -->MsiExec.exe /I{C4CBAD7E-DF4A-4FEC-AC17-8BC709AFB844}
            -->MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
            -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{55B781F0-060E-11D4-99D7-00C04FCCB775}\Setup.exe" -l0x40c
            -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C183A21C-395A-490F-99D4-CCAB35E32859}\Setup.exe" -l0x40c
            Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
            Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5102}
            Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
            Adobe Help Center 2.1-->MsiExec.exe /I{25569723-DC5A-4467-A639-79535BF01B71}
            Adobe Photoshop Elements 5.0-->msiexec /I {A7B609FB-83D8-4FC3-8477-1BC65ECFE85B}
            Adobe Premiere Elements 3.0.2 Templates-->MsiExec.exe /I{6EACDDF4-4220-49A3-9204-984C86852C3D}
            Adobe Premiere Elements 3.0.2-->msiexec /I {530AFAFF-6F0A-48BB-88D0-04F9658322D3}
            Adobe Premiere Elements 3.0.2-->MsiExec.exe /I{530AFAFF-6F0A-48BB-88D0-04F9658322D3}
            Adobe Reader 9.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A92000000001}
            Alps Pointing-device for VAIO-->C:\Program Files\Apoint\Uninstap.exe ADDREMOVE
            Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
            Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
            Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
            Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
            Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
            BitDefender Internet Security 2008-->MsiExec.exe /I{72D13706-D84C-40D4-AD80-A3F2A0684E01}
            Bluetooth Stack for Windows by Toshiba-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
            Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
            Browser Address Error Redirector-->regsvr32 /u /s "C:\PROGRA~1\GOOGLE~1\BAE.dll"
            CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
            Click to DVD 2.0.05 Menu Data-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E407618-D9CD-4F39-9490-9ED45294073D}\setup.exe" -l0x40c -removeonly
            Click to DVD BD 3.0.00-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E809063C-51A3-4269-8984-D1EB742F2151}\setup.exe" -l0x40c -removeonly
            Click to DVD Menu Data 1.0 for BD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B06FE058-3C46-40D1-9298-E43CB6CA35C9}\setup.exe" -l0x40c -removeonly
            Dealio Toolbar v4.0.1-->MsiExec.exe /X{94C3BB3A-56A1-43DE-A242-8B41F46E97EF}
            DSD Direct Player-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{533D0A8A-D7E7-4F15-BC9E-FF2916A6BAA7}\setup.exe" -l0x40c -removeonly
            DSD Direct-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{82D5BACA-3619-4D34-99DB-3A65CFB4DA33}\setup.exe" -l0x40c -removeonly
            DSD Playback Plug-in-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{009E7FB7-1775-4D89-8956-F5C9A1C019FC}\setup.exe" -l0x40c -removeonly
            Fichiers de prise en charge de l'installation de Microsoft SQL Server (Français)-->MsiExec.exe /X{3380F354-C5F7-4E71-8F51-EEE6C3F06C62}
            Free Video Converter V 2.3-->"C:\Program Files\Free Video Converter\unins000.exe"
            Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
            GDR 4053 for SQL Server Database Services 2005 ENU (KB970892)-->C:\Windows\SQL9_KB970892_ENU\Hotfix.exe /Uninstall
            Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
            HDAUDIO SoftV92 Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200\HXFSETUP.EXE -U -ISnSZIRXz.inf
            HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
            Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
            Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
            iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
            Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
            Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
            Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
            Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
            Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
            Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
            Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
            Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
            Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
            Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
            Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
            Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
            Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
            Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
            Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
            Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0122-040C-0000-0000000FF1CE}
            Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
            Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
            Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
            Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
            Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
            Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
            Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
            Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
            Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
            Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
            Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
            Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
            Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
            Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
            Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
            Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
            Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
            Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
            Microsoft SQL Server 2005 Express Edition (VAIO_VEDB)-->MsiExec.exe /I{480DBB60-F0B6-45F2-B26F-1A2E11197791}
            Microsoft SQL Server 2005-->"c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
            Microsoft SQL Server Native Client-->MsiExec.exe /I{1F24E48F-7692-4E89-8784-68DD4D2712A0}
            Microsoft SQL Server VSS Writer-->MsiExec.exe /I{A30179B7-997A-4D47-AA43-57AE59A9C78B}
            Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
            Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
            Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
            Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
            Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
            Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
            Mise à jour Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {51EFB347-1F3D-4BAC-8B79-F056B904FE21}
            Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
            Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
            Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
            Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
            MobileMe Control Panel-->MsiExec.exe /I{3AC54383-31D1-4907-961B-B12CBB1D0AE8}
            Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
            Mozilla Firefox (3.0.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
            MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
            MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
            MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
            MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
            MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
            Nero 7 Essentials-->MsiExec.exe /X{BC61F51E-8AF7-46B9-AF20-B33B5EE81036}
            neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
            Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
            NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
            OpenMG Limited Patch 4.7-07-13-24-01-->C:\Program Files\Common Files\Sony Shared\OpenMG\HotFixes\HotFix4.7-07-13-24-01\HotFixSetup\setup.exe /u
            OpenMG Secure Module 4.7.00-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1150\INTEL3~1\IDriver.exe /M{CCD663AE-610D-4BDF-AAB0-E914B044527D} UNINSTALL
            Outil de restauration de données VAIO-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}\setup.exe" -l0x40c -removeonly
            Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
            Outil VAIO Media Registration 6.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}\setup.exe" -l0x40c UNINSTALL -removeonly
            Picasa 2-->"C:\Program Files\Picasa2\Uninstall.exe"
            Plugins SonicStage Mastering Studio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9C1C8A04-F8CA-4472-A92D-4288CE32DE86}\setup.exe" -l0x40c -removeonly
            QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
            Roxio Easy Media Creator Home-->MsiExec.exe /I{B7FB0C86-41A4-4402-9A33-912C462042A0}
            Safari-->MsiExec.exe /I{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}
            Search Settings 1.2.2-->MsiExec.exe /X{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
            Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
            Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
            Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
            Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
            Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
            Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
            Security Update for Microsoft Office Outlook 2007 (KB972363)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {120BE9A0-9B09-4855-9E0C-7DEE45CB03C0}
            Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
            Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
            Security Update for Microsoft Office Publisher 2007 (KB969693)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
            Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
            Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
            Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
            Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
            Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
            Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
            Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
            Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
            Setting Utility Series-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59452470-A902-477F-9338-9B88101681BD}\setup.exe" -l0x40c UNINSTALL -removeonly
            Skype 3.0-->"C:\Program Files\Skype\Phone\unins000.exe"
            Skype Plugin Manager-->MsiExec.exe /I{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}
            SonicStage 4.3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A0EB195B-5876-48E6-879D-33D4B2102610}\setup.exe" -l0x40c UNINSTALL -removeonly
            SonicStage Mastering Studio Audio Filter Custom Preset-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EC37A846-53AC-4DA7-98FA-76A4E74AA900}\setup.exe" -l0x40c -removeonly
            SonicStage Mastering Studio Audio Filter-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DF7DB916-90E5-40F2-9010-B8125EB5FD6F}\setup.exe" -l0x40c -removeonly
            SonicStage Mastering Studio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6332AFF1-9D9A-429C-AA03-F82749FA4F49}\setup.exe" -l0x40c -removeonly
            Sony Utilities DLL-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF3D45BB-2260-4008-88EA-492E7744A9DF}\setup.exe" -l0x9 -removeonly
            Sony Video Shared Library-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}\setup.exe" -l0x40c -removeonly
            Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
            Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
            Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
            Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
            Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
            Update for Outlook 2007 Junk Email Filter (kb975960)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F1AB1BED-7477-4D5A-BD0C-04C2109459A5}
            VAIO Aqua Breeze Wallpaper-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{97BCD719-6ECB-458F-97D6-F38D2E07375E}\setup.exe" -l0x9 -removeonly
            VAIO AV Mode Launcher-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{428A6DA3-FD56-44AE-B602-15DCCD6A7515}\setup.exe" -l0x40c -removeonly
            VAIO Camera Capture Utility-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6D2576EC-A0E9-418A-A09A-409933A3B6F4}\setup.exe" -l0x40c -removeonly
            VAIO Camera Utility-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1417F599-1DBD-4499-9375-B2813E9F890C}\setup.exe" -l0x40c -removeonly
            VAIO Content Importer / VAIO Content Exporter-->C:\Program Files\InstallShield Installation Information\{68A69CFF-130D-4CDE-AB0E-7374ECB144C8}\setup.exe -runfromtemp -l0x040c -removeonly
            VAIO Control Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC37C108-821D-4EDE-8F40-D5B497586805}\setup.exe" -l0x40c -removeonly
            VAIO Cozy Orange Wallpaper-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A2FF7F5-6F0E-4A5D-A881-39365E718BD6}\setup.exe" -l0x9 -removeonly
            VAIO Entertainment Platform-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6B1F20F2-6321-4669-A58C-33DF8E7517FF}\setup.exe" -l0x40c -removeonly
            VAIO Event Service-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}\setup.exe" -l0x40c -removeonly
            VAIO Hardware Diagnostics-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A947C2B3-7445-42C4-9063-EE704CACCB22}\Setup.exe" -l0x40c
            VAIO Media 6.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{560F6B2E-F0DF-44E5-8190-A4A161F0E205}\setup.exe" -l0x40c UNINSTALL -removeonly
            VAIO Media AC3 Decoder 1.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2063C2E8-3812-4BBD-9998-6610F80C1DD4}\Setup.exe" -l0x40c UNINSTALL
            VAIO Media Content Collection 6.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{500162A0-4DD5-460A-BAFD-895AAE48C532}\setup.exe" -l0x40c UNINSTALL -removeonly
            VAIO Media Integrated Server 6.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{785EB1D4-ECEC-4195-99B4-73C47E187721}\setup.exe" -l0x40c UNINSTALL -removeonly
            VAIO Media Redistribution 6.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}\setup.exe" -l0x40c UNINSTALL -removeonly
            VAIO Original Screen Saver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1BEF9285-5530-426B-A5F1-5836B95C7EB1}\Setup.exe" -l0x40c
            VAIO Photo 2007-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5E343EF6-D27C-4CFC-9FAE-9AAFB541BCEE}\setup.exe" -l0x9 -removeonly
            VAIO Power Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E319E96-ED8E-4B01-9775-C521A1869A25}\setup.exe" -l0x40c UNINSTALL -removeonly
            VAIO Tender Green Wallpaper-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{934A3213-1CB6-4264-84A2-EE080C017BCA}\setup.exe" -l0x9 -removeonly
            VAIO Update 4-->"C:\Program Files\InstallShield Installation Information\{83CDA18E-0BF3-4ACA-872C-B4CDABF2360E}\setup.exe" -runfromtemp -l0x040c -removeonly
            VLC media player 0.9.4-->C:\Program Files\VideoLAN\VLC\uninstall.exe
            Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
            Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
            Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
            Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
            Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
            Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
            Windows Live Movie Maker-->MsiExec.exe /X{53B20C18-D8D4-4588-8737-9BBFE303C354}
            Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
            Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
            Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
            WinDVD BD for VAIO-->C:\Program Files\InstallShield Installation Information\{20471B27-D702-4FE8-8DEC-0702CC8C0A85}\setup.exe -runfromtemp -l0x040c
            Wireless Switch Setting Utility-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}\setup.exe" -l0x40c -removeonly
            Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE

            ======Security center information======

            AV: Bitdefender Antivirus
            FW: Bitdefender Firewall (disabled)
            AS: BitDefender AntiSpam
            AS: Windows Defender (disabled)

            ======System event log======

            Computer Name: PC-de-user
            Event Code: 4
            Message: Le filtre de système de fichiers « bdfsfltr » (Version 6.0, 2007-12-31T10:12:12.000Z) n’a pas réussi à s’attacher au volume « \Device\CdRom0 ». Le filtre a renvoyé un état final non standard 0xc0000013. Ce filtre et/ou les applications qui le prennent en charge doivent gérer cette condition. Si cette condition persiste, contactez le fournisseur.
            Record Number: 182061
            Source Name: Microsoft-Windows-FilterManager
            Time Written: 20091001084908.897626-000
            Event Type: Avertissement
            User: PC-de-user\user

            Computer Name: PC-de-user
            Event Code: 1003
            Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir du serveur DHCP) pour la carte réseau dont l'adresse réseau est 001B77739F08. Il s'est produit l'erreur suivante :
            L'opération a été annulée par l'utilisateur.. Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du serveur d'adresse réseau (DHCP).
            Record Number: 182050
            Source Name: Microsoft-Windows-Dhcp-Client
            Time Written: 20091001082319.000000-000
            Event Type: Avertissement
            User:

            Computer Name: PC-de-user
            Event Code: 4
            Message: Le filtre de système de fichiers « bdfsfltr » (Version 6.0, 2007-12-31T10:12:12.000Z) n’a pas réussi à s’attacher au volume « \Device\CdRom0 ». Le filtre a renvoyé un état final non standard 0xc0000013. Ce filtre et/ou les applications qui le prennent en charge doivent gérer cette condition. Si cette condition persiste, contactez le fournisseur.
            Record Number: 182041
            Source Name: Microsoft-Windows-FilterManager
            Time Written: 20091001081535.146626-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            Computer Name: PC-de-user
            Event Code: 7000
            Message: Le service Planificateur LiveUpdate automatique n'a pas pu démarrer en raison de l'erreur :
            Le chemin d'accès spécifié est introuvable.
            Record Number: 181982
            Source Name: Service Control Manager
            Time Written: 20091001081218.000000-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-user
            Event Code: 7000
            Message: Le service Parallel port driver n'a pas pu démarrer en raison de l'erreur :
            Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
            Record Number: 181968
            Source Name: Service Control Manager
            Time Written: 20091001081218.000000-000
            Event Type: Erreur
            User:

