Cheval de Troie Cliker.AEYB

Résolu
Bonsoir à tous,

Voila je viens vers vous un peu désespéré...

J'ai eu plusieurs problèmes d'un coup avec mon PC, j'ai pu en résoudre grâce à votre forum (merci au passage), mais la, j'en bave.

AVG me signale une alerte d'un cheval de Troie nommé Clicker.AEYB. caché dans les fichiers temp.

Il ne peut pas le supprimer, et j'ai bien éssayer d'autres antivirus et autres programmes mais rien y fait...

Je ne suis pas un spécialiste, mais je suis évidemment à votre écoute pour essayer de résoudre ce léger chantier...

Merci par avance.
Configuration: Windows Vista Internet Explorer 7.0

30 réponses

Résumé de la discussion

Le problème décrit est une alerte de cheval de Troie Clicker.AEYB détectée par AVG dans des fichiers temporaires sous Windows Vista et Internet Explorer 7, que le logiciel de sécurité ne parvient pas à supprimer. Plusieurs solutions proposées incluent RSIT, HijackThis, AD-Remover, USBFix, Malwarebytes et OTMoveIt, avec des instructions pour générer des rapports et partager les résultats afin d'orienter le processus de désinfection. En cas de persistance, certaines procédures recommandent temporairement de désactiver l'UAC et la restauration système pour purger les éléments restants, d'où la nécessité d'un redémarrage et d'une réactivation ultérieure.

Bobot (l’IA à votre service)
  1. bien,c'est la misère !

    arrête le scan d'avg,
    lance ceci :

    • Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.
    http://images.malwareremoval.com/random/RSIT.exe

    Tuto : https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
    Double clique sur RSIT.exe pour lancer l'outil.
    Clique sur ' continue ' à l'écran Disclaimer.
    Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
    Une fois le scan fini, 2 rapports vont apparaître. Poste le contenu des 2 rapports séparément. Ils se trouvent sur c :
    (log.txt & info.txt)
    (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
    2
    1. Je vais essayé de relancer un scan d'avg, mais un autre problème (que je suis entrain de résoudre) ne lui laisse pas le temps de finir son analyse.

      Malheureusement Ma42T, il y a bien des trucs que je veux garder, et je n'ai ni sauvegarder mon PC lors de sa première utilisation, et, miracle de la technologie, je n'ai pas de Cd d'installation de Windows...

      (Je sais, je cumule... :s).

      Croisons les doigts pour l'analyse...
      1
      1. bien,dans l'ordre :

        • /!\ Utilisateur de Vista : Ne pas oublier de désactiver l’UAC juste le temps de désinfection de ton pc, il sera à réactiver plus tard :
        Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

        Télécharge de AD-Remover sur ton Bureau. (Merci à Cyrildu17 / C_XX)
        http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

        Miroir:

        https://www.androidworld.fr/

        /!\ Déconnecte-toi d’internet et ferme toutes applications en cours /!\

        - Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
        - Double-clique sur l'icône Ad-remover située sur ton Bureau.
        /!\Utilisateur de Vista : Clique droit sur le logo de AD-Remover, « exécuter en tant qu’Administrateur »
        - Au menu principal, choisis l'option « L ».
        - Laisse travailler l’outil.

        - Poste le rapport qui apparaît à la fin.

        (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)

        (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

        Note :
        "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.

        Tuto : http://pagesperso-orange.fr/NosTools/tuto_adr_3.html

        • /!\ Utilisateur de vista et windows 7 : ne pas oublier de désactiver Le contrôle des comptes utilisateurs
        https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

        Télécharge USBFIX sur ton bureau
        http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
        ou ici :
        https://www.ionos.fr/?affiliate_id=77097

        /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

        • Double clic sur le raccourci UsbFix présent sur ton bureau .
        /!\Utilisateur de Vista et windows 7 : Clique droit sur le logo de USBFIX, « exécuter en tant qu’Administrateur »

        • Choisis l'option 2

        • Laisse travailler l'outil.


        • Ensuite post le rapport UsbFix.txt qui apparaîtra.

        • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

        ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

        • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.

