Rougue "RegClen Pro"

Bonjour, Ma grand mère viens récemment de choper le rougue "RegClean Pro"
Pourriez vous nous en débarrasser au plusvite s-il vous plait (elle a Windows Vista ave seulement 542Mo de libre sur son DD)

Cordialement, Firefox 3



--
tic tac toe ie7 vs firefox qui gagne firefox bien sur

13 réponses

  1. Bonjour
    Essaye ceci

    Télécharge sur le bureau RogueKiller
    * Quitte tous les programmes en cours, c'est important
    * Sous Vista/Seven , clic droit -> lancer en tant qu'administrateur
    * Sinon lance simplement RogueKiller.exe
    * Lorsque demandé, tape 2 et valide
    * Un rapport à dû s'ouvrir (RKreport.txt se trouve également à côté de l'exécutable), poste
    le contenu
    * Si le programme a été bloqué, ne pas hésiter a essayer plusieurs fois. Si vraiment cela ne passe pas (ça peut arriver), le renommer en winlogon.exe
    1
    1. RogueKiller V5.3.4 [30/08/2011] par Tigzy
      contact sur https://www.luanagames.com/index.fr.html
      mail: tigzyRK<at>gmail<dot>com
      Remontees: https://www.luanagames.com/index.fr.html

      Systeme d'exploitation: Windows Vista (6.0.6001 Service Pack 1) 32 bits version
      Demarrage : Mode normal
      Utilisateur: henri [Droits d'admin]
      Mode: Suppression -- Date : 17/09/2011 15:43:09

      Processus malicieux: 0

      Entrees de registre: 4
      [HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
      [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
      [HJ] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> REPLACED (0)
      [HJ] HKCU\[...]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> REPLACED (0)

      Fichiers / Dossiers particuliers:

      Fichier HOSTS:
      127.0.0.1 localhost
      ::1 localhost

      Termine : << RKreport[1].txt >>
      RKreport[1].txt

      Voilace que cela m'affiche
      0
      1. Il faudrait si possible libérer un peu d'espace disque, car vu ce qu'il reste,
        Windows a probablement désactivé la restauration système, car il n'a plus
        assez de place pour créer des points de restaurations
        Essaye de voir ce qui pourrait être inutile

        On va scanner le système

        * Télécharge ZHPDiag (de Nicolas Coolman)
        http://www.premiumorange.com/zeb-help-process/zhpdiag.html

        Au cas où le premier lien ne marcherai pas, clique sur celui de dessous
        ftp://zebulon.fr/ZHPDiag2.exe

        * Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.
        * Surtout, n'oublie pas d'installer son icône sur le bureau
        * Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
        * Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
        Héberge le rapport ICI
        Note : Le rapport est sauvegardé dans C:\ZHP\ZHPDiag.txt
        0
        1. Le premier lien Ne marche pas
          Le second n'installe rien du tout :S ( j'ai vérifié dans le dossier programmes aussi )
          0
          1. Chez moi, les liens fonctionnent parfaitement
            0
            1. A ça y'est :)
              https://www.luanagames.com/index.fr.html
              tic tac toe ie7 vs firefox qui gagne firefox bien sur
              0
              1. Y'a plusieurs infections à nettoyer dont Navipromo que le programme Game Bar a installé
                et il y a des adwares puis Reglean Pro qui est encore présent, on va nettoyer tout ça

                Télécharge Ad-Remover sur ton bureau:
                http://www.teamxscript.org/adremoverTelechargement.html ( Lien officiel )
                https://www.androidworld.fr/ ( Miroir )

                /!\ Ferme toutes tes applications ouvertes. /!\

                Double clique sur le fichier que tu viens de télécharger, à l'écran qui apparait, clique sur Nettoyer.
                Laisse travailler l'outil.
                Poste le rapport qui s'affiche à l'écran quand l'analyse est terminée.
                Il est sauvegardé dans C:\Ad-Remover-CLEAN[1].txt
                0
            2. ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

              Mis à jour par TeamXscript le 12/04/11
              Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
              Site web: http://www.teamxscript.org

              C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 16:48:25 le 17/09/2011, Mode normal

              Microsoft® Windows Vista(TM) Édition Familiale Premium Service Pack 1 (X86)
              henri@PC-DE-C (Acer Aspire 7220)

              ============== ACTION(S) ==============

              Fichier supprimé: C:\Windows\system32\nvs2.inf
              Dossier supprimé: C:\Users\henri\AppData\LocalLow\alot
              Dossier supprimé: C:\Program Files\alot
              Dossier supprimé: C:\Program Files\GamesBar
              Dossier supprimé: C:\Users\henri\AppData\Roaming\OpenCandy
              Dossier supprimé: C:\Users\henri\AppData\Local\OpenCandy
              Fichier supprimé: C:\Users\henri\AppData\Local\efqdlefua_nav.dat
              Fichier supprimé: C:\Users\henri\AppData\Local\efqdlefua.dat
              Fichier supprimé: C:\Users\henri\AppData\Local\efqdlefua_navps.dat
              Fichier supprimé: C:\Users\henri\AppData\Local\efqdlefua_navup.dat

              (!) -- Fichiers temporaires supprimés.

              Clé supprimée: HKLM\Software\Classes\CLSID\{14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6}
              Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6}
              Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6}
              Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6}
              Clé supprimée: HKLM\Software\Classes\CLSID\{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7}
              Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7}
              Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7}
              Clé supprimée: HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\efqdlefua
              Clé supprimée: HKLM\Software\GamesBarSetup
              Clé supprimée: HKLM\Software\OpenCandy NSIS SDK
              Clé supprimée: HKCU\Software\Lanconfig
              Clé supprimée: HKCU\Software\AppDataLow\Software\alot
              Clé supprimée: HKLM\Software\Messenger Plus!\OpenCandy
              Clé supprimée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}
              Clé supprimée: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6795114A-1CC4-462b-99E6-2C7B0FA69CDC}
              Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\alotToolbar
              Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\alotToolbar
              Clé supprimée: HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\62119EF862C6B3A0D853419B87EB3E2F6C78640A
              Clé supprimée: HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7EE743314C844C7F445B8B1D7617612DF1FDD50F
              Clé supprimée: HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\E6A6A4A475FCE37F8B5AC2F1244DEB2BFCA5615A

              Valeur supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo jimddp
              Valeur supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo hpfanicgkffmccehnpkikogcffaepkfp
              Valeur supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo dgnckdmmolaijpbbakmplfhlfpdhglgc
              Valeur supprimée: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7}

              ============== SCAN ADDITIONNEL ==============

              **** Mozilla Firefox Version [4.0 (fr)] ****

              HKLM_MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1 (x)
              Searchplugins\bing.xml ( hxxp://www.bing.com/search)
              Components\browsercomps.dll (Mozilla Foundation)

              -- C:\Users\henri\AppData\Roaming\Mozilla\FireFox\Profiles\v9ebgoe6.default --
              Prefs.js - browser.startup.homepage_override.buildID, 20110318052756
              Prefs.js - browser.startup.homepage_override.mstone, rv:2.0