            =====Application event log=====

            Computer Name: PC-de-user
            Event Code: 1530
            Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

            DÉTAIL -
            1 user registry handles leaked from \Registry\User\S-1-5-21-465353627-1503491201-1444154407-1003_Classes:
            Process 1068 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-465353627-1503491201-1444154407-1003_CLASSES

            Record Number: 40556
            Source Name: Microsoft-Windows-User Profiles Service
            Time Written: 20090331135200.000000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            Computer Name: PC-de-user
            Event Code: 1530
            Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

            DÉTAIL -
            1 user registry handles leaked from \Registry\User\S-1-5-21-465353627-1503491201-1444154407-1003:
            Process 1068 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-465353627-1503491201-1444154407-1003

            Record Number: 40555
            Source Name: Microsoft-Windows-User Profiles Service
            Time Written: 20090331135159.000000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            Computer Name: PC-de-user
            Event Code: 3
            Message: La configuration du protocole AdminConnection\TCP n'est pas valide dans l'instance SQL VAIO_VEDB.
            Record Number: 40512
            Source Name: SQLBrowser
            Time Written: 20090331130214.000000-000
            Event Type: Avertissement
            User:

            Computer Name: PC-de-user
            Event Code: 1530
            Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

            DÉTAIL -
            1 user registry handles leaked from \Registry\User\S-1-5-21-465353627-1503491201-1444154407-1003_Classes:
            Process 1076 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-465353627-1503491201-1444154407-1003_CLASSES

            Record Number: 40483
            Source Name: Microsoft-Windows-User Profiles Service
            Time Written: 20090330210818.000000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            Computer Name: PC-de-user
            Event Code: 1530
            Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

            DÉTAIL -
            1 user registry handles leaked from \Registry\User\S-1-5-21-465353627-1503491201-1444154407-1003:
            Process 1076 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-465353627-1503491201-1444154407-1003

            Record Number: 40482
            Source Name: Microsoft-Windows-User Profiles Service
            Time Written: 20090330210817.000000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            =====Security event log=====

            Computer Name: PC-de-user
            Event Code: 4672
            Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

            Sujet :
            ID de sécurité : S-1-5-18
            Nom du compte : SYSTEM
            Domaine du compte : AUTORITE NT
            ID d’ouverture de session : 0x3e7

            Privilèges : SeAssignPrimaryTokenPrivilege
            SeTcbPrivilege
            SeSecurityPrivilege
            SeTakeOwnershipPrivilege
            SeLoadDriverPrivilege
            SeBackupPrivilege
            SeRestorePrivilege
            SeDebugPrivilege
            SeAuditPrivilege
            SeSystemEnvironmentPrivilege
            SeImpersonatePrivilege
            Record Number: 47921
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090731221841.429881-000
            Event Type: Succès de l'audit
            User:

            Computer Name: PC-de-user
            Event Code: 4624
            Message: L’ouverture de session d’un compte s’est correctement déroulée.

            Sujet :
            ID de sécurité : S-1-5-18
            Nom du compte : PC-DE-USER$
            Domaine du compte : WORKGROUP
            ID d’ouverture de session : 0x3e7

            Type d’ouverture de session : 5

            Nouvelle ouverture de session :
            ID de sécurité : S-1-5-18
            Nom du compte : SYSTEM
            Domaine du compte : AUTORITE NT
            ID d’ouverture de session : 0x3e7
            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

            Informations sur le processus :
            ID du processus : 0x304
            Nom du processus : C:\Windows\System32\services.exe

            Informations sur le réseau :
            Nom de la station de travail :
            Adresse du réseau source : -
            Port source : -

            Informations détaillées sur l’authentification :
            Processus d’ouverture de session : Advapi
            Package d’authentification : Negotiate
            Services en transit : -
            Nom du package (NTLM uniquement) : -
            Longueur de la clé : 0

            Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

            Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

            Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

            Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

            Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

            Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
            - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
            - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
            - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
            - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
            Record Number: 47920
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090731221841.429881-000
            Event Type: Succès de l'audit
            User:

            Computer Name: PC-de-user
            Event Code: 4648
            Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

            Sujet :
            ID de sécurité : S-1-5-18
            Nom du compte : PC-DE-USER$
            Domaine du compte : WORKGROUP
            ID d’ouverture de session : 0x3e7
            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

            Compte dont les informations d’identification ont été utilisées :
            Nom du compte : SYSTEM
            Domaine du compte : AUTORITE NT
            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

            Serveur cible :
            Nom du serveur cible : localhost
            Informations supplémentaires : localhost

            Informations sur le processus :
            ID du processus : 0x304
            Nom du processus : C:\Windows\System32\services.exe

            Informations sur le réseau :
            Adresse du réseau : -
            Port : -

            Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
            Record Number: 47919
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090731221841.429881-000
            Event Type: Succès de l'audit
            User:

            Computer Name: PC-de-user
            Event Code: 4902
            Message: La table de stratégie d’audit par utilisateur a été créée.

            Nombre d’éléments : 0
            ID de la stratégie : 0x11cd3
            Record Number: 47918
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090731221841.367481-000
            Event Type: Succès de l'audit
            User:

            Computer Name: PC-de-user
            Event Code: 4624
            Message: L’ouverture de session d’un compte s’est correctement déroulée.

            Sujet :
            ID de sécurité : S-1-0-0
            Nom du compte : -
            Domaine du compte : -
            ID d’ouverture de session : 0x0

            Type d’ouverture de session : 0

            Nouvelle ouverture de session :
            ID de sécurité : S-1-5-18
            Nom du compte : SYSTEM
            Domaine du compte : AUTORITE NT
            ID d’ouverture de session : 0x3e7
            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

            Informations sur le processus :
            ID du processus : 0x4
            Nom du processus :

            Informations sur le réseau :
            Nom de la station de travail : -
            Adresse du réseau source : -
            Port source : -

            Informations détaillées sur l’authentification :
            Processus d’ouverture de session : -
            Package d’authentification : -
            Services en transit : -
            Nom du package (NTLM uniquement) : -
            Longueur de la clé : 0

            Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

            Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

            Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

            Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

            Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

            Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
            - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
            - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
            - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
            - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
            Record Number: 47917
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090731221841.211480-000
            Event Type: Succès de l'audit
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Microsoft SQL Server\90\Tools\binn\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\Common Files\Adobe\AGL;C:\Program Files\QuickTime\QTSystem\
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
            "PROCESSOR_ARCHITECTURE"=x86
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "USERNAME"=SYSTEM
            "windir"=%SystemRoot%
            "PROCESSOR_LEVEL"=6
            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 10, GenuineIntel
            "PROCESSOR_REVISION"=0f0a
            "NUMBER_OF_PROCESSORS"=2
            "configsetroot"=%SystemRoot%\ConfigSetRoot
            "RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
            "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
            "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

            -----------------EOF-----------------
            0
            1. Contributeur sécurité
              ( C:\RSIT\log.txt et C:\RSIT\info.txt )
              0
              1. sa y'est c fait merci encore de m'aider
                0
                1. Contributeur sécurité
                  ba dite donc tu en as des infections, infections search settings infections usb ......

