Plus de réseaux Erreur1068 + 1747

Bonjour à tous,
Depuis trois jours mon PC est en berne. Mon antivirus est avast et je tourne sur Vista.

Depuis l'installation d'un logiciel sur mon PC, celui-çi ne trouve plus de réseaux. J'ai le message "Erreur 1068: Le service de dépendance n'a pas pu démarrer"
Il est très lent au démarrage.
A chaque démarrage le message "Windows n'a pas pu se connecter au Service de notification d'événement système etc." s'affiche.
Il est aussi impossible d'imprimer des documents "à cause de problème de configuration". J'ai fait un tour dans le panneau de config et la section imprimante est en effet vide maintenant.
Quand j'essaye de modifier l'état des services j'obtiens l'erreur 1747. Je ne peux donc pas activer le service de configuration WLAN.

J'ai fait quelques recherches et finalement je soupçonne un virus hdlrr ou bagle/beagle.

J'ai vérifié que le protocole EAP était démarré et en automatique puis que dans hkey local machine>system>currentcontrol set>services>Ndisuio, le start était bien sur le numero 3. J'ai aussi essayé d'entrer "netsh winsock reset" dans invite de commande. Sans résultat.

Je vous en prie si vous avez la moindre idée de ce que je pourrais faire pour retrouver un ordinateur sain aidez-moi.

Merci d'avance!

28 réponses

Résumé de la discussion

Plusieurs symptômes indiquent une infection sur Windows Vista: impossibilité de détecter des réseaux, messages d'erreur 1068 et 1747 liés au démarrage et au service, et imprimerie bloquée par une mauvaise configuration. Des interventions proposent des outils de détection et nettoyage tels que FindyKill, ZHPDiag et ComboFix, avec des procédures étape par étape, désactivation temporaire de protections et envoi des rapports vers des services en ligne. Des infections spécifiques sont évoquées, notamment Qhozoa.exe, et plusieurs répondants recommandent des scans complémentaires via TDSSKiller ou des rapports Combofix pour identifier et supprimer les menaces avant de rétablir les services réseau et l'impression. Certaines interventions soulignent la nécessité d'utiliser des outils compatibles Vista et de sauvegarder les données avant toute manipulation.

Bobot (l’IA à votre service)
  1. Bonjour

    Vérifions si il s'agit de Bagle.

    Utilisateurs de Vista /!\

    Désactivez le contrôle des comptes utilisateurs avant utilisation de cet outil:

    * Allez dans "Démarrer" puis Panneau de configuration.
    * Double Cliquez sur l'icône Comptes d'utilisateurs et sur "Activer ou désactiver le contrôle des comptes d'utilisateurs".
    * Décochez la case "Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur".
    * Validez par OK et redémarrez.
    * Aide en image.

    Explications option 1 (Recherche) :

    Télécharge FindyKill ( de El Desaparecido) sur ton bureau et installe le :

    http://www.teamxscript.org/findykillTelechargement.html

    ! Déconnecte toi et ferme toutes applications en cours !

    * Double clique sur "FindyKill.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut.

    * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)

    * Double-clique sur le raccourci FindyKill qui est sur ton bureau pour lancer l'outil.
    * Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

    * Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]

    Laisse travailler l'outil et ne touche à rien ...

    --> Poste le rapport qui apparaît à la fin , sur le forum ...

    ( le rapport est sauvegardé aussi sous C:\FindyKill.txt )
    ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

    Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

    @+
    0
    1. Merci beaucoup pour ton aide guillaume,

      Voilà le rapport Findykill:

      ############################## | FindyKill V5.052 |

      # User : Meg (Administrateurs) # PC-DE-MEG
      # Update on 23/10/2010 by El Desaparecido
      # Start at: 15:32:26 | 19/12/2010
      # Website : http://www.teamxscript.org/
      # Contact : eldesaparecido@teamxscript.org

      # AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
      # Microsoft® Windows Vista(TM) Édition Intégrale (6.0.6001 32-bit) # Service Pack 1
      # Internet Explorer 7.0.6001.18000
      # Windows Firewall Status : Enabled

      # C:\ # Disque fixe local # 232,88 Go (13,31 Go free) # NTFS
      # D:\ # Disque CD-ROM
      # E:\ # Disque CD-ROM
      # F:\ # Disque amovible # 965,61 Mo (427,94 Mo free) # FAT
      # G:\ # Disque CD-ROM

      ################## | Eléments infectieux |

      C:\Windows\prefetch\KEYGEN NEW.EXE-7EA6E1C1.pf
      C:\Windows\prefetch\KEYGEN.EXE-27228029.pf

      ################## | Registre |

      ################## | Etat |

      # Affichage des fichiers cachés : OK

      # Mode sans echec : OK

      # (!) Uac = 0x0

      # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
      # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
      # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
      # (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
      # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )

      ################## | ! Fin du rapport # FindyKill V5.052 ! |
      0
      1. Re

        1)! Déconnecte toi et ferme toutes applications en cours (navigateur compris) .

        * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)

        * Relance "FindyKill" : au menu principal choisis l'option " F " pour français et tape sur [entrée] .

        * Au second menu choisis l'option 2 (suppression) et tape sur [entrée]

        * Le pc va redémarrer automatiquement ...

        ? le programme va travailler, ne touche à rien ... , ton bureau ne sera pas accessible c est normal !

        --> Poste le rapport qui apparaît à la fin ( le rapport est sauvegardé aussi sous C:\FindyKill.txt )

        /!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valide

        2)Pour vérifications plus approfondies, fait ceci stp

        Ouvre ce lien et télécharge ZHPDiag de Nicolas Coolman :

        https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

        Ou

        https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/

        Serveur N°2

        Ou

        http://www.premiumorange.com/zeb-help-process/zhpdiag.html
        en bas de la page ZHP avec un numéro de version.

        Une fois le téléchargement achevé, dé zippe le fichier obtenu et place ZHPDiag.exe sur ton Bureau.

        Double-clique sur l'icône pour lancer le programme. Sous Vista ou Seven clic droit « exécuter en tant que administrateur »

        Clique sur la loupe pour lancer l'analyse.

        Laisse l'outil travailler, il peut être assez long.

        Ferme ZHPDiag en fin d'analyse.

        Pour transmettre le rapport clique sur ce lien :

        http://www.cijoint.fr/index.php
        Clique sur Parcourir et cherche le répertoire où est installé ZHPDiag (en général C:\Program Files\ZHPDiag).

        Sélectionne le fichier ZHPDiag.txt.

        Clique sur "Cliquez ici pour déposer le fichier".

        Un lien de cette forme :

        http://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt

        est ajouté dans la page.

        Copie ce lien dans ta réponse.

        Poste le rapports au fur et à mesure.

        Merci.

        @+
        0
        1. voilà le deuxième rapport Findykill. Je vais de suite faire l'analyse ZHPDiag.

          ############################## | FindyKill V5.052 |

          # User : Meg (Administrateurs) # PC-DE-MEG
          # Update on 23/10/2010 by El Desaparecido
          # Start at: 16:01:38 | 19/12/2010
          # Website : http://www.teamxscript.org/
          # Contact : eldesaparecido@teamxscript.org

          # AMD Athlon(tm) 64 X2 Dual Core Processor 5000+
          # Microsoft® Windows Vista(TM) Édition Intégrale (6.0.6001 32-bit) # Service Pack 1
          # Internet Explorer 7.0.6001.18000
          # Windows Firewall Status : Enabled

          # C:\ # Disque fixe local # 232,88 Go (13,06 Go free) # NTFS
          # D:\ # Disque CD-ROM
          # E:\ # Disque CD-ROM
          # G:\ # Disque CD-ROM

          ################## | Eléments infectieux |

          Supprimé ! C:\Windows\prefetch\KEYGEN NEW.EXE-7EA6E1C1.pf
          Supprimé ! C:\Windows\prefetch\KEYGEN.EXE-27228029.pf

          ################## | CRC32 ... |

          ################## | Registre |

          ################## | Etat |

          # Mode sans echec : OK

          # Affichage des fichiers cachés : OK

          # Uac : OK

          # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
          # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
          # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
          # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
          # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )

          ################## | Fichiers corrompus |

          ... OK !

          ################## | Upload |
          0
          1. Et voilà le lien fournit par ci joint: http://www.cijoint.fr/cjlink.php?file=cj201012/cijsM9j9KA.txt

            Et le rapport ZHPDiag:

            Rapport de ZHPDiag v1.27.143 par Nicolas Coolman, Update du 18/12/2010
            Run by Meg at 19/12/2010 21:17:42
            Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
            Contact : nicolascoolman@yahoo.fr

            ---\\ Web Browser
            MSIE: Internet Explorer v7.0.6001.18000 (Defaut)

            ---\\ System Information
            Windows Vista Ultimate Edition, 32-bit Service Pack 1 (Build 6001)
            Processor: x86 Family 15 Model 107 Stepping 2, AuthenticAMD
            Operating System: 32 Bits
            Boot mode: Normal (Normal boot)
            Total RAM: 2045 MB (63% free)
            System Restore: Activé (Enable)
            System drive C: has 13 GB (5%) free of 233 GB

            ---\\ Logged in mode
            Computer Name: PC-DE-MEG
            User Name: Meg
            All Users Names: Meg, Administrateur,
            Unselected Option: O1,O45,O61,O62,O65,O82
            Logged in as Administrator

            ---\\ DOS/Devices
            C:\ Hard drive, Flash drive, Thumb drive (Free 13 Go of 233 Go)
            D:\ CD-ROM drive (Not Inserted)
            E:\ CD-ROM drive (Not Inserted)
            F:\ Floppy drive, Flash card reader, USB Key (Free 0 Go of 1 Go)
            G:\ CD-ROM drive (Not Inserted)

            ---\\ Security Center & Tools Informations
            [HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK
            [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
            [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
            [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
            [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
            [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
            [HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK
            [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK
            [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK
            [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK
            [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
            [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK

            ---\\ Recherche particulière de fichiers génériques
            [MD5.4F554999D7D5F05DAAEBBA7B5BA1089D] - (.Microsoft Corporation - Explorateur Windows.) (.29/10/2008 07:29:41.) -- C:\Windows\Explorer.exe [2927104]
            [MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de démarrage de Windows.) (.21/01/2008 03:21:52.) -- C:\Windows\System32\Wininit.exe [96768]
            [MD5.C2610B6BDBEFC053BBDAB4F1B965CB24] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.21/01/2008 03:22:59.) -- C:\Windows\System32\Winlogon.exe [314880]
            [MD5.2D9C903DC76A66813D350A562DE40ED9] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.21/01/2008 03:21:09.) -- C:\Windows\System32\drivers\atapi.sys [21560]
            [MD5.B4EFFE29EB4F15538FD8A9681108492D] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.21/01/2008 03:21:58.) -- C:\Windows\System32\drivers\ntfs.sys [1081912]

            ---\\ Processus lancés
            [MD5.25B2065B6EE1B9DA77899CE8BAC251A2] - (.Wacom Technology, Corp. - Tablet user module for professional driver.) -- C:\Windows\system32\WTablet\Wacom_TabletUser.exe [1823528]
            [MD5.D93985F5D87DF1A119E939EADB5C4B9E] - (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Windows\RtHDVCpl.exe [6266880]
            [MD5.3A0647BDED81DBE0BCBB51D70B22C9E0] - (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jusched.exe [149280]
            [MD5.38AE7A942FC3FAB1C6A27EB65DE8F827] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2837864]
            [MD5.2DFCB2393528446AEB9FB861A8FC39AB] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [421160]
            [MD5.BF08674925F151BD4537B89A493E3E0C] - (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehtray.exe [125952]
            [MD5.33C014C1709F7222CEFF61B780EDC967] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Monitoring program.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe [49152]
            [MD5.7D168E7A2B6C2B477C4D193C8D51EE41] - (.SmartSoft - Smart Protector Pro.) -- C:\Program Files\Smart Protector Pro\SmartProtector-Pro.exe [1945600]
            [MD5.0F4195B9B348DE5CF9B822F81704B20E] - (.Microsoft Corporation - Media Center Media Status Aggregator Servic.) -- C:\Windows\ehome\ehmsas.exe [37376]
            [MD5.BA7D56C1F3DD385EE58ADDA14C6FFB54] - (.ATI Technologies Inc. - Catalyst Control Centre: Host application.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [49152]
            [MD5.DAF60E13E96ECB67F0EDAA89C6B01B8D] - (.Microsoft Corporation - Bloc-notes.) -- C:\Windows\system32\NOTEPAD.EXE [151040]
            [MD5.D3300FF793D1746A73BE59C23E3D25FB] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [620544]

            ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2)
            P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\Macromed\Flash\NPSWF32.dll
            P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
            P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
            P2 - FPN: [HKLM] [@wacom.com/wacom-plugin,version=1.1.0.3] - (.Wacom, Inc. - Wacom Dynamic Link Library.) -- C:\Program Files\TabletPlugins\npwacom.dll

            ---\\ Internet Explorer, Démarrage,Recherche,URSearchHook (R0,R1,R3)
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
            R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} . (.DeviceVM Inc. - DeviceVM Url Search Hook.) (1.0.4.9) -- C:\Windows\System32\dvmurl.dll
            R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (7.00.6000.16386 (vista_rtm.061101-2205)) -- C:\Windows\system32\ieframe.dll

            ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
            F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
            F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe
            F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

            ---\\ Browser Helper Objects de navigateur (O2)
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} . (.Safer Networking Limited - SBSD IE Protection.) -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll

            ---\\ Internet Explorer Toolbars (O3)
            O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
            O3 - Toolbar: Veoh Video Compass - {52836EB0-631A-47B1-94A6-61F9D9112DAE} . (.Veoh Networks - Veoh Video Compass.) -- C:\Program Files\Veoh Networks\Veoh Video Compass\SearchRecsPlugin.dll
            0
            1. ---\\ Applications démarrées par registre & par dossier (O4)
              O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Windows\RtHDVCpl.exe
              O4 - HKLM\..\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jusched.exe
              O4 - HKLM\..\Run: [avast5] . (.AVAST Software - avast! Antivirus.) -- C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
              O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe
              O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
              O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
              O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
              O4 - HKCU\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
              O4 - HKCU\..\Run: [SPSTEALT] . (.SmartSoft - Smart Protector Pro.) -- C:\Program Files\Smart Protector Pro\SmartProtector-Pro.exe
              O4 - HKCU\..\Run: [JP595IR86O] . (.Windows (R) Codename Longhorn DDK provider - Windows Setup API.) -- C:\Users\Meg\AppData\Local\Temp\Qgx.exe
              O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (.not file.)
              O4 - HKCU\..\Run: [Shareaza] C:\Program Files\Shareaza\Shareaza.exe (.not file.)
              O4 - HKCU\..\Run: [MsnMsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
              O4 - HKUS\S-1-5-21-1951595872-2322908241-4017401938-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
              O4 - HKUS\S-1-5-21-1951595872-2322908241-4017401938-1000\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
              O4 - HKUS\S-1-5-21-1951595872-2322908241-4017401938-1000\..\Run: [SPSTEALT] . (.SmartSoft - Smart Protector Pro.) -- C:\Program Files\Smart Protector Pro\SmartProtector-Pro.exe
              O4 - HKUS\S-1-5-21-1951595872-2322908241-4017401938-1000\..\Run: [JP595IR86O] . (.Windows (R) Codename Longhorn DDK provider - Windows Setup API.) -- C:\Users\Meg\AppData\Local\Temp\Qgx.exe
              O4 - HKUS\S-1-5-21-1951595872-2322908241-4017401938-1000\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (.not file.)
              O4 - HKUS\S-1-5-21-1951595872-2322908241-4017401938-1000\..\Run: [Shareaza] C:\Program Files\Shareaza\Shareaza.exe (.not file.)
              O4 - HKUS\S-1-5-21-1951595872-2322908241-4017401938-1000\..\Run: [MsnMsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              O4 - Global Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk . (.Pas de propriétaire.) -- C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe
              O4 - Global Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk . (.Adobe Systems Incorporated.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe

              ---\\ Autres liens utilisateurs (O4)
              O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\Adobe Photoshop CS3.lnk . (.Adobe Systems, Incorporated.) -- C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe
              O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\Media Player Classic.lnk . (.mpc-hc@Sourceforge.) -- C:\Program Files\mplayerc_homecinema_x86_v1.2.908.0\mplayerc.exe
              O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\Microsoft Office Outlook 2007.lnk . (.Pas de propriétaire.) -- C:\Windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
              O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\Microsoft Office Word 2007.lnk . (.Pas de propriétaire.) -- C:\Windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
              O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\Nero Burning ROM.lnk . (.Nero AG.) -- C:\Program Files\Nero\Nero8\Nero Burning Rom\nero.exe
              O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\SmartProtector.lnk . (.SmartSoft.) -- C:\Program Files\Smart Protector Pro\SmartProtector-Pro.exe
              O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\Spybot - Search & Destroy.lnk . (.Safer Networking Limited.) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
              O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
              O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Mail\WinMail.exe
              O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
              O4 - Global Startup: C:\Users\Meg\Desktop\Adobe Photoshop CS3.lnk . (.Adobe Systems, Incorporated.) -- C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe
              O4 - Global Startup: C:\Users\Meg\Desktop\Media Player Classic.lnk . (.mpc-hc@Sourceforge.) -- C:\Program Files\mplayerc_homecinema_x86_v1.2.908.0\mplayerc.exe
              O4 - Global Startup: C:\Users\Meg\Desktop\Microsoft Office Outlook 2007.lnk . (.Pas de propriétaire.) -- C:\Windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
              O4 - Global Startup: C:\Users\Meg\Desktop\Microsoft Office Word 2007.lnk . (.Pas de propriétaire.) -- C:\Windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
              O4 - Global Startup: C:\Users\Meg\Desktop\Nero Burning ROM.lnk . (.Nero AG.) -- C:\Program Files\Nero\Nero8\Nero Burning Rom\nero.exe
              O4 - Global Startup: C:\Users\Meg\Desktop\SmartProtector.lnk . (.SmartSoft.) -- C:\Program Files\Smart Protector Pro\SmartProtector-Pro.exe
              O4 - Global Startup: C:\Users\Meg\Desktop\Spybot - Search & Destroy.lnk . (.Safer Networking Limited.) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
              O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
              O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk . (.Microsoft Corporation.) -- C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
              O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\NJStar Communicator.lnk . (.NJStar Software Corp..) -- C:\Program Files\NJStar Communicator\NJCOM32.exe
              O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - Clé orpheline
              O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk . (.Safer Networking Limited.) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
              O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - Clé orpheline
              O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe

              ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
              O8 - Extra context menu item: Append to existing PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
              O8 - Extra context menu item: Convert link target to Adobe PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
              O8 - Extra context menu item: Convert link target to existing PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
              O8 - Extra context menu item: Convert selected links to Adobe PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
              O8 - Extra context menu item: Convert selected links to existing PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
              O8 - Extra context menu item: Convert selection to Adobe PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
              O8 - Extra context menu item: Convert selection to existing PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
              O8 - Extra context menu item: Convert to Adobe PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
              O8 - Extra context menu item: Free YouTube to Mp3 Converter . (.Pas de propriétaire - Pas de description.) -- C:\Users\Meg\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm

              ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~1\MICROS~2\Office12\REFBARH.ICO
              O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} . (.not file.) - (.not file.)

              ---\\ Winsock hijacker (Layered Service Provider) (O10)
              O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
              O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
              O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
              O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
              O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
              O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll

              ---\\ Objets ActiveX (Downloaded Program Files)(O16)
              O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} () - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

              ---\\ Modification Domaine/Adresses DNS (O17)
              O17 - HKLM\System\CCS\Services\Tcpip\..\{284122EE-762F-48C8-BA67-C70299E1EF89}: DhcpNameServer = 89.2.0.1 89.2.0.2
              O17 - HKLM\System\CS1\Services\Tcpip\..\{284122EE-762F-48C8-BA67-C70299E1EF89}: DhcpNameServer = 89.2.0.1 89.2.0.2
              O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2

              ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
              O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Contrôleur de site Web.) -- C:\Windows\system32\webcheck.dll

              ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
              O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\system32\browseui.dll

              ---\\ Liste des services NT non Microsoft et non désactivés (O23)
              O23 - Service: (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
              O23 - Service: (Ati External Event Utility) . (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) - C:\Windows\system32\Ati2evxx.exe
              O23 - Service: (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
              O23 - Service: (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: (TabletServiceWacom) . (.Wacom Technology, Corp. - Tablet Service for professional driver.) - C:\Windows\system32\Wacom_Tablet.exe
              O23 - Service: ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) . (.Cyberlink Corp. - FCL Driver.) - C:\Program Files\CyberLink\PowerDVD8\000.fcl

              ---\\ Enumération Active Desktop & MHTML Editor (O24)
              O24 - Default MHTML Editor: Last - .(.Pas de propriétaire - Pas de description.) - "C:\Program Files\Microsoft Office\Office12\WINWORD.exe (.not file.)