              ========================================

              **** Internet Explorer Version [8.0.6001.19088] ****

              HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
              HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
              HKCU_Main|Start Page - hxxp://fr.msn.com/
              HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
              HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
              HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              HKLM_Main|Start Page - hxxp://fr.msn.com/
              HKCU_ElevationPolicy\{47EB25E3-7A3A-4B31-A299-606AE2B8BC90} - C:\Windows\System32\Macromed\Flash\FlashUtil9e.exe (x)
              HKCU_ElevationPolicy\{F78BB3EA-1FC9-405C-8893-3EB6C3596D4E} - C:\Program Files\Java\jre1.6.0_07\bin\ssvagent.exe (x)
              HKLM_ElevationPolicy\{15B3FB63-66F4-4EFC-B717-BB283B85E79B} - D:\Programme\Reader\AcroBroker.exe (x)
              HKLM_ElevationPolicy\{358E6F10-DE8A-4602-8424-179CA217F8EE} - D:\Programme\Reader\AcroRd32Info.exe (x)
              HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files\Internet Explorer\iedw.exe (x)
              HKLM_ElevationPolicy\{8E1F80F4-953F-41E7-8460-E64AE5BE4ED3} - D:\Programme\Reader\AdobeCollabSync.exe (x)
              HKLM_ElevationPolicy\{9C6A861C-B233-4994-AFB1-C158EE4FC578} - D:\Programme\Reader\AcroRd32.exe (x)
              BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)

              ========================================

              C:\Program Files\Ad-Remover\Quarantine: 128 Fichier(s)
              C:\Program Files\Ad-Remover\Backup: 15 Fichier(s)

              C:\Ad-Report-CLEAN[1].txt - 17/09/2011 16:48:28 (5857 Octet(s))

              Fin à: 16:49:57, 17/09/2011

              ============== E.O.F ==============
              RegClean Pro est toujours la :(
              0
              1. Attends soit patient, c'est pas terminé
                Relance Ad Remover, et clique sur Désinstaller

                Ensuite

                Copie les lignes suivantes en gras ci dessous, c'est à dire
                que tu sélectionnes les lignes indiquées en gras avec ta souris, tu fait
                clic droit dessus>copier

                [MD5.5B0581382F07901504B89A40A7CA0FCB] [APT] [RegClean Pro] (.Systweak Inc.) -- C:\Program Files\RegClean Pro\RegCleanPro.exe
                [MD5.5B0581382F07901504B89A40A7CA0FCB] [APT] [RegClean Pro_DEFAULT] (.Systweak Inc.) -- C:\Program Files\RegClean Pro\RegCleanPro.exe
                [MD5.5B0581382F07901504B89A40A7CA0FCB] [APT] [RegClean Pro_UPDATES] (.Systweak Inc.) -- C:\Program Files\RegClean Pro\RegCleanPro.exe
                O39 - APT:Automatic Planified Task - C:\Windows\Tasks\RegClean Pro_DEFAULT.job
                O39 - APT:Automatic Planified Task - C:\Windows\Tasks\RegClean Pro_UPDATES.job
                O43 - CFD: 05/09/2011 - 09:48:12 - [13697252] ----D- C:\Program Files\RegClean Pro
                O43 - CFD: 11/11/2007 - 12:59:20 - [2368696] ----D- C:\Program Files\Common Files\Symantec Shared
                O53 - SMSR:HKLM\...\startupreg\efqdlefua [Key] . (...) -- c:\users\henri\appdata\local\efqdlefua.exe (.not file.)
                SS - | Auto 0 | (Planificateur LiveUpdate automatique) . (...) - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                SS - | Demand 10/12/2006 1174152 | (Symantec Core LC) . (.Symantec Corporation.) - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                [MD5.2CA8B5CD5D2EDF2C033DB34E7E09DC1D] [SPRF][18/03/2011] (.BabylonToolbar - Pas de description.) -- C:\Users\henri\AppData\Local\Temp\MyBabylonTB.exe [1334800]
                [MD5.2CA8B5CD5D2EDF2C033DB34E7E09DC1D] [SPRF][21/03/2011] (.BabylonToolbar - Pas de description.) -- C:\Users\henri\AppData\Local\Temp\MyBabylonTB[1].exe
                [MD5.A02AD427897C6B4D2D7A61EDFD81BA8F] [SPRF][02/05/2008] (...) -- C:\Users\henri\AppData\Local\sjtluerqt.exe [12837]


                * Lance ZHPFix, soit à partir d'un raccourci sur le bureau, soit à partir de
                ZHPDiag (avec Vista/Seven, clic droit dessus, et sur exécuter en
                tant qu'administrateur
                )
                Clique sur l'icône représentant la lettre H (« coller les lignes Helper »)
                - Les lignes se collent automatiquement dans ZHPFix, sinon colle les lignes
                - Clique sur le bouton « GO » pour lancer le nettoyage,
                - Copie/colle la totalité du rapport dans ta prochaine réponse
                Note: le rapport est sauvegardé dans C:\ZHP\ZHPFixReport.txt

                Redémarre ton PC

                Ensuite, poste moi un nouveau rapport ZHPDiag
                0
            3. Impossible de déinstaller AD-Remover
              "ERROR: UNINSTALLER_NOT_FOUND"
              Je le supprime manuellement???

              Rapport :
              Rapport de ZHPFix 1.12.3360 par Nicolas Coolman, Update du 29/08/2011
              Fichier d'export Registre :
              Run by henri at 17/09/2011 17:42:15
              Windows Vista Home Premium Edition, 32-bit Service Pack 1 (Build 6001)
              Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html

              ========== Processus mémoire ==========
              SUPPRIME Memory Process: C:\Program Files\RegClean Pro\RegCleanPro.exe
              SUPPRIME Memory Process: C:\Users\henri\AppData\Local\sjtluerqt.exe

              ========== Clé(s) du Registre ==========
              ABSENT Key: StartupReg: efqdlefua
              SUPPRIME Key: Service: Planificateur LiveUpdate automatique
              SUPPRIME Key: Service: Symantec Core LC

              ========== Dossier(s) ==========
              SUPPRIME Folder: C:\Program Files\RegClean Pro
              SUPPRIME Folder: C:\Program Files\Common Files\Symantec Shared

              ========== Fichier(s) ==========
              SUPPRIME File**: c:\program files\regclean pro\regcleanpro.exe
              ABSENT Folder/File: c:\program files\regclean pro\regcleanpro.exe
              ABSENT File: c:\windows\tasks\regclean pro_default.job
              ABSENT File: c:\windows\tasks\regclean pro_updates.job
              ABSENT File: c:\users\henri\appdata\local\efqdlefua.exe
              ABSENT File: c:\program files\symantec\liveupdate\aluschedulersvc.exe
              ABSENT File: c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe
              ABSENT Folder/File: c:\users\henri\appdata\local\temp\mybabylontb.exe
              ABSENT Folder/File: c:\users\henri\appdata\local\temp\mybabylontb
              SUPPRIME File: c:\users\henri\appdata\local\sjtluerqt.exe

              ========== Tache planifiée ==========
              SUPPRIME Task: RegClean Pro
              SUPPRIME Task: RegClean Pro_DEFAULT
              SUPPRIME Task: RegClean Pro_UPDATES

              ========== Récapitulatif ==========
              2 : Processus mémoire
              3 : Clé(s) du Registre
              2 : Dossier(s)
              10 : Fichier(s)
              3 : Tache planifiée

              End of the scan in 00mn 09s

              ========== Chemin de fichier rapport ==========
              C:\ZHP\ZHPFix[R1].txt - 17/09/2011 17:42:15 [1849]
              D'aprés ce que j'ai pu constater sur le bureau, ça a l'air d'être bon, tu confirme???
              0
              1. C'est pas parce que les symptômes disparaissent que le PC est complètement
                clean
                Il y a encore des restants à supprimer