        • /!\ Utilisateur de Vista : Ne pas oublier de désactiver l’UAC juste le temps de désinfection de ton pc, il sera à réactiver plus tard :
        Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

        Télécharge Malwarebytes' Anti-Malware et enregistre le sur ton bureau:
        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

        ou ici : http://www.malwarebytes.org/mbam/program/mbam-setup.exe

        /!\Utilisateur de Vista : Clique droit sur le logo de Malwarebytes' Anti-Malware, « exécuter en tant qu’Administrateur »

        . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
        . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
        . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
        . Une fois la mise à jour terminé
        . rend-toi dans l'onglet, Recherche
        . Sélectionnes Exécuter un examen complet
        . Cliques sur Rechercher
        . Le scan démarre.
        . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
        . Cliques sur Ok pour poursuivre.
        . Si des malwares ont été détectés, cliques sur Afficher les résultats
        . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine
        .
        . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
        . rends toi dans l'onglet rapport/log
        . tu cliques dessus pour l'afficher une fois affiché
        . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
        . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
        . Tu cliques droit dans le cadre de la réponse et coller
        . À la fin du scan, il se peut que MBAM ait besoin de redémarrer le pc pour finaliser la suppression, donc pas de panique, redémarre ton pc !!!
        Si tu as besoin d'aide regarde ce tutoriel :
        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

        je regarde tes rapports demain,
        sur ce, bonne nuit et à demain :-)
        1
        1. avant de faire la fête, on va vérifier :

          • /!\AVERTISSEMENT :
          ce script n'est à utiliser que pour ce pc infecté et sur ce topic, il n'est valable pour aucun autre pc.

          Télécharge OtmoveIT (de Old_Timer) sur ton Bureau


          http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/
          ou :
          https://www.androidworld.fr/

          (c est le numéro 7 en bas de la page) :

          * Double-clique sur OTMoveIt.exe pour le lancer.
          * Copie la liste qui se trouve en gras dans la citation ci-dessous et colle-la dans le cadre de gauche de OTMoveIt sous Paste List of Files/Folders to move.

          :processes
          explorer.exe
          antivirus plus.70700.dll

          :services
          AntiVirus Plus

          :files
          C:\Users\Emilie\AppData\Roaming\AntiVirus Plus

          :reg
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AntiVirus Plus]

          :Commands
          [emptytemp]
          [purity]
          [start explorer]
          [Reboot]


          # clique sur MoveIt! pour lancer la suppression.

          # Le résultat apparaitra dans le cadre "Results".

          # Clique sur Exit pour fermer.

          # Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

          # Il te sera peut-être demandé de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.
          1
          1. bonsoir,
            peux tu envyer en copier coller le rapport d'avag sur ton prochain message ?
            0
            1. est ce que tu as des truc que tu veut garder sur ton pc ?
              0
              1. Je suis sous Vista, le scan Hijackthis arrive...
                0
                1. si veut tout refaire a 0 ? ou nan ?
                  0
                  1. ça c'est un virus à la con super dur à enlever , j'ai eût le même et j'ai essayé pleins de trucs , de logiciels ( antivirus ) mais rien n'y faisait .

                    J'ai essayé en dernier lieu spybot , ça n'a rien donné et malwerebytes' , il m'a trouvé la saloprie en question et n'a pas réussi à la supprimer mais m'a donné son emplacement ( c prog files , fichiers communs , systeme et là un seul fichier avec un nom super long qui veut rien dire et qui est impossible à retenir ) .

                    J'ai redémarré et fais un mode console ( avec l'aide de quelqu'un ) et supprimé le fichier en question .

                    Essaye de faire pareil ! ( si tu n'y arrive pas en console fais un mode sans echec )
                    0
                    1. Info :