              ---\\ Tâches planifiées en automatique (O39)
              O39 - APT:Automatic Planified Task - C:\Windows\Tasks\CreateChoiceProcessTask.job

              ---\\ Composants installés (ActiveSetup Installed Components) (O40)
              O40 - ASIC: Windows Media Player 5.2 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Pas de propriétaire - Pas de description.) -- C:\Windows\INF\mswmp.inf
              O40 - ASIC: Microsoft Windows Mail 7 - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Pas de propriétaire - Pas de description.) -- "C:\Program Files\Windows Mail\WinMail.exe
              O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 10.1 r53.) -- C:\Windows\system32\Macromed\Flash\Flash10h.ocx

              ---\\ Pilotes lancés au démarrage (O41)
              O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
              O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
              O41 - Driver: (CSC) . (.Microsoft Corporation - Windows Client Side Caching Driver.) - C:\Windows\System32\drivers\csc.sys
              O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
              O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\System32\DRIVERS\i8042prt.sys
              O41 - Driver: (kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\System32\DRIVERS\kbdclass.sys
              O41 - Driver: (mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\System32\DRIVERS\mouclass.sys
              O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
              O41 - Driver: (netbt) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
              O41 - Driver: (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
              O41 - Driver: C:\Windows\system32\drivers\pacer.sys (PSched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
              O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\System32\DRIVERS\rasacd.sys
              O41 - Driver: (rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\System32\DRIVERS\rdbss.sys
              O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
              O41 - Driver: (RDPENCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
              O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\Windows\System32\DRIVERS\serial.sys
              O41 - Driver: C:\Windows\system32\tcpipcfg.dll (Smb) . (.Microsoft Corporation - SMB Transport driver.) - C:\Windows\System32\DRIVERS\smb.sys
              O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
              O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
              O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
              O41 - Driver: (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
              0
              1. ---\\ Logiciels installés (O42)
                O42 - Logiciel: AC3Filter (remove only) - (.Pas de propriétaire.) [HKLM] -- AC3Filter
                O42 - Logiciel: AHV content for Acrobat and Flash - (.Adobe Systems Incorporated.) [HKLM] -- {6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
                O42 - Logiciel: Add or Remove Adobe Creative Suite 3 Design Premium - (.Adobe Systems Incorporated.) [HKLM] -- Adobe_c14ac4070fd9614ffe63f4bb533db2c
                O42 - Logiciel: Adobe Anchor Service CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {90176341-0A8B-4CCC-A78D-F862228A6B95}
                O42 - Logiciel: Adobe Asset Services CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
                O42 - Logiciel: Adobe Bridge CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {9C9824D9-9000-4373-A6A5-D0E5D4831394}
                O42 - Logiciel: Adobe Bridge Start Meeting - (.Adobe Systems Incorporated.) [HKLM] -- {08B32819-6EEF-4057-AEDA-5AB681A36A23}
                O42 - Logiciel: Adobe BridgeTalk Plugin CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {B7F560B3-6EFF-4026-A982-843895A41149}
                O42 - Logiciel: Adobe CMaps - (.Adobe Systems Incorporated.) [HKLM] -- {A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
                O42 - Logiciel: Adobe Camera Raw 4.0 - (.Adobe Systems Incorporated.) [HKLM] -- {B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
                O42 - Logiciel: Adobe Color - Photoshop Specific - (.Adobe Systems Incorporated.) [HKLM] -- {A2D81E70-2A98-4A08-A628-94388B063C5E}
                O42 - Logiciel: Adobe Color Common Settings - (.Adobe Systems Incorporated.) [HKLM] -- {DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
                O42 - Logiciel: Adobe Color EU Extra Settings - (.Adobe Systems Incorporated.) [HKLM] -- {51846830-E7B2-4218-8968-B77F0FF475B8}
                O42 - Logiciel: Adobe Color JA Extra Settings - (.Adobe Systems Incorporated.) [HKLM] -- {DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
                O42 - Logiciel: Adobe Color NA Recommended Settings - (.Adobe Systems Incorporated.) [HKLM] -- {95655ED4-7CA5-46DF-907F-7144877A32E5}
                O42 - Logiciel: Adobe Creative Suite 3 Design Premium - (.Adobe Systems Incorporated.) [HKLM] -- {D1C18EDD-571A-4BDD-BE7B-1DD86027D7FF}
                O42 - Logiciel: Adobe Default Language CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
                O42 - Logiciel: Adobe Device Central CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
                O42 - Logiciel: Adobe ExtendScript Toolkit 2 - (.Adobe Systems Incorporated.) [HKLM] -- {C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
                O42 - Logiciel: Adobe Extension Manager CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {BE5F3842-8309-4754-92D5-83E02E6077A3}
                O42 - Logiciel: Adobe Flash CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {6B52140A-F189-4945-BFFC-DB3F00B8C589}
                O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
                O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems, Inc..) [HKLM] -- {ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
                O42 - Logiciel: Adobe Fonts All - (.Adobe Systems Incorporated.) [HKLM] -- {6ABE0BEE-D572-4FE8-B434-9E72A289431B}
                O42 - Logiciel: Adobe Help Viewer CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {04AF207D-9A77-465A-8B76-991F6AB66245}
                O42 - Logiciel: Adobe InDesign CS3 Icon Handler - (.Adobe Systems Incorporated.) [HKLM] -- {EA7B3CC4-366D-4CF6-8350-FD7A7034116E}
                O42 - Logiciel: Adobe Linguistics CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {54793AA1-5001-42F4-ABB6-C364617C6078}
                O42 - Logiciel: Adobe MotionPicture Color Files - (.Adobe Systems Incorporated.) [HKLM] -- {6B708481-748A-4EB4-97C1-CD386244FF77}
                O42 - Logiciel: Adobe PDF Library Files - (.Adobe Systems Incorporated.) [HKLM] -- {D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
                O42 - Logiciel: Adobe Photoshop CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {0046FA01-C5B9-4985-BACB-398DC480FC05}
                O42 - Logiciel: Adobe Reader 9.3.4 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A93000000001}
                O42 - Logiciel: Adobe SING CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {B671CBFD-4109-4D35-9252-3062D3CCB7B2}
                O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM] -- {09E2111C-16B1-4DDF-BF0D-F994C9A12350}
                O42 - Logiciel: Adobe Stock Photos CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {29E5EA97-5F74-4A57-B8B2-D4F169117183}
                O42 - Logiciel: Adobe Type Support - (.Adobe Systems Incorporated.) [HKLM] -- {8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
                O42 - Logiciel: Adobe Update Manager CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {E69AE897-9E0B-485C-8552-7841F48D42D8}
                O42 - Logiciel: Adobe Version Cue CS3 Client - (.Adobe Systems Incorporated.) [HKLM] -- {D0DFF92A-492E-4C40-B862-A74A173C25C5}
                O42 - Logiciel: Adobe WAS CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {C5BD220A-EFE8-48A5-B70E-9503D535FACE}
                O42 - Logiciel: Adobe WinSoft Linguistics Plugin - (.Adobe Systems Incorporated.) [HKLM] -- {184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
                O42 - Logiciel: Adobe XMP Panels CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {802771A9-A856-4A41-ACF7-1450E523C923}
                O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {EE6097DD-05F4-4178-9719-D3170BF098E8}
                O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {308B6AEA-DE50-4666-996D-0FA461719D6B}
                O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                O42 - Logiciel: ArcSoft Panorama Maker 4 - (.ArcSoft.) [HKLM] -- {D45E8C45-B601-4A80-AFD8-E16338744DE1}
                O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM] -- {D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
                O42 - Logiciel: Audacity 1.2.6 - (.Pas de propriétaire.) [HKLM] -- Audacity_is1
                O42 - Logiciel: Browser Configuration Utility - (.DeviceVM Inc..) [HKLM] -- {E8AEA11B-E60A-455E-B008-E4E763604612}
                O42 - Logiciel: Canon ScanGear Starter - (.Pas de propriétaire.) [HKLM] -- {18A5DFF2-8A95-49F3-873F-743CB5549F3D}
                O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM] -- {D3B1C799-CB73-42DE-BA0F-2344793A095C}
                O42 - Logiciel: CopyTrans Suite désinstallation uniquement - (.Pas de propriétaire.) [HKLM] -- CopyTrans Suite
                O42 - Logiciel: CoreAVC Professional Edition (remove only) - (.Pas de propriétaire.) [HKLM] -- CoreAVC Professional Edition
                O42 - Logiciel: CyberLink PowerDVD 8 - (.CyberLink Corp..) [HKLM] -- InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}
                O42 - Logiciel: File Uploader - (.Nikon.) [HKLM] -- {237CD223-1B9D-47E8-A76C-E478B83CCEA2}
                O42 - Logiciel: Free Audio CD Burner version 1.4 - (.DVDVideoSoft Limited..) [HKLM] -- Free Audio CD Burner_is1
                O42 - Logiciel: Free Video to iPod Converter version 4.0 - (.DVDVideoSoft Limited..) [HKLM] -- Free Video to iPod Converter_is1
                O42 - Logiciel: Free YouTube Download 2.4 - (.DVDVideoSoft Limited..) [HKLM] -- Free YouTube Download_is1
                O42 - Logiciel: Free YouTube to MP3 Converter version 3.8 - (.DVDVideoSoft Limited..) [HKLM] -- Free YouTube to MP3 Converter_is1
                O42 - Logiciel: Free YouTube to iPhone Converter version 2.7 - (.DVDVideoSoft Limited..) [HKLM] -- Free YouTube to iPhone Converter_is1
                O42 - Logiciel: Google SketchUp 8 - (.Google, Inc..) [HKLM] -- {B700113B-24A8-4D4C-8484-0CC944F764C8}
                O42 - Logiciel: Haali Media Splitter - (.Pas de propriétaire.) [HKLM] -- HaaliMkx
                O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
                O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
                O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
                O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- {46ABBC54-1872-4AA3-95E2-F2C063A63F31}
                O42 - Logiciel: Java(TM) 6 Update 17 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216011FF}
                O42 - Logiciel: Les Sims 2 - (.Pas de propriétaire.) [HKLM] -- {6E7DD182-9FC6-4651-0095-2E666CC6AF35}
                O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
                O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
                O42 - Logiciel: Microsoft .NET Framework 3.5 Language Pack SP1 - fra - (.Microsoft Corporation.) [HKLM] -- {3E31821C-7917-367E-938E-E65FC413EA31}
                O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
                O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}_PROPLUS_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                O42 - Logiciel: Microsoft Office Access MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Excel MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office InfoPath MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Outlook MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- PROPLUS
                O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Proof (German) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Proofing (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002C-040C-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}_PROPLUS_{14809F99-C601-4D4A-9391-F1E8FAA964C5}
                O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{A0516415-ED61-419A-981D-93596DA74165}
                O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}
                O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}_PROPLUS_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}
                O42 - Logiciel: Microsoft Office Publisher MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Office Word MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}
                O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118}
                O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {7299052b-02a4-4627-81f2-1818da5d550d}
                O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
                O42 - Logiciel: Microsoft Windows Application Compatibility Database - (.Pas de propriétaire.) [HKLM] -- {deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
                O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 Language Pack SP1 - fra
                O42 - Logiciel: NJStar Communicator - (.NJStar Software Corp..) [HKLM] -- NJStar Communicator
                O42 - Logiciel: Nero 8 - (.Nero AG.) [HKLM] -- {BE282C23-5484-47FF-B2C1-EBEA5C891036}
                O42 - Logiciel: Nikon Message Center - (.Nikon.) [HKLM] -- {D2FCC1AE-6311-47C5-8130-C6C66D77DD71}
                O42 - Logiciel: Nikon Transfer - (.Nikon.) [HKLM] -- {E9757890-7EC5-46C8-99AB-B00F07B6525C}
                O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM] -- {205C6BDD-7B73-42DE-8505-9A093F35A238}
                O42 - Logiciel: PC Connectivity Solution - (.Nokia.) [HKLM] -- {AC599724-5755-48C1-ABE7-ABB857652930}
                O42 - Logiciel: PDF Settings - (.Adobe Systems Incorporated.) [HKLM] -- {AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
                O42 - Logiciel: Package de pilotes Windows - Nokia pccsmcfd (10/12/2007 6.85.4.0) - (.Nokia.) [HKLM] -- 3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F
                O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {E7004147-2CCA-431C-AA05-2AB166B9785D}
                O42 - Logiciel: Realtek 8169 8168 8101E 8102E Ethernet Driver - (.Realtek.) [HKLM] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}
                O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
                O42 - Logiciel: SAMSUNG Mobile USB Modem 1.0 Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile USB Modem 1.0
                O42 - Logiciel: SAMSUNG Mobile USB Modem Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile USB Modem
                O42 - Logiciel: SAMSUNG SYMBIAN USB Download Driver - (.SAMSUNG Electronics CO,.LTD.) [HKLM] -- {D8CE69B0-9274-4b8c-BA49-0FF6A20A3C65}
                O42 - Logiciel: SAMSUNG USB Mobile Device Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG USB Mobile Device
                O42 - Logiciel: Samsung Mobile phone USB driver Software - (.Pas de propriétaire.) [HKLM] -- Samsung Mobile phone USB driver
                O42 - Logiciel: SamsungConnectivityCableDriver - (.Samsung.) [HKLM] -- {7E84FAC8-C518-40F9-9807-7455301D6D25}
                O42 - Logiciel: Screenshot Captor 2.44.01 - (.Pas de propriétaire.) [HKLM] -- ScreenshotCaptor_is1
                O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB978380) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{667A88D1-0369-4070-A62A-70672D68A9BF}
                O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB978382) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6DE3DABF-0203-426B-B330-7287D1003E86}
                O42 - Logiciel: Security Update for Microsoft Office Outlook 2007 (KB972363) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{120BE9A0-9B09-4855-9E0C-7DEE45CB03C0}
                O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB957789) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{7559E742-FF9F-4FAE-B279-008ED296CB4D}
                O42 - Logiciel: Security Update for Microsoft Office Publisher 2007 (KB980470) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{34573F17-DADE-4D0D-835F-A54A1DE8AC1F}
                O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}
                O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB969613) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
                O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                O42 - Logiciel: Spybot - Search & Destroy - (.Safer Networking Limited.) [HKLM] -- {B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1
                O42 - Logiciel: Tablette Wacom - (.Wacom Technology Corp..) [HKLM] -- Wacom Tablet Driver
                O42 - Logiciel: The Sims 2 University - (.Pas de propriétaire.) [HKLM] -- {8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}
                O42 - Logiciel: Uninstall 1.0.0.1 - (.Pas de propriétaire.) [HKLM] -- Uninstall_is1
                O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                O42 - Logiciel: Update for 2007 Microsoft Office System (KB981715) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{661B3F32-FFE4-4606-AE3A-DFA11DCC0D79}
                O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
                O42 - Logiciel: Update for Microsoft Office InfoPath 2007 (KB976416) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{432C5EE4-8096-4FF1-95E1-65219365DFF7}
                O42 - Logiciel: Update for Microsoft Office Word 2007 (KB974561) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
                O42 - Logiciel: Update for Outlook 2007 Junk Email Filter (kb981433) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5A6859A6-042D-4DF7-84E2-79F8DEFB5D48}
                O42 - Logiciel: VCRedistSetup - (.Nero AG.) [HKLM] -- {3921A67A-5AB1-4E48-9444-C71814CF3027}
                O42 - Logiciel: VLC media player 1.0.5 - (.VideoLAN Team.) [HKLM] -- VLC media player
                O42 - Logiciel: Veoh Video Compass - (.Veoh Networks, Inc..) [HKLM] -- Veoh Video Compass
                O42 - Logiciel: Viton cyrillic azerty v.2 - (.Luc Petr.) [HKLM] -- {9B17173C-B2CB-461F-8DF3-17D61E1941F4}
                O42 - Logiciel: WebTablet IE Plugin - (.Wacom Technology Corp..) [HKLM] -- Wacom WebTabletPlugin for IE
                O42 - Logiciel: WebTablet Netscape Plugin - (.Wacom Technology Corp..) [HKLM] -- Wacom WebTabletPlugin for Netscape
                O42 - Logiciel: WinRAR archiver - (.Pas de propriétaire.) [HKLM] -- WinRAR archiver
                O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {ED00D08A-3C5F-488D-93A0-A04F21F23956}
                O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {770F1BEC-2871-4E70-B837-FB8525FFA3B1}
                O42 - Logiciel: avast! Free Antivirus - (.Alwil Software.) [HKLM] -- avast5
                O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {FAE36873-1941-4076-A9A5-48812B5EA0B7}
                O42 - Logiciel: neroxml - (.Nero AG.) [HKLM] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}

                ---\\ HKCU & HKLM Software Keys
                [HKCU\Software\AC3Filter]
                [HKCU\Software\ALWIL Software]
                [HKCU\Software\ATI Technologies Inc.]
                [HKCU\Software\ATI]
                [HKCU\Software\AVS4YOU]
                [HKCU\Software\Abvent]
                [HKCU\Software\Adobe]
                [HKCU\Software\Ahead]
                [HKCU\Software\AppDataLow\Software\Adobe]
                [HKCU\Software\AppDataLow\Software\Conduit]
                [HKCU\Software\AppDataLow\Software\Microsoft]
                [HKCU\Software\AppDataLow\Software\Monitored]
                [HKCU\Software\AppDataLow\Software\settings]
                [HKCU\Software\AppDataLow\Software]
                [HKCU\Software\AppDataLow]
                [HKCU\Software\Apple Computer, Inc.]
                [HKCU\Software\Apple Inc.]
                [HKCU\Software\ArcSoft]
                [HKCU\Software\Audacity]
                [HKCU\Software\Bobyte]
                [HKCU\Software\Bugsplat]
                [HKCU\Software\CDDB]
                [HKCU\Software\CORE]
                [HKCU\Software\Canon]
                [HKCU\Software\Classes]
                [HKCU\Software\Clients]
                [HKCU\Software\CoreAAC]
                [HKCU\Software\Cyberlink]
                [HKCU\Software\Cygnus Solutions]
                [HKCU\Software\DT Soft]
                [HKCU\Software\DVDVideoSoft]
                [HKCU\Software\Dance Kit]
                [HKCU\Software\Digital River]
                [HKCU\Software\DivXNetworks]
                [HKCU\Software\DownloadCenter]
                [HKCU\Software\Elaborate Bytes]
                [HKCU\Software\Freeware]
                [HKCU\Software\GNU]
                [HKCU\Software\Gabest]
                [HKCU\Software\Google]
                [HKCU\Software\H3O8CABBPI]
                [HKCU\Software\Haali]
                [HKCU\Software\IM Providers]
                [HKCU\Software\JP595IR86O]
                [HKCU\Software\JavaSoft]
                [HKCU\Software\KasperskyLab]
                [HKCU\Software\Lake]
                [HKCU\Software\Local AppWizard-Generated Applications]
                [HKCU\Software\Macromedia]
                [HKCU\Software\MagicDisc]
                [HKCU\Software\Magnet]
                [HKCU\Software\Malwarebytes' Anti-Malware]
                [HKCU\Software\Mozilla]
                [HKCU\Software\NJStar]
                [HKCU\Software\NeroDigital]
                [HKCU\Software\Nero]
                [HKCU\Software\Netscape]
                [HKCU\Software\Nikon]
                [HKCU\Software\ODBC]
                [HKCU\Software\Policies]
                [HKCU\Software\Pvm]
                [HKCU\Software\Realtek]
                [HKCU\Software\SETTEC]
                [HKCU\Software\SYSTEMAX Software Development]
                [HKCU\Software\Safer Networking Limited]
                [HKCU\Software\Samsung]
                [HKCU\Software\SecuROM]
                [HKCU\Software\Smart Soft]
                [HKCU\Software\Synthesia]
                [HKCU\Software\Sysinternals]
                [HKCU\Software\Trolltech]
                [HKCU\Software\VB and VBA Program Settings]
                [HKCU\Software\Veoh]
                [HKCU\Software\WinRAR SFX]
                [HKCU\Software\WinRAR]
                [HKCU\Software\YahooPartnerToolbar]
                [HKLM\Software\ALWIL Software]
                [HKLM\Software\AMD]
                [HKLM\Software\ATI Technologies]
                [HKLM\Software\ATI]
                [HKLM\Software\AVS4YOU]
                [HKLM\Software\Adobe]
                [HKLM\Software\Ahead]
                [HKLM\Software\Apple Computer, Inc.]
                [HKLM\Software\Apple Inc.]
                [HKLM\Software\ArcSoft]
                [HKLM\Software\Audible]
                [HKLM\Software\AviSynth]
                [HKLM\Software\BrowserChoice]
                [HKLM\Software\C07ft5Y]
                [HKLM\Software\Canon]
                [HKLM\Software\Classes]
                [HKLM\Software\Clients]
                [HKLM\Software\CoreCodec]
                [HKLM\Software\CyberLink]
                [HKLM\Software\Cygnus Solutions]
                [HKLM\Software\DEVGURU]
                [HKLM\Software\DT Soft]
                [HKLM\Software\DVDVideoSoft]
                [HKLM\Software\Debug]
                [HKLM\Software\DeviceVM Inc.]
                [HKLM\Software\Distortion]
                [HKLM\Software\EA GAMES]
                [HKLM\Software\Electronic Arts]
                [HKLM\Software\GEAR Software]
                [HKLM\Software\GNU]
                [HKLM\Software\Gabest]
                [HKLM\Software\Google]
                [HKLM\Software\InstallShield]
                [HKLM\Software\Intel]
                [HKLM\Software\InterVideo]
                [HKLM\Software\JavaSoft]
                [HKLM\Software\JreMetrics]
                [HKLM\Software\Lake]
                [HKLM\Software\Licenses]
                [HKLM\Software\MAXSOFT-OCRON]
                [HKLM\Software\MCCI]
                [HKLM\Software\Macromedia]
                [HKLM\Software\Macrovision]
                [HKLM\Software\Malwarebytes' Anti-Malware]
                [HKLM\Software\MarkAny]
                [HKLM\Software\MozillaPlugins]
                [HKLM\Software\Mozilla]
                [HKLM\Software\NJStar]
                [HKLM\Software\NeroDigital]
                [HKLM\Software\Nero]
                [HKLM\Software\Nikon]
                [HKLM\Software\ODBC]
                [HKLM\Software\PC Connectivity Solution]
                [HKLM\Software\PCSuite]
                [HKLM\Software\Pegasys Inc.]
                [HKLM\Software\Policies]
                [HKLM\Software\RTLSetup]
                [HKLM\Software\Realtek Semiconductor Corp.]
                [HKLM\Software\Realtek]
                [HKLM\Software\RegisteredApplications]
                [HKLM\Software\SRS Labs]
                [HKLM\Software\Safer Networking Limited]
                [HKLM\Software\Samsung]
                [HKLM\Software\Sonic]
                [HKLM\Software\Synthesia]
                [HKLM\Software\TrendMicro]
                [HKLM\Software\VideoConverter]
                [HKLM\Software\VideoLAN]
                [HKLM\Software\Volatile]
                [HKLM\Software\WOW6432Node]
                [HKLM\Software\Wacom]
                [HKLM\Software\Waves Audio]
                [HKLM\Software\WinRAR]
                [HKLM\Software\Windows]
                [HKLM\Software\mozilla.org]
                [HKLM\Software\vLite]