                Tu vas faire un scan généraliste
                Télécharge MalwareBytes' anti-malware sur le bureau
                https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
                Double-clique sur l'icône Download_mbam-setup.exe
                pour lancer le processus d'installation
                Si la pare-feu demande l'autorisation de se connecter pour malwareBytes, accepte
                Il va se mettre à jour une fois faite
                Va dans l'onglet recherche
                Sélectionne exécuter un examen complet
                Clique sur rechercher
                Le scan démarre
                A la fin de l'analyse, le message s'affiche: L'examen s'est terminé normalement.
                Clique sur afficher les résultats pour afficher les objets trouvés
                Clique sur OK pour poursuivre
                Si des malwares ont été détectés, cliquer sur afficher les résultats
                Sélectionne tout (ou laisser coché)
                Clique sur tout supprimer
                MalwareBytes va détruire les fichiers et les clés de registre et en mettre une
                copie dans la quarantaine
                Malewarebytes va ouvrir le bloc-note et y copier le rapport
                Redémarre le PC
                Une fois redémarré, double-clique sur MalewareBytes
                Va dans l'onglet rapport/log
                Clique dessus pour l'afficher une fois affiché, cliquer sur édition
                en haut du bloc-note puis sur sélectionner tout
                Revient sur édition, puis sur copier et reviens
                sur le forum dans ta réponse
                Clic droit dans le cadre de la réponse et coller

                0
                1. Rapport de ZHPDiag v1.28.1346 par Nicolas Coolman, Update du 29/08/2011
                  Run by henri at 17/09/2011 17:57:11
                  Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html

                  ---\\ Web Browser
                  MSIE: Internet Explorer v8.0.6001.19088

                  ---\\ Windows Product Information
                  Windows Vista Home Premium Edition, 32-bit Service Pack 1 (Build 6001)
                  Windows Server License Manager Script : OK
                  ~ Vista, OEM_SLP channel
                  System Locked Preinstallation (OEM_SLP) : OK
                  Windows ID Activation : OK
                  ~ Windows Partial Key : 6CJ97
                  Windows License : OK
                  Windows Automatic Updates : OK

                  ---\\ System Information
                  ~ Processor: x86 Family 15 Model 76 Stepping 2, AuthenticAMD
                  ~ Operating System: 32 Bits
                  Boot mode: Normal (Normal boot)
                  Total RAM: 1790 MB (38% free)
                  System Restore: Désactivé (Disabled)
                  System drive C: has 1 GB (2%) free of 33 GB

                  ---\\ Logged in mode
                  ~ Computer Name: PC-DE-C
                  ~ User Name: henri
                  ~ All Users Names: LogMeInRemoteUser, henri, Administrateur,
                  ~ Unselected Option: O45,O61,O62,O65,O66,O82
                  Logged in as Administrator

                  ---\\ Environnement Variables
                  ~ System Unit : C:\
                  ~ %AppData% : C:\Users\henri\AppData\Roaming\
                  ~ %Desktop% : C:\Users\henri\Desktop\
                  ~ %Favorites% : C:\Users\henri\Favorites\
                  ~ %LocalAppData% : C:\Users\henri\AppData\Local\
                  ~ %StartMenu% : C:\Users\henri\AppData\Roaming\Microsoft\Windows\Start Menu\
                  ~ %Windir% : C:\Windows\
                  ~ %System% : C:\Windows\system32\

                  ---\\ DOS/Devices
                  C:\ Hard drive, Flash drive, Thumb drive (Free 1 Go of 33 Go)
                  D:\ Hard drive, Flash drive, Thumb drive (Free 32 Go of 32 Go)
                  E:\ CD-ROM drive (Not Inserted)
                  H:\ Hard drive, Flash drive, Thumb drive (Free 461 Go of 466 Go)

                  ---\\ Security Center & Tools Informations
                  [HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
                  [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK
                  [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
                  [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
                  [HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : OK
                  ~ Scan Security Center in 00mn 00s

                  ---\\ Recherche particulière de fichiers génériques
                  [MD5.4F554999D7D5F05DAAEBBA7B5BA1089D] - (.Microsoft Corporation - Explorateur Windows.) (.10/12/2008 - 07:29:41.) -- C:\Windows\Explorer.exe [2927104]
                  [MD5.4B555106290BD117334E9A08761C035A] - (....) (.02/11/2006 - 10:45:37.) -- C:\Windows\system32\rundll32.exe [44544]
                  [MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de démarrage de Windows.) (.24/06/2008 - 08:33:37.) -- C:\Windows\system32\Wininit.exe [96768]
                  [MD5.DE4685DE5130039FA63DA66C0F72F787] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.17/06/2011 - 07:08:58.) -- C:\Windows\system32\wininet.dll [916480]
                  [MD5.C2610B6BDBEFC053BBDAB4F1B965CB24] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.24/06/2008 - 08:33:37.) -- C:\Windows\system32\Winlogon.exe [314880]
                  [MD5.2D9C903DC76A66813D350A562DE40ED9] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.24/06/2008 - 08:41:30.) -- C:\Windows\system32\drivers\atapi.sys [21560]
                  [MD5.B4EFFE29EB4F15538FD8A9681108492D] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.24/06/2008 - 08:43:40.) -- C:\Windows\system32\drivers\ntfs.sys [1081912]
                  [MD5.95F5FF73B076576C41740F1A842B9B57] - (....) (.24/06/2008 - 08:34:10.) -- C:\Windows\system32\fr-FR\user32.dll.mui [20480]
                  ~ Scan Generic Processes in 00mn 00s

                  ---\\ Etat des fichiers cachés (Caché/Total)
                  ~ Mes images (My Pictures) : 0/6
                  ~ Mes musiques (My Musics) : 2/23
                  ~ Mes Videos (My Videos) : 1/2
                  ~ Mes Favoris (My Favorites) : 3/71
                  ~ Mes Documents (My Documents) : 1/20
                  ~ Mon Bureau (My Desktop) : 0/13
                  ~ Menu demarrer (Programs) : 6/24
                  ~ Scan Hidden Files in 00mn 00s

