Se connecter / S'enregistrer
Votre question

Besoin d'aide pour remettre un PC "au carré"

Tags :
  • Sécurité
Dernière réponse : dans Sécurité et virus
28 Février 2009 18:48:56

Bonjour,

j'ai été sauvé il a qeulques temps sur ce forum.

Me voilà en vacances chez mes parents, qui dipsoe d'un PC à mon sens vérolé...

Quelqu'un peut-il m'indiquer comment le remettre "au carré"?

D'avance merci !

Autres pages sur : besoin aide remettre carre

a c 267 8 Sécurité
28 Février 2009 19:02:35

Salut,

Nous allons regarder cela :

  • Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
  • Double-clique sur RSIT.exe afin de lancer le programme.
  • Clique sur Continue à l'écran Disclaimer.
  • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
  • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

    Note : les rapports sont sauvegardés dans le dossier C:\rsit\.
    m
    0
    l
    1 Mars 2009 15:28:21

    Salut Destrio 5 !

    voilà les fichiers texte :

    log.txt :
    Logfile of random's system information tool 1.05 (written by random/random)
    Run by Patrick at 2009-03-01 15:22:21
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 17 GB (44%) free of 38 GB
    Total RAM: 255 MB (13% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:24:23, on 01/03/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxWatch.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\USBIcon.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
    C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
    C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\documents and settings\patrick\local settings\application data\mqyyu.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
    C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxMediaDB.exe
    C:\PROGRA~1\Wanadoo\ComComp.exe
    C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe
    C:\PROGRA~1\Wanadoo\Watch.exe
    C:\Program Files\Logitech\QuickCam10\COCIManager.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Patrick\Bureau\reponse pc au carré\RSIT.exe
    C:\Documents and Settings\Patrick\Mes documents\Eric\Patrick.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar BETA - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: (no name) - {03A2D7B5-7F29-C057-69BA-28A6D6BFD1C8} - (no file)
    O2 - BHO: (no name) - {063E9396-D103-146C-6233-44983B844B4E} - (no file)
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {16C8ED8F-9FBB-BE03-83E5-EF1C71227B4C} - (no file)
    O2 - BHO: (no name) - {1B05716B-5FEA-54F5-0792-D4CE74369E8C} - (no file)
    O2 - BHO: (no name) - {213C3374-2B1F-7A96-5E35-570933B9E400} - (no file)
    O2 - BHO: (no name) - {26ED9CDF-2406-B407-B126-1D1BFA0A9292} - (no file)
    O2 - BHO: (no name) - {28508A5E-910A-809D-3A15-B9AA1A3A479C} - (no file)
    O2 - BHO: (no name) - {28A5E86A-BEB3-2A6B-44A8-08239C13BA8E} - (no file)
    O2 - BHO: (no name) - {292B04EC-6483-FC6A-77F9-29A441F0ED52} - (no file)
    O2 - BHO: (no name) - {367AB86B-4560-ABE0-DA70-7E3A543F553D} - (no file)
    O2 - BHO: (no name) - {433C7071-2FBD-32B1-026E-7B1AF33C122A} - (no file)
    O2 - BHO: (no name) - {482ED513-8F9F-5049-FF7A-8FB035464E5F} - (no file)
    O2 - BHO: (no name) - {4AA55173-B7E5-2D82-CB60-CF53B9F7341B} - (no file)
    O2 - BHO: (no name) - {5022D84C-7E63-46D2-7871-DE7A933DED9A} - (no file)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {55E6CF7B-F013-B32D-B116-5147DD5BB2CC} - (no file)
    O2 - BHO: (no name) - {57B4D25A-EE68-B64A-2938-76F3DE0A7059} - (no file)
    O2 - BHO: (no name) - {588BC16B-2124-BE3A-2619-785389967943} - (no file)
    O2 - BHO: (no name) - {588DFBFB-53C8-6E13-2FC6-8BE47B26484A} - (no file)
    O2 - BHO: (no name) - {5AC5C3B9-9CEC-BC17-DFFB-3F33F50B8236} - (no file)
    O2 - BHO: (no name) - {6C7FF605-A242-47BA-6F53-DF6E15E38036} - (no file)
    O2 - BHO: (no name) - {767C3BCA-1931-C2D3-5152-1EAC589AADF7} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {80139715-66E1-6FA3-B786-BA675AA08141} - (no file)
    O2 - BHO: (no name) - {85350E27-DDF3-4D24-ABE1-57F9792608C9} - (no file)
    O2 - BHO: (no name) - {8A235E4F-CBA3-E0AF-678D-29D9ABA51389} - (no file)
    O2 - BHO: (no name) - {8F990BB6-92DA-5618-847A-5DD4057B1ECE} - (no file)
    O2 - BHO: (no name) - {9286760E-4D31-7E63-1FA6-40EFEFFA75A2} - (no file)
    O2 - BHO: (no name) - {972C70DC-3F58-38DC-719C-265704EEF8A0} - (no file)
    O2 - BHO: (no name) - {9D9CB61B-156B-3C2C-B9AB-BCB95AA0D47C} - (no file)
    O2 - BHO: (no name) - {9DE1545A-6CDE-C52E-C2EE-15ABB18D6F1A} - (no file)
    O2 - BHO: (no name) - {AA30113B-75AD-4CC2-907F-30AA0D758A2F} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: (no name) - {BA684D9D-88F0-4E2E-9B28-CA547ADE9EE3} - (no file)
    O2 - BHO: (no name) - {BAEA961E-A27E-4D7B-55F3-039B88D04CC3} - (no file)
    O2 - BHO: (no name) - {CA0F8F73-786A-51FF-066A-6822CAAE4F95} - (no file)
    O2 - BHO: (no name) - {CD1DA3EE-42C1-88F4-6A75-72D4A81AE705} - (no file)
    O2 - BHO: (no name) - {DFEF27C0-5F32-6983-6737-5F21C8EF035D} - (no file)
    O2 - BHO: (no name) - {E1855C39-8820-BABA-C94F-7C3D2AD1C652} - (no file)
    O2 - BHO: (no name) - {EDCBB3FD-788F-D69A-C205-FAE58398A2D6} - (no file)
    O2 - BHO: (no name) - {F3229D57-F62B-1F6E-54F4-EAF76321F1C8} - (no file)
    O2 - BHO: (no name) - {F322AB0B-621C-11A3-B1AE-7A7FC2B40350} - (no file)
    O2 - BHO: (no name) - {FA30FBE1-2D6A-60CB-19A0-CC0872CC2F67} - (no file)
    O2 - BHO: (no name) - {FA6BD27F-288F-002A-F4A9-ABCF232371D9} - (no file)
    O3 - Toolbar: Yahoo! Toolbar BETA - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
    O4 - HKLM\..\Run: [MCI USB Icon] C:\WINDOWS\system32\USBIcon.exe
    O4 - HKLM\..\Run: [winjb.exe] C:\WINDOWS\system32\winjb.exe
    O4 - HKLM\..\Run: [nter32.exe] C:\WINDOWS\system32\nter32.exe
    O4 - HKLM\..\Run: [ipws32.exe] C:\WINDOWS\system32\ipws32.exe
    O4 - HKLM\..\Run: [applu32.exe] C:\WINDOWS\system32\applu32.exe
    O4 - HKLM\..\Run: [d3vm32.exe] C:\WINDOWS\system32\d3vm32.exe
    O4 - HKLM\..\Run: [msqd.exe] C:\WINDOWS\system32\msqd.exe
    O4 - HKLM\..\Run: [javawq.exe] C:\WINDOWS\system32\javawq.exe
    O4 - HKLM\..\Run: [ieug.exe] C:\WINDOWS\system32\ieug.exe
    O4 - HKLM\..\Run: [winnk32.exe] C:\WINDOWS\system32\winnk32.exe
    O4 - HKLM\..\Run: [ntzz32.exe] C:\WINDOWS\system32\ntzz32.exe
    O4 - HKLM\..\Run: [msoc32.exe] C:\WINDOWS\system32\msoc32.exe
    O4 - HKLM\..\Run: [apizk.exe] C:\WINDOWS\system32\apizk.exe
    O4 - HKLM\..\Run: [wintu32.exe] C:\WINDOWS\system32\wintu32.exe
    O4 - HKLM\..\Run: [ipkv.exe] C:\WINDOWS\system32\ipkv.exe
    O4 - HKLM\..\Run: [netxb.exe] C:\WINDOWS\system32\netxb.exe
    O4 - HKLM\..\Run: [sysjs.exe] C:\WINDOWS\sysjs.exe
    O4 - HKLM\..\Run: [ieex.exe] C:\WINDOWS\ieex.exe
    O4 - HKLM\..\Run: [syslt.exe] C:\WINDOWS\system32\syslt.exe
    O4 - HKLM\..\Run: [ntyk32.exe] C:\WINDOWS\system32\ntyk32.exe
    O4 - HKLM\..\Run: [ieos.exe] C:\WINDOWS\ieos.exe
    O4 - HKLM\..\Run: [iefa32.exe] C:\WINDOWS\system32\iefa32.exe
    O4 - HKLM\..\Run: [ntct32.exe] C:\WINDOWS\system32\ntct32.exe
    O4 - HKLM\..\Run: [javadt.exe] C:\WINDOWS\system32\javadt.exe
    O4 - HKLM\..\Run: [sysdr.exe] C:\WINDOWS\system32\sysdr.exe
    O4 - HKLM\..\Run: [sdkao32.exe] C:\WINDOWS\system32\sdkao32.exe
    O4 - HKLM\..\Run: [netxe32.exe] C:\WINDOWS\system32\netxe32.exe
    O4 - HKLM\..\Run: [javayb.exe] C:\WINDOWS\system32\javayb.exe
    O4 - HKLM\..\Run: [d3br.exe] C:\WINDOWS\system32\d3br.exe
    O4 - HKLM\..\Run: [d3di.exe] C:\WINDOWS\system32\d3di.exe
    O4 - HKLM\..\Run: [addwz32.exe] C:\WINDOWS\system32\addwz32.exe
    O4 - HKLM\..\Run: [javaod.exe] C:\WINDOWS\system32\javaod.exe
    O4 - HKLM\..\Run: [addmc.exe] C:\WINDOWS\system32\addmc.exe
    O4 - HKLM\..\Run: [iett32.exe] C:\WINDOWS\system32\iett32.exe
    O4 - HKLM\..\Run: [d3gg32.exe] C:\WINDOWS\system32\d3gg32.exe
    O4 - HKLM\..\Run: [appyt32.exe] C:\WINDOWS\system32\appyt32.exe
    O4 - HKLM\..\Run: [atlbo.exe] C:\WINDOWS\system32\atlbo.exe
    O4 - HKLM\..\Run: [atlqu.exe] C:\WINDOWS\system32\atlqu.exe
    O4 - HKLM\..\Run: [winxc.exe] C:\WINDOWS\system32\winxc.exe
    O4 - HKLM\..\Run: [netcq32.exe] C:\WINDOWS\system32\netcq32.exe
    O4 - HKLM\..\Run: [ntik32.exe] C:\WINDOWS\system32\ntik32.exe
    O4 - HKLM\..\Run: [atlen.exe] C:\WINDOWS\system32\atlen.exe
    O4 - HKLM\..\Run: [mfcrd.exe] C:\WINDOWS\system32\mfcrd.exe
    O4 - HKLM\..\Run: [winah.exe] C:\WINDOWS\system32\winah.exe
    O4 - HKLM\..\Run: [msxd.exe] C:\WINDOWS\system32\msxd.exe
    O4 - HKLM\..\Run: [syset.exe] C:\WINDOWS\syset.exe
    O4 - HKLM\..\Run: [sysxw.exe] C:\WINDOWS\sysxw.exe
    O4 - HKLM\..\Run: [sdkzg32.exe] C:\WINDOWS\sdkzg32.exe
    O4 - HKLM\..\Run: [mfcjl.exe] C:\WINDOWS\system32\mfcjl.exe
    O4 - HKLM\..\Run: [mfcpt.exe] C:\WINDOWS\system32\mfcpt.exe
    O4 - HKLM\..\Run: [d3al32.exe] C:\WINDOWS\system32\d3al32.exe
    O4 - HKLM\..\Run: [sysqd32.exe] C:\WINDOWS\system32\sysqd32.exe
    O4 - HKLM\..\Run: [d3bo.exe] C:\WINDOWS\system32\d3bo.exe
    O4 - HKLM\..\Run: [javaea.exe] C:\WINDOWS\system32\javaea.exe
    O4 - HKLM\..\Run: [ntix32.exe] C:\WINDOWS\system32\ntix32.exe
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\fichie~1\instal~1\update~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
    O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [amhjrte] c:\documents and settings\patrick\local settings\application data\amhjrte.exe amhjrte
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [mqyyu] "c:\documents and settings\patrick\local settings\application data\mqyyu.exe" mqyyu
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
    O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod3\v4\yhexbmes.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod3\v4\yhexbmes.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
    O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
    O16 - DPF: {952F9A71-131A-11D5-8404-00500445A7D0} (ActiveMiniplug Class) - https://intranet.unss.org/plugins/mplugax.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C8316DFD-C648-4C98-AA44-E0F93994BA56}: NameServer = 80.10.246.130 81.253.149.10
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O20 - Winlogon Notify: opnomlj - opnomlj.dll (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxLiveShare.exe
    O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxMediaDB.exe
    O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxWatch.exe