                      info.txt logfile of random's system information tool 1.06 2010-02-07 21:42:07

                      ======Uninstall list======

                      -->"C:\Program Files\HP Games\5 Card Deluxe\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Agatha Christie - Death on the Nile\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Age of Castles\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Build-a-lot 2\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Cake Mania\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
                      -->"C:\Program Files\HP Games\FATE\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Fish Tycoon\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Granny in Paradise\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Mahjongg Artifacts\Uninstall.exe"
                      -->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Polar Pool\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
                      -->"C:\Program Files\HP Games\The Treasures of Montezuma\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Virtual Villagers - The Secret City\Uninstall.exe"
                      -->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
                      -->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                      ActiveCheck component for HP Active Support Library-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
                      Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                      Adobe Flash Player 10 Plugin-->MsiExec.exe /X{0DFB3DE8-65B9-44FF-AA0A-3BECC5A2BFD1}
                      Adobe Shockwave Player-->MsiExec.exe /X{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}
                      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                      AVG Free 9.0-->C:\Program Files\AVG\AVG9\setup.exe /UNINSTALL
                      Catalyst Control Center - Branding-->MsiExec.exe /I{187817E2-6407-461C-B59B-56CE73363D34}
                      CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
                      ESU for Microsoft Vista-->MsiExec.exe /I{3877C901-7B90-4727-A639-B6ED2DD59D43}
                      Free Internet Eraser 3.0-->"C:\Program Files\PrivacyEraser Computing\Free Internet Eraser\unins000.exe"
                      Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
                      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                      HP Active Support Library-->"C:\Program Files\InstallShield Installation Information\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}\setup.exe" -runfromtemp -l0x0409 -removeonly
                      HP Common Access Service Library-->MsiExec.exe /I{732A3F80-008B-4350-BD58-EC5AE98707B8}
                      HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57A5AEC1-97FC-474D-92C4-908FCC2253D4}\setup.exe" -l0x9 -removeonly
                      HP Help and Support-->MsiExec.exe /I{0054A0F6-00C9-4498-B821-B5C9578F433E}
                      HP MediaSmart DVD-->"C:\Program Files\InstallShield Installation Information\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\setup.exe" /z-uninstall
                      HP MediaSmart DVD-->"C:\Program Files\InstallShield Installation Information\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\setup.exe" /z-uninstall
                      HP MediaSmart Music/Photo/Video-->"C:\Program Files\InstallShield Installation Information\{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}\setup.exe" /z-uninstall
                      HP MediaSmart Music/Photo/Video-->"C:\Program Files\InstallShield Installation Information\{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}\setup.exe" /z-uninstall /zMS
                      HP MediaSmart SmartMenu-->MsiExec.exe /I{A7AC8E69-01FF-494E-9A2C-423B82CEA604}
                      HP MediaSmart TV-->"C:\Program Files\InstallShield Installation Information\{67626E09-5366-4480-8F1E-93FADF50CA15}\Setup.exe" /z-uninstall
                      HP MediaSmart TV-->"C:\Program Files\InstallShield Installation Information\{67626E09-5366-4480-8F1E-93FADF50CA15}\Setup.exe" /z-uninstall
                      HP MediaSmart Webcam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
                      HP MediaSmart Webcam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall /z
                      HP Quick Launch Buttons 6.40 L1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x040c uninst
                      HP Total Care Advisor-->MsiExec.exe /X{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}
                      HP Total Care Setup-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{95A747E0-DF19-46CB-A622-20A0107201BD}\setup.exe" -l0x9 -removeonly
                      HP Update-->MsiExec.exe /X{47F36D92-E58E-456D-B73C-3382737E4C42}
                      HP User Guides 0134-->MsiExec.exe /X{6ABE0E28-3A8E-4ADC-A050-784064B76236}
                      HP Wireless Assistant-->MsiExec.exe /X{E5E29403-3D25-40C6-892B-F9FEE2A95585}
                      HPAsset component for HP Active Support Library-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
                      HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
                      IDT Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\setup.exe" -l0x40c -remove -removeonly
                      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                      Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
                      Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
                      Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                      JMicron JMB38X Flash Media Controller Driver-->"C:\Windows\JMCR_DIR\setup.exe" delpkg
                      Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
                      LabelPrint-->"C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall
                      LabelPrint-->"C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall
                      LightScribe System Software 1.14.17.1-->MsiExec.exe /X{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}
                      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                      Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                      Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                      Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                      Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
                      Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
                      Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
                      Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
                      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                      Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
                      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                      Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
                      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                      Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                      Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                      Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
                      Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
                      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729-->MsiExec.exe /X{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}
                      Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
                      Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                      Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
                      Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                      Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
                      Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                      MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
                      muvee Reveal-->MsiExec.exe /X{E8020EC7-5DD8-80C9-7237-7B2E9BDA8CC6}
                      My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
                      Norton Internet Security-->MsiExec.exe /I{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}
                      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                      Package de pilotes Windows - ENE (enecir) HIDClass (09/04/2008 2.6.0.0)-->C:\PROGRA~1\DIFX\270581355A767BF1\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\enecir.inf_1a3c82dd\enecir.inf
                      Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
                      Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
                      PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
                      PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
                      ProtectSmart Hard Drive Protection-->MsiExec.exe /X{9D615069-AA8F-4E89-AE9D-77AAE90F529F}
                      Realtek 8169 8168 8101E 8102E Ethernet Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
                      Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                      Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
                      Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
                      Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
                      Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
                      Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
                      Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                      Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                      Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
                      Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                      Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3
                      0
                      1. Info :