                  ---\\ Processus lancés
                  [MD5.EE4FB1BB6757675625699A32E0F80E20] - (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Windows\RtHDVCpl.exe [4468736] [PID.3692]
                  [MD5.4297C3FC97F9FD96CC5BDC471A045882] - (.Dritek System Inc. - Launch Manager.) -- C:\Program Files\Launch Manager\LManager.exe [752136] [PID.3972]
                  [MD5.B150D1BCB625600479EEBA51811E33CB] - (.Alps Electric Co., Ltd. - Alps Pointing-device Driver.) -- C:\Program Files\Apoint2K\Apoint.exe [159744] [PID.3980]
                  [MD5.4B555106290BD117334E9A08761C035A] - (...) -- C:\Windows\System32\rundll32.exe [44544] [PID.]
                  [MD5.2E5212A0BFB98FE0167C92C76C87AFE3] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [249064] [PID.4012]
                  [MD5.BAD6BEA0DE1F69C82BDB74378CE0C20A] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288] [PID.4028]
                  [MD5.9D5E8B45BD348DF0882C69EED0E83111] - (.Avira GmbH - Antivirus System Tray Tool.) -- D:\Programme\Avira\AntiVir Desktop\avgnt.exe [281768] [PID.4036]
                  [MD5.BF08674925F151BD4537B89A493E3E0C] - (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehtray.exe [125952] [PID.4080]
                  [MD5.0F4195B9B348DE5CF9B822F81704B20E] - (.Microsoft Corporation - Media Center Media Status Aggregator Servic.) -- C:\Windows\ehome\ehmsas.exe [37376] [PID.3628]
                  [MD5.7914370AAC5CDE8DCAE1C674A6C90229] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [669696] [PID.3164]
                  [MD5.5EF87457AB8A58694EBE35E55D093D04] - (.Realtek Semiconductor Corp. - Realtek HD Audio Data Rerouter.) -- C:\Users\henri\AppData\Local\Temp\RtkBtMnt.exe [208896] [PID.3952]
                  [MD5.F96EBC5A624349D81DCC7600A3C5DC43] - (.Microsoft Corporation - Console IME.) -- C:\Windows\system32\conime.exe [69120] [PID.3436]
                  [MD5.42370C1DE2B83844B253478DB8A907D5] - (.Alps Electric Co., Ltd. - ApMsgFwd.) -- C:\Program Files\Apoint2K\ApMsgFwd.exe [50736] [PID.2820]
                  [MD5.8D78BE3690DB07A2FD03D2A6B61E3DCD] - (.Alps Electric Co., Ltd. - Alps Pointing-device Driver for Windows NT/.) -- C:\Program Files\Apoint2K\Apntex.exe [49152] [PID.444]
                  [MD5.CF672C71844A3B407EB86042829BCE09] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 177.1.) -- C:\Windows\system32\nvvsvc.exe [203296] [PID.]
                  [MD5.0BA91E1358AD25236863039BB2609A2E] - (.Microsoft Corporation - Service de gestion des licences Microsoft.) -- C:\Windows\system32\SLsvc.exe [2623488] [PID.]
                  [MD5.A5BCBAF0477C4869B67E0195AEA4A9CD] - (.Avira GmbH - Antivirus Scheduler.) -- D:\Programme\Avira\AntiVir Desktop\sched.exe [136360] [PID.]
                  [MD5.3845B6555DE995F6C0C07AE2ABCC0532] - (.Pas de propriétaire - ALaunchSvc Image.) -- C:\Acer\ALaunch\ALaunchSvc.exe [50688] [PID.]
                  [MD5.3CCE4AFA4AACDB28E01A148394212186] - (.Avira GmbH - Antivirus On-Access Service.) -- D:\Programme\Avira\AntiVir Desktop\avguard.exe [269480] [PID.]
                  [MD5.FB5383BFD4DEC6792AAEF76C9343ECFF] - (.Acer Inc. - Acer eLock Management.) -- C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe [24576] [PID.]
                  [MD5.9316C26F089CF2CEA2BD1496AC9F38A4] - (.Acer Inc. - acer eNet Management Service.) -- C:\Acer\Empowering Technology\eNet\eNet Service.exe [135168] [PID.]
                  [MD5.793FF718477345CD5D232C50BED1E452] - (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440] [PID.]
                  [MD5.CDE000884FD7BAF0C1FDFE029B0891DE] - (.Avira GmbH - AntiVir shadow copy service.) -- D:\Programme\Avira\AntiVir Desktop\avshadow.exe [76968] [PID.]
                  [MD5.7CF1B716372B89568AE4C0FE769F5869] - (.Microsoft Corporation - Machine Debug Manager.) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872] [PID.]
                  [MD5.842684E0DF20A59E293DA1C6F0DFE261] - (...) -- C:\Acer\Mobility Center\MobilityService.exe [107008] [PID.]
                  [MD5.15A317674A08DF26BE65164D959E9203] - (.Conexant Systems, Inc. - Modem Audio Service.) -- C:\Windows\system32\DRIVERS\xaudio.exe [386560] [PID.]
                  [MD5.3D184410EF5EE017E186AC96181B3FF8] - (.Acer Inc. - eRecoveryService.) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [53248] [PID.]
                  [MD5.CF2584CDF90DA24D3044021AAAD5DBAB] - (.Pas de propriétaire - Service.) -- C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [24576] [PID.]
                  [MD5.EE80AC462A171DBF06EEB2058B5D3BC6] - (.acer - WMIServi Application.) -- C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [163840] [PID.]
                  ~ Scan Processes Running in 00mn 02s

                  ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
                  P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32.dll
                  P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
                  P2 - FPN: [HKLM] [@google.com/npPicasa2,version=2.0.0] - (...) -- C:\Program Files\Picasa2\npPicasa2.dll (.not file.)
                  P2 - FPN: [HKLM] [@google.com/npPicasa3,version=3.0.0] - (.Google, Inc. - Picasa plugin.) -- D:\Picasa\Picasa3\npPicasa3.dll
                  P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_24 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
                  P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.60531.0.) -- C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
                  P2 - FPN: [HKLM] [@microsoft.com/OfficeLive,version=1.3] - (.Microsoft Corp. - Office Live Update v1.3.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll
                  P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8117.0416] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
                  P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
                  P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
                  P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
                  P2 - FPN: [HKLM] [@videolan.org/vlc,version=1.1.7] - (.the VideoLAN Team - Version 1.1.7, copyright 1996-2011 The VideoLAN Team<br><a href="http:.) -- D:\Programme\VLC\npvlc.dll
                  P2 - FPN: [HKLM] [yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1] - (.Yahoo! Inc. - Yahoo! activeX Plug-in Bridge.) -- C:\Program Files\Yahoo!\common\npyaxmpb.dll
                  ~ Scan Firefox Browser in 00mn 00s

                  ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R0 - HKUS\S-1-5-21-3796123287-618471144-467302437-1003\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.microsoft.com/fr-fr/
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.microsoft.com/fr-fr/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
                  ~ Scan IE Browser in 00mn 00s

                  ---\\ Internet Explorer, Proxy Management (R5)
                  R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
                  R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
                  R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
                  R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
                  R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
                  ~ Scan Proxy management in 00mn 00s

                  ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
                  F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
                  F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
                  ~ Scan Keys in 00mn 00s

                  ---\\ Redirection du fichier Hosts (O1)
                  ~ Scan Hosts File in 00mn 00s

                  ---\\ Browser Helper Objects de navigateur (O2)
                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} . (.Yahoo! Inc. - Yahoo! Toolbar.) -- C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  ~ Scan BHO in 00mn 00s

                  ---\\ Internet Explorer Toolbars (O3)
                  O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} . (.Yahoo! Inc. - Yahoo! Toolbar.) -- C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  ~ Scan Toolbar in 00mn 00s

                  ---\\ Applications démarrées par registre & par dossier (O4)
                  O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Windows\RtHDVCpl.exe
                  O4 - HKLM\..\Run: [Acer Tour] Clé orpheline
                  O4 - HKLM\..\Run: [LManager] . (.Dritek System Inc. - Launch Manager.) -- C:\PROGRA~1\LAUNCH~1\LManager.exe
                  O4 - HKLM\..\Run: [Apoint] . (.Alps Electric Co., Ltd. - Alps Pointing-device Driver.) -- C:\Program Files\Apoint2K\Apoint.exe
                  O4 - HKLM\..\Run: [eRecoveryService] Clé orpheline
                  O4 - HKLM\..\Run: [NvCplDaemon] . (.NVIDIA Corporation - NVIDIA Display Properties Extension.) -- C:\Windows\system32\NvCpl.dll
                  O4 - HKLM\..\Run: [NvMediaCenter] . (.NVIDIA Corporation - NVIDIA Media Center Library.) -- C:\Windows\system32\NvMcTray.dll
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] D:\Programme\Reader\Reader_sl.exe (.not file.)
                  O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
                  O4 - HKLM\..\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- D:\Programme\Avira\AntiVir Desktop\avgnt.exe
                  O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
                  O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  O4 - HKCU\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] . (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] oobefldr.dll
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
                  O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] oobefldr.dll
                  O4 - HKUS\S-1-5-21-3796123287-618471144-467302437-1003\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
                  O4 - HKUS\S-1-5-21-3796123287-618471144-467302437-1003\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  O4 - HKUS\S-1-5-21-3796123287-618471144-467302437-1003\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
                  O4 - HKUS\S-1-5-21-3796123287-618471144-467302437-1003\..\Run: [WMPNSCFG] . (.Microsoft Corporation - Application de configuration du service Par.) -- C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  ~ Scan Application in 00mn 00s