                ---\\ Contenu des dossiers ProgramFiles/ProgramData (O43)
                O43 - CFD: 01/01/2009 - 11:41:46 ----D- C:\Program Files\AC3Filter
                O43 - CFD: 20/01/2010 - 12:58:30 ----D- C:\Program Files\Adobe
                O43 - CFD: 17/08/2009 - 16:31:32 ----D- C:\Program Files\Aglare Mp4 to AVI Converter
                O43 - CFD: 26/06/2010 - 09:29:36 ----D- C:\Program Files\Alwil Software
                O43 - CFD: 01/01/2009 - 17:17:30 ----D- C:\Program Files\Apple Software Update
                O43 - CFD: 30/12/2009 - 19:33:00 ----D- C:\Program Files\ArcSoft
                O43 - CFD: 17/12/2010 - 19:41:26 ----D- C:\Program Files\Artlantis Studio 3
                O43 - CFD: 01/01/2009 - 10:23:02 ----D- C:\Program Files\ATI
                O43 - CFD: 01/01/2009 - 10:19:36 ----D- C:\Program Files\ATI Technologies
                O43 - CFD: 24/08/2010 - 12:15:14 ----D- C:\Program Files\Audacity
                O43 - CFD: 22/04/2009 - 09:46:16 ----D- C:\Program Files\AviSynth 2.5
                O43 - CFD: 30/11/2009 - 21:38:38 ----D- C:\Program Files\AVS4YOU
                O43 - CFD: 06/11/2010 - 22:55:16 ----D- C:\Program Files\bobyte
                O43 - CFD: 17/12/2010 - 18:27:10 ----D- C:\Program Files\Bonjour
                O43 - CFD: 01/01/2009 - 10:11:48 ----D- C:\Program Files\Browser Configuration Utility
                O43 - CFD: 30/12/2009 - 19:35:02 ----D- C:\Program Files\Common Files
                O43 - CFD: 27/09/2009 - 13:32:34 ----D- C:\Program Files\CORE
                O43 - CFD: 01/01/2009 - 11:43:08 ----D- C:\Program Files\CoreCodec
                O43 - CFD: 19/04/2009 - 10:37:52 ----D- C:\Program Files\Cucusoft
                O43 - CFD: 01/01/2009 - 11:36:50 ----D- C:\Program Files\CyberLink
                O43 - CFD: 05/04/2009 - 14:44:00 ----D- C:\Program Files\DAEMON Tools Lite
                O43 - CFD: 06/12/2009 - 14:15:40 ----D- C:\Program Files\DIFX
                O43 - CFD: 19/08/2010 - 12:10:14 ----D- C:\Program Files\DVDVideoSoft
                O43 - CFD: 02/07/2010 - 22:29:48 ----D- C:\Program Files\EA GAMES
                O43 - CFD: 01/01/2009 - 12:06:56 ----D- C:\Program Files\Elaborate Bytes
                O43 - CFD: 20/04/2009 - 21:04:48 ----D- C:\Program Files\Feneris
                O43 - CFD: 01/01/2009 - 10:07:50 -SH-D- C:\Program Files\Fichiers communs
                O43 - CFD: 30/11/2010 - 10:00:26 ----D- C:\Program Files\Google
                O43 - CFD: 01/01/2009 - 11:43:18 ----D- C:\Program Files\Haali
                O43 - CFD: 28/06/2010 - 17:49:58 --H-D- C:\Program Files\InstallShield Installation Information
                O43 - CFD: 01/04/2010 - 09:59:38 ----D- C:\Program Files\Internet Explorer
                O43 - CFD: 03/12/2010 - 19:14:14 ----D- C:\Program Files\iPod
                O43 - CFD: 03/12/2010 - 19:15:04 ----D- C:\Program Files\iTunes
                O43 - CFD: 11/03/2010 - 12:36:20 ----D- C:\Program Files\Java
                O43 - CFD: 01/01/2009 - 11:09:44 ----D- C:\Program Files\Kaspersky Lab
                O43 - CFD: 02/05/2009 - 20:04:02 ----D- C:\Program Files\MagicDisc
                O43 - CFD: 15/02/2010 - 17:38:12 ----D- C:\Program Files\MagicISO
                O43 - CFD: 17/12/2010 - 23:40:42 ----D- C:\Program Files\Malwarebytes' Anti-Malware
                O43 - CFD: 02/12/2009 - 16:45:46 ----D- C:\Program Files\Microsoft
                O43 - CFD: 02/11/2006 - 13:35:52 ----D- C:\Program Files\Microsoft Games
                O43 - CFD: 01/01/2009 - 10:33:30 ----D- C:\Program Files\Microsoft Office
                O43 - CFD: 01/01/2009 - 10:33:26 ----D- C:\Program Files\Microsoft Visual Studio
                O43 - CFD: 01/01/2009 - 10:30:00 ----D- C:\Program Files\Microsoft Visual Studio 8
                O43 - CFD: 29/09/2009 - 06:14:48 ----D- C:\Program Files\Microsoft Works
                O43 - CFD: 01/01/2009 - 10:32:32 ----D- C:\Program Files\Microsoft.NET
                O43 - CFD: 11/03/2010 - 11:32:30 ----D- C:\Program Files\Movie Maker
                O43 - CFD: 17/12/2010 - 19:41:06 ----D- C:\Program Files\Mozilla Firefox
                O43 - CFD: 01/01/2009 - 11:57:02 ----D- C:\Program Files\mplayerc_homecinema_x86_v1.2.908.0
                O43 - CFD: 01/01/2009 - 10:33:48 ----D- C:\Program Files\MSBuild
                O43 - CFD: 02/01/2009 - 01:24:12 ----D- C:\Program Files\MSXML 4.0
                O43 - CFD: 01/01/2009 - 11:03:40 ----D- C:\Program Files\Nero
                O43 - CFD: 31/12/2009 - 00:42:00 ----D- C:\Program Files\Nikon
                O43 - CFD: 19/04/2010 - 21:25:16 ----D- C:\Program Files\NJStar Communicator
                O43 - CFD: 28/06/2010 - 17:15:58 ----D- C:\Program Files\PAP40
                O43 - CFD: 28/06/2010 - 17:43:34 ----D- C:\Program Files\PC Connectivity Solution
                O43 - CFD: 27/11/2010 - 17:30:22 ----D- C:\Program Files\Pvm
                O43 - CFD: 30/09/2010 - 09:52:00 ----D- C:\Program Files\QuickTime
                O43 - CFD: 01/01/2009 - 10:14:28 ----D- C:\Program Files\Realtek
                O43 - CFD: 02/11/2006 - 13:35:52 ----D- C:\Program Files\Reference Assemblies
                O43 - CFD: 06/12/2009 - 14:15:52 ----D- C:\Program Files\Samsung
                O43 - CFD: 07/01/2009 - 21:07:22 ----D- C:\Program Files\ScreenshotCaptor
                O43 - CFD: 10/11/2010 - 21:51:14 ----D- C:\Program Files\Shareaza
                O43 - CFD: 05/04/2009 - 16:01:08 ----D- C:\Program Files\Smart Protector Pro
                O43 - CFD: 19/12/2010 - 12:06:20 ----D- C:\Program Files\Spybot - Search & Destroy
                O43 - CFD: 13/07/2010 - 22:12:10 ----D- C:\Program Files\Tablet
                O43 - CFD: 13/07/2010 - 22:12:50 ----D- C:\Program Files\TabletPlugins
                O43 - CFD: 02/11/2006 - 14:00:32 --H-D- C:\Program Files\Uninstall Information
                O43 - CFD: 02/07/2010 - 23:22:26 ----D- C:\Program Files\Veoh Networks
                O43 - CFD: 16/03/2010 - 10:34:46 ----D- C:\Program Files\VideoLAN
                O43 - CFD: 21/01/2008 - 03:33:50 ----D- C:\Program Files\Windows Calendar
                O43 - CFD: 21/01/2008 - 03:33:48 ----D- C:\Program Files\Windows Collaboration
                O43 - CFD: 02/12/2009 - 16:45:10 ----D- C:\Program Files\Windows Live
                O43 - CFD: 02/12/2009 - 16:45:30 ----D- C:\Program Files\Windows Live SkyDrive
                O43 - CFD: 15/04/2010 - 13:32:00 ----D- C:\Program Files\Windows Mail
                O43 - CFD: 29/10/2009 - 10:58:28 ----D- C:\Program Files\Windows Media Player
                O43 - CFD: 01/01/2009 - 10:07:50 ----D- C:\Program Files\Windows NT
                O43 - CFD: 21/01/2008 - 03:33:46 ----D- C:\Program Files\Windows Photo Gallery
                O43 - CFD: 21/01/2008 - 03:33:50 ----D- C:\Program Files\Windows Sidebar
                O43 - CFD: 27/02/2010 - 18:29:28 ----D- C:\Program Files\WindSolutions
                O43 - CFD: 01/01/2009 - 10:26:22 ----D- C:\Program Files\WinRAR
                O43 - CFD: 19/12/2010 - 21:17:46 ----D- C:\Program Files\ZHPDiag
                O43 - CFD: 20/01/2010 - 12:58:46 ----D- C:\Program Files\Common Files\Adobe
                O43 - CFD: 03/12/2010 - 19:14:14 ----D- C:\Program Files\Common Files\Apple
                O43 - CFD: 30/11/2009 - 21:38:38 ----D- C:\Program Files\Common Files\AVSMedia
                O43 - CFD: 01/01/2009 - 11:36:38 ----D- C:\Program Files\Common Files\CyberLink
                O43 - CFD: 01/01/2009 - 10:33:26 ----D- C:\Program Files\Common Files\DESIGNER
                O43 - CFD: 19/08/2010 - 12:10:20 ----D- C:\Program Files\Common Files\DVDVideoSoft
                O43 - CFD: 30/12/2009 - 19:33:48 ----D- C:\Program Files\Common Files\InstallShield
                O43 - CFD: 02/02/2009 - 11:46:18 ----D- C:\Program Files\Common Files\Macrovision Shared
                O43 - CFD: 29/09/2009 - 06:15:10 ----D- C:\Program Files\Common Files\microsoft shared
                O43 - CFD: 30/12/2009 - 19:35:02 ----D- C:\Program Files\Common Files\muvee Technologies
                O43 - CFD: 01/01/2009 - 11:03:52 ----D- C:\Program Files\Common Files\Nero
                O43 - CFD: 30/12/2009 - 19:44:04 ----D- C:\Program Files\Common Files\Nikon
                O43 - CFD: 02/11/2006 - 12:18:34 ----D- C:\Program Files\Common Files\Services
                O43 - CFD: 01/01/2009 - 10:29:40 ----D- C:\Program Files\Common Files\System
                O43 - CFD: 02/12/2009 - 16:42:02 ----D- C:\Program Files\Common Files\Windows Live
                O43 - CFD: 01/01/2009 - 17:31:48 -SH-D- C:\Program Files\Common Files\WindowsLiveInstaller
                O43 - CFD: 15/12/2010 - 23:15:56 ----D- C:\ProgramData\Abvent
                O43 - CFD: 24/01/2010 - 10:58:18 ----D- C:\ProgramData\Adobe
                O43 - CFD: 26/06/2010 - 09:29:06 ----D- C:\ProgramData\Alwil Software
                O43 - CFD: 22/04/2009 - 09:27:04 ----D- C:\ProgramData\Apowersoft
                O43 - CFD: 01/01/2009 - 17:16:40 ----D- C:\ProgramData\Apple
                O43 - CFD: 01/01/2009 - 17:19:04 ----D- C:\ProgramData\Apple Computer
                O43 - CFD: 02/11/2006 - 14:00:40 -SH-D- C:\ProgramData\Application Data
                O43 - CFD: 29/11/2009 - 19:27:56 ----D- C:\ProgramData\ASign
                O43 - CFD: 01/01/2009 - 10:23:08 ----D- C:\ProgramData\ATI
                O43 - CFD: 30/11/2009 - 20:48:16 ----D- C:\ProgramData\AVS4YOU
                O43 - CFD: 01/01/2009 - 10:07:50 -SH-D- C:\ProgramData\Bureau
                O43 - CFD: 01/01/2009 - 11:37:12 ----D- C:\ProgramData\CyberLink
                O43 - CFD: 05/04/2009 - 14:44:04 ----D- C:\ProgramData\DAEMON Tools Lite
                O43 - CFD: 02/11/2006 - 14:00:40 -SH-D- C:\ProgramData\Desktop
                O43 - CFD: 02/11/2006 - 14:00:40 -SH-D- C:\ProgramData\Documents
                O43 - CFD: 01/01/2009 - 18:34:16 ----D- C:\ProgramData\DonationCoder
                O43 - CFD: 02/07/2010 - 21:31:32 ----D- C:\ProgramData\eMule
                O43 - CFD: 30/12/2009 - 19:34:02 ----D- C:\ProgramData\EnterNHelp
                O43 - CFD: 01/01/2009 - 10:07:50 -SH-D- C:\ProgramData\Favoris
                O43 - CFD: 02/11/2006 - 14:00:40 -SH-D- C:\ProgramData\Favorites
                O43 - CFD: 30/12/2009 - 19:34:02 ----D- C:\ProgramData\Filters
                O43 - CFD: 01/12/2010 - 22:06:28 ----D- C:\ProgramData\FLEXnet
                O43 - CFD: 30/11/2010 - 10:01:50 ----D- C:\ProgramData\Google
                O43 - CFD: 14/11/2010 - 23:50:30 ----D- C:\ProgramData\KB Piano
                O43 - CFD: 17/12/2010 - 23:40:30 ----D- C:\ProgramData\Malwarebytes
                O43 - CFD: 01/01/2009 - 10:07:50 -SH-D- C:\ProgramData\Menu Démarrer
                O43 - CFD: 19/12/2010 - 10:32:18 ----D- C:\ProgramData\Microsoft
                O43 - CFD: 15/04/2010 - 10:05:22 ----D- C:\ProgramData\Microsoft Help
                O43 - CFD: 01/01/2009 - 10:07:50 -SH-D- C:\ProgramData\Modèles
                O43 - CFD: 01/01/2009 - 11:03:40 ----D- C:\ProgramData\Nero
                O43 - CFD: 30/12/2009 - 19:34:58 ----D- C:\ProgramData\Nikon
                O43 - CFD: 06/12/2009 - 14:21:10 ----D- C:\ProgramData\PC Suite
                O43 - CFD: 19/12/2010 - 14:07:48 ----D- C:\ProgramData\Spybot - Search & Destroy
                O43 - CFD: 02/11/2006 - 14:00:40 -SH-D- C:\ProgramData\Start Menu
                O43 - CFD: 08/01/2009 - 21:25:24 ----D- C:\ProgramData\SYSTEMAX Software Development
                O43 - CFD: 28/06/2010 - 17:11:54 ----D- C:\ProgramData\Tablet
                O43 - CFD: 17/12/2010 - 23:00:24 ----D- C:\ProgramData\TEMP
                O43 - CFD: 02/11/2006 - 14:00:40 -SH-D- C:\ProgramData\Templates
                O43 - CFD: 30/12/2009 - 19:34:02 ----D- C:\ProgramData\Ultima_T15
                O43 - CFD: 27/02/2010 - 18:29:22 ----D- C:\ProgramData\WindSolutions
                O43 - CFD: 01/01/2009 - 23:16:56 ----D- C:\ProgramData\WinZip
                O43 - CFD: 01/01/2009 - 17:29:30 ----D- C:\ProgramData\WLInstaller
                O43 - CFD: 20/01/2010 - 12:58:46 ----D- C:\Program Files\Common Files\Adobe
                O43 - CFD: 03/12/2010 - 19:14:14 ----D- C:\Program Files\Common Files\Apple
                O43 - CFD: 30/11/2009 - 21:38:38 ----D- C:\Program Files\Common Files\AVSMedia
                O43 - CFD: 01/01/2009 - 11:36:38 ----D- C:\Program Files\Common Files\CyberLink
                O43 - CFD: 01/01/2009 - 10:33:26 ----D- C:\Program Files\Common Files\DESIGNER
                O43 - CFD: 19/08/2010 - 12:10:20 ----D- C:\Program Files\Common Files\DVDVideoSoft
                O43 - CFD: 30/12/2009 - 19:33:48 ----D- C:\Program Files\Common Files\InstallShield
                O43 - CFD: 02/02/2009 - 11:46:18 ----D- C:\Program Files\Common Files\Macrovision Shared
                O43 - CFD: 29/09/2009 - 06:15:10 ----D- C:\Program Files\Common Files\microsoft shared
                O43 - CFD: 30/12/2009 - 19:35:02 ----D- C:\Program Files\Common Files\muvee Technologies
                O43 - CFD: 01/01/2009 - 11:03:52 ----D- C:\Program Files\Common Files\Nero
                O43 - CFD: 30/12/2009 - 19:44:04 ----D- C:\Program Files\Common Files\Nikon
                O43 - CFD: 02/11/2006 - 12:18:34 ----D- C:\Program Files\Common Files\Services
                O43 - CFD: 01/01/2009 - 10:29:40 ----D- C:\Program Files\Common Files\System
                O43 - CFD: 02/12/2009 - 16:42:02 ----D- C:\Program Files\Common Files\Windows Live
                O43 - CFD: 01/01/2009 - 17:31:48 -SH-D- C:\Program Files\Common Files\WindowsLiveInstaller

                ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
                O44 - LFC:[MD5.1C30555DDF92A71DDCC34B5BC9DE28A6] - 19/12/2010 - 21:01:34 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\WindowsUpdate.log [1445728]
                O44 - LFC:[MD5.C1AC5341FAD6A8CC71BF830A38CBB492] - 19/12/2010 - 20:58:25 -S-A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\bootstat.dat [67584]
                O44 - LFC:[MD5.6E6DC441E3195F1A310AC9980B4DACFD] - 19/12/2010 - 20:22:19 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\FyK.txt [1512]
                O44 - LFC:[MD5.E87234048390A342DF4B5CA03901E236] - 19/12/2010 - 16:18:05 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\FindyKill_Upload_Me_PC-de-Meg.zip [749]
                O44 - LFC:[MD5.BAE4A2A80B8D57564EF603F746A8EBD3] - 19/12/2010 - 11:30:27 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\PerfStringBackup.INI [1477980]
                O44 - LFC:[MD5.A419F599CC5DB5560C9B31C0547B4A97] - 19/12/2010 - 11:30:27 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\perfc009.dat [101896]
                O44 - LFC:[MD5.58D8724A120D8D48961628BCFB2F828D] - 19/12/2010 - 11:30:27 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\perfc00C.dat [124228]
                O44 - LFC:[MD5.27E471047B10535CC98CFA23B1ACB766] - 19/12/2010 - 11:30:27 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\perfh009.dat [589884]
                O44 - LFC:[MD5.FF96962508AE5FAE78A47D8BA95C76BB] - 19/12/2010 - 11:30:27 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\perfh00C.dat [672096]
                O44 - LFC:[MD5.CB3D0B6AEDD320CD0FCE679BC4BFFA03] - 18/12/2010 - 19:49:18 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\ntbtlog.txt [218762]
                O44 - LFC:[MD5.B98F373607AABF33E030E6E2C36BDF70] - 18/12/2010 - 18:30:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\PFRO.log [114256]
                O44 - LFC:[MD5.C7BC96C3711C0D269DA26D1F0ECEC547] - 17/12/2010 - 18:53:24 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\NeroDigital.ini [69]
                O44 - LFC:[MD5.7D9FB0FC3E8FDCFFCF2CEF84BC4239CA] - 17/12/2010 - 17:37:38 ---A- . (.Windows (R) Codename Longhorn DDK provider - Windows Setup API.) -- C:\Windows\Qhozoa.exe [223232]
                O44 - LFC:[MD5.1313EE12E4C066B50CCAF23506939CF8] - 08/12/2010 - 06:39:14 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\Wacom_Tablet.dat [3729]
                O44 - LFC:[MD5.E74DC2F3F9675A6025A4AA020EDD4341] - 29/11/2010 - 17:42:18 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\System32\drivers\mbamswissarmy.sys [38224]
                O44 - LFC:[MD5.9B5CC6C481BDD00A963829B892623247] - 29/11/2010 - 17:42:06 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\System32\drivers\mbam.sys [20952]
                O44 - LFC:[MD5.75FAEDE794C780BD665A797DBF616383] - 27/11/2010 - 17:20:56 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\setupact.log [99245]
                0
                1. ---\\ MountPoints2 Shell Key (MPSK) (O51)
                  O51 - MPSK:{3ab552bf-6982-11de-9f24-001fd095b43e}\Shell\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- H:\LaunchU3.exe (.not file.)
                  O51 - MPSK:{e7c4c643-f1eb-11dd-a735-001fd095b43e}\Shell\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- I:\LaunchU3.exe (.not file.)
                  O51 - MPSK:{e9a4f666-dc09-11de-9251-001fd095b43e}\Shell\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- H:\EmDesk.exe (.not file.)