    --
    End of file - 17525 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1131214138.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar BETA - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2006-12-08 802840]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2008-12-28 251504]
    {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - GamesBar - C:\Program Files\GamesBar\oberontb.dll [2008-01-06 540672]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "MCI USB Icon"=C:\WINDOWS\system32\USBIcon.exe [2004-09-17 81920]
    "winjb.exe"=C:\WINDOWS\system32\winjb.exe []
    "nter32.exe"=C:\WINDOWS\system32\nter32.exe []
    "ipws32.exe"=C:\WINDOWS\system32\ipws32.exe []
    "applu32.exe"=C:\WINDOWS\system32\applu32.exe []
    "d3vm32.exe"=C:\WINDOWS\system32\d3vm32.exe []
    "msqd.exe"=C:\WINDOWS\system32\msqd.exe []
    "javawq.exe"=C:\WINDOWS\system32\javawq.exe []
    "ieug.exe"=C:\WINDOWS\system32\ieug.exe []
    "winnk32.exe"=C:\WINDOWS\system32\winnk32.exe []
    "ntzz32.exe"=C:\WINDOWS\system32\ntzz32.exe []
    "msoc32.exe"=C:\WINDOWS\system32\msoc32.exe []
    "apizk.exe"=C:\WINDOWS\system32\apizk.exe []
    "wintu32.exe"=C:\WINDOWS\system32\wintu32.exe []
    "ipkv.exe"=C:\WINDOWS\system32\ipkv.exe []
    "netxb.exe"=C:\WINDOWS\system32\netxb.exe []
    "sysjs.exe"=C:\WINDOWS\sysjs.exe []
    "ieex.exe"=C:\WINDOWS\ieex.exe []
    "syslt.exe"=C:\WINDOWS\system32\syslt.exe []
    "ntyk32.exe"=C:\WINDOWS\system32\ntyk32.exe []
    "ieos.exe"=C:\WINDOWS\ieos.exe []
    "iefa32.exe"=C:\WINDOWS\system32\iefa32.exe []
    "ntct32.exe"=C:\WINDOWS\system32\ntct32.exe []
    "javadt.exe"=C:\WINDOWS\system32\javadt.exe []
    "sysdr.exe"=C:\WINDOWS\system32\sysdr.exe []
    "sdkao32.exe"=C:\WINDOWS\system32\sdkao32.exe []
    "netxe32.exe"=C:\WINDOWS\system32\netxe32.exe []
    "javayb.exe"=C:\WINDOWS\system32\javayb.exe []
    "d3br.exe"=C:\WINDOWS\system32\d3br.exe []
    "d3di.exe"=C:\WINDOWS\system32\d3di.exe []
    "addwz32.exe"=C:\WINDOWS\system32\addwz32.exe []
    "javaod.exe"=C:\WINDOWS\system32\javaod.exe []
    "addmc.exe"=C:\WINDOWS\system32\addmc.exe []
    "iett32.exe"=C:\WINDOWS\system32\iett32.exe []
    "d3gg32.exe"=C:\WINDOWS\system32\d3gg32.exe []
    "appyt32.exe"=C:\WINDOWS\system32\appyt32.exe []
    "atlbo.exe"=C:\WINDOWS\system32\atlbo.exe []
    "atlqu.exe"=C:\WINDOWS\system32\atlqu.exe []
    "winxc.exe"=C:\WINDOWS\system32\winxc.exe []
    "netcq32.exe"=C:\WINDOWS\system32\netcq32.exe []
    "ntik32.exe"=C:\WINDOWS\system32\ntik32.exe []
    "atlen.exe"=C:\WINDOWS\system32\atlen.exe []
    "mfcrd.exe"=C:\WINDOWS\system32\mfcrd.exe []
    "winah.exe"=C:\WINDOWS\system32\winah.exe []
    "msxd.exe"=C:\WINDOWS\system32\msxd.exe []
    "syset.exe"=C:\WINDOWS\syset.exe []
    "sysxw.exe"=C:\WINDOWS\sysxw.exe []
    "sdkzg32.exe"=C:\WINDOWS\sdkzg32.exe []
    "mfcjl.exe"=C:\WINDOWS\system32\mfcjl.exe []
    "mfcpt.exe"=C:\WINDOWS\system32\mfcpt.exe []
    "d3al32.exe"=C:\WINDOWS\system32\d3al32.exe []
    "sysqd32.exe"=C:\WINDOWS\system32\sysqd32.exe []
    "d3bo.exe"=C:\WINDOWS\system32\d3bo.exe []
    "javaea.exe"=C:\WINDOWS\system32\javaea.exe []
    "ntix32.exe"=C:\WINDOWS\system32\ntix32.exe []
    "LogitechCommunicationsManager"=C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe [2006-10-31 284184]
    "LogitechQuickCamRibbon"=C:\Program Files\Logitech\QuickCam10\QuickCam10.exe [2006-11-15 746520]
    "NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
    "ISUSScheduler"=C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe [2005-02-16 81920]
    "ISUSPM Startup"=c:\progra~1\fichie~1\instal~1\update~1\isuspm.exe [2004-07-27 221184]
    "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-07-19 78008]
    "WOOWATCH"=C:\PROGRA~1\Wanadoo\Watch.exe [2004-05-13 24576]
    "WOOTASKBARICON"=C:\PROGRA~1\Wanadoo\TaskbarIcon.exe [2004-05-13 49152]
    "CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2007-05-14 644696]
    "CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2007-04-03 1603152]
    "SSBkgdUpdate"=C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
    "OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
    "LDM"=C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-02-19 67128]
    "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-07-29 68856]
    "amhjrte"=c:\documents and settings\patrick\local settings\application data\amhjrte.exe amhjrte []
    "SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]
    "mqyyu"=c:\documents and settings\patrick\local settings\application data\mqyyu.exe [2009-02-26 303104]
    "msnmsgr"=C:\Program Files\MSN Messenger\msnmsgr.exe [2007-01-19 5674352]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adaptec DirectCD]
    C:\PROGRA~1\Adaptec\DirectCD\directcd.exe [2000-08-31 1126400]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\addbk32.exe]
    C:\WINDOWS\addbk32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adddw32.exe]
    C:\WINDOWS\adddw32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\addea32.exe]
    C:\WINDOWS\addea32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apihz32.exe]
    C:\WINDOWS\apihz32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apimu32.exe]
    C:\WINDOWS\apimu32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apiwb32.exe]
    C:\WINDOWS\apiwb32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apiwn32.exe]
    C:\WINDOWS\apiwn32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apixk.exe]
    C:\WINDOWS\apixk.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apizj32.exe]
    C:\WINDOWS\apizj32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\appdh.exe]
    C:\WINDOWS\appdh.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\appfx.exe]
    C:\WINDOWS\appfx.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apphx.exe]
    C:\WINDOWS\apphx.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\appkn32.exe]
    C:\WINDOWS\appkn32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\appxv32.exe]
    C:\WINDOWS\appxv32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atldp.exe]
    C:\WINDOWS\atldp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atlih32.exe]
    C:\WINDOWS\atlih32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atlth.exe]
    C:\WINDOWS\atlth.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atlwp32.exe]
    C:\WINDOWS\atlwp32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDSwitchAgent]
    C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BeachLifeSetup.exe]
    C:\DOCUME~1\Patrick\MESDOC~1\P1D78~1.MOR\BEACHL~1.EXE /r []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe [2006-11-16 139264]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bruqbtbpep]
    c:\documents and settings\patrick\local settings\application data\bruqbtbpep.exe bruqbtbpep []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio]
    RunDll32 cmicnfg.cpl []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\crib.exe]
    C:\WINDOWS\crib.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\crnc.exe]
    C:\WINDOWS\crnc.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\crpl.exe]
    C:\WINDOWS\crpl.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D.tmp]
    C:\DOCUME~1\Patrick\LOCALS~1\Temp\D.tmp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D.tmp.exe]
    C:\DOCUME~1\Patrick\LOCALS~1\Temp\D.tmp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\d3fl32.exe]
    C:\WINDOWS\d3fl32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\d3sw.exe]
    C:\WINDOWS\d3sw.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXDllRegExe]
    dxdllreg.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E.tmp]
    C:\DOCUME~1\Patrick\LOCALS~1\Temp\E.tmp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E.tmp.exe]
    C:\DOCUME~1\Patrick\LOCALS~1\Temp\E.tmp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2003-06-26 212992]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    C:\Program Files\HP\HP Software Update\HPWuSchd.exe [2003-06-25 49152]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iebe32.exe]
    C:\WINDOWS\iebe32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ietv32.exe]
    C:\WINDOWS\ietv32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ieua32.exe]
    C:\WINDOWS\ieua32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ieuf.exe]
    C:\WINDOWS\ieuf.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ieuj32.exe]
    C:\WINDOWS\ieuj32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ievw.exe]
    C:\WINDOWS\ievw.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipbq32.exe]
    C:\WINDOWS\ipbq32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipgo32.exe]
    C:\WINDOWS\ipgo32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipjn.exe]
    C:\WINDOWS\ipjn.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipng.exe]
    C:\WINDOWS\ipng.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipnv32.exe]
    C:\WINDOWS\ipnv32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipqi.exe]
    C:\WINDOWS\ipqi.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipzg32.exe]
    C:\WINDOWS\ipzg32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
    C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-07-27 221184]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\javafo32.exe]
    C:\WINDOWS\javafo32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\javaiw32.exe]
    C:\WINDOWS\javaiw32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\javapc32.exe]
    C:\WINDOWS\javapc32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\javasl.exe]
    C:\WINDOWS\javasl.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\javayr32.exe]
    C:\WINDOWS\javayr32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\javazk.exe]
    C:\WINDOWS\javazk.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    C:\WINDOWS\system32\dumprep 0 -k []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcim.exe]
    C:\WINDOWS\mfcim.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcmo32.exe]
    C:\WINDOWS\mfcmo32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcpo32.exe]
    C:\WINDOWS\mfcpo32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcwa32.exe]
    C:\WINDOWS\mfcwa32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcwf.exe]
    C:\WINDOWS\mfcwf.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcwu32.exe]
    C:\WINDOWS\mfcwu32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcxv.exe]
    C:\WINDOWS\mfcxv.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msel.exe]
    C:\WINDOWS\msel.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msib32.exe]
    C:\WINDOWS\msib32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msji.exe]
    C:\WINDOWS\msji.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mspo.exe]
    C:\WINDOWS\mspo.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mssc.exe]
    C:\WINDOWS\mssc.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netkh32.exe]
    C:\WINDOWS\netkh32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netld.exe]
    C:\WINDOWS\netld.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netnu.exe]
    C:\WINDOWS\netnu.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netsr32.exe]
    C:\WINDOWS\netsr32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nettp.exe]
    C:\WINDOWS\nettp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netzd32.exe]
    C:\WINDOWS\netzd32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntlj32.exe]
    C:\WINDOWS\ntlj32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntnk.exe]
    C:\WINDOWS\ntnk.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntnw32.exe]
    C:\WINDOWS\ntnw32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
    C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxWatchTray.exe [2006-02-14 163840]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sdkeh.exe]
    C:\WINDOWS\sdkeh.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sdksp32.exe]
    C:\WINDOWS\sdksp32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sdktk32.exe]
    C:\WINDOWS\sdktk32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
    C:\WINDOWS\SOUNDMAN.EXE [2004-02-09 65024]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware-Secure]
    C:\Documents and Settings\Patrick\Mes documents\Spyware-Secure\Spyware-Secure_trial.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\syszl32.exe]
    C:\WINDOWS\syszl32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ukbhdlbqeu]
    c:\documents and settings\patrick\local settings\application data\ukbhdlbqeu.exe ukbhdlbqeu []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\windp32.exe]
    C:\WINDOWS\windp32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winel32.exe]
    C:\WINDOWS\winel32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wingb32.exe]
    C:\WINDOWS\wingb32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winng32.exe]
    C:\WINDOWS\winng32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winrt.exe]
    C:\WINDOWS\winrt.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winug32.exe]
    C:\WINDOWS\winug32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winxh32.exe]
    C:\WINDOWS\winxh32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winyq.exe]
    C:\WINDOWS\winyq.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WooCnxMon]
    C:\PROGRA~1\Wanadoo\CnxMon.exe [2004-05-13 24576]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
    C:\PROGRA~1\Wanadoo\TaskbarIcon.exe [2004-05-13 49152]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
    C:\PROGRA~1\Wanadoo\Watch.exe [2004-05-13 24576]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^DSLMON.lnk]
    C:\PROGRA~1\SAGEM\SAGEMF~1\dslmon.exe [2003-05-02 954475]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
    C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2003-07-07 233472]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
    C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE [2005-06-14 278528]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^MioSync.lnk]
    C:\PROGRA~1\MIOTEC~1\MioSync\mioSync.exe [2007-03-12 647168]