                  ---\\ Autres liens utilisateurs (O4)
                  O4 - Global Startup: C:\Users\henri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
                  O4 - Global Startup: C:\Users\henri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Mail\WinMail.exe
                  O4 - Global Startup: C:\Users\henri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
                  O4 - Global Startup: C:\Users\henri\Desktop\AD-R.lnk . (...) -- C:\Program Files\Ad-Remover\main.exe
                  O4 - Global Startup: C:\Users\henri\Desktop\Chess.lnk . (...) -- C:\Program Files\Microsoft Games\Chess\Chess.exe (.not file.)
                  O4 - Global Startup: C:\Users\henri\Desktop\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
                  O4 - Global Startup: C:\Users\henri\Desktop\shutdown.exe.lnk . (.Microsoft Corporation.) -- C:\Windows\System32\shutdown.exe
                  O4 - Global Startup: C:\Users\henri\Desktop\Solitaire.lnk . (.Microsoft Corporation.) -- C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe
                  O4 - Global Startup: C:\Users\henri\Desktop\WordBiz.lnk . (...) -- D:\Programme\WordBiz\WordBiz.exe
                  O4 - Global Startup: C:\Users\henri\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
                  O4 - Global Startup: C:\Users\henri\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk . (.Google Inc..) -- D:\Programme\Picasa\Picasa3\Picasa3.exe
                  O4 - Global Startup: C:\Users\henri\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Solitaire.lnk . (.Microsoft Corporation.) -- C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe
                  O4 - Global Startup: C:\Users\henri\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
                  ~ Scan Global Startup in 00mn 00s

                  ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
                  O8 - Extra context menu item: Add to Google Photos Screensa&ver . (.Google Inc. - Google Photos Screensaver.) -- C:\Windows\system32\GPhotos.scr
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~2\Office12\EXCEL.exe
                  ~ Scan IE Menu Contextuel in 00mn 00s

                  ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
                  O9 - Extra button: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft Office OneNote Internet Explorer Add-in.) -- C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                  O9 - Extra button: &Envoyer à OneNote - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\PROGRA~1\MICROS~2\Office12\REFBARH.ICO
                  ~ Scan IE Extra Buttons in 00mn 00s

                  ---\\ Winsock hijacker (Layered Service Provider) (O10)
                  O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
                  O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
                  O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
                  O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
                  O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
                  O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
                  ~ Scan Winsock in 00mn 00s

                  ---\\ Objets ActiveX (Downloaded Program Files)(O16)
                  O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
                  O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} () - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                  ~ Scan Objets ActiveX in 00mn 00s

                  ---\\ Modification Domaine/Adresses DNS (O17)
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{5569A5D1-DE1F-47B6-806A-E3DB2F8BCF1B}: DhcpNameServer = 192.168.1.1
                  O17 - HKLM\System\CS1\Services\Tcpip\..\{5569A5D1-DE1F-47B6-806A-E3DB2F8BCF1B}: DhcpNameServer = 192.168.1.1
                  O17 - HKLM\System\CS3\Services\Tcpip\..\{5569A5D1-DE1F-47B6-806A-E3DB2F8BCF1B}: DhcpNameServer = 192.168.1.1
                  ~ Scan Domain in 00mn 00s

                  ---\\ Protocole additionnel (O18)
                  O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
                  O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                  O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll
                  O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                  O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                  O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                  O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                  O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
                  O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
                  O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                  O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                  O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
                  O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\system32\inetcomm.dll
                  O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                  O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
                  O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
                  O18 - Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
                  O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                  O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
                  O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll
                  O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
                  O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files\Windows Live\Mail\mailcomm.dll
                  O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
                  O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
                  O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
                  O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                  O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                  O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
                  ~ Scan Protocole Additionnel in 00mn 00s

                  ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
                  O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Contrôleur de site Web.) -- C:\Windows\System32\webcheck.dll
                  ~ Scan SSODL in 00mn 00s

                  ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
                  O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\system32\browseui.dll
                  ~ Scan STS/SSO in 00mn 00s

                  ---\\ Liste des services NT non Microsoft et non désactivés (O23)
                  O23 - Service: ALaunch Service (ALaunchService) . (.Pas de propriétaire - ALaunchSvc Image.) - C:\Acer\ALaunch\ALaunchSvc.exe
                  O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - D:\Programme\Avira\AntiVir Desktop\sched.exe
                  O23 - Service: Avira AntiVir Guard (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - D:\Programme\Avira\AntiVir Desktop\avguard.exe
                  O23 - Service: eLock Service (eLockService) . (.Acer Inc. - Acer eLock Management.) - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                  O23 - Service: eNet Service (eNet Service) . (.Acer Inc. - acer eNet Management Service.) - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                  O23 - Service: eRecovery Service (eRecoveryService) . (.Acer Inc. - eRecoveryService.) - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                  O23 - Service: eSettings Service (eSettingsService) . (.Pas de propriétaire - Service.) - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                  O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) . (.Hewlett-Packard Company - Pas de description.) - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: MobilityService (MobilityService) . (...) - C:\Acer\Mobility Center\MobilityService.exe
                  O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 177.1.) - C:\Windows\system32\nvvsvc.exe
                  O23 - Service: ePower Service (WMIService) . (.acer - WMIServi Application.) - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                  O23 - Service: XAudioService (XAudioService) . (.Conexant Systems, Inc. - Modem Audio Service.) - C:\Windows\system32\DRIVERS\xaudio.exe
                  ~ Scan Services in 00mn 00s

                  ---\\ Enumération Active Desktop & MHTML Editor (O24)
                  O24 - Default MHTML Editor: Last - .(...) - (.not file.)
                  ~ Scan Desktop Component in 00mn 00s

                  ---\\ Tâches planifiées en automatique (O39)
                  O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
                  O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
                  [MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
                  [MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
                  [MD5.00000000000000000000000000000000] [APT] [PMVService.exe_0012310868] (...) -- C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe (.not file.)
                  [MD5.7B43567B4C32AD7ADED537CD3B1342B9] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
                  ~ Scan Scheduled Task in 00mn 11s

                  ---\\ Pilotes lancés au démarrage (O41)
                  O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
                  O41 - Driver: (avipbb) . (.Avira GmbH - Avira Driver for Security Enhancement.) - C:\Windows\system32\DRIVERS\avipbb.sys
                  O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\DRIVERS\cdrom.sys
                  O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\system32\Drivers\dfsc.sys
                  O41 - Driver: (DritekPortIO) . (.Dritek System Inc. - General Port I/O.) - C:\PROGRA~1\LAUNCH~1\DPortIO.sys
                  O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\system32\DRIVERS\i8042prt.sys
                  O41 - Driver: (kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\system32\DRIVERS\kbdclass.sys
                  O41 - Driver: (kbdhid) . (.Microsoft Corporation - Pilote de filtre clavier HID.) - C:\Windows\system32\DRIVERS\kbdhid.sys
                  O41 - Driver: (mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\system32\DRIVERS\mouclass.sys
                  O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\system32\DRIVERS\netbios.sys
                  O41 - Driver: (netbt) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\system32\DRIVERS\netbt.sys
                  O41 - Driver: (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\system32\drivers\nsiproxy.sys
                  O41 - Driver: C:\Windows\system32\drivers\pacer.sys (PSched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\system32\DRIVERS\pacer.sys
                  O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\system32\DRIVERS\rasacd.sys
                  O41 - Driver: (rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\system32\DRIVERS\rdbss.sys
                  O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\DRIVERS\RDPCDD.sys
                  O41 - Driver: (RDPENCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\drivers\rdpencdd.sys
                  O41 - Driver: C:\Windows\system32\tcpipcfg.dll (Smb) . (.Microsoft Corporation - SMB Transport driver.) - C:\Windows\system32\DRIVERS\smb.sys
                  O41 - Driver: (ssmdrv) . (.Avira GmbH - AVIRA SnapShot Driver.) - C:\Windows\system32\DRIVERS\ssmdrv.sys
                  O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys
                  O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\system32\DRIVERS\termdd.sys
                  O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
                  O41 - Driver: (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\system32\DRIVERS\wanarp.sys
                  ~ Scan Drivers in 00mn 03s