                  ---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)
                  O52 - TDSD: \Drivers32\"vidc.i420"="i420vfw.dll" . (.www.helixcommunity.org - Helix I420 YUV Codec.) -- C:\Windows\System32\i420vfw.dll
                  O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
                  O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll
                  O52 - TDSD: \Drivers32\"msacm.ac3filter"="ac3filter.acm" . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\ac3filter.acm
                  O52 - TDSD: \Drivers32\"vidc.VP60"="C:\Windows\system32\vp6vfw.dll" . (.On2.com - VP6 VIDEO FOR WINDOWS CODEC.) -- C:\Windows\system32\vp6vfw.dll
                  O52 - TDSD: \Drivers32\"vidc.VP61"="C:\Windows\system32\vp6vfw.dll" . (.On2.com - VP6 VIDEO FOR WINDOWS CODEC.) -- C:\Windows\system32\vp6vfw.dll
                  O52 - TDSD: \Drivers32\"vidc.yv12"="yv12vfw.dll" . (.www.helixcommunity.org - Helix YV12 YUV Codec.) -- C:\Windows\System32\yv12vfw.dll
                  O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
                  O52 - TDSD: \drivers.desc\"ac3filter.acm"="AC3Filter AC3/DTS codec" . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\ac3filter.acm
                  O52 - TDSD: \drivers.desc\"vp6vfw.dll"="EA VP6 Codec" . (.On2.com - VP6 VIDEO FOR WINDOWS CODEC.) -- C:\Windows\System32\vp6vfw.dll

                  ---\\ ShareTools MSconfig StartupReg (SMSR) (O53)
                  O53 - SMSR:HKLM\...\startupreg\Acrobat Assistant 8.0 [Key] . (.Pas de propriétaire - Pas de description.) -- "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
                  O53 - SMSR:HKLM\...\startupreg\DAEMON Tools Lite [Key] . (.Pas de propriétaire - Pas de description.) -- "C:\Program Files\DAEMON Tools Lite\daemon.exe
                  O53 - SMSR:HKLM\...\startupreg\MsnMsgr [Key] . (.Pas de propriétaire - Pas de description.) -- "C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  O53 - SMSR:HKLM\...\startupreg\Nikon Transfer Monitor [Key] . (.Nikon Corporation - Nikon Transfer Monitor.) -- C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
                  O53 - SMSR:HKLM\...\startupreg\Shareaza [Key] . (.Pas de propriétaire - Pas de description.) -- "C:\Program Files\Shareaza\Shareaza.exe
                  O53 - SMSR:HKLM\...\startupreg\SpybotSD TeaTimer [Key] . (.Safer Networking Limited - System settings protector.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O53 - SMSR:HKLM\...\startupreg\VeohPlugin [Key] . (.Pas de propriétaire - Pas de description.) -- "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                  O53 - SMSR:HKLM\...\startupreg\VirtualCloneDrive [Key] . (.Pas de propriétaire - Pas de description.) -- "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe

                  ---\\ Microsoft Control Security Providers (MCSP) (O54)
                  O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TS Single Sign On Security Package.) -- C:\Windows\system32\credssp.dll
                  O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TS Single Sign On Security Package.) -- C:\Windows\system32\credssp.dll

                  ---\\ Microsoft Windows Policies System (MWPS) (O55)
                  O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=0
                  O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=0
                  O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
                  O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1
                  O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
                  O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
                  O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
                  O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
                  O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
                  O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
                  O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
                  O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
                  O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
                  O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
                  O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
                  O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
                  O55 - MWPS:[HKLM\...\Policies\System] - "UacDisableNotify"=0

                  ---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
                  O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145

                  ---\\ Liste des Drivers Système (SDL) (O58)
                  O58 - SDL:[MD5.04F0FCAC69C7C71A3AC4EB97FAFC8303] - 21/01/2008 - 03:21:29 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\system32\drivers\adp94xx.sys [422968]
                  O58 - SDL:[MD5.60505E0041F7751BDBB80F88BF45C2CE] - 21/01/2008 - 03:21:33 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\system32\drivers\adpahci.sys [300600]
                  O58 - SDL:[MD5.8A42779B02AEC986EAB64ECFC98F8BD7] - 21/01/2008 - 03:21:34 ---A- . (.Adaptec, Inc. - Adaptec LH Ultra160 Driver (x86).) -- C:\Windows\system32\drivers\adpu160m.sys [101432]
                  O58 - SDL:[MD5.241C9E37F8CE45EF51C3DE27515CA4E5] - 21/01/2008 - 03:21:35 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\system32\drivers\adpu320.sys [149560]
                  O58 - SDL:[MD5.9EAEF5FC9B8E351AFA7E78A6FAE91F91] - 21/01/2008 - 03:21:09 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\system32\drivers\aliide.sys [17464]
                  O58 - SDL:[MD5.5D2888182FB46632511ACEE92FDAD522] - 21/01/2008 - 03:21:32 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\system32\drivers\arc.sys [79416]
                  O58 - SDL:[MD5.5E2A321BD7C8B3624E41FDEC3E244945] - 21/01/2008 - 03:21:32 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\system32\drivers\arcsas.sys [79928]
                  O58 - SDL:[MD5.0C0B08847F2F24BAA7BD43D8F2C6C8B0] - 28/06/2010 - 21:32:33 ---A- . (.ALWIL Software - avast! File System Access Blocking Driver.) -- C:\Windows\system32\drivers\aswFsBlk.sys [17744]
                  O58 - SDL:[MD5.EFFC39A1EDF04E83A42279D9DAA696A7] - 28/06/2010 - 21:32:56 ---A- . (.ALWIL Software - avast! File System Minifilter for Windows 2003/Vista.) -- C:\Windows\system32\drivers\aswMonFlt.sys [50256]
                  O58 - SDL:[MD5.F385FFD39165453FDA96736AA3EDFD9D] - 28/06/2010 - 21:33:13 ---A- . (.ALWIL Software - avast! TDI RDR Driver.) -- C:\Windows\system32\drivers\aswRdr.sys [23376]
                  O58 - SDL:[MD5.45ADEA26BF613A54FED64ECDD12E58A7] - 28/06/2010 - 21:37:30 ---A- . (.ALWIL Software - avast! self protection module.) -- C:\Windows\system32\drivers\aswSP.sys [165456]
                  O58 - SDL:[MD5.C4EE975C87176F1900662D2874233C7F] - 28/06/2010 - 21:37:52 ---A- . (.ALWIL Software - avast! TDI Filter Driver.) -- C:\Windows\system32\drivers\aswTdi.sys [46672]
                  O58 - SDL:[MD5.D2E9ACB68FA61C911CC21E07F87705BF] - 01/12/2008 - 23:14:33 ---A- . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\system32\drivers\atikmdag.sys [4179968]
                  O58 - SDL:[MD5.9F9ACC7F7CCDE8A15C282D3F88B43309] - 02/11/2006 - 09:24:45 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\system32\drivers\BrFiltLo.sys [13568]
                  O58 - SDL:[MD5.56801AD62213A41F6497F96DEE83755A] - 02/11/2006 - 09:24:46 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\system32\drivers\BrFiltUp.sys [5248]
                  O58 - SDL:[MD5.B304E75CFF293029EDDF094246747113] - 02/11/2006 - 09:25:24 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\system32\drivers\BrSerId.sys [71808]
                  O58 - SDL:[MD5.203F0B1E73ADADBBB7B7B1FABD901F6B] - 02/11/2006 - 09:24:44 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\system32\drivers\BrSerWdm.sys [62336]
                  O58 - SDL:[MD5.BD456606156BA17E60A04E18016AE54B] - 02/11/2006 - 09:24:44 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\system32\drivers\BrUsbMdm.sys [12160]
                  O58 - SDL:[MD5.AF72ED54503F717A43268B3CC5FAEC2E] - 02/11/2006 - 09:24:47 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\system32\drivers\BrUsbSer.sys [11904]
                  O58 - SDL:[MD5.0CA25E686A4928484E9FDABD168AB629] - 21/01/2008 - 03:21:09 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\cmdide.sys [19000]
                  O58 - SDL:[MD5.AE1FDF7BF7BB6C6A70F67699D880592A] - 02/11/2006 - 10:50:11 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\system32\drivers\djsvs.sys [71272]
                  O58 - SDL:[MD5.5425F74AC0C1DBD96A1E04F17D63F94C] - 21/01/2008 - 03:21:33 ---A- . (.Intel Corporation - Pilote désérialisé NDIS 6 de la carte Intel(R) PRO/1000.) -- C:\Windows\system32\drivers\E1G60I32.sys [118784]
                  O58 - SDL:[MD5.23B62471681A124889978F6295B3F4C6] - 21/01/2008 - 03:21:30 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\system32\drivers\elxstor.sys [342584]
                  O58 - SDL:[MD5.8182FF89C65E4D38B2DE4BB0FB18564E] - 18/05/2009 - 13:17:00 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\system32\drivers\GEARAspiWDM.sys [26600]
                  O58 - SDL:[MD5.16EE7B23A009E00D835CDB79574A91A6] - 21/01/2008 - 03:21:34 ---A- . (.Hewlett-Packard Company - Smart Array Storport Driver.) -- C:\Windows\system32\drivers\HpCISSs.sys [40504]
                  O58 - SDL:[MD5.54155EA1B0DF185878E0FC9EC3AC3A14] - 21/01/2008 - 03:21:31 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver (base).) -- C:\Windows\system32\drivers\iaStorV.sys [235064]
                  O58 - SDL:[MD5.2D077BF86E843F901D8DB709C95B49A5] - 02/11/2006 - 10:50:17 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\system32\drivers\iirsp.sys [41576]
                  O58 - SDL:[MD5.BCED60D16156E428F8DF8CF27B0DF150] - 02/11/2006 - 10:50:07 ---A- . (.Integrated Technology Express, Inc. - ITE IT8211 ATA/ATAPI SCSI miniport.) -- C:\Windows\system32\drivers\iteatapi.sys [35944]
                  O58 - SDL:[MD5.06FA654504A498C30ADCA8BEC4E87E7E] - 02/11/2006 - 10:50:09 ---A- . (.Integrated Technology Express, Inc. - ITE IT8212 ATA RAID SCSI miniport.) -- C:\Windows\system32\drivers\iteraid.sys [35944]
                  O58 - SDL:[MD5.C7E15E82879BF3235B559563D4185365] - 21/01/2008 - 03:21:31 ---A- . (.LSI Logic - LSI Logic Fusion-MPT FC Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_fc.sys [96312]
                  O58 - SDL:[MD5.EE01EBAE8C9BF0FA072E0FF68718920A] - 21/01/2008 - 03:21:33 ---A- . (.LSI Logic - LSI Logic Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas.sys [89656]
                  O58 - SDL:[MD5.912A04696E9CA30146A62AFA1463DD5C] - 21/01/2008 - 03:21:31 ---A- . (.LSI Logic - LSI Logic Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_scsi.sys [96312]
                  O58 - SDL:[MD5.9B5CC6C481BDD00A963829B892623247] - 29/11/2010 - 17:42:06 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\system32\drivers\mbam.sys [20952]
                  O58 - SDL:[MD5.E74DC2F3F9675A6025A4AA020EDD4341] - 29/11/2010 - 17:42:18 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\system32\drivers\mbamswissarmy.sys [38224]
                  O58 - SDL:[MD5.8FD868E32459ECE2A1BB0169F513D31E] - 24/02/2009 - 17:42:14 ---A- . (.MagicISO, Inc. - MagicISO SCSI Host Controller.) -- C:\Windows\system32\drivers\mcdbus.sys [116736]
                  O58 - SDL:[MD5.0001CE609D66632FA17B84705F658879] - 21/01/2008 - 03:21:35 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows Vista/Longhorn for x.) -- C:\Windows\system32\drivers\megasas.sys [31288]
                  O58 - SDL:[MD5.C252F32CD9A49DBFC25ECF26EBD51A99] - 21/01/2008 - 03:21:35 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\system32\drivers\MegaSR.sys [386616]
                  O58 - SDL:[MD5.4FBBB70D30FD20EC51F80061703B001E] - 02/11/2006 - 10:49:59 ---A- . (.LSI Logic Corporation - MegaRAID RAID Controller Driver for Windows Vista/Longhorn for.) -- C:\Windows\system32\drivers\Mraid35x.sys [33384]
                  O58 - SDL:[MD5.2E7FB731D4790A1BC6270ACCEFACB36E] - 02/11/2006 - 10:50:19 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\system32\drivers\nfrd960.sys [45160]
                  O58 - SDL:[MD5.E875C093AEC0C978A90F30C9E0DFBB72] - 02/11/2006 - 08:36:50 ---A- . (.N-trig Innovative Technologies - Pilote intégré de digitalisateur de tablette N-trig.) -- C:\Windows\system32\drivers\ntrigdigi.sys [20608]
                  O58 - SDL:[MD5.2EDF9E7751554B42CBB60116DE727101] - 21/01/2008 - 03:21:29 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\system32\drivers\nvraid.sys [102968]
                  O58 - SDL:[MD5.ABED0C09758D1D97DB0042DBB2688177] - 21/01/2008 - 03:21:29 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor.sys [45112]
                  O58 - SDL:[MD5.175CC28DCF819F78CAA3FBD44AD9E52A] - 17/09/2007 - 15:53:26 ---A- . (.Nokia - PCCS Mode Change Filter Driver.) -- C:\Windows\system32\drivers\pccsmcfd.sys [21632]
                  O58 - SDL:[MD5.0A6DB55AFB7820C99AA1F3A1D270F4F6] - 21/01/2008 - 03:21:33 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\system32\drivers\ql2300.sys [1122360]
                  O58 - SDL:[MD5.81A7E5C076E59995D54BC1ED3A16E60B] - 02/11/2006 - 10:50:35 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\system32\drivers\ql40xx.sys [106088]
                  O58 - SDL:[MD5.1AA29238D4B14F4A20B2C4AAEA6E0F6E] - 18/06/2008 - 04:19:54 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\Windows\system32\drivers\RtHDMIV.sys [147168]
                  O58 - SDL:[MD5.5D26CCB06E1F3B5C26E863DF3F4F2611] - 03/07/2008 - 10:03:48 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\Windows\system32\drivers\RTKVHDA.sys [2152088]
                  O58 - SDL:[MD5.2FC33077F85D7DC0D03678C06D43898C] - 02/05/2008 - 06:59:40 ---A- . (.Realtek Corporation - Realtek 8101E/8168/8169 NDIS6 32-bit Driver.) -- C:\Windows\system32\drivers\Rtlh86.sys [122368]
                  O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 02/11/2006 - 07:37:21 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\system32\drivers\secdrv.sys [20480]
                  O58 - SDL:[MD5.A99C6C8B0BAA970D8AA59DDC50B57F94] - 21/01/2008 - 03:21:34 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\system32\drivers\sisraid4.sys [74808]
                  O58 - SDL:[MD5.24EE12006FFC547700ECFD7FF8EE1200] - 05/04/2009 - 00:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\drivers\sptd.sys [717296]
                  O58 - SDL:[MD5.306521935042FC0A6988D528643619B3] - 25/10/2007 - 17:26:10 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\drivers\StarOpen.sys [5632]
                  O58 - SDL:[MD5.192AA3AC01DF071B541094F251DEED10] - 02/11/2006 - 10:50:05 ---A- . (.LSI Logic - LSI Logic 8XX SCSI Miniport Driver.) -- C:\Windows\system32\drivers\symc8xx.sys [35944]
                  O58 - SDL:[MD5.8C8EB8C76736EBAF3B13B633B2E64125] - 02/11/2006 - 10:49:56 ---A- . (.LSI Logic - LSI Logic Hi-Perf SCSI Miniport Driver.) -- C:\Windows\system32\drivers\sym_hi.sys [31848]
                  O58 - SDL:[MD5.8072AF52B5FD103BBBA387A1E49F62CB] - 02/11/2006 - 10:50:03 ---A- . (.LSI Logic - LSI Logic Ultra160 SCSI Miniport Driver.) -- C:\Windows\system32\drivers\sym_u3.sys [34920]
                  O58 - SDL:[MD5.9224BB254F591DE4CA8D572A5F0D635C] - 21/01/2008 - 03:21:28 ---A- . (.ULi Electronics Inc. - ULi SATA Controller Driver.) -- C:\Windows\system32\drivers\uliahci.sys [238648]
                  O58 - SDL:[MD5.8514D0E5CD0534467C5FC61BE94A569F] - 02/11/2006 - 10:50:35 ---A- . (.Promise Technology, Inc. - Promise Ultra/Sata Series Driver for Win2003.) -- C:\Windows\system32\drivers\ulsata.sys [98408]
                  O58 - SDL:[MD5.38C3C6E62B157A6BC46594FADA45C62B] - 21/01/2008 - 03:21:31 ---A- . (.Promise Technology, Inc. - Promise SATAII150 Series Windows Drivers.) -- C:\Windows\system32\drivers\ulsata2.sys [115816]
                  O58 - SDL:[MD5.5C2BDC152BBAB34F36473DEAF7713F22] - 28/09/2010 - 15:44:52 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\system32\drivers\usbaapl.sys [41984]
                  O58 - SDL:[MD5.2CC2660B3EC3434C88D2C808DD7937D4] - 02/03/2009 - 12:41:49 ---A- . (.Elaborate Bytes AG - VirtualCloneCD Driver.) -- C:\Windows\system32\drivers\VClone.sys [29184]
                  O58 - SDL:[MD5.AADF5587A4063F52C2C3FED7887426FC] - 21/01/2008 - 03:21:09 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\viaide.sys [20024]
                  O58 - SDL:[MD5.587253E09325E6BF226B299774B728A9] - 21/01/2008 - 03:21:32 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\system32\drivers\vsmraid.sys [130616]
                  O58 - SDL:[MD5.8724531219AE3F9E3729012B61DCE527] - 28/08/2009 - 00:06:32 ---A- . (.Wacom Technology - Wacom HID Mouse Monitor Filter Driver.) -- C:\Windows\system32\drivers\wacmoumonitor.sys [16168]
                  O58 - SDL:[MD5.427A8BC96F16C40DF81C2D2F4EDD32DD] - 16/02/2007 - 20:12:36 ---A- . (.Wacom Technology - Wacom Mouse Filter Driver.) -- C:\Windows\system32\drivers\wacommousefilter.sys [11312]
                  O58 - SDL:[MD5.51D580F30D1A1F2EA4965AF6ABC2BCB2] - 20/05/2009 - 20:54:06 ---A- . (.Wacom Technology - Virtual Hid Device.) -- C:\Windows\system32\drivers\wacomvhid.sys [13736]
                  O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 02/11/2006 - 08:09:42 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\ANSI.SYS [9029]
                  O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 02/11/2006 - 08:09:45 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\country.sys [27097]
                  O58 - SDL:[MD5.790A4CA68F44BE35967B3DF61F3E4675] - 07/04/2009 - 09:39:44 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\FsUsbExDisk.Sys [36608]
                  O58 - SDL:[MD5.E6BC0F98FECEF245A0010D350C1A0B9B] - 02/11/2006 - 08:09:41 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\HIMEM.SYS [4768]
                  O58 - SDL:[MD5.492090267B9608C62B956CD29BE3AFB7] - 02/11/2006 - 08:09:44 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\KEY01.SYS [42809]
                  O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 02/11/2006 - 08:09:44 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\KEYBOARD.SYS [42537]
                  O58 - SDL:[MD5.FFFF296A08DBF2AC0126C62E3778AC0D] - 02/11/2006 - 08:09:29 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\NTDOS.SYS [27866]
                  O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 02/11/2006 - 08:09:35 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\NTDOS404.SYS [29146]
                  O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 02/11/2006 - 08:09:38 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\NTDOS411.SYS [29370]
                  O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 02/11/2006 - 08:09:40 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\NTDOS412.SYS [29274]
                  O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 02/11/2006 - 08:09:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\NTDOS804.SYS [29146]
                  O58 - SDL:[MD5.2E4112FB7D1B76E11ADFD7487B5D0E95] - 02/11/2006 - 08:09:20 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\NTIO.SYS [33952]
                  O58 - SDL:[MD5.A98EBD4C2DF983665BF2D1AF49949974] - 02/11/2006 - 08:09:23 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\NTIO404.SYS [34672]
                  O58 - SDL:[MD5.3F7E6406EDEF197C5CAAB2240EEF6F48] - 02/11/2006 - 08:09:24 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\NTIO411.SYS [35776]
                  O58 - SDL:[MD5.3E64D681B776CC57BDC38A46D881F85B] - 02/11/2006 - 08:09:26 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\NTIO412.SYS [35536]
                  O58 - SDL:[MD5.D86B6435729231C171432B4E77801BDB] - 02/11/2006 - 08:09:22 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\NTIO804.SYS [34672]

