Sujet pour methafo !!

jacques.gache Messages postés 34829 Statut Contributeur sécurité -  
 ax -
Bonjour, comme je te disais ICI je t'ouvre un sujet je colle le lien de ton zhpdiag afin que tout le mode puisse suivre et comprendre !!

rapport zhpdiag de methafo

et au vu de ce rapport je vois qu' il y a pas mal d'infection divers sur ton pc , tu fais ce qui suit , Merci

1) tu fixes les lignes infectieuse donnés avec zhpfix

. Copie les lignes suivantes en GRAS

R3 - URLSearchHook: P2P Energy Toolbar - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} . (.Spigot, Inc. - Search Settings IE.) (1, 2, 2, 2) -- C:\Program Files\Search Settings\kb128\SearchSettings.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O4 - HKCU\..\Run: [GabPath] C:\Documents and Settings\christian\Application Data\GabPath\gabpath.exe (.not file.)
O4 - HKCU\..\Run: [SfKg6wIPuSp] . (.Pas de propriétaire - Pas de description.) -- C:\Documents and Settings\christian\Application Data\Microsoft\Windows\jnipmo.exe
O39 - APT:Automatic Planified Task - C:\windows\Tasks\Scheduled Update for Ask Toolbar.job
O42 - Logiciel: EoRezo 10.3 - (.EoRezo.) [HKLM] -- EoRezo_is1
O42 - Logiciel: Search Settings 1.2.2 - (.Spigot, Inc..) [HKLM] -- {0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
O42 - Logiciel: SoftwareUpdate 1.0 - (.eoRezo.) [HKLM] -- SoftwareUpdate_is1
O42 - Logiciel: pdfforge Toolbar v1.1.1 - (.Spigot, Inc..) [HKLM] -- {4EF8BE6A-899C-4196-94E7-297C5F7A203E}
[HKCU\Software\AppDataLow\AskBarDis]
[HKCU\Software\AppDataLow\AskHomepage]
[HKCU\Software\AppDataLow\Software\pdfforge]
[HKCU\Software\Ask.com]
[HKCU\Software\BulletProofSoft.com]
[HKCU\Software\EoRezo]
[HKCU\Software\IEBarProperties]
[HKCU\Software\LanConfig]
[HKCU\Software\Search Settings]
[HKCU\Software\SpiderMessenger]
[HKCU\Software\Visio RAS Script]
[HKCU\Software\mc]
[HKCU\Software\sponsoradulto]
[HKLM\Software\AskPBar]
[HKLM\Software\Search Settings]
[HKLM\Software\UControl]
[HKLM\Software\egroup]
[HKLM\Software\pdfforge]
O43 - CFD:Common File Directory ----D- C:\Program Files\EoRezo
O43 - CFD:Common File Directory ----D- C:\Program Files\IEToolbar
O43 - CFD:Common File Directory ----D- C:\Program Files\pdfforge Toolbar
O43 - CFD:Common File Directory ----D- C:\Program Files\Search Settings
O43 - CFD:Common File Directory ----D- C:\Program Files\WordUninstaller
O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\UControl
O61 - LFC:Last File Created 24/09/2010 - 20:04:22 ---A- C:\Documents And Settings\christian\Application Data\Microsoft\Windows\jnipmo.exe [450560]
O61 - LFC:Last File Created 25/09/2010 - 17:45:01 ---A- C:\Documents And Settings\All Users\Application Data\Alwil Software\Avast5\fw\config.xml [2516]
O61 - LFC:Last File Created 25/09/2010 - 17:45:31 ---A- C:\Documents And Settings\christian\Application Data\Skype\bequissou315\config.xml [27584]
O64 - Services: CurCS - (.not file.) - ndisrd (ndisrd) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDISRD
O64 - Services: CurCS - (.not file.) - Windows Log (Windows Log) .(.Pas de propriétaire - Pas de description.) - LEGACY_WINDOWS_LOG
O65 - LUF:07/09/2006 (.Pas de propriétaire - DOT Application.) (1, 0, 0, 2) - c:\windows\system32\WinSys.exe
O69 - SBI: prefs.js [christian - cxci8hgi.default] user_pref("extensions.asktb.cbid", "VX");
O69 - SBI: prefs.js [christian - cxci8hgi.default] user_pref("extensions.asktb.default-channel-url-mask", "https://fr.ask.com/?o=0&l=dir&ad=dirN{query}&o={o}&l={l}&qsrc={qsrc}");
O69 - SBI: prefs.js [christian - cxci8hgi.default] user_pref("extensions.asktb.fresh-install", false);
O69 - SBI: prefs.js [christian - cxci8hgi.default] user_pref("extensions.asktb.l", "dis");
O69 - SBI: prefs.js [christian - cxci8hgi.default] user_pref("extensions.asktb.last-config-req", "1277170945008");
O69 - SBI: prefs.js [christian - cxci8hgi.default] user_pref("extensions.asktb.locale", "fr_US");
O69 - SBI: prefs.js [christian - cxci8hgi.default] user_pref("extensions.asktb.o", "14778");
O69 - SBI: prefs.js [christian - cxci8hgi.default] user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
O69 - SBI: prefs.js [christian - cxci8hgi.default] user_pref("extensions.asktb.qsrc", "2871");
O69 - SBI: prefs.js [christian - cxci8hgi.default] user_pref("extensions.asktb.r", "8");
O69 - SBI: prefs.js [christian - cxci8hgi.default] user_pref("extensions.snipit.askTbInstalled", true);
O69 - SBI: prefs.js [christian - cxci8hgi.default] user_pref("extensions.toolbar@ask.com.install-event-fired", true);



. Lance ZHPFix de Nicolas Coolman qui se trouve sur ton bureau
. Pour XP, double-clique sur ZHPFix
. pour Vista et seven, faire un clic droit sur l'icône et exécute en tant qu'administrateur.
. Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)

Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

. cliques sur OK
. Clique sur « Tous », puis sur « Nettoyer »
. Copie/colle la totalité du rapport dans ta prochaine réponse
tu le trouveras dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport

on va vériffier si pas de résidu avec des outils plus spéciphiques, merci

1) passes ad-remover en option nettoyage

Déactives ton anti-virus et anti-spyware le temps du scan

Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

Télécharge Ad-Remover sur ton bureau:
http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe
ou:
https://www.androidworld.fr/

/!\ Ferme toutes tes applications ouvertes. /!\

Double clique sur le fichier que tu viens de télécharger, à l'écran qui apparait, clique sur "Nettoyer".
Laisse travailler l'outil.
Poste le rapport qui s'affiche à l'écran quand l'analyse est terminée.

( Le rapport est sauvegardé sous C:\Ad-report-clean.log )

2) passes navilog comme expliqué

Téléchargez et enregistrez Navilog1 sur le Bureau.

Sous XP : double-cliquez sur l'icône pour lancer l'outil.

Sous vista : faites un clic droit sur Navilog1 présent sur le Bureau et choisissez "Exécuter en tant qu'administrateur".

Choisissez votre langue, appuyez sur F pour Français.

Appuyez sur une touche jusqu'à ce que vous arriviez au menu des options.

Choisissez l'option 1 (Recherche / Désinfection Automatique).

Laissez le programme travailler, il pourrait durer une dizaine de minutes.

Si l'outil trouve quelque chose, il sera amené à faire redémarrer l'ordinateur.

Lorsque le message "Scan terminé le..." s'affichera, appuyez sur une touche pour faire apparaitre le rapport dans le Bloc-notes (il sera aussi enregistré automatiquement sur votre disque dur : C:\cleannavi.txt)

Voici un tutoriel qui vous explique le fonctionnement de Navilog1 : Lien

3) fais un examen complet de ton pc avec malwarebytes

!! ATTENTION !!! près de 2 heures de scan !!!

Télécharge Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe

si problème essais avec celui ci : https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

(NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installation, alors télécharge le ici :COMCTL32.OCX

. enregistres le sur le bureau
. Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
. Utilisateur de Vista et Windows 7 : Clique droit sur le logo de Malwarebytes' Anti-Malware, « exécuter en tant qu'Administrateur »
. si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
. Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
. Une fois la mise à jour terminée
. rend-toi dans l'onglet, Recherche
. Sélectionnes Exécuter un examen complet
. Cliques sur Rechercher
. Le scan démarre.
. A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
. Cliques sur Ok pour poursuivre.
. Si des malwares ont été détectés, cliques sur Afficher les résultats
. Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
. Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
. redemarre le pc si il le fait pas lui même
. une fois redémarré double-cliques sur malwarebytes
. rends toi dans l'onglet rapport/log
. tu cliques dessus pour l'afficher une fois affiché
. tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
. tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
. tu cliques droit dans le cadre de la reponse et coller

Si tu as besoin d'aide regarde ce tutoriel :
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

4) postes un nouveau zhpdiag pour voir les avancées

Double cliques sur le raccourci ZHPDiag sur ton Bureau pour XP sinon clique droit et en tant que administrateur !!

Clique sur le Tournevis puis sur Tous pour cocher toutes les cases des options.

Cliques sur la loupe pour lancer l'analyse.

Laisses l'outil travailler, il peut être assez long.

A la fin de l'analyse,clique sur l'appareil photo et enregistre le rapport sur ton Bureau.

Fermes ZHPDiag en fin d'analyse.

Pour me le transmettre clique sur ce lien :

http://www.cijoint.fr/index.php

Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\bureau\.ZHPDiag.txt

ou directement en choisissant bureau et ZHPDiag.txt clique dessus

Clique sur Ouvrir.

Clique sur "Cliquez ici pour déposer le fichier".

Un lien de cette forme :

http://www.cijoint.fr/cjlink.php?file=cj200905/cib7SU.txt

est ajouté dans la page.

Copie ce lien dans ta réponse.



--
Perso je ne sais peut être pas grand chose, mais si le peu que je sais p­eut aider et bien,
je veux bien le partager avec toi !!

16 réponses

  1. methafo
     
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Version de la base de données: 4707

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    27/09/2010 17:57:06
    mbam-log-2010-09-27 (17-57-06).txt

    Type d'examen: Examen complet (C:\|F:\|G:\|)
    Elément(s) analysé(s): 357551
    Temps écoulé: 1 heure(s), 43 minute(s), 4 seconde(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 4
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 2
    Fichier(s) infecté(s): 3

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\questbrowser (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\QuestBrowser (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_QUESTBROWSER_SERVICE (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QuestBrowser Service (Adware.QuestBrowser) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    C:\Program Files\QuestBrowser (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\QuestBrowser (Adware.QuestBrowser) -> Quarantined and deleted successfully.

    Fichier(s) infecté(s):
    C:\Program Files\QuestBrowser\questbrowser.exe (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\QuestBrowser\questbrowser117.exe (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    C:\Program Files\QuestBrowser\uninstall.exe (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      bonjour as tu fais ce qui était demandé dans l'ordre car j'ai pas le rapport de zhpfix que tu trouveras dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport
      et puis celui de AD-Remover qui est dans C:\Ad-report-clean.log
      ni celui de navilog C:\cleannavi.txt

      ici sur ccm nous sommes tous la bénévolement pour vous aider , mais on en attent de votre part un minimum d'aide oui pour vous aider nous avons besoin de votre aide en faisant ni plus ni moins que ce qui est demander ???
      la tu as poster directement malwarebytes que tu avais fais avant , ok mais fais ce qui est demandé , et quand tu arriveras pour malwarebytes tu lui fais faire la mise à jour et tu fais un nouveau examen , merci
      0
    2. ax
       
      Malwarebytes Anti-Malware 1.61.0.1400
      www.malwarebytes.org

      Version de la base de données: v2012.04.29.04

      Windows Vista Service Pack 2 x86 NTFS (Mode sans échec/Réseau)
      Internet Explorer 9.0.8112.16421
      Axelle :: PC-DE-AXELLE [administrateur]

      29/04/2012 19:14:08
      mbam-log-2012-04-29 (19-14-08).txt

      Type d'examen: Examen complet
      Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
      Options d'examen désactivées: P2P
      Elément(s) analysé(s): 337963
      Temps écoulé: 1 heure(s), 16 minute(s), 25 seconde(s)

      Processus mémoire détecté(s): 0
      (Aucun élément nuisible détecté)

      Module(s) mémoire détecté(s): 0
      (Aucun élément nuisible détecté)

      Clé(s) du Registre détectée(s): 1
      HKCU\SOFTWARE\fcn (Rogue.Residue) -> Mis en quarantaine et supprimé avec succès.

      Valeur(s) du Registre détectée(s): 1
      HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|509018E3 (Trojan.Agent) -> Données: C:\Users\Axelle\AppData\Roaming\Gpfkodjsh\20C45501509018E3D7FD.exe -> Mis en quarantaine et supprimé avec succès.

      Elément(s) de données du Registre détecté(s): 0
      (Aucun élément nuisible détecté)

      Dossier(s) détecté(s): 0
      (Aucun élément nuisible détecté)

      Fichier(s) détecté(s): 5
      C:\Users\Axelle\AppData\Roaming\Gpfkodjsh\20C45501509018E3D7FD.exe (Trojan.Agent) -> Mis en quarantaine et supprimé avec succès.
      C:\Users\Axelle\AppData\Local\Temp\jar_cache5340555540767927279.tmp (Trojan.FakeMS) -> Mis en quarantaine et supprimé avec succès.
      C:\Users\Axelle\AppData\Local\Temp\ms0cfg32.exe (Trojan.FakeMS) -> Mis en quarantaine et supprimé avec succès.
      C:\Users\Axelle\AppData\Local\Temp\shrdqtfwyg.pre (Trojan.Agent) -> Mis en quarantaine et supprimé avec succès.
      C:\Users\Axelle\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14\63b97b8e-162553a4-temp (Trojan.FakeMS) -> Mis en quarantaine et supprimé avec succès.

      (fin)
      0
  2. methafo
     
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Version de la base de données: 4712

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    28/09/2010 09:11:23
    mbam-log-2010-09-28 (09-11-23).txt

    Type d'examen: Examen complet (C:\|F:\|G:\|)
    Elément(s) analysé(s): 357155
    Temps écoulé: 1 heure(s), 40 minute(s), 46 seconde(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      et les autre rapport , merci de faire ce qui est demandé et de poster les rapport demandé et attendu pour pouvoir suivre la désinfection , sinon je perds mon temps @+
      0
  3. methafo
     
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Version de la base de données: 4707

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    27/09/2010 17:57:06
    mbam-log-2010-09-27 (17-57-06).txt

    Type d'examen: Examen complet (C:\|F:\|G:\|)
    Elément(s) analysé(s): 357551
    Temps écoulé: 1 heure(s), 43 minute(s), 4 seconde(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 4
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 2
    Fichier(s) infecté(s): 3

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\questbrowser (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\QuestBrowser (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_QUESTBROWSER_SERVICE (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QuestBrowser Service (Adware.QuestBrowser) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    C:\Program Files\QuestBrowser (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\QuestBrowser (Adware.QuestBrowser) -> Quarantined and deleted successfully.

    Fichier(s) infecté(s):
    C:\Program Files\QuestBrowser\questbrowser.exe (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\QuestBrowser\questbrowser117.exe (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    C:\Program Files\QuestBrowser\uninstall.exe (Adware.QuestBrowser) -> Quarantined and deleted successfully.
    0
  4. methafo
     
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Version de la base de données: 4712

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    28/09/2010 09:11:23
    mbam-log-2010-09-28 (09-11-23).txt

    Type d'examen: Examen complet (C:\|F:\|G:\|)
    Elément(s) analysé(s): 357155
    Temps écoulé: 1 heure(s), 40 minute(s), 46 seconde(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      pourquoi continu tu as me poster un rapport de malwarebytes !! je te demande de faire ce qui est dans le premier message et de poster les rapport au fure et à mesure , si mes explication ne sont pas assé claire ou mal écrit pas suffisament claire et français tu le dis et je verrais pour faire mieux bref tu fais comme demandé dans le message que je t'ai mis pour t'ouvrir la discution !!! MERCI
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. methafo
     
    ======= RAPPORT D'AD-REMOVER 2.0.0.1,F | UNIQUEMENT XP/VISTA/7 =======

    Mis à jour par C_XX le 16/09/10 à 13:30
    Contact: AdRemover.contact[AT]gmail.com
    Site web: http://www.teamxscript.org

    C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 14:54:55 le 27/09/2010, Mode normal

    Microsoft Windows XP Édition familiale Service Pack 3 (X86)
    christian@CHRIS ( )

    ============== ACTION(S) ==============

    0,Dossier supprimé: C:\Documents and Settings\christian\Local Settings\Application Data\Conduit

    (!) -- Fichiers temporaires supprimés.

    -- Fichier ouvert: C:\Documents and Settings\christian\Application Data\Mozilla\FireFox\Profiles\cxci8hgi.default\Prefs.js --
    Ligne supprimée: user_pref("CT1060933.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER...
    Ligne supprimée: user_pref("CT1060933.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT106...
    Ligne supprimée: user_pref("CT2124320.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER...
    Ligne supprimée: user_pref("CT2124320.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT212...
    Ligne supprimée: user_pref("CT2124320.ct2467816.SearchEngine", "Recherche||hxxp://search.conduit.com/Results.aspx?q=U...
    Ligne supprimée: user_pref("CT2542115.SearchEngine", "Recherche||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_...
    Ligne supprimée: user_pref("CT2542115.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT254...
    Ligne supprimée: user_pref("browser.search.defaultengine", "Ask.com");
    Ligne supprimée: user_pref("browser.search.defaultthis.engineName", "Freecorder Customized Web Search");
    Ligne supprimée: user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&Sea...
    Ligne supprimée: user_pref("browser.search.order.1", "Ask.com");
    Ligne supprimée: user_pref("browser.search.selectedEngine", "Freecorder Customized Web Search");
    Ligne supprimée: user_pref("extensions.asktb.cbid", "VX");
    Ligne supprimée: user_pref("extensions.asktb.first-launch-url", "hxxp://www.facebook.com/n/?profile.php&id=1000000522...
    Ligne supprimée: user_pref("extensions.asktb.fresh-install", false);
    Ligne supprimée: user_pref("extensions.asktb.l", "dis");
    Ligne supprimée: user_pref("extensions.asktb.last-config-req", "1277170945008");
    Ligne supprimée: user_pref("extensions.asktb.locale", "fr_US");
    Ligne supprimée: user_pref("extensions.asktb.o", "14778");
    Ligne supprimée: user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
    Ligne supprimée: user_pref("extensions.asktb.qsrc", "2871");
    Ligne supprimée: user_pref("extensions.asktb.r", "8");
    Ligne supprimée: user_pref("extensions.mywebsearch.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opensea...
    Ligne supprimée: user_pref("extensions.mywebsearch.prevKwdEnabled", true);
    Ligne supprimée: user_pref("extensions.snipit.askTbInstalled", true);
    Ligne supprimée: user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&q=");
    -- Fichier Fermé --

    0,Clé supprimée: HKCU\Software\Conduit

    ============== SCAN ADDITIONNEL ==============

    ** Mozilla Firefox Version [4.0b6 (fr)] **

    -- C:\Documents and Settings\christian\Application Data\Mozilla\FireFox\Profiles\cxci8hgi.default\Prefs.js --
    browser.download.dir, C:\\Documents and Settings\\christian\\Bureau
    browser.download.lastDir, C:\\Documents and Settings\\christian\\Bureau
    browser.search.defaultenginename, SearchCanvas
    browser.startup.homepage, hxxp://fr.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
    browser.startup.homepage_override.buildID, 20100914073604
    browser.startup.homepage_override.mstone, rv:2.0b6

    ========================================

    ** Internet Explorer Version [8.0.6001.18702] **

    [HKCU\Software\Microsoft\Internet Explorer\Main]
    AutoHide: yes
    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Do404Search: 0x01000000
    Enable Browser Extensions: yes
    SearchAssistant:
    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
    Show_ToolBar: yes
    Start Page: hxxp://fr.msn.com/
    Use Custom Search URL: 1
    Use Search Asst: no

    [HKLM\Software\Microsoft\Internet Explorer\Main]
    Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Delete_Temp_Files_On_Exit: yes
    Search bar: hxxp://search.msn.com/spbasic.htm
    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Start Page: hxxp://fr.msn.com/
    Use Custom Search URL: 1

    [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
    Tabs: res://ieframe.dll/tabswelcome.htm
    Blank: res://mshtml.dll/blank.htm