                  ---\\ Logiciels installés (O42)
                  O42 - Logiciel: ALPS Touch Pad Driver - (.Alps Electric.) [HKLM] -- {9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}
                  O42 - Logiciel: Acer Crystal Eye webcam - (.Acer Crystal Eye webcam.) [HKLM] -- {DD1DED37-2486-4F56-8F89-56AA814003F5}
                  O42 - Logiciel: Acer Empowering Technology - (.Acer Inc..) [HKLM] -- {AB6097D9-D722-4987-BD9E-A076E2848EE2}
                  O42 - Logiciel: Acer GridVista - (.Pas de propriétaire.) [HKLM] -- GridVista
                  O42 - Logiciel: Acer Mobility Center Plug-In - (.Acer Inc..) [HKLM] -- {11316260-6666-467B-AC34-183FCB5D4335}
                  O42 - Logiciel: Acer ScreenSaver - (.Acer Inc..) [HKLM] -- {79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}
                  O42 - Logiciel: Acer Tour - (.Acer Inc..) [HKLM] -- {94389919-B0AA-4882-9BE8-9F0B004ECA35}
                  O42 - Logiciel: Acer eAudio Management - (.Pas de propriétaire.) [HKLM] -- {57265292-228A-41FA-9AEC-4620CBCC2739}
                  O42 - Logiciel: Acer eLock Management - (.Acer Inc..) [HKLM] -- {116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}
                  O42 - Logiciel: Acer eNet Management - (.Acer Inc..) [HKLM] -- {C06554A1-2C1E-4D20-B613-EE62C79927CC}
                  O42 - Logiciel: Acer ePower Management - (.Acer Inc..) [HKLM] -- {58E5844B-7CE2-413D-83D1-99294BF6C74F}
                  O42 - Logiciel: Acer ePresentation Management - (.Acer Inc..) [HKLM] -- {BF839132-BD43-4056-ACBF-4377F4A88E2A}
                  O42 - Logiciel: Acer eSettings Management - (.Acer Inc..) [HKLM] -- {CE65A9A0-9686-45C6-9098-3C9543A412F0}
                  O42 - Logiciel: Activation Assistant for the 2007 Microsoft Office suites - (.Microsoft Corporation.) [HKLM] -- Activation Assistant for the 2007 Microsoft Office suites
                  O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
                  O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
                  O42 - Logiciel: Animation Conforama - (.Pas de propriétaire.) [HKLM] -- Animation Conforama
                  O42 - Logiciel: Avira AntiVir Personal - Free Antivirus - (.Avira GmbH.) [HKLM] -- Avira AntiVir Desktop
                  O42 - Logiciel: Big Kahuna Reef 2 - (.Oberon Media.) [HKLM] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111310630}
                  O42 - Logiciel: Cake Mania - (.Oberon Media.) [HKLM] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}
                  O42 - Logiciel: Cheat Engine 6.0 - (.Dark Byte.) [HKLM] -- Cheat Engine 6.0_is1
                  O42 - Logiciel: Dynasty - (.Oberon Media.) [HKLM] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111473353}
                  O42 - Logiciel: Galapago - (.Oberon Media.) [HKLM] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}
                  O42 - Logiciel: HDAUDIO Soft Data Fax Modem with SmartCP - (.Pas de propriétaire.) [HKLM] -- CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118
                  O42 - Logiciel: HP Customer Participation Program 8.0 - (.HP.) [HKLM] -- HPExtendedCapabilities
                  O42 - Logiciel: HP Imaging Device Functions 8.0 - (.HP.) [HKLM] -- HP Imaging Device Functions
                  O42 - Logiciel: HP OCR Software 8.0 - (.HP.) [HKLM] -- HPOCR
                  O42 - Logiciel: HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B - (.HP.) [HKLM] -- {C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}
                  O42 - Logiciel: HP Solution Center 8.0 - (.HP.) [HKLM] -- HP Solution Center & Imaging Support Tools
                  O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
                  O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
                  O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
                  O42 - Logiciel: Launch Manager - (.Pas de propriétaire.) [HKLM] -- LManager
                  O42 - Logiciel: Messenger Plus! Live - (.Yuna Software.) [HKLM] -- Messenger Plus! Live
                  O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
                  O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}_HOMESTUDENTR_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}_PROPLUS_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-00A1-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                  O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                  O42 - Logiciel: Microsoft Office Home and Student 2007 - (.Microsoft Corporation.) [HKLM] -- HOMESTUDENTR
                  O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- PROPLUS
                  O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}_HOMESTUDENTR_{14809F99-C601-4D4A-9391-F1E8FAA964C5}
                  O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}_PROPLUS_{14809F99-C601-4D4A-9391-F1E8FAA964C5}
                  O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}
                  O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{A0516415-ED61-419A-981D-93596DA74165}
                  O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                  O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                  O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}
                  O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}
                  O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}_HOMESTUDENTR_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                  O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}_PROPLUS_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                  O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}
                  O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}
                  O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 Language Pack SP1 - fra
                  O42 - Logiciel: Module linguistique Microsoft .NET Framework 4 Client Profile FRA - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile FRA Language Pack
                  O42 - Logiciel: Mystery Case Files - Prime Suspects - (.Oberon Media.) [HKLM] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111271497}
                  O42 - Logiciel: Mystery Case Files Ravenhearst - (.Oberon Media.) [HKLM] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112179547}
                  O42 - Logiciel: NTI Backup NOW! 4.7 - (.NewTech Infosystems.) [HKLM] -- {67ADE9AF-5CD9-4089-8825-55DE4B366799}
                  O42 - Logiciel: NTI CD & DVD-Maker - (.NewTech Infosystems.) [HKLM] -- InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}
                  O42 - Logiciel: NVIDIA Drivers - (.NVIDIA Corporation.) [HKLM] -- NVIDIA Drivers
                  O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM] -- Picasa 3
                  O42 - Logiciel: PowerProducer - (.Pas de propriétaire.) [HKLM] -- {B7A0CE06-068E-11D6-97FD-0050BACBF861}
                  O42 - Logiciel: RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 - (.Pas de propriétaire.) [HKLM] -- {59F6A514-9813-47A3-948C-8A155460CC2A}
                  O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
                  O42 - Logiciel: RegClean Pro - (.Systweak Inc.) [HKLM] -- RegClean Pro_is1
                  O42 - Logiciel: Samsung Master - (.Samsung.) [HKLM] -- {AEC0CEBC-0FC7-4716-8222-1C4A742719B1}
                  O42 - Logiciel: Samsung USB Driver - (.Samsung Techwin.) [HKLM] -- {86D6A20D-3910-4441-A3E5-EB6977251C86}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288621) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5C497F0B-2061-4CC9-A61C-6B45B867354D}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288621) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{5C497F0B-2061-4CC9-A61C-6B45B867354D}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288931) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{CD769337-C8AC-46DB-A7DC-643E50089263}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288931) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CD769337-C8AC-46DB-A7DC-643E50089263}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2345043) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{536FB502-775F-4494-BACE-C02CC90B7A5B}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2345043) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{536FB502-775F-4494-BACE-C02CC90B7A5B}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2553074) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5729F1AE-5895-468F-9165-BAD161C9E982}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2553074) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{5729F1AE-5895-468F-9165-BAD161C9E982}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2553089) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{01D4CA59-7070-4420-9BCC-0EFA7C5D76BE}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2553089) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{01D4CA59-7070-4420-9BCC-0EFA7C5D76BE}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2553090) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{643C12A2-AF9A-4712-B8BE-3B7650AFE00A}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2553090) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{643C12A2-AF9A-4712-B8BE-3B7650AFE00A}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2584063) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{BF3F1CBD-B05C-4644-AE43-6EE0FCC227A4}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2584063) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{BF3F1CBD-B05C-4644-AE43-6EE0FCC227A4}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{7F207DCA-3399-40CB-A968-6E5991B1421A}
                  O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{7F207DCA-3399-40CB-A968-6E5991B1421A}
                  O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- KB931906
                  O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2416473
                  O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2446708
                  O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2478663
                  O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2518870
                  O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
                  O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5A4E43D5-858F-49BD-BA72-8F30E1793060}
                  O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB2553073) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{65EA4836-B5A3-4C1D-8883-0C35E471003A}
                  O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB2553073) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{65EA4836-B5A3-4C1D-8883-0C35E471003A}
                  O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB2510061) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5D930261-AA5B-48D1-931F-425C9D767490}
                  O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1109D0B3-EFA3-4553-AAED-4C3E9AD130E8}
                  O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
                  O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
                  O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB2535818) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{8588DD11-6BD7-4400-B55C-DD5AB74B43E1}
                  O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB2535818) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{8588DD11-6BD7-4400-B55C-DD5AB74B43E1}
                  O42 - Logiciel: Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{D75E6D0C-BADF-4F41-98B2-0C0F02C15062}
                  O42 - Logiciel: Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{D75E6D0C-BADF-4F41-98B2-0C0F02C15062}
                  O42 - Logiciel: Security Update for Microsoft Office Publisher 2007 (KB2284697) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3A4CDE54-2403-483D-8D9A-15E3264410DF}
                  O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                  O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                  O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB2344993) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
                  O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB2344993) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
                  O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}
                  O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}
                  O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                  O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                  O42 - Logiciel: Security Update for Module linguistique Microsoft .NET Framework 4 Client Profile FRA (KB2478663) - (.Microsoft Corporation.) [HKLM] -- {0F5B4A82-9DAF-3D13-8CB8-AEB25E4A614E}.KB2478663
                  O42 - Logiciel: Security Update for Module linguistique Microsoft .NET Framework 4 Client Profile FRA (KB2518870) - (.Microsoft Corporation.) [HKLM] -- {0F5B4A82-9DAF-3D13-8CB8-AEB25E4A614E}.KB2518870
                  O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                  O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                  O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
                  O42 - Logiciel: Update for Microsoft Office 2007 (KB2508958) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}
                  O42 - Logiciel: Update for Microsoft Office 2007 (KB2508958) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}
                  O42 - Logiciel: Update for Microsoft Office 2007 System (KB2539530) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B4CEEAE-AA88-490C-BCB2-AAC3421981A4}
                  O42 - Logiciel: Update for Microsoft Office 2007 System (KB2539530) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B4CEEAE-AA88-490C-BCB2-AAC3421981A4}
                  O42 - Logiciel: Update for Microsoft Office OneNote 2007 (KB980729) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{329050A9-EF80-40F9-B633-74508F54C1FF}
                  O42 - Logiciel: Update for Microsoft Office Outlook 2007 (KB2583910) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{BDC21583-5601-4B2B-88F3-7919F6DE8FB1}
                  O42 - Logiciel: Update for Outlook 2007 Junk Email Filter (KB2553110) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{05D27A23-8E87-46B5-9EAF-F5B4DE7CCCA0}
                  O42 - Logiciel: VLC media player 1.1.7 - (.VideoLAN.) [HKLM] -- VLC media player
                  O42 - Logiciel: WinRAR 4.00 bêta 4 (32-bit) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver
                  O42 - Logiciel: WordBiz version 1.8 - (.Internet Scrabble Club.) [HKLM] -- Internet Scrabble Club_is1
                  O42 - Logiciel: Xvid 1.1.2 final uninstall - (.Xvid team (Koepi).) [HKLM] -- Xvid_is1
                  O42 - Logiciel: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - (.Pas de propriétaire.) [HKLM] -- Yahoo! Companion
                  O42 - Logiciel: Zuma Deluxe - (.Oberon Media.) [HKLM] -- {82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}