                  ▶ Télécharge UsbFix et enregistre-le sur ton bureau

                  ▶ tutoriel recherche

                  ▶ Double-clique sur UsbFix présent sur ton bureau, l'installation se fera automatiquement

                  ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                  ▶ Choisi l'option 1 (recherche)

                  ▶ Laisse travailler l'outil

                  ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra

                  * Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

                  * Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

                  * Note : "SniffC.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                  Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                  Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                  0
                  1. ############################## | UsbFix V6.067 |

                    User : user (Administrateurs) # PC-DE-USER
                    Update on 24/12/2009 by Chiquitine29, C_XX & Chimay8
                    Start at: 23:24:59 | 27/12/2009
                    Website : http://pagesperso-orange.fr/NosTools/index.html
                    Contact : FindyKill.Contact@gmail.com

                    Intel(R) Core(TM)2 Duo CPU T7300 @ 2.00GHz
                    Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                    Internet Explorer 7.0.6002.18005
                    Windows Firewall Status : Enabled
                    AV : Bitdefender Antivirus 8.0 [ Enabled | Updated ]
                    FW : Bitdefender Firewall[ (!) Disabled ]8.0

                    C:\ -> Disque fixe local # 176,53 Go (56,09 Go free) # NTFS
                    D:\ -> Disque amovible
                    E:\ -> Disque amovible
                    F:\ -> Disque CD-ROM
                    G:\ -> Disque amovible # 976,23 Mo (898,52 Mo free) # FAT
                    H:\ -> Disque amovible # 249,72 Mo (79,71 Mo free) # FAT

                    ############################## | Processus actifs |

                    C:\Windows\System32\smss.exe 404
                    C:\Windows\system32\csrss.exe 672
                    C:\Windows\system32\wininit.exe 724
                    C:\Windows\system32\csrss.exe 736
                    C:\Windows\system32\services.exe 772
                    C:\Windows\system32\lsass.exe 804
                    C:\Windows\system32\lsm.exe 816
                    C:\Windows\system32\winlogon.exe 840
                    C:\Windows\system32\svchost.exe 976
                    C:\Windows\system32\svchost.exe 1036
                    C:\Windows\System32\svchost.exe 1072
                    C:\Windows\System32\svchost.exe 1160
                    C:\Windows\System32\svchost.exe 1204
                    C:\Windows\system32\svchost.exe 1216
                    C:\Windows\system32\SLsvc.exe 1376
                    C:\Windows\system32\svchost.exe 1416
                    C:\Windows\system32\svchost.exe 1600
                    C:\Windows\System32\spoolsv.exe 1908
                    C:\Windows\system32\svchost.exe 1936
                    C:\Windows\system32\taskeng.exe 1960
                    C:\Windows\system32\taskeng.exe 292
                    C:\Windows\system32\Dwm.exe 508
                    C:\Windows\Explorer.EXE 676
                    C:\Program Files\Windows Defender\MSASCui.exe 1720
                    C:\Program Files\Apoint\Apoint.exe 1848
                    C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe 1020
                    C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe 1716
                    C:\Program Files\sony\VAIO Camera Utility\VCUServe.exe 1520
                    C:\Program Files\sony\ISB Utility\ISBMgr.exe 1304
                    C:\Windows\System32\rundll32.exe 1820
                    C:\Windows\System32\rundll32.exe 1952
                    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe 768
                    C:\Program Files\Java\jre6\bin\jusched.exe 2128
                    C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe 2164
                    C:\Program Files\iTunes\iTunesHelper.exe 2248
                    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 2424
                    C:\Program Files\Bonjour\mDNSResponder.exe 2444
                    C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe 2496
                    C:\Program Files\Common Files\LightScribe\LSSrvc.exe 2516
                    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe 2604
                    C:\Program Files\Windows Sidebar\sidebar.exe 2656
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe 2680
                    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe 2724
                    C:\Users\user\Program Files\DNA\btdna.exe 2732
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe 2752
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe 2800
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe 2824
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe 2900
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe 3000
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe 3364
                    C:\Windows\system32\svchost.exe 3548
                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 3560
                    C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe 3612
                    C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe 3632
                    C:\Windows\system32\stacsv.exe 3644
                    C:\Windows\system32\svchost.exe 3712
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe 3832
                    C:\Program Files\sony\VAIO Event Service\VESMgr.exe 3880
                    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe 4092
                    C:\Windows\System32\svchost.exe 1408
                    C:\Program Files\sony\VAIO Event Service\VESMgrSub.exe 1280
                    C:\Windows\system32\SearchIndexer.exe 2324
                    C:\Windows\system32\WUDFHost.exe 1612
                    C:\Windows\system32\DRIVERS\xaudio.exe 1976
                    C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe 2968
                    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe 1808
                    C:\Program Files\Sony\VAIO Power Management\SPMgr.exe 3904
                    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe 2108
                    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe 3540
                    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe 3168
                    C:\Program Files\iPod\bin\iPodService.exe 4412
                    C:\Windows\System32\svchost.exe 4572
                    C:\Program Files\Apoint\ApMsgFwd.exe 5264
                    C:\Windows\system32\taskeng.exe 5364
                    C:\Program Files\Apoint\Apntex.exe 5588
                    C:\Windows\system32\conime.exe 5616
                    C:\Windows\system32\vssvc.exe 5220
                    C:\Windows\System32\svchost.exe 5580
                    C:\Program Files\Mozilla Firefox\firefox.exe 5664
                    C:\Program Files\Windows Live\Contacts\wlcomm.exe 5396
                    C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe 5540
                    C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe 5060
                    C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe 4872
                    C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe 5748
                    C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe 3992
                    C:\Users\user\AppData\Local\Google\Chrome\Application\chrome.exe 448
                    \\?\C:\Windows\system32\wbem\WMIADAP.EXE 4120
                    C:\Windows\system32\wbem\wmiprvse.exe 5128
                    C:\Windows\system32\wbem\wmiprvse.exe 5832