    ========================================

    C:\Program Files\Ad-Remover\Quarantine: 1 Fichier(s)
    C:\Program Files\Ad-Remover\Backup: 14 Fichier(s)

    C:\Ad-Report-CLEAN[1].txt - 27/09/2010 (3204 Octet(s))

    Fin à: 15:03:11, 27/09/2010

    ============== E.O.F ==============
    0
  7. methafo
     
    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Home Edition
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x0000007c

    Kernel Drivers (total 163):
    0x804D7000 \windows\system32\ntoskrnl.exe
    0x806FF000 \windows\system32\hal.dll
    0xF7987000 \windows\system32\KDCOM.DLL
    0xF7897000 \windows\system32\BOOTVID.dll
    0xF75A7000 ACPI.sys
    0xF7989000 \windows\System32\DRIVERS\WMILIB.SYS
    0xF7596000 pci.sys
    0xF75F7000 isapnp.sys
    0xF74E0000 ps7aey8l.sys
    0xF74CA000 ps7aezgb.sys
    0xF7A4F000 pciide.sys
    0xF7707000 \windows\System32\DRIVERS\PCIIDEX.SYS
    0xF7607000 MountMgr.sys
    0xF74AB000 ftdisk.sys
    0xF770F000 PartMgr.sys
    0xF7A50000 siside.sys
    0xF7617000 VolSnap.sys
    0xF7493000 atapi.sys
    0xF7627000 disk.sys
    0xF7637000 \windows\System32\DRIVERS\CLASSPNP.SYS
    0xF7473000 fltmgr.sys
    0xF7461000 sr.sys
    0xF7647000 PxHelp20.sys
    0xF744A000 KSecDD.sys
    0xF7B52000 Ntfs.sys
    0xF741D000 NDIS.sys
    0xF786A000 aswNdis2.sys
    0xF798B000 aswNdis.sys
    0xF7657000 uagp35.sys
    0xF789B000 sisperf.sys
    0xF7667000 sisidex.sys
    0xF7677000 SISAGPX.sys
    0xBA748000 pf2aezgb.sys
    0xBA730000 pf2aey8l.sys
    0xBA71D000 pe3aezgb.sys
    0xBA70A000 pe3aey8l.sys
    0xF7687000 ohci1394.sys
    0xF7697000 \windows\system32\DRIVERS\1394BUS.SYS
    0xBA6F0000 Mup.sys
    0xF789F000 atisgkaf.sys
    0xF74F6000 \SystemRoot\System32\DRIVERS\intelppm.sys
    0xB9CE9000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
    0xB9CD5000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xB9CC1000 \SystemRoot\System32\DRIVERS\parport.sys
    0xB9CB0000 \SystemRoot\System32\DRIVERS\serial.sys
    0xB9E02000 \SystemRoot\System32\DRIVERS\serenum.sys
    0xB9DFE000 \SystemRoot\system32\DRIVERS\gameenum.sys
    0xBA7E0000 \SystemRoot\system32\drivers\Imapi.sys
    0xBA7D0000 \SystemRoot\System32\DRIVERS\cdrom.sys
    0xBA7C0000 \SystemRoot\System32\DRIVERS\redbook.sys
    0xB9C8D000 \SystemRoot\System32\DRIVERS\ks.sys
    0xF780F000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
    0xB9BFF000 \SystemRoot\system32\drivers\smwdm.sys
    0xB9BDB000 \SystemRoot\system32\drivers\portcls.sys
    0xBA7A0000 \SystemRoot\system32\drivers\drmk.sys
    0xF7A09000 \SystemRoot\system32\drivers\aeaudio.sys
    0xF7817000 \SystemRoot\System32\DRIVERS\usbohci.sys
    0xB9BB7000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
    0xF781F000 \SystemRoot\System32\DRIVERS\usbehci.sys
    0xF771F000 \SystemRoot\system32\DRIVERS\sisnic.sys
    0xF7737000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0xBA790000 \SystemRoot\system32\DRIVERS\nic1394.sys
    0xBA780000 \SystemRoot\system32\DRIVERS\mf.sys
    0xB9DE0000 \SystemRoot\System32\DRIVERS\audstub.sys
    0xBA08B000 \SystemRoot\System32\DRIVERS\rasirda.sys
    0xBA083000 \SystemRoot\System32\DRIVERS\TDI.SYS
    0xBA37C000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
    0xB9DF2000 \SystemRoot\System32\DRIVERS\ndistapi.sys
    0xB952E000 \SystemRoot\System32\DRIVERS\ndiswan.sys
    0xBA36C000 \SystemRoot\System32\DRIVERS\raspppoe.sys
    0xBA35C000 \SystemRoot\System32\DRIVERS\raspptp.sys
    0xB951D000 \SystemRoot\System32\DRIVERS\psched.sys
    0xF7586000 \SystemRoot\System32\DRIVERS\msgpc.sys
    0xBA07B000 \SystemRoot\System32\DRIVERS\ptilink.sys
    0xBA073000 \SystemRoot\System32\DRIVERS\raspti.sys
    0xBA34C000 \SystemRoot\System32\Drivers\pcouffin.sys
    0xF7576000 \SystemRoot\System32\DRIVERS\termdd.sys
    0xBA06B000 \SystemRoot\System32\DRIVERS\kbdclass.sys
    0xBA063000 \SystemRoot\System32\DRIVERS\mouclass.sys
    0xBA031000 \SystemRoot\System32\DRIVERS\swenum.sys
    0xB94BF000 \SystemRoot\System32\DRIVERS\update.sys
    0xB9DEA000 \SystemRoot\System32\DRIVERS\mssmbios.sys
    0xB9FCE000 \SystemRoot\System32\Drivers\wpdusb.sys
    0xF7999000 \SystemRoot\System32\Drivers\USBD.SYS
    0xB8C2E000 \SystemRoot\system32\DRIVERS\NmPar.sys
    0xB8C1C000 \SystemRoot\system32\DRIVERS\nmserial.sys
    0xF76C7000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xF7546000 \SystemRoot\System32\DRIVERS\usbhub.sys
    0xA9CEC000 \SystemRoot\System32\Drivers\Cdr4_xp.SYS
    0xAA077000 \SystemRoot\System32\Drivers\Cdralw2k.SYS
    0xF79C5000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xAA074000 \SystemRoot\System32\Drivers\Null.SYS
    0xF79C7000 \SystemRoot\System32\Drivers\Beep.SYS
    0xF77DF000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0xF77EF000 \SystemRoot\System32\drivers\vga.sys
    0xF79CB000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xF79CD000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xF77F7000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xF77FF000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xA9C03000 \SystemRoot\System32\Drivers\UdfReadr_xp.SYS
    0xBA332000 \SystemRoot\System32\DRIVERS\rasacd.sys
    0xA9BDE000 \SystemRoot\System32\DRIVERS\ipsec.sys
    0xA9B85000 \SystemRoot\System32\DRIVERS\tcpip.sys
    0xA9B44000 \SystemRoot\System32\Drivers\aswFW.SYS
    0xA9B1E000 \SystemRoot\System32\DRIVERS\ipnat.sys
    0xB90F8000 \SystemRoot\System32\Drivers\aswTdi.SYS
    0xA9ACE000 \SystemRoot\System32\DRIVERS\netbt.sys
    0xB90E8000 \SystemRoot\System32\DRIVERS\wanarp.sys
    0xA9AA2000 \SystemRoot\System32\drivers\afd.sys
    0xB90D8000 \SystemRoot\system32\DRIVERS\arp1394.sys
    0xB90C8000 \SystemRoot\System32\DRIVERS\netbios.sys
    0xF7807000 \SystemRoot\System32\Drivers\StarOpen.SYS
    0xA9A77000 \SystemRoot\System32\DRIVERS\rdbss.sys
    0xB90A0000 \SystemRoot\system32\drivers\orbvckmd.sys
    0xA9A07000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
    0xF7536000 \SystemRoot\System32\Drivers\Fips.SYS
    0xA99B8000 \SystemRoot\System32\Drivers\aswSP.SYS
    0xA9955000 \SystemRoot\System32\Drivers\aswSnx.SYS
    0xB9090000 \SystemRoot\System32\Drivers\Aavmker4.SYS
    0xB9088000 \SystemRoot\System32\DRIVERS\usbccgp.sys
    0xA9DE5000 \SystemRoot\System32\Drivers\Modem.SYS
    0xAACA0000 \SystemRoot\System32\Drivers\LHidUsbK.Sys
    0xA9D83000 \SystemRoot\System32\Drivers\HIDCLASS.SYS
    0xA9C84000 \SystemRoot\System32\Drivers\LUsbKbd.Sys
    0xA9D33000 \SystemRoot\system32\drivers\LVUSBSta.sys
    0xA86B3000 \SystemRoot\system32\DRIVERS\lvuvc.sys
    0xA9D23000 \SystemRoot\system32\drivers\usbaudio.sys
    0xA8654000 \SystemRoot\system32\DRIVERS\lvrs.sys
    0xBA66C000 \SystemRoot\system32\drivers\MODEMCSA.sys
    0xA9B1A000 \SystemRoot\system32\DRIVERS\kbdhid.sys
    0xA9DA5000 \SystemRoot\system32\DRIVERS\LHidKE.Sys
    0xA9B16000 \SystemRoot\System32\DRIVERS\mouhid.sys
    0xF7516000 \SystemRoot\system32\DRIVERS\LMouKE.Sys
    0xB9FAE000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xBA6C4000 \SystemRoot\System32\drivers\Dxapi.sys
    0xBA05B000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xB9F40000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF012000 \SystemRoot\System32\ati2dvag.dll
    0xBF048000 \SystemRoot\System32\ati2cqag.dll
    0xBF080000 \SystemRoot\System32\ati3duag.dll
    0xBF24E000 \SystemRoot\System32\ativvaxx.dll
    0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
    0xA9B0A000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
    0xBA053000 \SystemRoot\system32\DRIVERS\AegisP.sys
    0xA82D1000 \SystemRoot\system32\DRIVERS\irda.sys
    0xA836F000 \SystemRoot\System32\DRIVERS\ndisuio.sys
    0xA817A000 \SystemRoot\System32\Drivers\aswMon2.SYS
    0xA7D05000 \SystemRoot\system32\drivers\wdmaud.sys
    0xA7E52000 \SystemRoot\system32\drivers\sysaudio.sys
    0xBA037000 \SystemRoot\System32\Drivers\ParVdm.SYS
    0xAAC07000 \??\C:\WINDOWS\system32\drivers\aslm75.sys
    0xA7AAB000 \SystemRoot\System32\Drivers\Aspi32.SYS
    0xA77B2000 \SystemRoot\System32\DRIVERS\srv.sys
    0xF7A07000 \SystemRoot\System32\Drivers\MCSTRM.SYS
    0xA7C72000 \SystemRoot\system32\drivers\npf.sys
    0xB9060000 \SystemRoot\system32\Drivers\LVPr2Mon.sys
    0xA6D21000 \??\C:\windows\system32\FsUsbExDisk.SYS
    0xB9058000 \SystemRoot\System32\Drivers\aswRdr.SYS
    0xA6BA8000 \SystemRoot\System32\Drivers\HTTP.sys
    0xB9068000 \??\C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\mbr.sys
    0x7C910000 \WINDOWS\system32\ntdll.dll

    Processes (total 52):
    0 System Idle Process
    4 SYSTEM
    856 C:\WINDOWS\system32\smss.exe
    920 csrss.exe
    944 C:\WINDOWS\system32\winlogon.exe
    988 C:\WINDOWS\system32\services.exe
    1000 C:\WINDOWS\system32\lsass.exe
    1172 C:\WINDOWS\system32\svchost.exe
    1236 svchost.exe
    1332 C:\WINDOWS\system32\svchost.exe
    1476 svchost.exe
    1620 C:\Program Files\Alwil Software\Avast5\afwServ.exe
    1840 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    188 C:\WINDOWS\explorer.exe
    268 C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    280 C:\Program Files\Logitech\iTouch\iTouch.exe
    288 C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
    312 C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    320 C:\Program Files\SuperCopier2\SuperCopier2.exe
    348 C:\Program Files\Skype\Phone\Skype.exe
    364 C:\Program Files\Internet Download Manager\IDMan.exe
    372 C:\WINDOWS\system32\ctfmon.exe
    444 C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
    484 F:\Weezo\bin\Weezo.exe
    756 C:\Program Files\Fichiers communs\LogiShrd\LQCVFX\COCIManager.exe
    1276 C:\WINDOWS\system32\spoolsv.exe
    2688 C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    2900 F:\Weezo\Apache\bin\weezoHttpd.exe
    3040 C:\WINDOWS\twain_32\SiPix\SCBLINK2\srvany.exe
    3052 C:\Program Files\Bonjour\mDNSResponder.exe
    3060 C:\WINDOWS\twain_32\SiPix\SCBLINK2\USBPNP.exe
    3084 C:\Program Files\Executive Software\Diskeeper\DkService.exe
    3304 C:\WINDOWS\system32\FsUsbExService.Exe
    3452 C:\Program Files\Java\jre6\bin\jqs.exe
    3536 C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    3868 C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    3956 F:\Weezo\Apache\bin\weezoHttpd.exe
    3972 C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\MDM.EXE
    4040 NMMediaServerService.exe
    3080 C:\Documents and Settings\All Users\Application Data\QuestBrowser\questbrowser117.exe
    3248 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    3260 C:\Program Files\QuestBrowser\questbrowser.exe
    3428 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    3512 C:\WINDOWS\system32\svchost.exe
    3556 C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
    4176 svchost.exe
    4460 alg.exe
    5184 C:\Program Files\Internet Download Manager\IEMonitor.exe
    5972 C:\Program Files\ZHPDiag\ZHPDiag.exe
    5404 C:\WINDOWS\system32\svchost.exe
    5556 C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
    5200 C:\Program Files\ZHPDiag\mbrcheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000'00007e00 (NTFS)
    \\.\F: --> \\.\PhysicalDrive0 at offset 0x00000018'69e59800 (NTFS)
    \\.\G: --> \\.\PhysicalDrive1 at offset 0x00000000'00007e00 (NTFS)

    PhysicalDrive0 Model Number: WDCWD3200AAJB-00J3A0, Rev: 01.03E01
    PhysicalDrive1 Model Number: Maxtor6Y080P0, Rev: YAR41BW0

    Size Device Name MBR Status
    --------------------------------------------
    298 GB \\.\PhysicalDrive0 Windows 98 MBR code detected
    SHA1: 48F01D7E76A0F3C038D08611E3FDC0EE4EF9FD3E
    76 GB \\.\PhysicalDrive1 Windows XP MBR code detected
    SHA1: 8637A6CD1F8DC55758E12C0B860CDE1133CA5719

    Done!
    0
  8. methafo
     
    Rapport de ZHPFix 1.12.32 par Nicolas Coolman, Update du 25/09/2010
    Fichier d'export Registre :
    Run by christian at 27/09/2010 14:48:29
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
    Contact : nicolascoolman@yahoo.fr

    ========== Récapitulatif ==========

    End of the scan
    0
  9. methafo
     
    Rapport de ZHPDiag v1.26.67 par Nicolas Coolman, Update du 25/09/2010
    Run by christian at 27/09/2010 18:38:44
    Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
    Contact : nicolascoolman@yahoo.fr

    ---\\ Web Browser
    MSIE: Internet Explorer v8.0.6001.18702
    MFIE: Mozilla Firefox (3.0.5)
    MFIE: Mozilla Firefox (3.6)
    MFIE: Mozilla Firefox 4.0b6 (x86 fr)

    ---\\ System Information
    Platform : Microsoft Windows XP (5.1.2600) Service Pack 3
    Processor: x86 Family 15 Model 3 Stepping 3, GenuineIntel
    Operating System: 32 Bits
    Boot mode: Normal (Normal boot)
    Total RAM: 2047 MB (58% free)
    System drive C: has 42 GB (43%) free of 98 GB

    ---\\ Logged in mode
    Computer Name: CHRIS
    User Name: christian
    All Users Names: SUPPORT_388945a0, NeroMediaHomeUser.4, LogMeInRemoteUser, HelpAssistant, christian, ASPNET, Administrateur,
    Unselected Option: None
    Logged in as Administrator

    ---\\ DOS/Devices
    C:\ Hard drive, Flash drive, Thumb drive (Free 42 Go of 98 Go)
    D:\ CD-ROM drive (Not Inserted)
    E:\ CD-ROM drive (Not Inserted)
    F:\ Hard drive, Flash drive, Thumb drive (Free 185 Go of 200 Go)
    G:\ Hard drive, Flash drive, Thumb drive (Free 61 Go of 76 Go)

    ---\\ Security Center & Tools Informations
    [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
    [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableTaskMgr: OK

    ---\\ Processus lancés
    [MD5.8408B80B5D1927D5063E1250EA5D9A78] - (.AVAST Software - avast! firewall service.) -- C:\Program Files\Alwil Software\Avast5\afwServ.exe [119200]
    [MD5.ACB544D7254F366DFB48F380BC36CD25] - (.AVAST Software - avast! Service.) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384]
    [MD5.4B5AE15E5C73EB4DC8DBEC2788230D41] - (.Apple Inc. - Apple Mobile Device Service.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [144672]
    [MD5.C9B18ABE9063A33E77F6BE81CC8DF0C5] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\twain_32\SiPix\SCBlink2\Srvany.exe [13312]
    [MD5.3F56903E124E820AEECE6D471583C6C1] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [238888]
    [MD5.2CD4EDA088A2292F4D1412A61A659F87] - (.NuCam Corp. - USBPNP.) -- C:\WINDOWS\twain_32\SiPix\SCBlink2\USBPNP.exe [26624]
    [MD5.E24C73D3BA872CA385E52739EE7BD10B] - (.Executive Software International, Inc. - DKSERVICE.EXE.) -- C:\Program Files\Executive Software\Diskeeper\DkService.exe [241664]
    [MD5.D3F9205CC4CB07553F2F9472C767EA87] - (.Teruten - FsUsbDevice.) -- C:\windows\system32\FsUsbExService.Exe [233472]
    [MD5.74E30A41CDCF331C74BC4D97BE40CC5B] - (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) -- C:\Program Files\Java\jre6\bin\jqs.exe [153376]
    [MD5.583B7D111304BE63D7D9CB65482D2187] - (.InstallShield Software Corporation - InstallShield Update Service Scheduler.) -- C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe [81920]
    [MD5.9AEE9BCB32D82BCC36474EB921F3BB49] - (.Logitech Inc. - iTouch Application.) -- C:\Program Files\Logitech\iTouch\iTouch.exe [892928]
    [MD5.53710476495886D9961BE46983A6A33F] - (.Hewlett-Packard Company - LightScribe Service.) -- C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe [79136]
    [MD5.2589FFE360BED8F824CBC6171CB5B874] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2793304]
    [MD5.6C1B31F5C16E03153F0037AC6C451FFD] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\avastUI.exe [2838912]
    [MD5.F6987FF6C6D683F79FDCE707B071A997] - (.SFX TEAM - SuperCopier 2 (explorer file copy replaceme.) -- C:\Program Files\SuperCopier2\SuperCopier2.exe [955392]
    [MD5.6FBBB73BE9FB38389AB73F38828A9CAC] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe [13351304]
    [MD5.0DDFDCAA92C7F553328DB06BA599BEA9] - (.Logitech Inc. - Logitech LVPrcSrv Module..) -- C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe [154136]
    [MD5.B41C51512AC95B3ADB11FF2A42006C83] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe [3220912]
    [MD5.11F714F85530A2BD134074DC30E99FCA] - (.Microsoft Corporation - Machine Debug Manager.) -- C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe [322120]
    [MD5.3B33BF4A13228EEC2670CF77B157C95F] - (.Pas de propriétaire - WG111v2 MFC Application.) -- C:\Program Files\NETGEAR\WG111v2\WG111v2.exe [1261568]
    [MD5.E5D5672572FD3A8AE672E0C5F43CF009] - (.Peer 2 World - Weezo UI.) -- F:\Weezo\bin\Weezo.exe [2342912]
    [MD5.98D472ECFBC0E8ED25A0483E765F42B6] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe [560472]
    [MD5.5334D3450B55FC929D50143F530597F0] - (.Apache Software Foundation - Apache HTTP Server.) -- F:\Weezo\Apache\bin\WeezoHttpd.exe [24645]
    [MD5.3978F082274F723AD5A0A8058C2417DD] - (.Analog Devices, Inc. - SoundMAX service agent component.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [45056]
    [MD5.F13DA74969897359A88F2A739F54A250] - (.Ulead Systems, Inc. - ULCDRSvr.) -- C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe [49152]
    [MD5.207B16FA69F61D1895F8D8532F587E4B] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe [263600]
    [MD5.1DD5E27417C3091D46C85563B48DD3C0] - (.IncrediMail, Ltd. - IncrediMail Application.) -- C:\Program Files\IncrediMail\bin\IncMail.exe [353736]
    [MD5.5A1C2D280D559844A517EAB580BB8F2A] - (.IncrediMail, Ltd. - IncrediMail Tray Application.) -- C:\Program Files\IncrediMail\bin\IMApp.exe [255432]
    [MD5.709EC7080A88406A393C925AF6749C76] - (.Mozilla Corporation - Firefox.) -- c:\program files\Mozilla Firefox 4.0 Beta 4\firefox.exe [923096]
    [MD5.06686A290FE2BB0F55D5D921D63A193E] - (.Mozilla Corporation - Plugin Container for Firefox.) -- c:\program files\Mozilla Firefox 4.0 Beta 4\plugin-container.exe [15320]
    [MD5.384D2C6B22C1F9AEC8B4DD5FB0E0A717] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [555008]