                  ---\\ HKCU & HKLM Software Keys
                  [HKCU\Software\ALWIL Software]
                  [HKCU\Software\Ad-Remover]
                  [HKCU\Software\Adobe]
                  [HKCU\Software\Alps]
                  [HKCU\Software\AppDataLow\Software\Google]
                  [HKCU\Software\AppDataLow\Software\Microsoft]
                  [HKCU\Software\AppDataLow\Software\Yahoo]
                  [HKCU\Software\AppDataLow\Software]
                  [HKCU\Software\AppDataLow]
                  [HKCU\Software\Apple Computer, Inc.]
                  [HKCU\Software\Avira]
                  [HKCU\Software\Cheat Engine]
                  [HKCU\Software\Classes]
                  [HKCU\Software\Clients]
                  [HKCU\Software\Compal]
                  [HKCU\Software\Cyberlink]
                  [HKCU\Software\GNU]
                  [HKCU\Software\Google]
                  [HKCU\Software\Hewlett-Packard]
                  [HKCU\Software\Hot-TV]
                  [HKCU\Software\IGA]
                  [HKCU\Software\IM Providers]
                  [HKCU\Software\JEDI-VCL]
                  [HKCU\Software\JavaSoft]
                  [HKCU\Software\Licenses]
                  [HKCU\Software\Local AppWizard-Generated Applications]
                  [HKCU\Software\LogMeIn]
                  [HKCU\Software\Macromedia]
                  [HKCU\Software\MozillaPlugins]
                  [HKCU\Software\Mozilla]
                  [HKCU\Software\NVIDIA Corporation]
                  [HKCU\Software\Netscape]
                  [HKCU\Software\ODBC]
                  [HKCU\Software\Patchou]
                  [HKCU\Software\Policies]
                  [HKCU\Software\Realtek]
                  [HKCU\Software\RegisteredApplications]
                  [HKCU\Software\STOIK Imagic 30]
                  [HKCU\Software\Softonic]
                  [HKCU\Software\Stoik]
                  [HKCU\Software\Systweak]
                  [HKCU\Software\VB and VBA Program Settings]
                  [HKCU\Software\Vision Thing]
                  [HKCU\Software\WinRAR SFX]
                  [HKCU\Software\WinRAR]
                  [HKCU\Software\YahooPartnerToolbar]
                  [HKCU\Software\Yahoo]
                  [HKCU\Software\acer]
                  [HKCU\Software\epsxe]
                  [HKLM\Software\ALWIL Software]
                  [HKLM\Software\Acer Crystal Eye webcam]
                  [HKLM\Software\Acer Inc.]
                  [HKLM\Software\Adobe]
                  [HKLM\Software\Alps]
                  [HKLM\Software\Applied Networking]
                  [HKLM\Software\Avira]
                  [HKLM\Software\BS_StillCap]
                  [HKLM\Software\BisonCam]
                  [HKLM\Software\BrowserChoice]
                  [HKLM\Software\CXT]
                  [HKLM\Software\Classes]
                  [HKLM\Software\Clients]
                  [HKLM\Software\Compal]
                  [HKLM\Software\Conexant]
                  [HKLM\Software\CyberLink]
                  [HKLM\Software\DivXNetworks]
                  [HKLM\Software\GNU]
                  [HKLM\Software\Google]
                  [HKLM\Software\Hewlett-Packard]
                  [HKLM\Software\Hot-TV]
                  [HKLM\Software\InstallShield]
                  [HKLM\Software\Intel]
                  [HKLM\Software\JavaSoft]
                  [HKLM\Software\JreMetrics]
                  [HKLM\Software\Licenses]
                  [HKLM\Software\LightScribe]
                  [HKLM\Software\LogMeIn, Inc.]
                  [HKLM\Software\LogMeIn]
                  [HKLM\Software\Macromedia]
                  [HKLM\Software\Messenger Plus!]
                  [HKLM\Software\MimarSinan]
                  [HKLM\Software\MozillaPlugins]
                  [HKLM\Software\Mozilla]
                  [HKLM\Software\NVIDIA Corporation]
                  [HKLM\Software\NewTech Infosystems]
                  [HKLM\Software\ODBC]
                  [HKLM\Software\Oberon Media]
                  [HKLM\Software\Patchou]
                  [HKLM\Software\Policies]
                  [HKLM\Software\Preclick]
                  [HKLM\Software\Realtek Semiconductor Corp.]
                  [HKLM\Software\Realtek]
                  [HKLM\Software\Reflexive Entertainment]
                  [HKLM\Software\RegisteredApplications]
                  [HKLM\Software\SRS Labs]
                  [HKLM\Software\Samsung Techwin]
                  [HKLM\Software\SamsungMaster]
                  [HKLM\Software\Samsung]
                  [HKLM\Software\Sonic]
                  [HKLM\Software\SymNRT]
                  [HKLM\Software\Symantec]
                  [HKLM\Software\Systweak]
                  [HKLM\Software\VideoLAN]
                  [HKLM\Software\WinRAR]
                  [HKLM\Software\Windows]
                  [HKLM\Software\X-AVCSD]
                  [HKLM\Software\Yahoo]
                  [HKLM\Software\acer]
                  [HKLM\Software\mozilla.org]
                  [HKLM\Software\muvee Technologies]
                  [HKLM\Software\nSplitter]
                  ~ Scan Softwares in 00mn 01s