                    ################## | Elements infectieux |

                    C:\Windows\msa.exe
                    C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
                    C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
                    C:\Windows\System32\sshnas.dll
                    C:\Users\user\AppData\Local\Temp\301.exe
                    C:\Users\user\AppData\Local\Temp\524.exe
                    C:\Users\user\AppData\Local\Temp\651.exe
                    C:\Users\user\AppData\Local\Temp\913.exe
                    C:\Users\user\AppData\Local\Temp\a.dat
                    G:\sys\Bo3afash.exe
                    G:\sys
                    H:\Recycler\S-1-5-21-1482476501-1644491937-682003330-1013\svchost.exe
                    H:\Recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
                    H:\Recycler\S-1-5-21-1482476501-1644491937-682003330-1013

                    ################## | Registre |

                    [HKCU\SOFTWARE\J8RPLTROBQ]
                    [HKCU\SOFTWARE\XML]
                    [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "J8RPLTROBQ"

                    ################## | Mountpoints2 |

                    HKCU\..\..\Explorer\MountPoints2\H
                    shell\AutoRun\command =H:\Autorun.exe

                    HKCU\..\..\Explorer\MountPoints2\{7565e02f-3c6a-11de-9c9b-001bfb18e5cd}
                    shell\AutoRun\command =G:\EmDesk.exe
                    shell\EmDesk\command =G:\EmDesk.exe

                    HKCU\..\..\Explorer\MountPoints2\{c7399f66-c97d-11dd-ac76-001bfb18e5cd}
                    shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs

                    HKCU\..\..\Explorer\MountPoints2\{e48762ec-cc6e-11de-8774-001bfb18e5cd}
                    shell\AutoRun\command =H:\PMB_P.exe

                    ################## | Cracks / Keygens / Serials |

                    ################## | ! Fin du rapport # UsbFix V6.067 ! |
                    0
                    1. Contributeur sécurité
                      ▶ tutoriel nettoyage

                      ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

                      ▶ Double clic sur le raccourci UsbFix présent sur ton bureau

                      ▶ choisi l'option 2 ( Suppression )

                      ▶ Ton bureau disparaîtra et le pc redémarrera .

                      ▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

                      ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .

                      ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                      ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                      0
                      1. ############################## | UsbFix V6.067 |

                        User : user (Administrateurs) # PC-DE-USER
                        Update on 24/12/2009 by Chiquitine29, C_XX & Chimay8
                        Start at: 23:44:15 | 27/12/2009
                        Website : http://pagesperso-orange.fr/NosTools/index.html
                        Contact : FindyKill.Contact@gmail.com

                        Intel(R) Core(TM)2 Duo CPU T7300 @ 2.00GHz
                        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                        Internet Explorer 7.0.6002.18005
                        Windows Firewall Status : Enabled
                        AV : Bitdefender Antivirus 8.0 [ Enabled | Updated ]
                        FW : Bitdefender Firewall[ (!) Disabled ]8.0

                        C:\ -> Disque fixe local # 176,53 Go (55,89 Go free) # NTFS
                        D:\ -> Disque amovible
                        E:\ -> Disque amovible
                        F:\ -> Disque CD-ROM
                        G:\ -> Disque amovible # 976,23 Mo (898,52 Mo free) # FAT
                        H:\ -> Disque amovible # 249,72 Mo (79,71 Mo free) # FAT

                        ############################## | Processus actifs |

                        C:\Windows\System32\smss.exe 420
                        C:\Windows\system32\csrss.exe 680
                        C:\Windows\system32\wininit.exe 732
                        C:\Windows\system32\csrss.exe 744
                        C:\Windows\system32\services.exe 780
                        C:\Windows\system32\winlogon.exe 808
                        C:\Windows\system32\lsass.exe 824
                        C:\Windows\system32\lsm.exe 836
                        C:\Windows\system32\svchost.exe 1012
                        C:\Windows\system32\svchost.exe 1072
                        C:\Windows\System32\svchost.exe 1112
                        C:\Windows\System32\svchost.exe 1200
                        C:\Windows\System32\svchost.exe 1244
                        C:\Windows\system32\svchost.exe 1256
                        C:\Windows\system32\SLsvc.exe 1412
                        C:\Windows\system32\svchost.exe 1444
                        C:\Windows\system32\svchost.exe 1604
                        C:\Windows\System32\spoolsv.exe 1928
                        C:\Windows\system32\svchost.exe 1972
                        C:\Windows\system32\taskeng.exe 2028
                        C:\Windows\system32\Dwm.exe 272
                        C:\Windows\Explorer.EXE 1004
                        C:\Windows\msa.exe 1252
                        C:\Windows\system32\taskeng.exe 1344
                        C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe 456
                        C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe 900
                        C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe 776
                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1864
                        C:\Program Files\Bonjour\mDNSResponder.exe 2060
                        C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe 2088
                        C:\Program Files\Common Files\LightScribe\LSSrvc.exe 2100
                        C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe 2176
                        C:\Windows\system32\svchost.exe 2252
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2272
                        C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe 2304
                        C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe 2324
                        C:\Windows\system32\stacsv.exe 2348
                        C:\Windows\system32\svchost.exe 2388
                        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe 2444
                        C:\Program Files\sony\VAIO Event Service\VESMgr.exe 2472
                        C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe 2500
                        C:\Windows\System32\svchost.exe 2732
                        C:\Windows\system32\SearchIndexer.exe 2772
                        C:\Windows\system32\DRIVERS\xaudio.exe 2816
                        C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe 2840
                        C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe 2932
                        C:\Windows\system32\WUDFHost.exe 2972
                        C:\Program Files\sony\VAIO Event Service\VESMgrSub.exe 3012
                        C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe 3020
                        C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe 3224
                        C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe 3264
                        C:\Windows\system32\PresentationSettings.exe 3436
                        C:\Program Files\Sony\VAIO Power Management\SPMgr.exe 3592
                        C:\Windows\System32\svchost.exe 3840
                        C:\Windows\system32\runonce.exe 3868
                        C:\Windows\system32\wbem\wmiprvse.exe 3892
                        C:\Windows\system32\conime.exe 3980