    ---\\ Page de démarrage de Mozilla Firefox (M0)
    M0 - MFSP: prefs.js [christian - cxci8hgi.default] https://start.mozilla.org/fr/

    ---\\ Programmes d'extension pour Mozilla Firefox (M2)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\CompactMenuCE@Merci.chao] [personalmenu] Personal Menu 4.3.2 (.Merci chao.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{0b38152b-1b20-484d-a11f-5e04a9b0661f}] [] Winamp Toolbar 4.3.2 (.AOL LLC.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{0b457cAA-602d-484a-8fe7-c1d894a011ba}] [] FireShot 0.80 (.Eugene G. Suslikov.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{1392b8d2-5c05-419f-a8f6-b9f15a596612}] [] Freecorder Toolbar 2.5.6.0 (.Conduit Ltd..)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{20a82645-c095-46ed-80e3-08825760534b}] [MicrosoftCG] Microsoft .NET Framework Assistant 2.5.6.0 (.Microsoft.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{37E4D8EA-8BDA-4831-8EA1-89053939A250}(2)] [] PDF Download 3.0.0.0 (.Nitro PDF, Inc..)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{3DB3D228-A2E9-4581-B400-CE1331C5269E}] [] EasyPrediction 2.0.0.0 (.Nitro PDF, Inc..)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{4daac69c-cba7-45e2-9bc8-1044483d3352}] [] Softonic_France Toolbar 2.5.8.6 (.Conduit Ltd..)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{57068FBE-1506-42ee-AB02-BD183E7999E4}] [] Compact Menu 2 2.5.8.6 (.Milly.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{6226BA26-C017-4007-928C-DE9715C6FA67}] [] Blingee Toolbar"> 2.5.8.6 (.Milly.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{635abd67-4fe9-1b23-4f01-e679fa7484c1}] [yahoo.ytff] Yahoo! Toolbar 1.5.4.20081105 (.Yahoo!.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{9b339f6e-ddcd-401b-8764-230adbd01761}] [] Messenger Plus Live Toolbar 2.5.4.7 (.Conduit Ltd..)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)] [dwhelper] DownloadHelper 4.6.2 (.Michel Gutierrez.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{fae389d5-e97e-4abd-8242-d9080c709167}] [] fullscreensavers Toolbar 2.5.6.0 (.Conduit Ltd..)

    ---\\ Plugins de navigateurs Opera/Firefox(P1/P2)
    P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files\Mozilla Firefox\Plugins\np-mswmp.dll
    P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeploytk.dll
    P2 - FPN:Firefox Plugin Navigator . (.mozilla.org - Default Plug-in.) -- C:\Program Files\Mozilla Firefox\Plugins\npnul32.dll
    P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 8.2.4.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin.dll
    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin2.dll
    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin3.dll
    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin4.dll
    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin5.dll
    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin6.dll
    P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\windows\system32\Macromed\Flash\NPSWF32.dll
    P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Pas de propriétaire - Pas de description.) -- F:\iTunes\Mozilla Plugins\npitunes.dll
    P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
    P2 - FPN: [HKLM] [@google.com/npPicasa3,version=3.0.0] - (.Google, Inc. - Picasa plugin.) -- F:\Installation Picassa 3\Google\Picasa3\npPicasa3.dll
    P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.50826.0.) -- C:\Program Files\Microsoft Silverlight\4.0.50826.0\npctrl.dll
    P2 - FPN: [HKLM] [@microsoft.com/OfficeLive,version=1.3] - (.Microsoft Corp. - Office Live Update v1.3.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll
    P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    P2 - FPN: [HKLM] [@pack.google.com/Google Updater;version=13] - (.Google - Google Updater plugin<br><a href="http://pack.google.com/">http://pack.) -- C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
    P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=8] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
    P2 - FPN: [HKLM] [@videolan.org/vlc,version=1.1.0] - (.the VideoLAN Team - Version 1.1.0, copyright 1996-2010 The VideoLAN Team<br><a href="http:.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll
    P2 - FPN: [HKCU] [@adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

    ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
    F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

    ---\\ Pages de démarrage d'Internet Explorer (R0)
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr

    ---\\ Pages de recherche d'Internet Explorer (R1)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    ---\\ Internet Explorer URLSearchHook (R3)
    R3 - URLSearchHook: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} . (.Conduit Ltd. - Conduit Toolbar.) (5, 2, 3, 1) -- C:\Program Files\P2P_Energy\tbP2P0.dll
    R3 - URLSearchHook: P2P Energy Toolbar - {fae389d5-e97e-4abd-8242-d9080c709167} . (.Conduit Ltd. - Conduit Toolbar.) (5, 3, 2, 0) -- C:\Program Files\fullscreensavers\tbfull.dll
    R3 - URLSearchHook: P2P Energy Toolbar - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (8.00.6001.18939 (longhorn_ie8_gdr.100616-1700)) -- C:\WINDOWS\system32\ieframe.dll
    R3 - URLSearchHook: P2P Energy Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} . (.Conduit Ltd. - Conduit Toolbar.) (5, 7, 3, 1) -- C:\Program Files\Freecorder\tbFre0.dll

    ---\\ Browser Helper Objects de navigateur (O2)
    O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Tonec Inc. - IDM BHO Module.) -- C:\Program Files\Internet Download Manager\IDMIECC.dll
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\Freecorder\tbFre0.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} . (.Microsoft Corporation - Search Helper for Internet Explorer.) -- C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Messenger Plus Live Toolbar - {9b339f6e-ddcd-401b-8764-230adbd01761} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\Messenger_Plus_Live\tbMess.dll
    O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} . (.Babylon Ltd. - Babylon Internet Explorer Addin.) -- F:\Babylon\Utils\BabylonIEPI.dll
    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Skype Technologies S.A. - Skype add-on for IE.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} . (.Sun Microsystems, Inc. - Java(TM) Quick Starter binary.) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} . (.SEIKO EPSON CORPORATION - EPSON Web-To-Page.) -- C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} . (.SpeedBit Ltd. - Download Accelerator Plus (DAP) MSIE Loader.) -- C:\PROGRA~1\DAP\dapieloader.dll

    ---\\ Internet Explorer Toolbars (O3)
    O3 - Toolbar: FireShot - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} . (.Pas de propriétaire - FSAddin Module.) -- C:\Documents and Settings\christian\Application Data\Mozilla\Firefox\Profiles\cxci8hgi.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fsaddin-0.80.dll
    O3 - Toolbar: Messenger Plus Live Toolbar - {9b339f6e-ddcd-401b-8764-230adbd01761} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\Messenger_Plus_Live\tbMess.dll
    O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} . (.PilotGroup LLC - SaveFlash.) -- C:\Program Files\Save Flash\SaveFlash.dll
    O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\Freecorder\tbFre0.dll
    O3 - Toolbar: (no name) - {1E796980-9CC5-11D1-A83F-00C04FC99D61} . (.Pas de propriétaire - Pas de description.) -- (.not file.)

    ---\\ Applications démarrées par registre & par dossier (O4)
    O4 - HKLM\..\Run: [ISUSPM Startup] . (.InstallShield Software Corporation - InstallShield Update Service Update Manager.) -- C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe
    O4 - HKLM\..\Run: [ISUSScheduler] . (.InstallShield Software Corporation - InstallShield Update Service Scheduler.) -- C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    O4 - HKLM\..\Run: [zBrowser Launcher] . (.Logitech Inc. - iTouch Application.) -- C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
    O4 - HKLM\..\Run: [avast5] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\avastUI.exe
    O4 - HKCU\..\Run: [SuperCopier2.exe] . (.SFX TEAM - SuperCopier 2 (explorer file copy replaceme.) -- C:\Program Files\SuperCopier2\SuperCopier2.exe
    O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe
    O4 - HKCU\..\Run: [AnnivJ] . (.http://www.kiteatao.net/standard.view?idMenu=2.1.1 - email: annivj@ - Annonce le jour J des anniversaires de vos.) -- C:\Program Files\AnnivJ\AnnivJ.exe
    O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe
    O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\windows\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
    O4 - HKUS\S-1-5-21-1220945662-1303643608-682003330-1012-1220945662-1303643608-682003330-1004\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Démarrage\NETGEAR WG111v2 Smart Wizard.lnk . (.Pas de propriétaire.) -- C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
    O4 - Global Startup: C:\Documents And Settings\christian\Menu Démarrer\Programmes\Démarrage\Weezo.lnk . (.Peer 2 World.) -- F:\Weezo\bin\Weezo.exe

    ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
    O8 - Extra context menu item: &Clean Traces . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
    O8 - Extra context menu item: &Download with &DAP . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\DAP\dapextie.htm
    O8 - Extra context menu item: Add to Google Photos Screensa&ver . (.Google Inc. - Google Photos Screensaver.) -- C:\windows\system32\GPhotos.scr
    O8 - Extra context menu item: Download &all with DAP . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\DAP\dapextie2.htm
    O8 - Extra context menu item: Download Video by Free YouTuBe Utility . (.Pas de propriétaire - Pas de description.) -- F:\Free YouTuBe Utility\IEydown.htm
    O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.exe
    O8 - Extra context menu item: Personnaliser . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\options.htm
    O8 - Extra context menu item: Rechercher sur Internet . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\search.htm
    O8 - Extra context menu item: Traduire . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\translat.htm
    O8 - Extra context menu item: Traduire dans R-Express . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\wts.htm
    O8 - Extra context menu item: Traduire dans WebView . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\webview.htm
    O8 - Extra context menu item: Traduire la page . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\page.htm
    O8 - Extra context menu item: Translate this web page with Babylon . (.Babylon Ltd. - Babylon Internet Explorer Addin.) -- F:\Babylon\Utils\BabylonIEPI.dll
    O8 - Extra context menu item: Translate with Babylon . (.Babylon Ltd. - Babylon Internet Explorer Addin.) -- F:\Babylon\Utils\BabylonIEPI.dll
    O8 - Extra context menu item: Télécharger avec IDM . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Internet Download Manager\IEExt.htm
    O8 - Extra context menu item: Télécharger avec IDM des videos FLV parmi les 10 dernières demandées . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Internet Download Manager\IEGetVL2.htm
    O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Internet Download Manager\IEGetVL.htm
    O8 - Extra context menu item: Télécharger tous les liens avec IDM . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Internet Download Manager\IEGetAll.htm

    ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
    O9 - Extra button: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\promt1.ico
    O9 - Extra 'Tools' menuitem: Personnalisez traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} . (.not file.) - (.not file.)
    O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~1\MICROS~2\OFFICE11\REFBARH.ICO
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.not file.) - (.not file.)
    O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} . (.Babylon Ltd. - Babylon Internet Explorer Addin.) -- F:\Babylon\Utils\BabylonIEPI.dll

    ---\\ Winsock hijacker (Layered Service Provider) (O10)
    O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\windows\system32\mswsock.dll
    O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\windows\system32\winrnr.dll
    O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\windows\system32\mswsock.dll
    O10 - WLSP:\000000000004\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll

    ---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
    O15 - Trusted Zone: [HKCU\...\Domains] http.localhost
    O15 - Trusted Zone: [HKCU\...\Domains\www] http.localhost

    ---\\ Objets ActiveX (Downloaded Program Files)(O16)
    O16 - DPF: Microsoft XML Parser for Java (Microsoft XML Parser for Java) - (.not file.) - file:\\C:\WINDOWS\Java\classes\xmldso.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} () - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    ---\\ Modification Domaine/Adresses DNS (O17)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{05F2DD38-00C2-4B02-82ED-E7D4262CBD04}: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C51E8F15-1EE2-4BFE-A8ED-856AFD57C1E8}: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{05F2DD38-00C2-4B02-82ED-E7D4262CBD04}: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{C51E8F15-1EE2-4BFE-A8ED-856AFD57C1E8}: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CS3\Services\Tcpip\..\{05F2DD38-00C2-4B02-82ED-E7D4262CBD04}: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CS3\Services\Tcpip\..\{C51E8F15-1EE2-4BFE-A8ED-856AFD57C1E8}: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1

    ---\\ Protocole additionnel et piratage de protocole (O18)
    O18 - Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} . (.Logitech Inc. - Logitech Desktop Messenger.) -- C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} . (.Skype Technologies S.A. - Skype add-on for IE.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O18 - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} . (.Skype Technologies - Skype for COM API.) -- C:\PROGRA~1\FICHIE~1\Skype\Skype4COM.dll

    ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
    O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\windows\System32\dimsntfy.dll
    O20 - Winlogon Notify: WgaLogon . (.Microsoft Corporation - Notifications Windows Genuine Advantage.) -- C:\windows\System32\WgaLogon.dll

    ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
    O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\windows\system32\SHELL32.dll
    O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\windows\system32\SHELL32.dll
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
    O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\System32\stobject.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\windows\system32\WPDShServiceObj.dll

    ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
    O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\windows\System32\browseui.dll

    ---\\ Liste des services NT non Microsoft et non désactivés (O23)
    O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - Apple Mobile Device Service.) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Firewall (avast! Firewall) . (.AVAST Software - avast! firewall service.) - C:\Program Files\Alwil Software\Avast5\afwServ.exe
    O23 - Service: Blink2PnP (Blink2PnP) . (.Pas de propriétaire - Pas de description.) - C:\WINDOWS\twain_32\SiPix\SCBlink2\Srvany.exe
    O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Diskeeper (Diskeeper) . (.Executive Software International, Inc. - DKSERVICE.EXE.) - C:\Program Files\executive Software\Diskeeper\DkService.exe
    O23 - Service: FsUsbExService (FsUsbExService) . (.Teruten - FsUsbDevice.) - C:\windows\system32\FsUsbExService.exe
    O23 - Service: Google Update Service (gupdate1c98769f00cfd4e) (gupdate1c98769f00cfd4e) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) . (.Google - gusvc.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) . (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) . (.Hewlett-Packard Company - LightScribe Service.) - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: Process Monitor (LVPrcSrv) . (.Logitech Inc. - Logitech LVPrcSrv Module..) - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: Nero MediaHome 4 Service (NeroMediaHomeService.4) . (.Nero AG - Nero MediaHome.) - F:\Néro MédiaHome 4\Nero MediaHome 4\NMMediaServerService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 178.2.) - C:\windows\system32\nvsvc32.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) . (.Analog Devices, Inc. - SoundMAX service agent component.) - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) . (.Ulead Systems, Inc. - ULCDRSvr.) - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe

    ---\\ Enumération Active Desktop & MHTML Editor (O24)
    O24 - Desktop General: BackupWallPaper - .(.Pas de propriétaire - Pas de description.) - C:\windows\webshots.bmp
    O24 - Desktop General: WallPaper - .(.Pas de propriétaire - Pas de description.) - C:\windows\webshots.bmp
    O24 - Default MHTML Editor: Last - .(.Pas de propriétaire - Pas de description.) - C:\Program Files\Microsoft Office\Office10\WINWORD.exe (.not file.)

    ---\\ Tâches planifiées en automatique (O39)
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\Ad-Aware Update (Weekly).job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\AppleSoftwareUpdate.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\AWC AutoSweep.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\Google Software Updater.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\Programme d'arrêt du système de l'onduleur.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\SpeedOptimizer Startup.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\User_Feed_Synchronization-{6C9EA0D2-CA42-477D-A069-8FC758E39ECE}.job

    ---\\ Composants installés (ActiveSetup Installed Components) (O40)
    O40 - ASIC: (no name) - >{0fa2357c-b1e7-4386-859a-8e7459641c1b} . (.Pas de propriétaire - Pas de description.) -- RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
    O40 - ASIC: LightScribe Control Panel - {10880D85-AAD9-4558-ABDC-2AB1552D831F} . (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files\Fichiers communs\LightScribe\LSRunOnce.exe
    O40 - ASIC: Macromedia Shockwave Director 10.1 - {166B1BCA-3F9C-11CF-8075-444553540000} . (.Adobe Systems, Inc. - Shockwave ActiveX Control.) -- C:\WINDOWS\system32\macromed\Director\SwDir.dll
    O40 - ASIC: Adobe Shockwave Director 10.2 - {233C1507-6A77-46A4-9443-F871F945D258} . (.Adobe Systems, Inc. - Shockwave ActiveX Control.) -- C:\WINDOWS\system32\Macromed\Director\SwDir.dll
    O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msnetmtg.inf
    O40 - ASIC: Windows Messenger 4.7 - {5945c046-1e7d-11d1-bc44-00c04fd912be} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msmsgs.inf
    O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Pas de propriétaire - Pas de description.) -- C:\windows\INF\wmp11.inf
    O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11cf-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 10.1 r53.) -- C:\windows\system32\Macromed\Flash\Flash10h.ocx

    ---\\ Pilotes lancés au démarrage (O41)
    O41 - Driver: Orb Virtual Cable (OrbVirtualCable) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\orbvckmd.sys