                  ---\\ Liste des outils de nettoyage (LATC) (O63)
                  O63 - Logiciel: ZHPDiag 1.27 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1

                  ---\\ Liste des services Legacy (LALS) (O64)
                  O64 - Services: CurCS - C:\Windows\system32\drivers\afd.sys - Ancilliary Function Driver for Winsock (AFD) .(.Microsoft Corporation - Ancillary Function Driver for WinSock.) - LEGACY_AFD
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWFSBLK.sys - (.not file.) - aswFsBlk (aswFsBlk) .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWFSBLK
                  O64 - Services: CurCS - C:\Windows\system32\drivers\aswMonFlt.sys - aswMonFlt (aswMonFlt) .(.ALWIL Software - avast! File System Minifilter for Windows 2.) - LEGACY_ASWMONFLT
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWRDR.sys - (.not file.) - aswRdr (aswRdr) .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWRDR
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWSP.sys - (.not file.) - avast! Self Protection (aswSP) .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWSP
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWTDI.sys - (.not file.) - avast! Network Shield Support (aswTdi) .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWTDI
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\BEEP.sys - (.not file.) - Beep (Beep) .(.Pas de propriétaire - Pas de description.) - LEGACY_BEEP
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\bowser.sys - Bowser (bowser) .(.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) - LEGACY_BOWSER
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\cdfs.sys - CD/DVD File System Reader (cdfs) .(.Microsoft Corporation - CD-ROM File System Driver.) - LEGACY_CDFS
                  O64 - Services: CurCS - C:\Windows\System32\CLFS.sys - Common Log (CLFS) (CLFS) .(.Microsoft Corporation - Common Log File System Driver.) - LEGACY_CLFS
                  O64 - Services: CurCS - C:\Windows\System32\drivers\crcdisk.sys - Crcdisk Filter Driver (crcdisk) .(.Microsoft Corporation - Disk Block Verification Filter Driver.) - LEGACY_CRCDISK
                  O64 - Services: CurCS - C:\Windows\System32\drivers\csc.sys - Offline Files Driver (CSC) .(.Microsoft Corporation - Windows Client Side Caching Driver.) - LEGACY_CSC
                  O64 - Services: CurCS - C:\Windows\system32\drivers\dfsc.sys (DfsC) .(.Microsoft Corporation - DFS Namespace Client Driver.) - LEGACY_DFSC
                  O64 - Services: CurCS - C:\Windows\system32\drivers\dxgkrnl.sys - LDDM Graphics Subsystem (DXGKrnl) .(.Microsoft Corporation - DirectX Graphics Kernel.) - LEGACY_DXGKRNL
                  O64 - Services: CurCS - C:\Windows\system32\eapsvc.dll (EapHost) .(.Microsoft Corporation - Service EAPHost Microsoft.) - LEGACY_EAPHOST
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\FASTFAT.sys - (.not file.) - FAT12/16/32 File System Driver (fastfat) .(.Pas de propriétaire - Pas de description.) - LEGACY_FASTFAT
                  O64 - Services: CurCS - C:\Windows\System32\drivers\fileinfo.sys - File Information FS MiniFilter (FileInfo) .(.Microsoft Corporation - FileInfo Filter Driver.) - LEGACY_FILEINFO
                  O64 - Services: CurCS - C:\Windows\System32\drivers\fltmgr.sys - FltMgr (FltMgr) .(.Microsoft Corporation - Gestionnaire de filtres de système de fichi.) - LEGACY_FLTMGR
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\FS_REC.sys - Fs_Rec (Fs_Rec) .(.Pas de propriétaire - Pas de description.) - LEGACY_FS_REC
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\fvevol.sys - BitLocker Drive Encryption Filter Driver (fvevol) .(.Microsoft Corporation - BitLocker Drive Encryption Driver.) - LEGACY_FVEVOL
                  O64 - Services: CurCS - C:\Windows\gdrv.sys - gdrv (gdrv) .(.Windows (R) 2000 DDK provider - GIGABYTE Tools.) - LEGACY_GDRV
                  O64 - Services: CurCS - C:\Windows\System32\drivers\HTTP.sys - HTTP (HTTP) .(.Microsoft Corporation - HTTP Pile du protocole.) - LEGACY_HTTP
                  O64 - Services: CurCS - (.not file.) - kl1 (kl1) .(.Pas de propriétaire - Pas de description.) - LEGACY_KL1
                  O64 - Services: CurCS - (.not file.) - Kaspersky Lab Driver (KLIF) .(.Pas de propriétaire - Pas de description.) - LEGACY_KLIF
                  O64 - Services: CurCS - C:\Windows\System32\Drivers\ksecdd.sys - KSecDD (KSecDD) .(.Microsoft Corporation - Kernel Security Support Provider Interface.) - LEGACY_KSECDD
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\lltdio.sys - Link-Layer Topology Discovery Mapper I/O Driver (lltdio) .(.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) - LEGACY_LLTDIO
                  O64 - Services: CurCS - C:\Windows\system32\drivers\luafv.sys - UAC File Virtualization (luafv) .(.Microsoft Corporation - Pilote de filtre de virtualisation de fichi.) - LEGACY_LUAFV
                  O64 - Services: CurCS - (.not file.) - mbr (mbr) .(.Pas de propriétaire - Pas de description.) - LEGACY_MBR
                  O64 - Services: CurCS - C:\Windows\System32\drivers\mountmgr.sys - Mount Point Manager (MountMgr) .(.Microsoft Corporation - Mount Point Manager.) - LEGACY_MOUNTMGR
                  O64 - Services: CurCS - C:\Windows\system32\FirewallAPI.dll (mpsdrv) .(.Microsoft Corporation - API du Pare-feu Windows.) - LEGACY_MPSDRV
                  O64 - Services: CurCS - C:\Windows\system32\drivers\mrxdav.sys - WebDav Client Redirector Driver (MRxDAV) .(.Microsoft Corporation - Windows NT WebDav Minirdr.) - LEGACY_MRXDAV
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\mrxsmb.sys - SMB MiniRedirector Wrapper and Engine (mrxsmb) .(.Microsoft Corporation - Windows NT SMB Minirdr.) - LEGACY_MRXSMB
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\mrxsmb10.sys - SMB 1.x MiniRedirector (mrxsmb10) .(.Microsoft Corporation - Longhorn SMB Downlevel SubRdr.) - LEGACY_MRXSMB10
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\mrxsmb20.sys - SMB 2.0 MiniRedirector (mrxsmb20) .(.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) - LEGACY_MRXSMB20
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\MSFS.sys - Msfs (Msfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_MSFS
                  O64 - Services: CurCS - C:\Windows\System32\drivers\msisadrv.sys - ISA/EISA Class Driver (msisadrv) .(.Microsoft Corporation - ISA Driver.) - LEGACY_MSISADRV
                  O64 - Services: CurCS - C:\Windows\System32\Drivers\mup.sys - Mup (Mup) .(.Microsoft Corporation - Multiple UNC Provider driver.) - LEGACY_MUP
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\nwifi.sys - Filtre NativeWiFi (NativeWifiP) .(.Microsoft Corporation - NativeWiFi Miniport Driver.) - LEGACY_NATIVEWIFIP
                  O64 - Services: CurCS - C:\Windows\System32\drivers\ndis.sys - NDIS System Driver (NDIS) .(.Microsoft Corporation - NDIS 6.0 wrapper driver.) - LEGACY_NDIS
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\ndisuio.sys - NDIS Usermode I/O Protocol (Ndisuio) .(.Microsoft Corporation - NDIS User mode I/O driver.) - LEGACY_NDISUIO
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\NDPROXY.sys - NDProxy (NDProxy) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDPROXY
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\netbios.sys - NetBIOS Interface (NetBIOS) .(.Microsoft Corporation - NetBIOS interface driver.) - LEGACY_NETBIOS
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\netbt.sys - NETBT (netbt) .(.Microsoft Corporation - MBT Transport driver.) - LEGACY_NETBT
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\NPFS.sys - Npfs (Npfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_NPFS
                  O64 - Services: CurCS - C:\Windows\System32\drivers\nsiproxy.sys - NSI proxy service (nsiproxy) .(.Microsoft Corporation - NSI Proxy.) - LEGACY_NSIPROXY
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\NTFS.sys - Ntfs (Ntfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_NTFS
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\NULL.sys - Null (Null) .(.Pas de propriétaire - Pas de description.) - LEGACY_NULL
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\parvdm.sys - Parvdm (Parvdm) .(.Microsoft Corporation - Pilote parallèle VDM.) - LEGACY_PARVDM
                  O64 - Services: CurCS - C:\Windows\System32\drivers\peauth.sys - PEAUTH (PEAUTH) .(.Microsoft Corporation - Protected Environment Authentication and Au.) - LEGACY_PEAUTH
                  O64 - Services: CurCS - C:\Windows\system32\p2psvc.dll (PNRPsvc) .(.Microsoft Corporation - Services pair à pair.) - LEGACY_PNRPSVC
                  O64 - Services: CurCS - C:\Windows\system32\drivers\pacer.sys (PSched) .(.Microsoft Corporation - Planificateur de paquets QoS.) - LEGACY_PSCHED
                  O64 - Services: CurCS - C:\Windows\system32\drivers\qwavedrv.sys (QWAVEdrv) .(.Microsoft Corporation - Pilote du support de Microsoft Quality Wind.) - LEGACY_QWAVEDRV
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\rasacd.sys - Remote Access Auto Connection Driver (RasAcd) .(.Microsoft Corporation - RAS Automatic Connection Driver.) - LEGACY_RASACD
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\rdbss.sys - Redirected Buffering Sub Sysytem (rdbss) .(.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - LEGACY_RDBSS
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\RDPCDD.sys - RDPCDD (RDPCDD) .(.Microsoft Corporation - RDP Miniport.) - LEGACY_RDPCDD
                  O64 - Services: CurCS - C:\Windows\System32\drivers\rdpencdd.sys - RDP Encoder Mirror Driver (RDPENCDD) .(.Microsoft Corporation - RDP Miniport.) - LEGACY_RDPENCDD
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\RDPWD.sys - (.not file.) - RDP Winstation Driver (RDPWD) .(.Pas de propriétaire - Pas de description.) - LEGACY_RDPWD
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\rspndr.sys - Link-Layer Topology Discovery Responder (rspndr) .(.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) - LEGACY_RSPNDR
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\SECDRV.sys - (.not file.) - Security Driver (secdrv) .(.Pas de propriétaire - Pas de description.) - LEGACY_SECDRV
                  O64 - Services: CurCS - C:\Windows\system32\tcpipcfg.dll (Smb) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_SMB
                  O64 - Services: CurCS - C:\Windows\system32\Drivers\SPLDR.sys - (.not file.) - Security Processor Loader Driver (spldr) .(.Pas de propriétaire - Pas de description.) - LEGACY_SPLDR
                  O64 - Services: CurCS - C:\Windows\System32\Drivers\sptd.sys - sptd (sptd) .(.Pas de propriétaire - Pas de description.) - LEGACY_SPTD
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\srv.sys - srv (srv) .(.Microsoft Corporation - Server driver.) - LEGACY_SRV
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\srv2.sys - srv2 (srv2) .(.Microsoft Corporation - Smb 2.0 Server driver.) - LEGACY_SRV2
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\srvnet.sys - srvnet (srvnet) .(.Microsoft Corporation - Server Network driver.) - LEGACY_SRVNET
                  O64 - Services: CurCS - C:\Windows\system32\tcpipcfg.dll (Tcpip) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_TCPIP
                  O64 - Services: CurCS - C:\Windows\System32\drivers\tcpipreg.sys - TCP/IP Registry Compatibility (tcpipreg) .(.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) - LEGACY_TCPIPREG
                  O64 - Services: CurCS - C:\Windows\System32\drivers\tdtcp.sys - TDTCP (TDTCP) .(.Microsoft Corporation - TCP Transport Driver.) - LEGACY_TDTCP
                  O64 - Services: CurCS - C:\Windows\system32\tcpipcfg.dll (tdx) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_TDX
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\tssecsrv.sys - Terminal Services Security Filter Driver (tssecsrv) .(.Microsoft Corporation - TS Security Filter Driver.) - LEGACY_TSSECSRV
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\udfs.sys - udfs (udfs) .(.Microsoft Corporation - UDF File System Driver.) - LEGACY_UDFS
                  O64 - Services: CurCS - C:\Windows\system32\drivers\vga.sys - VgaSave (VgaSave) .(.Microsoft Corporation - VGA/Super VGA Video Driver.) - LEGACY_VGASAVE
                  O64 - Services: CurCS - C:\Windows\System32\drivers\volmgrx.sys - Dynamic Volume Manager (volmgrx) .(.Microsoft Corporation - Volume Manager Extension Driver.) - LEGACY_VOLMGRX
                  O64 - Services: CurCS - C:\Windows\System32\drivers\volsnap.sys - Volumes de stockage (volsnap) .(.Microsoft Corporation - Pilote de cliché instantané du volume.) - LEGACY_VOLSNAP
                  O64 - Services: CurCS - C:\Windows\System32\DRIVERS\wanarp.sys - Remote Access IPv6 ARP Driver (Wanarpv6) .(.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - LEGACY_WANARPV6
                  O64 - Services: CurCS - C:\Windows\System32\drivers\Wdf01000.sys - Kernel Mode Driver Frameworks service (Wdf01000) .(.Microsoft Corporation - WDF dynamique.) - LEGACY_WDF01000
                  O64 - Services: CurCS - C:\Windows\System32\wlansvc.dll (Wlansvc) .(.Microsoft Corporation - DLL du service de configuration automatique.) - LEGACY_WLANSVC
                  O64 - Services: CurCS - "C:\Program Files\Windows Media Player\wmpnetwk.exe (.not file.) - @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) .(.Pas de propriétaire - Pas de description.) - LEGACY_WMPNETWORKSVC
                  O64 - Services: CurCS - C:\Program Files\CyberLink\PowerDVD8\000.fcl - {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054} ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) .(.Cyberlink Corp. - FCL Driver.) - LEGACY_{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}

                  ---\\ File Associations Shell Spawning (O67)
                  O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] "%1" %* (.not file.)
                  O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
                  O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] "%1" %* (.not file.)
                  O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] "%1" %* (.not file.)
                  O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] "%1" %* (.not file.)
                  O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Pas de propriétaire - Pas de description.) -- "C:\Program Files\Internet Explorer\iexplore.exe
                  O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
                  O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
                  O67 - Shell Spawning: <.com> <>[HKU\..\open\Command] (.Not Key.)
                  O67 - Shell Spawning: <.exe> <>[HKU\..\open\Command] (.Not Key.)
                  O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] "%1" %* (.not file.)
                  O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
                  O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] "%1" %* (.not file.)
                  O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] "%1" %* (.not file.)
                  O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] "%1" %* (.not file.)
                  O67 - Shell Spawning: <.html> <htmlfile>[HKCR\..\open\Command] (.Pas de propriétaire - Pas de description.) -- "C:\Program Files\Internet Explorer\iexplore.exe
                  O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
                  O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe

                  ---\\ Start Menu Internet (SMI) (O68)
                  O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe

                  ---\\ Search Browser Infection (SBI) (O69)
                  O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) - https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}
                  O69 - SBI: SearchScopes [HKCU] {AC854C16-CA1E-43f1-8513-0D2F36C726ED} [DefaultScope] - (Google) - http://www.samenc.com/search/?q={searchTerms}&ie=utf-8&oe=utf-8&aq=t&rls=MSXWZVzC
                  O69 - SBI: SearchScopes [HKCU] {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9} - (DAEMON Search) - http://www.daemon-search.com/search/web?q={searchTerms}
                  O69 - SBI: SearchScopes [HKCU] {FD63BF63-BFFF-4B8F-9D26-4267DF7F17DD} - (Google) - https://www.google.com/webhp{searchTerms}&sa.x=0&sa.y=0&safe=active&client=pub-3794288947762788&forid=1&channel=1975384696&ie=UTF-8&oe=UTF-8&hl=fr&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1

                  ---\\ Recherche des services démarrés par Svchost (SSS) (O83)
                  O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d'application.) -- C:\Windows\System32\aelupsvc.dll [24576]
                  O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [62976]
                  O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\system32\shsvcs.dll [247296]
                  O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [40448]
                  O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [40448]
                  O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\system32\srvsvc.dll [122880]
                  O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [574464]
                  O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [438272]
                  O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [314368]
                  O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d'accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
                  O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [260608]
                  O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d'interface dynamique.) -- C:\Windows\System32\mprdim.dll [68608]
                  O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d'événements système (SENS).) -- C:\Windows\System32\sens.dll [47104]
                  O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [288256]
                  O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242688]
                  O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes Terminal Server.) -- C:\Windows\System32\termsrv.dll [448512]
                  O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\system32\wuaueng.dll [1929952]
                  O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [758272]
                  O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [247296]
                  O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [190464]
                  O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [19968]
                  O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d'application.) -- C:\Windows\System32\appinfo.dll [33280]
                  O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\system32\iscsiexe.dll [111616]
                  O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\system32\mmcss.dll [45056]
                  O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [153600]
                  O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [57344]
                  O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [161792]
                  O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\system32\schedsvc.dll [596992]
                  O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service de configuration des services Terminal Server.) -- C:\Windows\system32\sessenv.dll [84992]
                  O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d'ordinateurs.) -- C:\Windows\System32\browser.dll [81920]
                  O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\system32\kmsvc.dll [68096]
                  O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [148992]

                  ---\\ Recherche particuliere à la racine de certains dossiers (SPRF) (O84)
                  [MD5.BFD203827AB373DE4650A8898DCD7E6A] [SPRF] (.Macromedia, Inc. - Macromedia Flash Player 6.0 r21.) -- C:\Users\Meg\AppData\Local\Temp\First15.exe [1453843]
                  [MD5.5A432A042DAE460ABE7199B758E8606C] [SPRF] (.Microsoft Corporation - Office Source Engine.) -- C:\Users\Meg\AppData\Local\Temp\ose00000.exe [145184]
                  [MD5.3F6BFE7811D2E28D7521B6EDC24F67BA] [SPRF] (.Windows (R) Codename Longhorn DDK provider - Windows Setup API.) -- C:\Users\Meg\AppData\Local\Temp\Qgx.exe [214016]
                  [MD5.5B2DA96D90C95228239806D40B720BD2] [SPRF] (.Pas de propriétaire - Pas de description.) -- C:\Users\Meg\AppData\Local\Temp\VP6.reg [340]
                  [MD5.1410ADCB69C267916EE702E2A443E93F] [SPRF] (.Pas de propriétaire - Pas de description.) -- C:\Users\Meg\AppData\Local\Temp\VP6Install.exe [23040]
                  [MD5.4D6F38D3CDA2D0BA502BC1C499A622CF] [SPRF] (.On2.com - VP6 VIDEO FOR WINDOWS CODEC.) -- C:\Users\Meg\AppData\Local\Temp\VP6VFW.dll [442368]
                  [MD5.A205551E7BA8580D2C0FF896A4D79FA9] [SPRF] (.Macrovision Corporation - Setup.exe.) -- C:\Users\Meg\AppData\Local\Temp\_isB1C1.exe [460248]

                  ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
                  SS - | Auto 16/10/2010 37664 | "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                  SR - | Auto 01/12/2008 720896 | C:\Windows\system32\Ati2evxx.exe (Ati External Event Utility) . (.ATI Technologies Inc..) - C:\Windows\system32\Ati2evxx.exe
                  SR - | Auto 28/06/2010 40384 | "C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                  SR - | Demand 28/06/2010 40384 | "C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (avast! Mail Scanner) . (.AVAST Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                  SR - | Demand 28/06/2010 40384 | "C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (avast! Web Scanner) . (.AVAST Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                  SS - | Auto 07/10/2010 345376 | "C:\Program Files\Bonjour\mDNSResponder.exe (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
                  SS - | Demand 02/02/2009 654848 | "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (FLEXnet Licensing Service) . (.Macrovision Europe Ltd..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                  SS - | Demand 04/04/2005 69632 | "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (IDriverT) . (.Macrovision Corporation.) - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  SR - | Demand 17/11/2010 820008 | "C:\Program Files\iPod\bin\iPodService.exe (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
                  SS - | Disabled 28/02/2008 529704 | "C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (NMIndexingService) . (.Nero AG.) - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                  SS - | Demand 07/04/2008 430592 | "C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (ServiceLayer) . (.Nokia..) - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                  SR - | Auto 06/10/2009 4463400 | C:\Windows\system32\Wacom_Tablet.exe (TabletServiceWacom) . (.Wacom Technology, Corp..) - C:\Windows\system32\Wacom_Tablet.exe
                  SS - | Auto 21/01/2008 21504 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\system32\svchost.exe
                  SR - | Auto 01/02/2008 41456 | C:\Program Files\CyberLink\PowerDVD8\000.fcl ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) . (.Cyberlink Corp..) - C:\Program Files\CyberLink\PowerDVD8\000.fcl

                  ---\\ Recherche Master Boot Record Infection (MBR)(O80)
                  Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.1 by Gmer, http://www.gmer.net
                  Run by Meg at 19/12/2010 21:18:07

                  device: opened successfully
                  user: MBR read successfully

                  Disk trace:
                  called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x856181F8]<<
                  1 ntkrnlpa!IofCallDriver[0x82AF705F] -> \Device\Harddisk0\DR0[0x85CCC408]
                  3 CLASSPNP[0x88FCC745] -> ntkrnlpa!IofCallDriver[0x82AF705F] -> [0x856EA270]
                  5 acpi[0x887456A0] -> ntkrnlpa!IofCallDriver[0x82AF705F] -> \Device\Ide\IdeDeviceP0T1L0-5[0x856D5030]
                  \Driver\atapi[0x8566D760] -> IRP_MJ_CREATE -> 0x856181F8
                  kernel: MBR read successfully
                  detected hooks:
                  \Driver\atapi -> 0x856181f8
                  user & kernel MBR OK
                  Warning: possible MBR rootkit infection !
                  Use "ZHPFix" command "MBRFix" to clear infection !