                        ################## | Elements infectieux |

                        Supprimé ! C:\Windows\msa.exe
                        Supprimé ! C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
                        Supprimé ! C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
                        Supprimé ! C:\Windows\System32\sshnas.dll
                        Non supprimé ! C:\Users\user\AppData\Local\Temp\301.exe
                        Supprimé ! C:\Users\user\AppData\Local\Temp\524.exe
                        Supprimé ! C:\Users\user\AppData\Local\Temp\651.exe
                        Supprimé ! C:\Users\user\AppData\Local\Temp\913.exe
                        Supprimé ! C:\Users\user\AppData\Local\Temp\a.dat
                        Supprimé ! C:\$Recycle.Bin\S-1-5-21-1228114898-1538922252-1431714860-500
                        Supprimé ! C:\$Recycle.Bin\S-1-5-21-2152478756-3922319563-605102323-500
                        Supprimé ! C:\$Recycle.Bin\S-1-5-21-2854422249-2929167621-1805498232-500
                        Supprimé ! C:\$Recycle.Bin\S-1-5-21-3919008197-636760245-3409343362-500
                        Supprimé ! C:\$Recycle.Bin\S-1-5-21-465353627-1503491201-1444154407-1003
                        Supprimé ! C:\Recycler\S-1-5-21-3935116140-9518244973-224092041-1492
                        Supprimé ! C:\Recycler\S-1-5-21-4432401802-0549390404-828885915-2676
                        Supprimé ! G:\sys\Bo3afash.exe
                        Supprimé ! G:\sys
                        Supprimé ! H:\Recycler\S-1-5-21-1482476501-1644491937-682003330-1013\svchost.exe
                        Supprimé ! H:\Recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
                        Supprimé ! H:\Recycler\S-1-5-21-1482476501-1644491937-682003330-1013

                        ################## | Registre |

                        Supprimé ! [HKCU\SOFTWARE\J8RPLTROBQ]
                        Supprimé ! [HKCU\SOFTWARE\XML]
                        Supprimé ! [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "J8RPLTROBQ"

                        ################## | Mountpoints2 |

                        Supprimé ! HKCU\...\Explorer\MountPoints2\H\Shell\AutoRun\Command
                        Supprimé ! HKCU\...\Explorer\MountPoints2\{7565e02f-3c6a-11de-9c9b-001bfb18e5cd}\Shell\AutoRun\Command
                        Supprimé ! HKCU\...\Explorer\MountPoints2\{c7399f66-c97d-11dd-ac76-001bfb18e5cd}\Shell\AutoRun\Command
                        Supprimé ! HKCU\...\Explorer\MountPoints2\{e48762ec-cc6e-11de-8774-001bfb18e5cd}\Shell\AutoRun\Command

                        ################## | Listing des fichiers présent |

                        [18/09/2006 22:43|--a------|24] C:\autoexec.bat
                        [11/04/2009 07:36|-rahs----|333257] C:\bootmgr
                        [28/04/2007 19:01|-ra-s----|8192] C:\BOOTSECT.BAK
                        [18/09/2006 22:43|--a------|10] C:\config.sys
                        [?|?|?] C:\hiberfil.sys
                        [28/04/2007 11:25|-rahs----|0] C:\IO.SYS
                        [28/04/2007 11:25|-rahs----|0] C:\MSDOS.SYS
                        [?|?|?] C:\pagefile.sys
                        [27/12/2009 23:52|--a------|6140] C:\UsbFix.txt
                        [22/06/2007 09:34|--a------|390416] C:\vcredist_x86.log
                        [05/12/2009 23:38|--a------|278540] G:\CV Logistique Quach Laurent.pdf
                        [21/01/2009 16:06|--a------|2404352] H:\Norton_Removal_Tool.exe
                        [21/04/2009 17:14|--a------|16384] H:\2.wps
                        [09/10/2007 22:58|--a------|1796608] H:\MONNAIEI.doc
                        [20/12/2007 00:08|--a------|2402832] H:\WLinstaller.exe
                        [30/11/2008 20:42|--a------|3146240] H:\exposé_id.. version 4.doc
                        [06/04/2009 10:46|--a------|810752] H:\Rapport de stage Laurent.docx
                        [18/11/2009 00:33|--a------|278478] H:\CV Marketing Quach Laurent.pdf
                        [04/04/2009 23:06|--a------|277746] H:\CAS1_0809.pdf
                        [13/03/2009 09:56|--a------|810570] H:\Rapport de stage Laurent version final.docx
                        [23/03/2009 00:05|--a------|31232] H:\LaurentQuachCV.doc
                        [04/04/2009 23:05|--a------|198249] H:\CAS2_2009.pdf
                        [12/05/2009 20:38|--a------|152064] H:\Dissertation sur la mondialisation version final de chez final word 2003.doc
                        [12/05/2009 16:48|--a------|118735] H:\Dissertation sur la mondialisation version final de chez final.docx
                        [12/05/2009 13:21|--a------|151156] H:\DOSS_MARKETING_M2_2009-2010.pdf
                        [12/05/2009 17:27|--a------|14165] H:\Quach Laurent lettre de motivation pour iae de dijon.docx
                        [22/05/2009 11:38|--ah-----|4096] H:\._.Trashes
                        [12/06/2009 00:04|--a------|13090] H:\lettre msi.docx
                        [12/06/2009 00:19|--a------|13281] H:\Lettre logistique.docx
                        [22/05/2009 12:10|--a------|24576] H:\lettre recommandation anglais.doc
                        [22/05/2009 12:10|--ah-----|4096] H:\._lettre recommandation anglais.doc
                        [12/06/2009 00:07|--a------|13761] H:\lettre marketing.docx
                        [12/06/2009 00:06|--a------|12889] H:\lettre innovation technologie.docx
                        [28/08/2009 12:09|--a------|446022] H:\Scn passeport de lolo.jpg
                        [18/10/2008 13:42|--a------|8372312] H:\Hironobu Kageyama - DBZ Hit Song Collection 13 - 'Battle & Hope' - 03 - Unmei no Hi ~Tamashii vs Tamashii~.mp3
                        [16/12/2007 20:30|--a------|18500624] H:\setupeng.exe
                        [16/12/2007 21:25|--a------|14991176] H:\avast_avast_4.7.1001_francais_anglais_11113.exe
                        [16/12/2007 21:54|--a------|17788920] H:\antivir-personal-edition-7_antivir_personal_edition_classic_7_7.06.00.270_anglais_10821.exe
                        [02/03/2008 22:45|--a------|37376] H:\AnthonyQuachCV.doc
                        [27/02/2008 16:08|--a------|11832] H:\Photo 020.jpg
                        [02/03/2008 22:45|--a------|37376] H:\AnthonyQuach CV.doc
                        [06/03/2008 19:53|--a------|30208] H:\AnthonyQuach Lettre de motivation.doc

                        ################## | Vaccination |

                        # C:\autorun.inf -> Dossier créé par UsbFix.
                        # G:\autorun.inf -> Dossier créé par UsbFix.
                        # H:\autorun.inf -> Dossier créé par UsbFix.