    ---\\ Logiciels installés (O42)
    O42 - Logiciel: 123 PDF to Image v1.4 - (.FreePDFtoImage.com.) [HKLM] -- 123 PDF to Image_is1
    O42 - Logiciel: ABBYY FineReader 6.0 Sprint - (.ABBYY Software House.) [HKLM] -- {ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
    O42 - Logiciel: ACDSee 5.0 Standard Trial - (.ACD Systems Ltd.) [HKLM] -- {7FFADA6F-9A46-4D80-8400-8D3B77C62908}
    O42 - Logiciel: Active GIF Creator 3.3 - (.Pas de propriétaire.) [HKLM] -- Active GIF Creator 3.3
    O42 - Logiciel: Add-in ODF pour Microsoft Word - (.Clever Age.) [HKLM] -- {8D774B5B-A1D9-45B3-AFB4-3F85604961BC}
    O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
    O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
    O42 - Logiciel: Adobe Photoshop CS - (.Adobe Systems, Inc..) [HKLM] -- {EFB21DE7-8C19-4A88-BB28-A766E16493BC}
    O42 - Logiciel: Adobe Reader 8.2.4 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A82000000003}
    O42 - Logiciel: Adobe Shockwave Player - (.Adobe Systems, Inc..) [HKLM] -- Adobe Shockwave Player
    O42 - Logiciel: Advanced Pdf to Word Converter 6.2 - (.Officeconvert Software, Inc..) [HKLM] -- Advanced Pdf to Word Converter_is1
    O42 - Logiciel: Advertising Center - (.Nero AG.) [HKLM] -- {B2EC4A38-B545-4A00-8214-13FE0E915E6D}
    O42 - Logiciel: AnmanieSMP 2.4 i - (.Christoph Walter.) [HKLM] -- AnmanieSMP_is1
    O42 - Logiciel: AnnivJ 2.0.0 - (.KiteAtao.) [HKLM] -- AnnivJ
    O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {3FA365DF-2D68-45ED-8F83-8C8A33E65143}
    O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
    O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {6956856F-B6B3-4BE0-BA0B-8F495BE32033}
    O42 - Logiciel: Archiveur WinRAR - (.Pas de propriétaire.) [HKLM] -- WinRAR archiver
    O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM] -- {D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
    O42 - Logiciel: Awesome Waves - (.Pas de propriétaire.) [HKLM] -- Awesome Waves
    O42 - Logiciel: Babylon - (.Babylon.) [HKLM] -- Babylon
    O42 - Logiciel: Bear Celebrates Free Screensaver 1.12 - (.Pas de propriétaire.) [HKLM] -- Bear Celebrates Free Screensaver_is1
    O42 - Logiciel: Bibliothèques GTK+ 2.14.7 rev a (supprimer uniquement) - (.Pas de propriétaire.) [HKLM] -- GTK 2.0
    O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {07287123-B8AC-41CE-8346-3D777245C35B}
    O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
    O42 - Logiciel: CDex extraction audio - (.Pas de propriétaire.) [HKLM] -- CDex
    O42 - Logiciel: Caricatures PRO [4.4.0.1] - (.Marseillesoft.) [HKLM] -- Caricatures PRO_is1
    O42 - Logiciel: CartaGoGo v3.1.8 - (.Generation Software.) [HKLM] -- CartaGoGo v3.1.8_is1
    O42 - Logiciel: Chinese Simplified Fonts Support For Adobe Reader 8 - (.Adobe Systems.) [HKLM] -- {AC76BA86-7AD7-2447-0000-800000000003}
    O42 - Logiciel: Codeur Windows Media Série 9 - (.Microsoft Corporation.) [HKLM] -- {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
    O42 - Logiciel: Codeur Windows Media Série 9 - (.Pas de propriétaire.) [HKLM] -- Windows Media Encoder 9
    O42 - Logiciel: Coffret de pilotes Logitech Webcam Software - (.Logitech Inc..) [HKLM] -- lvdrivers_12.10
    O42 - Logiciel: Coloriage 2 - (.Pas de propriétaire.) [HKLM] -- Coloriage 2
    O42 - Logiciel: Compatibility Pack for the 2007 Office system - (.Microsoft Corporation.) [HKLM] -- {90120000-0020-0409-0000-0000000FF1CE}
    O42 - Logiciel: DFX for Windows Media Player - (.Power Technology.) [HKLM] -- {f1990716-8ee0-4c3e-8ebd-84026f3a09d5}
    O42 - Logiciel: DJ Pofessionnel 2008 7.3.2.2 - (.Marseillesoft.) [HKLM] -- DJ Professionnel 2008_is1
    O42 - Logiciel: DVD Shrink 3.2 - (.DVD Shrink.) [HKLM] -- DVD Shrink_is1
    O42 - Logiciel: Desktop Graffitist - (.Pas de propriétaire.) [HKLM] -- Desktop Graffitist
    O42 - Logiciel: DiapoPat v4.9 - (.LucVil.) [HKLM] -- DiapoPat v4.9_is1
    O42 - Logiciel: Diskeeper Professional Edition - (.Executive Software.) [HKLM] -- {A320805E-26CE-4332-9239-2F4837165C8B}
    O42 - Logiciel: DolbyFiles - (.Nero AG.) [HKLM] -- {B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}
    O42 - Logiciel: Download Accelerator Plus (DAP) - (.Speedbit Ltd..) [HKLM] -- Download Accelerator Plus (DAP)
    O42 - Logiciel: EPSON Attach To Email - (.Pas de propriétaire.) [HKLM] -- InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}
    O42 - Logiciel: EPSON Printer Software - (.Pas de propriétaire.) [HKLM] -- EPSON Printer and Utilities
    O42 - Logiciel: EPSON Scan - (.Pas de propriétaire.) [HKLM] -- EPSON Scanner
    O42 - Logiciel: ESCX3700 User's Guide - (.Pas de propriétaire.) [HKLM] -- ESCX3700 User's Guide
    O42 - Logiciel: ESET Online Scanner v3 - (.Pas de propriétaire.) [HKLM] -- ESET Online Scanner
    O42 - Logiciel: EZ-DUB - (.Pas de propriétaire.) [HKLM] -- EZ-DUB5.0.1
    O42 - Logiciel: EasyPrediction - (.EasyPrediction Ltd..) [HKLM] -- EasyPrediction
    O42 - Logiciel: EnveloppesEditor1.09 - (.J.L.F..) [HKLM] -- EnveloppesEditor1.09_is1
    O42 - Logiciel: EnveloppesEditor1.10 - (.J.L.F..) [HKLM] -- EnveloppesEditor1.10_is1
    O42 - Logiciel: Etats Et Requêtes - (.Pas de propriétaire.) [HKLM] -- Etats Et Requêtes
    O42 - Logiciel: Extended Online Call for Skype - (.EBS SkypeTools.) [HKCU] -- 21e31c10007f8a6a
    O42 - Logiciel: Extension de Windows Live Toolbar (Windows Live Toolbar) - (.Microsoft Corporation.) [HKLM] -- {0CA6047C-D28B-4295-834A-07C52BA20C2D}
    O42 - Logiciel: FastCipher - (.Pas de propriétaire.) [HKLM] -- FastCipher_is1
    O42 - Logiciel: FixMessenger - (.Pas de propriétaire.) [HKLM] -- FixMessenger
    O42 - Logiciel: Flash Saving Plugin - (.UnH Solutions.) [HKLM] -- {6D74E1F4-32D5-44D0-9054-8D57E981F59F}_is1
    O42 - Logiciel: Font Explorer v.1.2 - (.Ivan BUBLOZ.) [HKLM] -- Font Explorer_is1
    O42 - Logiciel: Free Mp3 Wma Converter V 1.7.3 - (.Koyote Soft.) [HKLM] -- Free Mp3 Wma Converter_is1
    O42 - Logiciel: Free Video Converter V 2.9 - (.Koyote Soft.) [HKLM] -- Free Video Converter_is1
    O42 - Logiciel: Free YouTuBe Utility 1.42 - (.Free-YouTuBe.com, Inc..) [HKLM] -- Free YouTuBe Utility_is1
    O42 - Logiciel: Freecorder Toolbar - (.Pas de propriétaire.) [HKLM] -- Freecorder Toolbar
    O42 - Logiciel: Freecorder Toolbar 3.02 Application - (.Applian Technologies Inc..) [HKLM] -- Freecorder Toolbar3.02
    O42 - Logiciel: FrostWire 4.17.2 - (.FrostWire, LLC.) [HKLM] -- FrostWire
    O42 - Logiciel: GIMP 2.6.9 - (.The GIMP Team.) [HKLM] -- WinGimp-2.0_is1
    O42 - Logiciel: Gommettes Version A - (.Pas de propriétaire.) [HKCU] -- Gommettes Version A
    O42 - Logiciel: GoodFrame - (.FDSoftware.) [HKLM] -- GoodFrame_is1
    O42 - Logiciel: GoodFrame - (.FDSoftware.) [HKLM] -- {10A19812-24CD-4AC4-A775-8AD8DE7E610C}
    O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome
    O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM] -- {DBEA1034-5882-4A88-8033-81C4EF0CFA29}
    O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
    O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {4286E640-B5FB-11DF-AC4B-005056C00008}
    O42 - Logiciel: Heures du Monde - (.Olivier RAVET.) [HKLM] -- Heures du Monde_is1
    O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
    O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
    O42 - Logiciel: Hotfix for Windows Media Format 11 SDK (KB929399) - (.Microsoft Corporation.) [HKLM] -- KB929399
    O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5
    O42 - Logiciel: Image Mender 1.2 - (.Phibit Software.) [HKLM] -- Image Mender
    O42 - Logiciel: IncrediMail - (.IncrediMail.) [HKLM] -- {5E97F3BD-CDDC-4188-9D98-532E14FABB5D}
    O42 - Logiciel: IncrediMail 2.0 - (.IncrediMail Ltd..) [HKLM] -- IncrediMail
    O42 - Logiciel: IncrediMail JunkFilter Plus - (.IncrediMail Ltd..) [HKLM] -- JunkFilterPlus
    O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
    O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- {133742BA-6F46-4D3E-85AF-78631D9AD8B8}
    O42 - Logiciel: Internet Download Manager - (.Pas de propriétaire.) [HKLM] -- Internet Download Manager
    O42 - Logiciel: J2SE Runtime Environment 5.0 Update 10 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0150100}
    O42 - Logiciel: Java(TM) 6 Update 19 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216016FF}
    O42 - Logiciel: Java(TM) 6 Update 3 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160030}
    O42 - Logiciel: Java(TM) 6 Update 5 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160050}
    O42 - Logiciel: Java(TM) SE Runtime Environment 6 Update 1 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160010}
    O42 - Logiciel: JiJiPEG - (.HavingTools.) [HKLM] -- {704DD559-F3DC-4ACD-A4BF-05F8ACDB4ADE}
    O42 - Logiciel: JpegExpress - (.Pas de propriétaire.) [HKLM] -- JpegExpress_is1
    O42 - Logiciel: JunkFilterPlus - (.IncrediMail.) [HKLM] -- {DC754D8F-1D06-4016-BF57-8D21F97E1F0A}
    O42 - Logiciel: KC Softwares IDPhotoStudio - (.KC Softwares.) [HKLM] -- KC Softwares IDPhotoStudio_is1
    O42 - Logiciel: KaraFun 1.18 - (.Recisio.) [HKLM] -- KaraFun_is1
    O42 - Logiciel: LM 2.0 - (.Pas de propriétaire.) [HKLM] -- LM 2.0
    O42 - Logiciel: Lecteur Windows Media 11 - (.Pas de propriétaire.) [HKLM] -- Windows Media Player
    O42 - Logiciel: Logitech Updater - (.Nom de votre société.) [HKLM] -- {53735ECE-E461-4FD0-B742-23A352436D3A}
    O42 - Logiciel: Logitech Vid - (.Logitech Inc..) [HKLM] -- {4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}
    O42 - Logiciel: Logitech Webcam Software - (.Logitech Inc..) [HKLM] -- {C27BC2A2-30DD-4014-B22E-63EB0DB572F9}
    O42 - Logiciel: Logitech iTouch Software - (.Pas de propriétaire.) [HKLM] -- {036AA4D4-6D32-11D4-9875-00105ACE7734}
    O42 - Logiciel: MSN Toolbar - (.Microsoft Corporation.) [HKLM] -- {08234a0d-cf39-4dca-99f0-0c5cb496da81}
    O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
    O42 - Logiciel: MSXML 4.0 SP2 (KB936181) - (.Microsoft Corporation.) [HKLM] -- {C04E32E0-0416-434D-AFB9-6969D703A9EF}
    O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
    O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
    O42 - Logiciel: MSXML 4.0 SP2 Parser and SDK - (.Microsoft Corporation.) [HKLM] -- {716E0306-8318-4364-8B8F-0CC4E9376BAC}
    O42 - Logiciel: MULTIPLEjm 1.0 - (.Pas de propriétaire.) [HKLM] -- MULTIPLEjm
    O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
    O42 - Logiciel: MemAv - (.Pas de propriétaire.) [HKLM] -- MemAv_is1
    O42 - Logiciel: Menus intelligents (Windows Live Toolbar) - (.Microsoft Corporation.) [HKLM] -- {0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
    O42 - Logiciel: Messenger_Plus_Live Toolbar - (.Pas de propriétaire.) [HKLM] -- Messenger_Plus_Live Toolbar
    O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Microsoft.) [HKLM] -- {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Pas de propriétaire.) [HKLM] -- Microsoft .NET Framework 1.1 (1033)
    O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB979906) - (.Pas de propriétaire.) [HKLM] -- M979906
    O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
    O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
    O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
    O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
    O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
    O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM] -- MSCompPackV1
    O42 - Logiciel: Microsoft Internationalized Domain Names Mitigation APIs - (.Microsoft Corporation.) [HKLM] -- IDNMitigationAPIs
    O42 - Logiciel: Microsoft National Language Support Downlevel APIs - (.Microsoft Corporation.) [HKLM] -- NLSDownlevelMapping
    O42 - Logiciel: Microsoft Office 2003 Primary Interop Assemblies - (.Microsoft Corporation.) [HKLM] -- {91490409-6000-11D3-8CFE-0150048383C9}
    O42 - Logiciel: Microsoft Office Excel Viewer - (.Microsoft Corporation.) [HKLM] -- {95120000-003F-040C-0000-0000000FF1CE}
    O42 - Logiciel: Microsoft Office Live Add-in 1.3 - (.Microsoft Corporation.) [HKLM] -- {57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
    O42 - Logiciel: Microsoft Office Outlook Connector - (.Microsoft Corporation.) [HKLM] -- {95120000-0122-0409-0000-0000000FF1CE}
    O42 - Logiciel: Microsoft Office Outlook Connector - (.Microsoft Corporation.) [HKLM] -- {95120000-0122-040C-0000-0000000FF1CE}
    O42 - Logiciel: Microsoft Office Professional Edition 2003 - (.Microsoft Corporation.) [HKLM] -- {9011040C-6000-11D3-8CFE-0150048383C9}
    O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
    O42 - Logiciel: Microsoft Search Enhancement Pack - (.Microsoft Corporation.) [HKLM] -- {06E6E30D-B498-442F-A943-07DE41D7F785}
    O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
    O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- Wudf01000
    O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118}
    O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {7299052b-02a4-4627-81f2-1818da5d550d}
    O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {A49F249F-0C91-497F-86DF-B2585E8E76B7}
    O42 - Logiciel: Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
    O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 - (.Microsoft Corporation.) [HKLM] -- {FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
    O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
    O42 - Logiciel: Module de compatibilité pour Microsoft Office System 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0020-040C-0000-0000000FF1CE}
    O42 - Logiciel: Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 2.0 Language Pack - FRA
    O42 - Logiciel: Mozilla Firefox (3.6) - (.Mozilla.) [HKLM] -- Mozilla Firefox (3.6)
    O42 - Logiciel: Mozilla Firefox 4.0b6 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 4.0b6 (x86 fr)
    O42 - Logiciel: NVIDIA Drivers - (.Pas de propriétaire.) [HKLM] -- NVIDIA Drivers
    O42 - Logiciel: Nero 7 Essentials - (.Nero AG.) [HKLM] -- {3A2AA418-42ED-41A2-8A4E-D887E24B1036}
    O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM] -- {BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}
    O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM] -- {F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}
    O42 - Logiciel: Nero Installer - (.Nero AG.) [HKLM] -- {E8A80433-302B-4FF1-815D-FCC8EAC482FF}
    O42 - Logiciel: Nero MediaHome 4 - (.Nero AG.) [HKLM] -- {99EF387E-633E-4CFB-BFA3-AB961B685DDF}
    O42 - Logiciel: Nero MediaHome 4 Help - (.Nero AG.) [HKLM] -- {69FC3B9A-4149-43DB-A557-6ED0C8D8BA44}
    O42 - Logiciel: Notification de cadeaux MSN - (.Microsoft.) [HKCU] -- Notification de cadeaux MSN
    O42 - Logiciel: OLYMPUS USB Reader/Writer - (.OLYMPUS OPTICAL CO.,LTD..) [HKLM] -- InstallShield_{9DFC9A77-86B4-4139-A4CF-A5E774422D28}
    O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM] -- {205C6BDD-7B73-42DE-8505-9A093F35A238}
    O42 - Logiciel: P2P_Energy Toolbar - (.Pas de propriétaire.) [HKLM] -- P2P_Energy Toolbar
    O42 - Logiciel: PC Connectivity Solution - (.Nokia.) [HKLM] -- {AC599724-5755-48C1-ABE7-ABB857652930}
    O42 - Logiciel: PDF-Viewer - (.Tracker Software Products Ltd.) [HKLM] -- {8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1
    O42 - Logiciel: PDFCreator - (.Frank Heindörfer, Philip Chinery.) [HKLM] -- {0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}
    O42 - Logiciel: Package de pilotes Windows - MobileTop (sshpmdm) Modem (01/26/2008 2.6.0.0) - (.MobileTop.) [HKLM] -- E24870CB6AA1C3511635FF9020A3E9471287FBE7
    O42 - Logiciel: Package de pilotes Windows - Nokia pccsmcfd (10/12/2007 6.85.4.0) - (.Nokia.) [HKLM] -- 3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F
    O42 - Logiciel: Paysage Noel Screensaver - (.Pas de propriétaire.) [HKLM] -- Paysage Noel Screensaver
    O42 - Logiciel: PerfV350 Guide d'utilisation - (.Pas de propriétaire.) [HKLM] -- PerfV350 Guide d'utilisation
    O42 - Logiciel: Personal Key Manager - (.Pas de propriétaire.) [HKLM] -- Personal Key Manager
    O42 - Logiciel: PhotoMail Maker - (.IncrediMail Ltd..) [HKLM] -- PhotoMail
    O42 - Logiciel: PhotoMail Maker - (.Nom de votre société.) [HKLM] -- {75AE8014-1184-4BC0-B279-C879540719EE}
    O42 - Logiciel: Photorécit 3 pour Windows - (.Microsoft Corporation.) [HKLM] -- {4F41AD68-89F2-4262-A32C-2F70B01FCE9E}
    O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM] -- Picasa 3
    O42 - Logiciel: PowerCours 777 Version 3 (3/10/6) - (.Pas de propriétaire.) [HKLM] -- Cours777_is1
    O42 - Logiciel: PowerpointImageExtractor - (.Pas de propriétaire.) [HKLM] -- PowerpointImageExtractor_is1
    O42 - Logiciel: Quick Startup 2.8.0.718 - (.GlarySoft.com.) [HKLM] -- Quick Startup_is1
    O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
    O42 - Logiciel: Reader BPI - (.Editions BPI.) [HKLM] -- {053B9AAD-A638-4D23-A6B6-A2551C0C1098}
    O42 - Logiciel: Revo Uninstaller 1.89 - (.VS Revo Group.) [HKLM] -- Revo Uninstaller
    O42 - Logiciel: SAMSUNG Mobile Composite Device Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile Composite Device
    O42 - Logiciel: SAMSUNG Mobile Modem Driver Set - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile Modem
    O42 - Logiciel: SAMSUNG Mobile Modem V2 Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile Modem V2
    O42 - Logiciel: SAMSUNG Mobile USB Modem 1.0 Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile USB Modem 1.0
    O42 - Logiciel: SAMSUNG Mobile USB Modem Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile USB Modem
    O42 - Logiciel: SAMSUNG SYMBIAN USB Download Driver - (.SAMSUNG Electronics CO,.LTD.) [HKLM] -- {D8CE69B0-9274-4b8c-BA49-0FF6A20A3C65}
    O42 - Logiciel: SAMSUNG USB Mobile Device Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG USB Mobile Device
    O42 - Logiciel: SCTE - (.ZOverLord Creations.) [HKCU] -- 4b8680acbb23381d
    O42 - Logiciel: SWF Opener - (.UnH Solutions.) [HKLM] -- {01386D1F-ADE7-43B4-A4E9-312FC5BC726F}_is1
    O42 - Logiciel: SWF2EXE Converter V1.0 - (.ApecSoft Inc..) [HKLM] -- ApecSoft SWF2EXE Converter_is1
    O42 - Logiciel: Samsung Mobile Modem Device Software - (.Pas de propriétaire.) [HKLM] -- Samsung Mobile Modem Device
    O42 - Logiciel: Samsung Mobile phone USB driver Software - (.Pas de propriétaire.) [HKLM] -- Samsung Mobile phone USB driver
    O42 - Logiciel: Samsung New PC Studio - (.Samsung Electronics Co., Ltd..) [HKLM] -- InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}
    O42 - Logiciel: Samsung New PC Studio - (.Samsung Electronics Co., Ltd..) [HKLM] -- {F193FC0E-9E18-40FC-A974-509A1BDD240A}
    O42 - Logiciel: SamsungConnectivityCableDriver - (.Samsung.) [HKLM] -- {7E84FAC8-C518-40F9-9807-7455301D6D25}
    O42 - Logiciel: Save Flash 4.3 - (.PilotGroup Ltd.) [HKLM] -- Save Flash
    O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- KB931906
    O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- {0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM] -- {A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
    O42 - Logiciel: SendMe 1.0.2 - (.LedPC Application.) [HKLM] -- SendMe_is1
    O42 - Logiciel: SereneScreen Aquarium - (.Prolific Publishing, Inc..) [HKLM] -- SereneScreen Aquarium_is1
    O42 - Logiciel: Shape Collage - (.Shape Collage Inc..) [HKLM] -- ShapeCollage
    O42 - Logiciel: Shared Add-in Extensibility Update for Microsoft .NET Framework 2.0 (KB908002) - (.Microsoft.) [HKLM] -- {09959E11-AD5D-408E-96AF-E3346954D6B8}
    O42 - Logiciel: Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002) - (.Microsoft.) [HKLM] -- {64F3B15C-24C7-4B2B-9B72-65CCBBD7F06B}
    O42 - Logiciel: SiS 900 PCI Fast Ethernet Adapter Driver - (.Pas de propriétaire.) [HKLM] -- SiSLan
    O42 - Logiciel: Skype Toolbars - (.Skype Technologies S.A..) [HKLM] -- {981029E0-7FC9-4CF3-AB39-6F133621921A}
    O42 - Logiciel: Skype for Outlook 1.0.0.0 - (.Skype Technologies.) [HKLM] -- SkypeForOutlook_is1
    O42 - Logiciel: Skype(TM) 4.2 - (.Skype Technologies S.A..) [HKLM] -- {D103C4BA-F905-437A-8049-DB24763BBE36}
    O42 - Logiciel: Socusoft Photo To Video Converter Free Version 8.00 - (.www.socusoft.com.) [HKLM] -- Socusoft Photo To Video Converter Free Version_is1
    O42 - Logiciel: SpeedBit Toolbar - (.SpeedBit Ltd..) [HKLM] -- SpeedBit Toolbar
    O42 - Logiciel: SpeedBit Video Downloader - (.SpeedBit Ltd..) [HKLM] -- SpeedBit Video Downloader
    O42 - Logiciel: Spelling Dictionaries Support For Adobe Reader 8 - (.Adobe Systems.) [HKLM] -- {AC76BA86-7AD7-5464-3428-800000000003}
    O42 - Logiciel: Streaming Video Recorder V2.0.7 - (.Apowersoft.) [HKLM] -- {2CD65167-671F-49A3-B6C7-3B919DF028E2}_is1
    O42 - Logiciel: SuperCopier2 - (.Pas de propriétaire.) [HKLM] -- SuperCopier2
    O42 - Logiciel: Surligneur (Windows Live Toolbar) - (.Microsoft Corporation.) [HKLM] -- {81B5F83F-2291-48B0-8375-36B63A9BF5B0}
    O42 - Logiciel: Switch Sound File Converter - (.NCH Software.) [HKLM] -- Switch
    O42 - Logiciel: Todae - Live Media - (.Todae.fr.) [HKLM] -- Live Media
    O42 - Logiciel: Toolbar Uninstaller 1.0.0.1 - (.Decomputeur.nl.) [HKLM] -- Toolbar Uninstaller_is1
    O42 - Logiciel: UControl Scan and Remove - (.Pas de propriétaire.) [HKLM] -- UControl Scan and Remove
    O42 - Logiciel: Ultimate Christmas Scenic Reflections 3.0 - (.ScenicReflections.com.) [HKLM] -- Ultimate Christmas Scenic Reflections
    O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
    O42 - Logiciel: V.I.M. (remove only) - (.Pas de propriétaire.) [HKLM] -- V.I.M.
    O42 - Logiciel: VB Runtime - (.Pas de propriétaire.) [HKLM] -- VB Runtime
    O42 - Logiciel: VCRedistSetup - (.Nero AG.) [HKLM] -- {3921A67A-5AB1-4E48-9444-C71814CF3027}
    O42 - Logiciel: VDownloader 1.12 - (.Enrique Puertas.) [HKLM] -- {CA567AD5-33A4-403D-86D1-EE2D38251951}_is1
    O42 - Logiciel: VLC media player 1.1.0 - (.VideoLAN.) [HKLM] -- VLC media player
    O42 - Logiciel: Visual C++ 2008 x86 Runtime - (v9.0.30729) - (.Microsoft Corporation.) [HKLM] -- {F333A33D-125C-32A2-8DCE-5C5D14231E27}
    O42 - Logiciel: Visual C++ 2008 x86 Runtime - v9.0.30729.01 - (.Microsoft Corporation.) [HKLM] -- {F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01
    O42 - Logiciel: Visual C++ 9.0 ATL (x86) WinSXS MSM - (.Microsoft Corporation.) [HKLM] -- {CEC8F2E3-AC9A-357C-BFCB-BFAC37C4AC50}
    O42 - Logiciel: Visual C++ 9.0 CRT (x86) WinSXS MSM - (.Microsoft Corporation.) [HKLM] -- {0138F525-6C8A-333F-A105-14AE030B9A54}
    O42 - Logiciel: VolvoxSoft Convertisseur Video Son Volvox 1.2 - (.VolvoxSoft.) [HKLM] -- Convertisseur Video Son Volvox
    O42 - Logiciel: Vos Photos à la Télé sur CD-DVD Deluxe Evaluation - (.Micro Application.) [HKLM] -- Vos Photos à la Télé sur CD-DVD Deluxe Evaluation
    O42 - Logiciel: Weezo - (.Peer 2 World.) [HKLM] -- Weezo_is1
    O42 - Logiciel: Weezo DLL Pack (C:\Program Files\Weezo\) - (.Pas de propriétaire.) [HKLM] -- ST6UNST #2
    O42 - Logiciel: Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray - (.Microsoft Corporation.) [HKLM] -- KB952011
    O42 - Logiciel: Windows Genuine Advantage Notifications (KB905474) - (.Microsoft Corporation.) [HKLM] -- WgaNotify
    O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM] -- KB892130
    O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM] -- WGA
    O42 - Logiciel: Windows Genuine Advantage v1.3.0254.0 - (.Microsoft.) [HKLM] -- {63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
    O42 - Logiciel: Windows Imaging Component - (.Microsoft Corporation.) [HKLM] -- WIC
    O42 - Logiciel: Windows Internet Explorer 7 - (.Microsoft Corporation.) [HKLM] -- ie7
    O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM] -- ie8
    O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {B3B487E7-6171-4376-9074-B28082CEB504}
    O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {3175E049-F9A9-4A3D-8F19-AC9FB04514D1}
    O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {445B183D-F4F1-45C8-B9DB-F11355CA657B}
    O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11
    O42 - Logiciel: Windows Media Format 11 runtime - (.Pas de propriétaire.) [HKLM] -- Windows Media Format Runtime
    O42 - Logiciel: Windows Media Player Firefox Plugin - (.Microsoft Corp.) [HKLM] -- {69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
    O42 - Logiciel: Windows XP Service Pack 3 - (.Microsoft Corporation.) [HKLM] -- Windows XP Service
    O42 - Logiciel: Windows XP Winter Fun Pack Screensavers - (.Microsoft Corporation.) [HKLM] -- {27D0C7AB-59F1-4D4D-A0BB-05A31AC919EA}
    O42 - Logiciel: WordSearcher - (.Pas de propriétaire.) [HKLM] -- WordSearcher
    O42 - Logiciel: YouTube MP4 To MP3 Converter V2.0 - (.YouTube MP3 Downloader.) [HKLM] -- YouTube MP4 To MP3 Converter_is1
    O42 - Logiciel: atropicaltreat_3142328 Screen Saver - (.Pas de propriétaire.) [HKLM] -- atropicaltreat_3142328
    O42 - Logiciel: avast! Internet Security - (.Alwil Software.) [HKLM] -- avast5
    O42 - Logiciel: dBpowerAMP WMA V9.1 Codec - (.Pas de propriétaire.) [HKLM] -- dBpowerAMP WMA V9.1 Codec
    O42 - Logiciel: eMule - (.Pas de propriétaire.) [HKLM] -- eMule
    O42 - Logiciel: fullscreensavers Toolbar - (.Pas de propriétaire.) [HKLM] -- fullscreensavers Toolbar
    O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {81063354-9060-42B2-A000-1EBE96778AA9}
    O42 - Logiciel: neroxml - (.Nero AG.) [HKLM] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}
    O42 - Logiciel: rosedance_3112166 Screen Saver - (.Pas de propriétaire.) [HKLM] -- rosedance_3112166
    O42 - Logiciel: tannenbaum_3147186 Screen Saver - (.Pas de propriétaire.) [HKLM] -- tannenbaum_3147186
    O42 - Logiciel: whitewinter_3133206 Screen Saver - (.Pas de propriétaire.) [HKLM] -- whitewinter_3133206