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnomlj]
    opnomlj.dll []

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{DB0B918E-A0A8-482B-8D75-A682816B0C7B}"=C:\WINDOWS\system32\opnomlj.dll []

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
    "authentication packages"=msv1_0
    C:\WINDOWS\system32\ssqrs.dll

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=95000000

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "HonorAutoRunSetting"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\OXYFSTUJ\incredimail_install[1].exe"="C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\OXYFSTUJ\incredimail_install[1].exe:*:Enabled:IncrediMail Installer"
    "C:\Program Files\InterVideo\DVD7\WinDVD.exe"="C:\Program Files\InterVideo\DVD7\WinDVD.exe:*:D isabled:WinDVD"
    "C:\Program Files\Securitoo\av_fw\backweb\1044199\Program\backWeb-1044199.exe"="C:\Program Files\Securitoo\av_fw\backweb\1044199\Program\backWeb-1044199.exe:*:D isabled:backWeb-1044199"
    "C:\Program Files\IncrediMail\bin\IMApp.exe"="C:\Program Files\IncrediMail\bin\IMApp.exe:*:Enabled:IncrediMail"
    "C:\Program Files\IncrediMail\bin\IncMail.exe"="C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail"
    "C:\Program Files\IncrediMail\bin\ImpCnt.exe"="C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail"
    "C:\Program Files\eChanblard\emule.exe"="C:\Program Files\eChanblard\emule.exe:*:Enabled:eMule"
    "C:\Program Files\3D Groove\Alien X\AlienX.exe"="C:\Program Files\3D Groove\Alien X\AlienX.exe:*:D isabled:p owered by 3D Groove"
    "C:\Program Files\Livecom\Application\eConfv4\livecomp.exe"="C:\Program Files\Livecom\Application\eConfv4\livecomp.exe:*:Enabled:Livecom Player"
    "C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe"="C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe:*:Enabled:Livecom"
    "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\EconfV4\ftplayer.exe"="C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\EconfV4\ftplayer.exe:*:Enabled:Livecom Media"
    "C:\Program Files\MSN Messenger\msncall.exe"="C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
    "C:\Program Files\Team17\Worms Armageddon\wa.exe"="C:\Program Files\Team17\Worms Armageddon\wa.exe:*:Enabled:Worms Armageddon"
    "C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe"="C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:D isabled:Nero ShowTime"
    "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
    "C:\WINDOWS\system32\tlonvchj.exe"="C:\WINDOWS\system32\tlo"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe"="C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe:*:Enabled:Livecom"
    "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\EconfV4\ftplayer.exe"="C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\EconfV4\ftplayer.exe:*:Enabled:Livecom Media"
    "C:\Program Files\MSN Messenger\msncall.exe"="C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
    "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2aaebe20-5b83-11db-96bb-000ea638261d}]
    shell\AutoRun\command - G:\LaunchU3.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{357eca18-9037-11dc-9a30-000ea638261d}]
    shell\Auto\command - bittorrent.exe e
    shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{779a5fca-e061-11da-95a7-4d6564696130}]
    shell\AutoRun\command - G:\LaunchU3.exe


    ======List of files/folders created in the last 1 months======

    2009-03-01 15:22:21 ----D---- C:\rsit
    2009-03-01 10:26:40 ----D---- C:\WINDOWS\LastGood
    2009-02-24 23:44:06 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
    2009-02-23 23:34:31 ----D---- C:\Documents and Settings\Patrick\Application Data\EleFun Games
    2009-02-16 22:43:01 ----D---- C:\Program Files\GamesBar
    2009-02-14 23:16:27 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
    2009-02-04 20:05:12 ----D---- C:\Documents and Settings\Patrick\Application Data\Canon

    ======List of files/folders modified in the last 1 months======

    2009-03-01 15:22:21 ----D---- C:\WINDOWS\Prefetch
    2009-03-01 14:41:24 ----D---- C:\WINDOWS\Temp
    2009-03-01 10:26:41 ----SD---- C:\WINDOWS\Downloaded Program Files
    2009-03-01 10:26:40 ----D---- C:\WINDOWS
    2009-03-01 10:26:28 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-02-28 18:41:13 ----D---- C:\WINDOWS\network diagnostic
    2009-02-28 18:25:51 ----D---- C:\Program Files\Wanadoo
    2009-02-28 18:19:19 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-02-28 09:22:49 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
    2009-02-25 22:45:19 ----A---- C:\WINDOWS\NeroDigital.ini
    2009-02-25 22:37:45 ----D---- C:\WINDOWS\Help
    2009-02-25 21:48:40 ----D---- C:\WINDOWS\system32
    2009-02-24 23:44:22 ----HD---- C:\WINDOWS\inf
    2009-02-24 23:44:13 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2009-02-24 23:09:49 ----D---- C:\Program Files\Oberon Media
    2009-02-24 22:09:09 ----HD---- C:\WINDOWS\$hf_mig$
    2009-02-16 22:43:01 ----RD---- C:\Program Files
    2009-02-16 07:42:30 ----D---- C:\Documents and Settings\Patrick\Application Data\U3
    2009-02-15 09:15:55 ----D---- C:\Documents and Settings\Patrick\Application Data\ArcSoft
    2009-02-14 23:16:30 ----A---- C:\WINDOWS\imsins.BAK
    2009-02-14 23:15:57 ----D---- C:\Program Files\Internet Explorer
    2009-02-14 23:15:43 ----D---- C:\WINDOWS\ie7updates
    2009-02-12 05:56:17 ----A---- C:\WINDOWS\system32\MRT.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-07-19 26944]
    R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
    R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-07-19 42912]
    R1 Cdr4_2K;Cdr4_2K; C:\WINDOWS\system32\drivers\Cdr4_2K.sys [2008-03-23 52464]
    R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2005-11-03 2560]
    R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
    R1 pwd_2K;pwd_2K; C:\WINDOWS\system32\drivers\pwd_2K.sys [2000-08-31 50358]
    R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
    R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-07-19 94416]
    R2 CdaC15BA;CdaC15BA; \??\C:\WINDOWS\system32\drivers\CdaC15BA.SYS []
    R3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2003-03-27 127145]
    R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-12-11 391424]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-02-18 610988]
    R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-07-19 23152]
    R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2004-08-04 701440]
    R3 FilterService;UVC Filter Service; C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys [2006-11-10 21536]
    R3 LVcKap;Logitech AEC Driver; C:\WINDOWS\system32\DRIVERS\LVcKap.sys [2006-11-15 1678368]
    R3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys [2006-11-15 1962912]
    R3 lvpopflt;Logitech POP Suppression Filter; C:\WINDOWS\system32\DRIVERS\lvpopflt.sys [2006-11-10 1512224]
    R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\WINDOWS\system32\drivers\LVPr2Mon.sys [2006-11-15 24736]
    R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2006-11-10 40352]
    R3 LVUVC;Logitech QuickCam Pro 5000(UVC); C:\WINDOWS\system32\DRIVERS\lvuvc.sys [2006-11-10 1083680]
    R3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
    R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
    R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S1 Cdudf;Cdudf; C:\WINDOWS\system32\drivers\Cdudf.sys [2000-08-31 221504]
    S1 UdfReadr;UdfReadr; C:\WINDOWS\system32\drivers\UdfReadr.sys [2000-06-15 206368]
    S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2003-03-25 46455]
    S3 bdfdll;bdfdll; \??\C:\Program Files\Softwin\BitDefender9\bdfdll.sys []
    S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
    S3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2004-02-20 815296]
    S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-08-11 51056]
    S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-08-11 16496]
    S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-08-11 21488]
    S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2000-08-31 16774]
    S3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
    S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
    S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
    S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
    S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
    S3 StillCam;Pilote d'appareil photo numérique série; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-08-23 6912]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
    S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
    S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
    S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-07-19 16056]
    R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-07-19 147640]
    R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2005-09-30 96341]
    R2 LVPrcSrv;Logitech Process Monitor; c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe [2006-11-15 109344]
    R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
    R2 RoxWatch;Roxio Hard Drive Watcher; C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxWatch.exe [2006-02-14 155648]
    R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
    R3 RoxMediaDB;RoxMediaDB; C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxMediaDB.exe [2006-02-14 864256]
    S2 LVSrvLauncher;LVSrvLauncher; C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe [2006-11-15 101152]
    S2 RoxLiveShare;LiveShare P2P Server; C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxLiveShare.exe [2006-02-14 233472]
    S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
    S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-07-19 250040]
    S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-07-23 348344]
    S3 Boonty Games;Boonty Games; C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2007-02-17 69120]
    S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-28 137200]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
    S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
    S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2003-08-11 65795]
    S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]

    -----------------EOF-----------------

    info.txt:

    info.txt logfile of random's system information tool 1.05 2009-03-01 15:25:13

    ======Uninstall list======

    -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
    -->C:\WINDOWS\UNRecode.exe /UNINSTALL
    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    Adaptec DirectCD-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Adaptec\DirectCD\DCDUnins.isu" -cC:\PROGRA~1\Adaptec\DirectCD\Dcduhlp.dll
    Adobe Acrobat 4.0-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 4.0\NT\Uninst.isu"
    Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
    Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
    Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
    Air Strike 2-->"C:\Program Files\orange\jeux\Air Strike 2\Uninstall.exe" "C:\Program Files\orange\jeux\Air Strike 2\install.log"
    Architecte Studio Pro 2005-->MsiExec.exe /I{92BA4078-653C-4192-B041-1917222CCAB3}
    Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
    ArcSoft Camera Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AD708DF0-9F04-4CB3-821A-85804A833B4D}\setup.exe" -l0x40c -uninst
    ArcSoft PhotoStudio 5.5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85309D89-7BE9-4094-BB17-24999C6118FC}\SETUP.EXE" -l0x40c
    avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
    Canon Camera Access Library-->"C:\Program Files\Fichiers communs\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\CAL\Uninst.ini"
    Canon Camera Support Core Library-->"C:\Program Files\Fichiers communs\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\CSCLIB\Uninst.ini"
    Canon Camera Window DC_DV 5 for ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC\Uninst.ini"
    Canon Camera Window DC_DV 6 for ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC6\Uninst.ini"
    Canon Camera Window MC 6 for ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowMC\Uninst.ini"
    Canon IJ Network Scan Utility-->C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSU.EXE
    Canon IJ Network Tool-->C:\Program Files\Canon\Canon IJ Network Tool\CNMNUU.exe
    CANON iMAGE GATEWAY Task-->"C:\Program Files\Fichiers communs\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\CRWUnInstall.ini"
    Canon Internet Library for ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\CIGUnInstall.ini"
    Canon MP Navigator EX 1.0-->"C:\Program Files\Canon\MP Navigator EX 1.0\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator EX 1.0\uninst.ini
    Canon MP970 series-->"C:\WINDOWS\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP970_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP970_series /L0x000c
    Canon My Printer-->C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini
    Canon PhotoRecord-->C:\WINDOWS\IsUn040c.exe -fC:\PROGRA~1\Canon\PhotoRecord\Uninst.isu -c"C:\PROGRA~1\Canon\PhotoRecord\Program\uninstdll.dll"
    Canon RAW Image Task for ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\RAW Image Task\Uninst.ini"
    Canon RemoteCapture Task for ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\RemoteCaptureTask DC\Uninst.ini"
    Canon Utilities Easy-PhotoPrint EX-->C:\Program Files\Canon\Easy-PhotoPrint EX\uninst.exe uninst.ini
    Canon Utilities Easy-PhotoPrint-->C:\Program Files\Canon\EPP\EPP\Easy-PhotoPrint\uninst.exe uninst.ini
    Canon Utilities EOS Utility-->"C:\Program Files\Fichiers communs\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\EOS Utility\Uninst.ini"
    Canon Utilities File Viewer Utility 1.2-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{755D3B4E-D3A3-4D05-99D8-FC35E26A331C}
    Canon Utilities PhotoStitch-->"C:\Program Files\Fichiers communs\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\PhotoStitch\Uninst.ini"
    Canon Utilities RemoteCapture 2.7-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{AB3AC39D-9915-435D-ACC4-9881E75326BC}
    Canon Utilities Solution Menu-->C:\Program Files\Canon\SolutionMenu\uninst.exe uninst.ini
    Canon Utilities ZoomBrowser EX-->"C:\Program Files\Fichiers communs\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\Uninst.ini"
    CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
    Cdiscount photos -->C:\Program Files\Cdiscount photos\uninst.exe
    CD-LabelPrint-->"C:\Program Files\Canon\CD-LabelPrint\Uninstal.exe" Canon.CDLabelPrint.Application
    ClickImpôts plus 2007-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6172D607-8EE9-4659-BE35-7FDA8A68E885}\Setup.exe" -l0x40c
    ClickImpôts plus 2008 2008.2.040-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{96329F8F-803E-4550-A054-362E03D7D516}\setup.exe" -l0x40c
    ClickImpôts plus 2009 2009.1.051-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88FCCB42-A002-4F94-83B4-7835E188F13B}\setup.exe" -l0x40c
    C-Media WDM Audio Driver-->C:\WINDOWS\system32\cmirmdrv.exe
    Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
    Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
    CS881X & MTM80X Driver(Auto Installation, Safely Remove Feature, Icon Utility)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8BD7D8D6-5E89-42B5-A313-5E75128BC144}\SETUP.exe" -l0x9 -removeonly
    Favorit-->"c:\documents and settings\patrick\local settings\application data\mqyyu.exe" -uninstall
    GamesBar 2.0.1.12-->C:\Program Files\GamesBar\uninst.exe
    Google Earth-->MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
    Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
    HijackThis 2.0.2-->"C:\Documents and Settings\Patrick\Mes documents\Eric\HijackThis.exe" /uninstall
    HP PSC & OfficeJet 3.0-->"C:\Program Files\HP\Digital Imaging\{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}\setup\hpzscr01.exe" -datfile hposcr03.dat
    HP Software Update-->MsiExec.exe /X{CC0A24CB-87C9-4F1C-A1F2-F87D8D4DDCAF}
    InterActual Player-->C:\Program Files\InterActual\InterActual Player\inuninst.exe
    InternetGameBox -->C:\Program Files\InternetGameBox\uninst.exe
    InterVideo WinDVD 7-->"C:\Program Files\InstallShield Installation Information\{90885A82-9673-49EA-AB39-AF776639C67C}\setup.exe" REMOVEALL
    Lecteur Windows Media 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
    Logitech Audio Echo Cancellation Component-->MsiExec.exe /X{BEF726DD-4037-4214-8C6A-E625C02D2870}
    Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x40c UNINSTALL
    Logitech QuickCam-->MsiExec.exe /X{10110FE9-1EE8-4A3D-ADFD-1294F86BE5FC}
    Logitech QuickCam-->MsiExec.exe /X{EC42ED6A-751D-45C0-A4F9-8CD00E4690FC}
    Logitech Video Enumerator-->MsiExec.exe /X{EA516024-D84D-41F1-814F-83175A6188F2}
    Magic Ball 3-->"C:\Program Files\orange\jeux\Magic Ball 3\Uninstall.exe" "C:\Program Files\orange\jeux\Magic Ball 3\install.log"
    Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
    Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
    Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
    Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
    Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
    Mio Technology Speedcam Synchronisation ( M2 ) 1.2.12.03.2007-->C:\PROGRA~1\MIOTEC~1\MioSync\Setup.exe /remove
    Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (K
    m
    0
    l
    Contenus similaires
    a c 267 8 Sécurité
    1 Mars 2009 16:12:18