                        ################## | Cracks / Keygens / Serials |

                        ################## | Upload |

                        Veuillez envoyer le fichier : C:\Users\user\Desktop\UsbFix_Upload_Me_PC-de-user.zip : https://www.ionos.fr/?affiliate_id=77097
                        Merci pour votre contribution .
                        0
                        1. voila c fait et ensuite je fait koi
                          0
                          1. Contributeur sécurité
                            Pour demain car je vais me coucher il est tard :

                            ▶ Télécharge Toolbar-S&D (de Team IDN) sur ton Bureau

                            ▶ Lance l'installation du programme en exécutant le fichier téléchargé.

                            ▶ Sous XP : Double-clique sur le raccourci de Toolbar-S&D.

                            ▶ Sous Vista : Fais un clic droit sur ToolbarSD et sélectionne "Exécuter en tant qu'administrateur".

                            ▶ Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.

                            ▶ Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.

                            ▶ Poste le rapport généré. (C:\TB.txt)
                            0
                            1. -----------\\ ToolBar S&D 1.2.9 XP/Vista

                              Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
                              X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T7300 @ 2.00GHz )
                              BIOS : Ver 1.00PARTTBL
                              USER : user ( Administrator )
                              BOOT : Normal boot
                              Antivirus : Bitdefender Antivirus 8.0 (Activated)
                              Firewall : Bitdefender Firewall 8.0 (Not Activated)
                              C:\ (Local Disk) - NTFS - Total:176 Go (Free:55 Go)
                              D:\ (USB)
                              E:\ (USB)
                              F:\ (CD or DVD)
                              G:\ (USB) - FAT - Total:976 Mo (Free:0 Go)
                              H:\ (USB) - FAT - Total:249 Mo (Free:0 Go)

                              "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                              Option : [1] ( 28/12/2009| 9:56 )

                              [ UAC => 1 ]

                              -----------\\ Recherche de Fichiers / Dossiers ...

                              C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
                              C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\CONTENT\searchsettingsplugin.js
                              C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\CONTENT\searchsettingsplugin.xul
                              C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\LOCALE\EN-US\searchsettingsplugin.dtd
                              C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\CHROME\LOCALE\EN-US\searchsettingsplugin.properties
                              C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com\COMPONENTS\SearchSettingsFF.dll
                              C:\Program Files\Search Settings
                              C:\Program Files\Search Settings\kb128
                              C:\Program Files\Search Settings\SearchSettings.exe
                              C:\Program Files\Search Settings\kb128\res
                              C:\Program Files\Search Settings\kb128\SearchSettings.dll
                              C:\Program Files\Search Settings\kb128\SearchSettingsRes409.dll
                              C:\Program Files\Search Settings\kb128\temp

                              -----------\\ [..\Internet Explorer\Main]

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                              "Local Page"="C:\\Windows\\system32\\blank.htm"
                              "Search Page"="https://actus.sfr.fr"
                              "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                              "Search Bar"="https://actus.sfr.fr"
                              "Url"="https://www.msn.com/fr-fr/actualite/"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                              "Start Page"="https://www.msn.com/fr-fr"
                              "Default_Page_URL"="http://www.club-vaio.com"
                              "Default_Search_URL"="https://actus.sfr.fr"
                              "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                              --------------------\\ Recherche d'autres infections

                              --------------------\\ Cracks & Keygens ..

                              C:\Users\user\Desktop\Laurent\Musique\Musique Hip Hop\Eminem-Relapse CD-2009\18-Crack A Bottle (Feat. Dr. Dre & 50 Cent.mp3
                              C:\Users\user\Music\iTunes\Mobile Applications\CrackCode.ipa

                              [ UAC => 1 ]

                              1 - "C:\ToolBar SD\TB_1.txt" - 28/12/2009|14:13 - Option : [1]

                              -----------\\ Fin du rapport a 14:13:51,11
                              0
                              1. Contributeur sécurité
                                ▶ Relance Toolbar-S&D.

                                ▶ Tape sur "2" puis valide en appuyant sur "Entrée".

                                /!\ Ne ferme pas la fenêtre lors de la suppression /!\

                                ▶ Un rapport sera généré, poste son contenu ici.

                                NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
                                Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
                                Tape explorer puis valide.

                                Ce qu'il faut savoir sur les toolbars (barres d'outils)
                                0
                                1. -----------\\ ToolBar S&D 1.2.9 XP/Vista

                                  Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
                                  X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T7300 @ 2.00GHz )
                                  BIOS : Ver 1.00PARTTBL
                                  USER : user ( Administrator )
                                  BOOT : Normal boot
                                  Antivirus : Bitdefender Antivirus 8.0 (Activated)
                                  Firewall : Bitdefender Firewall 8.0 (Not Activated)
                                  C:\ (Local Disk) - NTFS - Total:176 Go (Free:53 Go)
                                  D:\ (USB)
                                  E:\ (USB)
                                  F:\ (CD or DVD)

                                  "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                                  Option : [2] ( 29/12/2009|13:37 )

                                  [ UAC => 1 ]

                                  -----------\\ Recherche de Fichiers / Dossiers ...

                                  -----------\\ [..\Internet Explorer\Main]

                                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                  "Local Page"="C:\\Windows\\system32\\blank.htm"
                                  "Search Page"="https://actus.sfr.fr"
                                  "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                                  "Search Bar"="https://actus.sfr.fr"
                                  "Url"="http://go.microsoft.com/fwlink/?LinkId=75720"

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                  "Start Page"="https://www.msn.com/fr-fr/"
                                  "Default_Page_URL"="http://www.club-vaio.com"
                                  "Default_Search_URL"="https://actus.sfr.fr"
                                  "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"

                                  --------------------\\ Recherche d'autres infections

                                  --------------------\\ Cracks & Keygens ..

                                  C:\Users\user\Desktop\Laurent\Musique\Musique Hip Hop\Eminem-Relapse CD-2009\18-Crack A Bottle (Feat. Dr. Dre & 50 Cent.mp3
                                  C:\Users\user\Music\iTunes\Mobile Applications\CrackCode.ipa

                                  [ UAC => 1 ]

                                  1 - "C:\ToolBar SD\TB_1.txt" - 28/12/2009|14:13 - Option : [1]
                                  2 - "C:\ToolBar SD\TB_2.txt" - 29/12/2009|16:48 - Option : [2]

                                  -----------\\ Fin du rapport a 16:48:57,75
                                  0
                                  1. Contributeur sécurité
                                    c'est bizarre à l'option 2 il n'y a pas de suppression tu peux me refaire l'option 1 STP.
                                    0
                                    1. salut a chaque fois que je fait une analyse avec toolbar ya l'utilitaire qgrep qui cesse de fonctionner et sa me fait ça tout au long du scan et je prend 4h pour faire un rapport
                                      0
                                      1. Contributeur sécurité
                                        Fait moi ceci alors :

                                        * Sous Vista : ▶ Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                                        * Clique sur Démarrer puis sur panneau de configuration
                                        * Double Clique sur l'icône "Comptes d'utilisateurs"
                                        * Clique ensuite sur désactiver et valide.
                                        * Redémarre le PC

                                        ▶ Rends-toi à cette adresse afin de télécharger AD-Remover (créé par C_XX) : https://www.androidworld.fr/

                                        ▶ Clique sur TÉLÉCHARGER et enregistre-le sur ton bureau.