                        info.txt logfile of random's system information tool 1.06 2010-02-07 21:42:07

                        ======Uninstall list======

                        -->"C:\Program Files\HP Games\5 Card Deluxe\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Agatha Christie - Death on the Nile\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Age of Castles\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Build-a-lot 2\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Cake Mania\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
                        -->"C:\Program Files\HP Games\FATE\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Fish Tycoon\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Granny in Paradise\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Mahjongg Artifacts\Uninstall.exe"
                        -->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Polar Pool\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
                        -->"C:\Program Files\HP Games\The Treasures of Montezuma\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Virtual Villagers - The Secret City\Uninstall.exe"
                        -->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
                        -->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                        ActiveCheck component for HP Active Support Library-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
                        Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                        Adobe Flash Player 10 Plugin-->MsiExec.exe /X{0DFB3DE8-65B9-44FF-AA0A-3BECC5A2BFD1}
                        Adobe Shockwave Player-->MsiExec.exe /X{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}
                        Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                        AVG Free 9.0-->C:\Program Files\AVG\AVG9\setup.exe /UNINSTALL
                        Catalyst Control Center - Branding-->MsiExec.exe /I{187817E2-6407-461C-B59B-56CE73363D34}
                        CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
                        ESU for Microsoft Vista-->MsiExec.exe /I{3877C901-7B90-4727-A639-B6ED2DD59D43}
                        Free Internet Eraser 3.0-->"C:\Program Files\PrivacyEraser Computing\Free Internet Eraser\unins000.exe"
                        Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
                        HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                        HP Active Support Library-->"C:\Program Files\InstallShield Installation Information\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}\setup.exe" -runfromtemp -l0x0409 -removeonly
                        HP Common Access Service Library-->MsiExec.exe /I{732A3F80-008B-4350-BD58-EC5AE98707B8}
                        HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57A5AEC1-97FC-474D-92C4-908FCC2253D4}\setup.exe" -l0x9 -removeonly
                        HP Help and Support-->MsiExec.exe /I{0054A0F6-00C9-4498-B821-B5C9578F433E}
                        HP MediaSmart DVD-->"C:\Program Files\InstallShield Installation Information\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\setup.exe" /z-uninstall
                        HP MediaSmart DVD-->"C:\Program Files\InstallShield Installation Information\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\setup.exe" /z-uninstall
                        HP MediaSmart Music/Photo/Video-->"C:\Program Files\InstallShield Installation Information\{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}\setup.exe" /z-uninstall
                        HP MediaSmart Music/Photo/Video-->"C:\Program Files\InstallShield Installation Information\{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}\setup.exe" /z-uninstall /zMS
                        HP MediaSmart SmartMenu-->MsiExec.exe /I{A7AC8E69-01FF-494E-9A2C-423B82CEA604}
                        HP MediaSmart TV-->"C:\Program Files\InstallShield Installation Information\{67626E09-5366-4480-8F1E-93FADF50CA15}\Setup.exe" /z-uninstall
                        HP MediaSmart TV-->"C:\Program Files\InstallShield Installation Information\{67626E09-5366-4480-8F1E-93FADF50CA15}\Setup.exe" /z-uninstall
                        HP MediaSmart Webcam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall
                        HP MediaSmart Webcam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\setup.exe" /z-uninstall /z
                        HP Quick Launch Buttons 6.40 L1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe -runfromtemp -l0x040c uninst
                        HP Total Care Advisor-->MsiExec.exe /X{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}
                        HP Total Care Setup-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{95A747E0-DF19-46CB-A622-20A0107201BD}\setup.exe" -l0x9 -removeonly
                        HP Update-->MsiExec.exe /X{47F36D92-E58E-456D-B73C-3382737E4C42}
                        HP User Guides 0134-->MsiExec.exe /X{6ABE0E28-3A8E-4ADC-A050-784064B76236}
                        HP Wireless Assistant-->MsiExec.exe /X{E5E29403-3D25-40C6-892B-F9FEE2A95585}
                        HPAsset component for HP Active Support Library-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
                        HPNetworkAssistant-->MsiExec.exe /I{228C6B46-64E2-404E-898A-EF0830603EF4}
                        IDT Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\setup.exe" -l0x40c -remove -removeonly
                        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                        Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
                        Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
                        Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                        JMicron JMB38X Flash Media Controller Driver-->"C:\Windows\JMCR_DIR\setup.exe" delpkg
                        Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
                        LabelPrint-->"C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall
                        LabelPrint-->"C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall
                        LightScribe System Software 1.14.17.1-->MsiExec.exe /X{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}
                        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                        Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                        Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                        Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
                        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                        Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                        Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
                        Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
                        Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
                        Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
                        Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
                        Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
                        Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
                        Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
                        Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
                        Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
                        Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
                        Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
                        Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
                        Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
                        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
                        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
                        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
                        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                        Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
                        Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
                        Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
                        Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
                        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                        Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                        Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                        Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                        Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
                        Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
                        Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729-->MsiExec.exe /X{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}
                        Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
                        Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
                        Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
                        Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
                        Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
                        Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                        MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
                        muvee Reveal-->MsiExec.exe /X{E8020EC7-5DD8-80C9-7237-7B2E9BDA8CC6}
                        My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
                        Norton Internet Security-->MsiExec.exe /I{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}
                        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                        Package de pilotes Windows - ENE (enecir) HIDClass (09/04/2008 2.6.0.0)-->C:\PROGRA~1\DIFX\270581355A767BF1\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\enecir.inf_1a3c82dd\enecir.inf
                        Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
                        Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
                        PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
                        PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
                        ProtectSmart Hard Drive Protection-->MsiExec.exe /X{9D615069-AA8F-4E89-AE9D-77AAE90F529F}
                        Realtek 8169 8168 8101E 8102E Ethernet Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
                        Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                        Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
                        Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
                        Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
                        Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
                        Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
                        Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                        Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                        Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
                        Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                        Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                        Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3
                        0
                        1. moi j'ai redemarrez le pc tout en appuyant F11 et j'ai fait restauration integrale et tu suit apres les instructions
                          0
                          1. log :