  • Télécharge Navilog1 (de IL-MAFIOSO) sur ton Bureau.
  • Double-clique sur Navilog1.exe afin de lancer l'installation.
  • Si le fix ne lance pas automatiquement après son installation, double-clique sur Navilog1 présent sur le Bureau.
  • Appuie sur F ou f puis valide par Entrée.
  • Appuie sur une touche de ton clavier à chaque fois que cela est demandé, tu arriveras au menu des options.
  • Choisis l'option 1 et appuie sur la touche Entrée pour valider ton choix.
  • Patiente jusqu'au message : *** Analyse terminée le ..... ***
  • Le scan fini, le Bloc-notes contenant le rapport sera affiché, poste le contenu de ce rapport dans ta prochaine réponse.
  • Si le résultat du scan ne s'affiche pas, tu le trouveras dans C:\fixnavi.txt

    N'utilise pas l'option 2, 3 et 4 sans notre accord, des fichiers légitimes peuvent être inclus dans ce scan.
    m
    0
    l
    1 Mars 2009 16:44:17

    Search Navipromo version 3.7.5 commencé le 01/03/2009 à 16:33:56,81

    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
    !!! Postez ce rapport sur le forum pour le faire analyser !!!
    !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

    Outil exécuté depuis C:\Program Files\navilog1

    Mise à jour le 26.02.2009 à 18h00 par IL-MAFIOSO

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) CPU 2.40GHz )
    BIOS : BIOS Date: 07/25/03 14:04:08 Ver: 08.00.09
    USER : Patrick ( Administrator )
    BOOT : Normal boot

    Antivirus : avast! antivirus 4.8.1229 [VPS 090228-0] 4.8.1229 (Activated)


    A:\ (USB)
    C:\ (Local Disk) - NTFS - Total:37 Go (Free:16 Go)
    D:\ (CD or DVD)
    E:\ (Local Disk) - NTFS - Total:39 Go (Free:37 Go)
    F:\ (USB)
    H:\ (USB)
    I:\ (USB)
    J:\ (USB)


    Recherche executé en mode normal

    *** Recherche Programmes installés ***

    Favorit
    InternetGameBox

    *** Recherche dossiers dans "C:\WINDOWS" ***


    *** Recherche dossiers dans "C:\Program Files" ***

    ...\InternetGameBox trouvé !

    *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

    ...\InternetGameBox trouvé !

    *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


    *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***


    *** Recherche dossiers dans "C:\Documents and Settings\Patrick\applic~1" ***


    *** Recherche dossiers dans "C:\Documents and Settings\Patrick\locals~1\applic~1" ***


    *** Recherche dossiers dans "C:\Documents and Settings\Patrick\menudm~1\progra~1" ***

    ...\InternetGameBox trouvé !

    *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
    pour + d'infos : http://www.gmer.net



    *** Recherche avec GenericNaviSearch ***
    !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
    !!! A vérifier impérativement avant toute suppression manuelle !!!

    * Recherche dans "C:\WINDOWS\system32" *

    * Recherche dans "C:\Documents and Settings\Patrick\locals~1\applic~1" *



    *** Recherche fichiers ***



    *** Recherche clés spécifiques dans le Registre ***
    !! Les clés trouvées ne sont pas forcément infectées !!


    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "amhjrte"="c:\\documents and settings\\patrick\\local settings\\application data\\amhjrte.exe amhjrte"

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "mqyyu"="\"c:\\documents and settings\\patrick\\local settings\\application data\\mqyyu.exe\" mqyyu"


    *** Module de Recherche complémentaire ***
    (Recherche fichiers spécifiques)

    1)Recherche nouveaux fichiers Instant Access :


    2)Recherche Heuristique :

    * Dans "C:\WINDOWS\system32" :

    pv.exe trouvé !

    * Dans "C:\Documents and Settings\Patrick\locals~1\applic~1" :

    amhjrte.exe.xpx trouvé !
    amhjrte.dat trouvé !
    amhjrte_nav.dat trouvé !
    amhjrte_navps.dat trouvé !
    mqyyu.exe trouvé !
    mqyyu.dat trouvé !
    mqyyu_nav.dat trouvé !
    mqyyu_navps.dat trouvé !
    ukbhdlbqeu.exe.xpx trouvé !
    ukbhdlbqeu.dat trouvé !
    ukbhdlbqeu_nav.dat trouvé !
    ukbhdlbqeu_navps.dat trouvé !

    3)Recherche Certificats :

    Certificat Egroup trouvé !
    Certificat Electronic-Group trouvé !
    Certificat Montorgueil absent !
    Certificat OOO-Favorit trouvé !
    Certificat Sunny-Day-Design-Ltd absent !

    4)Recherche autres dossiers et fichiers connus :

    C:\WINDOWS\system32\srqss.ini2 trouvé ! Infection Vundo possible non traitée par cet outil !


    *** Analyse terminée le 01/03/2009 à 16:43:28,45 ***
    m
    0
    l
    a c 267 8 Sécurité
    1 Mars 2009 16:53:04

  • Relance Navilog1, fais l'option 2 et poste le rapport (C:\cleannavi.txt).
    m
    0
    l
    1 Mars 2009 17:18:33

    Clean Navipromo version 3.7.5 commencé le 01/03/2009 à 16:59:46,36

    Outil exécuté depuis C:\Program Files\navilog1

    Mise à jour le 26.02.2009 à 18h00 par IL-MAFIOSO

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) CPU 2.40GHz )
    BIOS : BIOS Date: 07/25/03 14:04:08 Ver: 08.00.09
    USER : Patrick ( Administrator )
    BOOT : Normal boot

    Antivirus : avast! antivirus 4.8.1229 [VPS 090228-0] 4.8.1229 (Activated)


    A:\ (USB)
    C:\ (Local Disk) - NTFS - Total:37 Go (Free:16 Go)
    D:\ (CD or DVD)
    E:\ (Local Disk) - NTFS - Total:39 Go (Free:37 Go)
    F:\ (USB)
    H:\ (USB)
    I:\ (USB)
    J:\ (USB)


    Mode suppression automatique
    avec prise en charge résultats Catchme et GNS


    Nettoyage exécuté au redémarrage de l'ordinateur


    *** fsbl1.txt non trouvé ***
    (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)


    *** Suppression avec sauvegardes résultats GenericNaviSearch ***

    * Suppression dans "C:\WINDOWS\System32" *


    * Suppression dans "C:\Documents and Settings\Patrick\locals~1\applic~1" *



    *** Suppression dossiers dans "C:\WINDOWS" ***


    *** Suppression dossiers dans "C:\Program Files" ***

    ...\InternetGamebox ...suppression...
    ...\InternetGamebox supprimé !


    *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

    ...\InternetGamebox ...suppression...
    ...\InternetGamebox supprimé !


    *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


    *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***


    *** Suppression dossiers dans "C:\Documents and Settings\Patrick\applic~1" ***


    *** Suppression dossiers dans "C:\Documents and Settings\Patrick\locals~1\applic~1" ***


    *** Suppression dossiers dans "C:\Documents and Settings\Patrick\menudm~1\progra~1" ***

    ...\InternetGamebox ...suppression...
    ...\InternetGamebox supprimé !



    *** Suppression fichiers ***


    *** Suppression fichiers temporaires ***

    Nettoyage contenu C:\WINDOWS\Temp effectué !
    Nettoyage contenu C:\Documents and Settings\Patrick\locals~1\Temp effectué !

    *** Traitement Recherche complémentaire ***
    (Recherche fichiers spécifiques)

    1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

    2)Recherche, création sauvegardes et suppression Heuristique :


    * Dans "C:\WINDOWS\system32" *


    C:\WINDOWS\prefetch\mqyyu*.pf trouvé !
    Copie C:\WINDOWS\prefetch\mqyyu*.pf réalisée avec succès !
    C:\WINDOWS\prefetch\mqyyu*.pf supprimé !

    pv.exe trouvé !
    Copie pv.exe réalisée avec succès !
    pv.exe supprimé !


    * Dans "C:\Documents and Settings\Patrick\locals~1\applic~1" *


    amhjrte.exe.xpx trouvé !
    Copie amhjrte.exe.xpx réalisée avec succès !
    amhjrte.exe.xpx supprimé !

    amhjrte.dat trouvé !
    Copie amhjrte.dat réalisée avec succès !
    amhjrte.dat supprimé !

    amhjrte_nav.dat trouvé !
    Copie amhjrte_nav.dat réalisée avec succès !
    amhjrte_nav.dat supprimé !

    amhjrte_navps.dat trouvé !
    Copie amhjrte_navps.dat réalisée avec succès !
    amhjrte_navps.dat supprimé !

    mqyyu.exe trouvé !
    Copie mqyyu.exe réalisée avec succès !
    mqyyu.exe supprimé !

    mqyyu.dat trouvé !
    Copie mqyyu.dat réalisée avec succès !
    mqyyu.dat supprimé !

    mqyyu_nav.dat trouvé !
    Copie mqyyu_nav.dat réalisée avec succès !
    mqyyu_nav.dat supprimé !

    mqyyu_navps.dat trouvé !
    Copie mqyyu_navps.dat réalisée avec succès !
    mqyyu_navps.dat supprimé !

    ukbhdlbqeu.exe.xpx trouvé !
    Copie ukbhdlbqeu.exe.xpx réalisée avec succès !
    ukbhdlbqeu.exe.xpx supprimé !

    ukbhdlbqeu.dat trouvé !
    Copie ukbhdlbqeu.dat réalisée avec succès !
    ukbhdlbqeu.dat supprimé !

    ukbhdlbqeu_nav.dat trouvé !
    Copie ukbhdlbqeu_nav.dat réalisée avec succès !
    ukbhdlbqeu_nav.dat supprimé !

    ukbhdlbqeu_navps.dat trouvé !
    Copie ukbhdlbqeu_navps.dat réalisée avec succès !
    ukbhdlbqeu_navps.dat supprimé !


    *** Sauvegarde du Registre vers dossier Safebackup ***

    sauvegarde du Registre réalisée avec succès !

    *** Nettoyage Registre ***

    Nettoyage Registre Ok


    *** Certificats ***

    Certificat Egroup supprimé !
    Certificat Electronic-Group supprimé !
    Certificat Montorgueil absent !
    Certificat OOO-Favorit supprimé !
    Certificat Sunny-Day-Design-Ltdt absent !