                  ---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)
                  Written by ad13, http://ad13.geekstog
                  Run by Meg at 19/12/2010 21:18:07
                  Use the desktop link 'MBRCheck' to have full report

                  ---\\ Liste des émulateurs de CD/DVD (Hook du MBR)
                  O58 - SDL:[MD5.24EE12006FFC547700ECFD7FF8EE1200] - 05/04/2009 - 00:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\drivers\sptd.sys [717296]

                  End of the scan (1113 lines in 00mn 25s)(0)
                  0
                  1. Re

                    Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                    Ou ici : https://forospyware.com
                    >Renomme le pour l'enregistrer sur ton bureau en asdehi (tout simplement pour que l'infection ne le contre pas)
                    -> Double clique combofix.exe.(ou clic droit sous vista « exécuter en tant que... » )
                    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                    Avant d'utiliser ComboFix :

                    -> Déconnecte toi d'Internet et referme les fenêtres de tous les programmes en cours.

                    -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

                    Une fois fait, sur ton bureau double-clic sur Combofix.exe ; (ou clic droit sous vista « exécuter en tant que... »)

                    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                    - Installe le console de récupération comme demandé ;utile en cas de plantage

                    - Attention Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programme. Risque de figer l'ordinateur

                    - En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                    -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                    -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

                    /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\ : risque de figer l'ordinateur (plantage complet)

                    ::Si combofix détecte quelque chose et de demande a redémarrer tu acceptes

                    @+
                    0
                    1. Voilà les résultats du scan combofix

                      ComboFix 10-12-18.02 - Meg 19/12/2010 23:54:38.1.2 - x86
                      Microsoft® Windows Vista(TM) Édition Intégrale 6.0.6001.1.1252.33.1036.18.2046.1256 [GMT 1:00]
                      Lancé depuis: c:\users\Meg\Desktop\asdehi.exe
                      SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                      .

                      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb

                      .
                      ((((((((((((((((((((((((((((( Fichiers créés du 2010-11-19 au 2010-12-19 ))))))))))))))))))))))))))))))))))))
                      .

                      2010-12-19 20:01 . 2010-12-19 20:01 -------- d-----w- c:\users\Meg\AppData\Local\VirtualStore
                      2010-12-19 14:29 . 2010-12-19 19:22 -------- d-----w- C:\FyK
                      2010-12-19 11:06 . 2010-12-19 13:07 -------- d-----w- c:\programdata\Spybot - Search & Destroy
                      2010-12-19 11:06 . 2010-12-19 11:06 -------- d-----w- c:\program files\Spybot - Search & Destroy
                      2010-12-17 22:41 . 2010-12-17 22:41 -------- d-----w- c:\users\Meg\AppData\Roaming\Malwarebytes
                      2010-12-17 22:40 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                      2010-12-17 22:40 . 2010-12-17 22:40 -------- d-----w- c:\programdata\Malwarebytes
                      2010-12-17 22:40 . 2010-12-17 22:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                      2010-12-17 22:40 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
                      2010-12-17 22:37 . 2010-05-27 19:16 738816 ----a-w- c:\windows\system32\inetcomm.dll
                      2010-12-17 22:34 . 2010-06-16 15:59 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
                      2010-12-17 22:26 . 2010-12-19 21:12 -------- d-----w- c:\program files\ZHPDiag
                      2010-12-17 22:24 . 2010-08-31 15:40 531968 ----a-w- c:\windows\system32\comctl32.dll
                      2010-12-17 16:37 . 2010-12-17 16:37 223232 ----a-w- c:\windows\Qhozoa.exe
                      2010-12-15 22:14 . 2010-12-15 22:15 -------- d-----w- c:\programdata\Abvent
                      2010-12-15 22:14 . 2010-12-15 22:14 -------- d-----w- c:\users\Meg\AppData\Roaming\Abvent
                      2010-12-15 22:11 . 2010-12-17 18:41 -------- d-----w- c:\program files\Artlantis Studio 3
                      2010-12-03 18:14 . 2010-12-03 18:14 -------- d-----w- c:\program files\iPod
                      2010-12-03 18:14 . 2010-12-03 18:15 -------- d-----w- c:\program files\iTunes
                      2010-11-30 09:00 . 2010-11-30 09:00 -------- d-----w- c:\program files\Google

                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2010-12-19 15:18 . 2010-12-19 15:18 749 ----a-w- C:\FindyKill_Upload_Me_PC-de-Meg.zip
                      2010-11-14 22:28 . 2010-11-14 22:28 30520 ----a-w- c:\windows\system32\midiwrap3405.deu
                      2010-11-07 00:26 . 2010-07-02 20:33 2560 ----a-w- c:\windows\_MSRSTRT.EXE
                      2010-10-07 11:23 . 2010-10-07 11:23 91424 ----a-w- c:\windows\system32\dnssd.dll
                      2010-10-07 11:23 . 2010-10-07 11:23 107808 ----a-w- c:\windows\system32\dns-sd.exe
                      2010-09-28 14:44 . 2010-09-28 14:44 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
                      2010-09-28 14:44 . 2010-09-28 14:44 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
                      .

                      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                      REGEDIT4

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
                      "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
                      "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
                      "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
                      "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
                      "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
                      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-17 421160]
                      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
                      "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

                      c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                      Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2009-2-2 295606]
                      Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                      "ConsentPromptBehaviorAdmin"= 0 (0x0)
                      "ConsentPromptBehaviorUser"= 0 (0x0)
                      "EnableUIADesktopToggle"= 0 (0x0)
                      "UacDisableNotify"= 0 (0x0)

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                      "aux1"=wdmaud.drv

                      [HKLM\~\startupfolder\C:^Users^Meg^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
                      path=c:\users\Meg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
                      backup=c:\windows\pss\MagicDisc.lnk.Startup
                      backupExtension=.Startup

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
                      2006-10-22 22:24 620152 ----a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
                      2008-12-29 10:40 687560 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
                      2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
                      0
                      1. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nikon Transfer Monitor]
                        2009-02-24 16:00 479232 ----a-w- c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                        2010-09-08 09:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPSTEALT]
                        2007-06-29 14:49 1945600 ----a-w- c:\program files\Smart Protector Pro\SmartProtector-Pro.exe

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
                        2009-01-26 14:31 2144088 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
                        2010-04-28 18:15 2633976 ----a-w- c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe

                        R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-04-07 36608]
                        S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-04-05 717296]
                        S1 aswSP;aswSP; [x]
                        S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [2008-02-01 41456]
                        S2 aswFsBlk;aswFsBlk; [x]
                        S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256]
                        S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2009-10-06 4463400]
                        S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2009-08-27 16168]

                        .
                        Contenu du dossier 'Tâches planifiées'

                        2010-04-01 c:\windows\Tasks\CreateChoiceProcessTask.job
                        - c:\windows\System32\browserchoice.exe [2010-04-01 10:48]
                        .
                        .
                        ------- Examen supplémentaire -------
                        .
                        uStart Page = hxxp://www.google.fr/
                        uInternet Settings,ProxyOverride = *.local
                        IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                        IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                        IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                        IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                        IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                        IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                        IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                        IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                        IE: Free YouTube to Mp3 Converter - c:\users\Meg\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
                        .
                        - - - - ORPHELINS SUPPRIMES - - - -

                        HKCU-Run-AutoStartNPSAgent - c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe
                        HKCU-Run-Shareaza - c:\program files\Shareaza\Shareaza.exe
                        MSConfigStartUp-Shareaza - c:\program files\Shareaza\Shareaza.exe
                        MSConfigStartUp-VirtualCloneDrive - c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe

                        **************************************************************************

                        catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2010-12-20 00:02
                        Windows 6.0.6001 Service Pack 1 NTFS

                        Recherche de processus cachés ...

                        Recherche d'éléments en démarrage automatique cachés ...

                        Recherche de fichiers cachés ...

                        Scan terminé avec succès
                        Fichiers cachés: 0

                        **************************************************************************

                        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
                        "ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
                        .
                        --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
                        @Denied: (A 2) (Everyone)
                        @="FlashBroker"
                        "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
                        "Enabled"=dword:00000001

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
                        @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
                        @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
                        @Denied: (A 2) (Everyone)
                        @="IFlashBroker4"

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
                        @="{00020424-0000-0000-C000-000000000046}"

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
                        @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                        "Version"="1.0"
                        .
                        Heure de fin: 2010-12-20 00:05:45
                        ComboFix-quarantined-files.txt 2010-12-19 23:05

                        Avant-CF: 13 481 963 520 octets libres
                        Après-CF: 17 635 676 160 octets libres

                        - - End Of File - - FC58275CE8E9F2622D94ECCCC2387E9D
                        0
                        1. Bonjour

                          Rends toi sur ce site :

                          https://www.virustotal.com/gui/

                          Clique sur " parcourir ", cherche un fichier à la fois :

                          Clique sur Send File.

                          c:\windows\Qhozoa.exe
                          c:\windows\system32\midiwrap3405.deu


                          Un rapport va s'élaborer ligne à ligne.

                          Attends la fin. Il doit comprendre la taille du fichier envoyé.

                          Sauvegarde le rapport en copiant le lien de Virus Total. (C'est mieux)

                          Copie le lien du rapport dans ta réponse et fait le pour chaque fichier ; merci

                          (!) Si Virus Total indique que le fichier a déjà été analysé, cliquer sur le bouton. Ré analyser le fichier maintenant

                          @+
                          0
                          1. Bonjour Guillaume,

                            Voilà le rapport pour midiwrap3405.deu

                            http://www.virustotal.com/file-scan/report.html?id=f3db4e27a07764e1c8f104dd781ed69ef6c0a5dca7881b04293c5050a63e3587-1292845324

                            Pour Qhozoa.exe c'est une autre histoire. Vu que mon PC infecté ne trouve plus de réseaux je fais toutes les manips demandant internet que tu me conseilles sur un autre PC. J'ai donc copié midiwrap3405 et Qhozoa.exe sur une vieille clé USB pour pouvoir les analyser sur Virus Total. Dès que j'ai branché la clé, Avast a mis Qhozoa.exe en quarantaine.

                            Nom de fichier: Qhozoa.exe
                            Description du fichier: Win32:Trojan-gen

                            Est-ce que je peux restaurer ce fichier sur ma clé USB et l'analyser?
                            0
                            1. Re

                              Non;

                              Ce fichier Qhozoa.exe est donc bien infectieux.

                              Procède comme ceci:

                              _____________________________________________________
                              ATTENTION /!\ Le script qui suit a été écrit spécialement pour cet ordinateur
                              |===>il est fort déconseillé de le transposer sur un autre ordinateur !<===|
                              -----------------------------------------------------------------------------------------------

                              Toujours avec toutes les protections désactivées, fais ceci :

                              * Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
                              * Copie/colle dans le bloc-notes ce qui est entre les lignes ci dessous (sans les lignes) :

                              -----------------------------------------------------------------------------------------------

                              File::
                              c:\windows\Qhozoa.exe

                              --------------------------------------------------------------------------------------------------

                              * Enregistre ce fichier sur ton Bureau (et pas ailleurs !) Sous le nom CFScript.txt
                              * Quitte le Bloc Notes

                              * Fais un glisser/déposer de ce fichier CFScript sur le fichier C-Fix.exe (combofix) comme sur ce lien : https://support.microsoft.com/en-us/windows?ui=en-US&rs=en-001&ad=US
                              * Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
                              * Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
                              * Si le fichier ne s'ouvre pas, il se trouve ici ? C:\ComboFix.txt

                              @+
                              0
                              1. Voilà le nouveau rapport Combofix:

                                ComboFix 10-12-18.02 - Meg 20/12/2010 14:59:41.2.2 - x86
                                Microsoft® Windows Vista(TM) Édition Intégrale 6.0.6001.1.1252.33.1036.18.2046.1194 [GMT 1:00]
                                Lancé depuis: c:\users\Meg\Desktop\asdehi.exe
                                Commutateurs utilisés :: c:\users\Meg\Desktop\CFScript.txt
                                SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                                .

                                ((((((((((((((((((((((((((((( Fichiers créés du 2010-11-20 au 2010-12-20 ))))))))))))))))))))))))))))))))))))
                                .

                                2010-12-20 14:07 . 2010-12-20 14:07 -------- d-----w- c:\users\Default\AppData\Local\temp
                                2010-12-19 23:05 . 2010-12-20 14:07 -------- d-----w- c:\users\Meg\AppData\Local\temp
                                2010-12-19 20:01 . 2010-12-19 20:01 -------- d-----w- c:\users\Meg\AppData\Local\VirtualStore
                                2010-12-19 14:29 . 2010-12-20 13:49 -------- d-----w- C:\FyK
                                2010-12-19 11:06 . 2010-12-19 13:07 -------- d-----w- c:\programdata\Spybot - Search & Destroy
                                2010-12-19 11:06 . 2010-12-19 11:06 -------- d-----w- c:\program files\Spybot - Search & Destroy
                                2010-12-17 22:41 . 2010-12-17 22:41 -------- d-----w- c:\users\Meg\AppData\Roaming\Malwarebytes
                                2010-12-17 22:40 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                                2010-12-17 22:40 . 2010-12-17 22:40 -------- d-----w- c:\programdata\Malwarebytes
                                2010-12-17 22:40 . 2010-12-17 22:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                                2010-12-17 22:40 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
                                2010-12-17 22:37 . 2010-05-27 19:16 738816 ----a-w- c:\windows\system32\inetcomm.dll
                                2010-12-17 22:34 . 2010-06-16 15:59 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
                                2010-12-17 22:26 . 2010-12-19 21:12 -------- d-----w- c:\program files\ZHPDiag
                                2010-12-17 22:24 . 2010-08-31 15:40 531968 ----a-w- c:\windows\system32\comctl32.dll
                                2010-12-17 16:37 . 2010-12-17 16:37 223232 ----a-w- c:\windows\Qhozoa.exe
                                2010-12-15 22:14 . 2010-12-15 22:15 -------- d-----w- c:\programdata\Abvent
                                2010-12-15 22:14 . 2010-12-15 22:14 -------- d-----w- c:\users\Meg\AppData\Roaming\Abvent
                                2010-12-15 22:11 . 2010-12-17 18:41 -------- d-----w- c:\program files\Artlantis Studio 3
                                2010-12-03 18:14 . 2010-12-03 18:14 -------- d-----w- c:\program files\iPod
                                2010-12-03 18:14 . 2010-12-03 18:15 -------- d-----w- c:\program files\iTunes
                                2010-11-30 09:00 . 2010-11-30 09:00 -------- d-----w- c:\program files\Google

                                .
                                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2010-12-19 15:18 . 2010-12-19 15:18 749 ----a-w- C:\FindyKill_Upload_Me_PC-de-Meg.zip
                                2010-11-14 22:28 . 2010-11-14 22:28 30520 ----a-w- c:\windows\system32\midiwrap3405.deu
                                2010-11-07 00:26 . 2010-07-02 20:33 2560 ----a-w- c:\windows\_MSRSTRT.EXE
                                2010-10-07 11:23 . 2010-10-07 11:23 91424 ----a-w- c:\windows\system32\dnssd.dll
                                2010-10-07 11:23 . 2010-10-07 11:23 107808 ----a-w- c:\windows\system32\dns-sd.exe
                                2010-09-28 14:44 . 2010-09-28 14:44 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
                                2010-09-28 14:44 . 2010-09-28 14:44 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
                                .

                                ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                REGEDIT4

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
                                "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
                                "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
                                "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
                                "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
                                "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
                                "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-17 421160]
                                "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
                                "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

                                c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                                Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2009-2-2 295606]
                                Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                "ConsentPromptBehaviorAdmin"= 0 (0x0)
                                "ConsentPromptBehaviorUser"= 0 (0x0)
                                "EnableUIADesktopToggle"= 0 (0x0)
                                "UacDisableNotify"= 0 (0x0)

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                "aux1"=wdmaud.drv

                                [HKLM\~\startupfolder\C:^Users^Meg^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
                                path=c:\users\Meg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
                                backup=c:\windows\pss\MagicDisc.lnk.Startup
                                backupExtension=.Startup

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
                                2006-10-22 22:24 620152 ----a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
                                2008-12-29 10:40 687560 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
                                2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nikon Transfer Monitor]
                                2009-02-24 16:00 479232 ----a-w- c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                                2010-09-08 09:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPSTEALT]
                                2007-06-29 14:49 1945600 ----a-w- c:\program files\Smart Protector Pro\SmartProtector-Pro.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
                                2009-01-26 14:31 2144088 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
                                2010-04-28 18:15 2633976 ----a-w- c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe

                                R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-04-07 36608]
                                S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-04-05 717296]
                                S1 aswSP;aswSP; [x]
                                S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [2008-02-01 41456]
                                S2 aswFsBlk;aswFsBlk; [x]
                                S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256]
                                S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2009-10-06 4463400]
                                S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2009-08-27 16168]

                                .
                                Contenu du dossier 'Tâches planifiées'

                                2010-04-01 c:\windows\Tasks\CreateChoiceProcessTask.job
                                - c:\windows\System32\browserchoice.exe [2010-04-01 10:48]
                                .
                                .
                                ------- Examen supplémentaire -------
                                .
                                uStart Page = hxxp://www.google.fr/
                                uInternet Settings,ProxyOverride = *.local
                                IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                                IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                                IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                                IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                                IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                                IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                                IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                                IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                                IE: Free YouTube to Mp3 Converter - c:\users\Meg\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
                                .

                                **************************************************************************

                                catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2010-12-20 15:07
                                Windows 6.0.6001 Service Pack 1 NTFS

                                Recherche de processus cachés ...

                                Recherche d'éléments en démarrage automatique cachés ...

                                Recherche de fichiers cachés ...

                                Scan terminé avec succès
                                Fichiers cachés: 0

                                **************************************************************************

                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
                                "ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
                                .
                                --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
                                @Denied: (A 2) (Everyone)
                                @="FlashBroker"
                                "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
                                "Enabled"=dword:00000001

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
                                @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
                                @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
                                @Denied: (A 2) (Everyone)
                                @="IFlashBroker4"

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
                                @="{00020424-0000-0000-C000-000000000046}"

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
                                @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                                "Version"="1.0"
                                .
                                Heure de fin: 2010-12-20 15:11:46
                                ComboFix-quarantined-files.txt 2010-12-20 14:11

                                Avant-CF: 17 422 188 544 octets libres
                                Après-CF: 16 865 337 344 octets libres

                                - - End Of File - - 1383C649ECD68361106332020FFC449C
                                0
                                1. Re

                                  Tu as raté ce script.

                                  Désinstalle en priorité Spybot

                                  File::
                                  c:\windows\Qhozoa.exe


                                  Ouvre le bloc notes (Démarrer / Tous les programmes / Accessoires / Bloc Notes )

                                  * Enregistre ce fichier sur ton Bureau (et pas ailleurs !) Sous le nom CFScript.txt
                                  * Quitte le Bloc Notes

                                  * Fais un glisser/déposer de ce fichier CFScript sur le fichier C-Fix.exe (combofix) comme sur ce lien : https://support.microsoft.com/en-us/windows?ui=en-US&rs=en-001&ad=US

                                  @+
                                  ---------Contributeur Sécurité---------
                                  On a tous été un jour débutant dans quelque chose.
                                  Mais le savoir est la récompense de l'assiduité.
                                  0
                                  1. J'ai désinstallé Spybot et d'autres logiciel anti-malware. Et désactivé Avast.

                                    ComboFix 10-12-18.02 - Meg 20/12/2010 15:44:42.3.2 - x86
                                    Microsoft® Windows Vista(TM) Édition Intégrale 6.0.6001.1.1252.33.1036.18.2046.1269 [GMT 1:00]
                                    Lancé depuis: c:\users\Meg\Desktop\asdehi.exe
                                    Commutateurs utilisés :: c:\users\Meg\Desktop\CFScript.txt
                                    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

                                    FILE ::
                                    "c:\windows\Qhozoa.exe"
                                    .

                                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .

                                    c:\windows\Qhozoa.exe

                                    .
                                    ((((((((((((((((((((((((((((( Fichiers créés du 2010-11-20 au 2010-12-20 ))))))))))))))))))))))))))))))))))))
                                    .