    ---\\ HKCU & HKLM Software Keys
    [HKCU\Software\120671120]
    [HKCU\Software\3rd Eye Solutions]
    [HKCU\Software\?? ?? ???? ????? ??? ?? ????]
    [HKCU\Software\ABBYY]
    [HKCU\Software\AC3Filter]
    [HKCU\Software\ACD Systems]
    [HKCU\Software\ALWIL Software]
    [HKCU\Softwar
    0
  10. methafo
     
    Fix Navipromo version 4.0.9 commencé le 28/09/2010 7:27:05,50

    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
    !!! Postez ce rapport sur le forum pour le faire analyser !!!

    Outil exécuté depuis C:\navilog1

    Mise à jour le 17.09.2010 à 16h00 par IL-MAFIOSO

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 2.80GHz )
    BIOS : Award Modular BIOS v6.0
    USER : christian ( Not Administrator ! )
    BOOT : Normal boot

    Antivirus : avast! Internet Security 5.0.83886757 (Activated)
    Firewall : avast! Internet Security 5.0.83886757 (Activated)

    C:\ (Local Disk) - NTFS - Total:97 Go (Free:42 Go)
    D:\ (CD or DVD)
    E:\ (CD or DVD)
    F:\ (Local Disk) - NTFS - Total:200 Go (Free:185 Go)
    G:\ (Local Disk) - NTFS - Total:76 Go (Free:61 Go)

    Recherche executée en mode normal

    [b]Aucune Infection Navipromo/Egdaccess trouvée/b

    *** Scan terminé 28/09/2010 7:27:29,71 ***
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      bonjour,
      ok ton rapport de zhpdiag n'est pas complet postes le par le biais de cijoint comme demandé , merci
      0
  11. methafo
     
    Rapport de ZHPDiag v1.26.67 par Nicolas Coolman, Update du 25/09/2010
    Run by christian at 29/09/2010 07:27:30
    Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
    Contact : nicolascoolman@yahoo.fr

    ---\\ Web Browser
    MSIE: Internet Explorer v8.0.6001.18702
    MFIE: Mozilla Firefox (3.0.5)
    MFIE: Mozilla Firefox (3.6)
    MFIE: Mozilla Firefox 4.0b6 (x86 fr)

    ---\\ System Information
    Platform : Microsoft Windows XP (5.1.2600) Service Pack 3
    Processor: x86 Family 15 Model 3 Stepping 3, GenuineIntel
    Operating System: 32 Bits
    Boot mode: Normal (Normal boot)
    Total RAM: 2047 MB (66% free)
    System drive C: has 42 GB (43%) free of 98 GB

    ---\\ Logged in mode
    Computer Name: CHRIS
    User Name: christian
    All Users Names: SUPPORT_388945a0, NeroMediaHomeUser.4, LogMeInRemoteUser, HelpAssistant, christian, ASPNET, Administrateur,
    Unselected Option: None
    Logged in as Administrator

    ---\\ DOS/Devices
    C:\ Hard drive, Flash drive, Thumb drive (Free 42 Go of 98 Go)
    D:\ CD-ROM drive (Not Inserted)
    E:\ CD-ROM drive (Not Inserted)
    F:\ Hard drive, Flash drive, Thumb drive (Free 185 Go of 200 Go)
    G:\ Hard drive, Flash drive, Thumb drive (Free 61 Go of 76 Go)

    ---\\ Security Center & Tools Informations
    [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
    [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableTaskMgr: OK

    ---\\ Processus lancés
    [MD5.8408B80B5D1927D5063E1250EA5D9A78] - (.AVAST Software - avast! firewall service.) -- C:\Program Files\Alwil Software\Avast5\afwServ.exe [119200]
    [MD5.ACB544D7254F366DFB48F380BC36CD25] - (.AVAST Software - avast! Service.) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384]
    [MD5.583B7D111304BE63D7D9CB65482D2187] - (.InstallShield Software Corporation - InstallShield Update Service Scheduler.) -- C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe [81920]
    [MD5.9AEE9BCB32D82BCC36474EB921F3BB49] - (.Logitech Inc. - iTouch Application.) -- C:\Program Files\Logitech\iTouch\iTouch.exe [892928]
    [MD5.2589FFE360BED8F824CBC6171CB5B874] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2793304]
    [MD5.6C1B31F5C16E03153F0037AC6C451FFD] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\avastUI.exe [2838912]
    [MD5.F6987FF6C6D683F79FDCE707B071A997] - (.SFX TEAM - SuperCopier 2 (explorer file copy replaceme.) -- C:\Program Files\SuperCopier2\SuperCopier2.exe [955392]
    [MD5.6FBBB73BE9FB38389AB73F38828A9CAC] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe [13351304]
    [MD5.B41C51512AC95B3ADB11FF2A42006C83] - (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe [3220912]
    [MD5.3B33BF4A13228EEC2670CF77B157C95F] - (.Pas de propriétaire - WG111v2 MFC Application.) -- C:\Program Files\NETGEAR\WG111v2\WG111v2.exe [1261568]
    [MD5.E5D5672572FD3A8AE672E0C5F43CF009] - (.Peer 2 World - Weezo UI.) -- F:\Weezo\bin\Weezo.exe [2342912]
    [MD5.98D472ECFBC0E8ED25A0483E765F42B6] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe [560472]
    [MD5.4B5AE15E5C73EB4DC8DBEC2788230D41] - (.Apple Inc. - Apple Mobile Device Service.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [144672]
    [MD5.C9B18ABE9063A33E77F6BE81CC8DF0C5] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\twain_32\SiPix\SCBlink2\Srvany.exe [13312]
    [MD5.3F56903E124E820AEECE6D471583C6C1] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [238888]
    [MD5.2CD4EDA088A2292F4D1412A61A659F87] - (.NuCam Corp. - USBPNP.) -- C:\WINDOWS\twain_32\SiPix\SCBlink2\USBPNP.exe [26624]
    [MD5.E24C73D3BA872CA385E52739EE7BD10B] - (.Executive Software International, Inc. - DKSERVICE.EXE.) -- C:\Program Files\Executive Software\Diskeeper\DkService.exe [241664]
    [MD5.D3F9205CC4CB07553F2F9472C767EA87] - (.Teruten - FsUsbDevice.) -- C:\windows\system32\FsUsbExService.Exe [233472]
    [MD5.74E30A41CDCF331C74BC4D97BE40CC5B] - (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) -- C:\Program Files\Java\jre6\bin\jqs.exe [153376]
    [MD5.5334D3450B55FC929D50143F530597F0] - (.Apache Software Foundation - Apache HTTP Server.) -- F:\Weezo\Apache\bin\WeezoHttpd.exe [24645]
    [MD5.53710476495886D9961BE46983A6A33F] - (.Hewlett-Packard Company - LightScribe Service.) -- C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe [79136]
    [MD5.0DDFDCAA92C7F553328DB06BA599BEA9] - (.Logitech Inc. - Logitech LVPrcSrv Module..) -- C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe [154136]
    [MD5.11F714F85530A2BD134074DC30E99FCA] - (.Microsoft Corporation - Machine Debug Manager.) -- C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe [322120]
    [MD5.3978F082274F723AD5A0A8058C2417DD] - (.Analog Devices, Inc. - SoundMAX service agent component.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [45056]
    [MD5.F13DA74969897359A88F2A739F54A250] - (.Ulead Systems, Inc. - ULCDRSvr.) -- C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe [49152]
    [MD5.207B16FA69F61D1895F8D8532F587E4B] - (.Tonec Inc. - Internet Download Manager agent for click m.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe [263600]
    [MD5.1DD5E27417C3091D46C85563B48DD3C0] - (.IncrediMail, Ltd. - IncrediMail Application.) -- C:\Program Files\IncrediMail\bin\IncMail.exe [353736]
    [MD5.5A1C2D280D559844A517EAB580BB8F2A] - (.IncrediMail, Ltd. - IncrediMail Tray Application.) -- C:\Program Files\IncrediMail\bin\IMApp.exe [255432]
    [MD5.384D2C6B22C1F9AEC8B4DD5FB0E0A717] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [555008]

    ---\\ Page de démarrage de Mozilla Firefox (M0)
    M0 - MFSP: prefs.js [christian - cxci8hgi.default] https://start.mozilla.org/fr/

    ---\\ Programmes d'extension pour Mozilla Firefox (M2)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\CompactMenuCE@Merci.chao] [personalmenu] Personal Menu 4.3.2 (.Merci chao.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{0b38152b-1b20-484d-a11f-5e04a9b0661f}] [] Winamp Toolbar 4.3.2 (.AOL LLC.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{0b457cAA-602d-484a-8fe7-c1d894a011ba}] [] FireShot 0.80 (.Eugene G. Suslikov.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{1392b8d2-5c05-419f-a8f6-b9f15a596612}] [] Freecorder Toolbar 2.5.6.0 (.Conduit Ltd..)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{20a82645-c095-46ed-80e3-08825760534b}] [MicrosoftCG] Microsoft .NET Framework Assistant 2.5.6.0 (.Microsoft.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{37E4D8EA-8BDA-4831-8EA1-89053939A250}(2)] [] PDF Download 3.0.0.0 (.Nitro PDF, Inc..)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{3DB3D228-A2E9-4581-B400-CE1331C5269E}] [] EasyPrediction 2.0.0.0 (.Nitro PDF, Inc..)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{4daac69c-cba7-45e2-9bc8-1044483d3352}] [] Softonic_France Toolbar 2.5.8.6 (.Conduit Ltd..)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{57068FBE-1506-42ee-AB02-BD183E7999E4}] [] Compact Menu 2 2.5.8.6 (.Milly.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{6226BA26-C017-4007-928C-DE9715C6FA67}] [] Blingee Toolbar"> 2.5.8.6 (.Milly.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{635abd67-4fe9-1b23-4f01-e679fa7484c1}] [yahoo.ytff] Yahoo! Toolbar 1.5.4.20081105 (.Yahoo!.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{9b339f6e-ddcd-401b-8764-230adbd01761}] [] Messenger Plus Live Toolbar 2.5.4.7 (.Conduit Ltd..)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)] [dwhelper] DownloadHelper 4.6.2 (.Michel Gutierrez.)
    M2 - MFEP: prefs.js [christian - cxci8hgi.default\{fae389d5-e97e-4abd-8242-d9080c709167}] [] fullscreensavers Toolbar 2.5.6.0 (.Conduit Ltd..)