                            Logfile of random's system information tool 1.06 (written by random/random)
                            Run by Emilie at 2010-02-07 21:47:10
                            Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                            System drive C: has 338 GB (72%) free of 466 GB
                            Total RAM: 3068 MB (47% free)

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 21:47:30, on 07/02/2010
                            Platform: Windows Vista SP2 (WinNT 6.00.1906)
                            MSIE: Internet Explorer v8.00 (8.00.6001.18882)
                            Boot mode: Normal

                            Running processes:
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\Explorer.EXE
                            C:\Windows\system32\taskeng.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
                            C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
                            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                            C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
                            C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
                            C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                            C:\Program Files\Java\jre6\bin\jusched.exe
                            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                            C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                            C:\Program Files\AVG\AVG9\avgtray.exe
                            C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe
                            C:\Program Files\IDT\WDM\sttray.exe
                            C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                            C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
                            C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                            C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                            C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
                            C:\Windows\system32\conime.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe
                            C:\Windows\system32\MsiExec.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\AVG\AVG9\avgscanx.exe
                            C:\Program Files\AVG\AVG9\avgcsrvx.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Users\Emilie\Desktop\RSIT.exe
                            C:\Program Files\trend micro\Emilie.exe

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.esc-larochelle.fr:3128
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                            O1 - Hosts: ::1 localhost
                            O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                            O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
                            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                            O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                            O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                            O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                            O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            O4 - HKLM\..\Run: [DVDAgent] "C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe"
                            O4 - HKLM\..\Run: [TSMAgent] "C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
                            O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
                            O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
                            O4 - HKLM\..\Run: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
                            O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
                            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                            O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                            O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
                            O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                            O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                            O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                            O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
                            O4 - HKLM\..\Run: [TVAgent] "C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe"
                            O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
                            O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                            O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                            O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                            O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
                            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                            O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                            O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                            O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                            O13 - Gopher Prefix:
                            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
                            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                            O20 - AppInit_DLLs: avgrsstx.dll
                            O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\aestsrv.exe
                            O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                            O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
                            O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
                            O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
                            O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                            O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                            O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                            O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
                            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
                            O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\STacSV.exe
                            O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
                            O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
                            0
                            1. ad remover :

                              .
                              ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
                              .
                              Mis à jour par C_XX le 05.02.2010 à 17:34
                              Contact: AdRemover.contact@gmail.com
                              Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                              .
                              Lancé à: 22:20:04, 07/02/2010 | Mode Normal | Option: CLEAN
                              Exécuté de: C:\Ad-Remover\
                              Système d'exploitation: Microsoft® Windows Vista™ HomePremium Service Pack 2 v6.0.6002
                              Nom du PC: PC-DE-EMILIE | Utilisateur actuel: Emilie
                              .
                              ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                              .

                              (!) -- Fichiers temporaires supprimés.