                                    2010-12-20 14:52 . 2010-12-20 14:52 -------- d-----w- c:\users\Meg\AppData\Local\temp
                                    2010-12-20 14:52 . 2010-12-20 14:52 -------- d-----w- c:\users\Default\AppData\Local\temp
                                    2010-12-19 20:01 . 2010-12-19 20:01 -------- d-----w- c:\users\Meg\AppData\Local\VirtualStore
                                    2010-12-19 14:29 . 2010-12-20 13:49 -------- d-----w- C:\FyK
                                    2010-12-19 11:06 . 2010-12-20 14:31 -------- d-----w- c:\program files\Spybot - Search & Destroy
                                    2010-12-19 11:06 . 2010-12-20 14:30 -------- d-----w- c:\programdata\Spybot - Search & Destroy
                                    2010-12-17 22:41 . 2010-12-17 22:41 -------- d-----w- c:\users\Meg\AppData\Roaming\Malwarebytes
                                    2010-12-17 22:40 . 2010-12-17 22:40 -------- d-----w- c:\programdata\Malwarebytes
                                    2010-12-17 22:37 . 2010-05-27 19:16 738816 ----a-w- c:\windows\system32\inetcomm.dll
                                    2010-12-17 22:34 . 2010-06-16 15:59 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
                                    2010-12-17 22:26 . 2010-12-19 21:12 -------- d-----w- c:\program files\ZHPDiag
                                    2010-12-17 22:24 . 2010-08-31 15:40 531968 ----a-w- c:\windows\system32\comctl32.dll
                                    2010-12-15 22:14 . 2010-12-15 22:15 -------- d-----w- c:\programdata\Abvent
                                    2010-12-15 22:14 . 2010-12-15 22:14 -------- d-----w- c:\users\Meg\AppData\Roaming\Abvent
                                    2010-12-15 22:11 . 2010-12-17 18:41 -------- d-----w- c:\program files\Artlantis Studio 3
                                    2010-12-03 18:14 . 2010-12-03 18:14 -------- d-----w- c:\program files\iPod
                                    2010-12-03 18:14 . 2010-12-03 18:15 -------- d-----w- c:\program files\iTunes
                                    2010-11-30 09:00 . 2010-11-30 09:00 -------- d-----w- c:\program files\Google

                                    .
                                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    2010-12-19 15:18 . 2010-12-19 15:18 749 ----a-w- C:\FindyKill_Upload_Me_PC-de-Meg.zip
                                    2010-11-14 22:28 . 2010-11-14 22:28 30520 ----a-w- c:\windows\system32\midiwrap3405.deu
                                    2010-11-07 00:26 . 2010-07-02 20:33 2560 ----a-w- c:\windows\_MSRSTRT.EXE
                                    2010-10-07 11:23 . 2010-10-07 11:23 91424 ----a-w- c:\windows\system32\dnssd.dll
                                    2010-10-07 11:23 . 2010-10-07 11:23 107808 ----a-w- c:\windows\system32\dns-sd.exe
                                    2010-09-28 14:44 . 2010-09-28 14:44 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
                                    2010-09-28 14:44 . 2010-09-28 14:44 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
                                    .

                                    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                    REGEDIT4

                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
                                    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
                                    "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
                                    "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
                                    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
                                    "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
                                    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-17 421160]
                                    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
                                    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

                                    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                                    Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2009-2-2 295606]
                                    Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                    "ConsentPromptBehaviorAdmin"= 0 (0x0)
                                    "ConsentPromptBehaviorUser"= 0 (0x0)
                                    "EnableUIADesktopToggle"= 0 (0x0)
                                    "UacDisableNotify"= 0 (0x0)

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                    "aux1"=wdmaud.drv

                                    [HKLM\~\startupfolder\C:^Users^Meg^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
                                    path=c:\users\Meg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
                                    backup=c:\windows\pss\MagicDisc.lnk.Startup
                                    backupExtension=.Startup

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
                                    2006-10-22 22:24 620152 ----a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
                                    2008-12-29 10:40 687560 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
                                    2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nikon Transfer Monitor]
                                    2009-02-24 16:00 479232 ----a-w- c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                                    2010-09-08 09:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPSTEALT]
                                    2007-06-29 14:49 1945600 ----a-w- c:\program files\Smart Protector Pro\SmartProtector-Pro.exe

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
                                    2010-04-28 18:15 2633976 ----a-w- c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe

                                    R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-04-07 36608]
                                    S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-04-05 717296]
                                    S1 aswSP;aswSP; [x]
                                    S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [2008-02-01 41456]
                                    S2 aswFsBlk;aswFsBlk; [x]
                                    S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256]
                                    S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2009-10-06 4463400]
                                    S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2009-08-27 16168]

                                    .
                                    Contenu du dossier 'Tâches planifiées'

                                    2010-04-01 c:\windows\Tasks\CreateChoiceProcessTask.job
                                    - c:\windows\System32\browserchoice.exe [2010-04-01 10:48]
                                    .
                                    .
                                    ------- Examen supplémentaire -------
                                    .
                                    uStart Page = hxxp://www.google.fr/
                                    uInternet Settings,ProxyOverride = *.local
                                    IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                                    IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                                    IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                                    IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                                    IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                                    IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                                    IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                                    IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                                    IE: Free YouTube to Mp3 Converter - c:\users\Meg\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
                                    .
                                    - - - - ORPHELINS SUPPRIMES - - - -

                                    MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe

                                    **************************************************************************

                                    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                    Rootkit scan 2010-12-20 15:52
                                    Windows 6.0.6001 Service Pack 1 NTFS

                                    Recherche de processus cachés ...

                                    Recherche d'éléments en démarrage automatique cachés ...

                                    Recherche de fichiers cachés ...

                                    Scan terminé avec succès
                                    Fichiers cachés: 0

                                    **************************************************************************

                                    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
                                    "ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
                                    .
                                    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
                                    @Denied: (A 2) (Everyone)
                                    @="FlashBroker"
                                    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
                                    "Enabled"=dword:00000001

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
                                    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
                                    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
                                    @Denied: (A 2) (Everyone)
                                    @="IFlashBroker4"

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
                                    @="{00020424-0000-0000-C000-000000000046}"

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
                                    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                                    "Version"="1.0"
                                    .
                                    Heure de fin: 2010-12-20 15:55:03
                                    ComboFix-quarantined-files.txt 2010-12-20 14:55
                                    ComboFix2.txt 2010-12-20 14:11

                                    Avant-CF: 17 163 972 608 octets libres
                                    Après-CF: 17 129 963 520 octets libres

                                    - - End Of File - - 3474E33B8ABADF32DEE92B94DA8F74C5
                                    0
                                    1. Re

                                      Quoi de neuf?

                                      Poste moi un nouveau rapport ZHPDiag;merci.

                                      @+
                                      0
                                      1. Pour l'instant les symptomes persistent.

                                        Rapport de ZHPDiag v1.27.143 par Nicolas Coolman, Update du 18/12/2010
                                        Run by Meg at 20/12/2010 16:21:57
                                        Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
                                        Contact : nicolascoolman@yahoo.fr

                                        ---\\ Web Browser
                                        MSIE: Internet Explorer v7.0.6001.18000 (Defaut)

                                        ---\\ System Information
                                        Windows Vista Ultimate Edition, 32-bit Service Pack 1 (Build 6001)
                                        Processor: x86 Family 15 Model 107 Stepping 2, AuthenticAMD
                                        Operating System: 32 Bits
                                        Boot mode: Normal (Normal boot)
                                        Total RAM: 2045 MB (60% free)
                                        System Restore: Activé (Enable)
                                        System drive C: has 15 GB (6%) free of 233 GB

                                        ---\\ Logged in mode
                                        Computer Name: PC-DE-MEG
                                        User Name: Meg
                                        All Users Names: Meg, Administrateur,
                                        Unselected Option: O1,O45,O61,O62,O65,O82
                                        Logged in as Administrator

                                        ---\\ DOS/Devices
                                        C:\ Hard drive, Flash drive, Thumb drive (Free 15 Go of 233 Go)
                                        D:\ CD-ROM drive (Not Inserted)
                                        E:\ CD-ROM drive (Not Inserted)
                                        G:\ CD-ROM drive (Not Inserted)

                                        ---\\ Security Center & Tools Informations
                                        [HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK
                                        [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
                                        [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
                                        [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
                                        [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
                                        [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
                                        [HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK
                                        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK
                                        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK
                                        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK
                                        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableTaskMgr: OK
                                        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableRegistryTools: OK
                                        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] NoDispScrSavPage: OK
                                        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK
                                        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
                                        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK

                                        ---\\ Recherche particulière de fichiers génériques
                                        [MD5.4F554999D7D5F05DAAEBBA7B5BA1089D] - (.Microsoft Corporation - Explorateur Windows.) (.29/10/2008 07:29:41.) -- C:\Windows\Explorer.exe [2927104]
                                        [MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de démarrage de Windows.) (.21/01/2008 03:21:52.) -- C:\Windows\System32\Wininit.exe [96768]
                                        [MD5.C2610B6BDBEFC053BBDAB4F1B965CB24] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.21/01/2008 03:22:59.) -- C:\Windows\System32\Winlogon.exe [314880]
                                        [MD5.2D9C903DC76A66813D350A562DE40ED9] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.21/01/2008 03:21:09.) -- C:\Windows\System32\drivers\atapi.sys [21560]
                                        [MD5.B4EFFE29EB4F15538FD8A9681108492D] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.21/01/2008 03:21:58.) -- C:\Windows\System32\drivers\ntfs.sys [1081912]

                                        ---\\ Processus lancés
                                        [MD5.25B2065B6EE1B9DA77899CE8BAC251A2] - (.Wacom Technology, Corp. - Tablet user module for professional driver.) -- C:\Windows\system32\WTablet\Wacom_TabletUser.exe [1823528]
                                        [MD5.D93985F5D87DF1A119E939EADB5C4B9E] - (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Windows\RtHDVCpl.exe [6266880]
                                        [MD5.3A0647BDED81DBE0BCBB51D70B22C9E0] - (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jusched.exe [149280]
                                        [MD5.38AE7A942FC3FAB1C6A27EB65DE8F827] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2837864]
                                        [MD5.2DFCB2393528446AEB9FB861A8FC39AB] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [421160]
                                        [MD5.A32B25970003B6ABA027EFF8EEDA12A3] - (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe [35760]
                                        [MD5.33C014C1709F7222CEFF61B780EDC967] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Monitoring program.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe [49152]
                                        [MD5.BF08674925F151BD4537B89A493E3E0C] - (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehtray.exe [125952]
                                        [MD5.090F01749074A52290A1CC2FB5FB20B7] - (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe [46200]
                                        [MD5.0F4195B9B348DE5CF9B822F81704B20E] - (.Microsoft Corporation - Media Center Media Status Aggregator Servic.) -- C:\Windows\ehome\ehmsas.exe [37376]
                                        [MD5.D3300FF793D1746A73BE59C23E3D25FB] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [620544]
                                        [MD5.BA7D56C1F3DD385EE58ADDA14C6FFB54] - (.ATI Technologies Inc. - Catalyst Control Centre: Host application.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [49152]

                                        ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2)
                                        P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\Macromed\Flash\NPSWF32.dll
                                        P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
                                        P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
                                        P2 - FPN: [HKLM] [@wacom.com/wacom-plugin,version=1.1.0.3] - (.Wacom, Inc. - Wacom Dynamic Link Library.) -- C:\Program Files\TabletPlugins\npwacom.dll

                                        ---\\ Internet Explorer, Démarrage,Recherche,URSearchHook (R0,R1,R3)
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm
                                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
                                        R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} . (.DeviceVM Inc. - DeviceVM Url Search Hook.) (1.0.4.9) -- C:\Windows\System32\dvmurl.dll
                                        R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (7.00.6000.16386 (vista_rtm.061101-2205)) -- C:\Windows\system32\ieframe.dll

                                        ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
                                        F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
                                        F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

                                        ---\\ Browser Helper Objects de navigateur (O2)
                                        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
                                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll

                                        ---\\ Internet Explorer Toolbars (O3)
                                        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                        O3 - Toolbar: Veoh Video Compass - {52836EB0-631A-47B1-94A6-61F9D9112DAE} . (.Veoh Networks - Veoh Video Compass.) -- C:\Program Files\Veoh Networks\Veoh Video Compass\SearchRecsPlugin.dll

                                        ---\\ Applications démarrées par registre & par dossier (O4)
                                        O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Windows\RtHDVCpl.exe
                                        O4 - HKLM\..\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jusched.exe
                                        O4 - HKLM\..\Run: [avast5] . (.AVAST Software - avast! Antivirus.) -- C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
                                        O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
                                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
                                        O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
                                        O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
                                        O4 - HKCU\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
                                        O4 - HKCU\..\Run: [MsnMsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                        O4 - HKUS\S-1-5-21-1951595872-2322908241-4017401938-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
                                        O4 - HKUS\S-1-5-21-1951595872-2322908241-4017401938-1000\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
                                        O4 - HKUS\S-1-5-21-1951595872-2322908241-4017401938-1000\..\Run: [MsnMsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                        O4 - Global Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk . (.Pas de propriétaire.) -- C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe
                                        O4 - Global Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk . (.Adobe Systems Incorporated.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe

                                        ---\\ Autres liens utilisateurs (O4)
                                        O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\Adobe Photoshop CS3.lnk . (.Adobe Systems, Incorporated.) -- C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe
                                        O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\Media Player Classic.lnk . (.mpc-hc@Sourceforge.) -- C:\Program Files\mplayerc_homecinema_x86_v1.2.908.0\mplayerc.exe
                                        O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\Microsoft Office Outlook 2007.lnk . (.Pas de propriétaire.) -- C:\Windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
                                        O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\Microsoft Office Word 2007.lnk . (.Pas de propriétaire.) -- C:\Windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
                                        O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\Nero Burning ROM.lnk . (.Nero AG.) -- C:\Program Files\Nero\Nero8\Nero Burning Rom\nero.exe
                                        O4 - Global Startup: C:\Documents And Settings\Meg\Desktop\SmartProtector.lnk . (.SmartSoft.) -- C:\Program Files\Smart Protector Pro\SmartProtector-Pro.exe
                                        O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
                                        O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Mail\WinMail.exe
                                        O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
                                        O4 - Global Startup: C:\Users\Meg\Desktop\Adobe Photoshop CS3.lnk . (.Adobe Systems, Incorporated.) -- C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe
                                        O4 - Global Startup: C:\Users\Meg\Desktop\Media Player Classic.lnk . (.mpc-hc@Sourceforge.) -- C:\Program Files\mplayerc_homecinema_x86_v1.2.908.0\mplayerc.exe
                                        O4 - Global Startup: C:\Users\Meg\Desktop\Microsoft Office Outlook 2007.lnk . (.Pas de propriétaire.) -- C:\Windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
                                        O4 - Global Startup: C:\Users\Meg\Desktop\Microsoft Office Word 2007.lnk . (.Pas de propriétaire.) -- C:\Windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
                                        O4 - Global Startup: C:\Users\Meg\Desktop\Nero Burning ROM.lnk . (.Nero AG.) -- C:\Program Files\Nero\Nero8\Nero Burning Rom\nero.exe
                                        O4 - Global Startup: C:\Users\Meg\Desktop\SmartProtector.lnk . (.SmartSoft.) -- C:\Program Files\Smart Protector Pro\SmartProtector-Pro.exe
                                        O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
                                        O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk . (.Microsoft Corporation.) -- C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
                                        O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\NJStar Communicator.lnk . (.NJStar Software Corp..) -- C:\Program Files\NJStar Communicator\NJCOM32.exe
                                        O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - Clé orpheline
                                        O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - Clé orpheline
                                        O4 - Global Startup: C:\Users\Meg\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe

                                        ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
                                        O8 - Extra context menu item: Append to existing PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                        O8 - Extra context menu item: Convert link target to Adobe PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                        O8 - Extra context menu item: Convert link target to existing PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                        O8 - Extra context menu item: Convert selected links to Adobe PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                        O8 - Extra context menu item: Convert selected links to existing PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                        O8 - Extra context menu item: Convert selection to Adobe PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                        O8 - Extra context menu item: Convert selection to existing PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                        O8 - Extra context menu item: Convert to Adobe PDF . (.Adobe Systems Incorporated - Adobe PDF Toolbar for Internet Explorer.) -- C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                        O8 - Extra context menu item: Free YouTube to Mp3 Converter . (.Pas de propriétaire - Pas de description.) -- C:\Users\Meg\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm

                                        ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
                                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~1\MICROS~2\Office12\REFBARH.ICO

                                        ---\\ Winsock hijacker (Layered Service Provider) (O10)
                                        O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
                                        O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
                                        O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
                                        O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
                                        O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
                                        O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll

                                        ---\\ Objets ActiveX (Downloaded Program Files)(O16)
                                        O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} () - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

                                        ---\\ Modification Domaine/Adresses DNS (O17)
                                        O17 - HKLM\System\CCS\Services\Tcpip\..\{284122EE-762F-48C8-BA67-C70299E1EF89}: DhcpNameServer = 89.2.0.1 89.2.0.2
                                        O17 - HKLM\System\CS1\Services\Tcpip\..\{284122EE-762F-48C8-BA67-C70299E1EF89}: DhcpNameServer = 89.2.0.1 89.2.0.2
                                        O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2

                                        ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
                                        O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Contrôleur de site Web.) -- C:\Windows\system32\webcheck.dll

                                        ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
                                        O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\system32\browseui.dll

                                        ---\\ Liste des services NT non Microsoft et non désactivés (O23)
                                        O23 - Service: (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                                        O23 - Service: (Ati External Event Utility) . (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) - C:\Windows\system32\Ati2evxx.exe
                                        O23 - Service: (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                                        O23 - Service: (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
                                        O23 - Service: (TabletServiceWacom) . (.Wacom Technology, Corp. - Tablet Service for professional driver.) - C:\Windows\system32\Wacom_Tablet.exe
                                        O23 - Service: ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) . (.Cyberlink Corp. - FCL Driver.) - C:\Program Files\CyberLink\PowerDVD8\000.fcl

                                        ---\\ Enumération Active Desktop & MHTML Editor (O24)
                                        O24 - Default MHTML Editor: Last - .(.Pas de propriétaire - Pas de description.) - "C:\Program Files\Microsoft Office\Office12\WINWORD.exe (.not file.)

                                        ---\\ Tâches planifiées en automatique (O39)
                                        O39 - APT:Automatic Planified Task - C:\Windows\Tasks\CreateChoiceProcessTask.job

                                        ---\\ Composants installés (ActiveSetup Installed Components) (O40)
                                        O40 - ASIC: Windows Media Player 5.2 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Pas de propriétaire - Pas de description.) -- C:\Windows\INF\mswmp.inf
                                        O40 - ASIC: Microsoft Windows Mail 7 - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Pas de propriétaire - Pas de description.) -- "C:\Program Files\Windows Mail\WinMail.exe
                                        O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 10.1 r53.) -- C:\Windows\system32\Macromed\Flash\Flash10h.ocx