    ---\\ Plugins de navigateurs Opera/Firefox(P1/P2)
    P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files\Mozilla Firefox\Plugins\np-mswmp.dll
    P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeploytk.dll
    P2 - FPN:Firefox Plugin Navigator . (.mozilla.org - Default Plug-in.) -- C:\Program Files\Mozilla Firefox\Plugins\npnul32.dll
    P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 8.2.4.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin.dll
    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin2.dll
    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin3.dll
    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin4.dll
    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin5.dll
    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin6.dll
    P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\windows\system32\Macromed\Flash\NPSWF32.dll
    P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Pas de propriétaire - Pas de description.) -- F:\iTunes\Mozilla Plugins\npitunes.dll
    P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
    P2 - FPN: [HKLM] [@google.com/npPicasa3,version=3.0.0] - (.Google, Inc. - Picasa plugin.) -- F:\Installation Picassa 3\Google\Picasa3\npPicasa3.dll
    P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.50917.0.) -- C:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll
    P2 - FPN: [HKLM] [@microsoft.com/OfficeLive,version=1.3] - (.Microsoft Corp. - Office Live Update v1.3.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll
    P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    P2 - FPN: [HKLM] [@pack.google.com/Google Updater;version=13] - (.Google - Google Updater plugin<br><a href="http://pack.google.com/">http://pack.) -- C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
    P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=8] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
    P2 - FPN: [HKLM] [@videolan.org/vlc,version=1.1.0] - (.the VideoLAN Team - Version 1.1.0, copyright 1996-2010 The VideoLAN Team<br><a href="http:.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll
    P2 - FPN: [HKCU] [@adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

    ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
    F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

    ---\\ Pages de démarrage d'Internet Explorer (R0)
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr

    ---\\ Pages de recherche d'Internet Explorer (R1)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    ---\\ Internet Explorer URLSearchHook (R3)
    R3 - URLSearchHook: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} . (.Conduit Ltd. - Conduit Toolbar.) (5, 2, 3, 1) -- C:\Program Files\P2P_Energy\tbP2P0.dll
    R3 - URLSearchHook: P2P Energy Toolbar - {fae389d5-e97e-4abd-8242-d9080c709167} . (.Conduit Ltd. - Conduit Toolbar.) (5, 3, 2, 0) -- C:\Program Files\fullscreensavers\tbfull.dll
    R3 - URLSearchHook: P2P Energy Toolbar - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (8.00.6001.18939 (longhorn_ie8_gdr.100616-1700)) -- C:\WINDOWS\system32\ieframe.dll
    R3 - URLSearchHook: P2P Energy Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} . (.Conduit Ltd. - Conduit Toolbar.) (5, 7, 3, 1) -- C:\Program Files\Freecorder\tbFre0.dll

    ---\\ Browser Helper Objects de navigateur (O2)
    O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} . (.Tonec Inc. - IDM BHO Module.) -- C:\Program Files\Internet Download Manager\IDMIECC.dll
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\Freecorder\tbFre0.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} . (.Microsoft Corporation - Search Helper for Internet Explorer.) -- C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Messenger Plus Live Toolbar - {9b339f6e-ddcd-401b-8764-230adbd01761} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\Messenger_Plus_Live\tbMess.dll
    O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} . (.Babylon Ltd. - Babylon Internet Explorer Addin.) -- F:\Babylon\Utils\BabylonIEPI.dll
    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} . (.Skype Technologies S.A. - Skype add-on for IE.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} . (.Sun Microsystems, Inc. - Java(TM) Quick Starter binary.) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} . (.SEIKO EPSON CORPORATION - EPSON Web-To-Page.) -- C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} . (.SpeedBit Ltd. - Download Accelerator Plus (DAP) MSIE Loader.) -- C:\PROGRA~1\DAP\dapieloader.dll

    ---\\ Internet Explorer Toolbars (O3)
    O3 - Toolbar: FireShot - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} . (.Pas de propriétaire - FSAddin Module.) -- C:\Documents and Settings\christian\Application Data\Mozilla\Firefox\Profiles\cxci8hgi.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fsaddin-0.80.dll
    O3 - Toolbar: Messenger Plus Live Toolbar - {9b339f6e-ddcd-401b-8764-230adbd01761} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\Messenger_Plus_Live\tbMess.dll
    O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} . (.PilotGroup LLC - SaveFlash.) -- C:\Program Files\Save Flash\SaveFlash.dll
    O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} . (.Conduit Ltd. - Conduit Toolbar.) -- C:\Program Files\Freecorder\tbFre0.dll
    O3 - Toolbar: (no name) - {1E796980-9CC5-11D1-A83F-00C04FC99D61} . (.Pas de propriétaire - Pas de description.) -- (.not file.)

    ---\\ Applications démarrées par registre & par dossier (O4)
    O4 - HKLM\..\Run: [ISUSPM Startup] . (.InstallShield Software Corporation - InstallShield Update Service Update Manager.) -- C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe
    O4 - HKLM\..\Run: [ISUSScheduler] . (.InstallShield Software Corporation - InstallShield Update Service Scheduler.) -- C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    O4 - HKLM\..\Run: [zBrowser Launcher] . (.Logitech Inc. - iTouch Application.) -- C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
    O4 - HKLM\..\Run: [avast5] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\avastUI.exe
    O4 - HKCU\..\Run: [SuperCopier2.exe] . (.SFX TEAM - SuperCopier 2 (explorer file copy replaceme.) -- C:\Program Files\SuperCopier2\SuperCopier2.exe
    O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe
    O4 - HKCU\..\Run: [AnnivJ] . (.http://www.kiteatao.net/standard.view?idMenu=2.1.1 - email: annivj@ - Annonce le jour J des anniversaires de vos.) -- C:\Program Files\AnnivJ\AnnivJ.exe
    O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe
    O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\windows\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
    O4 - HKUS\S-1-5-21-1220945662-1303643608-682003330-1012-1220945662-1303643608-682003330-1004\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Démarrage\NETGEAR WG111v2 Smart Wizard.lnk . (.Pas de propriétaire.) -- C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
    O4 - Global Startup: C:\Documents And Settings\christian\Menu Démarrer\Programmes\Démarrage\Weezo.lnk . (.Peer 2 World.) -- F:\Weezo\bin\Weezo.exe

    ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
    O8 - Extra context menu item: &Clean Traces . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
    O8 - Extra context menu item: &Download with &DAP . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\DAP\dapextie.htm
    O8 - Extra context menu item: Add to Google Photos Screensa&ver . (.Google Inc. - Google Photos Screensaver.) -- C:\windows\system32\GPhotos.scr
    O8 - Extra context menu item: Download &all with DAP . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\DAP\dapextie2.htm
    O8 - Extra context menu item: Download Video by Free YouTuBe Utility . (.Pas de propriétaire - Pas de description.) -- F:\Free YouTuBe Utility\IEydown.htm
    O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.exe
    O8 - Extra context menu item: Personnaliser . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\options.htm
    O8 - Extra context menu item: Rechercher sur Internet . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\search.htm
    O8 - Extra context menu item: Traduire . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\translat.htm
    O8 - Extra context menu item: Traduire dans R-Express . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\wts.htm
    O8 - Extra context menu item: Traduire dans WebView . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\webview.htm
    O8 - Extra context menu item: Traduire la page . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\page.htm
    O8 - Extra context menu item: Translate this web page with Babylon . (.Babylon Ltd. - Babylon Internet Explorer Addin.) -- F:\Babylon\Utils\BabylonIEPI.dll
    O8 - Extra context menu item: Translate with Babylon . (.Babylon Ltd. - Babylon Internet Explorer Addin.) -- F:\Babylon\Utils\BabylonIEPI.dll
    O8 - Extra context menu item: Télécharger avec IDM . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Internet Download Manager\IEExt.htm
    O8 - Extra context menu item: Télécharger avec IDM des videos FLV parmi les 10 dernières demandées . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Internet Download Manager\IEGetVL2.htm
    O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Internet Download Manager\IEGetVL.htm
    O8 - Extra context menu item: Télécharger tous les liens avec IDM . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Internet Download Manager\IEGetAll.htm

    ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
    O9 - Extra button: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\PROMT98\promtie4\promt1.ico
    O9 - Extra 'Tools' menuitem: Personnalisez traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} . (.not file.) - (.not file.)
    O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~1\MICROS~2\OFFICE11\REFBARH.ICO
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.not file.) - (.not file.)
    O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} . (.Babylon Ltd. - Babylon Internet Explorer Addin.) -- F:\Babylon\Utils\BabylonIEPI.dll

    ---\\ Winsock hijacker (Layered Service Provider) (O10)
    O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\windows\system32\mswsock.dll
    O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\windows\system32\winrnr.dll
    O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\windows\system32\mswsock.dll
    O10 - WLSP:\000000000004\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll

    ---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
    O15 - Trusted Zone: [HKCU\...\Domains] http.localhost
    O15 - Trusted Zone: [HKCU\...\Domains\www] http.localhost

    ---\\ Objets ActiveX (Downloaded Program Files)(O16)
    O16 - DPF: Microsoft XML Parser for Java (Microsoft XML Parser for Java) - (.not file.) - file:\\C:\WINDOWS\Java\classes\xmldso.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} () - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    ---\\ Modification Domaine/Adresses DNS (O17)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{05F2DD38-00C2-4B02-82ED-E7D4262CBD04}: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C51E8F15-1EE2-4BFE-A8ED-856AFD57C1E8}: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{05F2DD38-00C2-4B02-82ED-E7D4262CBD04}: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{C51E8F15-1EE2-4BFE-A8ED-856AFD57C1E8}: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CS3\Services\Tcpip\..\{05F2DD38-00C2-4B02-82ED-E7D4262CBD04}: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CS3\Services\Tcpip\..\{C51E8F15-1EE2-4BFE-A8ED-856AFD57C1E8}: DhcpNameServer = 192.168.0.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1

    ---\\ Protocole additionnel et piratage de protocole (O18)
    O18 - Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} . (.Logitech Inc. - Logitech Desktop Messenger.) -- C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} . (.Skype Technologies S.A. - Skype add-on for IE.) -- C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O18 - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} . (.Skype Technologies - Skype for COM API.) -- C:\PROGRA~1\FICHIE~1\Skype\Skype4COM.dll

    ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
    O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\windows\System32\dimsntfy.dll
    O20 - Winlogon Notify: WgaLogon . (.Microsoft Corporation - Notifications Windows Genuine Advantage.) -- C:\windows\System32\WgaLogon.dll

    ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
    O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\windows\system32\SHELL32.dll
    O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\windows\system32\SHELL32.dll
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
    O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\System32\stobject.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\windows\system32\WPDShServiceObj.dll

    ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
    O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\windows\System32\browseui.dll

    ---\\ Liste des services NT non Microsoft et non désactivés (O23)
    O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - Apple Mobile Device Service.) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: avast! Firewall (avast! Firewall) . (.AVAST Software - avast! firewall service.) - C:\Program Files\Alwil Software\Avast5\afwServ.exe
    O23 - Service: Blink2PnP (Blink2PnP) . (.Pas de propriétaire - Pas de description.) - C:\WINDOWS\twain_32\SiPix\SCBlink2\Srvany.exe
    O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Diskeeper (Diskeeper) . (.Executive Software International, Inc. - DKSERVICE.EXE.) - C:\Program Files\executive Software\Diskeeper\DkService.exe
    O23 - Service: FsUsbExService (FsUsbExService) . (.Teruten - FsUsbDevice.) - C:\windows\system32\FsUsbExService.exe
    O23 - Service: Google Update Service (gupdate1c98769f00cfd4e) (gupdate1c98769f00cfd4e) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) . (.Google - gusvc.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) . (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) . (.Hewlett-Packard Company - LightScribe Service.) - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: Process Monitor (LVPrcSrv) . (.Logitech Inc. - Logitech LVPrcSrv Module..) - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: Nero MediaHome 4 Service (NeroMediaHomeService.4) . (.Nero AG - Nero MediaHome.) - F:\Néro MédiaHome 4\Nero MediaHome 4\NMMediaServerService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 178.2.) - C:\windows\system32\nvsvc32.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) . (.Analog Devices, Inc. - SoundMAX service agent component.) - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) . (.Ulead Systems, Inc. - ULCDRSvr.) - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe

    ---\\ Enumération Active Desktop & MHTML Editor (O24)
    O24 - Desktop General: BackupWallPaper - .(.Pas de propriétaire - Pas de description.) - C:\windows\webshots.bmp
    O24 - Desktop General: WallPaper - .(.Pas de propriétaire - Pas de description.) - C:\windows\webshots.bmp
    O24 - Default MHTML Editor: Last - .(.Pas de propriétaire - Pas de description.) - C:\Program Files\Microsoft Office\Office10\WINWORD.exe (.not file.)

    ---\\ Tâches planifiées en automatique (O39)
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\Ad-Aware Update (Weekly).job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\AppleSoftwareUpdate.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\AWC AutoSweep.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\Google Software Updater.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\Programme d'arrêt du système de l'onduleur.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\SpeedOptimizer Startup.job
    O39 - APT:Automatic Planified Task - C:\windows\Tasks\User_Feed_Synchronization-{6C9EA0D2-CA42-477D-A069-8FC758E39ECE}.job

    ---\\ Composants installés (ActiveSetup Installed Components) (O40)
    O40 - ASIC: (no name) - >{0fa2357c-b1e7-4386-859a-8e7459641c1b} . (.Pas de propriétaire - Pas de description.) -- RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
    O40 - ASIC: LightScribe Control Panel - {10880D85-AAD9-4558-ABDC-2AB1552D831F} . (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files\Fichiers communs\LightScribe\LSRunOnce.exe
    O40 - ASIC: Macromedia Shockwave Director 10.1 - {166B1BCA-3F9C-11CF-8075-444553540000} . (.Adobe Systems, Inc. - Shockwave ActiveX Control.) -- C:\WINDOWS\system32\macromed\Director\SwDir.dll
    O40 - ASIC: Adobe Shockwave Director 10.2 - {233C1507-6A77-46A4-9443-F871F945D258} . (.Adobe Systems, Inc. - Shockwave ActiveX Control.) -- C:\WINDOWS\system32\Macromed\Director\SwDir.dll
    O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msnetmtg.inf
    O40 - ASIC: Windows Messenger 4.7 - {5945c046-1e7d-11d1-bc44-00c04fd912be} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msmsgs.inf
    O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Pas de propriétaire - Pas de description.) -- C:\windows\INF\wmp11.inf
    O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11cf-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 10.1 r53.) -- C:\windows\system32\Macromed\Flash\Flash10h.ocx

    ---\\ Pilotes lancés au démarrage (O41)
    O41 - Driver: Orb Virtual Cable (OrbVirtualCable) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\orbvckmd.sys