    *** Recherche autres dossiers et fichiers connus ***

    C:\WINDOWS\system32\srqss.ini2 trouvé ! Infection Vundo possible non traitée par cet outil !


    *** Nettoyage terminé le 01/03/2009 à 17:13:07,54 ***

    m
    0
    l
    a c 267 8 Sécurité
    1 Mars 2009 17:25:48

  • Désinstalle Navilog1.

  • Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
  • Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
  • Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
  • Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
  • Sélectionne Exécuter un examen rapide.
  • Clique sur Rechercher.
  • L'analyse démarre.
  • A la fin de l'analyse, un message s'affiche :
    Citation :
    L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

  • Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
  • Ferme tes navigateurs.
  • Si des malwares ont été détectés, clique sur Afficher les résultats.
  • Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
  • MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
    m
    0
    l
    1 Mars 2009 17:57:24

    alwarebytes' Anti-Malware 1.34
    Version de la base de données: 1813
    Windows 5.1.2600 Service Pack 3

    01/03/2009 17:55:13
    mbam-log-2009-03-01 (17-55-13).txt

    Type de recherche: Examen rapide
    Eléments examinés: 69147
    Temps écoulé: 9 minute(s), 30 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 26
    Valeur(s) du Registre infectée(s): 3
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 2

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    HKEY_CLASSES_ROOT\oberontb.band (Adware.Gamesbar) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\oberontb.band.1 (Adware.Gamesbar) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{db0b918e-a0a8-482b-8d75-a682816b0c7b} (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{934785db-c826-c699-1b51-85371f56ac8a} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{a4626f5d-18f2-c0a7-8d1b-631bfd287428} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{cf295b84-1f3d-a13c-944e-90632373707e} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{dcba9611-b4b0-16c9-9872-c35c216f9b05} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a93c934-025b-4c3a-b38e-9654a7003239} (Adware.Gamesbar) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1f158a1e-a687-4a11-9679-b3ac64b86a1c} (Adware.Seekmo) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{28508a5e-910a-809d-3a15-b9aa1a3a479c} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{55e6cf7b-f013-b32d-b116-5147dd5bb2cc} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{cd1da3ee-42c1-88f4-6a75-72d4a81ae705} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{1a93c934-025b-4c3a-b38e-9654a7003239} (Adware.Gamesbar) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{28508a5e-910a-809d-3a15-b9aa1a3a479c} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{db0b918e-a0a8-482b-8d75-a682816b0c7b} (Trojan.Downloader) -> Quarantined and deleted successfully.

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    C:\Program Files\GamesBar\oberontb.dll (Adware.Gamesbar) -> Quarantined and deleted successfully.
    C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
    m
    0
    l
    a c 267 8 Sécurité
    1 Mars 2009 18:03:57

  • Relance MBAM, va dans Quarantaine et supprime tout.

  • Refais un scan RSIT mais choisis l'option 3 months cette fois-ci et poste le rapport.
    m
    0
    l
    2 Mars 2009 14:35:38

    Logfile of random's system information tool 1.05 (written by random/random)
    Run by Patrick at 2009-03-02 14:33:52
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 17 GB (45%) free of 38 GB
    Total RAM: 255 MB (21% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:24:23, on 01/03/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxWatch.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\USBIcon.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
    C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
    C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\documents and settings\patrick\local settings\application data\mqyyu.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
    C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxMediaDB.exe
    C:\PROGRA~1\Wanadoo\ComComp.exe
    C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe
    C:\PROGRA~1\Wanadoo\Watch.exe
    C:\Program Files\Logitech\QuickCam10\COCIManager.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Patrick\Bureau\reponse pc au carré\RSIT.exe
    C:\Documents and Settings\Patrick\Mes documents\Eric\Patrick.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar BETA - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: (no name) - {03A2D7B5-7F29-C057-69BA-28A6D6BFD1C8} - (no file)
    O2 - BHO: (no name) - {063E9396-D103-146C-6233-44983B844B4E} - (no file)
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {16C8ED8F-9FBB-BE03-83E5-EF1C71227B4C} - (no file)
    O2 - BHO: (no name) - {1B05716B-5FEA-54F5-0792-D4CE74369E8C} - (no file)
    O2 - BHO: (no name) - {213C3374-2B1F-7A96-5E35-570933B9E400} - (no file)
    O2 - BHO: (no name) - {26ED9CDF-2406-B407-B126-1D1BFA0A9292} - (no file)
    O2 - BHO: (no name) - {28508A5E-910A-809D-3A15-B9AA1A3A479C} - (no file)
    O2 - BHO: (no name) - {28A5E86A-BEB3-2A6B-44A8-08239C13BA8E} - (no file)
    O2 - BHO: (no name) - {292B04EC-6483-FC6A-77F9-29A441F0ED52} - (no file)
    O2 - BHO: (no name) - {367AB86B-4560-ABE0-DA70-7E3A543F553D} - (no file)
    O2 - BHO: (no name) - {433C7071-2FBD-32B1-026E-7B1AF33C122A} - (no file)
    O2 - BHO: (no name) - {482ED513-8F9F-5049-FF7A-8FB035464E5F} - (no file)
    O2 - BHO: (no name) - {4AA55173-B7E5-2D82-CB60-CF53B9F7341B} - (no file)
    O2 - BHO: (no name) - {5022D84C-7E63-46D2-7871-DE7A933DED9A} - (no file)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {55E6CF7B-F013-B32D-B116-5147DD5BB2CC} - (no file)
    O2 - BHO: (no name) - {57B4D25A-EE68-B64A-2938-76F3DE0A7059} - (no file)
    O2 - BHO: (no name) - {588BC16B-2124-BE3A-2619-785389967943} - (no file)
    O2 - BHO: (no name) - {588DFBFB-53C8-6E13-2FC6-8BE47B26484A} - (no file)
    O2 - BHO: (no name) - {5AC5C3B9-9CEC-BC17-DFFB-3F33F50B8236} - (no file)
    O2 - BHO: (no name) - {6C7FF605-A242-47BA-6F53-DF6E15E38036} - (no file)
    O2 - BHO: (no name) - {767C3BCA-1931-C2D3-5152-1EAC589AADF7} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {80139715-66E1-6FA3-B786-BA675AA08141} - (no file)
    O2 - BHO: (no name) - {85350E27-DDF3-4D24-ABE1-57F9792608C9} - (no file)
    O2 - BHO: (no name) - {8A235E4F-CBA3-E0AF-678D-29D9ABA51389} - (no file)
    O2 - BHO: (no name) - {8F990BB6-92DA-5618-847A-5DD4057B1ECE} - (no file)
    O2 - BHO: (no name) - {9286760E-4D31-7E63-1FA6-40EFEFFA75A2} - (no file)
    O2 - BHO: (no name) - {972C70DC-3F58-38DC-719C-265704EEF8A0} - (no file)
    O2 - BHO: (no name) - {9D9CB61B-156B-3C2C-B9AB-BCB95AA0D47C} - (no file)
    O2 - BHO: (no name) - {9DE1545A-6CDE-C52E-C2EE-15ABB18D6F1A} - (no file)
    O2 - BHO: (no name) - {AA30113B-75AD-4CC2-907F-30AA0D758A2F} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: (no name) - {BA684D9D-88F0-4E2E-9B28-CA547ADE9EE3} - (no file)
    O2 - BHO: (no name) - {BAEA961E-A27E-4D7B-55F3-039B88D04CC3} - (no file)
    O2 - BHO: (no name) - {CA0F8F73-786A-51FF-066A-6822CAAE4F95} - (no file)
    O2 - BHO: (no name) - {CD1DA3EE-42C1-88F4-6A75-72D4A81AE705} - (no file)
    O2 - BHO: (no name) - {DFEF27C0-5F32-6983-6737-5F21C8EF035D} - (no file)
    O2 - BHO: (no name) - {E1855C39-8820-BABA-C94F-7C3D2AD1C652} - (no file)
    O2 - BHO: (no name) - {EDCBB3FD-788F-D69A-C205-FAE58398A2D6} - (no file)
    O2 - BHO: (no name) - {F3229D57-F62B-1F6E-54F4-EAF76321F1C8} - (no file)
    O2 - BHO: (no name) - {F322AB0B-621C-11A3-B1AE-7A7FC2B40350} - (no file)
    O2 - BHO: (no name) - {FA30FBE1-2D6A-60CB-19A0-CC0872CC2F67} - (no file)
    O2 - BHO: (no name) - {FA6BD27F-288F-002A-F4A9-ABCF232371D9} - (no file)
    O3 - Toolbar: Yahoo! Toolbar BETA - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
    O4 - HKLM\..\Run: [MCI USB Icon] C:\WINDOWS\system32\USBIcon.exe
    O4 - HKLM\..\Run: [winjb.exe] C:\WINDOWS\system32\winjb.exe
    O4 - HKLM\..\Run: [nter32.exe] C:\WINDOWS\system32\nter32.exe
    O4 - HKLM\..\Run: [ipws32.exe] C:\WINDOWS\system32\ipws32.exe
    O4 - HKLM\..\Run: [applu32.exe] C:\WINDOWS\system32\applu32.exe
    O4 - HKLM\..\Run: [d3vm32.exe] C:\WINDOWS\system32\d3vm32.exe
    O4 - HKLM\..\Run: [msqd.exe] C:\WINDOWS\system32\msqd.exe
    O4 - HKLM\..\Run: [javawq.exe] C:\WINDOWS\system32\javawq.exe
    O4 - HKLM\..\Run: [ieug.exe] C:\WINDOWS\system32\ieug.exe
    O4 - HKLM\..\Run: [winnk32.exe] C:\WINDOWS\system32\winnk32.exe
    O4 - HKLM\..\Run: [ntzz32.exe] C:\WINDOWS\system32\ntzz32.exe
    O4 - HKLM\..\Run: [msoc32.exe] C:\WINDOWS\system32\msoc32.exe
    O4 - HKLM\..\Run: [apizk.exe] C:\WINDOWS\system32\apizk.exe
    O4 - HKLM\..\Run: [wintu32.exe] C:\WINDOWS\system32\wintu32.exe
    O4 - HKLM\..\Run: [ipkv.exe] C:\WINDOWS\system32\ipkv.exe
    O4 - HKLM\..\Run: [netxb.exe] C:\WINDOWS\system32\netxb.exe
    O4 - HKLM\..\Run: [sysjs.exe] C:\WINDOWS\sysjs.exe
    O4 - HKLM\..\Run: [ieex.exe] C:\WINDOWS\ieex.exe
    O4 - HKLM\..\Run: [syslt.exe] C:\WINDOWS\system32\syslt.exe
    O4 - HKLM\..\Run: [ntyk32.exe] C:\WINDOWS\system32\ntyk32.exe
    O4 - HKLM\..\Run: [ieos.exe] C:\WINDOWS\ieos.exe
    O4 - HKLM\..\Run: [iefa32.exe] C:\WINDOWS\system32\iefa32.exe
    O4 - HKLM\..\Run: [ntct32.exe] C:\WINDOWS\system32\ntct32.exe
    O4 - HKLM\..\Run: [javadt.exe] C:\WINDOWS\system32\javadt.exe
    O4 - HKLM\..\Run: [sysdr.exe] C:\WINDOWS\system32\sysdr.exe
    O4 - HKLM\..\Run: [sdkao32.exe] C:\WINDOWS\system32\sdkao32.exe
    O4 - HKLM\..\Run: [netxe32.exe] C:\WINDOWS\system32\netxe32.exe
    O4 - HKLM\..\Run: [javayb.exe] C:\WINDOWS\system32\javayb.exe
    O4 - HKLM\..\Run: [d3br.exe] C:\WINDOWS\system32\d3br.exe
    O4 - HKLM\..\Run: [d3di.exe] C:\WINDOWS\system32\d3di.exe
    O4 - HKLM\..\Run: [addwz32.exe] C:\WINDOWS\system32\addwz32.exe
    O4 - HKLM\..\Run: [javaod.exe] C:\WINDOWS\system32\javaod.exe
    O4 - HKLM\..\Run: [addmc.exe] C:\WINDOWS\system32\addmc.exe
    O4 - HKLM\..\Run: [iett32.exe] C:\WINDOWS\system32\iett32.exe
    O4 - HKLM\..\Run: [d3gg32.exe] C:\WINDOWS\system32\d3gg32.exe
    O4 - HKLM\..\Run: [appyt32.exe] C:\WINDOWS\system32\appyt32.exe
    O4 - HKLM\..\Run: [atlbo.exe] C:\WINDOWS\system32\atlbo.exe
    O4 - HKLM\..\Run: [atlqu.exe] C:\WINDOWS\system32\atlqu.exe
    O4 - HKLM\..\Run: [winxc.exe] C:\WINDOWS\system32\winxc.exe
    O4 - HKLM\..\Run: [netcq32.exe] C:\WINDOWS\system32\netcq32.exe
    O4 - HKLM\..\Run: [ntik32.exe] C:\WINDOWS\system32\ntik32.exe
    O4 - HKLM\..\Run: [atlen.exe] C:\WINDOWS\system32\atlen.exe
    O4 - HKLM\..\Run: [mfcrd.exe] C:\WINDOWS\system32\mfcrd.exe
    O4 - HKLM\..\Run: [winah.exe] C:\WINDOWS\system32\winah.exe
    O4 - HKLM\..\Run: [msxd.exe] C:\WINDOWS\system32\msxd.exe
    O4 - HKLM\..\Run: [syset.exe] C:\WINDOWS\syset.exe
    O4 - HKLM\..\Run: [sysxw.exe] C:\WINDOWS\sysxw.exe
    O4 - HKLM\..\Run: [sdkzg32.exe] C:\WINDOWS\sdkzg32.exe
    O4 - HKLM\..\Run: [mfcjl.exe] C:\WINDOWS\system32\mfcjl.exe
    O4 - HKLM\..\Run: [mfcpt.exe] C:\WINDOWS\system32\mfcpt.exe
    O4 - HKLM\..\Run: [d3al32.exe] C:\WINDOWS\system32\d3al32.exe
    O4 - HKLM\..\Run: [sysqd32.exe] C:\WINDOWS\system32\sysqd32.exe
    O4 - HKLM\..\Run: [d3bo.exe] C:\WINDOWS\system32\d3bo.exe
    O4 - HKLM\..\Run: [javaea.exe] C:\WINDOWS\system32\javaea.exe
    O4 - HKLM\..\Run: [ntix32.exe] C:\WINDOWS\system32\ntix32.exe
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\fichie~1\instal~1\update~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
    O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [amhjrte] c:\documents and settings\patrick\local settings\application data\amhjrte.exe amhjrte
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [mqyyu] "c:\documents and settings\patrick\local settings\application data\mqyyu.exe" mqyyu
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
    O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod3\v4\yhexbmes.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Companion\Modules\messmod3\v4\yhexbmes.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
    O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
    O16 - DPF: {952F9A71-131A-11D5-8404-00500445A7D0} (ActiveMiniplug Class) - https://intranet.unss.org/plugins/mplugax.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C8316DFD-C648-4C98-AA44-E0F93994BA56}: NameServer = 80.10.246.130 81.253.149.10
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O20 - Winlogon Notify: opnomlj - opnomlj.dll (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxLiveShare.exe
    O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxMediaDB.exe
    O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxWatch.exe