                                        ---\\ Pilotes lancés au démarrage (O41)
                                        O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
                                        O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
                                        O41 - Driver: (CSC) . (.Microsoft Corporation - Windows Client Side Caching Driver.) - C:\Windows\System32\drivers\csc.sys
                                        O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
                                        O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\System32\DRIVERS\i8042prt.sys
                                        O41 - Driver: (kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\System32\DRIVERS\kbdclass.sys
                                        O41 - Driver: (mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\System32\DRIVERS\mouclass.sys
                                        O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
                                        O41 - Driver: (netbt) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
                                        O41 - Driver: (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
                                        O41 - Driver: C:\Windows\system32\drivers\pacer.sys (PSched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
                                        O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\System32\DRIVERS\rasacd.sys
                                        O41 - Driver: (rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\System32\DRIVERS\rdbss.sys
                                        O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
                                        O41 - Driver: (RDPENCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
                                        O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\Windows\System32\DRIVERS\serial.sys
                                        O41 - Driver: C:\Windows\system32\tcpipcfg.dll (Smb) . (.Microsoft Corporation - SMB Transport driver.) - C:\Windows\System32\DRIVERS\smb.sys
                                        O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
                                        O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
                                        O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
                                        O41 - Driver: (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
                                        0
                                        1. ---\\ Logiciels installés (O42)
                                          O42 - Logiciel: AC3Filter (remove only) - (.Pas de propriétaire.) [HKLM] -- AC3Filter
                                          O42 - Logiciel: AHV content for Acrobat and Flash - (.Adobe Systems Incorporated.) [HKLM] -- {6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
                                          O42 - Logiciel: Add or Remove Adobe Creative Suite 3 Design Premium - (.Adobe Systems Incorporated.) [HKLM] -- Adobe_c14ac4070fd9614ffe63f4bb533db2c
                                          O42 - Logiciel: Adobe Anchor Service CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {90176341-0A8B-4CCC-A78D-F862228A6B95}
                                          O42 - Logiciel: Adobe Asset Services CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
                                          O42 - Logiciel: Adobe Bridge CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {9C9824D9-9000-4373-A6A5-D0E5D4831394}
                                          O42 - Logiciel: Adobe Bridge Start Meeting - (.Adobe Systems Incorporated.) [HKLM] -- {08B32819-6EEF-4057-AEDA-5AB681A36A23}
                                          O42 - Logiciel: Adobe BridgeTalk Plugin CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {B7F560B3-6EFF-4026-A982-843895A41149}
                                          O42 - Logiciel: Adobe CMaps - (.Adobe Systems Incorporated.) [HKLM] -- {A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
                                          O42 - Logiciel: Adobe Camera Raw 4.0 - (.Adobe Systems Incorporated.) [HKLM] -- {B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
                                          O42 - Logiciel: Adobe Color - Photoshop Specific - (.Adobe Systems Incorporated.) [HKLM] -- {A2D81E70-2A98-4A08-A628-94388B063C5E}
                                          O42 - Logiciel: Adobe Color Common Settings - (.Adobe Systems Incorporated.) [HKLM] -- {DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
                                          O42 - Logiciel: Adobe Color EU Extra Settings - (.Adobe Systems Incorporated.) [HKLM] -- {51846830-E7B2-4218-8968-B77F0FF475B8}
                                          O42 - Logiciel: Adobe Color JA Extra Settings - (.Adobe Systems Incorporated.) [HKLM] -- {DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
                                          O42 - Logiciel: Adobe Color NA Recommended Settings - (.Adobe Systems Incorporated.) [HKLM] -- {95655ED4-7CA5-46DF-907F-7144877A32E5}
                                          O42 - Logiciel: Adobe Creative Suite 3 Design Premium - (.Adobe Systems Incorporated.) [HKLM] -- {D1C18EDD-571A-4BDD-BE7B-1DD86027D7FF}
                                          O42 - Logiciel: Adobe Default Language CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
                                          O42 - Logiciel: Adobe Device Central CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
                                          O42 - Logiciel: Adobe ExtendScript Toolkit 2 - (.Adobe Systems Incorporated.) [HKLM] -- {C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
                                          O42 - Logiciel: Adobe Extension Manager CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {BE5F3842-8309-4754-92D5-83E02E6077A3}
                                          O42 - Logiciel: Adobe Flash CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {6B52140A-F189-4945-BFFC-DB3F00B8C589}
                                          O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
                                          O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems, Inc..) [HKLM] -- {ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
                                          O42 - Logiciel: Adobe Fonts All - (.Adobe Systems Incorporated.) [HKLM] -- {6ABE0BEE-D572-4FE8-B434-9E72A289431B}
                                          O42 - Logiciel: Adobe Help Viewer CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {04AF207D-9A77-465A-8B76-991F6AB66245}
                                          O42 - Logiciel: Adobe InDesign CS3 Icon Handler - (.Adobe Systems Incorporated.) [HKLM] -- {EA7B3CC4-366D-4CF6-8350-FD7A7034116E}
                                          O42 - Logiciel: Adobe Linguistics CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {54793AA1-5001-42F4-ABB6-C364617C6078}
                                          O42 - Logiciel: Adobe MotionPicture Color Files - (.Adobe Systems Incorporated.) [HKLM] -- {6B708481-748A-4EB4-97C1-CD386244FF77}
                                          O42 - Logiciel: Adobe PDF Library Files - (.Adobe Systems Incorporated.) [HKLM] -- {D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
                                          O42 - Logiciel: Adobe Photoshop CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {0046FA01-C5B9-4985-BACB-398DC480FC05}
                                          O42 - Logiciel: Adobe Reader 9.3.4 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A93000000001}
                                          O42 - Logiciel: Adobe SING CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {B671CBFD-4109-4D35-9252-3062D3CCB7B2}
                                          O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM] -- {09E2111C-16B1-4DDF-BF0D-F994C9A12350}
                                          O42 - Logiciel: Adobe Stock Photos CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {29E5EA97-5F74-4A57-B8B2-D4F169117183}
                                          O42 - Logiciel: Adobe Type Support - (.Adobe Systems Incorporated.) [HKLM] -- {8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
                                          O42 - Logiciel: Adobe Update Manager CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {E69AE897-9E0B-485C-8552-7841F48D42D8}
                                          O42 - Logiciel: Adobe Version Cue CS3 Client - (.Adobe Systems Incorporated.) [HKLM] -- {D0DFF92A-492E-4C40-B862-A74A173C25C5}
                                          O42 - Logiciel: Adobe WAS CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {C5BD220A-EFE8-48A5-B70E-9503D535FACE}
                                          O42 - Logiciel: Adobe WinSoft Linguistics Plugin - (.Adobe Systems Incorporated.) [HKLM] -- {184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
                                          O42 - Logiciel: Adobe XMP Panels CS3 - (.Adobe Systems Incorporated.) [HKLM] -- {802771A9-A856-4A41-ACF7-1450E523C923}
                                          O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {EE6097DD-05F4-4178-9719-D3170BF098E8}
                                          O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {308B6AEA-DE50-4666-996D-0FA461719D6B}
                                          O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                                          O42 - Logiciel: ArcSoft Panorama Maker 4 - (.ArcSoft.) [HKLM] -- {D45E8C45-B601-4A80-AFD8-E16338744DE1}
                                          O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM] -- {D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
                                          O42 - Logiciel: Audacity 1.2.6 - (.Pas de propriétaire.) [HKLM] -- Audacity_is1
                                          O42 - Logiciel: Browser Configuration Utility - (.DeviceVM Inc..) [HKLM] -- {E8AEA11B-E60A-455E-B008-E4E763604612}
                                          O42 - Logiciel: Canon ScanGear Starter - (.Pas de propriétaire.) [HKLM] -- {18A5DFF2-8A95-49F3-873F-743CB5549F3D}
                                          O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM] -- {D3B1C799-CB73-42DE-BA0F-2344793A095C}
                                          O42 - Logiciel: CopyTrans Suite désinstallation uniquement - (.Pas de propriétaire.) [HKLM] -- CopyTrans Suite
                                          O42 - Logiciel: CoreAVC Professional Edition (remove only) - (.Pas de propriétaire.) [HKLM] -- CoreAVC Professional Edition
                                          O42 - Logiciel: CyberLink PowerDVD 8 - (.CyberLink Corp..) [HKLM] -- InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}
                                          O42 - Logiciel: File Uploader - (.Nikon.) [HKLM] -- {237CD223-1B9D-47E8-A76C-E478B83CCEA2}
                                          O42 - Logiciel: Free Audio CD Burner version 1.4 - (.DVDVideoSoft Limited..) [HKLM] -- Free Audio CD Burner_is1
                                          O42 - Logiciel: Free Video to iPod Converter version 4.0 - (.DVDVideoSoft Limited..) [HKLM] -- Free Video to iPod Converter_is1
                                          O42 - Logiciel: Free YouTube Download 2.4 - (.DVDVideoSoft Limited..) [HKLM] -- Free YouTube Download_is1
                                          O42 - Logiciel: Free YouTube to MP3 Converter version 3.8 - (.DVDVideoSoft Limited..) [HKLM] -- Free YouTube to MP3 Converter_is1
                                          O42 - Logiciel: Free YouTube to iPhone Converter version 2.7 - (.DVDVideoSoft Limited..) [HKLM] -- Free YouTube to iPhone Converter_is1
                                          O42 - Logiciel: Google SketchUp 8 - (.Google, Inc..) [HKLM] -- {B700113B-24A8-4D4C-8484-0CC944F764C8}
                                          O42 - Logiciel: Haali Media Splitter - (.Pas de propriétaire.) [HKLM] -- HaaliMkx
                                          O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
                                          O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
                                          O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
                                          O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- {46ABBC54-1872-4AA3-95E2-F2C063A63F31}
                                          O42 - Logiciel: Java(TM) 6 Update 17 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216011FF}
                                          O42 - Logiciel: Les Sims 2 - (.Pas de propriétaire.) [HKLM] -- {6E7DD182-9FC6-4651-0095-2E666CC6AF35}
                                          O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                                          O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                                          O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
                                          O42 - Logiciel: Microsoft .NET Framework 3.5 Language Pack SP1 - fra - (.Microsoft Corporation.) [HKLM] -- {3E31821C-7917-367E-938E-E65FC413EA31}
                                          O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
                                          O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                                          O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
                                          O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                                          O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                          O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                          O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                          O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                          O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                          O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                          O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                                          O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}_PROPLUS_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                                          O42 - Logiciel: Microsoft Office Access MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Excel MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office InfoPath MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Outlook MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- PROPLUS
                                          O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Proof (German) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Proofing (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002C-040C-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}_PROPLUS_{14809F99-C601-4D4A-9391-F1E8FAA964C5}
                                          O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{A0516415-ED61-419A-981D-93596DA74165}
                                          O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                                          O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}
                                          O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}_PROPLUS_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                                          O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}
                                          O42 - Logiciel: Microsoft Office Publisher MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Office Word MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}
                                          O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118}
                                          O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {7299052b-02a4-4627-81f2-1818da5d550d}
                                          O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
                                          O42 - Logiciel: Microsoft Windows Application Compatibility Database - (.Pas de propriétaire.) [HKLM] -- {deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
                                          O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 Language Pack SP1 - fra
                                          O42 - Logiciel: NJStar Communicator - (.NJStar Software Corp..) [HKLM] -- NJStar Communicator
                                          O42 - Logiciel: Nero 8 - (.Nero AG.) [HKLM] -- {BE282C23-5484-47FF-B2C1-EBEA5C891036}
                                          O42 - Logiciel: Nikon Message Center - (.Nikon.) [HKLM] -- {D2FCC1AE-6311-47C5-8130-C6C66D77DD71}
                                          O42 - Logiciel: Nikon Transfer - (.Nikon.) [HKLM] -- {E9757890-7EC5-46C8-99AB-B00F07B6525C}
                                          O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM] -- {205C6BDD-7B73-42DE-8505-9A093F35A238}
                                          O42 - Logiciel: PC Connectivity Solution - (.Nokia.) [HKLM] -- {AC599724-5755-48C1-ABE7-ABB857652930}
                                          O42 - Logiciel: PDF Settings - (.Adobe Systems Incorporated.) [HKLM] -- {AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
                                          O42 - Logiciel: Package de pilotes Windows - Nokia pccsmcfd (10/12/2007 6.85.4.0) - (.Nokia.) [HKLM] -- 3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F
                                          O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {E7004147-2CCA-431C-AA05-2AB166B9785D}
                                          O42 - Logiciel: Realtek 8169 8168 8101E 8102E Ethernet Driver - (.Realtek.) [HKLM] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}
                                          O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
                                          O42 - Logiciel: SAMSUNG Mobile USB Modem 1.0 Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile USB Modem 1.0
                                          O42 - Logiciel: SAMSUNG Mobile USB Modem Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG Mobile USB Modem
                                          O42 - Logiciel: SAMSUNG SYMBIAN USB Download Driver - (.SAMSUNG Electronics CO,.LTD.) [HKLM] -- {D8CE69B0-9274-4b8c-BA49-0FF6A20A3C65}
                                          O42 - Logiciel: SAMSUNG USB Mobile Device Software - (.Pas de propriétaire.) [HKLM] -- SAMSUNG USB Mobile Device
                                          O42 - Logiciel: Samsung Mobile phone USB driver Software - (.Pas de propriétaire.) [HKLM] -- Samsung Mobile phone USB driver
                                          O42 - Logiciel: SamsungConnectivityCableDriver - (.Samsung.) [HKLM] -- {7E84FAC8-C518-40F9-9807-7455301D6D25}
                                          O42 - Logiciel: Screenshot Captor 2.44.01 - (.Pas de propriétaire.) [HKLM] -- ScreenshotCaptor_is1
                                          O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                                          O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB978380) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{667A88D1-0369-4070-A62A-70672D68A9BF}
                                          O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB978382) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6DE3DABF-0203-426B-B330-7287D1003E86}
                                          O42 - Logiciel: Security Update for Microsoft Office Outlook 2007 (KB972363) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{120BE9A0-9B09-4855-9E0C-7DEE45CB03C0}
                                          O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB957789) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{7559E742-FF9F-4FAE-B279-008ED296CB4D}
                                          O42 - Logiciel: Security Update for Microsoft Office Publisher 2007 (KB980470) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{34573F17-DADE-4D0D-835F-A54A1DE8AC1F}
                                          O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                                          O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}
                                          O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB969613) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
                                          O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                                          O42 - Logiciel: Tablette Wacom - (.Wacom Technology Corp..) [HKLM] -- Wacom Tablet Driver
                                          O42 - Logiciel: The Sims 2 University - (.Pas de propriétaire.) [HKLM] -- {8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}
                                          O42 - Logiciel: Uninstall 1.0.0.1 - (.Pas de propriétaire.) [HKLM] -- Uninstall_is1
                                          O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                                          O42 - Logiciel: Update for 2007 Microsoft Office System (KB981715) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{661B3F32-FFE4-4606-AE3A-DFA11DCC0D79}
                                          O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
                                          O42 - Logiciel: Update for Microsoft Office InfoPath 2007 (KB976416) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{432C5EE4-8096-4FF1-95E1-65219365DFF7}
                                          O42 - Logiciel: Update for Microsoft Office Word 2007 (KB974561) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
                                          O42 - Logiciel: Update for Outlook 2007 Junk Email Filter (kb981433) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5A6859A6-042D-4DF7-84E2-79F8DEFB5D48}
                                          O42 - Logiciel: VCRedistSetup - (.Nero AG.) [HKLM] -- {3921A67A-5AB1-4E48-9444-C71814CF3027}
                                          O42 - Logiciel: VLC media player 1.0.5 - (.VideoLAN Team.) [HKLM] -- VLC media player
                                          O42 - Logiciel: Veoh Video Compass - (.Veoh Networks, Inc..) [HKLM] -- Veoh Video Compass
                                          O42 - Logiciel: Viton cyrillic azerty v.2 - (.Luc Petr.) [HKLM] -- {9B17173C-B2CB-461F-8DF3-17D61E1941F4}
                                          O42 - Logiciel: WebTablet IE Plugin - (.Wacom Technology Corp..) [HKLM] -- Wacom WebTabletPlugin for IE
                                          O42 - Logiciel: WebTablet Netscape Plugin - (.Wacom Technology Corp..) [HKLM] -- Wacom WebTabletPlugin for Netscape
                                          O42 - Logiciel: WinRAR archiver - (.Pas de propriétaire.) [HKLM] -- WinRAR archiver
                                          O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                                          O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {ED00D08A-3C5F-488D-93A0-A04F21F23956}
                                          O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {770F1BEC-2871-4E70-B837-FB8525FFA3B1}
                                          O42 - Logiciel: avast! Free Antivirus - (.Alwil Software.) [HKLM] -- avast5
                                          O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {FAE36873-1941-4076-A9A5-48812B5EA0B7}
                                          O42 - Logiciel: neroxml - (.Nero AG.) [HKLM] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}

                                          ---\\ HKCU & HKLM Software Keys
                                          [HKCU\Software\AC3Filter]
                                          [HKCU\Software\ALWIL Software]
                                          [HKCU\Software\ATI Technologies Inc.]
                                          [HKCU\Software\ATI]
                                          [HKCU\Software\AVS4YOU]
                                          [HKCU\Software\Abvent]
                                          [HKCU\Software\Adobe]
                                          [HKCU\Software\Ahead]
                                          [HKCU\Software\AppDataLow\Software\Adobe]
                                          [HKCU\Software\AppDataLow\Software\Conduit]
                                          [HKCU\Software\AppDataLow\Software\Microsoft]
                                          [HKCU\Software\AppDataLow\Software\Monitored]
                                          [HKCU\Software\AppDataLow\Software\settings]
                                          [HKCU\Software\AppDataLow\Software]
                                          [HKCU\Software\AppDataLow]
                                          [HKCU\Software\Apple Computer, Inc.]
                                          [HKCU\Software\Apple Inc.]
                                          [HKCU\Software\ArcSoft]
                                          [HKCU\Software\Audacity]
                                          [HKCU\Software\Bobyte]
                                          [HKCU\Software\Bugsplat]
                                          [HKCU\Software\CDDB]
                                          [HKCU\Software\CORE]
                                          [HKCU\Software\Canon]
                                          [HKCU\Software\Classes]
                                          [HKCU\Software\Clients]
                                          [HKCU\Software\CoreAAC]
                                          [HKCU\Software\Cyberlink]
                                          [HKCU\Software\Cygnus Solutions]
                                          [HKCU\Software\DT Soft]
                                          [HKCU\Software\DVDVideoSoft]
                                          [HKCU\Software\Dance Kit]
                                          [HKCU\Software\Digital River]
                                          [HKCU\Software\DivXNetworks]
                                          [HKCU\Software\DownloadCenter]
                                          [HKCU\Software\Elaborate Bytes]
                                          [HKCU\Software\Freeware]
                                          [HKCU\Software\GNU]
                                          [HKCU\Software\Gabest]
                                          [HKCU\Software\Google]
                                          [HKCU\Software\H3O8CABBPI]
                                          [HKCU\Software\Haali]
                                          [HKCU\Software\IM Providers]
                                          [HKCU\Software\JP595IR86O]
                                          [HKCU\Software\JavaSoft]
                                          [HKCU\Software\KasperskyLab]
                                          [HKCU\Software\Lake]
                                          [HKCU\Software\Local AppWizard-Generated Applications]
                                          [HKCU\Software\Macromedia]
                                          [HKCU\Software\MagicDisc]
                                          [HKCU\Software\Magnet]
                                          [HKCU\Software\Malwarebytes' Anti-Malware]
                                          [HKCU\Software\Mozilla]
                                          [HKCU\Software\NJStar]
                                          [HKCU\Software\NeroDigital]
                                          [HKCU\Software\Nero]
                                          [HKCU\Software\Netscape]
                                          [HKCU\Software\Nikon]
                                          [HKCU\Software\ODBC]
                                          [HKCU\Software\Policies]
                                          [HKCU\Software\Pvm]
                                          [HKCU\Software\Realtek]
                                          [HKCU\Software\SETTEC]
                                          [HKCU\Software\SYSTEMAX Software Development]
                                          [HKCU\Software\Safer Networking Limited]
                                          [HKCU\Software\Samsung]
                                          [HKCU\Software\SecuROM]
                                          [HKCU\Software\Smart Soft]
                                          [HKCU\Software\Synthesia]
                                          [HKCU\Software\Sysinternals]
                                          [HKCU\Software\Trolltech]
                                          [HKCU\Software\VB and VBA Program Settings]
                                          [HKCU\Software\Veoh]
                                          [HKCU\Software\Wget]
                                          [HKCU\Software\WinRAR SFX]
                                          [HKCU\Software\WinRAR]
                                          [HKCU\Software\YahooPartnerToolbar]
                                          [HKLM\Software\ALWIL Software]
                                          [HKLM\Software\AMD]
                                          [HKLM\Software\ATI Technologies]
                                          [HKLM\Software\ATI]
                                          [HKLM\Software\AVS4YOU]
                                          [HKLM\Software\Adobe]
                                          [HKLM\Software\Ahead]
                                          [HKLM\Software\Apple Computer, Inc.]
                                          [HKLM\Software\Apple Inc.]
                                          [HKLM\Software\ArcSoft]
                                          [HKLM\Software\Audible]
                                          [HKLM\Software\AviSynth]
                                          [HKLM\Software\BrowserChoice]
                                          [HKLM\Software\C07ft5Y]
                                          [HKLM\Software\Canon]
                                          [HKLM\Software\Classes]
                                          [HKLM\Software\Clients]
                                          [HKLM\Software\CoreCodec]
                                          [HKLM\Software\CyberLink]
                                          [HKLM\Software\Cygnus Solutions]
                                          [HKLM\Software\DEVGURU]
                                          [HKLM\Software\DT Soft]
                                          [HKLM\Software\DVDVideoSoft]
                                          [HKLM\Software\Debug]
                                          [HKLM\Software\DeviceVM Inc.]
                                          [HKLM\Software\Distortion]
                                          [HKLM\Software\EA GAMES]
                                          [HKLM\Software\Electronic Arts]
                                          [HKLM\Software\GEAR Software]
                                          [HKLM\Software\GNU]
                                          [HKLM\Software\Gabest]
                                          [HKLM\Software\Google]
                                          [HKLM\Software\InstallShield]
                                          [HKLM\Software\Intel]
                                          [HKLM\Software\InterVideo]
                                          [HKLM\Software\JavaSoft]
                                          [HKLM\Software\JreMetrics]
                                          [HKLM\Software\Lake]
                                          [HKLM\Software\Licenses]
                                          [HKLM\Software\MAXSOFT-OCRON]
                                          [HKLM\Software\MCCI]
                                          [HKLM\Software\Macromedia]
                                          [HKLM\Software\Macrovision]
                                          [HKLM\Software\Malwarebytes' Anti-Malware]
                                          [HKLM\Software\MarkAny]
                                          [HKLM\Software\MozillaPlugins]
                                          [HKLM\Software\Mozilla]
                                          [HKLM\Software\NJStar]
                                          [HKLM\Software\NeroDigital]
                                          [HKLM\Software\Nero]
                                          [HKLM\Software\Nikon]
                                          [HKLM\Software\ODBC]
                                          [HKLM\Software\PC Connectivity Solution]
                                          [HKLM\Software\PCSuite]
                                          [HKLM\Software\Pegasys Inc.]
                                          [HKLM\Software\Policies]
                                          [HKLM\Software\RTLSetup]
                                          [HKLM\Software\Realtek Semiconductor Corp.]
                                          [HKLM\Software\Realtek]
                                          [HKLM\Software\RegisteredApplications]
                                          [HKLM\Software\SRS Labs]
                                          [HKLM\Software\Safer Networking Limited]
                                          [HKLM\Software\Samsung]
                                          [HKLM\Software\Sonic]
                                          [HKLM\Software\Swearware]
                                          [HKLM\Software\Synthesia]
                                          [HKLM\Software\TrendMicro]
                                          [HKLM\Software\VideoConverter]
                                          [HKLM\Software\VideoLAN]
                                          [HKLM\Software\Volatile]
                                          [HKLM\Software\WOW6432Node]
                                          [HKLM\Software\Wacom]
                                          [HKLM\Software\Waves Audio]
                                          [HKLM\Software\WinRAR]
                                          [HKLM\Software\mozilla.org]
                                          [HKLM\Software\vLite]
                                          0
                                          • 1
                                          • 2