    ---\\ Logiciels installés (O42)
    O42 - Logiciel: 123 PDF to Image v1.4 - (.FreePDFtoImage.com.) [HKLM] -- 123 PDF to Image_is1
    O42 - Logiciel: ABBYY FineReader 6.0 Sprint - (.ABBYY Software House.) [HKLM] -- {ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
    O42 - Logiciel: ACDSee 5.0 Standard Trial - (.ACD Systems Ltd.) [HKLM] -- {7FFADA6F-9A46-4D80-8400-8D3B77C62908}
    O42 - Logiciel: Active GIF Creator 3.3 - (.Pas de propriétaire.) [HKLM] -- Active GIF Creator 3.3
    O42 - Logiciel: Add-in ODF pour Microsoft Word - (.Clever Age.) [HKLM] -- {8D774B5B-A1D9-45B3-AFB4-3F85604961BC}
    O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
    O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
    O42 - Logiciel: Adobe Photoshop CS - (.Adobe Systems, Inc..) [HKLM] -- {EFB21DE7-8C19-4A88-BB28-A766E16493BC}
    O42 - Logiciel: Adobe Reader 8.2.4 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A82000000003}
    O42 - Logiciel: Adobe Shockwave Player - (.Adobe Systems, Inc..) [HKLM] -- Adobe Shockwave Player
    O42 - Logiciel: Advanced Pdf to Word Converter 6.2 - (.Officeconvert Software, Inc..) [HKLM] -- Advanced Pdf to Word Converter_is1
    O42 - Logiciel: Advertising Center - (.Nero AG.) [HKLM] -- {B2EC4A38-B545-4A00-8214-13FE0E915E6D}
    O42 - Logiciel: AnmanieSMP 2.4 i - (.Christoph Walter.) [HKLM] -- AnmanieSMP_is1
    O42 - Logiciel: AnnivJ 2.0.0 - (.KiteAtao.) [HKLM] -- AnnivJ
    O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {3FA365DF-2D68-45ED-8F83-8C8A33E65143}
    O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
    O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {6956856F-B6B3-4BE0-BA0B-8F495BE32033}
    O42 - Logiciel: Archiveur WinRAR - (.Pas de propriétaire.) [HKLM] -- WinRAR archiver
    O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM] -- {D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
    O42 - Logiciel: Awesome Waves - (.Pas de propriétaire.) [HKLM] -- Awesome Waves
    O42 - Logiciel: Babylon - (.Babylon.) [HKLM] -- Babylon
    O42 - Logiciel: Bear Celebrates Free Screensaver 1.12 - (.Pas de propriétaire.) [HKLM] -- Bear Celebrates Free Screensaver_is1
    O42 - Logiciel: Bibliothèques GTK+ 2.14.7 rev a (supprimer uniquement) - (.Pas de propriétaire.) [HKLM] -- GTK 2.0
    O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {07287123-B8AC-41CE-8346-3D777245C35B}
    O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
    O42 - Logiciel: CDex extraction audio - (.Pas de propriétaire.) [HKLM] -- CDex
    O42 - Logiciel: Caricatures PRO [4.4.0.1] - (.Marseillesoft.) [HKLM] -- Caricatures PRO_is1
    O42 - Logiciel: CartaGoGo v3.1.8 - (.Generation Software.) [HKLM] -- CartaGoGo v3.1.8_is1
    O42 - Logiciel: Chinese Simplified Fonts Support For Adobe Reader 8 - (.Adobe Systems.) [HKLM] -- {AC76BA86-7AD7-2447-0000-800000000003}
    O42 - Logiciel: Codeur Windows Media Série 9 - (.Microsoft Corporation.) [HKLM] -- {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
    O42 - Logiciel: Codeur Windows Media Série 9 - (.Pas de propriétaire.) [HKLM] -- Windows Media Encoder 9
    O42 - Logiciel: Coffret de pilotes Logitech Webcam Software - (.Logitech Inc..) [HKLM] -- lvdrivers_12.10
    O42 - Logiciel: Coloriage 2 - (.Pas de propriétaire.) [HKLM] -- Coloriage 2
    O42 - Logiciel: Compatibility Pack for the 2007 Office system - (.Microsoft Corporation.) [HKLM] -- {90120000-0020-0409-0000-0000000FF1CE}
    O42 - Logiciel: DFX for Windows Media Player - (.Power Technology.) [HKLM] -- {f1990716-8ee0-4c3e-8ebd-84026f3a09d5}
    O42 - Logiciel: DJ Pofessionnel 2008 7.3.2.2 - (.Marseillesoft.) [HKLM] -- DJ Professionnel 2008_is1
    O42 - Logiciel: DVD Shrink 3.2 - (.DVD Shrink.) [HKLM] -- DVD Shrink_is1
    O42 - Logiciel: Desktop Graffitist - (.Pas de propriétaire.) [HKLM] -- Desktop Graffitist
    O42 - Logiciel: DiapoPat v4.9 - (.LucVil.) [HKLM] -- DiapoPat v4.9_is1
    O42 - Logiciel: Diskeeper Professional Edition - (.Executive Software.) [HKLM] -- {A320805E-26CE-4332-9239-2F4837165C8B}
    O42 - Logiciel: DolbyFiles - (.Nero AG.) [HKLM] -- {B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}
    O42 - Logiciel: Download Accelerator Plus (DAP) - (.Speedbit Ltd..) [HKLM] -- Download Accelerator Plus (DAP)
    O42 - Logiciel: EPSON Attach To Email - (.Pas de propriétaire.) [HKLM] -- InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}
    O42 - Logiciel: EPSON Printer Software - (.Pas de propriétaire.) [HKLM] -- EPSON Printer and Utilities
    O42 - Logiciel: EPSON Scan - (.Pas de propriétaire.) [HKLM] -- EPSON Scanner
    O42 - Logiciel: ESCX3700 User's Guide - (.Pas de propriétaire.) [HKLM] -- ESCX3700 User's Guide
    O42 - Logiciel: ESET Online Scanner v3 - (.Pas de propriétaire.) [HKLM] -- ESET Online Scanner
    O42 - Logiciel: EZ-DUB - (.Pas de propriétaire.) [HKLM] -- EZ-DUB5.0.1
    O42 - Logiciel: EasyPrediction - (.EasyPrediction Ltd..) [HKLM] -- EasyPrediction
    O42 - Logiciel: EnveloppesEditor1.09 - (.J.L.F..) [HKLM] -- EnveloppesEditor1.09_is1
    O42 - Logiciel: EnveloppesEditor1.10 - (.J.L.F..) [HKLM] -- EnveloppesEditor1.10_is1
    O42 - Logiciel: Etats Et Requêtes - (.Pas de propriétaire.) [HKLM] -- Etats Et Requêtes
    O42 - Logiciel: Extended Online Call for Skype - (.EBS SkypeTools.) [HKCU] -- 21e31c10007f8a6a
    O42 - Logiciel: Extension de Windows Live Toolbar (Windows Live Toolbar) - (.Microsoft Corporation.) [HKLM] -- {0CA6047C-D28B-4295-834A-07C52BA20C2D}
    O42 - Logiciel: FastCipher - (.Pas de propriétaire.) [HKLM] -- FastCipher_is1
    O42 - Logiciel: FixMessenger - (.Pas de propriétaire.) [HKLM] -- FixMessenger
    O42 - Logiciel: Flash Saving Plugin - (.UnH Solutions.) [HKLM] -- {6D74E1F4-32D5-44D0-9054-8D57E981F59F}_is1
    O42 - Logiciel: Font Explorer v.1.2 - (.Ivan BUBLOZ.) [HKLM] -- Font Explorer_is1
    O42 - Logiciel: Free Mp3 Wma Converter V 1.7.3 - (.Koyote Soft.) [HKLM] -- Free Mp3 Wma Converter_is1
    O42 - Logiciel: Free Video Converter V 2.9 - (.Koyote Soft.) [HKLM] -- Free Video Converter_is1
    O42 - Logiciel: Free YouTuBe Utility 1.42 - (.Free-YouTuBe.com, Inc..) [HKLM] -- Free YouTuBe Utility_is1
    O42 - Logiciel: Freecorder Toolbar - (.Pas de propriétaire.) [HKLM] -- Freecorder Toolbar
    O42 - Logiciel: Freecorder Toolbar 3.02 Application - (.Applian Technologies Inc..) [HKLM] -- Freecorder Toolbar3.02
    O42 - Logiciel: FrostWire 4.17.2 - (.FrostWire, LLC.) [HKLM] -- FrostWire
    O42 - Logiciel: GIMP 2.6.9 - (.The GIMP Team.) [HKLM] -- WinGimp-2.0_is1
    O42 - Logiciel: Gommettes Version A - (.Pas de propriétaire.) [HKCU] -- Gommettes Version A
    O42 - Logiciel: GoodFrame - (.FDSoftware.) [HKLM] -- GoodFrame_is1
    O42 - Logiciel: GoodFrame - (.FDSoftware.) [HKLM] -- {10A19812-24CD-4AC4-A775-8AD8DE7E610C}
    O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome
    O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM] -- {DBEA1034-5882-4A88-8033-81C4EF0CFA29}
    O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
    O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {4286E640-B5FB-11DF-AC4B-005056C00008}
    O42 - Logiciel: Heures du Monde - (.Olivier RAVET.) [HKLM] -- Heures du Monde_is1
    O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
    O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
    O42 - Logiciel: Hotfix for Windows Media Format 11 SDK (KB929399) - (.Microsoft Corporation.) [HKLM] -- KB929399
    O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5
    O42 - Logiciel: Image Mender 1.2 - (.Phibit Software.) [HKLM] -- Image Mender
    O42 - Logiciel: IncrediMail - (.IncrediMail.) [HKLM] -- {5E97F3BD-CDDC-4188-9D98-532E14FABB5D}
    O42 - Logiciel: IncrediMail 2.0 - (.IncrediMail Ltd..) [HKLM] -- IncrediMail
    O42 - Logiciel: IncrediMail JunkFilter Plus - (.IncrediMail Ltd..) [HKLM] -- JunkFilterPlus
    O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
    O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- {133742BA-6F46-4D3E-85AF-78631D9AD8B8}
    O42 - Logiciel: Internet Download Manager - (.Pas de propriétaire.) [HKLM] -- Internet Download Manager
    O42 - Logiciel: J2SE Runtime Environment 5.0 Update 10 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0150100}
    O42 - Logiciel: Java(TM) 6 Update 19 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216016FF}
    O42 - Logiciel: Java(TM) 6 Update 3 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160030}
    O42 - Logiciel: Java(TM) 6 Update 5 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160050}
    O42 - Logiciel: Java(TM) SE Runtime Environment 6 Update 1 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160010}
    O42 - Logiciel: JiJiPEG - (.HavingTools.) [HKLM] -- {704DD559-F3DC-4ACD-A4BF-05F8ACDB4ADE}
    O42 - Logiciel: JpegExpress - (.Pas de propriétaire.) [HKLM] -- JpegExpress_is1
    O42 - Logiciel: JunkFilterPlus - (.IncrediMail.) [HKLM] -- {DC754D8F-1D06-4016-BF57-8D21F97E1F0A}
    O42 - Logiciel: KC Softwares IDPhotoStudio - (.KC Softwares.) [HKLM] -- KC Softwares IDPhotoStudio_is1
    O42 - Logiciel: KaraFun 1.18 - (.Recisio.) [HKLM] -- KaraFun_is1
    O42 - Logiciel: LM 2.0 - (.Pas de propriétaire.) [HKLM] -- LM 2.0
    O42 - Logiciel: Lecteur Windows Media 11 - (.Pas de propriétaire.) [HKLM] -- Windows Media Player
    O42 - Logiciel: Logitech Updater - (.Nom de votre société.) [HKLM] -- {53735ECE-E461-4FD0-B742-23A352436D3A}
    O42 - Logiciel: Logitech Vid - (.Logitech Inc..) [HKLM] -- {4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}
    O42 - Logiciel: Logitech Webcam Software - (.Logitech Inc..) [HKLM] -- {C27BC2A2-30DD-4014-B22E-63EB0DB572F9}
    O42 - Logiciel: Logitech iTouch Software - (.Pas de propriétaire.) [HKLM] -- {036AA4D4-6D32-11D4-9875-00105ACE7734}
    O42 - Logiciel: MSN Toolbar - (.Microsoft Corporation.) [HKLM] -- {08234a0d-cf39-4dca-99f0-0c5cb496da81}
    O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
    O42 - Logiciel: MSXML 4.0 SP2 (KB936181) - (.Microsoft Corporation.) [HKLM] -- {C04E32E0-0416-434D-AFB9-6969D703A9EF}
    O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
    O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
    O42 - Logiciel: MSXML 4.0 SP2 Parser and SDK - (.Microsoft Corporation.) [HKLM] -- {716E0306-8318-4364-8B8F-0CC4E9376BAC}
    O42 - Logiciel: MULTIPLEjm 1.0 - (.Pas de propriétaire.) [HKLM] -- MULTIPLEjm
    O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
    O42 - Logiciel: MemAv - (.Pas de propriétaire.) [HKLM] -- MemAv_is1
    O42 - Logiciel: Menus intelligents (Windows Live Toolbar) - (.Microsoft Corporation.) [HKLM] -- {0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
    O42 - Logiciel: Messenger_Plus_Live Toolbar - (.Pas de propriétaire.) [HKLM] -- Messenger_Plus_Live Toolbar
    O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Microsoft.) [HKLM] -- {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Pas de propriétaire.) [HKLM] -- Microsoft .NET Framework 1.1 (1033)
    O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB979906) - (.Pas de propriétaire.) [HKLM] -- M979906
    O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
    O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
    O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
    O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
    O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
    O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM] -- MSCompPackV1
    O42 - Logiciel: Microsoft Internationalized Domain Names Mitigation APIs - (.Microsoft Corporation.) [HKLM] -- IDNMitigationAPIs
    O42 - Logiciel: Microsoft National Language Support Downlevel APIs - (.Microsoft Corporation.) [HKLM] -- NLSDownlevelMapping
    O42 - Logiciel: Microsoft Office 2003 Primary Interop Assemblies - (.Microsoft Corporation.) [HKLM] -- {91490409-6000-11D3-8CFE-0150048383C9}
    O42 - Logiciel: Microsoft Office Excel Viewer - (.Microsoft Corporation.) [HKLM] -- {95120000-003F-040C-0000-0000000FF1CE}
    O42 - Logiciel: Microsoft Office Live Add-in 1.3 - (.Microsoft Corporation.) [HKLM] -- {57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
    O42 - Logiciel: Microsoft Office Outlook Connector - (.Microsoft Corporation.) [HKLM] -- {95120000-0122-0409-0000-0000000FF1CE}
    O42 - Logiciel: Microsoft Office Outlook Connector - (.Microsoft Corporation.) [HKLM] -- {95120000-0122-040C-0000-0000000FF1CE}
    O42 - Logiciel: Microsoft Office Professional Edition 2003 - (.Microsoft Corporation.) [HKLM] -- {9011040C-6000-11D3-8CFE-0150048383C9}
    O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
    O42 - Logiciel: Microsoft Search Enhancement Pack - (.Microsoft Corporation.) [HKLM] -- {06E6E30D-B498-442F-A943-07DE41D7F785}
    O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
    O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- Wudf01000
    O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118}
    O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {7299052b-02a4-4627-81f2-1818da5d550d}
    O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {A49F249F-0C91-497F-86DF-B2585E8E76B7}
    O42 - Logiciel: Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
    O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 - (.Microsoft Corporation.) [HKLM] -- {FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
    O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
    O42 - Logiciel: Module de compatibilité pour Microsoft Office System 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0020-040C-0000-0000000FF1CE}
    O42 - Logiciel: Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 2.0 Language Pack - FRA
    O42 - Logiciel: Mozilla Firefox (3.6) - (.Mozilla.) [HKLM] -- Mozilla Firefox (3.6)
    O42 - Logiciel: Mozilla Firefox 4.0b6 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 4.0b6 (x86 fr)
    O42 - Logiciel: NVIDIA Drivers - (.Pas de propriétaire.) [HKLM] -- NVIDIA Drivers
    O42 - Logiciel: Nero 7 Essentials - (.Nero AG.) [HKLM] -- {3A2AA418-42ED-41A2-8A4E-D887E24B1036}
    O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM] -- {BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}
    O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM] -- {F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}
    O42 - Logiciel: Nero Installer - (.Nero AG.) [HKLM] -- {E8A80433-302B-4FF1-815D-FCC8EAC482FF}
    O42 - Logiciel: Nero MediaHome 4 - (.Nero AG.) [HKLM] -- {99EF387E-633E-4CFB-BFA3-AB961B685DDF}
    O42 - Logiciel: Nero MediaHome 4 Help - (.Nero AG.) [HKLM] -- {69FC3B9A-4149-43DB-A557-6ED0C8D8BA44}
    O42 - Logiciel: Notification de cadeaux MSN - (.Microsoft.) [HKCU] -- Notification de cadeaux MSN
    O42 - Logiciel: OLYMPUS USB Reader/Writer - (.OLYMPUS OPTICAL CO.,LTD..) [HKLM] -- InstallShield_{9DFC9A77-86B4-4139-A4CF-A5E774422D28}
    O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM] -- {205C6BDD-7B73-42DE-8505-9A093F35A238}
    O42 - Logiciel: P2P_Energy Toolbar - (.Pas de propriétaire.) [HKLM] -- P2P_Energy Toolbar
    O42 - Logiciel: PC Connectivity Solution - (.Nokia.) [HKLM] -- {AC599724-5755-48C1-ABE7-ABB857652930}
    O42 - Logiciel: PDF-Viewer - (.Tracker Software Products Ltd.) [HKLM] -- {8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1
    O42 - Logiciel: PDFCreator - (.Frank Heindörfer, Philip Chinery.) [HKLM] -- {0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}
    O42 - Logiciel: Package de pilotes Windows - MobileTop (sshpmdm) Modem (01/26/2008 2.6.0.0) - (.MobileTop.) [HKLM] -- E24870CB6AA1C3511635FF9020A3E9471287FBE7
    O42 - Logiciel: Package de pilotes Windows - Nokia pccsmcfd (10/12/2007 6.85.4.0) - (.Nokia.) [HKLM] -- 3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F
    O42 - Logiciel: Paysage Noel Screensaver - (.Pas de propriétaire.) [HKLM] -- Paysage Noel Screensaver
    O42 - Logiciel: PerfV350 Guide d'utilisation - (.Pas de propriétaire.) [HKLM] -- PerfV350 Guide d'utilisation
    O42 - Logiciel: Personal Key Manager - (.Pas de propriétaire.) [HKLM] -- Personal Key Manager
    O42 - Logiciel: PhotoMail Maker - (.IncrediMail Ltd..) [HKLM] -- PhotoMail
    O42 - Logiciel: PhotoMail Maker - (.Nom de votre société.) [HKLM] -- {75AE8014-1184-4BC0-B279-C879540719EE}
    O42 - Logiciel: Photorécit 3 pour Windows - (.Microsoft Corporation.) [HKLM] -- {4F41AD68-89F2-4262-A32C-2F70B01FCE9E}
    O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM] -- Picasa 3
    O42 - Logiciel: PowerCours 777 Version 3 (3/10/6) - (.Pas de propriétaire.) [HKLM] -- Cours777_is1
    O42 - Logiciel: PowerpointImageExtractor - (.Pas de propriétaire.) [HKLM] -- PowerpointImageExtractor_is1
    O42 - Logiciel: Quick Startup 2.8.0.718 - (.GlarySoft.com.) [HKLM] -- Quick Startup_is1
    O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
    O42 - Logiciel: Reader BPI - (.Editions BPI.) [HKLM] -- {053B9AAD-A638-4D23-A6B6-A2551C0C1098}
    O42 - Logiciel: Revo Uninstaller 1.89 - (.VS Revo Group.) [HKLM] -- Revo Uninstaller
    O42 - Logiciel: SAMSUNG Mobile Composite Device Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile Composite Device
    O42 - Logiciel: SAMSUNG Mobile Modem Driver Set - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile Modem
    O42 - Logiciel: SAMSUNG Mobile Modem V2 Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile Modem V2
    O42 - Logiciel: SAMSUNG Mobile USB Modem 1.0 Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile USB Modem 1.0
    O42 - Logiciel: SAMSUNG Mobile USB Modem Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile USB Modem
    O42 - Logiciel: SAMSUNG SYMBIAN USB Download Driver - (.SAMSUNG Electronics CO,.LTD.) [HKLM] -- {D8CE69B0-9274-4b8c-BA49-0FF6A20A3C65}
    O42 - Logiciel: SAMSUNG USB Mobile Device Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG USB Mobile Device
    O42 - Logiciel: SCTE - (.ZOverLord Creations.) [HKCU] -- 4b8680acbb23381d
    O42 - Logiciel: SWF Opener - (.UnH Solutions.) [HKLM] -- {01386D1F-ADE7-43B4-A4E9-312FC5BC726F}_is1
    O42 - Logiciel: SWF2EXE Converter V1.0 - (.ApecSoft Inc..) [HKLM] -- ApecSoft SWF2EXE Converter_is1
    O42 - Logiciel: Samsung Mobile Modem Device Software - (.Pas de propriétaire.) [HKLM] -- Samsung Mobile Modem Device
    O42 - Logiciel: Samsung Mobile phone USB driver Software - (.Pas de propriétaire.) [HKLM] -- Samsung Mobile phone USB driver
    O42 - Logiciel: Samsung New PC Studio - (.Samsung Electronics Co., Ltd..) [HKLM] -- InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}
    O42 - Logiciel: Samsung New PC Studio - (.Samsung Electronics Co., Ltd..) [HKLM] -- {F193FC0E-9E18-40FC-A974-509A1BDD240A}
    O42 - Logiciel: SamsungConnectivityCableDriver - (.Samsung.) [HKLM] -- {7E84FAC8-C518-40F9-9807-7455301D6D25}
    O42 - Logiciel: Save Flash 4.3 - (.PilotGroup Ltd.) [HKLM] -- Save Flash
    O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- KB931906
    O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- {0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM] -- {A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
    O42 - Logiciel: SendMe 1.0.2 - (.LedPC Application.) [HKLM] -- SendMe_is1
    O42 - Logiciel: SereneScreen Aquarium - (.Prolific Publishing, Inc..) [HKLM] -- SereneScreen Aquarium_is1
    O42 - Logiciel: Shape Collage - (.Shape Collage Inc..) [HKLM] -- ShapeCollage
    O42 - Logiciel: Shared Add-in Extensibility Update for Microsoft .NET Framework 2.0 (KB908002) - (.Microsoft.) [HKLM] -- {09959E11-AD5D-408E-96AF-E3346954D6B8}
    O42 - Logiciel: Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002) - (.Microsoft.) [HKLM] -- {64F3B15C-24C7-4B2B-9B72-65CCBBD7F06B}
    O42 - Logiciel: SiS 900 PCI Fast Ethernet Adapter Driver - (.Pas de propriétaire.) [HKLM] -- SiSLan
    O42 - Logiciel: Skype Toolbars - (.Skype Technologies S.A..) [HKLM] -- {981029E0-7FC9-4CF3-AB39-6F133621921A}
    O42 - Logiciel: Skype for Outlook 1.0.0.0 - (.Skype Technologies.) [HKLM] -- SkypeForOutlook_is1
    O42 - Logiciel: Skype(TM) 4.2 - (.Skype Technologies S.A..) [HKLM] -- {D103C4BA-F905-437A-8049-DB24763BBE36}
    O42 - Logiciel: Socusoft Photo To Video Converter Free Version 8.00 - (.www.socusoft.com.) [HKLM] -- Socusoft Photo To Video Converter Free Version_is1
    O42 - Logiciel: SpeedBit Toolbar - (.SpeedBit Ltd..) [HKLM] -- SpeedBit Toolbar
    O42 - Logiciel: SpeedBit Video Downloader - (.SpeedBit Ltd..) [HKLM] -- SpeedBit Video Downloader
    O42 - Logiciel: Spelling Dictionaries Support For Adobe Reader 8 - (.Adobe Systems.) [HKLM] -- {AC76BA86-7AD7-5464-3428-800000000003}
    O42 - Logiciel: Streaming Video Recorder V2.0.7 - (.Apowersoft.) [HKLM] -- {2CD65167-671F-49A3-B6C7-3B919DF028E2}_is1
    O42 - Logiciel: SuperCopier2 - (.Pas de propriétaire.) [HKLM] -- SuperCopier2
    O42 - Logiciel: Surligneur (Windows Live Toolbar) - (.Microsoft Corporation.) [HKLM] -- {81B5F83F-2291-48B0-8375-36B63A9BF5B0}
    O42 - Logiciel: Switch Sound File Converter - (.NCH Software.) [HKLM] -- Switch
    O42 - Logiciel: Todae - Live Media - (.Todae.fr.) [HKLM] -- Live Media
    O42 - Logiciel: Toolbar Uninstaller 1.0.0.1 - (.Decomputeur.nl.) [HKLM] -- Toolbar Uninstaller_is1
    O42 - Logiciel: UControl Scan and Remove - (.Pas de propriétaire.) [HKLM] -- UControl Scan and Remove
    O42 - Logiciel: Ultimate Christmas Scenic Reflections 3.0 - (.ScenicReflections.com.) [HKLM] -- Ultimate Christmas Scenic Reflections
    O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
    O42 - Logiciel: V.I.M. (remove only) - (.Pas de propriétaire.) [HKLM] -- V.I.M.
    O42 - Logiciel: VB Runtime - (.Pas de propriétaire.) [HKLM] -- VB Runtime
    O42 - Logiciel: VCRedistSetup - (.Nero AG.) [HKLM] -- {3921A67A-5AB1-4E48-9444-C71814CF3027}
    O42 - Logiciel: VDownloader 1.12 - (.Enrique Puertas.) [HKLM] -- {CA567AD5-33A4-403D-86D1-EE2D38251951}_is1
    O42 - Logiciel: VLC media player 1.1.0 - (.VideoLAN.) [HKLM] -- VLC media player
    O42 - Logiciel: Visual C++ 2008 x86 Runtime - (v9.0.30729) - (.Microsoft Corporation.) [HKLM] -- {F333A33D-125C-32A2-8DCE-5C5D14231E27}
    O42 - Logiciel: Visual C++ 2008 x86 Runtime - v9.0.30729.01 - (.Microsoft Corporation.) [HKLM] -- {F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01
    O42 - Logiciel: Visual C++ 9.0 ATL (x86) WinSXS MSM - (.Microsoft Corporation.) [HKLM] -- {CEC8F2E3-AC9A-357C-BFCB-BFAC37C4AC50}
    O42 - Logiciel: Visual C++ 9.0 CRT (x86) WinSXS MSM - (.Microsoft Corporation.) [HKLM] -- {0138F525-6C8A-333F-A105-14AE030B9A54}
    O42 - Logiciel: VolvoxSoft Convertisseur Video Son Volvox 1.2 - (.VolvoxSoft.) [HKLM] -- Convertisseur Video Son Volvox
    O42 - Logiciel: Vos Photos à la Télé sur CD-DVD Deluxe Evaluation - (.Micro Application.) [HKLM] -- Vos Photos à la Télé sur CD-DVD Deluxe Evaluation
    O42 - Logiciel: Weezo - (.Peer 2 World.) [HKLM] -- Weezo_is1
    O42 - Logiciel: Weezo DLL Pack (C:\Program Files\Weezo\) - (.Pas de propriétaire.) [HKLM] -- ST6UNST #2
    O42 - Logiciel: Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray - (.Microsoft Corporation.) [HKLM] -- KB952011
    O42 - Logiciel: Windows Genuine Advantage Notifications (KB905474) - (.Microsoft Corporation.) [HKLM] -- WgaNotify
    O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM] -- KB892130
    O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM] -- WGA
    O42 - Logiciel: Windows Genuine Advantage v1.3.0254.0 - (.Microsoft.) [HKLM] -- {63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
    O42 - Logiciel: Windows Imaging Component - (.Microsoft Corporation.) [HKLM] -- WIC
    O42 - Logiciel: Windows Internet Explorer 7 - (.Microsoft Corporation.) [HKLM] -- ie7
    O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM] -- ie8
    O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {B3B487E7-6171-4376-9074-B28082CEB504}
    O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {3175E049-F9A9-4A3D-8F19-AC9FB04514D1}
    O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {445B183D-F4F1-45C8-B9DB-F11355CA657B}
    O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11
    O42 - Logiciel: Windows Media Format 11 runtime - (.Pas de propriétaire.) [HKLM] -- Windows Media Format Runtime
    O42 - Logiciel: Windows Media Player Firefox Plugin - (.Microsoft Corp.) [HKLM] -- {69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
    O42 - Logiciel: Windows XP Service Pack 3 - (.Microsoft Corporation.) [HKLM] -- Windows XP Service
    O42 - Logiciel: Windows XP Winter Fun Pack Screensavers - (.Microsoft Corporation.) [HKLM] -- {27D0C7AB-59F1-4D4D-A0BB-05A31AC919EA}
    O42 - Logiciel: WordSearcher - (.Pas de propriétaire.) [HKLM] -- WordSearcher
    O42 - Logiciel: YouTube MP4 To MP3 Converter V2.0 - (.YouTube MP3 Downloader.) [HKLM] -- YouTube MP4 To MP3 Converter_is1
    O42 - Logiciel: atropicaltreat_3142328 Screen Saver - (.Pas de propriétaire.) [HKLM] -- atropicaltreat_3142328
    O42 - Logiciel: avast! Internet Security - (.Alwil Software.) [HKLM] -- avast5
    O42 - Logiciel: dBpowerAMP WMA V9.1 Codec - (.Pas de propriétaire.) [HKLM] -- dBpowerAMP WMA V9.1 Codec
    O42 - Logiciel: eMule - (.Pas de propriétaire.) [HKLM] -- eMule
    O42 - Logiciel: fullscreensavers Toolbar - (.Pas de propriétaire.) [HKLM] -- fullscreensavers Toolbar
    O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {81063354-9060-42B2-A000-1EBE96778AA9}
    O42 - Logiciel: neroxml - (.Nero AG.) [HKLM] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}
    O42 - Logiciel: rosedance_3112166 Screen Saver - (.Pas de propriétaire.) [HKLM] -- rosedance_3112166
    O42 - Logiciel: tannenbaum_3147186 Screen Saver - (.Pas de propriétaire.) [HKLM] -- tannenbaum_3147186
    O42 - Logiciel: whitewinter_3133206 Screen Saver - (.Pas de propriétaire.) [HKLM] -- whitewinter_3133206