                  ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
                  O43 - CFD: 11/11/2010 - 12:36:54 - [286632138] ----D- C:\Program Files\Acer GameZone
                  O43 - CFD: 01/01/2007 - 01:30:50 - [1360873] ----D- C:\Program Files\Acer Inc
                  O43 - CFD: 10/12/2006 - 15:12:56 - [12683094] ----D- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
                  O43 - CFD: 17/09/2011 - 16:48:16 - [116031425] ----D- C:\Program Files\Ad-Remover
                  O43 - CFD: 01/01/2007 - 01:29:10 - [11413487] ----D- C:\Program Files\Apoint2K
                  O43 - CFD: 18/03/2011 - 11:46:06 - [2221118] ----D- C:\Program Files\Apple Software Update
                  O43 - CFD: 17/09/2011 - 17:42:16 - [868394055] ----D- C:\Program Files\Common Files
                  O43 - CFD: 10/12/2006 - 14:25:58 - [741376] ----D- C:\Program Files\CONEXANT
                  O43 - CFD: 10/12/2006 - 14:47:00 - [200665197] ----D- C:\Program Files\CyberLink
                  O43 - CFD: 09/10/2007 - 20:32:50 - [0] -SH-D- C:\Program Files\Fichiers communs
                  O43 - CFD: 17/09/2011 - 17:52:52 - [92519443] ----D- C:\Program Files\Google
                  O43 - CFD: 25/12/2007 - 15:29:40 - [0] ----D- C:\Program Files\Hewlett-Packard
                  O43 - CFD: 25/12/2007 - 15:32:14 - [251895632] ----D- C:\Program Files\HP
                  O43 - CFD: 13/03/2010 - 23:35:42 - [65425866] --H-D- C:\Program Files\InstallShield Installation Information
                  O43 - CFD: 18/06/2011 - 12:00:52 - [5832640] ----D- C:\Program Files\Internet Explorer
                  O43 - CFD: 18/03/201
                  0
                  1. Malwarebytes' Anti-Malware 1.51.2.1300
                    www.malwarebytes.org

                    Version de la base de données: 7734

                    Windows 6.0.6001 Service Pack 1
                    Internet Explorer 8.0.6001.19088

                    17/09/2011 19:06:14
                    mbam-log-2011-09-17 (19-06-14).txt

                    Type d'examen: Examen complet (C:\|D:\|)
                    Elément(s) analysé(s): 329161
                    Temps écoulé: 54 minute(s), 46 seconde(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 0
                    Valeur(s) du Registre infectée(s): 0
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 0

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Valeur(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s):
                    (Aucun élément nuisible détecté)
                    Rien :)
                    C'est bon??? J'aimerais bien ne pas sauter mon repas du soir :D
                    0
                    1. On va nettoyer tous les restes

                      Copie les lignes suivantes en gras ci dessous, c'est à dire
                      que tu sélectionnes les lignes indiquées en gras avec ta souris, tu fait
                      clic droit dessus>copier

                      O4 - HKLM\..\Run: [Acer Tour] Clé orpheline => Orphean Key not necessary
                      O4 - HKLM\..\Run: [eRecoveryService] Clé orpheline => Orphean Key not necessary
                      O43 - CFD: 18/07/2011 - 10:34:06 - [0] ----D- C:\Users\henri\AppData\Local\{3D354150-9DA4-434B-BDBA-2F2FCF7616B4} => Empty Folder not necessary
                      O44 - LFC:[MD5.26AC3866AFCF0D2A1AE47C4BBFF03B65] - 17/09/2011 - 15:49:58 ---A- . (...) -- C:\Ad-Report-CLEAN[1].txt [5996]
                      [HKCU\Software\Hot-TV] => Hot-TV
                      [HKLM\Software\BS_StillCap]
                      [HKLM\Software\Hot-TV] => Hot-TV
                      O43 - CFD: 11/05/2008 - 17:04:38 - [3007] ----D- C:\Users\henri\AppData\Roaming\Hamachi => Hamachi PeerToPeer
                      OPT:O4 - HKLM\..\Run: [LManager] . (.Dritek System Inc. - Launch Manager.) -- C:\PROGRA~1\LAUNCH~1\LManager.exe
                      OPT:O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] D:\Programme\Reader\Reader_sl.exe (.not file.)
                      OPT:O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] oobefldr.dll
                      OPT:O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] oobefldr.dll
                      [HKLM\Software\BrowserChoice]
                      [HKLM\Software\Symantec]
                      [HKLM\Software\Systweak]
                      [HKCU\Software\Systweak]
                      EmptyTemp
                      EmptyFlash


                      * Lance ZHPFix, soit à partir d'un raccourci sur le bureau, soit à partir de
                      ZHPDiag (avec Vista/Seven, clic droit dessus, et sur exécuter en
                      tant qu'administrateur
                      )
                      Clique sur l'icône représentant la lettre H (« coller les lignes Helper »)
                      - Les lignes se collent automatiquement dans ZHPFix, sinon colle les lignes
                      - Clique sur le bouton « GO » pour lancer le nettoyage,
                      - Copie/colle la totalité du rapport dans ta prochaine réponse
                      Note: le rapport est sauvegardé dans C:\ZHP\ZHPFixReport.txt

                      Redémarre ton PC

                      Ensuite, poste moi un nouveau rapport ZHPDiag
                      0