    --
    End of file - 17525 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1131214138.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar BETA - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2006-12-08 802840]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2008-12-28 251504]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "MCI USB Icon"=C:\WINDOWS\system32\USBIcon.exe [2004-09-17 81920]
    "winjb.exe"=C:\WINDOWS\system32\winjb.exe []
    "nter32.exe"=C:\WINDOWS\system32\nter32.exe []
    "ipws32.exe"=C:\WINDOWS\system32\ipws32.exe []
    "applu32.exe"=C:\WINDOWS\system32\applu32.exe []
    "d3vm32.exe"=C:\WINDOWS\system32\d3vm32.exe []
    "msqd.exe"=C:\WINDOWS\system32\msqd.exe []
    "javawq.exe"=C:\WINDOWS\system32\javawq.exe []
    "ieug.exe"=C:\WINDOWS\system32\ieug.exe []
    "winnk32.exe"=C:\WINDOWS\system32\winnk32.exe []
    "ntzz32.exe"=C:\WINDOWS\system32\ntzz32.exe []
    "msoc32.exe"=C:\WINDOWS\system32\msoc32.exe []
    "apizk.exe"=C:\WINDOWS\system32\apizk.exe []
    "wintu32.exe"=C:\WINDOWS\system32\wintu32.exe []
    "ipkv.exe"=C:\WINDOWS\system32\ipkv.exe []
    "netxb.exe"=C:\WINDOWS\system32\netxb.exe []
    "sysjs.exe"=C:\WINDOWS\sysjs.exe []
    "ieex.exe"=C:\WINDOWS\ieex.exe []
    "syslt.exe"=C:\WINDOWS\system32\syslt.exe []
    "ntyk32.exe"=C:\WINDOWS\system32\ntyk32.exe []
    "ieos.exe"=C:\WINDOWS\ieos.exe []
    "iefa32.exe"=C:\WINDOWS\system32\iefa32.exe []
    "ntct32.exe"=C:\WINDOWS\system32\ntct32.exe []
    "javadt.exe"=C:\WINDOWS\system32\javadt.exe []
    "sysdr.exe"=C:\WINDOWS\system32\sysdr.exe []
    "sdkao32.exe"=C:\WINDOWS\system32\sdkao32.exe []
    "netxe32.exe"=C:\WINDOWS\system32\netxe32.exe []
    "javayb.exe"=C:\WINDOWS\system32\javayb.exe []
    "d3br.exe"=C:\WINDOWS\system32\d3br.exe []
    "d3di.exe"=C:\WINDOWS\system32\d3di.exe []
    "addwz32.exe"=C:\WINDOWS\system32\addwz32.exe []
    "javaod.exe"=C:\WINDOWS\system32\javaod.exe []
    "addmc.exe"=C:\WINDOWS\system32\addmc.exe []
    "iett32.exe"=C:\WINDOWS\system32\iett32.exe []
    "d3gg32.exe"=C:\WINDOWS\system32\d3gg32.exe []
    "appyt32.exe"=C:\WINDOWS\system32\appyt32.exe []
    "atlbo.exe"=C:\WINDOWS\system32\atlbo.exe []
    "atlqu.exe"=C:\WINDOWS\system32\atlqu.exe []
    "winxc.exe"=C:\WINDOWS\system32\winxc.exe []
    "netcq32.exe"=C:\WINDOWS\system32\netcq32.exe []
    "ntik32.exe"=C:\WINDOWS\system32\ntik32.exe []
    "atlen.exe"=C:\WINDOWS\system32\atlen.exe []
    "mfcrd.exe"=C:\WINDOWS\system32\mfcrd.exe []
    "winah.exe"=C:\WINDOWS\system32\winah.exe []
    "msxd.exe"=C:\WINDOWS\system32\msxd.exe []
    "syset.exe"=C:\WINDOWS\syset.exe []
    "sysxw.exe"=C:\WINDOWS\sysxw.exe []
    "sdkzg32.exe"=C:\WINDOWS\sdkzg32.exe []
    "mfcjl.exe"=C:\WINDOWS\system32\mfcjl.exe []
    "mfcpt.exe"=C:\WINDOWS\system32\mfcpt.exe []
    "d3al32.exe"=C:\WINDOWS\system32\d3al32.exe []
    "sysqd32.exe"=C:\WINDOWS\system32\sysqd32.exe []
    "d3bo.exe"=C:\WINDOWS\system32\d3bo.exe []
    "javaea.exe"=C:\WINDOWS\system32\javaea.exe []
    "ntix32.exe"=C:\WINDOWS\system32\ntix32.exe []
    "LogitechCommunicationsManager"=C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe [2006-10-31 284184]
    "LogitechQuickCamRibbon"=C:\Program Files\Logitech\QuickCam10\QuickCam10.exe [2006-11-15 746520]
    "NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
    "ISUSScheduler"=C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe [2005-02-16 81920]
    "ISUSPM Startup"=c:\progra~1\fichie~1\instal~1\update~1\isuspm.exe [2004-07-27 221184]
    "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-07-19 78008]
    "WOOWATCH"=C:\PROGRA~1\Wanadoo\Watch.exe [2004-05-13 24576]
    "WOOTASKBARICON"=C:\PROGRA~1\Wanadoo\TaskbarIcon.exe [2004-05-13 49152]
    "CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2007-05-14 644696]
    "CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2007-04-03 1603152]
    "SSBkgdUpdate"=C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
    "OpwareSE4"=C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
    "LDM"=C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-02-19 67128]
    "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-07-29 68856]
    "SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]
    "msnmsgr"=C:\Program Files\MSN Messenger\msnmsgr.exe [2007-01-19 5674352]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adaptec DirectCD]
    C:\PROGRA~1\Adaptec\DirectCD\directcd.exe [2000-08-31 1126400]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\addbk32.exe]
    C:\WINDOWS\addbk32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adddw32.exe]
    C:\WINDOWS\adddw32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\addea32.exe]
    C:\WINDOWS\addea32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apihz32.exe]
    C:\WINDOWS\apihz32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apimu32.exe]
    C:\WINDOWS\apimu32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apiwb32.exe]
    C:\WINDOWS\apiwb32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apiwn32.exe]
    C:\WINDOWS\apiwn32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apixk.exe]
    C:\WINDOWS\apixk.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apizj32.exe]
    C:\WINDOWS\apizj32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\appdh.exe]
    C:\WINDOWS\appdh.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\appfx.exe]
    C:\WINDOWS\appfx.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\apphx.exe]
    C:\WINDOWS\apphx.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\appkn32.exe]
    C:\WINDOWS\appkn32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\appxv32.exe]
    C:\WINDOWS\appxv32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atldp.exe]
    C:\WINDOWS\atldp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atlih32.exe]
    C:\WINDOWS\atlih32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atlth.exe]
    C:\WINDOWS\atlth.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atlwp32.exe]
    C:\WINDOWS\atlwp32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDSwitchAgent]
    C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BeachLifeSetup.exe]
    C:\DOCUME~1\Patrick\MESDOC~1\P1D78~1.MOR\BEACHL~1.EXE /r []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe [2006-11-16 139264]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bruqbtbpep]
    c:\documents and settings\patrick\local settings\application data\bruqbtbpep.exe bruqbtbpep []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio]
    RunDll32 cmicnfg.cpl []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\crib.exe]
    C:\WINDOWS\crib.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\crnc.exe]
    C:\WINDOWS\crnc.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\crpl.exe]
    C:\WINDOWS\crpl.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D.tmp]
    C:\DOCUME~1\Patrick\LOCALS~1\Temp\D.tmp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D.tmp.exe]
    C:\DOCUME~1\Patrick\LOCALS~1\Temp\D.tmp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\d3fl32.exe]
    C:\WINDOWS\d3fl32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\d3sw.exe]
    C:\WINDOWS\d3sw.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXDllRegExe]
    dxdllreg.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E.tmp]
    C:\DOCUME~1\Patrick\LOCALS~1\Temp\E.tmp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E.tmp.exe]
    C:\DOCUME~1\Patrick\LOCALS~1\Temp\E.tmp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2003-06-26 212992]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    C:\Program Files\HP\HP Software Update\HPWuSchd.exe [2003-06-25 49152]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iebe32.exe]
    C:\WINDOWS\iebe32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ietv32.exe]
    C:\WINDOWS\ietv32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ieua32.exe]
    C:\WINDOWS\ieua32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ieuf.exe]
    C:\WINDOWS\ieuf.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ieuj32.exe]
    C:\WINDOWS\ieuj32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ievw.exe]
    C:\WINDOWS\ievw.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipbq32.exe]
    C:\WINDOWS\ipbq32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipgo32.exe]
    C:\WINDOWS\ipgo32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipjn.exe]
    C:\WINDOWS\ipjn.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipng.exe]
    C:\WINDOWS\ipng.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipnv32.exe]
    C:\WINDOWS\ipnv32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipqi.exe]
    C:\WINDOWS\ipqi.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ipzg32.exe]
    C:\WINDOWS\ipzg32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
    C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-07-27 221184]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\javafo32.exe]
    C:\WINDOWS\javafo32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\javaiw32.exe]
    C:\WINDOWS\javaiw32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\javapc32.exe]
    C:\WINDOWS\javapc32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\javasl.exe]
    C:\WINDOWS\javasl.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\javayr32.exe]
    C:\WINDOWS\javayr32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\javazk.exe]
    C:\WINDOWS\javazk.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    C:\WINDOWS\system32\dumprep 0 -k []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcim.exe]
    C:\WINDOWS\mfcim.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcmo32.exe]
    C:\WINDOWS\mfcmo32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcpo32.exe]
    C:\WINDOWS\mfcpo32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcwa32.exe]
    C:\WINDOWS\mfcwa32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcwf.exe]
    C:\WINDOWS\mfcwf.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcwu32.exe]
    C:\WINDOWS\mfcwu32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfcxv.exe]
    C:\WINDOWS\mfcxv.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msel.exe]
    C:\WINDOWS\msel.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msib32.exe]
    C:\WINDOWS\msib32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msji.exe]
    C:\WINDOWS\msji.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mspo.exe]
    C:\WINDOWS\mspo.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mssc.exe]
    C:\WINDOWS\mssc.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netkh32.exe]
    C:\WINDOWS\netkh32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netld.exe]
    C:\WINDOWS\netld.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netnu.exe]
    C:\WINDOWS\netnu.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netsr32.exe]
    C:\WINDOWS\netsr32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nettp.exe]
    C:\WINDOWS\nettp.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netzd32.exe]
    C:\WINDOWS\netzd32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntlj32.exe]
    C:\WINDOWS\ntlj32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntnk.exe]
    C:\WINDOWS\ntnk.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntnw32.exe]
    C:\WINDOWS\ntnw32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
    C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxWatchTray.exe [2006-02-14 163840]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sdkeh.exe]
    C:\WINDOWS\sdkeh.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sdksp32.exe]
    C:\WINDOWS\sdksp32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sdktk32.exe]
    C:\WINDOWS\sdktk32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
    C:\WINDOWS\SOUNDMAN.EXE [2004-02-09 65024]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware-Secure]
    C:\Documents and Settings\Patrick\Mes documents\Spyware-Secure\Spyware-Secure_trial.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\syszl32.exe]
    C:\WINDOWS\syszl32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\windp32.exe]
    C:\WINDOWS\windp32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winel32.exe]
    C:\WINDOWS\winel32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wingb32.exe]
    C:\WINDOWS\wingb32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winng32.exe]
    C:\WINDOWS\winng32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winrt.exe]
    C:\WINDOWS\winrt.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winug32.exe]
    C:\WINDOWS\winug32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winxh32.exe]
    C:\WINDOWS\winxh32.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winyq.exe]
    C:\WINDOWS\winyq.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WooCnxMon]
    C:\PROGRA~1\Wanadoo\CnxMon.exe [2004-05-13 24576]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
    C:\PROGRA~1\Wanadoo\TaskbarIcon.exe [2004-05-13 49152]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
    C:\PROGRA~1\Wanadoo\Watch.exe [2004-05-13 24576]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^DSLMON.lnk]
    C:\PROGRA~1\SAGEM\SAGEMF~1\dslmon.exe [2003-05-02 954475]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
    C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2003-07-07 233472]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
    C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE [2005-06-14 278528]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^MioSync.lnk]
    C:\PROGRA~1\MIOTEC~1\MioSync\mioSync.exe [2007-03-12 647168]