    ---\\ HKCU & HKLM Software Keys
    [HKCU\Software\120671120]
    [HKCU\Software\3rd Eye Solutions]
    [HKCU\Software\?? ?? ???? ????? ??? ?? ????]
    [HKCU\Software\ABBYY]
    [HKCU\Software\AC3Filter]
    [HKCU\Software\ACD Systems]
    [HKCU\Software\ALWIL Software]
    [HKCU\Software\ASProtect]
    [HKCU\Software\AT21 sarl]
    [HKCU\Software\Ad-Remover]
    [HKCU\Software\Adaptec]
    [HKCU\Software\Adobe]
    [HKCU\Software\Ahead]
    [HKCU\Software\Analog Devices]
    [HKCU\Software\Anark]
    [HKCU\Software\Anfy Team]
    [HKCU\Software\AntiToolbar]
    [HKCU\Software\Anuman
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      methabo tu deviens fatiguant je te demande de poster ton rapport en utilisant cijoint comme demander dans la procédure , car il est trop long pour passer sur le forum , merci de le faire

      Pour me le transmettre clique sur ce lien :

      http://www.cijoint.fr/index.php

      Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\bureau\.ZHPDiag.txt

      ou directement en choisissant bureau et ZHPDiag.txt clique dessus

      Clique sur Ouvrir.

      Clique sur "Cliquez ici pour déposer le fichier".

      Un lien de cette forme :

      http://www.cijoint.fr/cjlink.php?file=cj200905/cib7SU.txt

      est ajouté dans la page.

      Copie ce lien dans ta réponse.


      et si problème de compréhention aide toi de ce petit tuto ou j'aui mis des images étapes par étapes !!


      envoie-le sur : http://www.cijoint.fr/index.php

      fais parcourir comme sur la capture d'écran : http://sd-1.archive-host.com/membres/images/89820622056365782/cijoint_ima_1.jpg

      recherche le rapport :http://sd-1.archive-host.com/membres/images/89820622056365782/cijoint_ima2.jpg

      sélectionne le rapport soit en cliquand dessus et ouvrir ou en double cliquand dessus

      et puis sur " cliquer ici pour déposer le fichier " : http://sd-1.archive-host.com/membres/images/89820622056365782/cijoint_ima3.jpg

      un lien bleu de cette forme va apparaitre :

      Veuillez noter le lien ci-dessous qui vous permettra d'accéder à ce fichier. 
      C'est ce même lien que vous devrez transmettre à vos correspondants
      http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt 
      


      comme sur l'image:
      http://sd-1.archive-host.com/membres/images/89820622056365782/cijjoint_ima4.jpg

      et c'est ce lien qu'il te faut copier coller sur la discution , merci
      0
  12. methafo
     
    Ia ora na,

    Je suis terriblement désolé du dérangement que je procure vu ma piètre connaissance en informatique et la peur de faire des bêtise, à Moorea, les techniciens en informatique ne courent pas le lagon, en cas d'erreur, je suis obligé d'emmener mon P.C sur Tahiti, île située face à celle de Moorea.
    Encore toutes mes excuses pour les dérangements et surtout un très grand merci pour ta gentillesse, ta patience, ton dévouement et pour ton temps passé à me rendre service.
    Mauruuru (merci en tahitien)

    Voici le lien :

    http://www.cijoint.fr/cjlink.php?file=cj201009/cijN3NA9XL.txt
    0
  13. methafo
     
    http://www.cijoint.fr/cjlink.php?file=cj201009/cijN3NA9XL.txt
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      ok tu vois quand tu fais exactement comme expliqué c'est bien plus simple , tu vas faire un nouveau fixe avec zhpfix tu fais exactement comme dit , et pas de problème

      1) fixes les ligne donnés

      pour les copier tu maintiens ton clique gauche de ta souris enfoncé , tu la déplaces pour les mettre en surbrillant et puis tu fais un clique droit dessus et COPIER et tu suis la procédure tranquillement , merci

      . Copie les lignes suivantes en GRAS


      [HKCU\Software\BulletProofSoft.com]
      [HKCU\Software\ImInstaller]
      [HKCU\Software\SpiderMessenger]
      [HKCU\Software\Visio RAS Script]
      [HKCU\Software\sponsoradulto]
      [HKLM\Software\AskPBar]
      [HKLM\Software\ImInstaller]
      [HKLM\Software\UControl]
      O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\UControl
      O61 - LFC:Last File Created 29/09/2010 - 07:03:28 ---A- C:\Documents And Settings\All Users\Application Data\Alwil Software\Avast5\fw\config.xml [2516]
      O61 - LFC:Last File Created 29/09/2010 - 07:03:34 ---A- C:\Documents And Settings\christian\Local Settings\Temp\config.xml [0]
      O61 - LFC:Last File Created 29/09/2010 - 07:05:01 ---A- C:\Documents And Settings\christian\Application Data\Skype\bequissou315\config.xml [27813]
      O64 - Services: CurCS - (.not file.) - ndisrd (ndisrd) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDISRD
      O64 - Services: CurCS - (.not file.) - Windows Log (Windows Log) .(.Pas de propriétaire - Pas de description.) - LEGACY_WINDOWS_LOG
      O65 - LUF:07/09/2006 (.Pas de propriétaire - DOT Application.) (1, 0, 0, 2) - c:\windows\system32\WinSys.exe




      . Lance ZHPFix de Nicolas Coolman qui se trouve sur ton bureau
      . Pour XP, double-clique sur ZHPFix
      . pour Vista et seven, faire un clic droit sur l'icône et exécute en tant qu'administrateur.

      . Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)

      Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

      Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

      . cliques sur OK
      . Clique sur « Tous », puis sur « Nettoyer »
      . Copie/colle la totalité du rapport dans ta prochaine réponse
      tu le trouveras dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport




      2) tu me dira comment va ton pc et puis tu postesras un nouveau zhpdiag pour contrôle et finaliser le nettoyage , merci


      Double cliques sur le raccourci ZHPDiag sur ton Bureau pour XP sinon clique droit et en tant que administrateur !!

      Clique sur le Tournevis puis sur Tous pour cocher toutes les cases des options.

      Cliques sur la loupe pour lancer l'analyse.

      Laisses l'outil travailler, il peut être assez long.

      A la fin de l'analyse,clique sur l'appareil photo et enregistre le rapport sur ton Bureau.


      Fermes ZHPDiag en fin d'analyse.


      Pour me le transmettre clique sur ce lien :

      http://www.cijoint.fr/index.php

      Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\bureau\.ZHPDiag.txt

      ou directement en choisissant bureau et ZHPDiag.txt clique dessus

      Clique sur Ouvrir.

      Clique sur "Cliquez ici pour déposer le fichier".

      Un lien de cette forme :

      http://www.cijoint.fr/cjlink.php?file=cj200905/cib7SU.txt

      est ajouté dans la page.

      Copie ce lien dans ta réponse.
      0
  14. methafo
     
    Ia ora na,

    Je retrouve un air de jeunesse à mon P.C.
    Voici le report suivant : http://www.cijoint.fr/cjlink.php?file=cj201009/cijw9QFS7K.txt
    Merci encore
    Christian
    0
  15. methafo
     
    Bon, cette fois-ci, j'espère avoir bien suivi la marche à suivre...!!!...

    Cordialement,

    Christian

    http://www.cijoint.fr/cjlink.php?file=cj201009/cijumHo3yy.txt
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      bonjour, parfait tu vois quand tu veux tu y arreive !! lol !!

      bon pour moi c'est bon sauf si toi tu me dis avoir toujours des problèmes ??

      si c'est bon pour toi tu pourras faire cela !!

      1) désinstalles les outils utiliser en utilisant delfix

      télecharge DELFIX :
      http://sd-1.archive-host.com/membres/up/17959594961240255/DelFix.exe

      lance le en option 2, valide avec entrée

      poste son rapport il devrait se trouver dan C:



      2) fais un nettoyage avec ccleaner et les réglages donnés


      télécharges Ccleaner à partir de cette adresses

      https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/


      .enregistres le sur le bureau
      .double-cliques sur le fichier pour lancer l'installation
      .sur la fenêtre de l'installation langage bien choisir français et OK
      .cliques sur suivant
      .lis la licence et j'accepte
      .cliques sur suivant
      .la tu ne gardes de coché que mettre un raccourci sur le bureau et puis contrôler automatiquement les mises à jour de Ccleaner
      .cliques sur intaller
      .cliques sur fermer
      .double-cliques sur l'icône de Ccleaner pour l'ouvrir
      .une fois ouvert tu cliques sur option et puis avancé
      .tu décoches effacer uniquement les fichiers, du dossier temp de windows plus vieux que 24 heures
      .cliques sur nettoyeur
      .cliques sur windows et dans la colonne avancé
      .cochesla première case vieilles données du perfetch que celle-la
      .cliques sur analyse une fois l'analyse terminé
      .cliques sur lancer le nettoyage et sur la demande de confirmation OK il vas falloir que tu le refasses une autre fois une fois fini vériffis en appuiant de nouveau sur analyse pour être sur qu'il n'y est plus rien
      .cliques maintenant sur registre et puis sur rechercher les erreurs
      .laisses tout cochées et cliques sur réparrer les erreurs sélectionnées
      .il te demande de sauvegarder OUI
      .tu lui donnes un nom pour pouvoir la retrouver et enregistre
      .cliques sur corriger toutes les erreurs sélectionnées et sur la demande de confirmation OK
      .il supprime et fermer tu vériffis en relancant rechercher les erreurs
      .tu retournes dans option et tu recoches la case effacer uniquement les fichiers, du dossier temp de windows plus vieux que 24 heures et sur nettoyeur, windows sous avancé tu décoches la première case vieilles données du perfetch
      .tu peux fermer Ccleaner

      pour aider si besion tutoriel: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php




      il restera la restauration système à purger et des petit conseil
      0
    2. methafo
       
      http://www.cijoint.fr/cjlink.php?file=cj201010/cijKI7QX2j.txt
      Merci encore
      0
    3. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      bonjour, si tu as fais le nettoyage avec ccleaner , tu pourras purger la restauration système, je te donne la procédure plus bas !
      tu as normalement toujours malwarebytes sur ton pc, je te conseillerais de le conserver et de faire un examen rapide de ton pc régulièrement avec cela sera un bon complément à Avast
      MAIS toujours lui faire faire la mise à jour avant de faire l'examen
      et puis maintemant tu as ccleaner que perso je te recommande de conserver et d'utiliser le plus souvant possible en mode nettoyeur , le mieux est de le faire à chaque arrêt du pc ou plus simple comme chez nous ou il est en automatique pour cette fonction !!
      et passe le en mode registre après chaques désinstallation de programmes !!
      et puis tu peux l'utiliser aussi pour stoper les démarrages automatique qui ne servent à rien sauf ralentir le pc au démarrage !! si tu veux savoir lesquelles tu le dis etr je te dirais d'après le dernier rapport de zhpdiag que tu ma donné !!

      bon tu pourras purger la restauration système



      Après une désinfection il est utile de supprimer tous les points de restauration système de façon à ne pas remonter, par mégarde, un point de restauration infecté.

      Pour cela, il faut désactiver la restauration système (ce qui aura pour conséquence de supprimer tous les points de restauration existants) puis la réactiver juste après pour que Windows continue à faire des points de sauvegarde réguliers.


      Supprimer les anciens points de restauration : System Volume Information\_restore

      (1) Désactiver la Restauration du système

      cliques sur Démarrer
      Cliques droit sur Poste de travail
      cliques sur Propriétés
      Cliques sur l'onglet Restauration du système
      Coches Désactiver la Restauration du système sur tous les lecteurs
      Cliques sur Appliquer, Lorsque le message de confirmation apparaît,
      cliques sur Oui.
      Cliques sur OK.


      (2) Activer la Restauration du système


      cliques sur Démarrer
      Cliques droit sur Poste de travail
      cliques sur Propriétés
      Cliques sur l'onglet Restauration du système
      Décoches Désactiver la Restauration du système sur tous les lecteurs
      Cliques sur Appliquer, Lorsque le message de confirmation apparaît,
      cliques sur Oui.
      Cliques sur OK.





      (3) Créer un point de restauration


      .cliquer sur démarrer
      .cliquer sur tous les programmes
      .cliquer sur accessoires
      .cliquer sur outils système
      .cliquer sur restauration du système
      .sur la fenêtre qui s'ouvre cocher créer un point de restauration
      .cliquer sur suivant
      .dans la fenêtre description du point de restauration lui donner un nom explisitede façon à savoir à quoi il correspond
      .cliquer sur céer
      .une fois que la page s'affiche avec en haut sur gauche le nom et l'heure de ton point de restauration fermes la fenêtre
      0
  16. Methafo Messages postés 11 Statut Membre
     
    Bonjour,
    Merci pour les conseils que j'ai suivi à la lettre ; j'ai tout fait comme tu m'as dit. Maintenant, il est vrai que tes conseils concernant les démarrages automatiques m'intéresse car je n'ai jamais oser le faire par méconnaissance.
    Encore un grand merci pour ton aide.
    Christian
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      bonjour, je te mets ce que tu as en démarrage automatique tu regarde et puis tu vois ce que tu veux garder , perso sur mes pc j'ai juste les outils de sécurité , mais si tu as un portable cela est différent car il y a le touche pad !!

      bon je te mets la liste et en gras ce que je ferais je te dis comment faire pour les stoper en bas !!

      O4 - HKLM\..\Run: [ISUSPM Startup] . (.InstallShield Software Corporation - InstallShield Update Service Update Manager.) -- C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe perso je déactiverais

      O4 - HKLM\..\Run: [ISUSScheduler] . (.InstallShield Software Corporation - InstallShield Update Service Scheduler.) -- C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe perso je déactiverais

      O4 - HKLM\..\Run: [zBrowser Launcher] . (.Logitech Inc. - iTouch Application.) -- C:\Program Files\Logitech\iTouch\iTouch.exe la je pense que c'est le touche pade !! donc je laisse

      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe la c'est la web cam !! donc pas vraiment utile au démarrage tu peux déactiver !! elle démarrera quand tu cliqueras sur la cam dans le poste de trvail ou avec msn !!

      O4 - HKLM\..\Run: [avast5] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\avastUI.exe TU CONSERVES C'EST TON ANTI-VIRUS

      O4 - HKCU\..\Run: [SuperCopier2.exe] . (.SFX TEAM - SuperCopier 2 (explorer file copy replaceme.) -- C:\Program Files\SuperCopier2\SuperCopier2.exe La perso je connais pas, mais surement pas indispensable au démarrage, donc perso je déactive

      O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe skype est un logiciel comme windows live messenger, et perso je vois pas l'utilité au démarrage tu le démarres si tu en as besoin en cliquand sur l'icône, donc perso je déactive

      O4 - HKCU\..\Run: [AnnivJ] . (.http://www.kiteatao.net/standard.view?idMenu=2.1.1 - email: annivj@ - Annonce le jour J des anniversaires de vos.) -- C:\Program Files\AnnivJ\AnnivJ.exe cela me semble un utilitaire de genre pense bête !! alors la tu fais comme tu veux mais bon j'en vois pas l'utilité!!

      O4 - HKCU\..\Run: [IDMan] . (.Tonec Inc. - Internet Download Manager (IDM).) -- C:\Program Files\Internet Download Manager\IDMan.exe déactives

      O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\windows\system32\ctfmon.exe tu peux déactiver toutes les lignes ctfmon mais il y en n'a qui reviendront car cela fais partie de windows pour incérer des carractérer spéciaux genre carractére arabe dans du texte

      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
      O4 - HKUS\S-1-5-21-1220945662-1303643608-682003330-1012-1220945662-1303643608-682003330-1004\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe

      O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Démarrage\NETGEAR WG111v2 Smart Wizard.lnk . (.Pas de propriétaire.) -- C:\Program Files\NETGEAR\WG111v2\WG111v2.exe tu touches pas c'est ta carte réseau wifi

      O4 - Global Startup: C:\Documents And Settings\christian\Menu Démarrer\Programmes\Démarrage\Weezo.lnk . (.Peer 2 World.) -- F:\Weezo\bin\Weezo.exe la si c'est toi qui as installer et si tu utilises cela ok tu fais comme tu veux , mais perso je vois pas trop l'intérêt d'avoir accés à ton pc à distance comme expliqué ici: https://www.commentcamarche.net/telecharger/communication/23749-weezo/

      bon maintenant que on sait qui sont les lignes , pour déactiver celle que tu veux , tu ouvres ccleaner , et puis sur outils , et puis sur démarrage, et la tu cliques sur la ligne que tu ne veux plus voir démarrer automatiquement, et déactiver "" surtout pas effacer l'entrée"" comme cela si tu trouves que c'était plus pratique en ayant en démarrage automatique il te suffit de la réactiver , perso après chaque installation de logiciel je fais un petit tour dans démarrages pour voir si il m'a pas coller quelque chose dedans et la je le déactive comme cela je ne conserve que le triste minimum
      0
  17. methafo
     
    Ok, j'ai tout fait comme tu m'as dit et ça marche. Weezo me sert à communiquer et partager photos, films et autres dossiers à ma famille en Métropole car depuis Tahiti et avec la distance, ce logiciel s'avère très pratique. Mon seul petit soucis est que parfois il fonctionne et parfois non, l'UPnP et l'entrée de port 80 ou autre que je n'arrive pas à configuré sur mon routeur Netgear DG834g.
    Voila, merci pour tout, si je peux faire quelque chose pour toi, n'hésites-pas.
    Christian
    0
    1. jacques.gache Messages postés 34829 Statut Contributeur sécurité 1 645
       
      ok si tu veux faire quelque chose pour moi envois moi un peu de soleil !!! pour les vahinés pas la penne ma femme va pas être d'accord !! lol !! mdr !!

      @+ et bonne route sur la toile
      0