                              .
                              HKLM\Software\Classes\TypeLib\{937936AF-28CA-4973-B8AE-F250406149A2}
                              .
                              ============== Scan additionnel ==============
                              .
                              .
                              * Internet Explorer Version 8.0.6001.18882 *
                              .
                              [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                              .
                              Start Page: hxxp://fr.msn.com/
                              Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                              Do404Search: 01000000
                              Local Page: C:\Windows\system32\blank.htm
                              Show_ToolBar: yes
                              Enable Browser Extensions: yes
                              Start Page Redirect Cache: hxxp://fr.msn.com/?ocid=iehp
                              Start Page Redirect Cache_TIMESTAMP: 065cf56c678dca01
                              Start Page Redirect Cache AcceptLangs: fr
                              Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                              Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                              .
                              [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                              .
                              Start Page: hxxp://fr.msn.com/
                              Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                              Delete_Temp_Files_On_Exit: yes
                              Local Page: C:\Windows\System32\blank.htm
                              Search bar: hxxp://search.msn.com/spbasic.htm
                              .
                              [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                              .
                              Tabs: res://ieframe.dll/tabswelcome.htm
                              .
                              ============== Suspect (Cracks, Serials, ...) ==============
                              .
                              C:\Users\Emilie\AppData\Local\VirtualStore\Program Files\BitComet\torrents\Age of Empires III + Add-on + Serial FR.torrent
                              .
                              ===================================
                              .
                              2106 Octet(s) - C:\Ad-Report-CLEAN[1].log
                              .
                              83 Fichier(s) - C:\Users\Emilie\AppData\Local\Temp
                              5 Fichier(s) - C:\Windows\Temp
                              0 Fichier(s) - C:\Windows\Prefetch
                              .
                              19 Fichier(s) - C:\Ad-Remover\BACKUP
                              0 Fichier(s) - C:\Ad-Remover\QUARANTINE
                              .
                              Fin à: 22:37:39 | 07/02/2010 - CLEAN[1]
                              .
                              ============== E.O.F ==============
                              .
                              0
                              1. USB Fix : (pas de clef, DD,...)

                                ############################## | UsbFix V6.092 |

                                User : Emilie (Administrateurs) # PC-DE-EMILIE
                                Update on 07/02/2010 by El Desaparecido , C_XX & Chimay8
                                Start at: 22:48:31 | 07/02/2010
                                Website : http://pagesperso-orange.fr/NosTools/index.html
                                Contact : FindyKill.Contact@gmail.com

                                Intel(R) Core(TM)2 Duo CPU P7350 @ 2.00GHz
                                Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                                Internet Explorer 8.0.6001.18882
                                Windows Firewall Status : Enabled

                                C:\ -> Disque fixe local # 455,17 Go (328,94 Go free) # NTFS
                                D:\ -> Disque fixe local # 10,59 Go (1,79 Go free) [RECOVERY] # NTFS
                                E:\ -> Disque CD-ROM

                                ############################## | Processus actifs |

                                C:\Windows\System32\smss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\wininit.exe
                                C:\Windows\system32\csrss.exe
                                C:\Program Files\AVG\AVG9\avgchsvx.exe
                                C:\Program Files\AVG\AVG9\avgrsx.exe
                                C:\Windows\system32\services.exe
                                C:\Windows\system32\lsass.exe
                                C:\Windows\system32\lsm.exe
                                C:\Program Files\AVG\AVG9\avgcsrvx.exe
                                C:\Windows\system32\winlogon.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\LogonUI.exe
                                C:\Windows\system32\Ati2evxx.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\STacSV.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\SLsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\Hpservice.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\Ati2evxx.exe
                                C:\Windows\System32\spoolsv.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\aestsrv.exe
                                C:\Program Files\AVG\AVG9\avgwdsvc.exe
                                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                C:\Windows\system32\msiexec.exe
                                C:\Program Files\AVG\AVG9\avgnsx.exe
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\Explorer.EXE
                                C:\Windows\system32\runonce.exe
                                C:\Program Files\SMINST\BLService.exe
                                C:\Program Files\CyberLink\Shared files\RichVideo.exe
                                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                C:\Windows\system32\conime.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
                                C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\SearchIndexer.exe
                                C:\Program Files\AVG\AVG9\avgemc.exe
                                C:\Program Files\AVG\AVG9\avgcsrvx.exe
                                C:\Windows\system32\wbem\wmiprvse.exe

                                ################## | Elements infectieux |

                                Supprimé ! C:\Windows\temp\akee.tmp\svchost.exe
                                Supprimé ! C:\Windows\System32\sdra64.exe
                                Supprimé ! C:\Users\Emilie\AppData\Roaming\SystemProc
                                Supprimé ! C:\$Recycle.Bin\S-1-5-21-3911995087-704351924-2775230539-1000
                                Supprimé ! D:\$Recycle.Bin\S-1-5-21-3911995087-704351924-2775230539-1000

                                ################## | Registre |

                                ################## | Mountpoints2 |

                                Supprimé ! HKCU\...\Explorer\MountPoints2\{28960f59-ea44-11de-b549-00238be0f406}\Shell\AutoRun\Command
                                Supprimé ! HKCU\...\Explorer\MountPoints2\{93153370-949a-11de-b9d8-806e6f6e6963}\Shell\AutoRun\Command
                                Supprimé ! HKCU\...\Explorer\MountPoints2\{e72fb404-baf2-11de-a7f0-00238be0f406}\Shell\AutoRun\Command
                                Supprimé ! HKCU\...\Explorer\MountPoints2\{e72fb40c-baf2-11de-a7f0-00238be0f406}\Shell\AutoRun\Command