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnomlj]
    opnomlj.dll []

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
    "authentication packages"=msv1_0
    C:\WINDOWS\system32\ssqrs.dll

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=95000000

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "HonorAutoRunSetting"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\OXYFSTUJ\incredimail_install[1].exe"="C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\OXYFSTUJ\incredimail_install[1].exe:*:Enabled:IncrediMail Installer"
    "C:\Program Files\InterVideo\DVD7\WinDVD.exe"="C:\Program Files\InterVideo\DVD7\WinDVD.exe:*:D isabled:WinDVD"
    "C:\Program Files\Securitoo\av_fw\backweb\1044199\Program\backWeb-1044199.exe"="C:\Program Files\Securitoo\av_fw\backweb\1044199\Program\backWeb-1044199.exe:*:D isabled:backWeb-1044199"
    "C:\Program Files\IncrediMail\bin\IMApp.exe"="C:\Program Files\IncrediMail\bin\IMApp.exe:*:Enabled:IncrediMail"
    "C:\Program Files\IncrediMail\bin\IncMail.exe"="C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail"
    "C:\Program Files\IncrediMail\bin\ImpCnt.exe"="C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail"
    "C:\Program Files\eChanblard\emule.exe"="C:\Program Files\eChanblard\emule.exe:*:Enabled:eMule"
    "C:\Program Files\3D Groove\Alien X\AlienX.exe"="C:\Program Files\3D Groove\Alien X\AlienX.exe:*:D isabled:p owered by 3D Groove"
    "C:\Program Files\Livecom\Application\eConfv4\livecomp.exe"="C:\Program Files\Livecom\Application\eConfv4\livecomp.exe:*:Enabled:Livecom Player"
    "C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe"="C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe:*:Enabled:Livecom"
    "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\EconfV4\ftplayer.exe"="C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\EconfV4\ftplayer.exe:*:Enabled:Livecom Media"
    "C:\Program Files\MSN Messenger\msncall.exe"="C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
    "C:\Program Files\Team17\Worms Armageddon\wa.exe"="C:\Program Files\Team17\Worms Armageddon\wa.exe:*:Enabled:Worms Armageddon"
    "C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe"="C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:D isabled:Nero ShowTime"
    "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
    "C:\WINDOWS\system32\tlonvchj.exe"="C:\WINDOWS\system32\tlo"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe"="C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe:*:Enabled:Livecom"
    "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\EconfV4\ftplayer.exe"="C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\EconfV4\ftplayer.exe:*:Enabled:Livecom Media"
    "C:\Program Files\MSN Messenger\msncall.exe"="C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
    "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2aaebe20-5b83-11db-96bb-000ea638261d}]
    shell\AutoRun\command - G:\LaunchU3.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{357eca18-9037-11dc-9a30-000ea638261d}]
    shell\Auto\command - bittorrent.exe e
    shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{779a5fca-e061-11da-95a7-4d6564696130}]
    shell\AutoRun\command - G:\LaunchU3.exe


    ======List of files/folders created in the last 3 months======

    2009-03-01 21:35:16 ----D---- C:\Documents and Settings\All Users\Application Data\GameHouse
    2009-03-01 21:34:51 ----D---- C:\Documents and Settings\Patrick\Application Data\Zylom
    2009-03-01 21:34:35 ----D---- C:\Documents and Settings\All Users\Application Data\Zylom
    2009-03-01 21:33:49 ----D---- C:\Program Files\Zylom Games
    2009-03-01 17:40:30 ----D---- C:\Documents and Settings\Patrick\Application Data\Malwarebytes
    2009-03-01 17:40:14 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2009-03-01 17:40:13 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2009-03-01 16:59:46 ----A---- C:\cleannavi.txt
    2009-03-01 16:33:56 ----A---- C:\fixnavi.txt
    2009-03-01 16:32:20 ----D---- C:\Program Files\Navilog1
    2009-03-01 15:22:21 ----D---- C:\rsit
    2009-02-24 23:44:06 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
    2009-02-23 23:34:31 ----D---- C:\Documents and Settings\Patrick\Application Data\EleFun Games
    2009-02-16 22:43:01 ----D---- C:\Program Files\GamesBar
    2009-02-14 23:16:27 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
    2009-02-04 20:05:12 ----D---- C:\Documents and Settings\Patrick\Application Data\Canon
    2009-01-25 22:31:55 ----D---- C:\Documents and Settings\All Users\Application Data\InterAction studios
    2009-01-25 22:04:29 ----D---- C:\Documents and Settings\All Users\Application Data\GamesBar
    2009-01-25 17:52:01 ----D---- C:\Program Files\ClickImpots plus 2009
    2009-01-24 10:18:18 ----A---- C:\WINDOWS\MAXLINK.INI
    2009-01-24 10:18:06 ----D---- C:\Documents and Settings\Patrick\Application Data\ScanSoft
    2009-01-24 10:17:45 ----D---- C:\Program Files\Fichiers communs\ScanSoft Shared
    2009-01-24 10:17:45 ----D---- C:\Documents and Settings\All Users\Application Data\ScanSoft
    2009-01-24 10:16:52 ----D---- C:\Program Files\ScanSoft
    2009-01-24 10:16:51 ----SHD---- C:\Config.Msi
    2009-01-24 09:30:01 ----HD---- C:\Documents and Settings\All Users\Application Data\CanonBJ
    2009-01-24 09:29:37 ----A---- C:\WINDOWS\system32\CNMLM91.DLL
    2009-01-24 09:29:21 ----HD---- C:\WINDOWS\system32\CanonIJ Uninstaller Information
    2009-01-24 09:29:08 ----A---- C:\WINDOWS\system32\CNC970O.DLL
    2009-01-24 09:29:07 ----A---- C:\WINDOWS\system32\CNC970L.DLL
    2009-01-24 09:29:07 ----A---- C:\WINDOWS\system32\CNC970I.DLL
    2009-01-24 09:29:07 ----A---- C:\WINDOWS\system32\CNC970C.DLL
    2009-01-24 09:28:53 ----HD---- C:\Program Files\CanonBJ
    2009-01-24 09:28:39 ----A---- C:\WINDOWS\system32\CNMNPUI.DLL
    2009-01-24 09:28:39 ----A---- C:\WINDOWS\system32\CNMNPPM.DLL
    2009-01-21 20:48:46 ----A---- C:\WINDOWS\system32\ffJmpWeb.dll
    2009-01-21 20:48:43 ----D---- C:\Program Files\Wanadoo Messager
    2009-01-14 07:45:04 ----D---- C:\WINDOWS\system32\Adobe
    2009-01-13 21:26:47 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
    2009-01-10 12:56:16 ----D---- C:\Documents and Settings\Patrick\Application Data\Ancient Quest of Saqqarah__oberon
    2009-01-10 12:50:17 ----D---- C:\Program Files\Oberon Media
    2009-01-10 12:50:16 ----D---- C:\Program Files\orange
    2008-12-10 21:43:23 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
    2008-12-10 21:42:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
    2008-12-10 21:42:19 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
    2008-12-10 21:42:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$

    ======List of files/folders modified in the last 3 months======

    2009-03-02 14:33:49 ----D---- C:\WINDOWS\Prefetch
    2009-03-02 13:59:16 ----D---- C:\WINDOWS\Temp
    2009-03-02 13:52:43 ----D---- C:\Program Files\Wanadoo
    2009-03-02 13:44:57 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-03-01 21:34:52 ----D---- C:\Documents and Settings\Patrick\Application Data\Identities
    2009-03-01 21:33:49 ----RD---- C:\Program Files
    2009-03-01 19:54:34 ----D---- C:\TEMP
    2009-03-01 17:55:13 ----D---- C:\WINDOWS
    2009-03-01 17:40:20 ----D---- C:\WINDOWS\system32\drivers
    2009-03-01 17:39:22 ----D---- C:\WINDOWS\system32
    2009-03-01 17:08:35 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-03-01 10:26:41 ----SD---- C:\WINDOWS\Downloaded Program Files
    2009-02-28 18:41:13 ----D---- C:\WINDOWS\network diagnostic
    2009-02-28 09:22:49 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
    2009-02-25 22:45:19 ----A---- C:\WINDOWS\NeroDigital.ini
    2009-02-25 22:37:45 ----D---- C:\WINDOWS\Help
    2009-02-24 23:44:22 ----HD---- C:\WINDOWS\inf
    2009-02-24 23:44:13 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2009-02-24 22:09:09 ----HD---- C:\WINDOWS\$hf_mig$
    2009-02-16 07:42:30 ----D---- C:\Documents and Settings\Patrick\Application Data\U3
    2009-02-15 09:15:55 ----D---- C:\Documents and Settings\Patrick\Application Data\ArcSoft
    2009-02-14 23:16:30 ----A---- C:\WINDOWS\imsins.BAK
    2009-02-14 23:15:57 ----D---- C:\Program Files\Internet Explorer
    2009-02-14 23:15:43 ----D---- C:\WINDOWS\ie7updates
    2009-02-12 05:56:17 ----A---- C:\WINDOWS\system32\MRT.exe
    2009-01-25 22:48:18 ----D---- C:\WINDOWS\system32\config
    2009-01-25 22:48:05 ----D---- C:\WINDOWS\system32\wbem
    2009-01-25 22:48:05 ----D---- C:\WINDOWS\Registration
    2009-01-25 17:53:37 ----D---- C:\Documents and Settings\Patrick\Application Data\HARVEST S.A
    2009-01-25 17:52:02 ----HD---- C:\Program Files\InstallShield Installation Information
    2009-01-25 10:42:11 ----SHD---- C:\WINDOWS\Installer
    2009-01-24 10:18:08 ----D---- C:\WINDOWS\WinSxS
    2009-01-24 10:17:45 ----D---- C:\Program Files\Fichiers communs
    2009-01-24 10:14:42 ----D---- C:\Program Files\ArcSoft
    2009-01-24 10:12:58 ----D---- C:\Program Files\Canon
    2009-01-24 09:36:23 ----D---- C:\Program Files\Fichiers communs\Canon
    2009-01-24 09:30:29 ----D---- C:\WINDOWS\Media
    2009-01-24 09:29:19 ----D---- C:\WINDOWS\twain_32
    2009-01-19 16:35:33 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2009-01-19 16:30:33 ----D---- C:\Program Files\Spybot - Search & Destroy
    2009-01-16 21:15:42 ----A---- C:\WINDOWS\system32\mshtml.dll
    2009-01-10 12:50:37 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
    2008-12-28 19:49:28 ----D---- C:\Program Files\Google
    2008-12-28 18:52:06 ----D---- C:\Documents and Settings\All Users\Application Data\Google
    2008-12-20 23:47:04 ----A---- C:\WINDOWS\system32\wininet.dll
    2008-12-20 23:47:03 ----A---- C:\WINDOWS\system32\webcheck.dll
    2008-12-20 23:47:03 ----A---- C:\WINDOWS\system32\urlmon.dll
    2008-12-20 23:47:02 ----A---- C:\WINDOWS\system32\url.dll
    2008-12-20 23:47:02 ----A---- C:\WINDOWS\system32\pngfilt.dll
    2008-12-20 23:47:02 ----A---- C:\WINDOWS\system32\occache.dll
    2008-12-20 23:47:02 ----A---- C:\WINDOWS\system32\mstime.dll
    2008-12-20 23:47:01 ----A---- C:\WINDOWS\system32\msrating.dll
    2008-12-20 23:47:01 ----A---- C:\WINDOWS\system32\mshtmled.dll
    2008-12-20 23:46:57 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
    2008-12-20 23:46:56 ----A---- C:\WINDOWS\system32\msfeeds.dll
    2008-12-20 23:46:56 ----A---- C:\WINDOWS\system32\jsproxy.dll
    2008-12-20 23:46:54 ----A---- C:\WINDOWS\system32\iertutil.dll
    2008-12-20 23:46:54 ----A---- C:\WINDOWS\system32\iernonce.dll
    2008-12-20 23:46:54 ----A---- C:\WINDOWS\system32\ieframe.dll
    2008-12-20 23:46:50 ----A---- C:\WINDOWS\system32\iedkcs32.dll
    2008-12-20 23:46:50 ----A---- C:\WINDOWS\system32\ieapfltr.dll
    2008-12-20 23:46:49 ----A---- C:\WINDOWS\system32\ieaksie.dll
    2008-12-20 23:46:49 ----A---- C:\WINDOWS\system32\ieakeng.dll
    2008-12-20 23:46:49 ----A---- C:\WINDOWS\system32\icardie.dll
    2008-12-20 23:46:49 ----A---- C:\WINDOWS\system32\extmgr.dll
    2008-12-20 23:46:48 ----A---- C:\WINDOWS\system32\dxtrans.dll
    2008-12-20 23:46:48 ----A---- C:\WINDOWS\system32\dxtmsft.dll
    2008-12-20 23:46:48 ----A---- C:\WINDOWS\system32\advpack.dll
    2008-12-19 10:11:12 ----A---- C:\WINDOWS\system32\ie4uinit.exe
    2008-12-19 10:10:15 ----A---- C:\WINDOWS\system32\ieudinit.exe
    2008-12-19 06:23:56 ----A---- C:\WINDOWS\system32\ieakui.dll
    2008-12-10 19:24:06 ----D---- C:\Program Files\Fichiers communs\Symantec Shared
    2008-12-10 19:23:52 ----SD---- C:\WINDOWS\Tasks