                                        ▶ tutoriel installation

                                        ▶ Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( le bureau )

                                        ▶ Ouvre le dossier Ad-remover présent sur ton bureau

                                        ▶ Double clique sur Ad-remover.bat.

                                        * Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"

                                        ▶ Au menu principal choisi l'option "L" et tape sur [entrée] .

                                        ▶ Laisse travailler l'outil et ne touche à rien ...

                                        ▶ Poste le rapport qui apparait à la fin.

                                        ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

                                        (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                        Note :

                                        Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.


                                        0
                                        1. .
                                          ======= RAPPORT D'AD-REMOVER 1.1.4.6_F | UNIQUEMENT XP/VISTA/7 =======
                                          .
                                          Mit à jour par C_XX le 26.12.2009 à 20:47
                                          Contact: AdRemover.contact@gmail.com
                                          Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                                          .
                                          Lancé à: 10:47:40, 01/01/2010 | Mode Normal | Option: CLEAN
                                          Exécuté de: C:\Program Files\Ad-Remover\
                                          Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 2 v6.0.6002
                                          Nom du PC: PC-DE-USER | Utilisateur actuel: user

                                          Bonnes fêtes de fin d'année à vous tous :)
                                          .
                                          ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                                          .

                                          C:\Program Files\Mozilla FireFox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
                                          C:\Program Files\Dealio Toolbar
                                          C:\Users\user\AppData\LocalLow\Dealio
                                          C:\Users\user\AppData\LocalLow\Search Settings
                                          C:\Windows\Installer\d7cb23.msi
                                          C:\Windows\Installer\d7cb29.msi

                                          (!) -- Fichiers temporaires supprimés.

                                          .
                                          HKCU\software\appdatalow\software\Dealio
                                          HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
                                          HKLM\Software\Classes\CLSID\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
                                          HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                                          HKLM\software\classes\installer\Features\A3BB3C491A65ED342A24B8144FE679FE
                                          HKLM\software\classes\installer\Products\79CAA1B036589D14EA74856E2A220F1E
                                          HKLM\software\classes\installer\Products\A3BB3C491A65ED342A24B8144FE679FE
                                          HKLM\Software\Classes\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}
                                          HKLM\software\classes\SearchSettings.BHO
                                          HKLM\software\classes\SearchSettings.BHO.1
                                          HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
                                          HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
                                          HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
                                          HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0292226F570267D459357AF78015E534
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\03285961954D5824C85975D955031EE8
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\23A03A6765D10864EB278629A2DF32C3
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\323D2420527EA994FB326F15D333660E
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\33E6E75CE56376F40AF9234753739ADB
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\3A4FCCE032CA50340A6975C92410AE30
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\588DFA161592E9747948BFFE475476F4
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6AC3985F4D64C2245A96D31569D1BF40
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6E00D9B24354FBA44AE2CA0FA86EF2E2
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\7C13F41728A69EF41AA1A3372FB86FA6
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\855847FA0E25FBA46B8516389DFDD4B3
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\8ED411B7A244E0E4C82C46284CA65B81
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\94E65EF7E080DDA4AA2F1DEDCE74AC5B
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9DC2844D0E3E8924C8973C3B3BAE1F58
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\AFEB575AA30ACB243B748619F62F0782
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\B072F84D5AF1BB34C980E01F5689D864
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\B92A2929968AED344BD6B34AD60E6604
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\BB1E992117B1B0B42BD2CDAEB8E749C4
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\C7D9132F42224AC49BD8C06A0F8E39C4
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\DA6F069968D91A540A1363E997581959
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\DBC7F2B5594E08A4C87EF4C22971C615
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F461B8DD96FF5AA41A52D14E1D7B69C7
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\79CAA1B036589D14EA74856E2A220F1E
                                          HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\A3BB3C491A65ED342A24B8144FE679FE
                                          .
                                          ============== Scan additionnel ==============
                                          .
                                          .
                                          * Mozilla FireFox Version 3.0.16 [fr] *
                                          .
                                          Nom du profil: 8ntocf6b.default (user)
                                          .
                                          (user, prefs.js) Browser.download.dir, C:\Users\user\Downloads
                                          (user, prefs.js) Browser.download.lastDir, C:\Users\user\Desktop\Laurent\PHOTO laurent\Jeux video
                                          (user, prefs.js) Browser.search.defaultenginename, Yahoo
                                          (user, prefs.js) Browser.startup.homepage, hxxp://www.google.fr/
                                          (user, prefs.js) Extensions.enabledItems, {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}:4.0.1,{d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1,{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.16
                                          (user, prefs.js) Keyword.URL, hxxp://fr.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=
                                          .
                                          .
                                          .
                                          * Internet Explorer Version 7.0.6002.18005 *
                                          .
                                          [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                                          .
                                          Do404Search: 01000000
                                          Local Page: C:\Windows\system32\blank.htm
                                          Show_ToolBar: yes
                                          Enable Browser Extensions: yes
                                          Start Page: hxxp://fr.msn.com/
                                          Use Search Asst: no
                                          Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                                          Use Custom Search URL: 1 (0x1)
                                          Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                          Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                          .
                                          [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                                          .
                                          Start Page: hxxp://fr.msn.com/
                                          Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                          Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                          Delete_Temp_Files_On_Exit: yes
                                          Local Page: %SystemRoot%\system32\blank.htm
                                          Search bar: hxxp://search.msn.com/spbasic.htm
                                          .
                                          [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                                          .
                                          Tabs: res://ieframe.dll/tabswelcome.htm
                                          .
                                          ============== Suspect (Cracks, Serials, ...) ==============
                                          .
                                          C:\Users\user\AppData\Roaming\BitTorrent\GTA_Chinatown_Wars_Patcher.torrent
                                          .
                                          ===================================
                                          .
                                          7024 Octet(s) - C:\Ad-Report-CLEAN[1].log
                                          .
                                          0 Fichier(s) - C:\Users\user\AppData\Local\Temp
                                          2 Fichier(s) - C:\Windows\Temp
                                          4 Fichier(s) - C:\Windows\Prefetch
                                          .
                                          20 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
                                          87 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
                                          .
                                          Fin à: 11:02:10 | 01/01/2010 - CLEAN[1]
                                          .
                                          ============== E.O.F ==============
                                          .
                                          0
                                          • 1
                                          • 2