                                ################## | Listing des fichiers présent |

                                [07/02/2010 18:52|--a------|2460] C:\aaw7boot.log
                                [07/02/2010 22:37|--a------|2445] C:\Ad-Report-CLEAN[1].log
                                [18/09/2006 22:43|--a------|24] C:\autoexec.bat
                                [11/04/2009 07:36|-rahs----|333257] C:\bootmgr
                                [18/09/2006 22:43|--a------|10] C:\config.sys
                                [?|?|?] C:\hiberfil.sys
                                [?|?|?] C:\pagefile.sys
                                [07/02/2010 22:55|--a------|3821] C:\UsbFix.txt
                                [12/08/2009 10:29|---hs----|13] D:\BLOCK.RIN
                                [03/10/2006 22:02|---hs----|438328] D:\bootmgr
                                [04/11/2008 16:37|---hs----|1199] D:\Desktop.ini
                                [10/09/2002 15:14|---hs----|8134] D:\Folder.htt
                                [07/02/2010 22:48|--ahs----|176] D:\MASTER.LOG
                                [12/09/2008 16:17|---hs----|381873] D:\protect.arabic
                                [15/09/2008 14:57|---hs----|182624] D:\protect.bulgarian
                                [16/09/2002 13:37|---hs----|181898] D:\protect.chinese hong kong
                                [16/09/2002 13:37|---hs----|181916] D:\protect.chinese simplified
                                [16/09/2002 13:37|---hs----|181898] D:\protect.chinese traditional
                                [27/04/2006 15:19|---hs----|181865] D:\protect.czech
                                [03/11/2005 14:21|---hs----|181726] D:\protect.danish
                                [10/09/2002 12:56|---hs----|181605] D:\protect.dutch
                                [10/09/2002 12:50|---hs----|181651] D:\protect.ed
                                [22/11/2004 14:28|---hs----|181648] D:\protect.english
                                [03/11/2005 14:20|---hs----|181673] D:\protect.finnish
                                [03/11/2005 14:19|---hs----|181736] D:\protect.french
                                [03/11/2005 14:18|---hs----|181669] D:\protect.german
                                [23/11/2005 14:56|---hs----|182689] D:\protect.greek
                                [23/01/2006 08:18|---hs----|182605] D:\protect.hebrew
                                [28/08/2007 13:58|---hs----|181696] D:\protect.hungarian
                                [03/11/2005 14:17|---hs----|181554] D:\protect.italian
                                [19/06/2007 14:22|---hs----|182351] D:\protect.japanese
                                [24/11/2005 10:24|---hs----|218295] D:\protect.korean
                                [03/11/2005 14:15|---hs----|181578] D:\protect.norwegian
                                [25/04/2006 13:44|---hs----|181789] D:\protect.polish
                                [03/11/2005 14:13|---hs----|181624] D:\protect.portuguese
                                [27/10/2005 18:24|---hs----|181882] D:\protect.portuguese brazilian
                                [15/09/2008 14:57|---hs----|181735] D:\protect.romanian
                                [28/06/2004 07:52|---hs----|211936] D:\protect.russian
                                [04/07/2007 10:46|---hs----|181954] D:\protect.slovak
                                [03/11/2005 14:11|---hs----|181586] D:\protect.spanish
                                [10/09/2002 13:15|---hs----|181602] D:\protect.swedish
                                [12/08/2003 09:37|---hs----|181783] D:\protect.turkish

                                ################## | Vaccination |

                                # C:\autorun.inf -> Dossier créé par UsbFix .
                                # D:\autorun.inf -> Dossier créé par UsbFix .

                                ################## | Upload |

                                Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_PC-de-Emilie.zip : https://www.ionos.fr/?affiliate_id=77097
                                Merci pour votre contribution .
                                0
                                1. malware bytes :

                                  Malwarebytes' Anti-Malware 1.44
                                  Version de la base de données: 3703
                                  Windows 6.0.6002 Service Pack 2 (Safe Mode)
                                  Internet Explorer 8.0.6001.18882

                                  07/02/2010 23:57:57
                                  mbam-log-2010-02-07 (23-57-57).txt

                                  Type de recherche: Examen complet (C:\|D:\|)
                                  Eléments examinés: 269078
                                  Temps écoulé: 39 minute(s), 43 second(s)

                                  Processus mémoire infecté(s): 0
                                  Module(s) mémoire infecté(s): 0
                                  Clé(s) du Registre infectée(s): 2
                                  Valeur(s) du Registre infectée(s): 1
                                  Elément(s) de données du Registre infecté(s): 0
                                  Dossier(s) infecté(s): 1
                                  Fichier(s) infecté(s): 3

                                  Processus mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Module(s) mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Clé(s) du Registre infectée(s):
                                  HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
                                  HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.

                                  Valeur(s) du Registre infectée(s):
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully.

                                  Elément(s) de données du Registre infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Dossier(s) infecté(s):
                                  C:\Windows\System32\lowsec (Stolen.data) -> Quarantined and deleted successfully.

                                  Fichier(s) infecté(s):
                                  C:\Windows\System32\lowsec\local.ds (Stolen.data) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\lowsec\user.ds (Stolen.data) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\lowsec\user.ds.lll (Stolen.data) -> Quarantined and deleted successfully.
                                  0
                                  1. Je te remercie Electricien 59, je pense que je m'en suis pas trop mal sorti :-). Pour info, je n'ai pas utilisé de supports USB donc a priori pas de risque d'infection d'élèments exterieurs.

                                    Je repasse demain en fin d'après-midi, bon courage pour déchiffrer tout ça !

                                    Encore merci !
                                    0
                                    1. bonjour,

                                      as tu envoté ce fichier afin d'améliorer usbfix ?

                                      Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_PC-de-Emilie.zip : https://www.ionos.fr/?affiliate_id=77097
                                      Merci pour ta contribution .

                                      repasse un autre rsit et poste son rapport
                                      note : tu n'auras q'un seul rapport (log.txt)

                                      @++
                                      0
                                      1. Bonjour,

                                        J'ai bien contribué à l'amélioration d'USBFix, je devais bien ça !

                                        voici le log RSIT, bonne journée

                                        Logfile of random's system information tool 1.06 (written by random/random)
                                        Run by Emilie at 2010-02-09 07:58:32
                                        Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                                        System drive C: has 336 GB (72%) free of 466 GB
                                        Total RAM: 3068 MB (64% free)

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 07:58:52, on 09/02/2010
                                        Platform: Windows Vista SP2 (WinNT 6.00.1906)
                                        MSIE: Internet Explorer v8.00 (8.00.6001.18882)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\Windows\system32\taskeng.exe
                                        C:\Windows\system32\Dwm.exe
                                        C:\Windows\Explorer.EXE
                                        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                        C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
                                        C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
                                        C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
                                        C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
                                        C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                                        C:\Program Files\Java\jre6\bin\jusched.exe
                                        C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                                        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                                        C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                                        C:\Program Files\AVG\AVG9\avgtray.exe
                                        C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe
                                        C:\Program Files\IDT\WDM\sttray.exe
                                        C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                                        C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                                        C:\Program Files\OpenOffice.org 3\program\soffice.exe
                                        C:\Program Files\OpenOffice.org 3\program\soffice.bin
                                        C:\Program Files\Internet Explorer\iexplore.exe
                                        C:\Program Files\Internet Explorer\iexplore.exe
                                        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                                        C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
                                        C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
                                        C:\Windows\system32\SearchProtocolHost.exe
                                        C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                                        C:\Windows\system32\SearchFilterHost.exe
                                        C:\Users\Emilie\Desktop\RSIT.exe
                                        C:\Program Files\trend micro\Emilie.exe

                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.esc-larochelle.fr:3128
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                        O1 - Hosts: ::1 localhost
                                        O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                                        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
                                        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                        O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                        O4 - HKLM\..\Run: [DVDAgent] "C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe"
                                        O4 - HKLM\..\Run: [TSMAgent] "C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
                                        O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
                                        O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
                                        O4 - HKLM\..\Run: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
                                        O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
                                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                        O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                                        O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
                                        O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                        O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                                        O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                                        O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
                                        O4 - HKLM\..\Run: [TVAgent] "C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe"
                                        O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
                                        O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                        O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                                        O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                                        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                        O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                                        O13 - Gopher Prefix:
                                        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
                                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                        O20 - AppInit_DLLs: avgrsstx.dll
                                        O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\aestsrv.exe
                                        O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                                        O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
                                        O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
                                        O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
                                        O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
                                        O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                                        O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                        O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
                                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                        O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
                                        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
                                        O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\STacSV.exe
                                        O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
                                        O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
                                        0
                                        • 1
                                        • 2