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-07-19 26944]
    R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
    R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-07-19 42912]
    R1 Cdr4_2K;Cdr4_2K; C:\WINDOWS\system32\drivers\Cdr4_2K.sys [2008-03-23 52464]
    R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2005-11-03 2560]
    R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
    R1 pwd_2K;pwd_2K; C:\WINDOWS\system32\drivers\pwd_2K.sys [2000-08-31 50358]
    R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
    R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-07-19 94416]
    R2 CdaC15BA;CdaC15BA; \??\C:\WINDOWS\system32\drivers\CdaC15BA.SYS []
    R3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2003-03-27 127145]
    R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-12-11 391424]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-02-18 610988]
    R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-07-19 23152]
    R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2004-08-04 701440]
    R3 FilterService;UVC Filter Service; C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys [2006-11-10 21536]
    R3 LVcKap;Logitech AEC Driver; C:\WINDOWS\system32\DRIVERS\LVcKap.sys [2006-11-15 1678368]
    R3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys [2006-11-15 1962912]
    R3 lvpopflt;Logitech POP Suppression Filter; C:\WINDOWS\system32\DRIVERS\lvpopflt.sys [2006-11-10 1512224]
    R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\WINDOWS\system32\drivers\LVPr2Mon.sys [2006-11-15 24736]
    R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2006-11-10 40352]
    R3 LVUVC;Logitech QuickCam Pro 5000(UVC); C:\WINDOWS\system32\DRIVERS\lvuvc.sys [2006-11-10 1083680]
    R3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
    R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
    R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S1 Cdudf;Cdudf; C:\WINDOWS\system32\drivers\Cdudf.sys [2000-08-31 221504]
    S1 UdfReadr;UdfReadr; C:\WINDOWS\system32\drivers\UdfReadr.sys [2000-06-15 206368]
    S2 ADILOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2003-03-25 46455]
    S3 bdfdll;bdfdll; \??\C:\Program Files\Softwin\BitDefender9\bdfdll.sys []
    S3 catchme;catchme; \??\C:\DOCUME~1\Patrick\LOCALS~1\Temp\catchme.sys []
    S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
    S3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2004-02-20 815296]
    S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-08-11 51056]
    S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-08-11 16496]
    S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-08-11 21488]
    S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2000-08-31 16774]
    S3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
    S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
    S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
    S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
    S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
    S3 StillCam;Pilote d'appareil photo numérique série; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-08-23 6912]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
    S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
    S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
    S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-07-19 16056]
    R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-07-19 147640]
    R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2005-09-30 96341]
    R2 LVPrcSrv;Logitech Process Monitor; c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe [2006-11-15 109344]
    R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
    R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
    R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-07-19 250040]
    R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
    S2 LVSrvLauncher;LVSrvLauncher; C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe [2006-11-15 101152]
    S2 RoxLiveShare;LiveShare P2P Server; C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxLiveShare.exe [2006-02-14 233472]
    S2 RoxWatch;Roxio Hard Drive Watcher; C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxWatch.exe [2006-02-14 155648]
    S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
    S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-07-23 348344]
    S3 Boonty Games;Boonty Games; C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2007-02-17 69120]
    S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-28 137200]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
    S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
    S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2003-08-11 65795]
    S3 RoxMediaDB;RoxMediaDB; C:\Program Files\Fichiers communs\Roxio Shared\SharedCOM8\RoxMediaDB.exe [2006-02-14 864256]

    -----------------EOF-----------------
    m
    0
    l
    a c 267 8 Sécurité
    2 Mars 2009 15:52:14

    1/

  • Démarre Spybot, clique sur Mode, coche Mode avancé.
  • A gauche, clique sur Outils, puis sur Résident.
  • Décoche la case devant Résident "TeaTimer" :

  • Quitte Spybot.


    2/

  • Télécharge Ad-Remover (de Cyrildu17 / C_XX) sur ton Bureau.

    /!\ Déconnecte-toi et ferme toutes applications en cours /!\

  • Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
  • Double-clique sur le raccourci d'Ad-Remover situé sur ton Bureau.
    (Sous Vista, il faut cliquer droit sur le raccourci d'Ad-Remover et choisir Exécuter en tant qu'administrateur)
  • Au menu principal, choisis l'option A.
  • Poste le rapport qui apparaît à la fin (C:\Ad-report(date).log).

    (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

    Note : "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    m
    0
    l
    2 Mars 2009 18:41:46


    ------- LOGFILE OF AD-REMOVER 1.1.1.5 | ONLY XP/VISTA -------

    Updated by C_XX on 25/02/2009 at 20:30

    Start at: 18:36:02 | Lun 02/03/2009 | Boot mode: Normal Boot
    Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
    Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
    Computer Name: PAT
    Current User: Patrick - Administrator
    Drive(s):
    - C:\ (File System: NTFS)
    - E:\ (File System: NTFS)
    System Drive: C:\
    Windows Directory: C:\WINDOWS\
    System Directory: C:\WINDOWS\System32\

    --- Running Processes: 42

    +-----------------| Boonty/Boonty Games Elements Found:

    Service: Boonty Games
    .
    HKCR\boontybox
    HKCU\Software\Boonty
    HKLM\Software\Boonty
    HKLM\Software\Classes\boontybox
    HKLM\System\ControlSet001\Services\Boonty Games
    HKLM\System\ControlSet002\Services\Boonty Games
    HKLM\System\CurrentControlSet\Services\Boonty Games
    HKLM\System\ControlSet003\Services\Boonty Games
    .
    C:\Program Files\Fichiers communs\BOONTY Shared
    C:\Documents and Settings\All Users\Application Data\BOONTY

    +-----------------| Eorezo Elements Found:

    .

    +-----------------| Infected Poker Softwares Elements Found:

    .

    +-----------------| FunWebProducts/MyWay/MyWebSearch Elements Found:

    .
    .

    +-----------------| It's TV Elements Found:

    .

    +-----------------| Sweetim Elements Found:

    .

    +-----------------| Other Adwares Found:

    .
    HKLM\Software\Trymedia Systems
    .
    C:\Documents and Settings\Patrick\Cookies\patrick@atdmt[2].txt
    C:\Documents and Settings\Patrick\Cookies\patrick@bs.serving-sys[1].txt

    +-----------------| Added Scan:

    ---- Internet Explorer Version 7.0.5730.11 ----

    +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

    Search bar: hxxp://www.wanadoo.fr/go/page_recherche/
    Search Page: hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http
    Start page: hxxp://www.wanadoo.fr

    +-[HKEY_USERS\S-1-5-21-725345543-1844823847-682003330-1004\..\Internet Explorer\Main]

    Search bar: hxxp://www.wanadoo.fr/go/page_recherche/
    Search Page: hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http
    Start page: hxxp://www.wanadoo.fr

    +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

    Default_Page_URL: hxxp:blank
    Default_Search_URL: hxxp:blank
    Search bar: hxxp:blank
    Search Page: hxxp:blank
    Start page: hxxp:blank

    +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

    Tabs: hxxp://ieframe.dll/tabswelcome.htm

    +---------------------------------------------------------------------------+

    [~2510 Bytes] - C:\Ad-Report-Scan-02.03.2009.log

    - C:\Program Files\Ad-remover\TOOLS\BACKUP
    - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

    End at: 18:39:30 | 02/03/2009
    .
    +-----------------| E.O.F - 64 Lines
    .
    m
    0
    l
    a c 267 8 Sécurité
    2 Mars 2009 18:53:24

    /!\ Déconnecte-toi et ferme toutes applications en cours /!\

  • Double-clique sur le raccourci d'Ad-Remover pour le lancer.
    (Sous Vista, il faut cliquer droit sur le raccourci d'Ad-Remover et choisir Exécuter en tant qu'administrateur)

  • Au menu principal, choisis l'option B.

  • Coche A à l'écran de sélection :



  • Puis choisis S, le programme va travailler.

  • Poste le rapport qui apparaît à la fin (C:\Ad-report.log).

    /!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide /!\
    m
    0
    l
    2 Mars 2009 19:07:22


    ------- LOGFILE OF AD-REMOVER 1.1.1.5 | ONLY XP/VISTA -------

    Updated by C_XX on 25/02/2009 at 20:30

    *** LIMITED TO ***

    Boonty/BoontyGames
    Eorezo
    Infected Poker Softwares
    FunWebProduct/MyWay/MyWebSearch
    It's TV
    Sweetim
    Other Adwares

    ******************

    Start at: 18:56:02 | Lun 02/03/2009 | Boot mode: Normal Boot
    Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
    Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
    Computer Name: PAT
    Current User: Patrick - Administrator
    Drive(s):
    - C:\ (File System: NTFS)
    - E:\ (File System: NTFS)
    System Drive: C:\
    Windows Directory: C:\WINDOWS\
    System Directory: C:\WINDOWS\System32\

    --- Running Processes: 39

    (!) ---- IE start pages/Tabs reset

    +--------------------| Boonty/Boonty Games Elements Deleted :

    Service: "Boonty Games"
    .
    HKCR\boontybox
    HKCU\Software\Boonty
    HKLM\Software\Boonty
    HKLM\System\ControlSet002\Services\Boonty Games
    HKLM\System\ControlSet003\Services\Boonty Games
    .
    C:\Program Files\Fichiers communs\BOONTY Shared
    C:\Documents and Settings\All Users\Application Data\BOONTY

    +-----------------| Eorezo Elements Deleted :

    .

    +-----------------| Infected Poker Softwares Elements Deleted :

    .

    +-----------------| FunWebProducts/MyWay/MyWebSearch Elements Deleted :

    .
    .

    +-----------------| It's TV Elements Deleted :

    .

    +-----------------| Sweetim Elements Deleted :

    .

    +-----------------| Other Adwares Deleted:

    .
    HKLM\Software\Trymedia Systems
    .
    C:\Documents and Settings\Patrick\Cookies\patrick@atdmt[2].txt
    C:\Documents and Settings\Patrick\Cookies\patrick@bs.serving-sys[1].txt

    (!) ---- Temp files deleted.
    (!) ---- Recycle bin emptied in all drives.


    +-----------------| Added Scan :

    ---- Internet Explorer Version 7.0.5730.11 ----

    +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnh...
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
    Search Page: hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http
    Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnh...

    +-[HKEY_USERS\S-1-5-21-725345543-1844823847-682003330-1004\..\Internet Explorer\Main]

    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnh...
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
    Search Page: hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http
    Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnh...

    +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnh...
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Search bar: hxxp://search.msn.com/spbasic.htm
    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Start page: hxxp://fr.msn.com/

    +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

    Tabs: hxxp://ieframe.dll/tabswelcome.htm

    +---------------------------------------------------------------------------+

    [~3297 Bytes] - C:\Ad-Report-Clean-02.03.2009.log
    [~2731 Bytes] - C:\Ad-Report-Scan-02.03.2009.log

    - C:\Program Files\Ad-remover\TOOLS\BACKUP
    - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

    End at: 19:00:48 | 02/03/2009
    .
    +-----------------| E.O.F - 77 Lines
    .
    m
    0
    l
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS