> Tous les forumsSécurité

 analyse hijackthisSujet résolu
2 pages : [1] 2 ... Fin
Bas de la page Page Précédente Page Suivante 
Statut du sujet : RESOLU Imprimer
 philou83
  Posté le 21/07/2010 @ 16:48  
 Petit astucien

528 Messages

bonjour

mon PC commence à merder (ralentissement,programmes qui ne repondent plus,...........)

a l'aide SVP

voilà le rapport hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:41:05, on 21/07/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Visagesoft\eXPert PDF 6 Converter\vspdfprsrv.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10c.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_r3610&r=17360610d006pe495v145w4502t45o
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_r3610&r=17360610d006pe495v145w4502t45o
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_r3610&r=17360610d006pe495v145w4502t45o
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files (x86)\Visagesoft\eXPert PDF 6 Converter\vspdfprsrv.exe --background
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1279046332601
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} ("Ma-Config.com control) - http://www.ma-config.com/plugins/MaConfig_4_1_0_3.cab
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMSAccess - Unknown owner - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\Partner.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - Unknown owner - C:\Windows\System32\TuneUpDefragService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10378 bytes

merci d'avance

 
 Aller en bas de la page  
 
Publicité
 pear  Posté le 21/07/2010 à 17:47  
  Astucien


8679 Messages

Bonjour,

Télécharger sur le bureauOTM by OldTimer .
Double-clic sur OTM.exe pour le lancer.
Sous Vista,Clic droit sur le fichier ->Choisir Exécuter en tant qu' Administrateur
* Copiez /Collez les lignes ci dessous) en vert:
:Processes
partner
:Services
"partner service"
:Files
c:\program files\partner\partner.exe
:Reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Partner Service]

:Commands
[purity]
[emptytemp]
[Reboot]

Revenez dans OTM,
Clic droit sur la fenêtre "Paste Instructions for Items to be Moved" sous la barre jaune et choisir Coller(Paste).
* Click le bouton rouge Moveit!
* Fermez OTM
Votre Pc va redémarrer.
Rendez vous dans le dossier C:\_OTM\MovedFiles ,
ouvrez le dernier fichier .log
Copiez/collez en le contenu dans votre prochaine réponse

Rsit, comme Hijackthis, ne connait pas les OS 64 bits, d'où les "File Missing"

Lancez cet outil de diagnostic:

Téléchargez ZhpDiag de Coolman
Il ne nécessite aucune installation.
- Il peut être lancé depuis n'importe quelle unité de disque.
- Il peut être lancé d'une clé USB.

image
Cliquez sur le tournevis
Dans la fenêtre qui s'ouvre, cochez tout.
Clic sur la Loupe pour lancer le scan
Au bout d'un moment ,vous pouvez avoir à Accepter Sysinternal->I agree
Postez en le rapport qui apparait en cliquant l'appareil photo.

 Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 21/07/2010 à 18:58  
Petit astucien

528 Messages

re

ça commence mal impossible de OTM.exe

j'ai l'erreur 403 FORBIDDEN

c'est quoi ça????

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 Anonyme  Posté le 21/07/2010 à 19:10  
  Astucien

7453 Messages
philou83 a écrit :

re

ça commence mal impossible de OTM.exe

j'ai l'erreur 403 FORBIDDEN

c'est quoi ça????

Bonsoir.

attend le retour de pear

ce n'est pas de ta faute...le site de l'editeur oldtimer est inaccessible pour l'instant.

@+



Modifié par Anonyme le 21/07/2010 19:11
 Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 21/07/2010 à 19:42  
Petit astucien

528 Messages

ok je vais attendre

merci

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 pear  Posté le 22/07/2010 à 11:19  
  Astucien


8679 Messages

Bonjour,

Le site est en maintenance suite à une attaque.

Utilisez ceci:

www.itxassociates.com/OT-Tools/OTM.exe

 Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 
Publicité
 philou83  Posté le 22/07/2010 à 14:13  
Petit astucien

528 Messages

re

merci,pear pour l'astuce pour le telechargement de OTM dont voici le rapport

All processes killed
========== PROCESSES ==========
No active process named partner was found!
========== SERVICES/DRIVERS ==========
Error: No service named "partner service" was found to stop!
Service\Driver key "partner service" not found.
========== FILES ==========
File/Folder c:\program files\partner\partner.exe not found.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Partner Service\ deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrateur
->Temp folder emptied: 578979 bytes
->Temporary Internet Files folder emptied: 736519 bytes
->Flash cache emptied: 75 bytes

User: All Users

User: AppData

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32969 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: philou
->Temp folder emptied: 1597131 bytes
->Temporary Internet Files folder emptied: 7096947 bytes
->FireFox cache emptied: 42032428 bytes
->Flash cache emptied: 1145 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 4832400 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 100892 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50406 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 54,00 mb


OTM by OldTimer - Version 3.1.15.0 log created on 07222010_151946

Files moved on Reboot...
C:\Users\philou\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File C:\Users\philou\AppData\Local\Temp\~DF0C2607EA9365C6EA.TMP not found!
File C:\Users\philou\AppData\Local\Temp\~DF36C0841400E36770.TMP not found!
File C:\Users\philou\AppData\Local\Temp\~DF428BC5D777E76CEE.TMP not found!
File C:\Users\philou\AppData\Local\Temp\~DFAD7D39E4921CD2D6.TMP not found!
C:\Users\philou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\O5JJMIOY\ads[4].htm moved successfully.
C:\Users\philou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\O5JJMIOY\sujet[1].htm moved successfully.
C:\Users\philou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\A70ESIJ0\ads[4].htm moved successfully.
C:\Users\philou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4N5KZ6W9\ads[1].htm moved successfully.
C:\Users\philou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4N5KZ6W9\ads[2].htm moved successfully.
C:\Users\philou\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.

Registry entries deleted on Reboot...

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 22/07/2010 à 14:17  
Petit astucien

528 Messages

par contre je n'arrives pas à t'envoyer le rapport pour ZHPDiag

j'ai le message suivant:

Microsoft OLE DB Provider for ODBC Drivers

[MySQL][ODBC 5.1 Driver][mysqld-5.1.33-community]Data too long for column 'R_MESSAGE' at row 1

/envoi_info.asp, ligne 1321

erreur '80004005'
  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 pear  Posté le 22/07/2010 à 15:00  
  Astucien


8679 Messages

Essayez de poster le rapport en 2 fois.

 Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 22/07/2010 à 15:03  
Petit astucien

528 Messages

ok

premiere partie

Rapport de ZHPDiag v1.26.29 par Nicolas Coolman, Update du 21/07/2010
Run by philou at 22/07/2010 15:32:35
Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
Contact : nicolascoolman@yahoo.fr

---\\ Web Browser
MSIE: Internet Explorer v8.0.7600.16385
MFIE: Mozilla Firefox (3.6.6)

---\\ System Information
Platform : Windows 7 Home Premium (6.1.7600)
Processor: Intel64 Family 6 Model 28 Stepping 2, GenuineIntel
Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 1791 MB (32% free)
System drive C: has 55 GB (50%) free of 109 GB

---\\ Logged in mode
Computer Name: PHILOU-PC
User Name: philou
All Users Names: philou, HomeGroupUser$, Administrateur,
Unselected Option: None
Logged in as Administrator

---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 55 Go of 109 Go)
D:\ Hard drive, Flash drive, Thumb drive (Free 78 Go of 110 Go)
E:\ Hard drive, Flash drive, Thumb drive (Free 349 Go of 466 Go)
F:\ CD-ROM drive (Not Inserted)
H:\ CD-ROM drive (Not Inserted)
I:\ Hard drive, Flash drive, Thumb drive (Free 20 Go of 149 Go)


---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableTaskMgr: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableRegistryTools: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] NoDispScrSavPage: OK


---\\ Processus lancés
[MD5.5D61BE7DB55B026A5D61A3EED09D0EAD] - (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408]
[MD5.390679F7A217A5E73D756276C40AE887] - (.Safer-Networking Ltd. - System settings protector.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480]
[MD5.0C27193F356DC9403C6D4FC7103AA959] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files (x86)\Visagesoft\eXPert PDF 6 Converter\vspdfprsrv.exe [983040]
[MD5.CF4A0E2C240501C826977ACC5F0E8411] - (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [282792]
[MD5.2C32E3E596CFE660353753EABEFB0540] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe [673048]
[MD5.CEDF6D51B66006142B892BE96F8E5E18] - (.Google Inc. - Google Toolbar Broker.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe [304304]
[MD5.AE619F242F2CE340F3B33DDEAA88248D] - (.Adobe Systems, Inc. - Adobe Flash Player Helper 10.0 r32.) -- C:\Windows\SysWow64\Macromed\Flash\FlashUtil10c.exe [257440]
[MD5.CAB49391861142F93F514B3A8843DA07] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [481280]


---\\ Plugins de navigateurs Opera/Firefox(P1/P2)
P2 - FPN:Firefox Plugin Navigator . (.mozilla.org - Default Plug-in.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npnul32.dll
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape "9.3.3".) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
P2 - FPN: [HKLM] [@ma-config.com/HardwareDetection] - (.Cybelsoft - Plugin NPAPI Ma-Config.com.) -- C:\Program Files\ma-config.com\x86\nphardwaredetection.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.50524.0.) -- C:\Program Files (x86)\Microsoft Silverlight\4.0.50524.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8081.0709] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@nvidia.com/3DVision] - (.NVIDIA Corporation - NVIDIA 3D Vision plugin for Mozilla browsers.) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
P2 - FPN: [HKLM] [@nvidia.com/3DVisionStreaming] - (.NVIDIA Corporation - NVIDIA 3D Vision Streaming plugin for Mozilla browsers.) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=8] - (.Google Inc. - Google Update.) -- C:\Program Files (x86)\Google\Update\1.2.183.29\npGoogleOneClick8.dll


---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=userinit.exe
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe
F2 - REG:system.ini: VMApplet=C:\WINDOWS\system32\SystemPropertiesPerformance.exe


---\\ Pages de recherche d'Internet Explorer (R1)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


---\\ Internet Explorer URLSearchHook (R3)
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (8.00.7600.16385 (win7_rtm.090713-1255)) -- C:\Windows\SysWOW64\ieframe.dll


---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} . (.Safer Networking Limited - SBSD IE Protection.) -- C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll


---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll


---\\ Applications démarrées par registre & par dossier(O4)
O4 - HKLM\..\Run: [vspdfprsrv.exe] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files (x86)\Visagesoft\eXPert PDF 6 Converter\vspdfprsrv.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] . (.Safer-Networking Ltd. - System settings protector.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] . (.SUPERAntiSpyware.com - SUPERAntiSpyware Application.) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [vspdfprsrv.exe] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files (x86)\Visagesoft\eXPert PDF 6 Converter\vspdfprsrv.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKLM\..\policies\Explorer: [NoActiveDesktop] Data=1
O4 - HKLM\..\policies\Explorer: [NoActiveDesktopChanges] Data=1
O4 - HKLM\..\policies\Explorer: [ForceActiveDesktopOn] Data=0
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\Run: [mctadmin] C:\Windows\System32\mctadmin.exe (.not file.)
O4 - HKUS\S-1-5-20\..\Run: [mctadmin] C:\Windows\System32\mctadmin.exe (.not file.)


---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~2\MICROS~1\Office12\EXCEL.exe
O8 - Extra context menu item: Google Sidewiki... . (.Google Inc. - Google Toolbar for Internet Explorer.) -- C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll


---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} . (.not file.) - (.not file.)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~2\MICROS~1\Office12\REFBARH.ICO
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} . (.not file.) - (.not file.)


---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll


---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1279046332601
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} ("Ma-Config.com control) - http://www.ma-config.com/plugins/MaConfig_4_1_0_3.cab


---\\ Protocole additionnel et piratage de protocole (O18)
O18 - Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} . (.Belarc, Inc. - Belarc VoilaX Control.) -- C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll


---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - AppInit_DLLs: . (.Pas de propriétaire - Pas de description.) - (.not file.)


---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.


---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: SAS Core Service (!SASCORE) . (.SUPERAntiSpyware.com - Core Service.) - C:\Program Files\SUPERAntiSpyware\SASCORE64.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: GRegService (Greg_Service) . (.Acer Incorporated - Global Registration Service.) - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: NMSAccess (NMSAccess) . (.Pas de propriétaire - Pas de description.) - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
O23 - Service: NTI IScheduleSvc (NTI IScheduleSvc) . (.NewTech Infosystems, Inc. - Backup Manager Module.) - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\nvvsvc.exe
O23 - Service: C:\Windows\system32\samsrv.dll (SamSs) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\lsass.exe
O23 - Service: C:\Windows\system32\spoolsv.exe (Spooler) . (.Pas de propriétaire - Pas de description.) - C:\Windows\System32\spoolsv.exe
O23 - Service: C:\Windows\system32\sppsvc.exe (sppsvc) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\sppsvc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) . (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Updater Service (Updater Service) . (.Acer - Acer Update Service.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe


---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Maintenance en 1 clic.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Registry Reviver64-philou-Startup.job


---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Pas de propriétaire - Pas de description.) -- "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 10.0 r32.) -- C:\Windows\SysWow64\Macromed\Flash\Flash10c.ocx


---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: C:\Windows\system32\drivers\afd.sys (AFD) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: avipbb (avipbb) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\avipbb.sys
O41 - Driver: (blbdrive) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\blbdrive.sys
O41 - Driver: Pilote de CD-ROM (cdrom) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\system32\drivers\discache.sys (discache) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\discache.sys
O41 - Driver: Microsoft System Management BIOS Driver (mssmbios) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\mssmbios.sys
O41 - Driver: mwlPSDFilter (mwlPSDFilter) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
O41 - Driver: mwlPSDNServ (mwlPSDNServ) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
O41 - Driver: mwlPSDVDisk (mwlPSDVDisk) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
O41 - Driver: NetBIOS Interface (NetBIOS) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\netbios.sys
O41 - Driver: NetBT (NetBT) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\system32\drivers\nsiproxy.sys (nsiproxy) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\system32\drivers\pacer.sys (Psched) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\system32\wkssvc.dll (rdbss) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\system32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\system32\drivers\RDPENCDD.sys (RDPENCDD) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\system32\drivers\RdpRefMp.sys (RDPREFMP) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\rdprefmp.sys
O41 - Driver: SASDIFSV (SASDIFSV) . (.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASDIFSV64.SYS.) - C:\Program Files\SUPERAntiSpyware\SASDIFSV64.sys
O41 - Driver: SASKUTIL (SASKUTIL) . (.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASKUTIL64.SYS.) - C:\Program Files\SUPERAntiSpyware\SASKUTIL64.sys
O41 - Driver: Terminal Device Driver (TermDD) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\termdd.sys
O41 - Driver: truecrypt (truecrypt) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\truecrypt.sys
O41 - Driver: (VgaSave) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: Virtual WiFi Filter Driver (vwififlt) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\vwififlt.sys
O41 - Driver: WFP Lightweight Filter (WfpLwf) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\wfplwf.sys


---\\ Logiciels installés (O42)
O42 - Logiciel: 7-Zip 4.65 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: AGEIA PhysX v7.07.09 - (.AGEIA Technologies, Inc..) [HKLM]
O42 - Logiciel: Acer Arcade Deluxe - (.CyberLink Corp..) [HKLM]
O42 - Logiciel: Acer Backup Manager - (.NewTech Infosystems.) [HKLM]
O42 - Logiciel: Acer Registration - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: Acer ScreenSaver - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: Acer Updater - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: Acer eRecovery Management - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: Acrobat.com - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM]
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe Reader 9.3.3 MUI - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Advertising Center - (.Nero AG.) [HKLM]
O42 - Logiciel: Air Conflicts Single Player Demo - (.I wanna play.) [HKLM]
O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Auslogics Disk Defrag - (.Auslogics Software Pty Ltd.) [HKLM]
O42 - Logiciel: Avira AntiVir Personal - Free Antivirus - (.Avira GmbH.) [HKLM]
O42 - Logiciel: Backup Manager Advance - (.NewTech Infosystems.) [HKLM]
O42 - Logiciel: Belarc Advisor 8.1 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: CANAL+ pour Windows Media Center - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM]
O42 - Logiciel: CDBurnerXP - (.CDBurnerXP.) [HKLM]
O42 - Logiciel: Call of Duty - United Offensive Single Player Demo - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Call of Duty Single Player Demo - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Call of Duty(R) 2 Demo - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Call of Duty(R) 4 - Modern Warfare(TM) - (.Activision.) [HKLM]
O42 - Logiciel: Clean Virus MSN - (.AxBx.) [HKLM]
O42 - Logiciel: ClickImpôts first step 2010.3.016 - (.Harvest.) [HKLM]
O42 - Logiciel: Conseiller de mise à niveau vers Windows 7 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: CrystalDiskInfo 3.2.0 - (.Crystal Dew World.) [HKLM]
O42 - Logiciel: GRID - (.Codemasters.) [HKLM]
O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM]
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM]
O42 - Logiciel: Google Earth - (.Google.) [HKLM]
O42 - Logiciel: HDD Health v3.3 Beta - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Hotkey Utility - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: Identity Card - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: ImgBurn - (.LIGHTNING UK!.) [HKLM]
O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Internet TV pour Windows Media Center - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Line of Sight - Vietnam Demo - (.Infogrames.) [HKLM]
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM]
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM]
O42 - Logiciel: Medal of Honor Allied Assault Demo - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: MediaCoder x64 0.7.3.4685 - (.Broad Intelligence.) [HKLM]
O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM]
O42 - Logiciel: Microsoft Office Access MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Excel MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office InfoPath MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Outlook MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (German) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proofing (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM]
O42 - Logiciel: Microsoft Office Publisher MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Word MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Module de compatibilité pour Microsoft Office System 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Mozilla Firefox (3.6.6) - (.Mozilla.) [HKLM]
O42 - Logiciel: MyWinLocker - (.Egis Technology Inc..) [HKLM]
O42 - Logiciel: NVIDIA Stereoscopic 3D Driver - (.NVIDIA Corporation.) [HKLM]
O42 - Logiciel: Nero 9 Essentials - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero DiscSpeed - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero DiscSpeed Help - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero DriveSpeed - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero DriveSpeed Help - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero Express Help - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero InfoTool - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero InfoTool Help - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero Installer - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero Online Upgrade - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero StartSmart - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero StartSmart Help - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero StartSmart OEM - (.Nero AG.) [HKLM]
O42 - Logiciel: NeroExpress - (.Nero AG.) [HKLM]
O42 - Logiciel: OpenAL - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Ralink RT2860 Wireless LAN Card - (.Ralink.) [HKLM]
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM]
O42 - Logiciel: SIW version 2010.04.28 - (.Topala Software Solutions.) [HKLM]
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB982312) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB982331) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB982308) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Outlook 2007 (KB980376) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB982158) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Publisher 2007 (KB982124) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB982135) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB969613) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM]
O42 - Logiciel: Sniper Elite Demo - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Spybot - Search & Destroy - (.Safer Networking Limited.) [HKLM]
O42 - Logiciel: System Requirements Lab - (.Husdawg, LLC.) [HKLM]
O42 - Logiciel: Tidy Start Menu - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Tom Clancy's H.A.W.X - (.Ubisoft.) [HKLM]
O42 - Logiciel: TrueCrypt - (.TrueCrypt Foundation.) [HKLM]
O42 - Logiciel: TuneUp Utilities 2008 - (.TuneUp Software.) [HKLM]
O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM]
O42 - Logiciel: Update for Outlook 2007 Junk Email Filter (kb2202131) - (.Microsoft.) [HKLM]
O42 - Logiciel: Utilitaire d'identification du processeur Intel(R) - (.Intel Corporation.) [HKLM]
O42 - Logiciel: VLC media player 1.1.0 - (.VideoLAN.) [HKLM]
O42 - Logiciel: Welcome Center - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live FolderShare - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Movie Maker - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Media Center Add-in for Silverlight - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: eSobi v2 - (.esobi Inc..) [HKLM]
O42 - Logiciel: eXPert PDF 6 Converter - (.Visage Software.) [HKLM]
O42 - Logiciel: neroxml - (.Nero AG.) [HKLM]

---\\ HKCU & HKLM Software Keys
[HKCU\Software\2015]
[HKCU\Software\7-Zip]
[HKCU\Software\Acer]
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\Software\Conduit]
[HKCU\Software\AppDataLow\Software\Google]
[HKCU\Software\AppDataLow\Software\Messenger_Plus_Live]
[HKCU\Software\AppDataLow\Software\Microsoft]
[HKCU\Software\AppDataLow\Software\Monitored]
[HKCU\Software\AppDataLow\Software\settings]
[HKCU\Software\AppDataLow\Software]
[HKCU\Software\AppDataLow]
[HKCU\Software\Auslogics]
[HKCU\Software\Avira]
[HKCU\Software\Belarc]
[HKCU\Software\Canneverbe Limited]
[HKCU\Software\Classes]
[HKCU\Software\CyberLink]
[HKCU\Software\DT Soft]
[HKCU\Software\EA Games]
[HKCU\Software\Google]
[HKCU\Software\HARVEST S.A.]
[HKCU\Software\IGA]
[HKCU\Software\IM Providers]
[HKCU\Software\ImgBurn]
[HKCU\Software\JEDI-VCL]
[HKCU\Software\Ledadu]
[HKCU\Software\Local AppWizard-Generated Applications]
[HKCU\Software\Macromedia]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MyDefrag]
[HKCU\Software\NVIDIA Corporation]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\ODBC]
[HKCU\Software\OEM]
[HKCU\Software\OrdinarySoft]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\Realtek]
[HKCU\Software\RonyaSoft]
[HKCU\Software\SUPERAntiSpyware.com]
[HKCU\Software\Safer Networking Limited]
[HKCU\Software\SecuROM]
[HKCU\Software\SeriousBit]
[HKCU\Software\Smart Soft]
[HKCU\Software\Softonic]
[HKCU\Software\System Requirements Lab]
[HKCU\Software\TuneUp]
[HKCU\Software\Ubisoft]
[HKCU\Software\Visage Software]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\Wow6432Node]
[HKCU\Software\cybelsoft]
[HKCU\Software\eSobi]
[HKLM\Software\AGEIA Technologies]
[HKLM\Software\Acer Incorporated]
[HKLM\Software\Activision]
[HKLM\Software\Adobe]
[HKLM\Software\America Online]
[HKLM\Software\Audible]
[HKLM\Software\Avira]
[HKLM\Software\Belarc]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Codemasters]
[HKLM\Software\CyberLink]
[HKLM\Software\DT Soft]
[HKLM\Software\EA GAMES]
[HKLM\Software\EgisTec Egis Software Update]
[HKLM\Software\Electronic Arts]
[HKLM\Software\Google]
[HKLM\Software\HaaliMkx]
[HKLM\Software\InstallShield]
[HKLM\Software\Intel Corporation]
[HKLM\Software\Intel]
[HKLM\Software\KOCH Media]
[HKLM\Software\Khronos]
[HKLM\Software\MC2]
[HKLM\Software\Macromedia]
[HKLM\Software\McAfeeInstaller]
[HKLM\Software\MediaCoder]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\NVIDIA Corporation]
[HKLM\Software\Nero]
[HKLM\Software\NewTech Infosystems]
[HKLM\Software\ODBC]
[HKLM\Software\OEM]
[HKLM\Software\OldTimer Tools]
[HKLM\Software\Patchou]
[HKLM\Software\Policies]
[HKLM\Software\Ralink]
[HKLM\Software\Realtek Semiconductor Corp.]
[HKLM\Software\Realtek]
[HKLM\Software\Rebellion]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Safer Networking Limited]
[HKLM\Software\TrendMicro]
[HKLM\Software\TuneUp]
[HKLM\Software\Ubisoft]
[HKLM\Software\Uniblue]
[HKLM\Software\Vid_0471]
[HKLM\Software\VideoLAN]
[HKLM\Software\Vietnamd]
[HKLM\Software\Visage Software]
[HKLM\Software\Wise Solutions]
[HKLM\Software\X-AVCSD]
[HKLM\Software\cybelsoft]
[HKLM\Software\mozilla.org]

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 22/07/2010 à 15:07  
Petit astucien

528 Messages

ok tu avais raison

une fois de plus je suppose!!!!

voilà la deuxième partie et il en aura une troisième

---\\ Contenu des dossiers Program Files (O43)
O43 - CFD:Common File Directory ----D- C:\Program Files\Acer
O43 - CFD:Common File Directory ----D- C:\Program Files\Acer Accessory Store
O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files
O43 - CFD:Common File Directory ----D- C:\Program Files\DVD Maker
O43 - CFD:Common File Directory ----D- C:\Program Files\EnhanceMySe7en
O43 - CFD:Common File Directory -SH-D- C:\Program Files\Fichiers communs
O43 - CFD:Common File Directory ----D- C:\Program Files\Free PDF to Word Converter
O43 - CFD:Common File Directory ----D- C:\Program Files\Google
O43 - CFD:Common File Directory ----D- C:\Program Files\Internet Explorer
O43 - CFD:Common File Directory ----D- C:\Program Files\ma-config.com
O43 - CFD:Common File Directory ----D- C:\Program Files\MediaCoder
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Baseline Security Analyzer 2
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Fix it Center
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Games
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Office
O43 - CFD:Common File Directory ----D- C:\Program Files\MSBuild
O43 - CFD:Common File Directory ----D- C:\Program Files\NVIDIA Corporation
O43 - CFD:Common File Directory ----D- C:\Program Files\Realtek
O43 - CFD:Common File Directory ----D- C:\Program Files\Reference Assemblies
O43 - CFD:Common File Directory ----D- C:\Program Files\SUPERAntiSpyware
O43 - CFD:Common File Directory ----D- C:\Program Files\TrueCrypt
O43 - CFD:Common File Directory --H-D- C:\Program Files\Uninstall Information
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Defender
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Journal
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Mail
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Media Player
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows NT
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Photo Viewer
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Portable Devices
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Sidebar
O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\Microsoft Shared
O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\Services
O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\SpeechEngines
O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\System
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\7-Zip
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Acer
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Acer Arcade Deluxe
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Activision
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Adobe
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\AGEIA Technologies
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Air Conflicts Demo
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Auslogics
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Avira
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\AxBx
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Belarc
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Call of Duty Single Player Demo
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Call of Duty United Offensive Single Player Demo
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\CCleaner
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\CDBurnerXP
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\ClickImpots first step 2010
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Codemasters
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\CrystalDiskInfo
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Cyberlink
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\DAEMON Tools Lite
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\EA GAMES
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\EgisTec
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\EgisTec Egis Software Update
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\eSobi
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Google
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\HDD Health
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\ImgBurn
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Infogrames
O43 - CFD:Common File Directory --H-D- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Intel Corporation
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Internet Explorer
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\ma-config.com
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Malwarebytes' Anti-Malware
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\MC2
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft Office
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft Visual Studio
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft Visual Studio 8
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft Works
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft.NET
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\MSBuild
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\MSXML 4.0
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Nero
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\NewTech Infosystems
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\NVIDIA Corporation
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\OpenAL
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Realtek
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Reference Assemblies
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\SIW
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Spybot - Search & Destroy
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\SystemRequirementsLab
O43 - CFD:Common File Directory --H-D- C:\Program Files (x86)\Temp
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Tidy Start Menu
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Trend Micro
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\TuneUp Utilities 2008
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Ubisoft
O43 - CFD:Common File Directory --H-D- C:\Program Files (x86)\Uninstall Information
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\VideoLAN
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Visagesoft
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Defender
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Live
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Live SkyDrive
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Mail
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Media Player
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows NT
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Sidebar
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\ZHPDiag
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Adobe AIR
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\DESIGNER
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\EgisTec
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Nero
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Oberon Media
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Services
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\System
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Windows Live
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Wise Installation Wizard


---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.A5F2F6A24BE5FCCE32602E47D81B9758] - 22/07/2010 - 15:31:33 --HA- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [15792]
O44 - LFC:[MD5.A5F2F6A24BE5FCCE32602E47D81B9758] - 22/07/2010 - 15:31:33 --HA- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [15792]
O44 - LFC:[MD5.00000000000000000000000000000000] - 22/07/2010 - 15:28:02 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\WindowsUpdate.log [1392122]
O44 - LFC:[MD5.AC849B99E032F4017BB1CE37934DD4AF] - 22/07/2010 - 15:23:25 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\setupact.log [112]
O44 - LFC:[MD5.FECB5A97E3397F65D32F2D2BF9A3E960] - 22/07/2010 - 15:23:20 -S-A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.F3613E3306859C8754060FD58C520692] - 22/07/2010 - 14:42:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\PerfStringBackup.INI [1549700]
O44 - LFC:[MD5.3D5A741F9365F564897AB5127BB6DAFF] - 22/07/2010 - 14:42:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\perfc009.dat [106190]
O44 - LFC:[MD5.A2DE8FAD57124F84E42A452C077581EC] - 22/07/2010 - 14:42:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\perfc00C.dat [130548]
O44 - LFC:[MD5.B205320ED8B3B5B96D82210F11CC7401] - 22/07/2010 - 14:42:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\perfh009.dat [615810]
O44 - LFC:[MD5.6A1F361F58F46AD9A18BF315BB597B73] - 22/07/2010 - 14:42:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\perfh00C.dat [704242]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 22/07/2010 - 08:19:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\setuperr.log [0]
O44 - LFC:[MD5.70BE044105DC7F9E393D7735BB7BB443] - 22/07/2010 - 08:19:14 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\PFRO.log [392]
O44 - LFC:[MD5.815372073DA85B2098A37DED84083C8A] - 18/07/2010 - 11:14:48 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\_MSRSTRT.EXE [2560]
O44 - LFC:[MD5.FD8D5FCDFDC5B82B5B121F9FFA466891] - 15/07/2010 - 12:10:59 --HA- . (.Pas de propriétaire - Pas de description.) -- C:\sys13026.bin [111]
O44 - LFC:[MD5.515E4684008E955DE0C81E6A7AEA1C2A] - 12/07/2010 - 21:55:38 ---A- . (.InstallShield Software Corporation - InstallShield® unInstaller.) -- C:\Windows\IsUninst.exe [306688]
O44 - LFC:[MD5.C98FB52FE64DC1BC063AE0285E538198] - 10/07/2010 - 22:05:06 ---A- . (.Ralink Technology, Corp. - Ralink Extensions DLL.) -- C:\Windows\SysNative\RAIHV.dll [1119008]
O44 - LFC:[MD5.397BEB20D714482E34DDD358B1012861] - 10/07/2010 - 20:17:38 ---A- . (.Khronos Group - OpenCL Client DLL.) -- C:\Windows\SysNative\OpenCL.dll [65128]
O44 - LFC:[MD5.397BEB20D714482E34DDD358B1012861] - 10/07/2010 - 20:17:38 ---A- . (.Khronos Group - OpenCL Client DLL.) -- C:\Windows\System32\OpenCL.dll [56936]
O44 - LFC:[MD5.09A7171731E1C52B479DBCC088DE1826] - 10/07/2010 - 20:17:34 ---A- . (.NVIDIA Corporation - NVIDIA Compatible OpenGL ICD.) -- C:\Windows\SysNative\nvoglv64.dll [21662312]
O44 - LFC:[MD5.80BC4DF8485FA3DBB222C86946AE90E1] - 10/07/2010 - 20:17:33 ---A- . (.NVIDIA Corporation - NVIDIA Video Decoder MFT, Version 257.21.) -- C:\Windows\SysNative\nvdecodemft.dll [405608]
O44 - LFC:[MD5.80BC4DF8485FA3DBB222C86946AE90E1] - 10/07/2010 - 20:17:33 ---A- . (.NVIDIA Corporation - NVIDIA Video Decoder MFT, Version 257.21.) -- C:\Windows\System32\nvdecodemft.dll [332392]
O44 - LFC:[MD5.5176F27EA1058CE9ACFE71EA603DE59F] - 10/07/2010 - 20:17:33 ---A- . (.NVIDIA Corporation - NVIDIA Video Encoder MFT, Version 257.21.) -- C:\Windows\SysNative\nvencodemft.dll [3184744]
O44 - LFC:[MD5.5176F27EA1058CE9ACFE71EA603DE59F] - 10/07/2010 - 20:17:33 ---A- . (.NVIDIA Corporation - NVIDIA Video Encoder MFT, Version 257.21.) -- C:\Windows\System32\nvencodemft.dll [2890856]
O44 - LFC:[MD5.C0EE2A390C5697E5AA4B042AE04C4435] - 10/07/2010 - 20:17:29 ---A- . (.NVIDIA Corporation - NVIDIA CUDA Video Decode API, Version 257.2.) -- C:\Windows\SysNative\nvcuvid.dll [2291304]
O44 - LFC:[MD5.C0EE2A390C5697E5AA4B042AE04C4435] - 10/07/2010 - 20:17:29 ---A- . (.NVIDIA Corporation - NVIDIA CUDA Video Decode API, Version 257.2.) -- C:\Windows\System32\nvcuvid.dll [2145896]
O44 - LFC:[MD5.D4E6F282C7B5DA716B48FB9ED3219BAF] - 10/07/2010 - 20:17:29 ---A- . (.NVIDIA Corporation - NVIDIA CUDA Video Encoder, Version 257.21.) -- C:\Windows\SysNative\nvcuvenc.dll [2867816]
O44 - LFC:[MD5.D4E6F282C7B5DA716B48FB9ED3219BAF] - 10/07/2010 - 20:17:29 ---A- . (.NVIDIA Corporation - NVIDIA CUDA Video Encoder, Version 257.21.) -- C:\Windows\System32\nvcuvenc.dll [2632296]
O44 - LFC:[MD5.FCF7EA1DEDA449F26982D3BC202B7CFD] - 10/07/2010 - 20:17:26 ---A- . (.NVIDIA Corporation - NVIDIA Compatible CUDA Driver, Version 257..) -- C:\Windows\SysNative\nvcuda.dll [6065768]
O44 - LFC:[MD5.FCF7EA1DEDA449F26982D3BC202B7CFD] - 10/07/2010 - 20:17:26 ---A- . (.NVIDIA Corporation - NVIDIA Compatible CUDA Driver, Version 257..) -- C:\Windows\System32\nvcuda.dll [4513384]
O44 - LFC:[MD5.6BA49A4D4D8C3F777BB18EAC0550F7A6] - 10/07/2010 - 20:17:26 ---A- . (.NVIDIA Corporation - NVIDIA Compatible Compiler, Version 257.21.) -- C:\Windows\System32\nvcompiler.dll [10263144]
O44 - LFC:[MD5.6BA49A4D4D8C3F777BB18EAC0550F7A6] - 10/07/2010 - 20:17:25 ---A- . (.NVIDIA Corporation - NVIDIA Compatible Compiler, Version 257.21.) -- C:\Windows\SysNative\nvcompiler.dll [14511720]
O44 - LFC:[MD5.66DB8B6A6B119CDDE85BCE76A65BB2B0] - 10/07/2010 - 20:17:25 ---A- . (.NVIDIA Corporation - NVIDIA Driver CoInstaller.) -- C:\Windows\SysNative\nvcod.dll [255592]
O44 - LFC:[MD5.66DB8B6A6B119CDDE85BCE76A65BB2B0] - 10/07/2010 - 20:17:25 ---A- . (.NVIDIA Corporation - NVIDIA Driver CoInstaller.) -- C:\Windows\SysNative\nvcod1921.dll [255592]
O44 - LFC:[MD5.87ED84FF3DD18F7744CF7D45D3ACDA56] - 10/07/2010 - 19:09:43 ---A- . (.Windows (R) Codename Longhorn DDK provider - NVAPO.) -- C:\Windows\SysNative\nvapo64v.dll [62976]
O44 - LFC:[MD5.FD1F4BEC1A99EC8AB2D4431A16589DF9] - 10/07/2010 - 19:09:42 ---A- . (.NVIDIA Corporation - NVIDIA Uninstaller Utility.) -- C:\Windows\SysNative\nvuhda6.exe [541216]
O44 - LFC:[MD5.D84EF4631835C908C0A051EC125433C1] - 10/07/2010 - 19:09:41 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\nvhda.nvu [1481]
O44 - LFC:[MD5.DE00239530F39B2305EE0DFC0E92DF82] - 07/07/2010 - 10:17:14 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\Empty.ico [15867]
O44 - LFC:[MD5.2B86E520BAE90CFBD0B96474F3822B6D] - 07/07/2010 - 09:49:30 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\vsmon1.dll [23040]
O44 - LFC:[MD5.5A8832D860238033A9DF15890CD5A382] - 05/07/2010 - 23:44:47 ---A- . (.Creative Labs - OpenAL32.) -- C:\Windows\SysNative\wrap_oal.dll [466456]
O44 - LFC:[MD5.ADA2FC9FBB9DF9F342A8FA86FED2971F] - 05/07/2010 - 23:44:47 ---A- . (.Portions (C) Creative Labs Inc. and NVIDIA - Standard OpenAL(TM) Implementation.) -- C:\Windows\SysNative\OpenAL32.dll [121880]
O44 - LFC:[MD5.5A8832D860238033A9DF15890CD5A382] - 05/07/2010 - 23:44:46 ---A- . (.Creative Labs - OpenAL32.) -- C:\Windows\System32\wrap_oal.dll [444952]
O44 - LFC:[MD5.ADA2FC9FBB9DF9F342A8FA86FED2971F] - 05/07/2010 - 23:44:46 ---A- . (.Portions (C) Creative Labs Inc. and NVIDIA - Standard OpenAL(TM) Implementation.) -- C:\Windows\System32\OpenAL32.dll [109080]
O44 - LFC:[MD5.849946AD8A164ED1460B2C5F3D957500] - 05/07/2010 - 21:52:26 ---A- . (.J.C. Kessels - MyDefrag Script Interpreter.) -- C:\Windows\SysNative\MyDefragScreenSaver_v4.3.1.exe [1147392]
O44 - LFC:[MD5.FB76AB9B8C9869882EA8EFF133FB0F37] - 05/07/2010 - 21:52:26 ---A- . (.J.C. Kessels - MyDefrag Script Interpreter.) -- C:\Windows\SysNative\MyDefragScreenSaver_v4.3.1.scr [485376]
O44 - LFC:[MD5.E15B492959DFABC12AA4CA070B38F21A] - 05/07/2010 - 09:17:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\binkw32.dll [286208]
O44 - LFC:[MD5.BFAC0E7CFF0F71B0E43D4D36A722AB89] - 03/07/2010 - 15:46:18 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\FNTCACHE.DAT [425776]
O44 - LFC:[MD5.767EE8126468D91C5119F25714D78DAF] - 03/07/2010 - 14:14:32 ---A- . (.Microsoft Corporation - Bibliothèque d'assistance au déploiement de.) -- C:\Windows\SysNative\dfshim.dll [1942856]
O44 - LFC:[MD5.767EE8126468D91C5119F25714D78DAF] - 03/07/2010 - 14:14:32 ---A- . (.Microsoft Corporation - Bibliothèque d'assistance au déploiement de.) -- C:\Windows\System32\dfshim.dll [1130824]
O44 - LFC:[MD5.5DB2E96514C8722BDB60F0C8EA0CF865] - 01/07/2010 - 14:46:47 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\win.ini [510]
O44 - LFC:[MD5.3C9EBFF68D64090FCCB9971ACA6D9E18] - 01/07/2010 - 14:12:29 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\SysNative\atmfd.dll [366080]
O44 - LFC:[MD5.3C9EBFF68D64090FCCB9971ACA6D9E18] - 01/07/2010 - 14:12:29 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\System32\atmfd.dll [293888]
O44 - LFC:[MD5.628D70483747CB6F70A2372937865A13] - 01/07/2010 - 14:12:28 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\SysNative\atmlib.dll [46080]
O44 - LFC:[MD5.628D70483747CB6F70A2372937865A13] - 01/07/2010 - 14:12:28 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\System32\atmlib.dll [34304]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 29/06/2010 - 22:39:12 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\nsreg.dat [0]
O44 - LFC:[MD5.E57B778208C783D8DEBAB320C16A1B82] - 29/06/2010 - 16:41:40 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\drivers\StarOpen.sys [7168]
O44 - LFC:[MD5.D4DFBB1B1883E538BAAAEE67C3B3B7D3] - 29/06/2010 - 16:37:31 ---A- . (.TuneUp Software GmbH - TuneUp WinLogon Extension.) -- C:\Windows\System32\authuitu.dll [16640]
O44 - LFC:[MD5.5320997505594BD848F2B3F654716B62] - 29/06/2010 - 16:37:29 ---A- . (.TuneUp Software GmbH - TuneUp Drive Defrag-Dienst.) -- C:\Windows\SysNative\TuneUpDefragService.exe [425216]
O44 - LFC:[MD5.0DE7675CA390B9A755A85F00AB39A48F] - 29/06/2010 - 16:37:29 ---A- . (.TuneUp Software GmbH - TuneUp Theme Extension.) -- C:\Windows\System32\uxtuneup.dll [29440]
O44 - LFC:[MD5.D4DFBB1B1883E538BAAAEE67C3B3B7D3] - 29/06/2010 - 16:37:29 ---A- . (.TuneUp Software GmbH - TuneUp WinLogon Extension.) -- C:\Windows\SysNative\authuitu.dll [19712]
O44 - LFC:[MD5.0DE7675CA390B9A755A85F00AB39A48F] - 29/06/2010 - 16:37:27 ---A- . (.TuneUp Software GmbH - TuneUp Theme Extension.) -- C:\Windows\SysNative\uxtuneup.dll [36096]
O44 - LFC:[MD5.8B9AAD376688C8F2DD7853EE4E540563] - 29/06/2010 - 16:22:02 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\cod2demo.ini [291]
O44 - LFC:[MD5.EDCB1DFDE6D5935856EB25517B633DAC] - 29/06/2010 - 16:19:54 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\license.rtf [53560]
O44 - LFC:[MD5.EDCB1DFDE6D5935856EB25517B633DAC] - 29/06/2010 - 16:19:54 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\license.rtf [53560]
O44 - LFC:[MD5.21752FFB8445EC8BBC1A60CC36C5BF1F] - 29/06/2010 - 16:01:48 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\game.ini [331]
O44 - LFC:[MD5.954AD7BE8D3E69BE52A4DE969128E41A] - 29/06/2010 - 14:23:24 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\oem_Get_OS_Language.log [341]


---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:Last File Created Prefetch 20/07/2010 - 23:58:47 ---A- C:\Windows\Prefetch\Layout.ini
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 08:20:28 ---A- C:\Windows\Prefetch\AgAppLaunch.db
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 08:20:39 ---A- C:\Windows\Prefetch\NTOSBOOT-B00DFAAD.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 08:20:45 ---A- C:\Windows\Prefetch\RUNDLL32.EXE-0D53616E.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 08:20:51 ---A- C:\Windows\Prefetch\SEARCHINDEXER.EXE-1CF42BC6.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 08:21:00 ---A- C:\Windows\Prefetch\SVCHOST.EXE-27D91624.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 08:27:37 ---A- C:\Windows\Prefetch\CONHOST.EXE-0C6456FB.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 08:27:38 ---A- C:\Windows\Prefetch\WSQMCONS.EXE-4048402C.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 08:28:04 ---A- C:\Windows\Prefetch\DLLHOST.EXE-576CF6B2.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 08:31:10 ---A- C:\Windows\Prefetch\AVCENTER.EXE-3575FD94.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 08:31:34 ---A- C:\Windows\Prefetch\DLLHOST.EXE-D9DCD0F3.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 08:32:16 ---A- C:\Windows\Prefetch\AVSCAN.EXE-3D14B848.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 08:32:45 ---A- C:\Windows\Prefetch\WERMGR.EXE-F439C551.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 13:29:34 ---A- C:\Windows\Prefetch\AgCx_SC1.db.trx
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 13:30:38 ---A- C:\Windows\Prefetch\AgCx_SC1.db
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 14:09:10 ---A- C:\Windows\Prefetch\GOOGLECRASHHANDLER.EXE-72B9F98E.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 14:29:37 ---A- C:\Windows\Prefetch\ALU.EXE-1C41B4D0.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 14:44:14 ---A- C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-3348865734-695653469-4227206278-1001.db
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 14:44:14 ---A- C:\Windows\Prefetch\AgGlUAD_S-1-5-21-3348865734-695653469-4227206278-1001.db
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 14:47:54 ---A- C:\Windows\Prefetch\GOOGLETOOLBARMANAGER_223E2B8E-C2175D85.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 14:47:54 ---A- C:\Windows\Prefetch\GOOGLEUPDATERSERVICE.EXE-A6285BB5.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 14:54:52 ---A- C:\Windows\Prefetch\VSSVC.EXE-6C8F0C66.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 14:54:59 ---A- C:\Windows\Prefetch\SVCHOST.EXE-6A249820.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 14:59:23 ---A- C:\Windows\Prefetch\DLLHOST.EXE-63B92852.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:01:46 ---A- C:\Windows\Prefetch\OTM.EXE-D19E9001.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:02:50 ---A- C:\Windows\Prefetch\AgRobust.db
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:02:51 ---A- C:\Windows\Prefetch\AgGlFaultHistory.db
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:02:51 ---A- C:\Windows\Prefetch\AgGlGlobalHistory.db
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:02:52 ---A- C:\Windows\Prefetch\AgGlFgAppHistory.db
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:06:19 ---A- C:\Windows\Prefetch\TASKHOST.EXE-A0F5E092.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:09:02 ---A- C:\Windows\Prefetch\GOOGLEUPDATE.EXE-0E1E7B82.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:09:03 ---A- C:\Windows\Prefetch\TASKENG.EXE-35FA9C06.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:21:18 ---A- C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:21:36 ---A- C:\Windows\Prefetch\PfSvPerfStats.bin
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:13 ---A- C:\Windows\Prefetch\NOTEPAD.EXE-D096D5BE.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:22 ---A- C:\Windows\Prefetch\GOOGLETOOLBARNOTIFIER.EXE-969E73DB.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:22 ---A- C:\Windows\Prefetch\RAVCPL64.EXE-4BB80510.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:22 ---A- C:\Windows\Prefetch\SUPERANTISPYWARE.EXE-35E59EB7.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:22 ---A- C:\Windows\Prefetch\TEATIMER.EXE-81948FA1.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:25 ---A- C:\Windows\Prefetch\RUNDLL32.EXE-F632BF02.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:27 ---A- C:\Windows\Prefetch\MSNMSGR.EXE-0A3C12F9.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:28 ---A- C:\Windows\Prefetch\SIDEBAR.EXE-BA7094F6.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:31 ---A- C:\Windows\Prefetch\ADOBEARM.EXE-F9223367.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:37 ---A- C:\Windows\Prefetch\VSPDFPRSRV.EXE-B345DCE1.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:38 ---A- C:\Windows\Prefetch\READER_SL.EXE-7918B6C3.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:42 ---A- C:\Windows\Prefetch\AVGNT.EXE-39B0C714.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:58 ---A- C:\Windows\Prefetch\WMPNSCFG.EXE-18FC9E64.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:25:59 ---A- C:\Windows\Prefetch\SSUPDATE64.EXE-4300FC12.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:26:06 ---A- C:\Windows\Prefetch\WMPNETWK.EXE-F6E20E14.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:26:24 ---A- C:\Windows\Prefetch\MSCORSVW.EXE-8CE1A322.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:26:25 ---A- C:\Windows\Prefetch\MSCORSVW.EXE-16B291C4.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:26:35 ---A- C:\Windows\Prefetch\SPLWOW64.EXE-57576C25.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:26:37 ---A- C:\Windows\Prefetch\SPPSVC.EXE-96070FE0.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:26:38 ---A- C:\Windows\Prefetch\AVWSC.EXE-FC348DC0.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:27:26 ---A- C:\Windows\Prefetch\WMIPRVSE.EXE-E8B8DD29.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:27:36 ---A- C:\Windows\Prefetch\GOOGLETOOLBARUSER_32.EXE-66EEE4D2.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:27:36 ---A- C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-766EFF52.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:28:15 ---A- C:\Windows\Prefetch\FLASHUTIL10C.EXE-F9EB315F.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:28:17 ---A- C:\Windows\Prefetch\WMIADAP.EXE-BB21CD77.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:28:49 ---A- C:\Windows\Prefetch\SDCLT.EXE-94EAE077.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:31:28 ---A- C:\Windows\Prefetch\ZHPDIAG_1.26.TMP-371B2514.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:31:36 ---A- C:\Windows\Prefetch\AUDIODG.EXE-AB22E9A6.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:31:36 ---A- C:\Windows\Prefetch\CONSENT.EXE-40419367.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:31:41 ---A- C:\Windows\Prefetch\DLLHOST.EXE-6389524F.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:31:46 ---A- C:\Windows\Prefetch\ZHPDIAG_1.26.EXE-9E0C9B82.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:31:47 ---A- C:\Windows\Prefetch\ZHPDIAG_1.26.TMP-BE139D30.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:31:57 ---A- C:\Windows\Prefetch\DLLHOST.EXE-4B6CB38A.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:32:00 ---A- C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-44162447.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:32:00 ---A- C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-69C456C3.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:32:02 ---A- C:\Windows\Prefetch\ZHPDIAG.EXE-6A1D0894.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:32:52 ---A- C:\Windows\Prefetch\SVCHOST.EXE-6E1A6101.pf
O45 - LFCP:Last File Created Prefetch 22/07/2010 - 15:34:52 ---A- C:\Windows\Prefetch\IEXPLORE.EXE-A033F7A0.pf


---\\ Déni du service (Local Security Authority) (LSA) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll


---\\ MountPoints2 Shell Key (MPSK) (O51)
O51 - MPSK:{26b97aaa-8378-11df-b659-bd7f7328e851}\Shell\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- F:\setup\rsrc\Autorun.exe (.not file.)
O51 - MPSK:{3a0081e0-84f7-11df-a409-bd3cf8f3e840}\Shell\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- H:\autorun.exe (.not file.)
O51 - MPSK:{811efe95-83a9-11df-9c4c-806e6f6e6963}\Shell\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- G:\setup\rsrc\Autorun.exe (.not file.)


---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\SysWOW64\l3codeca.acm" . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll
O52 - TDSD: \drivers.desc\"C:\Windows\SysWOW64\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Pas de propriétaire - Pas de description.) -- (.not file.)


---\\ Microsoft Control Security Providers (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - "SecurityProviders"=credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - "SecurityProviders"=credssp.dll


---\\ Microsoft Windows Policies System (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0


---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\Policies\Explorer] - "NoActiveDesktop"=1
O56 - MWPE:[HKLM\...\Policies\Explorer] - "NoActiveDesktopChanges"=1
O56 - MWPE:[HKLM\...\Policies\Explorer] - "ForceActiveDesktopOn"=0

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 
Publicité
 philou83  Posté le 22/07/2010 à 15:09  
Petit astucien

528 Messages

et la troisieme

---\\ Liste des Drivers Système (SDL) (O58)
O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 05:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\system32\drivers\adp94xx.sys
O58 - SDL:[MD5.597F78224EE9224EA1A13D6350CED962] - 14/07/2009 - 05:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\system32\drivers\adpahci.sys
O58 - SDL:[MD5.E109549C90F62FB570B9540C4B148E54] - 14/07/2009 - 05:52:21 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\system32\drivers\adpu320.sys
O58 - SDL:[MD5.5812713A477A3AD7363C7438CA2EE038] - 14/07/2009 - 05:52:21 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\system32\drivers\aliide.sys
O58 - SDL:[MD5.7A4B413614C055935567CF88A9734D38] - 14/07/2009 - 05:52:21 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\system32\drivers\amdsata.sys
O58 - SDL:[MD5.F67F933E79241ED32FF46A4F29B5120B] - 14/07/2009 - 05:52:20 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows -.) -- C:\Windows\system32\drivers\amdsbs.sys
O58 - SDL:[MD5.B4AD0CACBAB298671DD6F6EF7E20679D] - 14/07/2009 - 05:52:21 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\system32\drivers\amdxata.sys
O58 - SDL:[MD5.C484F8CEB1717C540242531DB7845C4E] - 14/07/2009 - 05:52:21 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\system32\drivers\arc.sys
O58 - SDL:[MD5.019AF6924AEFE7839F61C830227FE79C] - 14/07/2009 - 05:52:21 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\system32\drivers\arcsas.sys
O58 - SDL:[MD5.5D4529AC4156E16BEDB01441AE0CF984] - 08/07/2009 - 13:49:16 ---A- . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driver.) -- C:\Windows\system32\drivers\athrx.sys
O58 - SDL:[MD5.ED2B23707F19CCC1B2A4382B05D31481] - 16/02/2010 - 14:24:00 ---A- . (.Avira GmbH - Avira Minifilter Driver.) -- C:\Windows\system32\drivers\avgntflt.sys
O58 - SDL:[MD5.C98FA6E5AD0E857D22716BD2B8B1F399] - 02/03/2010 - 13:35:01 ---A- . (.Avira GmbH - Avira Driver for Security Enhancement.) -- C:\Windows\system32\drivers\avipbb.sys
O58 - SDL:[MD5.B5ACE6968304A3900EEB1EBFD9622DF2] - 11/06/2009 - 00:34:23 ---A- . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) -- C:\Windows\system32\drivers\b57nd60a.sys
O58 - SDL:[MD5.F09EEE9EDC320B5E1501F749FDE686C8] - 11/06/2009 - 00:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\system32\drivers\BrFiltLo.sys
O58 - SDL:[MD5.B114D3098E9BDB8BEA8B053685831BE6] - 11/06/2009 - 00:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\system32\drivers\BrFiltUp.sys
O58 - SDL:[MD5.43BEA8D483BF1870F018E2D02E06A5BD] - 14/07/2009 - 05:19:07 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\system32\drivers\BrSerId.sys
O58 - SDL:[MD5.A6ECA2151B08A09CACECA35C07F05B42] - 11/06/2009 - 00:41:10 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\system32\drivers\BrSerWdm.sys
O58 - SDL:[MD5.B79968002C277E869CF38BD22CD61524] - 11/06/2009 - 00:41:10 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\system32\drivers\BrUsbMdm.sys
O58 - SDL:[MD5.A87528880231C54E75EA7A44943B38BF] - 11/06/2009 - 00:41:10 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\system32\drivers\BrUsbSer.sys
O58 - SDL:[MD5.3E5B191307609F7514148C6832BB0842] - 11/06/2009 - 00:34:28 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\system32\drivers\bxvbda.sys
O58 - SDL:[MD5.E19D3F095812725D88F9001985B94EDD] - 14/07/2009 - 05:52:31 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\cmdide.sys
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 05:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\system32\drivers\elxstor.sys
O58 - SDL:[MD5.DC5D737F51BE844D8C82C695EB17372F] - 11/06/2009 - 00:34:33 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\system32\drivers\evbda.sys
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 11/06/2009 - 00:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\system32\drivers\hcw85cir.sys
O58 - SDL:[MD5.0886D440058F203EBA0E1825E4355914] - 14/07/2009 - 05:47:48 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\system32\drivers\HpSAMD.sys
O58 - SDL:[MD5.D83EFB6FD45DF9D55E9A1AFC63640D50] - 14/07/2009 - 05:48:04 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\system32\drivers\iaStorV.sys
O58 - SDL:[MD5.5C18831C61933628F5BB0EA2675B9D21] - 14/07/2009 - 05:48:04 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\system32\drivers\iirsp.sys
O58 - SDL:[MD5.1A93E54EB0ECE102495A51266DCDB6A6] - 14/07/2009 - 05:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_fc.sys
O58 - SDL:[MD5.1047184A9FDC8BDBFF857175875EE810] - 14/07/2009 - 05:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas.sys
O58 - SDL:[MD5.30F5C0DE1EE8B5BC9306C1F0E4A75F93] - 14/07/2009 - 05:48:04 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas2.sys
O58 - SDL:[MD5.0504EACAFF0D3C8AED161C4B0D369D4A] - 14/07/2009 - 05:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_scsi.sys
O58 - SDL:[MD5.E330051CCE41EB4522E5DCEBC15ADCEA] - 29/04/2010 - 15:39:28 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\system32\drivers\mbam.sys
O58 - SDL:[MD5.A55805F747C6EDB6A9080D7C633BD0F4] - 14/07/2009 - 05:48:04 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for.) -- C:\Windows\system32\drivers\megasas.sys
O58 - SDL:[MD5.BAF74CE0072480C3B6B7C13B2A94D6B3] - 14/07/2009 - 05:48:04 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\system32\drivers\MegaSR.sys
O58 - SDL:[MD5.6FFECC25B39DC7652A0CEC0ADA9DB589] - 02/06/2009 - 15:15:30 ---A- . (.Egis Technology Inc. - PSD Filter Driver.) -- C:\Windows\system32\drivers\mwlPSDFilter.sys
O58 - SDL:[MD5.0BEFE32CA56D6EE89D58175725596A85] - 02/06/2009 - 15:15:30 ---A- . (.Egis Technology Inc. - MyWinLocker PSD Named Pipe Driver.) -- C:\Windows\system32\drivers\mwlPSDNserv.sys
O58 - SDL:[MD5.D43BC633B8660463E446E28E14A51262] - 02/06/2009 - 15:15:30 ---A- . (.Egis Technology Inc. - MyWinLocker PSD Virtual Disk Driver.) -- C:\Windows\system32\drivers\mwlPSDVDisk.sys
O58 - SDL:[MD5.254AF6DF67EAFA8C6E0AA0D316487673] - 12/10/2009 - 08:42:24 ---A- . (.Ralink Technology, Corp. - Ralink 802.11 Wireless Adapter Driver.) -- C:\Windows\system32\drivers\netr28x.sys
O58 - SDL:[MD5.77889813BE4D166CDAB78DDBA990DA92] - 14/07/2009 - 05:48:26 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\system32\drivers\nfrd960.sys
O58 - SDL:[MD5.64DDD0DEE976302F4BD93E5EFCC2F013] - 06/05/2009 - 03:46:08 ---A- . (.NewTech Infosystems, Inc. - NTI CD-ROM Filter Driver.) -- C:\Windows\system32\drivers\NTIDrvr.sys
O58 - SDL:[MD5.AD37248BD442D41C9A896E53EB8A85EE] - 22/08/2009 - 00:24:02 ---A- . (.NVIDIA Corporation - NVIDIA HDMI Audio Driver.) -- C:\Windows\system32\drivers\nvhda64v.sys
O58 - SDL:[MD5.2B9FD17492FBD799726369F2DB3E4827] - 08/06/2010 - 03:58:00 ---A- . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 257.21.) -- C:\Windows\system32\drivers\nvlddmkm.sys
O58 - SDL:[MD5.A85B4F2EF3A7304A5399EF0526423040] - 11/06/2009 - 00:35:35 ---A- . (.NVIDIA Corporation - NVIDIA MCP Networking Function Driver..) -- C:\Windows\system32\drivers\nvm62x64.sys
O58 - SDL:[MD5.0AA2A6AAE14BDF0BEA29056EE759B200] - 01/07/2009 - 08:20:56 ---A- . (.NVIDIA Corporation - NVIDIA MCP Networking Function Driver..) -- C:\Windows\system32\drivers\nvmf6264.sys
O58 - SDL:[MD5.3E38712941E9BB4DDBEE00AFFE3FED3D] - 14/07/2009 - 05:48:27 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\system32\drivers\nvraid.sys
O58 - SDL:[MD5.E58D81FB8616D0CB55C1E36AA0B213C9] - 28/06/2009 - 20:36:44 ---A- . (.NVIDIA Corporation - NVIDIA nForce(TM) SMU Microcontroller Driver.) -- C:\Windows\system32\drivers\nvsmu.sys
O58 - SDL:[MD5.477DC4D6DEB99BE37084C9AC6D013DA1] - 14/07/2009 - 05:45:45 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor.sys
O58 - SDL:[MD5.1E45F96342429D63DC30E0D9117DA3D8] - 21/09/2009 - 09:45:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor64.sys
O58 - SDL:[MD5.A53A15A11EBFD21077463EE2C7AFEEF0] - 14/07/2009 - 05:45:46 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\system32\drivers\ql2300.sys
O58 - SDL:[MD5.4F6D12B51DE1AAEFF7DC58C4D75423C8] - 14/07/2009 - 05:45:45 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\system32\drivers\ql40xx.sys
O58 - SDL:[MD5.BC64B75E8E0A0B8982AB773483164E72] - 20/07/2009 - 14:52:38 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\Windows\system32\drivers\RTKVHD64.sys
O58 - SDL:[MD5.3EA8A16169C26AFBEB544E0E48421186] - 11/06/2009 - 00:37:19 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\system32\drivers\secdrv.sys
O58 - SDL:[MD5.843CAF1E5FDE1FFD5FF768F23A51E2E1] - 14/07/2009 - 05:45:45 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\system32\drivers\sisraid2.sys
O58 - SDL:[MD5.6A6C106D42E9FFFF8B9FCB4F754F6DA4] - 14/07/2009 - 05:45:46 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\system32\drivers\sisraid4.sys
O58 - SDL:[MD5.00000000000000000000000000000000] - 29/06/2010 - 23:50:46 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\drivers\sptd.sys
O58 - SDL:[MD5.E57B778208C783D8DEBAB320C16A1B82] - 12/11/2009 - 14:48:56 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\drivers\StarOpen.sys
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 05:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\system32\drivers\stexstor.sys
O58 - SDL:[MD5.C4238AF5AAF167C3E5113F98F5427A0B] - 20/07/2010 - 18:29:58 ---A- . (.TrueCrypt Foundation - TrueCrypt Driver.) -- C:\Windows\system32\drivers\truecrypt.sys
O58 - SDL:[MD5.2E22C1FD397A5A9FFEF55E9D1FC96C00] - 06/05/2009 - 03:46:08 ---A- . (.NewTech Infosystems Corporation - NTI CDROM Filter Driver.) -- C:\Windows\system32\drivers\UBHelper.sys
O58 - SDL:[MD5.E7E39FC335904E95B4DC831842146623] - 25/06/2010 - 15:32:30 ---A- . (.Oracle Corporation - VirtualBox Support Driver.) -- C:\Windows\system32\drivers\VBoxDrv.sys
O58 - SDL:[MD5.82A6CB9C68E42C1088318EB8824D6F89] - 25/06/2010 - 15:32:34 ---A- . (.Oracle Corporation - VirtualBox Host-Only Network Adapter Driver.) -- C:\Windows\system32\drivers\VBoxNetAdp.sys
O58 - SDL:[MD5.1257BB5B21C8003AA52389C7788D0E10] - 25/06/2010 - 15:32:32 ---A- . (.Oracle Corporation - VirtualBox USB Monitor Driver.) -- C:\Windows\system32\drivers\VBoxUSBMon.sys
O58 - SDL:[MD5.E5689D93FFE4E5D66C0178761240DD54] - 14/07/2009 - 05:45:55 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\viaide.sys
O58 - SDL:[MD5.5E2016EA6EBACA03C04FEAC5F330D997] - 14/07/2009 - 05:45:55 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\system32\drivers\vsmraid.sys
O58 - SDL:[MD5.323860EC84BB332B613530D904380A4D] - 11/05/2009 - 12:49:28 ---A- . (.AVIRA GmbH - Avira AntiVir File Filter Driver.) -- C:\Windows\SysWOW64\drivers\avgntdd.sys
O58 - SDL:[MD5.7F8283EA8284DFDE226E3262BED8C92A] - 11/05/2009 - 12:49:28 ---A- . (.AVIRA GmbH - Avira Antivir File Filter Driver Manager.) -- C:\Windows\SysWOW64\drivers\avgntmgr.sys
O58 - SDL:[MD5.C7DD7D9739785BD3A6B8499EEC1DEE7E] - 29/04/2010 - 15:39:38 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\SysWOW64\drivers\mbamswissarmy.sys
O58 - SDL:[MD5.F92254B0BCFCD10CAAC7BCCC7CB7F467] - 12/11/2009 - 14:48:56 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysWOW64\drivers\StarOpen.sys


---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC:Last File Created 19/07/2010 - 01:38:36 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-18-2010( 11-18-16 ).SDB [5535]
O61 - LFC:Last File Created 19/07/2010 - 08:17:03 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-19-2010( 8-17-3 ).463.SDB [1194]
O61 - LFC:Last File Created 19/07/2010 - 09:17:46 ---A- C:\Users\philou\AppData\Roaming\Auslogics\Disk Defrag\Reports\Disk_Defrag_Report.html [13557]
O61 - LFC:Last File Created 19/07/2010 - 09:18:03 ---A- C:\Users\philou\AppData\Roaming\Auslogics\Disk Defrag\Reports\Disk_Defrag_Report.xml [6698]
O61 - LFC:Last File Created 19/07/2010 - 15:09:10 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-19-2010( 8-17-58 ).SDB [5534]
O61 - LFC:Last File Created 19/07/2010 - 17:26:12 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-19-2010( 17-26-12 ).498.SDB [1554]
O61 - LFC:Last File Created 19/07/2010 - 17:53:45 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.000\results.xsl [49097]
O61 - LFC:Last File Created 19/07/2010 - 17:54:07 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.000\NetworkDiagnostics.0.debugreport.xml [3504]
O61 - LFC:Last File Created 19/07/2010 - 17:54:08 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.000\ResultReport.xml [38039]
O61 - LFC:Last File Created 19/07/2010 - 17:54:08 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.000\results.xml [256]
O61 - LFC:Last File Created 19/07/2010 - 17:55:20 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.001\72ACC0F3-9289-475A-96EE-7192E3CC6ABA.Diagnose.0.etl [327680]
O61 - LFC:Last File Created 19/07/2010 - 17:55:24 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.001\NetworkConfiguration.cab [1411]
O61 - LFC:Last File Created 19/07/2010 - 17:55:47 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.001\72ACC0F3-9289-475A-96EE-7192E3CC6ABA.Repair.1.etl [196608]
O61 - LFC:Last File Created 19/07/2010 - 17:55:53 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.001\72ACC0F3-9289-475A-96EE-7192E3CC6ABA.Verify.2.etl [262144]
O61 - LFC:Last File Created 19/07/2010 - 17:55:53 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.001\NetworkDiagnostics.0.debugreport.xml [77815]
O61 - LFC:Last File Created 19/07/2010 - 17:55:54 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.001\results.xsl [49097]
O61 - LFC:Last File Created 19/07/2010 - 18:14:31 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.001\NetworkDiagnostics.1.debugreport.xml [68005]
O61 - LFC:Last File Created 19/07/2010 - 18:14:31 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.001\ResultReport.xml [53031]
O61 - LFC:Last File Created 19/07/2010 - 18:14:31 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010071913.001\results.xml [256]
O61 - LFC:Last File Created 19/07/2010 - 21:36:13 ---A- C:\Users\Public\NTUSER.DAT [262144]
O61 - LFC:Last File Created 19/07/2010 - 21:36:13 -SHA- C:\Users\Public\NTUSER.DAT.LOG1 [5120]
O61 - LFC:Last File Created 20/07/2010 - 01:48:45 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-19-2010( 17-27-5 ).SDB [5534]
O61 - LFC:Last File Created 20/07/2010 - 11:00:46 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-20-2010( 11-0-46 ).555.SDB [1298]
O61 - LFC:Last File Created 20/07/2010 - 11:05:32 ---A- C:\Users\philou\AppData\Local\Google\Toolbar Cache\6.5.708.1000\fr\translate_languages.json.content [1481]
O61 - LFC:Last File Created 20/07/2010 - 14:16:08 ---A- C:\Users\philou\AppData\Roaming\Microsoft\Office\PowerP12.pip [1468]
O61 - LFC:Last File Created 20/07/2010 - 14:39:06 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072010.000\results.xsl [49097]
O61 - LFC:Last File Created 20/07/2010 - 14:39:30 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072010.000\NetworkDiagnostics.0.debugreport.xml [4130]
O61 - LFC:Last File Created 20/07/2010 - 14:39:30 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072010.000\ResultReport.xml [38039]
O61 - LFC:Last File Created 20/07/2010 - 14:39:30 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072010.000\results.xml [256]
O61 - LFC:Last File Created 20/07/2010 - 14:55:38 ---A- C:\Users\philou\AppData\Roaming\TuneUp Software\TuneUp Utilities\Backups\00000005.rcb [28716]
O61 - LFC:Last File Created 20/07/2010 - 17:46:38 ---A- C:\Users\philou\AppData\Roaming\Microsoft\Office\Word12.pip [1684]
O61 - LFC:Last File Created 20/07/2010 - 18:52:10 ---A- C:\Users\philou\AppData\Roaming\Tidy Start Menu\backup\Start Menu before use Tidy Start Menu.xml [16430]
O61 - LFC:Last File Created 20/07/2010 - 18:54:08 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-20-2010( 11-1-12 ).SDB [5534]
O61 - LFC:Last File Created 20/07/2010 - 18:54:13 ---A- C:\Users\philou\AppData\Roaming\TrueCrypt\Configuration.xml [2519]
O61 - LFC:Last File Created 20/07/2010 - 21:05:30 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLIST.DB [28272992]
O61 - LFC:Last File Created 20/07/2010 - 21:06:15 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLISTRELATED.DB [1482589]
O61 - LFC:Last File Created 20/07/2010 - 22:50:20 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-20-2010( 22-50-20 ).81.SDB [1450]
O61 - LFC:Last File Created 21/07/2010 - 00:53:56 ---A- C:\Users\philou\AppData\Roaming\SeriousBit\EnhanceMySe7en\ffexcl.dtw [10912]
O61 - LFC:Last File Created 21/07/2010 - 00:58:41 ---A- C:\Users\philou\Documents\cc_20100721_005834.reg [6410]
O61 - LFC:Last File Created 21/07/2010 - 01:03:41 ---A- C:\Users\philou\AppData\Roaming\TuneUp Software\TuneUp Utilities\Backups\00000006.rcb [564]
O61 - LFC:Last File Created 21/07/2010 - 01:04:41 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.000\81BF9929-A186-4598-86A2-F874157CB4C6.Diagnose.0.etl [262144]
O61 - LFC:Last File Created 21/07/2010 - 01:04:45 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.000\NetworkConfiguration.cab [1411]
O61 - LFC:Last File Created 21/07/2010 - 01:04:59 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.000\81BF9929-A186-4598-86A2-F874157CB4C6.Repair.1.etl [196608]
O61 - LFC:Last File Created 21/07/2010 - 01:05:14 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.000\81BF9929-A186-4598-86A2-F874157CB4C6.Verify.2.etl [196608]
O61 - LFC:Last File Created 21/07/2010 - 01:05:18 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.000\9F742310-B8B5-43D2-8FD3-2855895E3675.Diagnose.3.etl [262144]
O61 - LFC:Last File Created 21/07/2010 - 01:05:19 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.000\NetworkDiagnostics.0.debugreport.xml [79776]
O61 - LFC:Last File Created 21/07/2010 - 01:05:40 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.000\NetworkDiagnostics.1.debugreport.xml [73995]
O61 - LFC:Last File Created 21/07/2010 - 01:05:41 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.000\results.xsl [49097]
O61 - LFC:Last File Created 21/07/2010 - 01:05:56 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.000\NetworkDiagnostics.2.debugreport.xml [73018]
O61 - LFC:Last File Created 21/07/2010 - 01:05:56 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.000\ResultReport.xml [53864]
O61 - LFC:Last File Created 21/07/2010 - 01:05:56 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.000\results.xml [371]
O61 - LFC:Last File Created 21/07/2010 - 01:06:22 ---A- C:\Users\philou\AppData\Local\Diagnostics\1612347604\2010072021.000\results.xsl [49097]
O61 - LFC:Last File Created 21/07/2010 - 01:06:38 ---A- C:\Users\philou\AppData\Local\Diagnostics\1612347604\2010072021.000\190579EF-8636-4AA4-A3F4-8E004047B748.Diagnose.0.etl [262144]
O61 - LFC:Last File Created 21/07/2010 - 01:06:39 ---A- C:\Users\philou\AppData\Local\Diagnostics\1612347604\2010072021.000\NetworkConfiguration.cab [1411]
O61 - LFC:Last File Created 21/07/2010 - 01:06:45 ---A- C:\Users\philou\AppData\Local\Diagnostics\1612347604\2010072021.000\190579EF-8636-4AA4-A3F4-8E004047B748.Repair.1.etl [196608]
O61 - LFC:Last File Created 21/07/2010 - 01:06:50 ---A- C:\Users\philou\AppData\Local\ElevatedDiagnostics\2551478646\2010072021.000\results.xsl [49097]
O61 - LFC:Last File Created 21/07/2010 - 01:07:01 ---A- C:\Users\philou\AppData\Local\Diagnostics\1612347604\2010072021.000\190579EF-8636-4AA4-A3F4-8E004047B748.Verify.2.etl [327680]
O61 - LFC:Last File Created 21/07/2010 - 01:07:03 ---A- C:\Users\philou\AppData\Local\Diagnostics\1612347604\2010072021.000\2CDDA2B0-32C8-4FC0-846D-044EF0814534.Diagnose.3.etl [327680]
O61 - LFC:Last File Created 21/07/2010 - 01:07:13 ---A- C:\Users\philou\AppData\Local\ElevatedDiagnostics\2551478646\2010072021.000\MaintenanceDiagnostic.0.debugreport.xml [11199]
O61 - LFC:Last File Created 21/07/2010 - 01:07:13 ---A- C:\Users\philou\AppData\Local\ElevatedDiagnostics\2551478646\2010072021.000\ResultReport.xml [9893]
O61 - LFC:Last File Created 21/07/2010 - 01:07:14 ---A- C:\Users\philou\AppData\Local\ElevatedDiagnostics\2551478646\2010072021.000\results.xml [343]
O61 - LFC:Last File Created 21/07/2010 - 01:07:14 ---A- C:\Users\philou\AppData\Local\ElevatedDiagnostics\2551478646\latest.cab [10301]
O61 - LFC:Last File Created 21/07/2010 - 01:07:17 ---A- C:\Users\philou\AppData\Local\Diagnostics\1612347604\2010072021.000\NetworkDiagnostics.0.debugreport.xml [78173]
O61 - LFC:Last File Created 21/07/2010 - 01:07:18 ---A- C:\Users\philou\AppData\Local\Diagnostics\1612347604\2010072021.000\ResultReport.xml [48384]
O61 - LFC:Last File Created 21/07/2010 - 01:07:18 ---A- C:\Users\philou\AppData\Local\Diagnostics\1612347604\2010072021.000\results.xml [382]
O61 - LFC:Last File Created 21/07/2010 - 01:07:18 ---A- C:\Users\philou\AppData\Local\Diagnostics\1612347604\latest.cab [40376]
O61 - LFC:Last File Created 21/07/2010 - 01:18:37 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.001\AD8E4A0A-EF76-43CF-90E0-818FB7C0A0FF.Diagnose.0.etl [262144]
O61 - LFC:Last File Created 21/07/2010 - 01:18:39 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.001\NetworkConfiguration.cab [1411]
O61 - LFC:Last File Created 21/07/2010 - 01:18:44 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.001\AD8E4A0A-EF76-43CF-90E0-818FB7C0A0FF.Repair.1.etl [131072]
O61 - LFC:Last File Created 21/07/2010 - 01:19:13 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.001\AD8E4A0A-EF76-43CF-90E0-818FB7C0A0FF.Verify.2.etl [327680]
O61 - LFC:Last File Created 21/07/2010 - 01:19:52 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.001\7665FACA-AB18-46FD-BF37-8E9381148E22.Diagnose.3.etl [327680]
O61 - LFC:Last File Created 21/07/2010 - 01:19:54 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.001\NetworkDiagnostics.0.debugreport.xml [77913]
O61 - LFC:Last File Created 21/07/2010 - 01:19:55 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.001\results.xsl [49097]
O61 - LFC:Last File Created 21/07/2010 - 01:20:09 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.001\NetworkDiagnostics.1.debugreport.xml [66355]
O61 - LFC:Last File Created 21/07/2010 - 01:20:09 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.001\ResultReport.xml [55543]
O61 - LFC:Last File Created 21/07/2010 - 01:20:09 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.001\results.xml [256]
O61 - LFC:Last File Created 21/07/2010 - 01:20:57 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-20-2010( 22-50-52 ).SDB [5534]
O61 - LFC:Last File Created 21/07/2010 - 01:22:47 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-21-2010( 1-22-47 ).596.SDB [1194]
O61 - LFC:Last File Created 21/07/2010 - 01:24:38 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.002\results.xsl [49097]
O61 - LFC:Last File Created 21/07/2010 - 01:25:01 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.002\0E55C0B4-9C44-44F2-B376-7F7AA164AFA7.Diagnose.0.etl [327680]
O61 - LFC:Last File Created 21/07/2010 - 01:25:07 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.002\NetworkConfiguration.cab [1411]
O61 - LFC:Last File Created 21/07/2010 - 01:25:12 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.002\0E55C0B4-9C44-44F2-B376-7F7AA164AFA7.Repair.1.etl [196608]
O61 - LFC:Last File Created 21/07/2010 - 01:25:43 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.002\0E55C0B4-9C44-44F2-B376-7F7AA164AFA7.Verify.2.etl [262144]
O61 - LFC:Last File Created 21/07/2010 - 01:26:28 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.002\37379FBC-EA5E-4DCA-8379-734CFE0CE046.Diagnose.3.etl [327680]
O61 - LFC:Last File Created 21/07/2010 - 01:26:34 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.002\NetworkDiagnostics.0.debugreport.xml [79851]
O61 - LFC:Last File Created 21/07/2010 - 01:26:34 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.002\ResultReport.xml [52378]
O61 - LFC:Last File Created 21/07/2010 - 01:26:34 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072021.002\results.xml [263]
O61 - LFC:Last File Created 21/07/2010 - 01:27:57 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-21-2010( 1-23-36 ).SDB [5534]
O61 - LFC:Last File Created 21/07/2010 - 08:31:05 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-21-2010( 8-31-5 ).678.SDB [1298]
O61 - LFC:Last File Created 21/07/2010 - 08:42:07 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLIST.ZIP [5350315]
O61 - LFC:Last File Created 21/07/2010 - 08:42:43 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLIST.BIN [13536929]
O61 - LFC:Last File Created 21/07/2010 - 08:42:58 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLISTRELATED.ZIP [182049]
O61 - LFC:Last File Created 21/07/2010 - 08:44:17 ---A- C:\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware\rules.ref [5268610]
O61 - LFC:Last File Created 21/07/2010 - 08:44:19 ---A- C:\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware\link.txt [126]
O61 - LFC:Last File Created 21/07/2010 - 08:44:19 ---A- C:\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware\news.txt [60]
O61 - LFC:Last File Created 21/07/2010 - 08:44:20 ---A- C:\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware\config.dat [778]
O61 - LFC:Last File Created 21/07/2010 - 08:44:20 ---A- C:\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware\local.dat [87]
O61 - LFC:Last File Created 21/07/2010 - 08:51:41 ---A- C:\Users\philou\AppData\Local\FixItCenter\Results\1acb52f3-f845-4c1f-a79c-5dd4f0daa3b3\ElevatedDiagnostics\DIAG_IEPerformanceDiagnostic.0.debugreport.xml [32705]
O61 - LFC:Last File Created 21/07/2010 - 08:51:43 ---A- C:\Users\philou\AppData\Local\FixItCenter\Results\1acb52f3-f845-4c1f-a79c-5dd4f0daa3b3\ElevatedDiagnostics\results.xsl [49097]
O61 - LFC:Last File Created 21/07/2010 - 08:54:18 ---A- C:\Users\philou\AppData\Local\FixItCenter\Results\1acb52f3-f845-4c1f-a79c-5dd4f0daa3b3\ElevatedDiagnostics\FixItCenterReport.xml [148]
O61 - LFC:Last File Created 21/07/2010 - 08:54:20 ---A- C:\Users\philou\AppData\Local\FixItCenter\Results\1acb52f3-f845-4c1f-a79c-5dd4f0daa3b3\ElevatedDiagnostics\DIAG_IEPerformanceDiagnostic.1.debugreport.xml [16343]
O61 - LFC:Last File Created 21/07/2010 - 08:54:20 ---A- C:\Users\philou\AppData\Local\FixItCenter\Results\1acb52f3-f845-4c1f-a79c-5dd4f0daa3b3\ElevatedDiagnostics\ResultReport.xml [25223]
O61 - LFC:Last File Created 21/07/2010 - 08:54:20 ---A- C:\Users\philou\AppData\Local\FixItCenter\Results\1acb52f3-f845-4c1f-a79c-5dd4f0daa3b3\ElevatedDiagnostics\results.xml [384]
O61 - LFC:Last File Created 21/07/2010 - 08:54:20 ---A- C:\Users\philou\AppData\Local\FixItCenter\Results\1acb52f3-f845-4c1f-a79c-5dd4f0daa3b3\latest.cab [13549]
O61 - LFC:Last File Created 21/07/2010 - 08:55:09 ---A- C:\Users\philou\AppData\Local\FixItCenter\Results\ae0e4fa6-10f4-4b29-aaa6-457046a04fcb\ElevatedDiagnostics\results.xsl [49097]
O61 - LFC:Last File Created 21/07/2010 - 08:56:34 ---A- C:\Users\philou\AppData\Local\FixItCenter\Results\ae0e4fa6-10f4-4b29-aaa6-457046a04fcb\ElevatedDiagnostics\IESecurityDiagnostic.0.debugreport.xml [6758]
O61 - LFC:Last File Created 21/07/2010 - 08:56:35 ---A- C:\Users\philou\AppData\Local\FixItCenter\Results\ae0e4fa6-10f4-4b29-aaa6-457046a04fcb\ElevatedDiagnostics\ResultReport.xml [5971]
O61 - LFC:Last File Created 21/07/2010 - 08:56:35 ---A- C:\Users\philou\AppData\Local\FixItCenter\Results\ae0e4fa6-10f4-4b29-aaa6-457046a04fcb\ElevatedDiagnostics\results.xml [393]
O61 - LFC:Last File Created 21/07/2010 - 08:56:35 ---A- C:\Users\philou\AppData\Local\FixItCenter\Results\ae0e4fa6-10f4-4b29-aaa6-457046a04fcb\latest.cab [9513]
O61 - LFC:Last File Created 21/07/2010 - 08:58:08 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072104.000\results.xsl [49097]
O61 - LFC:Last File Created 21/07/2010 - 08:58:26 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072104.000\165CCE45-7810-447C-9C3F-D6EFA97BE5AE.Diagnose.0.etl [262144]
O61 - LFC:Last File Created 21/07/2010 - 08:58:30 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072104.000\NetworkConfiguration.cab [1732]
O61 - LFC:Last File Created 21/07/2010 - 08:58:39 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072104.000\NetworkDiagnostics.0.debugreport.xml [72033]
O61 - LFC:Last File Created 21/07/2010 - 08:58:39 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072104.000\ResultReport.xml [51020]
O61 - LFC:Last File Created 21/07/2010 - 08:58:39 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\2010072104.000\results.xml [256]
O61 - LFC:Last File Created 21/07/2010 - 08:58:40 ---A- C:\Users\philou\AppData\Local\Diagnostics\460911090\latest.cab [27575]
O61 - LFC:Last File Created 21/07/2010 - 09:52:38 ---A- C:\Users\philou\AppData\Roaming\Adobe\Acrobat\9.0\TMDocs.sav [36]
O61 - LFC:Last File Created 21/07/2010 - 09:52:38 ---A- C:\Users\philou\AppData\Roaming\Adobe\Acrobat\9.0\TMGrpPrm.sav [54]
O61 - LFC:Last File Created 21/07/2010 - 09:52:50 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-21-2010( 8-33-32 ).SDB [14047]
O61 - LFC:Last File Created 21/07/2010 - 11:02:24 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-21-2010( 11-2-24 ).54.SDB [1194]
O61 - LFC:Last File Created 21/07/2010 - 11:59:35 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-21-2010( 11-2-54 ).SDB [5534]
O61 - LFC:Last File Created 21/07/2010 - 12:59:56 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-21-2010( 12-59-56 ).647.SDB [1246]
O61 - LFC:Last File Created 21/07/2010 - 13:00:28 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-21-2010( 13-0-28 ).SDB [5444]
O61 - LFC:Last File Created 21/07/2010 - 16:12:54 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-21-2010( 16-12-54 ).87.SDB [1298]
O61 - LFC:Last File Created 21/07/2010 - 17:10:30 ---A- C:\Users\philou\AppData\Roaming\Adobe\Acrobat\9.0\JavaScripts\glob.js [0]
O61 - LFC:Last File Created 21/07/2010 - 17:10:30 ---A- C:\Users\philou\AppData\Roaming\Adobe\Acrobat\9.0\JavaScripts\glob.settings.js [10]
O61 - LFC:Last File Created 21/07/2010 - 17:14:44 ---A- C:\Users\All Users\DAEMON Tools Lite\license.dat [1620]
O61 - LFC:Last File Created 21/07/2010 - 17:15:33 ---A- C:\Users\philou\AppData\Roaming\DAEMON Tools Lite\ImageCatalog.xml [3950]
O61 - LFC:Last File Created 21/07/2010 - 18:16:05 ---A- C:\Users\All Users\NVIDIA Corporation\Drs\nvdrsdb0.bin [245004]
O61 - LFC:Last File Created 21/07/2010 - 18:16:06 ---A- C:\Users\All Users\NVIDIA Corporation\Drs\nvdrsdb1.bin [245004]
O61 - LFC:Last File Created 21/07/2010 - 18:16:06 ---A- C:\Users\All Users\NVIDIA Corporation\Drs\nvdrssel.bin [1]
O61 - LFC:Last File Created 21/07/2010 - 18:40:40 ---A- C:\Users\philou\AppData\Roaming\SeriousBit\EnhanceMySe7en\propshq.hdm [0]
O61 - LFC:Last File Created 21/07/2010 - 18:40:41 ---A- C:\Users\philou\AppData\Roaming\SeriousBit\EnhanceMySe7en\excls.exc [1940]
O61 - LFC:Last File Created 21/07/2010 - 18:40:52 ---A- C:\Users\philou\AppData\Roaming\SeriousBit\EnhanceMySe7en\logs.txt [17928]
O61 - LFC:Last File Created 21/07/2010 - 20:31:07 -SHA- C:\Users\Administrateur\NTUSER.DAT [1048576]
O61 - LFC:Last File Created 21/07/2010 - 20:31:07 -SHA- C:\Users\Administrateur\ntuser.dat.LOG1 [262144]
O61 - LFC:Last File Created 21/07/2010 - 22:25:01 ---A- C:\Users\philou\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents [3072]
O61 - LFC:Last File Created 22/07/2010 - 00:35:52 ---A- C:\Users\philou\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2010-07-22 (00-34-55).txt [1057]
O61 - LFC:Last File Created 22/07/2010 - 00:57:37 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-21-2010( 16-13-27 ).SDB [5534]
O61 - LFC:Last File Created 22/07/2010 - 08:19:39 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-22-2010( 8-19-39 ).130.SDB [1246]
O61 - LFC:Last File Created 22/07/2010 - 08:19:43 ---A- C:\Users\All Users\NVIDIA\Resource.old [1021767]
O61 - LFC:Last File Created 22/07/2010 - 08:19:52 ---A- C:\Users\philou\AppData\Roaming\Microsoft\MSN Messenger\sqmnoopt00.sqm [296]
O61 - LFC:Last File Created 22/07/2010 - 14:29:27 ---A- C:\Users\All Users\Acer\Acer Updater\_UpdaterService_CFG.ini [94]
O61 - LFC:Last File Created 22/07/2010 - 14:30:30 ---A- C:\Users\All Users\Acer\Acer Updater\ServerInfo.xml_debug.xml [7731]
O61 - LFC:Last File Created 22/07/2010 - 14:30:30 ---A- C:\Users\All Users\Acer\Acer Updater\ServerInfo.xml_ori.xml [7654]
O61 - LFC:Last File Created 22/07/2010 - 14:30:31 ---A- C:\Users\All Users\Acer\Acer Updater\Info\ALU_Status_7.txt [0]
O61 - LFC:Last File Created 22/07/2010 - 14:30:31 ---A- C:\Users\All Users\Acer\Acer Updater\ServerInfo.xml [7731]
O61 - LFC:Last File Created 22/07/2010 - 15:21:15 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-22-2010( 8-19-53 ).SDB [5534]
O61 - LFC:Last File Created 22/07/2010 - 15:21:20 --HA- C:\Users\philou\AppData\Local\IconCache.db [3264521]
O61 - LFC:Last File Created 22/07/2010 - 15:21:37 R---- C:\Users\All Users\BackupManager\Logs\SyncJob.log [9594]
O61 - LFC:Last File Created 22/07/2010 - 15:23:48 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-22-2010( 15-23-48 ).651.SDB [934]
O61 - LFC:Last File Created 22/07/2010 - 15:24:08 ---A- C:\Users\All Users\NVIDIA\Resource.dat [1021767]
O61 - LFC:Last File Created 22/07/2010 - 15:25:17 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-22-2010( 15-25-17 ).SDB [0]
O61 - LFC:Last File Created 22/07/2010 - 15:25:20 ---A- C:\Users\philou\AppData\Local\Temp\FXSAPIDebugLogFile.txt [0]
O61 - LFC:Last File Created 22/07/2010 - 15:25:31 ---A- C:\Users\philou\AppData\Local\Temp\AdobeARM.log [947]
O61 - LFC:Last File Created 22/07/2010 - 15:25:40 ---A- C:\Users\philou\AppData\Roaming\Microsoft\MSN Messenger\sqmnoopt01.sqm [296]
O61 - LFC:Last File Created 22/07/2010 - 15:25:57 ---A- C:\Users\philou\Tracing\WindowsLiveMessenger-uccapi-0.uccapilog [0]
O61 - LFC:Last File Created 22/07/2010 - 15:26:33 ---A- C:\Users\philou\AppData\Roaming\Microsoft\Sticky Notes\StickyNotes.snt [4608]
O61 - LFC:Last File Created 22/07/2010 - 15:34:09 ---A- C:\Users\All Users\Acer\Acer Updater\_UpdaterService_LOG.txt [80763]
O61 - LFC:Last File Created 22/07/2010 - 15:34:58 ---A- C:\Users\philou\AppData\Local\Temp\StructuredQuery.log [811]
O61 - LFC:Last File Created 22/07/2010 - 15:35:13 ---A- C:\Users\philou\AppData\Roaming\Google\Local Search History\google%2Eweb.w [576]


---\\ Liste des outils de nettoyage (LATC) (O63)
O63 - Logiciel: HijackThis 2.0.2 - (.TrendMicro.)
O63 - Logiciel: ZHPDiag 1.26 - (.Nicolas Coolman.)
O63 - Logiciel: OTM - (.OldTimer.)


---\\ Liste des services Legacy (LALS) (O64)
O64 - Services: CurCS - C:\Windows\system32\drivers\afd.sys (AFD) .(.Pas de propriétaire - Pas de description.) - LEGACY_AFD
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\atapi.sys - IDE Channel (atapi) .(.Pas de propriétaire - Pas de description.) - LEGACY_ATAPI
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\avgntflt.sys - avgntflt (avgntflt) .(.Pas de propriétaire - Pas de description.) - LEGACY_AVGNTFLT
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\avipbb.sys - avipbb (avipbb) .(.Pas de propriétaire - Pas de description.) - LEGACY_AVIPBB
O64 - Services: CurCS - (.not file.) - Beep (Beep) .(.Pas de propriétaire - Pas de description.) - LEGACY_BEEP
O64 - Services: CurCS - C:\Windows\system32\browser.dll (bowser) .(.Pas de propriétaire - Pas de description.) - LEGACY_BOWSER
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\cdfs.sys - CD/DVD File System Reader (cdfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_CDFS
O64 - Services: CurCS - C:\Windows\system32\clfs.sys (CLFS) .(.Pas de propriétaire - Pas de description.) - LEGACY_CLFS
O64 - Services: CurCS - C:\Windows\system32\Drivers\cng.sys - CNG (CNG) .(.Pas de propriétaire - Pas de description.) - LEGACY_CNG
O64 - Services: CurCS - C:\Program Files\MediaCoder\sysInfoX64.sys - CrystalSysInfo (CrystalSysInfo) .(.Pas de propriétaire - Pas de description.) - LEGACY_CRYSTALSYSINFO
O64 - Services: CurCS - C:\Windows\system32\drivers\dfsc.sys (DfsC) .(.Pas de propriétaire - Pas de description.) - LEGACY_DFSC
O64 - Services: CurCS - C:\Windows\system32\drivers\discache.sys (discache) .(.Pas de propriétaire - Pas de description.) - LEGACY_DISCACHE
O64 - Services: CurCS - C:\Windows\system32\drivers\dxgkrnl.sys - LDDM Graphics Subsystem (DXGKrnl) .(.Pas de propriétaire - Pas de description.) - LEGACY_DXGKRNL
O64 - Services: CurCS - (.not file.) - FAT12/16/32 File System Driver (fastfat) .(.Pas de propriétaire - Pas de description.) - LEGACY_FASTFAT
O64 - Services: CurCS - C:\Windows\system32\drivers\fileinfo.sys (FileInfo) .(.Pas de propriétaire - Pas de description.) - LEGACY_FILEINFO
O64 - Services: CurCS - C:\Windows\system32\drivers\fltmgr.sys (FltMgr) .(.Pas de propriétaire - Pas de description.) - LEGACY_FLTMGR
O64 - Services: CurCS - C:\Windows\system32\Drivers\FS_REC.sys - Fs_Rec (Fs_Rec) .(.Pas de propriétaire - Pas de description.) - LEGACY_FS_REC
O64 - Services: CurCS - C:\Windows\system32\drivers\fvevol.sys (fvevol) .(.Pas de propriétaire - Pas de description.) - LEGACY_FVEVOL
O64 - Services: CurCS - C:\Windows\system32\drivers\http.sys (HTTP) .(.Pas de propriétaire - Pas de description.) - LEGACY_HTTP
O64 - Services: CurCS - C:\Windows\system32\drivers\hwpolicy.sys (hwpolicy) .(.Pas de propriétaire - Pas de description.) - LEGACY_HWPOLICY
O64 - Services: CurCS - C:\Windows\system32\Drivers\ksecdd.sys - KSecDD (KSecDD) .(.Pas de propriétaire - Pas de description.) - LEGACY_KSECDD
O64 - Services: CurCS - C:\Windows\system32\Drivers\ksecpkg.sys - KSecPkg (KSecPkg) .(.Pas de propriétaire - Pas de description.) - LEGACY_KSECPKG
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\lltdio.sys - Link-Layer Topology Discovery Mapper I/O Driver (lltdio) .(.Pas de propriétaire - Pas de description.) - LEGACY_LLTDIO
O64 - Services: CurCS - C:\Windows\system32\drivers\luafv.sys (luafv) .(.Pas de propriétaire - Pas de description.) - LEGACY_LUAFV
O64 - Services: CurCS - C:\Windows\system32\drivers\modem.sys - modem (modem) .(.Pas de propriétaire - Pas de description.) - LEGACY_MODEM
O64 - Services: CurCS - C:\Windows\system32\drivers\mountmgr.sys (mountmgr) .(.Pas de propriétaire - Pas de description.) - LEGACY_MOUNTMGR
O64 - Services: CurCS - C:\Windows\system32\Drivers\MPFP.sys - MPFP (MPFP) .(.Pas de propriétaire - Pas de description.) - LEGACY_MPFP
O64 - Services: CurCS - C:\Windows\system32\wkssvc.dll (mrxsmb) .(.Pas de propriétaire - Pas de description.) - LEGACY_MRXSMB
O64 - Services: CurCS - C:\Windows\system32\wkssvc.dll (mrxsmb10) .(.Pas de propriétaire - Pas de description.) - LEGACY_MRXSMB10
O64 - Services: CurCS - C:\Windows\system32\wkssvc.dll (mrxsmb20) .(.Pas de propriétaire - Pas de description.) - LEGACY_MRXSMB20
O64 - Services: CurCS - C:\Windows\system32\Drivers\MSFS.sys - Msfs (Msfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_MSFS
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\msisadrv.sys - msisadrv (msisadrv) .(.Pas de propriétaire - Pas de description.) - LEGACY_MSISADRV
O64 - Services: CurCS - C:\Windows\system32\drivers\mup.sys (Mup) .(.Pas de propriétaire - Pas de description.) - LEGACY_MUP
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\mwlPSDFilter.sys - mwlPSDFilter (mwlPSDFilter) .(.Pas de propriétaire - Pas de description.) - LEGACY_MWLPSDFILTER
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\mwlPSDNServ.sys - mwlPSDNServ (mwlPSDNServ) .(.Pas de propriétaire - Pas de description.) - LEGACY_MWLPSDNSERV
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys - mwlPSDVDisk (mwlPSDVDisk) .(.Pas de propriétaire - Pas de description.) - LEGACY_MWLPSDVDISK
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\nwifi.sys - NativeWiFi Filter (NativeWifiP) .(.Pas de propriétaire - Pas de description.) - LEGACY_NATIVEWIFIP
O64 - Services: CurCS - C:\Windows\system32\drivers\ndis.sys (NDIS) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDIS
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\ndisuio.sys - NDIS Usermode I/O Protocol (Ndisuio) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDISUIO
O64 - Services: CurCS - C:\Windows\system32\Drivers\NDPROXY.sys - NDProxy (NDProxy) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDPROXY
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\netbios.sys - NetBIOS Interface (NetBIOS) .(.Pas de propriétaire - Pas de description.) - LEGACY_NETBIOS
O64 - Services: CurCS - C:\Windows\system32\drivers\netbt.sys (NetBT) .(.Pas de propriétaire - Pas de description.) - LEGACY_NETBT
O64 - Services: CurCS - C:\Windows\system32\Drivers\NPFS.sys - Npfs (Npfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_NPFS
O64 - Services: CurCS - C:\Windows\system32\drivers\nsiproxy.sys (nsiproxy) .(.Pas de propriétaire - Pas de description.) - LEGACY_NSIPROXY
O64 - Services: CurCS - C:\Windows\system32\Drivers\NTFS.sys - Ntfs (Ntfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_NTFS
O64 - Services: CurCS - C:\Windows\system32\Drivers\NULL.sys - Null (Null) .(.Pas de propriétaire - Pas de description.) - LEGACY_NULL
O64 - Services: CurCS - C:\Windows\system32\drivers\pcw.sys - Performance Counters for Windows Driver (pcw) .(.Pas de propriétaire - Pas de description.) - LEGACY_PCW
O64 - Services: CurCS - C:\Windows\system32\drivers\peauth.sys - PEAUTH (PEAUTH) .(.Pas de propriétaire - Pas de description.) - LEGACY_PEAUTH
O64 - Services: CurCS - C:\Windows\system32\drivers\pacer.sys (Psched) .(.Pas de propriétaire - Pas de description.) - LEGACY_PSCHED
O64 - Services: CurCS - C:\Windows\system32\wkssvc.dll (rdbss) .(.Pas de propriétaire - Pas de description.) - LEGACY_RDBSS
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\RDPCDD.sys (RDPCDD) .(.Pas de propriétaire - Pas de description.) - LEGACY_RDPCDD
O64 - Services: CurCS - C:\Windows\system32\drivers\RDPENCDD.sys (RDPENCDD) .(.Pas de propriétaire - Pas de description.) - LEGACY_RDPENCDD
O64 - Services: CurCS - C:\Windows\system32\drivers\RdpRefMp.sys (RDPREFMP) .(.Pas de propriétaire - Pas de description.) - LEGACY_RDPREFMP
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\rspndr.sys - Link-Layer Topology Discovery Responder (rspndr) .(.Pas de propriétaire - Pas de description.) - LEGACY_RSPNDR
O64 - Services: CurCS - C:\Program Files\SUPERAntiSpyware\SASDIFSV64.sys - SASDIFSV (SASDIFSV) .(.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASDIFSV64.SYS.) - LEGACY_SASDIFSV
O64 - Services: CurCS - C:\Program Files\SUPERAntiSpyware\SASKUTIL64.sys - SASKUTIL (SASKUTIL) .(.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASKUTIL64.SYS.) - LEGACY_SASKUTIL
O64 - Services: CurCS - (.not file.) - Security Driver (secdrv) .(.Pas de propriétaire - Pas de description.) - LEGACY_SECDRV
O64 - Services: CurCS - (.not file.) - Security Processor Loader Driver (spldr) .(.Pas de propriétaire - Pas de description.) - LEGACY_SPLDR
O64 - Services: CurCS - C:\Windows\system32\Drivers\sptd.sys - sptd (sptd) .(.Pas de propriétaire - Pas de description.) - LEGACY_SPTD
O64 - Services: CurCS - C:\Windows\system32\srvsvc.dll (srv) .(.Pas de propriétaire - Pas de description.) - LEGACY_SRV
O64 - Services: CurCS - C:\Windows\system32\srvsvc.dll (srv2) .(.Pas de propriétaire - Pas de description.) - LEGACY_SRV2
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\srvnet.sys - srvnet (srvnet) .(.Pas de propriétaire - Pas de description.) - LEGACY_SRVNET
O64 - Services: CurCS - C:\Windows\system32\drivers\tcpipreg.sys - TCP/IP Registry Compatibility (tcpipreg) .(.Pas de propriétaire - Pas de description.) - LEGACY_TCPIPREG
O64 - Services: CurCS - C:\Windows\system32\drivers\truecrypt.sys - truecrypt (truecrypt) .(.Pas de propriétaire - Pas de description.) - LEGACY_TRUECRYPT
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\udfs.sys - udfs (udfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_UDFS
O64 - Services: CurCS - C:\Windows\system32\drivers\vga.sys - VgaSave (VgaSave) .(.Pas de propriétaire - Pas de description.) - LEGACY_VGASAVE
O64 - Services: CurCS - C:\Windows\system32\drivers\volmgrx.sys (volmgrx) .(.Pas de propriétaire - Pas de description.) - LEGACY_VOLMGRX
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\volsnap.sys - Volumes de stockage (volsnap) .(.Pas de propriétaire - Pas de description.) - LEGACY_VOLSNAP
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\vwififlt.sys - Virtual WiFi Filter Driver (vwififlt) .(.Pas de propriétaire - Pas de description.) - LEGACY_VWIFIFLT
O64 - Services: CurCS - C:\Windows\system32\drivers\Wdf01000.sys - Kernel Mode Driver Frameworks service (Wdf01000) .(.Pas de propriétaire - Pas de description.) - LEGACY_WDF01000
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\wfplwf.sys - WFP Lightweight Filter (WfpLwf) .(.Pas de propriétaire - Pas de description.) - LEGACY_WFPLWF
O64 - Services: CurCS - C:\Windows\system32\drivers\WudfPf.sys - User Mode Driver Frameworks Platform Driver (WudfPf) .(.Pas de propriétaire - Pas de description.) - LEGACY_WUDFPF


---\\ Observateur d'évènement d'application (OEA) (O66)
O66 - EventLog: ID=1000 (Application Error) - (.Pas de propriétaire - Pas de description.) -- C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3sp.exe
O66 - EventLog: ID=1000 (Application Error) - (.Adobe Systems Incorporated - Adobe Reader 9.3.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe
O66 - EventLog: ID=1000 (Application Error) - (.InstallShield Software Corporation - Setup.exe.) -- C:\Users\philou\Desktop\medal_of_honor_batailles_du_pacifique_demo_solo_anglais.exe
O66 - EventLog: ID=1000 (Application Error) - (.Microsoft Corporation - Microsoft Management Console.) -- C:\Windows\system32\mmc.exe


---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\system32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.evt> <evtfile>[HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\system32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <htmlfile>[HKCR\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe


---\\ Start Menu Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe


---\\ Search Browser Infection (SBI) (O69)
O69 - SBI: prefs.js [philou - 4lrj2qsx.default] user_pref("CT2124320.SearchEngine", "Search||http://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2124320
O69 - SBI: prefs.js [philou - 4lrj2qsx.default] user_pref("CT2124320.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2124320&q=");
[HKCU\Software\Microsoft\Internet Explorer\MenuExt\E&xporter vers Microsoft Excel]
[HKCU\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...]
O69 - SBI: SearchScopes {67A2568C-7A0A-4EED-AECC-B5405DE63B64} [DefaultScope] - (Google) - http://www.google.com
O69 - SBI: SearchScopes {6A1806CD-94D4-4689-BA73-E35EA1EA9990}- (Google) - http://www.google.com


---\\ Recherche d'infection Master Boot Record (O80)
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
Run by philou at 22/07/2010 15:42:02
device: opened successfully
user: MBR read successfully
kernel: error reading MBR

End of the scan (1142 lines in 16mn 42s)

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 22/07/2010 à 15:10  
Petit astucien

528 Messages

tout a réussi à passer

qu'en penses tu????

pour ma part,j'ai l'impression que ça va mieux

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 pear  Posté le 22/07/2010 à 17:59  
  Astucien


8679 Messages

Si vous êtes sous Vista:Désactiver L'UAC ,avant sont utilisation.
Menu Démarrer \ Panneau de Configuration \ Comptes d'utilisateurs et protection des utilisateurs \ Comptes d'utilisateurs \ Activer ou désactiver le contrôle des comptes d'utilisateurs \ décoche la case Utiliser le contrôle ... et valider par OK ,
il sera demandé de redémarrer


Téléchargez AD-Remover sur le bureau
Déconnectez-vous et fermez toutes les applications en cours
Cliquer sur "Ad-R.exe" pour lancer l'installation et laisser les paramètres par défaut .
Une fenêtre s'affichera Vous prévenant des risques de l'utilisation de ce logiciel
Cliquez sur "OUI"
Double cliquer sur l'icône Ad-remover sur le bureau
image
Au menu principal choisir l'optionScanner et Validez

Patientez pendant le travail de l'outil.
Poster le rapport qui apparait à la fin .
Il est sauvegardé aussi sous C:\Ad-report.log

Ensuite

Relancer Ad- remover , choisir l'option Nettoyer

Il y aura 2 rapports à poster après Scanner et Nettoyer

Pour désinstaller AD-Remover, lancez avec l'option D puis supprimer l'icône du bureau.

Prévention:
Désactiver l'autorun sur tous les lecteur (USB, CD, DVD, SATA, Firewire, etc.

Sous Vista/7
Copier/coller ce qui suiten vertdans le bloc notes,sans ligne blanche au début.mais une à la fin.
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers]
"DisableAutoplay"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf]
@="@SYS:DoesNotExist"


Fichier ->Enregistrez sous..
Clic sur bureau à gauche
Dans type de fichier->Tous les fichiers
Dans Nom-> regis.reg.
Allez sur le bureau
Cliquez droit sur le fichier ->fusionner
Acceptez la modification du Régistre




Télécharger Usb Fix , sur le bureau

Installez le.
Vous devez désactiver la protection en temps réel de votre Antivirus qui peut considérer certains composants de ce logiciel comme néfastes.
* Pour cela, faites un clic droit sur l'icône de l'antivirus en bas à droite à côté de l'horloge puis Disable Guard ou Shield ou Résident...
Si vous êtes sous Vista et 7, si l'UAC est activé il faut le lancer en mode "Administrateur".
Clic droit sur USBFix.exe et choisir Exécuter en tant qu'administrateur.
Sous XP, Double-cliquer sur USBFix.exe pour le lancer.

Lancer l'installation avec les paramètres par défault
Brancher les périphériques externes (clé USB, disque dur externe, etc...) sans les ouvrir
Faire un Clic-droit sur le raccourci Usbfix sur le bureau et choisir "Exécuter en tant qu'administrateur".

Lancer l' option 1(Recherche)
le rapport UsbFix.txt est sauvegardé à la racine du disque .
Faites en un copier/coller dans le bloc notes pour le poster.

Ensuite,
Lancer l'option 2(Suppression)
Le bureau disparait et le pc redémarre
Patientez le temps du scan.
le rapport UsbFix.txt est sauvegardé à la racine du disque
Faites en un copier/coller dans le bloc notes pour le poster.


Vaccination
Pour vous éviter une infection ultérieure:
Lancer l' Option 3 (vaccination)



Pour Désinstaller
Double clic sur le raccourci UsbFix sur le bureau
Lancer l' option 5 ( Désinstaller ) ....

 Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 23/07/2010 à 09:01  
Petit astucien

528 Messages

le premier rapport

======= RAPPORT D'AD-REMOVER 2.0.0.1,D | UNIQUEMENT XP/VISTA/7 =======

Mis à jour par C_XX le 21/07/10 à 14:00
Contact: AdRemover.contact[AT]gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html

C:\Program Files (x86)\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 10:51:09 le 23/07/2010, Mode normal

Microsoft Windows 7 Édition Familiale Premium (X64)
philou@PHILOU-PC (Acer Aspire R3610)

============== RECHERCHE ==============


3,Fichier trouvé: C:\Windows\Installer\c57a7.msi

-- Fichier ouvert: C:\Users\philou\AppData\Roaming\Mozilla\FireFox\Profiles\4lrj2qsx.default\Prefs.js --
Ligne trouvée: user_pref("CT2124320.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER...
Ligne trouvée: user_pref("CT2124320.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT212...
-- Fichier Fermé --

0,Clé trouvée: HKCU\Software\AppDataLow\Software\Conduit


============== SCAN ADDITIONNEL ==============

** Mozilla Firefox Version [3.6.6 (fr)] **

-- C:\Users\philou\AppData\Roaming\Mozilla\FireFox\Profiles\4lrj2qsx.default\Prefs.js --
browser.startup.homepage_override.mstone, rv:1.9.2.6

========================================

** Internet Explorer Version [8.0.7600.16385] **

[HKCU\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_r3610&r=17360610d006pe495v145w4502t45o
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\Windows\system32\blank.htm
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Show_ToolBar: yes
Start Page: hxxp://www.google.fr/

[HKLM\Software\Microsoft\Internet Explorer\Main]
AutoHide: yes
Default_Page_URL: hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_r3610&r=17360610d006pe495v145w4502t45o
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Delete_Temp_Files_On_Exit: yes
Local Page: C:\Windows\SysWOW64\blank.htm
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&m=aspire_r3610&r=17360610d006pe495v145w4502t45o

[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm

========================================

C:\Program Files (x86)\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Program Files (x86)\Ad-Remover\Backup: 0 Fichier(s)

C:\Ad-Report-SCAN[1].txt - 23/07/2010 (2467 Octet(s))

Fin à: 10:54:33, 23/07/2010

============== E.O.F ==============

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 23/07/2010 à 09:17  
Petit astucien

528 Messages

maintenant le rapport de clean

======= RAPPORT D'AD-REMOVER 2.0.0.1,D | UNIQUEMENT XP/VISTA/7 =======

Mis à jour par C_XX le 21/07/10 à 14:00
Contact: AdRemover.contact[AT]gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html

C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 11:03:31 le 23/07/2010, Mode normal

Microsoft Windows 7 Édition Familiale Premium (X64)
philou@PHILOU-PC (Acer Aspire R3610)

============== ACTION(S) ==============


3,Fichier supprimé: C:\Windows\Installer\c57a7.msi

(!) -- Fichiers temporaires supprimés.


-- Fichier ouvert: C:\Users\philou\AppData\Roaming\Mozilla\FireFox\Profiles\4lrj2qsx.default\Prefs.js --
Ligne supprimée: user_pref("CT2124320.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER...
Ligne supprimée: user_pref("CT2124320.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT212...
-- Fichier Fermé --

0,Clé supprimée: HKCU\Software\AppDataLow\Software\Conduit


============== SCAN ADDITIONNEL ==============

** Mozilla Firefox Version [3.6.6 (fr)] **

-- C:\Users\philou\AppData\Roaming\Mozilla\FireFox\Profiles\4lrj2qsx.default\Prefs.js --
browser.startup.homepage_override.mstone, rv:1.9.2.6

========================================

** Internet Explorer Version [8.0.7600.16385] **

[HKCU\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\Windows\system32\blank.htm
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/

[HKLM\Software\Microsoft\Internet Explorer\Main]
AutoHide: yes
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Local Page: C:\Windows\SysWOW64\blank.htm
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/

[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm

========================================

C:\Program Files (x86)\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Program Files (x86)\Ad-Remover\Backup: 0 Fichier(s)

C:\Ad-Report-CLEAN[1].txt - 23/07/2010 (2516 Octet(s))
C:\Ad-Report-SCAN[1].txt - 23/07/2010 (2596 Octet(s))

Fin à: 11:06:53, 23/07/2010

============== E.O.F ==============

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 
Publicité
 philou83  Posté le 23/07/2010 à 09:35  
Petit astucien

528 Messages

############################## | UsbFix 7.017 | [Recherche]

Utilisateur: philou (Administrateur) # PHILOU-PC [Acer Aspire R3610]
Mis à jour le 22/07/10 par El Desaparecido / C_XX
Lancé à 11:29:43 | 23/07/2010
Site Web: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com

CPU: Intel(R) Atom(TM) CPU 330 @ 1.60GHz
CPU 2: Intel(R) Atom(TM) CPU 330 @ 1.60GHz
Microsoft Windows 7 Édition Familiale Premium (6.1.7600 64-Bit) #
Internet Explorer 8.0.7600.16385

Pare-feu Windows: Activé
RAM -> 1791 Mo
C:\ (%systemdrive%) -> Disque fixe # 109 Go (55 Go libre(s) - 51%) [Acer] # NTFS
D:\ -> Disque fixe # 110 Go (78 Go libre(s) - 71%) [DATA] # NTFS
E:\ -> Disque fixe # 466 Go (219 Go libre(s) - 47%) [Transcend] # FAT32
F:\ -> CD-ROM
H:\ -> CD-ROM

################## | Éléments infectieux |


################## | Registre |

Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

################## | Mountpoints2 |

HKCU\.\.\.\.\Explorer\MountPoints2\{26b97aaa-8378-11df-b659-bd7f7328e851}
Shell\AutoRun\Command = F:\setup\rsrc\Autorun.exe
Shell\dinstall\Command = F:\Directx\dxsetup.exe

HKCU\.\.\.\.\Explorer\MountPoints2\{3a0081e0-84f7-11df-a409-bd3cf8f3e840}
Shell\AutoRun\Command = H:\autorun.exe

HKCU\.\.\.\.\Explorer\MountPoints2\{811efe95-83a9-11df-9c4c-806e6f6e6963}
Shell\AutoRun\Command = G:\setup\rsrc\Autorun.exe
Shell\dinstall\Command = G:\Directx\dxsetup.exe


################## | Vaccin |

(!) Cet ordinateur n'est pas vacciné!

################## | E.O.F |

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 23/07/2010 à 09:48  
Petit astucien

528 Messages

############################## | UsbFix 7.017 | [Suppression]

Utilisateur: philou (Administrateur) # PHILOU-PC [Acer Aspire R3610]
Mis à jour le 22/07/10 par El Desaparecido / C_XX
Lancé à 11:36:37 | 23/07/2010
Site Web: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com

CPU: Intel(R) Atom(TM) CPU 330 @ 1.60GHz
CPU 2: Intel(R) Atom(TM) CPU 330 @ 1.60GHz
Microsoft Windows 7 Édition Familiale Premium (6.1.7600 64-Bit) #
Internet Explorer 8.0.7600.16385

Pare-feu Windows: Activé
RAM -> 1791 Mo
C:\ (%systemdrive%) -> Disque fixe # 109 Go (55 Go libre(s) - 51%) [Acer] # NTFS
D:\ -> Disque fixe # 110 Go (78 Go libre(s) - 71%) [DATA] # NTFS
E:\ -> Disque fixe # 466 Go (219 Go libre(s) - 47%) [Transcend] # FAT32
F:\ -> CD-ROM
H:\ -> CD-ROM

################## | Éléments infectieux |


################## | Registre |

Supprimé! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

################## | Mountpoints2 |

Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{26b97aaa-8378-11df-b659-bd7f7328e851}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{3a0081e0-84f7-11df-a409-bd3cf8f3e840}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{811efe95-83a9-11df-9c4c-806e6f6e6963}

################## | Listing |

[23/07/2010 - 11:38:55 | SHD ] C:\$Recycle.Bin
[30/03/2010 - 18:29:02 | AD ] C:\book
[13/10/2009 - 02:58:36 | RASH | 8192] C:\BOOTSECT.BAK
[22/07/2010 - 08:19:13 | SHD ] C:\Config.Msi
[14/07/2009 - 09:08:56 | SHD ] C:\Documents and Settings
[07/11/2007 - 08:00:40 | A | 17734] C:\eula.1028.txt
[07/11/2007 - 08:00:40 | A | 17734] C:\eula.1031.txt
[07/11/2007 - 08:00:40 | A | 10134] C:\eula.1033.txt
[07/11/2007 - 08:00:40 | A | 17734] C:\eula.1036.txt
[07/11/2007 - 08:00:40 | A | 17734] C:\eula.1040.txt
[07/11/2007 - 08:00:40 | A | 118] C:\eula.1041.txt
[07/11/2007 - 08:00:40 | A | 17734] C:\eula.1042.txt
[07/11/2007 - 08:00:40 | A | 17734] C:\eula.2052.txt
[07/11/2007 - 08:00:40 | A | 17734] C:\eula.3082.txt
[07/11/2007 - 08:00:40 | A | 1110] C:\globdata.ini
[07/11/2007 - 08:44:20 | A | 855040] C:\install.exe
[07/11/2007 - 08:00:40 | A | 843] C:\install.ini
[07/11/2007 - 08:44:20 | A | 75280] C:\install.res.1028.dll
[07/11/2007 - 08:44:20 | A | 95248] C:\install.res.1031.dll
[07/11/2007 - 08:44:20 | A | 90128] C:\install.res.1033.dll
[07/11/2007 - 08:44:20 | A | 96272] C:\install.res.1036.dll
[07/11/2007 - 08:44:20 | A | 94224] C:\install.res.1040.dll
[07/11/2007 - 08:44:20 | A | 80400] C:\install.res.1041.dll
[07/11/2007 - 08:44:20 | A | 78864] C:\install.res.1042.dll
[07/11/2007 - 08:44:20 | A | 74768] C:\install.res.2052.dll
[07/11/2007 - 08:44:20 | A | 95248] C:\install.res.3082.dll
[13/10/2009 - 02:35:43 | RHD ] C:\MSOCache
[10/07/2010 - 20:17:13 | D ] C:\NVIDIA
[29/06/2010 - 14:24:11 | HD ] C:\OEM
[23/07/2010 - 11:08:48 | ASH | 3145728000] C:\pagefile.sys
[01/07/2010 - 16:39:03 | D ] C:\PerfLogs
[22/07/2010 - 08:27:59 | RD ] C:\Program Files
[23/07/2010 - 11:20:32 | RD ] C:\Program Files (x86)
[21/07/2010 - 21:10:13 | HD ] C:\ProgramData
[29/06/2010 - 14:22:47 | SHD ] C:\Recovery
[13/10/2009 - 02:23:54 | A | 2035] C:\RHDSetup.log
[23/07/2010 - 11:09:35 | AH | 111] C:\sys13026.bin
[22/07/2010 - 14:54:50 | SHD ] C:\System Volume Information
[23/07/2010 - 11:38:55 | D ] C:\UsbFix
[23/07/2010 - 11:36:38 | A | 3414] C:\UsbFix.txt
[18/07/2010 - 11:01:34 | RD ] C:\Users
[07/11/2007 - 08:00:40 | A | 5686] C:\vcredist.bmp
[07/11/2007 - 08:50:40 | A | 1927956] C:\VC_RED.cab
[07/11/2007 - 08:53:12 | A | 242176] C:\VC_RED.MSI
[22/07/2010 - 08:19:31 | D ] C:\Windows
[22/07/2010 - 15:19:46 | D ] C:\_OTM
[23/07/2010 - 11:38:55 | SHD ] D:\$RECYCLE.BIN
[17/07/2010 - 18:48:33 | A | 80555] D:\3535257528_91a1c6a3f6_o.jpg
[07/07/2010 - 21:28:50 | A | 49] D:\adresse jacqueline.txt
[09/07/2010 - 23:16:30 | A | 208080] D:\Belarc Advisor Current Profile acer revo 3610.mht
[07/07/2010 - 21:27:06 | D ] D:\boulot
[01/07/2010 - 18:59:40 | D ] D:\burgmann 400
[11/06/2010 - 22:58:10 | A | 96988134] D:\catalogue.pdf
[21/07/2010 - 20:56:24 | A | 6386] D:\cc_20100721_205609.reg
[01/07/2010 - 18:59:52 | D ] D:\choix pc
[22/05/2010 - 21:48:38 | A | 3534240] D:\choixpc201005.exe
[07/07/2010 - 08:51:24 | A | 6797000704] D:\COD4MW.ISO
[07/07/2010 - 08:51:24 | A | 8414] D:\COD4MW.MDS
[01/07/2010 - 19:00:08 | D ] D:\comique
[01/07/2010 - 19:01:28 | D ] D:\CommentCaMarche
[12/06/2010 - 22:28:04 | A | 18] D:\compte LDLC.txt
[21/05/2009 - 20:05:42 | A | 1050] D:\Contacts de balou83 (msn).ctt
[21/07/2010 - 16:24:47 | A | 57214] D:\Corsair Value SO-DIMM DDR2-SDRAM 1 Go PC6400 - VS1GSDS800D2 - Achat - Vente Mémoire PC Portable sur LDLC_com.htm
[21/07/2010 - 16:24:49 | D ] D:\Corsair Value SO-DIMM DDR2-SDRAM 1 Go PC6400 - VS1GSDS800D2 - Achat - Vente Mémoire PC Portable sur LDLC_com_fichiers
[07/09/2006 - 17:00:50 | A | 986112] D:\Crofoname.exe
[18/07/2010 - 11:51:18 | A | 1544] D:\DD HITACHI.txt
[01/07/2010 - 19:01:30 | D ] D:\dictionnaire anglais
[12/07/2010 - 22:32:42 | A | 172] D:\faire tourner CODWAW.txt
[07/07/2010 - 21:52:12 | D ] D:\fichiers excel
[22/07/2010 - 00:12:24 | D ] D:\Fichiers INTERNET
[22/07/2010 - 00:13:12 | D ] D:\fichiers PDF
[01/07/2010 - 19:02:49 | D ] D:\fichiers txt
[03/07/2010 - 14:46:48 | D ] D:\fichiers word
[01/07/2010 - 19:03:00 | D ] D:\fichiers zevisit
[01/07/2010 - 19:03:02 | D ] D:\fichiers.pps
[01/07/2010 - 19:03:09 | D ] D:\Free PDF to Word Doc Converter
[01/07/2010 - 19:03:09 | D ] D:\GMPA
[01/07/2010 - 19:03:10 | RD ] D:\icones
[01/07/2010 - 19:03:14 | D ] D:\informatique
[01/07/2010 - 19:03:21 | D ] D:\Jargon Informatique
[01/07/2010 - 19:03:21 | D ] D:\JDA
[01/07/2010 - 19:03:24 | D ] D:\jeux
[01/07/2010 - 19:03:25 | D ] D:\LA RUN
[21/07/2010 - 16:21:34 | A | 66127] D:\LDLC Quality Select webcam nightsight - Achat - Vente Webcam sur LDLC_com.htm
[21/07/2010 - 16:21:37 | D ] D:\LDLC Quality Select webcam nightsight - Achat - Vente Webcam sur LDLC_com_fichiers
[03/07/2010 - 14:34:41 | D ] D:\les glorieuses
[01/07/2010 - 19:03:25 | D ] D:\lettres type
[17/07/2010 - 23:39:01 | D ] D:\logiciels compatibles 7
[01/07/2010 - 18:19:08 | RD ] D:\Ma musique
[10/07/2010 - 21:50:07 | A | 1025709] D:\maconfig.pdf
[23/06/2010 - 18:37:08 | D ] D:\Mes fichiers reçus
[01/07/2010 - 18:29:11 | D ] D:\Mes Google Gadgets
[01/07/2010 - 18:29:11 | D ] D:\Mes Historiques de Conversation
[19/07/2010 - 08:56:59 | RD ] D:\Mes images
[01/07/2010 - 18:20:30 | D ] D:\micro hebdo
[21/07/2010 - 17:09:46 | A | 531876] D:\mini lecteur multimedia.PNG
[15/07/2010 - 12:14:22 | A | 9] D:\mot de passe administrateur.txt
[20/07/2010 - 23:35:19 | A | 24397046] D:\MPIX357-HD.pdf
[07/07/2010 - 21:41:17 | D ] D:\MSKeyViewerPlus-v1.6.5
[01/07/2010 - 19:38:43 | D ] D:\mylene farmer
[13/07/2010 - 19:02:59 | A | 3484681] D:\ParagonDriveBackup9.0Express.pdf
[13/07/2010 - 23:32:11 | A | 555] D:\Philips VLounge.lnk
[12/07/2010 - 22:11:34 | D ] D:\Photos campagne 2003 2004 Philou
[01/07/2010 - 18:23:17 | D ] D:\photos video
[01/07/2010 - 18:24:35 | D ] D:\Poster Forge
[12/07/2010 - 10:01:21 | A | 2806368] D:\rapport de performances 12 juillet 2010.html
[01/07/2010 - 19:43:26 | D ] D:\reportages
[07/07/2010 - 21:37:08 | D ] D:\retraites
[01/07/2010 - 19:43:26 | D ] D:\Seychelles
[01/07/2010 - 18:46:19 | D ] D:\Simul.SCA
[01/07/2010 - 18:46:19 | D ] D:\Sony Ericsson
[17/02/2010 - 00:37:42 | A | 2207] D:\Spybot-Sites.cmd
[22/07/2010 - 14:56:06 | SHD ] D:\System Volume Information
[01/07/2010 - 19:47:26 | D ] D:\tele nivose
[07/07/2010 - 21:33:35 | D ] D:\telephone portable
[01/07/2010 - 18:49:11 | D ] D:\wikipedia
[16/02/2010 - 19:58:18 | SHD ] E:\Recycled
[16/02/2010 - 19:58:18 | SHD ] E:\System Volume Information
[02/03/2010 - 22:49:18 | A | 118059] E:\27209_101108106593570_100000831441333_28551_6010169_n.jpg
[26/04/2010 - 17:06:36 | D ] E:\Exportations Picasa
[26/04/2010 - 17:06:38 | D ] E:\phil et ses neveux
[26/04/2010 - 17:06:40 | D ] E:\+100a memeré
[26/04/2010 - 17:06:50 | D ] E:\1er janvier 05
[26/04/2010 - 17:06:54 | D ] E:\1er novembre
[26/04/2010 - 17:07:00 | D ] E:\100 ans memere
[26/04/2010 - 17:07:16 | D ] E:\alain
[26/04/2010 - 17:07:40 | D ] E:\Photo de nico
[26/04/2010 - 17:07:52 | D ] E:\anni nico+boost
[26/04/2010 - 17:08:00 | D ] E:\anni katy
[26/04/2010 - 17:08:30 | D ] E:\anni maxetbérinice
[26/04/2010 - 17:08:34 | D ] E:\anniversaire kenny
[26/04/2010 - 17:08:40 | D ] E:\apéro floréal
[26/04/2010 - 17:08:44 | D ] E:\appareil photo maman
[26/04/2010 - 17:08:44 | D ] E:\assistante maternelle
[26/04/2010 - 17:08:50 | D ] E:\appart max
[26/04/2010 - 17:09:00 | D ] E:\calendrier
[26/04/2010 - 17:09:04 | D ] E:\camera
[26/04/2010 - 17:09:08 | D ] E:\chez mado
[26/04/2010 - 17:09:12 | D ] E:\cindi émi
[26/04/2010 - 17:09:28 | D ] E:\darwin
[26/04/2010 - 17:09:48 | D ] E:\domy
[26/04/2010 - 17:09:54 | D ] E:\doria&olivier
[26/04/2010 - 17:10:00 | D ] E:\famille jully
[26/04/2010 - 17:10:06 | D ] E:\gonfaron
[26/04/2010 - 17:10:20 | D ] E:\hallowen
[26/04/2010 - 17:10:28 | AD ] E:\kenny
[26/04/2010 - 17:12:28 | D ] E:\kylian
[18/06/2010 - 10:48:46 | ASH | 17920] E:\Thumbs.db
[08/04/2010 - 20:07:52 | AH | 96] E:\.picasa.ini
[26/04/2010 - 17:20:14 | D ] E:\sexy
[26/04/2010 - 17:20:28 | D ] E:\Petit bobo
[26/04/2010 - 17:20:30 | D ] E:\sortie famille video
[26/04/2010 - 17:20:44 | D ] E:\le vacoa
[26/04/2010 - 17:20:48 | D ] E:\volcan
[26/04/2010 - 17:21:06 | D ] E:\A 380
[26/04/2010 - 17:21:08 | D ] E:\les glorieuses
[26/04/2010 - 17:21:10 | D ] E:\maïdo
[26/04/2010 - 17:21:54 | D ] E:\photo nivose
[26/04/2010 - 17:22:10 | D ] E:\amie et famille
[26/04/2010 - 17:22:30 | D ] E:\appat run
[26/04/2010 - 17:22:36 | D ] E:\kelonia et aquarium
[26/04/2010 - 17:23:08 | D ] E:\funny.photo
[26/04/2010 - 17:23:12 | D ] E:\coucher de soleil la run
[26/04/2010 - 17:23:12 | D ] E:\IZI et nico
[26/04/2010 - 17:23:22 | D ] E:\MOBYLETTE
[26/04/2010 - 17:23:24 | D ] E:\Nouveau calendrier.el4 léa.el4.Data
[26/04/2010 - 17:23:24 | D ] E:\DIVERS
[26/04/2010 - 17:23:28 | D ] E:\RUGBY
[07/02/2010 - 21:56:38 | A | 3511] E:\philou en marin.jpg
[09/03/2010 - 02:55:24 | A | 27182] E:\ArrestPiratesNivose-Fr100306.jpg
[15/12/2009 - 18:06:14 | A | 3163648] E:\album run+VIDEO.MSWMM
[15/12/2009 - 18:54:44 | A | 247398677] E:\PROGET RUN.wmv
[17/06/2010 - 23:40:50 | D ] E:\philou
[06/07/2010 - 00:28:36 | SHD ] E:\$RECYCLE.BIN
[19/07/2010 - 23:17:10 | D ] E:\Iomega

################## | Vaccin |

C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
D:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
E:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)

################## | E.O.F |

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 23/07/2010 à 10:19  
Petit astucien

528 Messages

voilà tout est fait

qu'en penses tu?????

mon épouse a un netbook,est ce que je peux faire les mêmes manip ou alors faut-il que je repostes un rapport hijackthis et si oui puis je le faire sur le meme post???

sinon j'ai réactive mon anti virus et l'UAC

pour la modif faite au registre,je reste comme ça???

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 pear  Posté le 23/07/2010 à 13:31  
  Astucien


8679 Messages

pour la modif faite au registre,je reste comme ça

oui.

On vérifie que tout va bien:

Sous Vista, désactivez l'UAC
Télécharger Kaspersky Virus Removal Tool(VRT)
Le fichier fait + de 70M°, soyez patient.

Très simple à utiliser,Kaspersky Virus Removal Tool n'est pas un antivirus ou un outil de surveillance,
Il n'y a pas non plus de mise-à-jour automatique, il vous faudra donc télécharger la nouvelle version, qui est quotidiennement mise à jour, et l'installer à chaque fois que vous désirez l'utiliser.
Cliquer sur le fichier téléchargé pour installer VRT.

image
A On threat détection(si un malware est détecté)
Choisissez, en bas Disinfect,delete if cannot disinfected
Sélectionner les fichiers ou répertoires à analyser (disque dur, périphériques ou documents spécifiques) puis de lancer le processus Start Scan.

A la fin du scan:
Cliquer sur"Report" pour voir et enregistrer le rapport à poster.

Ensuite taper sur Exit pour désinstaller l'outil

Pour le pc de votre femme, je vous conseille d'ouvrir un autre sujet car je ne serai pas disponible ce Week-end.

A moins que cela puisse attendre.

En aucun cas, vous ne devez utiliser les outils précédents sauf s'ils vous sont prescrits par un conseiller.

Chaque désinfection est unique et les outils adaptés aux problèmes rencontrés.

Vous posterez le rapport de cet outil:



Téléchargez ZhpDiag de Coolman
Il ne nécessite aucune installation.
- Il peut être lancé depuis n'importe quelle unité de disque.
- Il peut être lancé d'une clé USB.

image
Cliquez sur le tournevis
Dans la fenêtre qui s'ouvre, cochez tout.
Clic sur la Loupe pour lancer le scan
Au bout d'un moment ,vous pouvez avoir à Accepter Sysinternal->I agree
Postez en le rapport qui apparait en cliquant l'appareil photo.



Modifié par pear le 23/07/2010 13:34
 Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 23/07/2010 à 15:17  
Petit astucien

528 Messages

merci pour tout,pear

je ne suis pas trop presse pour le pc de mon épouse

ça pourra attendre la semaine prochaine

sinon j'execute ZHPDiag sur son pc et non pas HIJACKTHIS c'est bien ça

et je poste le dernier rapport des que j'ai telechargé le logiciel

bon week end

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 
Publicité
 pear  Posté le 23/07/2010 à 16:05  
  Astucien


8679 Messages

sinon j'execute ZHPDiag sur son pc et non pas HijackThis c'est bien ça

oui, c'est cela et pour 2 raisons:

la première est que l'examen est bien plus approfondi,

la seconde est que, contrairement à Hijackthis, cela fonctionne sur tous les Windows.

A Lundi, si vous le voulez bien.

 Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 23/07/2010 à 16:12  
Petit astucien

528 Messages

bien sur merci et bon week-end

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 23/07/2010 à 21:11  
Petit astucien

528 Messages

voila le resultat

Autoscan: completed 1 minute ago (events: 2, objects: 936018, time: 04:50:09)
23/07/2010 18:20:10 Task started
23/07/2010 23:10:20 Task completed

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 romuald45  Posté le 23/07/2010 à 21:33  
Petit astucien

478 Messages

Suis calmé quand je regarde tout ca ! chapeau

 Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 pear  Posté le 26/07/2010 à 12:15  
  Astucien


8679 Messages

Bonjour,

Ce n'est pas le rapport attendu:c'est celui de KVRT

J'attends celui de Zhpdiag pour la 2 machine.

Cliquez sur le tournevis
Dans la fenêtre qui s'ouvre, cochez tout.
Clic sur la Loupe pour lancer le scan
Au bout d'un moment ,vous pouvez avoir à Accepter Sysinternal->I agree
Postez en le rapport qui apparait en cliquant l'appareil photo.



Modifié par pear le 26/07/2010 13:42
 Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 
Publicité
 philou83  Posté le 28/07/2010 à 13:19  
Petit astucien

528 Messages

Rapport de ZHPDiag v1.26.29 par Nicolas Coolman, Update du 21/07/2010
Run by philou at 28/07/2010 15:04:37
Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
Contact : nicolascoolman@yahoo.fr

---\\ Web Browser
MSIE: Internet Explorer v8.0.7600.16385
MFIE: Mozilla Firefox (3.6.6)

---\\ System Information
Platform : Windows 7 Home Premium (6.1.7600)
Processor: Intel64 Family 6 Model 28 Stepping 2, GenuineIntel
Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 1791 MB (46% free)
System drive C: has 53 GB (48%) free of 109 GB

---\\ Logged in mode
Computer Name: PHILOU-PC
User Name: philou
All Users Names: philou, HomeGroupUser$, Administrateur,
Unselected Option: None
Logged in as Administrator

---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 53 Go of 109 Go)
D:\ Hard drive, Flash drive, Thumb drive (Free 76 Go of 110 Go)
F:\ CD-ROM drive (Not Inserted)
H:\ CD-ROM drive (Not Inserted)


---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableTaskMgr: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableRegistryTools: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] NoDispScrSavPage: OK


---\\ Processus lancés
[MD5.5D61BE7DB55B026A5D61A3EED09D0EAD] - (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408]
[MD5.0C27193F356DC9403C6D4FC7103AA959] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files (x86)\Visagesoft\eXPert PDF 6 Converter\vspdfprsrv.exe [983040]
[MD5.CF4A0E2C240501C826977ACC5F0E8411] - (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [282792]
[MD5.CEDF6D51B66006142B892BE96F8E5E18] - (.Google Inc. - Google Toolbar Broker.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe [304304]
[MD5.CAB49391861142F93F514B3A8843DA07] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [481280]


---\\ Plugins de navigateurs Opera/Firefox(P1/P2)
P2 - FPN:Firefox Plugin Navigator . (.mozilla.org - Default Plug-in.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npnul32.dll
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape "9.3.3".) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
P2 - FPN: [HKLM] [@ma-config.com/HardwareDetection] - (.Cybelsoft - Plugin NPAPI Ma-Config.com.) -- C:\Program Files\ma-config.com\x86\nphardwaredetection.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.50524.0.) -- C:\Program Files (x86)\Microsoft Silverlight\4.0.50524.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8081.0709] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@nvidia.com/3DVision] - (.NVIDIA Corporation - NVIDIA 3D Vision plugin for Mozilla browsers.) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
P2 - FPN: [HKLM] [@nvidia.com/3DVisionStreaming] - (.NVIDIA Corporation - NVIDIA 3D Vision Streaming plugin for Mozilla browsers.) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=8] - (.Google Inc. - Google Update.) -- C:\Program Files (x86)\Google\Update\1.2.183.29\npGoogleOneClick8.dll


---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\Windows\SysWOW64\Userinit.exe,
F2 - REG:system.ini: VMApplet=C:\WINDOWS\system32\SystemPropertiesPerformance.exe


---\\ Pages de recherche d'Internet Explorer (R1)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch


---\\ Internet Explorer URLSearchHook (R3)
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (8.00.7600.16385 (win7_rtm.090713-1255)) -- C:\Windows\SysWOW64\ieframe.dll


---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll


---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll


---\\ Applications démarrées par registre & par dossier(O4)
O4 - HKLM\..\Run: [vspdfprsrv.exe] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files (x86)\Visagesoft\eXPert PDF 6 Converter\vspdfprsrv.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] . (.SUPERAntiSpyware.com - SUPERAntiSpyware Application.) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [vspdfprsrv.exe] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files (x86)\Visagesoft\eXPert PDF 6 Converter\vspdfprsrv.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKLM\..\policies\Explorer: [NoActiveDesktop] Data=1
O4 - HKLM\..\policies\Explorer: [NoActiveDesktopChanges] Data=1
O4 - HKLM\..\policies\Explorer: [ForceActiveDesktopOn] Data=0
O4 - HKLM\..\policies\Explorer: [NoDriveAutoRun] Data=0
O4 - HKLM\..\policies\Explorer: [NoDriveTypeAutoRun] Data=0
O4 - HKCU\..\policies\Explorer: [NoDriveAutoRun] Data=0
O4 - HKCU\..\policies\Explorer: [NoDriveTypeAutoRun] Data=0
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\Run: [mctadmin] C:\Windows\System32\mctadmin.exe (.not file.)
O4 - HKUS\S-1-5-20\..\Run: [mctadmin] C:\Windows\System32\mctadmin.exe (.not file.)

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 28/07/2010 à 13:20  
Petit astucien

528 Messages

---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~2\MICROS~1\Office12\EXCEL.exe
O8 - Extra context menu item: Google Sidewiki... . (.Google Inc. - Google Toolbar for Internet Explorer.) -- C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll


---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} . (.not file.) - (.not file.)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~2\MICROS~1\Office12\REFBARH.ICO


---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll


---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1279046332601
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} ("Ma-Config.com control) - http://www.ma-config.com/plugins/MaConfig_4_1_0_3.cab


---\\ Protocole additionnel et piratage de protocole (O18)
O18 - Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} . (.Belarc, Inc. - Belarc VoilaX Control.) -- C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll


---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - AppInit_DLLs: . (.Pas de propriétaire - Pas de description.) - (.not file.)


---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.


---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: SAS Core Service (!SASCORE) . (.SUPERAntiSpyware.com - Core Service.) - C:\Program Files\SUPERAntiSpyware\SASCORE64.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: GRegService (Greg_Service) . (.Acer Incorporated - Global Registration Service.) - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: NMSAccess (NMSAccess) . (.Pas de propriétaire - Pas de description.) - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
O23 - Service: NTI IScheduleSvc (NTI IScheduleSvc) . (.NewTech Infosystems, Inc. - Backup Manager Module.) - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\nvvsvc.exe
O23 - Service: C:\Windows\system32\samsrv.dll (SamSs) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\lsass.exe
O23 - Service: C:\Windows\system32\spoolsv.exe (Spooler) . (.Pas de propriétaire - Pas de description.) - C:\Windows\System32\spoolsv.exe
O23 - Service: C:\Windows\system32\sppsvc.exe (sppsvc) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\sppsvc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) . (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Updater Service (Updater Service) . (.Acer - Acer Update Service.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe


---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Maintenance en 1 clic.job


---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Pas de propriétaire - Pas de description.) -- "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 10.0 r32.) -- C:\Windows\SysWow64\Macromed\Flash\Flash10c.ocx


---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: C:\Windows\system32\drivers\afd.sys (AFD) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: avipbb (avipbb) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\avipbb.sys
O41 - Driver: (blbdrive) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\blbdrive.sys
O41 - Driver: Pilote de CD-ROM (cdrom) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\cdrom.sys
O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\system32\drivers\discache.sys (discache) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\discache.sys
O41 - Driver: Microsoft System Management BIOS Driver (mssmbios) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\mssmbios.sys
O41 - Driver: mwlPSDFilter (mwlPSDFilter) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
O41 - Driver: mwlPSDNServ (mwlPSDNServ) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
O41 - Driver: mwlPSDVDisk (mwlPSDVDisk) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
O41 - Driver: NetBIOS Interface (NetBIOS) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\netbios.sys
O41 - Driver: NetBT (NetBT) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\system32\drivers\nsiproxy.sys (nsiproxy) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\system32\drivers\pacer.sys (Psched) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\system32\wkssvc.dll (rdbss) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\system32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\system32\drivers\RDPENCDD.sys (RDPENCDD) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\system32\drivers\RdpRefMp.sys (RDPREFMP) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\rdprefmp.sys
O41 - Driver: SASDIFSV (SASDIFSV) . (.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASDIFSV64.SYS.) - C:\Program Files\SUPERAntiSpyware\SASDIFSV64.sys
O41 - Driver: SASKUTIL (SASKUTIL) . (.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASKUTIL64.SYS.) - C:\Program Files\SUPERAntiSpyware\SASKUTIL64.sys
O41 - Driver: Terminal Device Driver (TermDD) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\termdd.sys
O41 - Driver: truecrypt (truecrypt) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\truecrypt.sys
O41 - Driver: (VgaSave) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: Virtual WiFi Filter Driver (vwififlt) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\vwififlt.sys
O41 - Driver: WFP Lightweight Filter (WfpLwf) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\wfplwf.sys


---\\ Logiciels installés (O42)
O42 - Logiciel: 7-Zip 4.65 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: AGEIA PhysX v7.07.09 - (.AGEIA Technologies, Inc..) [HKLM]
O42 - Logiciel: Acer Arcade Deluxe - (.CyberLink Corp..) [HKLM]
O42 - Logiciel: Acer Backup Manager - (.NewTech Infosystems.) [HKLM]
O42 - Logiciel: Acer Registration - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: Acer ScreenSaver - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: Acer Updater - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: Acer eRecovery Management - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: Acrobat.com - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM]
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe Reader 9.3.3 MUI - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Advertising Center - (.Nero AG.) [HKLM]
O42 - Logiciel: Air Conflicts Single Player Demo - (.I wanna play.) [HKLM]
O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Auslogics Disk Defrag - (.Auslogics Software Pty Ltd.) [HKLM]
O42 - Logiciel: Avira AntiVir Personal - Free Antivirus - (.Avira GmbH.) [HKLM]
O42 - Logiciel: Backup Manager Advance - (.NewTech Infosystems.) [HKLM]
O42 - Logiciel: Belarc Advisor 8.1 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: CANAL+ pour Windows Media Center - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM]
O42 - Logiciel: CDBurnerXP - (.CDBurnerXP.) [HKLM]
O42 - Logiciel: Call of Duty Single Player Demo - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Call of Duty(R) 2 Demo - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Call of Duty(R) 4 - Modern Warfare(TM) - (.Activision.) [HKLM]
O42 - Logiciel: Clean Virus MSN - (.AxBx.) [HKLM]
O42 - Logiciel: ClickImpôts first step 2010.3.016 - (.Harvest.) [HKLM]
O42 - Logiciel: Conseiller de mise à niveau vers Windows 7 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: CrystalDiskInfo 3.2.0 - (.Crystal Dew World.) [HKLM]
O42 - Logiciel: Free FLV Converter V 6.8.0 - (.Koyote Soft.) [HKLM]
O42 - Logiciel: GRID - (.Codemasters.) [HKLM]
O42 - Logiciel: GT Interactive - Driver - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM]
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM]
O42 - Logiciel: Google Earth - (.Google.) [HKLM]
O42 - Logiciel: HDD Health v3.3 Beta - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Hotkey Utility - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: Identity Card - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: ImgBurn - (.LIGHTNING UK!.) [HKLM]
O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Internet TV pour Windows Media Center - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Line of Sight - Vietnam Demo - (.Infogrames.) [HKLM]
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM]
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM]
O42 - Logiciel: Medal of Honor Allied Assault Demo - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: MediaCoder x64 0.7.3.4685 - (.Broad Intelligence.) [HKLM]
O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM]
O42 - Logiciel: Microsoft Office Access MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Excel MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office InfoPath MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Outlook MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (German) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proofing (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM]
O42 - Logiciel: Microsoft Office Publisher MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Word MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Module de compatibilité pour Microsoft Office System 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Mozilla Firefox (3.6.6) - (.Mozilla.) [HKLM]
O42 - Logiciel: MyWinLocker - (.Egis Technology Inc..) [HKLM]
O42 - Logiciel: NVIDIA Stereoscopic 3D Driver - (.NVIDIA Corporation.) [HKLM]
O42 - Logiciel: Nero 9 Essentials - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero DiscSpeed - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero DiscSpeed Help - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero DriveSpeed - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero DriveSpeed Help - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero Express Help - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero InfoTool - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero InfoTool Help - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero Installer - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero Online Upgrade - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero StartSmart - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero StartSmart Help - (.Nero AG.) [HKLM]
O42 - Logiciel: Nero StartSmart OEM - (.Nero AG.) [HKLM]
O42 - Logiciel: NeroExpress - (.Nero AG.) [HKLM]
O42 - Logiciel: OpenAL - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Photo to Sketch 4.0 - (.Thinker Software, Inc..) [HKLM]
O42 - Logiciel: Race Driver - (.Codemasters.) [HKLM]
O42 - Logiciel: Ralink RT2860 Wireless LAN Card - (.Ralink.) [HKLM]
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM]
O42 - Logiciel: SIW version 2010.04.28 - (.Topala Software Solutions.) [HKLM]
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB982312) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB982331) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB982308) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Outlook 2007 (KB980376) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB982158) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Publisher 2007 (KB982124) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB982135) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB969613) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM]
O42 - Logiciel: Sniper Elite Demo - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: System Requirements Lab - (.Husdawg, LLC.) [HKLM]
O42 - Logiciel: Tidy Start Menu - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Tom Clancy's H.A.W.X - (.Ubisoft.) [HKLM]
O42 - Logiciel: TrueCrypt - (.TrueCrypt Foundation.) [HKLM]
O42 - Logiciel: TuneUp Utilities 2008 - (.TuneUp Software.) [HKLM]
O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM]
O42 - Logiciel: Update for Outlook 2007 Junk Email Filter (kb2202131) - (.Microsoft.) [HKLM]
O42 - Logiciel: Utilitaire d'identification du processeur Intel(R) - (.Intel Corporation.) [HKLM]
O42 - Logiciel: VLC media player 1.1.0 - (.VideoLAN.) [HKLM]
O42 - Logiciel: Welcome Center - (.Acer Incorporated.) [HKLM]
O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live FolderShare - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Movie Maker - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Media Center Add-in for Silverlight - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: eSobi v2 - (.esobi Inc..) [HKLM]
O42 - Logiciel: eXPert PDF 6 Converter - (.Visage Software.) [HKLM]
O42 - Logiciel: neroxml - (.Nero AG.) [HKLM]

---\\ HKCU & HKLM Software Keys
[HKCU\Software\2015]
[HKCU\Software\7-Zip]
[HKCU\Software\Acer]
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\Software\Google]
[HKCU\Software\AppDataLow\Software\Messenger_Plus_Live]
[HKCU\Software\AppDataLow\Software\Microsoft]
[HKCU\Software\AppDataLow\Software\Monitored]
[HKCU\Software\AppDataLow\Software\settings]
[HKCU\Software\AppDataLow\Software]
[HKCU\Software\AppDataLow]
[HKCU\Software\Auslogics]
[HKCU\Software\Avira]
[HKCU\Software\Belarc]
[HKCU\Software\Canneverbe Limited]
[HKCU\Software\Classes]
[HKCU\Software\CyberLink]
[HKCU\Software\DT Soft]
[HKCU\Software\EA Games]
[HKCU\Software\Google]
[HKCU\Software\HARVEST S.A.]
[HKCU\Software\IGA]
[HKCU\Software\IM Providers]
[HKCU\Software\ImgBurn]
[HKCU\Software\JEDI-VCL]
[HKCU\Software\Ledadu]
[HKCU\Software\Local AppWizard-Generated Applications]
[HKCU\Software\Macromedia]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MyDefrag]
[HKCU\Software\NVIDIA Corporation]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\ODBC]
[HKCU\Software\OEM]
[HKCU\Software\OrdinarySoft]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\Realtek]
[HKCU\Software\RonyaSoft]
[HKCU\Software\SUPERAntiSpyware.com]
[HKCU\Software\Safer Networking Limited]
[HKCU\Software\SecuROM]
[HKCU\Software\SeriousBit]
[HKCU\Software\Smart Soft]
[HKCU\Software\Softonic]
[HKCU\Software\Sysinternals]
[HKCU\Software\System Requirements Lab]
[HKCU\Software\TuneUp]
[HKCU\Software\Ubisoft]
[HKCU\Software\Visage Software]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\Wow6432Node]
[HKCU\Software\cybelsoft]
[HKCU\Software\eSobi]
[HKLM\Software\14919ea49a8f3b4aa3cf1058d9a64cec]
[HKLM\Software\AGEIA Technologies]
[HKLM\Software\Acer Incorporated]
[HKLM\Software\Activision]
[HKLM\Software\Adobe]
[HKLM\Software\Ahead]
[HKLM\Software\America Online]
[HKLM\Software\Audible]
[HKLM\Software\Avira]
[HKLM\Software\Belarc]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Codemasters]
[HKLM\Software\CyberLink]
[HKLM\Software\DT Soft]
[HKLM\Software\EA GAMES]
[HKLM\Software\EgisTec Egis Software Update]
[HKLM\Software\Electronic Arts]
[HKLM\Software\GT Interactive]
[HKLM\Software\Google]
[HKLM\Software\HaaliMkx]
[HKLM\Software\InstallShield]
[HKLM\Software\Intel Corporation]
[HKLM\Software\Intel]
[HKLM\Software\KOCH Media]
[HKLM\Software\Khronos]
[HKLM\Software\MC2]
[HKLM\Software\Macromedia]
[HKLM\Software\McAfeeInstaller]
[HKLM\Software\MediaCoder]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\NVIDIA Corporation]
[HKLM\Software\Nero]
[HKLM\Software\NewTech Infosystems]
[HKLM\Software\ODBC]
[HKLM\Software\OEM]
[HKLM\Software\OldTimer Tools]
[HKLM\Software\Patchou]
[HKLM\Software\Policies]
[HKLM\Software\Ralink]
[HKLM\Software\Realtek Semiconductor Corp.]
[HKLM\Software\Realtek]
[HKLM\Software\Rebellion]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Safer Networking Limited]
[HKLM\Software\TrendMicro]
[HKLM\Software\TuneUp]
[HKLM\Software\Ubisoft]
[HKLM\Software\Uniblue]
[HKLM\Software\Vid_0471]
[HKLM\Software\VideoLAN]
[HKLM\Software\Vietnamd]
[HKLM\Software\Visage Software]
[HKLM\Software\Wise Solutions]
[HKLM\Software\X-AVCSD]
[HKLM\Software\cybelsoft]
[HKLM\Software\instinno]
[HKLM\Software\lameme]
[HKLM\Software\mozilla.org]

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 28/07/2010 à 13:22  
Petit astucien

528 Messages

---\\ Contenu des dossiers Program Files (O43)
O43 - CFD:Common File Directory ----D- C:\Program Files\Acer
O43 - CFD:Common File Directory ----D- C:\Program Files\Acer Accessory Store
O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files
O43 - CFD:Common File Directory ----D- C:\Program Files\DVD Maker
O43 - CFD:Common File Directory ----D- C:\Program Files\EnhanceMySe7en
O43 - CFD:Common File Directory -SH-D- C:\Program Files\Fichiers communs
O43 - CFD:Common File Directory ----D- C:\Program Files\Free PDF to Word Converter
O43 - CFD:Common File Directory ----D- C:\Program Files\Google
O43 - CFD:Common File Directory ----D- C:\Program Files\Internet Explorer
O43 - CFD:Common File Directory ----D- C:\Program Files\ma-config.com
O43 - CFD:Common File Directory ----D- C:\Program Files\MediaCoder
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Baseline Security Analyzer 2
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Fix it Center
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Games
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Office
O43 - CFD:Common File Directory ----D- C:\Program Files\MSBuild
O43 - CFD:Common File Directory ----D- C:\Program Files\NVIDIA Corporation
O43 - CFD:Common File Directory ----D- C:\Program Files\Realtek
O43 - CFD:Common File Directory ----D- C:\Program Files\Reference Assemblies
O43 - CFD:Common File Directory ----D- C:\Program Files\SUPERAntiSpyware
O43 - CFD:Common File Directory ----D- C:\Program Files\TrueCrypt
O43 - CFD:Common File Directory --H-D- C:\Program Files\Uninstall Information
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Defender
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Journal
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Mail
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Media Player
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows NT
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Photo Viewer
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Portable Devices
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Sidebar
O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\Microsoft Shared
O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\Services
O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\SpeechEngines
O43 - CFD:Common File Directory ----D- C:\Program Files\Common Files\System
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\7-Zip
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Acer
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Acer Arcade Deluxe
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Activision
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Adobe
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\AGEIA Technologies
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Air Conflicts Demo
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Auslogics
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Avira
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\AxBx
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Belarc
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Call of Duty Single Player Demo
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\CCleaner
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\CDBurnerXP
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\ClickImpots first step 2010
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Codemasters
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\CrystalDiskInfo
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Cyberlink
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\DAEMON Tools Lite
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\EA GAMES
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\EgisTec
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\EgisTec Egis Software Update
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\eSobi
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Free FLV Converter
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Google
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\GT Interactive
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\HDD Health
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\ImgBurn
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Infogrames
O43 - CFD:Common File Directory --H-D- C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Intel Corporation
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Internet Explorer
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\ma-config.com
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Malwarebytes' Anti-Malware
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\MC2
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft Office
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft Visual Studio
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft Visual Studio 8
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft Works
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Microsoft.NET
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Mozilla Firefox
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\MSBuild
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\MSXML 4.0
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Nero
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\NewTech Infosystems
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\NVIDIA Corporation
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\OpenAL
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Photo to Sketch
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Realtek
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Reference Assemblies
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\SIW
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\SystemRequirementsLab
O43 - CFD:Common File Directory --H-D- C:\Program Files (x86)\Temp
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Tidy Start Menu
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Trend Micro
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\TuneUp Utilities 2008
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Ubisoft
O43 - CFD:Common File Directory --H-D- C:\Program Files (x86)\Uninstall Information
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\VideoLAN
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Visagesoft
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Defender
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Live
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Live SkyDrive
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Mail
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Media Player
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows NT
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Portable Devices
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Windows Sidebar
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\ZHPDiag
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Adobe
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Adobe AIR
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\DESIGNER
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\EgisTec
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Nero
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Oberon Media
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Services
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\System
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Windows Live
O43 - CFD:Common File Directory ----D- C:\Program Files (x86)\Common Files\Wise Installation Wizard


---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.2319E97B93B1BEFB67CC409280238E08] - 28/07/2010 - 14:48:03 --HA- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [15792]
O44 - LFC:[MD5.2319E97B93B1BEFB67CC409280238E08] - 28/07/2010 - 14:48:03 --HA- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [15792]
O44 - LFC:[MD5.A48D8C80F99A5473D174152BE48B05B5] - 28/07/2010 - 14:40:08 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\setupact.log [952]
O44 - LFC:[MD5.5FA1A030D3A12A0A97B27AE12A444392] - 28/07/2010 - 14:40:05 -S-A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.00000000000000000000000000000000] - 28/07/2010 - 12:06:05 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\WindowsUpdate.log [1622224]
O44 - LFC:[MD5.F3613E3306859C8754060FD58C520692] - 25/07/2010 - 16:54:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\PerfStringBackup.INI [1549700]
O44 - LFC:[MD5.3D5A741F9365F564897AB5127BB6DAFF] - 25/07/2010 - 16:54:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\perfc009.dat [106190]
O44 - LFC:[MD5.A2DE8FAD57124F84E42A452C077581EC] - 25/07/2010 - 16:54:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\perfc00C.dat [130548]
O44 - LFC:[MD5.B205320ED8B3B5B96D82210F11CC7401] - 25/07/2010 - 16:54:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\perfh009.dat [615810]
O44 - LFC:[MD5.6A1F361F58F46AD9A18BF315BB597B73] - 25/07/2010 - 16:54:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\perfh00C.dat [704242]
O44 - LFC:[MD5.F623EAD4C66CA3AAD40757C0A0BC0608] - 25/07/2010 - 14:43:24 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\Directx.log [219]
O44 - LFC:[MD5.36932522D014499D7F7B1BB921D05842] - 25/07/2010 - 11:26:16 ---A- . (.InstallShield Software Corporation - InstallShield® unInstaller.) -- C:\Windows\IsUn040c.exe [327168]
O44 - LFC:[MD5.DBA1E8AF3F5F51471D83CB4B86D1AE1E] - 24/07/2010 - 12:13:31 --HA- . (.Pas de propriétaire - Pas de description.) -- C:\sys13026.bin [111]
O44 - LFC:[MD5.84CB7CDA47ADBCED3DECCE61A23E9327] - 24/07/2010 - 12:12:47 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\PFRO.log [1092]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 22/07/2010 - 08:19:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\setuperr.log [0]
O44 - LFC:[MD5.815372073DA85B2098A37DED84083C8A] - 18/07/2010 - 11:14:48 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\_MSRSTRT.EXE [2560]
O44 - LFC:[MD5.515E4684008E955DE0C81E6A7AEA1C2A] - 12/07/2010 - 21:55:38 ---A- . (.InstallShield Software Corporation - InstallShield® unInstaller.) -- C:\Windows\IsUninst.exe [306688]
O44 - LFC:[MD5.C98FB52FE64DC1BC063AE0285E538198] - 10/07/2010 - 22:05:06 ---A- . (.Ralink Technology, Corp. - Ralink Extensions DLL.) -- C:\Windows\SysNative\RAIHV.dll [1119008]
O44 - LFC:[MD5.397BEB20D714482E34DDD358B1012861] - 10/07/2010 - 20:17:38 ---A- . (.Khronos Group - OpenCL Client DLL.) -- C:\Windows\SysNative\OpenCL.dll [65128]
O44 - LFC:[MD5.397BEB20D714482E34DDD358B1012861] - 10/07/2010 - 20:17:38 ---A- . (.Khronos Group - OpenCL Client DLL.) -- C:\Windows\System32\OpenCL.dll [56936]
O44 - LFC:[MD5.09A7171731E1C52B479DBCC088DE1826] - 10/07/2010 - 20:17:34 ---A- . (.NVIDIA Corporation - NVIDIA Compatible OpenGL ICD.) -- C:\Windows\SysNative\nvoglv64.dll [21662312]
O44 - LFC:[MD5.80BC4DF8485FA3DBB222C86946AE90E1] - 10/07/2010 - 20:17:33 ---A- . (.NVIDIA Corporation - NVIDIA Video Decoder MFT, Version 257.21.) -- C:\Windows\SysNative\nvdecodemft.dll [405608]
O44 - LFC:[MD5.80BC4DF8485FA3DBB222C86946AE90E1] - 10/07/2010 - 20:17:33 ---A- . (.NVIDIA Corporation - NVIDIA Video Decoder MFT, Version 257.21.) -- C:\Windows\System32\nvdecodemft.dll [332392]
O44 - LFC:[MD5.5176F27EA1058CE9ACFE71EA603DE59F] - 10/07/2010 - 20:17:33 ---A- . (.NVIDIA Corporation - NVIDIA Video Encoder MFT, Version 257.21.) -- C:\Windows\SysNative\nvencodemft.dll [3184744]
O44 - LFC:[MD5.5176F27EA1058CE9ACFE71EA603DE59F] - 10/07/2010 - 20:17:33 ---A- . (.NVIDIA Corporation - NVIDIA Video Encoder MFT, Version 257.21.) -- C:\Windows\System32\nvencodemft.dll [2890856]
O44 - LFC:[MD5.C0EE2A390C5697E5AA4B042AE04C4435] - 10/07/2010 - 20:17:29 ---A- . (.NVIDIA Corporation - NVIDIA CUDA Video Decode API, Version 257.2.) -- C:\Windows\SysNative\nvcuvid.dll [2291304]
O44 - LFC:[MD5.C0EE2A390C5697E5AA4B042AE04C4435] - 10/07/2010 - 20:17:29 ---A- . (.NVIDIA Corporation - NVIDIA CUDA Video Decode API, Version 257.2.) -- C:\Windows\System32\nvcuvid.dll [2145896]
O44 - LFC:[MD5.D4E6F282C7B5DA716B48FB9ED3219BAF] - 10/07/2010 - 20:17:29 ---A- . (.NVIDIA Corporation - NVIDIA CUDA Video Encoder, Version 257.21.) -- C:\Windows\SysNative\nvcuvenc.dll [2867816]
O44 - LFC:[MD5.D4E6F282C7B5DA716B48FB9ED3219BAF] - 10/07/2010 - 20:17:29 ---A- . (.NVIDIA Corporation - NVIDIA CUDA Video Encoder, Version 257.21.) -- C:\Windows\System32\nvcuvenc.dll [2632296]
O44 - LFC:[MD5.FCF7EA1DEDA449F26982D3BC202B7CFD] - 10/07/2010 - 20:17:26 ---A- . (.NVIDIA Corporation - NVIDIA Compatible CUDA Driver, Version 257..) -- C:\Windows\SysNative\nvcuda.dll [6065768]
O44 - LFC:[MD5.FCF7EA1DEDA449F26982D3BC202B7CFD] - 10/07/2010 - 20:17:26 ---A- . (.NVIDIA Corporation - NVIDIA Compatible CUDA Driver, Version 257..) -- C:\Windows\System32\nvcuda.dll [4513384]
O44 - LFC:[MD5.6BA49A4D4D8C3F777BB18EAC0550F7A6] - 10/07/2010 - 20:17:26 ---A- . (.NVIDIA Corporation - NVIDIA Compatible Compiler, Version 257.21.) -- C:\Windows\System32\nvcompiler.dll [10263144]
O44 - LFC:[MD5.6BA49A4D4D8C3F777BB18EAC0550F7A6] - 10/07/2010 - 20:17:25 ---A- . (.NVIDIA Corporation - NVIDIA Compatible Compiler, Version 257.21.) -- C:\Windows\SysNative\nvcompiler.dll [14511720]
O44 - LFC:[MD5.66DB8B6A6B119CDDE85BCE76A65BB2B0] - 10/07/2010 - 20:17:25 ---A- . (.NVIDIA Corporation - NVIDIA Driver CoInstaller.) -- C:\Windows\SysNative\nvcod.dll [255592]
O44 - LFC:[MD5.66DB8B6A6B119CDDE85BCE76A65BB2B0] - 10/07/2010 - 20:17:25 ---A- . (.NVIDIA Corporation - NVIDIA Driver CoInstaller.) -- C:\Windows\SysNative\nvcod1921.dll [255592]
O44 - LFC:[MD5.87ED84FF3DD18F7744CF7D45D3ACDA56] - 10/07/2010 - 19:09:43 ---A- . (.Windows (R) Codename Longhorn DDK provider - NVAPO.) -- C:\Windows\SysNative\nvapo64v.dll [62976]
O44 - LFC:[MD5.FD1F4BEC1A99EC8AB2D4431A16589DF9] - 10/07/2010 - 19:09:42 ---A- . (.NVIDIA Corporation - NVIDIA Uninstaller Utility.) -- C:\Windows\SysNative\nvuhda6.exe [541216]
O44 - LFC:[MD5.D84EF4631835C908C0A051EC125433C1] - 10/07/2010 - 19:09:41 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\nvhda.nvu [1481]
O44 - LFC:[MD5.DE00239530F39B2305EE0DFC0E92DF82] - 07/07/2010 - 10:17:14 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\Empty.ico [15867]
O44 - LFC:[MD5.2B86E520BAE90CFBD0B96474F3822B6D] - 07/07/2010 - 09:49:30 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\vsmon1.dll [23040]
O44 - LFC:[MD5.5A8832D860238033A9DF15890CD5A382] - 05/07/2010 - 23:44:47 ---A- . (.Creative Labs - OpenAL32.) -- C:\Windows\SysNative\wrap_oal.dll [466456]
O44 - LFC:[MD5.ADA2FC9FBB9DF9F342A8FA86FED2971F] - 05/07/2010 - 23:44:47 ---A- . (.Portions (C) Creative Labs Inc. and NVIDIA - Standard OpenAL(TM) Implementation.) -- C:\Windows\SysNative\OpenAL32.dll [121880]
O44 - LFC:[MD5.5A8832D860238033A9DF15890CD5A382] - 05/07/2010 - 23:44:46 ---A- . (.Creative Labs - OpenAL32.) -- C:\Windows\System32\wrap_oal.dll [444952]
O44 - LFC:[MD5.ADA2FC9FBB9DF9F342A8FA86FED2971F] - 05/07/2010 - 23:44:46 ---A- . (.Portions (C) Creative Labs Inc. and NVIDIA - Standard OpenAL(TM) Implementation.) -- C:\Windows\System32\OpenAL32.dll [109080]
O44 - LFC:[MD5.849946AD8A164ED1460B2C5F3D957500] - 05/07/2010 - 21:52:26 ---A- . (.J.C. Kessels - MyDefrag Script Interpreter.) -- C:\Windows\SysNative\MyDefragScreenSaver_v4.3.1.exe [1147392]
O44 - LFC:[MD5.FB76AB9B8C9869882EA8EFF133FB0F37] - 05/07/2010 - 21:52:26 ---A- . (.J.C. Kessels - MyDefrag Script Interpreter.) -- C:\Windows\SysNative\MyDefragScreenSaver_v4.3.1.scr [485376]
O44 - LFC:[MD5.E15B492959DFABC12AA4CA070B38F21A] - 05/07/2010 - 09:17:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\binkw32.dll [286208]
O44 - LFC:[MD5.BFAC0E7CFF0F71B0E43D4D36A722AB89] - 03/07/2010 - 15:46:18 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\FNTCACHE.DAT [425776]
O44 - LFC:[MD5.767EE8126468D91C5119F25714D78DAF] - 03/07/2010 - 14:14:32 ---A- . (.Microsoft Corporation - Bibliothèque d'assistance au déploiement de.) -- C:\Windows\SysNative\dfshim.dll [1942856]
O44 - LFC:[MD5.767EE8126468D91C5119F25714D78DAF] - 03/07/2010 - 14:14:32 ---A- . (.Microsoft Corporation - Bibliothèque d'assistance au déploiement de.) -- C:\Windows\System32\dfshim.dll [1130824]
O44 - LFC:[MD5.5DB2E96514C8722BDB60F0C8EA0CF865] - 01/07/2010 - 14:46:47 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\win.ini [510]
O44 - LFC:[MD5.3C9EBFF68D64090FCCB9971ACA6D9E18] - 01/07/2010 - 14:12:29 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\SysNative\atmfd.dll [366080]
O44 - LFC:[MD5.3C9EBFF68D64090FCCB9971ACA6D9E18] - 01/07/2010 - 14:12:29 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\System32\atmfd.dll [293888]
O44 - LFC:[MD5.628D70483747CB6F70A2372937865A13] - 01/07/2010 - 14:12:28 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\SysNative\atmlib.dll [46080]
O44 - LFC:[MD5.628D70483747CB6F70A2372937865A13] - 01/07/2010 - 14:12:28 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\System32\atmlib.dll [34304]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 29/06/2010 - 22:39:12 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\nsreg.dat [0]
O44 - LFC:[MD5.E57B778208C783D8DEBAB320C16A1B82] - 29/06/2010 - 16:41:40 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\drivers\StarOpen.sys [7168]
O44 - LFC:[MD5.D4DFBB1B1883E538BAAAEE67C3B3B7D3] - 29/06/2010 - 16:37:31 ---A- . (.TuneUp Software GmbH - TuneUp WinLogon Extension.) -- C:\Windows\System32\authuitu.dll [16640]
O44 - LFC:[MD5.5320997505594BD848F2B3F654716B62] - 29/06/2010 - 16:37:29 ---A- . (.TuneUp Software GmbH - TuneUp Drive Defrag-Dienst.) -- C:\Windows\SysNative\TuneUpDefragService.exe [425216]
O44 - LFC:[MD5.0DE7675CA390B9A755A85F00AB39A48F] - 29/06/2010 - 16:37:29 ---A- . (.TuneUp Software GmbH - TuneUp Theme Extension.) -- C:\Windows\System32\uxtuneup.dll [29440]
O44 - LFC:[MD5.D4DFBB1B1883E538BAAAEE67C3B3B7D3] - 29/06/2010 - 16:37:29 ---A- . (.TuneUp Software GmbH - TuneUp WinLogon Extension.) -- C:\Windows\SysNative\authuitu.dll [19712]
O44 - LFC:[MD5.0DE7675CA390B9A755A85F00AB39A48F] - 29/06/2010 - 16:37:27 ---A- . (.TuneUp Software GmbH - TuneUp Theme Extension.) -- C:\Windows\SysNative\uxtuneup.dll [36096]
O44 - LFC:[MD5.8B9AAD376688C8F2DD7853EE4E540563] - 29/06/2010 - 16:22:02 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\cod2demo.ini [291]
O44 - LFC:[MD5.EDCB1DFDE6D5935856EB25517B633DAC] - 29/06/2010 - 16:19:54 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\license.rtf [53560]
O44 - LFC:[MD5.EDCB1DFDE6D5935856EB25517B633DAC] - 29/06/2010 - 16:19:54 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\license.rtf [53560]
O44 - LFC:[MD5.21752FFB8445EC8BBC1A60CC36C5BF1F] - 29/06/2010 - 16:01:48 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\game.ini [331]
O44 - LFC:[MD5.954AD7BE8D3E69BE52A4DE969128E41A] - 29/06/2010 - 14:23:24 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysNative\oem_Get_OS_Language.log [341]


---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:Last File Created Prefetch 24/07/2010 - 00:29:43 ---A- C:\Windows\Prefetch\AgAppLaunch.db
O45 - LFCP:Last File Created Prefetch 24/07/2010 - 12:14:00 ---A- C:\Windows\Prefetch\NTOSBOOT-B00DFAAD.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 17:34:09 ---A- C:\Windows\Prefetch\WLXPHOTOGALLERY.EXE-23C23094.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 17:57:42 ---A- C:\Windows\Prefetch\AgCx_SC4.db
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 18:22:17 ---A- C:\Windows\Prefetch\DLLHOST.EXE-A010D183.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 19:19:56 ---A- C:\Windows\Prefetch\FIREFOX.EXE-359C61A4.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 20:28:49 ---A- C:\Windows\Prefetch\AgCx_SC1.db.trx
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 20:29:50 ---A- C:\Windows\Prefetch\AgCx_SC1.db
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 20:59:21 ---A- C:\Windows\Prefetch\MSIEXEC.EXE-8FFB1633.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 21:00:00 ---A- C:\Windows\Prefetch\MSIEXEC.EXE-CDBFC0F7.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 21:26:28 ---A- C:\Windows\Prefetch\WERFAULT.EXE-661188F3.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 21:26:49 ---A- C:\Windows\Prefetch\WN.EXE-346D85FF.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 21:29:38 ---A- C:\Windows\Prefetch\NOTEPAD.EXE-C5670914.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 21:30:41 ---A- C:\Windows\Prefetch\DTLITE.EXE-F2B47E43.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 21:30:53 ---A- C:\Windows\Prefetch\DLLHOST.EXE-63B92852.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 21:45:09 ---A- C:\Windows\Prefetch\WERFAULT.EXE-155C56CF.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 21:48:06 ---A- C:\Windows\Prefetch\DEVICEDISPLAYOBJECTPROVIDER.E-D37241ED.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 21:51:52 ---A- C:\Windows\Prefetch\GUARDHLP.EXE-6D0FD417.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 21:52:49 ---A- C:\Windows\Prefetch\AVGUARD.EXE-346125BE.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 21:54:39 ---A- C:\Windows\Prefetch\AVSHADOW.EXE-3CEC5035.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 21:58:47 ---A- C:\Windows\Prefetch\GAME.EXE-0438A05D.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 22:11:02 ---A- C:\Windows\Prefetch\RACEDRIVER.EXE-7252804A.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 22:12:21 ---A- C:\Windows\Prefetch\GRID.EXE-2584B0A0.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 22:31:16 ---A- C:\Windows\Prefetch\TASKMGR.EXE-4C8500BA.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 22:31:58 ---A- C:\Windows\Prefetch\ONECLICK.EXE-7440C711.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 22:32:03 ---A- C:\Windows\Prefetch\REGISTRYCLEANER.EXE-638E9BD0.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 22:32:13 ---A- C:\Windows\Prefetch\MBAM.EXE-493D9B94.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 22:35:48 ---A- C:\Windows\Prefetch\SOLITAIRE.EXE-556099DE.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 22:49:42 ---A- C:\Windows\Prefetch\NOTEPAD.EXE-032BB3D8.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 22:56:51 ---A- C:\Windows\Prefetch\EXPLORER.EXE-D5E97654.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 22:58:11 ---A- C:\Windows\Prefetch\MMC.EXE-9B848A1C.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 23:03:11 ---A- C:\Windows\Prefetch\WATADMINSVC.EXE-E43424E2.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 23:03:13 ---A- C:\Windows\Prefetch\SLUI.EXE-3E441AEE.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 23:06:11 ---A- C:\Windows\Prefetch\ENHANCEMYSE7EN.EXE-D8C0897F.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 23:10:56 ---A- C:\Windows\Prefetch\MCUPDATE.EXE-16C69080.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 23:14:34 ---A- C:\Windows\Prefetch\CCLEANER.EXE-32C46248.pf
O45 - LFCP:Last File Created Prefetch 25/07/2010 - 23:15:15 ---A- C:\Windows\Prefetch\SUPERANTISPYWARE.EXE-35E59EB7.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:15:31 ---A- C:\Windows\Prefetch\AVNOTIFY.EXE-6F8A1F6C.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:15:52 ---A- C:\Windows\Prefetch\UPDATE.EXE-5CF8B53B.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:16:20 ---A- C:\Windows\Prefetch\EHSCHED.EXE-467C570D.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:16:20 ---A- C:\Windows\Prefetch\EHTRAY.EXE-C0111622.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:16:28 ---A- C:\Windows\Prefetch\EHPRIVJOB.EXE-B398AE2E.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:17:21 ---A- C:\Windows\Prefetch\EHREC.EXE-979B7E74.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:17:30 ---A- C:\Windows\Prefetch\MCGLIDHOST.EXE-D116A317.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:17:33 ---A- C:\Windows\Prefetch\EHRECVR.EXE-62A89F4C.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:18:19 ---A- C:\Windows\Prefetch\SDCLT.EXE-94EAE077.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:18:51 ---A- C:\Windows\Prefetch\WUAUCLT.EXE-5D573F0E.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:18:52 ---A- C:\Windows\Prefetch\MPAS-D_BD1.EXE-779EC0BD.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:18:54 ---A- C:\Windows\Prefetch\MPMINISIGSTUB.EXE-8EC96B48.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:18:54 ---A- C:\Windows\Prefetch\MPSIGSTUB.EXE-5D0450B3.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:20:43 ---A- C:\Windows\Prefetch\DLLHOST.EXE-D9DCD0F3.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:21:35 ---A- C:\Windows\Prefetch\GOOGLEUPDATE.EXE-EB93BF1A.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:21:36 ---A- C:\Windows\Prefetch\GOOGLEUPDATESETUP_08959B9F761-A4AE81B9.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:21:51 ---A- C:\Windows\Prefetch\GOOGLETOOLBARMANAGER_223E2B8E-C2175D85.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:22:01 ---A- C:\Windows\Prefetch\GOOGLEUPDATERSERVICE.EXE-A6285BB5.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:40:09 ---A- C:\Windows\Prefetch\Layout.ini
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:40:19 ---A- C:\Windows\Prefetch\DEFRAG.EXE-3D9E8D72.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:40:19 ---A- C:\Windows\Prefetch\SVCHOST.EXE-67EC2DA7.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:43:06 ---A- C:\Windows\Prefetch\RUNDLL32.EXE-6FD72002.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:45:06 ---A- C:\Windows\Prefetch\POWERCFG.EXE-954C9186.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:50:00 ---A- C:\Windows\Prefetch\RUNDLL32.EXE-7FB5A65F.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:50:10 ---A- C:\Windows\Prefetch\SDIAGNHOST.EXE-B3171AA1.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:50:30 ---A- C:\Windows\Prefetch\VSSVC.EXE-6C8F0C66.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:50:32 ---A- C:\Windows\Prefetch\CSC.EXE-0E09149C.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:50:32 ---A- C:\Windows\Prefetch\CVTRES.EXE-F4BA0E72.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:50:32 ---A- C:\Windows\Prefetch\SVCHOST.EXE-6A249820.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:50:45 ---A- C:\Windows\Prefetch\W32TM.EXE-C4E0F88E.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:50:54 ---A- C:\Windows\Prefetch\PING.EXE-4A8A6853.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 11:53:14 ---A- C:\Windows\Prefetch\ALU.EXE-1C41B4D0.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 12:00:44 ---A- C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-766EFF52.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 12:05:58 ---A- C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 12:06:03 ---A- C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-3348865734-695653469-4227206278-1001.db
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 12:06:03 ---A- C:\Windows\Prefetch\AgGlUAD_S-1-5-21-3348865734-695653469-4227206278-1001.db
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 12:06:10 ---A- C:\Windows\Prefetch\AgRobust.db
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 12:06:10 ---A- C:\Windows\Prefetch\PfSvPerfStats.bin
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 12:06:22 ---A- C:\Windows\Prefetch\AgGlGlobalHistory.db
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 12:06:23 ---A- C:\Windows\Prefetch\AgGlFaultHistory.db
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 12:06:23 ---A- C:\Windows\Prefetch\AgGlFgAppHistory.db
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:41:27 ---A- C:\Windows\Prefetch\TASKENG.EXE-35FA9C06.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:41:32 ---A- C:\Windows\Prefetch\SVCHOST.EXE-27D91624.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:41:43 ---A- C:\Windows\Prefetch\SSUPDATE64.EXE-4300FC12.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:41:50 ---A- C:\Windows\Prefetch\WMPNSCFG.EXE-18FC9E64.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:41:53 ---A- C:\Windows\Prefetch\GOOGLECRASHHANDLER.EXE-72B9F98E.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:41:55 ---A- C:\Windows\Prefetch\WMPNETWK.EXE-F6E20E14.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:41:57 ---A- C:\Windows\Prefetch\GOOGLEUPDATE.EXE-0E1E7B82.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:42:08 ---A- C:\Windows\Prefetch\SPLWOW64.EXE-57576C25.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:42:09 ---A- C:\Windows\Prefetch\WMIPRVSE.EXE-E8B8DD29.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:42:56 ---A- C:\Windows\Prefetch\MSCORSVW.EXE-8CE1A322.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:42:57 ---A- C:\Windows\Prefetch\MSCORSVW.EXE-16B291C4.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:43:07 ---A- C:\Windows\Prefetch\SPPSVC.EXE-96070FE0.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:44:21 ---A- C:\Windows\Prefetch\WMIADAP.EXE-BB21CD77.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:45:15 ---A- C:\Windows\Prefetch\WLCOMM.EXE-81BAE51F.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:46:58 ---A- C:\Windows\Prefetch\FLASHUTIL10C.EXE-F9EB315F.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:47:58 ---A- C:\Windows\Prefetch\AGCP.EXE-4C29BE7E.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:49:14 ---A- C:\Windows\Prefetch\WSQMCONS.EXE-4048402C.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:49:23 ---A- C:\Windows\Prefetch\TASKHOST.EXE-A0F5E092.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:51:23 ---A- C:\Windows\Prefetch\CONHOST.EXE-0C6456FB.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:51:32 ---A- C:\Windows\Prefetch\MPCMDRUN.EXE-2C9109F9.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:51:42 ---A- C:\Windows\Prefetch\IEXPLORE.EXE-A033F7A0.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:53:26 ---A- C:\Windows\Prefetch\WERMGR.EXE-F439C551.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:53:36 ---A- C:\Windows\Prefetch\RUNDLL32.EXE-D2A040D5.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:57:01 ---A- C:\Windows\Prefetch\MSNMSGR.EXE-0A3C12F9.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:57:15 ---A- C:\Windows\Prefetch\IEXPLORE.EXE-058FE8F5.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:57:16 ---A- C:\Windows\Prefetch\GOOGLETOOLBARUSER_32.EXE-66EEE4D2.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:59:17 ---A- C:\Windows\Prefetch\ACRORD32.EXE-1066739E.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 14:59:25 ---A- C:\Windows\Prefetch\ADOBEARM.EXE-F9223367.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:02:47 ---A- C:\Windows\Prefetch\CONSENT.EXE-40419367.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:02:52 ---A- C:\Windows\Prefetch\DLLHOST.EXE-6389524F.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:02:54 ---A- C:\Windows\Prefetch\ZHPDIAG_1.26.TMP-E4A68E7A.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:02:56 ---A- C:\Windows\Prefetch\AUDIODG.EXE-AB22E9A6.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:02:58 ---A- C:\Windows\Prefetch\ZHPDIAG_1.26.TMP-F95446A4.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:03:07 ---A- C:\Windows\Prefetch\AVWSC.EXE-FC348DC0.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:03:29 ---A- C:\Windows\Prefetch\ZHPDIAG_1.26.EXE-C0E40EA5.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:03:29 ---A- C:\Windows\Prefetch\ZHPDIAG_1.26.TMP-8F08B0F9.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:03:39 ---A- C:\Windows\Prefetch\ZHPDIAG.EXE-6A1D0894.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:04:53 ---A- C:\Windows\Prefetch\SVCHOST.EXE-6E1A6101.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:05:40 ---A- C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-44162447.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:05:40 ---A- C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-69C456C3.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:06:12 ---A- C:\Windows\Prefetch\DLLHOST.EXE-4B6CB38A.pf
O45 - LFCP:Last File Created Prefetch 28/07/2010 - 15:06:19 ---A- C:\Windows\Prefetch\OBJECTIF TAROT.EXE-E57B5B35.pf


---\\ Déni du service (Local Security Authority) (LSA) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll


---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\SysWOW64\l3codeca.acm" . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll
O52 - TDSD: \drivers.desc\"C:\Windows\SysWOW64\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Pas de propriétaire - Pas de description.) -- (.not file.)


---\\ Microsoft Control Security Providers (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - "SecurityProviders"=credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - "SecurityProviders"=credssp.dll


---\\ Microsoft Windows Policies System (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 28/07/2010 à 13:25  
Petit astucien

528 Messages

---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\Policies\Explorer] - "NoDriveAutoRun"=0
O56 - MWPE:[HKCU\...\Policies\Explorer] - "NoDriveTypeAutoRun"=0
O56 - MWPE:[HKLM\...\Policies\Explorer] - "NoActiveDesktop"=1
O56 - MWPE:[HKLM\...\Policies\Explorer] - "NoActiveDesktopChanges"=1
O56 - MWPE:[HKLM\...\Policies\Explorer] - "ForceActiveDesktopOn"=0
O56 - MWPE:[HKLM\...\Policies\Explorer] - "NoDriveAutoRun"=0
O56 - MWPE:[HKLM\...\Policies\Explorer] - "NoDriveTypeAutoRun"=0


---\\ Liste des Drivers Système (SDL) (O58)
O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 05:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\system32\drivers\adp94xx.sys
O58 - SDL:[MD5.597F78224EE9224EA1A13D6350CED962] - 14/07/2009 - 05:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\system32\drivers\adpahci.sys
O58 - SDL:[MD5.E109549C90F62FB570B9540C4B148E54] - 14/07/2009 - 05:52:21 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\system32\drivers\adpu320.sys
O58 - SDL:[MD5.5812713A477A3AD7363C7438CA2EE038] - 14/07/2009 - 05:52:21 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\system32\drivers\aliide.sys
O58 - SDL:[MD5.7A4B413614C055935567CF88A9734D38] - 14/07/2009 - 05:52:21 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\system32\drivers\amdsata.sys
O58 - SDL:[MD5.F67F933E79241ED32FF46A4F29B5120B] - 14/07/2009 - 05:52:20 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows -.) -- C:\Windows\system32\drivers\amdsbs.sys
O58 - SDL:[MD5.B4AD0CACBAB298671DD6F6EF7E20679D] - 14/07/2009 - 05:52:21 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\system32\drivers\amdxata.sys
O58 - SDL:[MD5.C484F8CEB1717C540242531DB7845C4E] - 14/07/2009 - 05:52:21 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\system32\drivers\arc.sys
O58 - SDL:[MD5.019AF6924AEFE7839F61C830227FE79C] - 14/07/2009 - 05:52:21 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\system32\drivers\arcsas.sys
O58 - SDL:[MD5.5D4529AC4156E16BEDB01441AE0CF984] - 08/07/2009 - 13:49:16 ---A- . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driver.) -- C:\Windows\system32\drivers\athrx.sys
O58 - SDL:[MD5.ED2B23707F19CCC1B2A4382B05D31481] - 16/02/2010 - 14:24:00 ---A- . (.Avira GmbH - Avira Minifilter Driver.) -- C:\Windows\system32\drivers\avgntflt.sys
O58 - SDL:[MD5.C98FA6E5AD0E857D22716BD2B8B1F399] - 02/03/2010 - 13:35:01 ---A- . (.Avira GmbH - Avira Driver for Security Enhancement.) -- C:\Windows\system32\drivers\avipbb.sys
O58 - SDL:[MD5.B5ACE6968304A3900EEB1EBFD9622DF2] - 11/06/2009 - 00:34:23 ---A- . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) -- C:\Windows\system32\drivers\b57nd60a.sys
O58 - SDL:[MD5.F09EEE9EDC320B5E1501F749FDE686C8] - 11/06/2009 - 00:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\system32\drivers\BrFiltLo.sys
O58 - SDL:[MD5.B114D3098E9BDB8BEA8B053685831BE6] - 11/06/2009 - 00:41:06 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\system32\drivers\BrFiltUp.sys
O58 - SDL:[MD5.43BEA8D483BF1870F018E2D02E06A5BD] - 14/07/2009 - 05:19:07 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\system32\drivers\BrSerId.sys
O58 - SDL:[MD5.A6ECA2151B08A09CACECA35C07F05B42] - 11/06/2009 - 00:41:10 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\system32\drivers\BrSerWdm.sys
O58 - SDL:[MD5.B79968002C277E869CF38BD22CD61524] - 11/06/2009 - 00:41:10 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\system32\drivers\BrUsbMdm.sys
O58 - SDL:[MD5.A87528880231C54E75EA7A44943B38BF] - 11/06/2009 - 00:41:10 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\system32\drivers\BrUsbSer.sys
O58 - SDL:[MD5.3E5B191307609F7514148C6832BB0842] - 11/06/2009 - 00:34:28 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\system32\drivers\bxvbda.sys
O58 - SDL:[MD5.E19D3F095812725D88F9001985B94EDD] - 14/07/2009 - 05:52:31 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\cmdide.sys
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 05:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\system32\drivers\elxstor.sys
O58 - SDL:[MD5.DC5D737F51BE844D8C82C695EB17372F] - 11/06/2009 - 00:34:33 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\system32\drivers\evbda.sys
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 11/06/2009 - 00:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\system32\drivers\hcw85cir.sys
O58 - SDL:[MD5.0886D440058F203EBA0E1825E4355914] - 14/07/2009 - 05:47:48 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\system32\drivers\HpSAMD.sys
O58 - SDL:[MD5.D83EFB6FD45DF9D55E9A1AFC63640D50] - 14/07/2009 - 05:48:04 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\system32\drivers\iaStorV.sys
O58 - SDL:[MD5.5C18831C61933628F5BB0EA2675B9D21] - 14/07/2009 - 05:48:04 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\system32\drivers\iirsp.sys
O58 - SDL:[MD5.1A93E54EB0ECE102495A51266DCDB6A6] - 14/07/2009 - 05:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_fc.sys
O58 - SDL:[MD5.1047184A9FDC8BDBFF857175875EE810] - 14/07/2009 - 05:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas.sys
O58 - SDL:[MD5.30F5C0DE1EE8B5BC9306C1F0E4A75F93] - 14/07/2009 - 05:48:04 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas2.sys
O58 - SDL:[MD5.0504EACAFF0D3C8AED161C4B0D369D4A] - 14/07/2009 - 05:48:04 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_scsi.sys
O58 - SDL:[MD5.E330051CCE41EB4522E5DCEBC15ADCEA] - 29/04/2010 - 15:39:28 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\system32\drivers\mbam.sys
O58 - SDL:[MD5.A55805F747C6EDB6A9080D7C633BD0F4] - 14/07/2009 - 05:48:04 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for.) -- C:\Windows\system32\drivers\megasas.sys
O58 - SDL:[MD5.BAF74CE0072480C3B6B7C13B2A94D6B3] - 14/07/2009 - 05:48:04 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\system32\drivers\MegaSR.sys
O58 - SDL:[MD5.6FFECC25B39DC7652A0CEC0ADA9DB589] - 02/06/2009 - 15:15:30 ---A- . (.Egis Technology Inc. - PSD Filter Driver.) -- C:\Windows\system32\drivers\mwlPSDFilter.sys
O58 - SDL:[MD5.0BEFE32CA56D6EE89D58175725596A85] - 02/06/2009 - 15:15:30 ---A- . (.Egis Technology Inc. - MyWinLocker PSD Named Pipe Driver.) -- C:\Windows\system32\drivers\mwlPSDNserv.sys
O58 - SDL:[MD5.D43BC633B8660463E446E28E14A51262] - 02/06/2009 - 15:15:30 ---A- . (.Egis Technology Inc. - MyWinLocker PSD Virtual Disk Driver.) -- C:\Windows\system32\drivers\mwlPSDVDisk.sys
O58 - SDL:[MD5.254AF6DF67EAFA8C6E0AA0D316487673] - 12/10/2009 - 08:42:24 ---A- . (.Ralink Technology, Corp. - Ralink 802.11 Wireless Adapter Driver.) -- C:\Windows\system32\drivers\netr28x.sys
O58 - SDL:[MD5.77889813BE4D166CDAB78DDBA990DA92] - 14/07/2009 - 05:48:26 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\system32\drivers\nfrd960.sys
O58 - SDL:[MD5.64DDD0DEE976302F4BD93E5EFCC2F013] - 06/05/2009 - 03:46:08 ---A- . (.NewTech Infosystems, Inc. - NTI CD-ROM Filter Driver.) -- C:\Windows\system32\drivers\NTIDrvr.sys
O58 - SDL:[MD5.AD37248BD442D41C9A896E53EB8A85EE] - 22/08/2009 - 00:24:02 ---A- . (.NVIDIA Corporation - NVIDIA HDMI Audio Driver.) -- C:\Windows\system32\drivers\nvhda64v.sys
O58 - SDL:[MD5.2B9FD17492FBD799726369F2DB3E4827] - 08/06/2010 - 03:58:00 ---A- . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 257.21.) -- C:\Windows\system32\drivers\nvlddmkm.sys
O58 - SDL:[MD5.A85B4F2EF3A7304A5399EF0526423040] - 11/06/2009 - 00:35:35 ---A- . (.NVIDIA Corporation - NVIDIA MCP Networking Function Driver..) -- C:\Windows\system32\drivers\nvm62x64.sys
O58 - SDL:[MD5.0AA2A6AAE14BDF0BEA29056EE759B200] - 01/07/2009 - 08:20:56 ---A- . (.NVIDIA Corporation - NVIDIA MCP Networking Function Driver..) -- C:\Windows\system32\drivers\nvmf6264.sys
O58 - SDL:[MD5.3E38712941E9BB4DDBEE00AFFE3FED3D] - 14/07/2009 - 05:48:27 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\system32\drivers\nvraid.sys
O58 - SDL:[MD5.E58D81FB8616D0CB55C1E36AA0B213C9] - 28/06/2009 - 20:36:44 ---A- . (.NVIDIA Corporation - NVIDIA nForce(TM) SMU Microcontroller Driver.) -- C:\Windows\system32\drivers\nvsmu.sys
O58 - SDL:[MD5.477DC4D6DEB99BE37084C9AC6D013DA1] - 14/07/2009 - 05:45:45 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor.sys
O58 - SDL:[MD5.1E45F96342429D63DC30E0D9117DA3D8] - 21/09/2009 - 09:45:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor64.sys
O58 - SDL:[MD5.A53A15A11EBFD21077463EE2C7AFEEF0] - 14/07/2009 - 05:45:46 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\system32\drivers\ql2300.sys
O58 - SDL:[MD5.4F6D12B51DE1AAEFF7DC58C4D75423C8] - 14/07/2009 - 05:45:45 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\system32\drivers\ql40xx.sys
O58 - SDL:[MD5.BC64B75E8E0A0B8982AB773483164E72] - 20/07/2009 - 14:52:38 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\Windows\system32\drivers\RTKVHD64.sys
O58 - SDL:[MD5.3EA8A16169C26AFBEB544E0E48421186] - 11/06/2009 - 00:37:19 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\system32\drivers\secdrv.sys
O58 - SDL:[MD5.843CAF1E5FDE1FFD5FF768F23A51E2E1] - 14/07/2009 - 05:45:45 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\system32\drivers\sisraid2.sys
O58 - SDL:[MD5.6A6C106D42E9FFFF8B9FCB4F754F6DA4] - 14/07/2009 - 05:45:46 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\system32\drivers\sisraid4.sys
O58 - SDL:[MD5.00000000000000000000000000000000] - 29/06/2010 - 23:50:46 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\drivers\sptd.sys
O58 - SDL:[MD5.E57B778208C783D8DEBAB320C16A1B82] - 12/11/2009 - 14:48:56 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\drivers\StarOpen.sys
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 05:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\system32\drivers\stexstor.sys
O58 - SDL:[MD5.C4238AF5AAF167C3E5113F98F5427A0B] - 20/07/2010 - 18:29:58 ---A- . (.TrueCrypt Foundation - TrueCrypt Driver.) -- C:\Windows\system32\drivers\truecrypt.sys
O58 - SDL:[MD5.2E22C1FD397A5A9FFEF55E9D1FC96C00] - 06/05/2009 - 03:46:08 ---A- . (.NewTech Infosystems Corporation - NTI CDROM Filter Driver.) -- C:\Windows\system32\drivers\UBHelper.sys
O58 - SDL:[MD5.E7E39FC335904E95B4DC831842146623] - 25/06/2010 - 15:32:30 ---A- . (.Oracle Corporation - VirtualBox Support Driver.) -- C:\Windows\system32\drivers\VBoxDrv.sys
O58 - SDL:[MD5.82A6CB9C68E42C1088318EB8824D6F89] - 25/06/2010 - 15:32:34 ---A- . (.Oracle Corporation - VirtualBox Host-Only Network Adapter Driver.) -- C:\Windows\system32\drivers\VBoxNetAdp.sys
O58 - SDL:[MD5.1257BB5B21C8003AA52389C7788D0E10] - 25/06/2010 - 15:32:32 ---A- . (.Oracle Corporation - VirtualBox USB Monitor Driver.) -- C:\Windows\system32\drivers\VBoxUSBMon.sys
O58 - SDL:[MD5.E5689D93FFE4E5D66C0178761240DD54] - 14/07/2009 - 05:45:55 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\viaide.sys
O58 - SDL:[MD5.5E2016EA6EBACA03C04FEAC5F330D997] - 14/07/2009 - 05:45:55 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\system32\drivers\vsmraid.sys
O58 - SDL:[MD5.323860EC84BB332B613530D904380A4D] - 11/05/2009 - 12:49:28 ---A- . (.AVIRA GmbH - Avira AntiVir File Filter Driver.) -- C:\Windows\SysWOW64\drivers\avgntdd.sys
O58 - SDL:[MD5.7F8283EA8284DFDE226E3262BED8C92A] - 11/05/2009 - 12:49:28 ---A- . (.AVIRA GmbH - Avira Antivir File Filter Driver Manager.) -- C:\Windows\SysWOW64\drivers\avgntmgr.sys
O58 - SDL:[MD5.C7DD7D9739785BD3A6B8499EEC1DEE7E] - 29/04/2010 - 15:39:38 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\SysWOW64\drivers\mbamswissarmy.sys
O58 - SDL:[MD5.F92254B0BCFCD10CAAC7BCCC7CB7F467] - 12/11/2009 - 14:48:56 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\Windows\SysWOW64\drivers\StarOpen.sys


---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC:Last File Created 25/07/2010 - 00:36:44 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-24-2010( 23-51-16 ).SDB [5534]
O61 - LFC:Last File Created 25/07/2010 - 11:13:12 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLIST.DB [28455710]
O61 - LFC:Last File Created 25/07/2010 - 11:13:55 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLISTRELATED.DB [1482589]
O61 - LFC:Last File Created 25/07/2010 - 11:15:17 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-25-2010( 11-15-17 ).722.SDB [1554]
O61 - LFC:Last File Created 25/07/2010 - 11:25:40 -SH-- C:\Users\Public\Music\Sample Music\AlbumArtSmall.jpg [7315]
O61 - LFC:Last File Created 25/07/2010 - 11:25:40 -SH-- C:\Users\Public\Music\Sample Music\Folder.jpg [32764]
O61 - LFC:Last File Created 25/07/2010 - 11:25:41 -SH-- C:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Large.jpg [32764]
O61 - LFC:Last File Created 25/07/2010 - 11:25:41 -SH-- C:\Users\Public\Music\Sample Music\AlbumArt_{5FA05D35-A682-4AF6-96F7-0773E42D4D16}_Small.jpg [7315]
O61 - LFC:Last File Created 25/07/2010 - 11:43:25 ---A- C:\Users\philou\AppData\Roaming\ImgBurn\Graph Data Files\LITE-ON_DVDRW_SHM-165P6S_MS0R_DIMANCHE-25-JUILLET-2010_11-38_N-A.ibg [59068]
O61 - LFC:Last File Created 25/07/2010 - 11:43:42 ---A- C:\Users\philou\AppData\Roaming\ImgBurn\Log Files\ImgBurn.log [7466]
O61 - LFC:Last File Created 25/07/2010 - 12:00:02 ---A- C:\Users\philou\AppData\Roaming\Canneverbe Limited\CDBurnerXP\UserSettings.ini [1429]
O61 - LFC:Last File Created 25/07/2010 - 17:19:25 ---A- C:\Users\philou\AppData\Roaming\Microsoft\OIS\Toolbars.dat [666]
O61 - LFC:Last File Created 25/07/2010 - 17:19:25 ---A- C:\Users\philou\AppData\Roaming\Microsoft\Office\OIS12.pip [420]
O61 - LFC:Last File Created 25/07/2010 - 17:48:31 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-25-2010( 11-15-31 ).SDB [5534]
O61 - LFC:Last File Created 25/07/2010 - 17:54:04 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-25-2010( 17-54-4 ).149.SDB [1402]
O61 - LFC:Last File Created 25/07/2010 - 19:15:40 ---A- C:\Users\philou\AppData\Roaming\FreeFLVConverter\config.ini [36]
O61 - LFC:Last File Created 25/07/2010 - 20:59:41 ---A- C:\Users\All Users\Win7codecs\{3C32D47E-419E-48B9-8D9F-F9C489A2D299}\1036.MST [54784]
O61 - LFC:Last File Created 25/07/2010 - 20:59:49 ---A- C:\Users\All Users\Win7codecs\{3C32D47E-419E-48B9-8D9F-F9C489A2D299}\Win7codecs.msi [21562880]
O61 - LFC:Last File Created 25/07/2010 - 21:30:34 ---A- C:\Users\All Users\DAEMON Tools Lite\license.dat [1620]
O61 - LFC:Last File Created 25/07/2010 - 22:10:34 ---A- C:\Users\philou\AppData\Roaming\DAEMON Tools Lite\ImageCatalog.xml [5901]
O61 - LFC:Last File Created 25/07/2010 - 22:12:27 ---A- C:\Users\philou\Documents\Codemasters\GRID\hardwaresettings\hardware_settings_config.xml [1822]
O61 - LFC:Last File Created 25/07/2010 - 22:12:27 ---A- C:\Users\philou\Documents\Codemasters\GRID\hardwaresettings\hardware_settings_info.xml [4710]
O61 - LFC:Last File Created 25/07/2010 - 22:31:20 ---A- C:\Users\All Users\Codemasters\GRID\DataCache\philou\replay\replay.pbf [2096898048]
O61 - LFC:Last File Created 25/07/2010 - 22:31:20 -SHA- C:\Users\All Users\Codemasters\GRID\DataCache\radial.cdb [1497088]
O61 - LFC:Last File Created 25/07/2010 - 22:33:27 ---A- C:\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware\rules.ref [5306239]
O61 - LFC:Last File Created 25/07/2010 - 22:33:28 ---A- C:\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware\news.txt [60]
O61 - LFC:Last File Created 25/07/2010 - 22:33:29 ---A- C:\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware\link.txt [126]
O61 - LFC:Last File Created 25/07/2010 - 22:33:32 ---A- C:\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware\config.dat [778]
O61 - LFC:Last File Created 25/07/2010 - 22:33:32 ---A- C:\Users\All Users\Malwarebytes\Malwarebytes' Anti-Malware\local.dat [87]
O61 - LFC:Last File Created 25/07/2010 - 22:49:33 ---A- C:\Users\philou\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2010-07-25 (22-49-33).txt [1033]
O61 - LFC:Last File Created 25/07/2010 - 22:50:19 ---A- C:\Users\philou\AppData\Roaming\TuneUp Software\TuneUp Utilities\Backups\00000009.rcb [17300]
O61 - LFC:Last File Created 25/07/2010 - 22:57:55 ---A- C:\Users\philou\AppData\Roaming\Microsoft\HTML Help\hh.dat [8898]
O61 - LFC:Last File Created 25/07/2010 - 23:14:02 ---A- C:\Users\philou\AppData\Roaming\SeriousBit\EnhanceMySe7en\propshq.hdm [0]
O61 - LFC:Last File Created 25/07/2010 - 23:14:03 ---A- C:\Users\philou\AppData\Roaming\SeriousBit\EnhanceMySe7en\excls.exc [1940]
O61 - LFC:Last File Created 25/07/2010 - 23:14:07 ---A- C:\Users\philou\AppData\Roaming\SeriousBit\EnhanceMySe7en\logs.txt [29611]
O61 - LFC:Last File Created 25/07/2010 - 23:16:03 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLIST.ZIP [5372655]
O61 - LFC:Last File Created 25/07/2010 - 23:16:37 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLIST.BIN [13609038]
O61 - LFC:Last File Created 25/07/2010 - 23:16:48 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLISTRELATED.ZIP [182051]
O61 - LFC:Last File Created 25/07/2010 - 23:18:23 --HA- C:\Users\philou\AppData\Local\IconCache.db [5369463]
O61 - LFC:Last File Created 25/07/2010 - 23:18:40 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-25-2010( 17-55-59 ).SDB [14129]
O61 - LFC:Last File Created 28/07/2010 - 11:12:48 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-28-2010( 11-12-48 ).357.SDB [1554]
O61 - LFC:Last File Created 28/07/2010 - 11:13:03 ---A- C:\Users\All Users\NVIDIA\Resource.old [1021767]
O61 - LFC:Last File Created 28/07/2010 - 11:21:22 ---A- C:\Users\philou\AppData\Local\Google\Toolbar Cache\6.5.708.1000\fr\translate_languages.json.content [1481]
O61 - LFC:Last File Created 28/07/2010 - 11:53:04 ---A- C:\Users\All Users\Acer\Acer Updater\_UpdaterService_CFG.ini [94]
O61 - LFC:Last File Created 28/07/2010 - 11:53:27 ---A- C:\Users\All Users\Acer\Acer Updater\ServerInfo.xml [7731]
O61 - LFC:Last File Created 28/07/2010 - 11:53:27 ---A- C:\Users\All Users\Acer\Acer Updater\ServerInfo.xml_debug.xml [7731]
O61 - LFC:Last File Created 28/07/2010 - 11:53:27 ---A- C:\Users\All Users\Acer\Acer Updater\ServerInfo.xml_ori.xml [7654]
O61 - LFC:Last File Created 28/07/2010 - 11:53:28 ---A- C:\Users\All Users\Acer\Acer Updater\Info\ALU_Status_7.txt [0]
O61 - LFC:Last File Created 28/07/2010 - 12:05:51 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-28-2010( 11-13-30 ).SDB [5534]
O61 - LFC:Last File Created 28/07/2010 - 12:06:38 R---- C:\Users\All Users\BackupManager\Logs\SyncJob.log [11826]
O61 - LFC:Last File Created 28/07/2010 - 14:40:17 ---A- C:\Users\All Users\!SASCORE\AppLogs\SASCORE-7-28-2010( 14-40-17 ).313.SDB [1246]
O61 - LFC:Last File Created 28/07/2010 - 14:40:20 ---A- C:\Users\All Users\NVIDIA\Resource.dat [1021767]
O61 - LFC:Last File Created 28/07/2010 - 14:40:31 ---A- C:\Users\philou\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-28-2010( 14-40-31 ).SDB [5445]
O61 - LFC:Last File Created 28/07/2010 - 14:40:54 ---A- C:\Users\philou\Tracing\WindowsLiveMessenger-uccapi-0.uccapilog [0]
O61 - LFC:Last File Created 28/07/2010 - 14:44:57 ---A- C:\Users\philou\AppData\Roaming\Microsoft\Sticky Notes\StickyNotes.snt [4608]
O61 - LFC:Last File Created 28/07/2010 - 14:50:20 ---A- C:\Users\All Users\Acer\Acer Updater\_UpdaterService_LOG.txt [100456]
O61 - LFC:Last File Created 28/07/2010 - 14:51:18 -SHA- C:\Users\Administrateur\NTUSER.DAT [1048576]
O61 - LFC:Last File Created 28/07/2010 - 14:51:18 -SHA- C:\Users\Administrateur\ntuser.dat.LOG1 [262144]
O61 - LFC:Last File Created 28/07/2010 - 14:56:54 ---A- C:\Users\philou\AppData\Local\Temp\MyWinLocker\FileList.txt [116]
O61 - LFC:Last File Created 28/07/2010 - 14:56:56 ---A- C:\Users\philou\AppData\Roaming\Microsoft\MSN Messenger\sqmnoopt00.sqm [296]
O61 - LFC:Last File Created 28/07/2010 - 14:56:56 ---A- C:\Users\philou\AppData\Roaming\Microsoft\MSN Messenger\sqmnoopt01.sqm [200]
O61 - LFC:Last File Created 28/07/2010 - 14:56:57 ---A- C:\Users\philou\AppData\Roaming\Microsoft\MSN Messenger\sqmnoopt02.sqm [836]
O61 - LFC:Last File Created 28/07/2010 - 14:59:25 ---A- C:\Users\philou\AppData\Local\Temp\AdobeARM.log [4032]
O61 - LFC:Last File Created 28/07/2010 - 14:59:38 ---A- C:\Users\philou\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents [3072]
O61 - LFC:Last File Created 28/07/2010 - 15:00:17 ---A- C:\Users\philou\AppData\Roaming\Google\Local Search History\google%2Eweb.w [6784]


---\\ Liste des outils de nettoyage (LATC) (O63)
O63 - Logiciel: HijackThis 2.0.2 - (.TrendMicro.)
O63 - Logiciel: ZHPDiag 1.26 - (.Nicolas Coolman.)


---\\ Liste des services Legacy (LALS) (O64)
O64 - Services: CurCS - C:\Windows\system32\Drivers\20316601.sys - 20316601 (20316601) .(.Pas de propriétaire - Pas de description.) - LEGACY_20316601
O64 - Services: CurCS - C:\Windows\system32\Drivers\20316602.sys - 20316602 Boot Guard Driver (20316602) .(.Pas de propriétaire - Pas de description.) - LEGACY_20316602
O64 - Services: CurCS - C:\Windows\system32\drivers\afd.sys (AFD) .(.Pas de propriétaire - Pas de description.) - LEGACY_AFD
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\atapi.sys - IDE Channel (atapi) .(.Pas de propriétaire - Pas de description.) - LEGACY_ATAPI
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\avgntflt.sys - avgntflt (avgntflt) .(.Pas de propriétaire - Pas de description.) - LEGACY_AVGNTFLT
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\avipbb.sys - avipbb (avipbb) .(.Pas de propriétaire - Pas de description.) - LEGACY_AVIPBB
O64 - Services: CurCS - (.not file.) - Beep (Beep) .(.Pas de propriétaire - Pas de description.) - LEGACY_BEEP
O64 - Services: CurCS - C:\Windows\system32\browser.dll (bowser) .(.Pas de propriétaire - Pas de description.) - LEGACY_BOWSER
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\cdfs.sys - CD/DVD File System Reader (cdfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_CDFS
O64 - Services: CurCS - C:\Windows\system32\clfs.sys (CLFS) .(.Pas de propriétaire - Pas de description.) - LEGACY_CLFS
O64 - Services: CurCS - C:\Windows\system32\Drivers\cng.sys - CNG (CNG) .(.Pas de propriétaire - Pas de description.) - LEGACY_CNG
O64 - Services: CurCS - (.not file.) - cpuz132 (cpuz132) .(.Pas de propriétaire - Pas de description.) - LEGACY_CPUZ132
O64 - Services: CurCS - C:\Program Files\MediaCoder\sysInfoX64.sys - CrystalSysInfo (CrystalSysInfo) .(.Pas de propriétaire - Pas de description.) - LEGACY_CRYSTALSYSINFO
O64 - Services: CurCS - C:\Windows\system32\drivers\dfsc.sys (DfsC) .(.Pas de propriétaire - Pas de description.) - LEGACY_DFSC
O64 - Services: CurCS - C:\Windows\system32\drivers\discache.sys (discache) .(.Pas de propriétaire - Pas de description.) - LEGACY_DISCACHE
O64 - Services: CurCS - C:\Windows\system32\drivers\dxgkrnl.sys - LDDM Graphics Subsystem (DXGKrnl) .(.Pas de propriétaire - Pas de description.) - LEGACY_DXGKRNL
O64 - Services: CurCS - (.not file.) - FAT12/16/32 File System Driver (fastfat) .(.Pas de propriétaire - Pas de description.) - LEGACY_FASTFAT
O64 - Services: CurCS - C:\Windows\system32\drivers\fileinfo.sys (FileInfo) .(.Pas de propriétaire - Pas de description.) - LEGACY_FILEINFO
O64 - Services: CurCS - C:\Windows\system32\drivers\fltmgr.sys (FltMgr) .(.Pas de propriétaire - Pas de description.) - LEGACY_FLTMGR
O64 - Services: CurCS - C:\Windows\system32\Drivers\FS_REC.sys - Fs_Rec (Fs_Rec) .(.Pas de propriétaire - Pas de description.) - LEGACY_FS_REC
O64 - Services: CurCS - C:\Windows\system32\drivers\fvevol.sys (fvevol) .(.Pas de propriétaire - Pas de description.) - LEGACY_FVEVOL
O64 - Services: CurCS - C:\Windows\system32\drivers\http.sys (HTTP) .(.Pas de propriétaire - Pas de description.) - LEGACY_HTTP
O64 - Services: CurCS - C:\Windows\system32\drivers\hwpolicy.sys (hwpolicy) .(.Pas de propriétaire - Pas de description.) - LEGACY_HWPOLICY
O64 - Services: CurCS - C:\Windows\system32\Drivers\ksecdd.sys - KSecDD (KSecDD) .(.Pas de propriétaire - Pas de description.) - LEGACY_KSECDD
O64 - Services: CurCS - C:\Windows\system32\Drivers\ksecpkg.sys - KSecPkg (KSecPkg) .(.Pas de propriétaire - Pas de description.) - LEGACY_KSECPKG
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\lltdio.sys - Link-Layer Topology Discovery Mapper I/O Driver (lltdio) .(.Pas de propriétaire - Pas de description.) - LEGACY_LLTDIO
O64 - Services: CurCS - C:\Windows\system32\drivers\luafv.sys (luafv) .(.Pas de propriétaire - Pas de description.) - LEGACY_LUAFV
O64 - Services: CurCS - C:\Windows\system32\drivers\modem.sys - modem (modem) .(.Pas de propriétaire - Pas de description.) - LEGACY_MODEM
O64 - Services: CurCS - C:\Windows\system32\drivers\mountmgr.sys (mountmgr) .(.Pas de propriétaire - Pas de description.) - LEGACY_MOUNTMGR
O64 - Services: CurCS - C:\Windows\system32\Drivers\MPFP.sys - MPFP (MPFP) .(.Pas de propriétaire - Pas de description.) - LEGACY_MPFP
O64 - Services: CurCS - C:\Windows\system32\wkssvc.dll (mrxsmb) .(.Pas de propriétaire - Pas de description.) - LEGACY_MRXSMB
O64 - Services: CurCS - C:\Windows\system32\wkssvc.dll (mrxsmb10) .(.Pas de propriétaire - Pas de description.) - LEGACY_MRXSMB10
O64 - Services: CurCS - C:\Windows\system32\wkssvc.dll (mrxsmb20) .(.Pas de propriétaire - Pas de description.) - LEGACY_MRXSMB20
O64 - Services: CurCS - C:\Windows\system32\Drivers\MSFS.sys - Msfs (Msfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_MSFS
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\msisadrv.sys - msisadrv (msisadrv) .(.Pas de propriétaire - Pas de description.) - LEGACY_MSISADRV
O64 - Services: CurCS - C:\Windows\system32\drivers\mup.sys (Mup) .(.Pas de propriétaire - Pas de description.) - LEGACY_MUP
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\mwlPSDFilter.sys - mwlPSDFilter (mwlPSDFilter) .(.Pas de propriétaire - Pas de description.) - LEGACY_MWLPSDFILTER
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\mwlPSDNServ.sys - mwlPSDNServ (mwlPSDNServ) .(.Pas de propriétaire - Pas de description.) - LEGACY_MWLPSDNSERV
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys - mwlPSDVDisk (mwlPSDVDisk) .(.Pas de propriétaire - Pas de description.) - LEGACY_MWLPSDVDISK
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\nwifi.sys - NativeWiFi Filter (NativeWifiP) .(.Pas de propriétaire - Pas de description.) - LEGACY_NATIVEWIFIP
O64 - Services: CurCS - C:\Windows\system32\drivers\ndis.sys (NDIS) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDIS
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\ndisuio.sys - NDIS Usermode I/O Protocol (Ndisuio) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDISUIO
O64 - Services: CurCS - C:\Windows\system32\Drivers\NDPROXY.sys - NDProxy (NDProxy) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDPROXY
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\netbios.sys - NetBIOS Interface (NetBIOS) .(.Pas de propriétaire - Pas de description.) - LEGACY_NETBIOS
O64 - Services: CurCS - C:\Windows\system32\drivers\netbt.sys (NetBT) .(.Pas de propriétaire - Pas de description.) - LEGACY_NETBT
O64 - Services: CurCS - C:\Windows\system32\Drivers\NPFS.sys - Npfs (Npfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_NPFS
O64 - Services: CurCS - C:\Windows\system32\drivers\nsiproxy.sys (nsiproxy) .(.Pas de propriétaire - Pas de description.) - LEGACY_NSIPROXY
O64 - Services: CurCS - C:\Windows\system32\Drivers\NTFS.sys - Ntfs (Ntfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_NTFS
O64 - Services: CurCS - C:\Windows\system32\Drivers\NULL.sys - Null (Null) .(.Pas de propriétaire - Pas de description.) - LEGACY_NULL
O64 - Services: CurCS - C:\Windows\system32\drivers\pcw.sys - Performance Counters for Windows Driver (pcw) .(.Pas de propriétaire - Pas de description.) - LEGACY_PCW
O64 - Services: CurCS - C:\Windows\system32\drivers\peauth.sys - PEAUTH (PEAUTH) .(.Pas de propriétaire - Pas de description.) - LEGACY_PEAUTH
O64 - Services: CurCS - C:\Windows\system32\drivers\pacer.sys (Psched) .(.Pas de propriétaire - Pas de description.) - LEGACY_PSCHED
O64 - Services: CurCS - C:\Windows\system32\wkssvc.dll (rdbss) .(.Pas de propriétaire - Pas de description.) - LEGACY_RDBSS
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\RDPCDD.sys (RDPCDD) .(.Pas de propriétaire - Pas de description.) - LEGACY_RDPCDD
O64 - Services: CurCS - C:\Windows\system32\drivers\RDPENCDD.sys (RDPENCDD) .(.Pas de propriétaire - Pas de description.) - LEGACY_RDPENCDD
O64 - Services: CurCS - C:\Windows\system32\drivers\RdpRefMp.sys (RDPREFMP) .(.Pas de propriétaire - Pas de description.) - LEGACY_RDPREFMP
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\rspndr.sys - Link-Layer Topology Discovery Responder (rspndr) .(.Pas de propriétaire - Pas de description.) - LEGACY_RSPNDR
O64 - Services: CurCS - C:\Program Files\SUPERAntiSpyware\SASDIFSV64.sys - SASDIFSV (SASDIFSV) .(.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASDIFSV64.SYS.) - LEGACY_SASDIFSV
O64 - Services: CurCS - C:\Program Files\SUPERAntiSpyware\SASKUTIL64.sys - SASKUTIL (SASKUTIL) .(.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASKUTIL64.SYS.) - LEGACY_SASKUTIL
O64 - Services: CurCS - (.not file.) - Security Driver (secdrv) .(.Pas de propriétaire - Pas de description.) - LEGACY_SECDRV
O64 - Services: CurCS - C:\Windows\system32\Drivers\SETUP_9.0.0.722_23.07.2010_15-35DRV.sys - setup_9.0.0.722_23.07.2010_15-35drv (setup_9.0.0.722_23.07.2010_15-35drv) .(.Pas de propriétaire - Pas de description.) - LEGACY_SETUP_9.0.0.722_23.07.2010_15-35DRV
O64 - Services: CurCS - (.not file.) - Security Processor Loader Driver (spldr) .(.Pas de propriétaire - Pas de description.) - LEGACY_SPLDR
O64 - Services: CurCS - C:\Windows\system32\Drivers\sptd.sys - sptd (sptd) .(.Pas de propriétaire - Pas de description.) - LEGACY_SPTD
O64 - Services: CurCS - C:\Windows\system32\srvsvc.dll (srv) .(.Pas de propriétaire - Pas de description.) - LEGACY_SRV
O64 - Services: CurCS - C:\Windows\system32\srvsvc.dll (srv2) .(.Pas de propriétaire - Pas de description.) - LEGACY_SRV2
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\srvnet.sys - srvnet (srvnet) .(.Pas de propriétaire - Pas de description.) - LEGACY_SRVNET
O64 - Services: CurCS - C:\Windows\system32\drivers\tcpipreg.sys - TCP/IP Registry Compatibility (tcpipreg) .(.Pas de propriétaire - Pas de description.) - LEGACY_TCPIPREG
O64 - Services: CurCS - C:\Windows\system32\drivers\truecrypt.sys - truecrypt (truecrypt) .(.Pas de propriétaire - Pas de description.) - LEGACY_TRUECRYPT
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\udfs.sys - udfs (udfs) .(.Pas de propriétaire - Pas de description.) - LEGACY_UDFS
O64 - Services: CurCS - C:\Windows\system32\drivers\vga.sys - VgaSave (VgaSave) .(.Pas de propriétaire - Pas de description.) - LEGACY_VGASAVE
O64 - Services: CurCS - C:\Windows\system32\drivers\volmgrx.sys (volmgrx) .(.Pas de propriétaire - Pas de description.) - LEGACY_VOLMGRX
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\volsnap.sys - Volumes de stockage (volsnap) .(.Pas de propriétaire - Pas de description.) - LEGACY_VOLSNAP
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\vwififlt.sys - Virtual WiFi Filter Driver (vwififlt) .(.Pas de propriétaire - Pas de description.) - LEGACY_VWIFIFLT
O64 - Services: CurCS - C:\Windows\system32\drivers\Wdf01000.sys - Kernel Mode Driver Frameworks service (Wdf01000) .(.Pas de propriétaire - Pas de description.) - LEGACY_WDF01000
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\wfplwf.sys - WFP Lightweight Filter (WfpLwf) .(.Pas de propriétaire - Pas de description.) - LEGACY_WFPLWF
O64 - Services: CurCS - C:\Windows\system32\drivers\WudfPf.sys - User Mode Driver Frameworks Platform Driver (WudfPf) .(.Pas de propriétaire - Pas de description.) - LEGACY_WUDFPF


---\\ Observateur d'évènement d'application (OEA) (O66)
O66 - EventLog: ID=1000 (Application Error) - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
O66 - EventLog: ID=1000 (Application Error) - (.Pas de propriétaire - Pas de description.) -- C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3sp.exe
O66 - EventLog: ID=1000 (Application Error) - (.Adobe Systems Incorporated - Adobe Reader 9.3.) -- C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe
O66 - EventLog: ID=1000 (Application Error) - (.InstallShield Software Corporation - Setup.exe.) -- C:\Users\philou\Desktop\medal_of_honor_batailles_du_pacifique_demo_solo_anglais.exe


---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\system32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.evt> <evtfile>[HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\system32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <htmlfile>[HKCR\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe


---\\ Start Menu Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe


---\\ Search Browser Infection (SBI) (O69)
O69 - SBI: prefs.js [philou - 4lrj2qsx.default] user_pref("CT2124320.SearchEngine", "Search||http://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=CT2124320
[HKCU\Software\Microsoft\Internet Explorer\MenuExt\E&xporter vers Microsoft Excel]
[HKCU\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...]
O69 - SBI: SearchScopes ${searchCLSID}- (@ieframe.dll,-12512) - http://search.live.com
O69 - SBI: SearchScopes {67A2568C-7A0A-4EED-AECC-B5405DE63B64} [DefaultScope] - (Google) - http://www.google.com
O69 - SBI: SearchScopes {6A1806CD-94D4-4689-BA73-E35EA1EA9990}- (Google) - http://www.google.com


---\\ Recherche d'infection Master Boot Record (O80)
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
Run by philou at 28/07/2010 15:13:34
device: opened successfully
user: MBR read successfully
kernel: error reading MBR

End of the scan (1100 lines in 11mn 15s)

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 pear  Posté le 28/07/2010 à 14:02  
  Astucien


8679 Messages

Bonjour,

Si vous êtes sous Vista:Désactiver L'UAC ,avant sont utilisation.
Menu Démarrer \ Panneau de Configuration \ Comptes d'utilisateurs et protection des utilisateurs \ Comptes d'utilisateurs \ Activer ou désactiver le contrôle des comptes d'utilisateurs \ décoche la case Utiliser le contrôle ... et valider par OK ,
il sera demandé de redémarrer


Téléchargez AD-Remover sur le bureau
Déconnectez-vous et fermez toutes les applications en cours
Cliquer sur "Ad-R.exe" pour lancer l'installation et laisser les paramètres par défaut .
Une fenêtre s'affichera Vous prévenant des risques de l'utilisation de ce logiciel
Cliquez sur "OUI"
Double cliquer sur l'icône Ad-remover sur le bureau
image
Au menu principal choisir l'optionScanner et Validez

Patientez pendant le travail de l'outil.
Poster le rapport qui apparait à la fin .
Il est sauvegardé aussi sous C:\Ad-report.log

Ensuite

Relancer Ad- remover , choisir l'option Nettoyer

Il y aura 2 rapports à poster après Scanner et Nettoyer

Pour désinstaller AD-Remover, lancez avec l'option D puis supprimer l'icône du bureau.


 Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 
Publicité
 philou83  Posté le 30/07/2010 à 14:35  
Petit astucien

528 Messages

d'abord le scan

======= RAPPORT D'AD-REMOVER 2.0.0.1,D | UNIQUEMENT XP/VISTA/7 =======

Mis à jour par C_XX le 26/07/10 à 12:00
Contact: AdRemover.contact[AT]gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html

C:\Program Files (x86)\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 16:16:21 le 30/07/2010, Mode normal

Microsoft Windows 7 Édition Familiale Premium (X64)
philou@PHILOU-PC (Acer Aspire R3610)

============== RECHERCHE ==============

-- Fichier ouvert: C:\Users\philou\AppData\Roaming\Mozilla\FireFox\Profiles\4lrj2qsx.default\Prefs.js --
Ligne trouvée: user_pref("CT2124320.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER...
-- Fichier Fermé --


============== SCAN ADDITIONNEL ==============

** Mozilla Firefox Version [3.6.6 (fr)] **

-- C:\Users\philou\AppData\Roaming\Mozilla\FireFox\Profiles\4lrj2qsx.default\Prefs.js --
browser.startup.homepage_override.mstone, rv:1.9.2.6

========================================

** Internet Explorer Version [8.0.7600.16385] **

[HKCU\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\Windows\system32\blank.htm
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Show_ToolBar: yes
Start Page: hxxp://www.google.fr/

[HKLM\Software\Microsoft\Internet Explorer\Main]
AutoHide: yes
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Local Page: C:\Windows\SysWOW64\blank.htm
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/

[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm

========================================

C:\Program Files (x86)\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Program Files (x86)\Ad-Remover\Backup: 1 Fichier(s)

C:\Ad-Report-SCAN[1].txt - 30/07/2010 (2253 Octet(s))

Fin à: 16:20:04, 30/07/2010

============== E.O.F ==============

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 30/07/2010 à 14:46  
Petit astucien

528 Messages

et le clean

======= RAPPORT D'AD-REMOVER 2.0.0.1,D | UNIQUEMENT XP/VISTA/7 =======

Mis à jour par C_XX le 26/07/10 à 12:00
Contact: AdRemover.contact[AT]gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html

C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 16:36:23 le 30/07/2010, Mode normal

Microsoft Windows 7 Édition Familiale Premium (X64)
philou@PHILOU-PC (Acer Aspire R3610)

============== ACTION(S) ==============

(!) -- Fichiers temporaires supprimés.


-- Fichier ouvert: C:\Users\philou\AppData\Roaming\Mozilla\FireFox\Profiles\4lrj2qsx.default\Prefs.js --
Ligne supprimée: user_pref("CT2124320.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER...
-- Fichier Fermé --


============== SCAN ADDITIONNEL ==============

** Mozilla Firefox Version [3.6.6 (fr)] **

-- C:\Users\philou\AppData\Roaming\Mozilla\FireFox\Profiles\4lrj2qsx.default\Prefs.js --
browser.startup.homepage_override.mstone, rv:1.9.2.6

========================================

** Internet Explorer Version [8.0.7600.16385] **

[HKCU\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\Windows\system32\blank.htm
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/

[HKLM\Software\Microsoft\Internet Explorer\Main]
AutoHide: yes
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Local Page: C:\Windows\SysWOW64\blank.htm
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/

[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm

========================================

C:\Program Files (x86)\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Program Files (x86)\Ad-Remover\Backup: 16 Fichier(s)

C:\Ad-Report-CLEAN[1].txt - 30/07/2010 (2277 Octet(s))
C:\Ad-Report-SCAN[1].txt - 30/07/2010 (2382 Octet(s))

Fin à: 16:39:41, 30/07/2010

============== E.O.F ==============

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 pear  Posté le 30/07/2010 à 15:16  
  Astucien


8679 Messages

Vous êtes bien sûr qu'il s'agit de la seconde machine ?

Car elle semble impeccable.

Il y aurait un problème quelconque ?

 Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 01/08/2010 à 19:30  
Petit astucien

528 Messages

et voici le deuxieme

Rapport de ZHPDiag v1.26.39 par Nicolas Coolman, Update du 01/08/2010
Run by Goumon Sylvie at 01/08/2010 21:19:12
Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
Contact : nicolascoolman@yahoo.fr

---\\ Web Browser
MSIE: Internet Explorer v8.0.6001.18702

---\\ System Information
Platform : Microsoft Windows XP (5.1.2600) Service Pack 3
Processor: x86 Family 6 Model 28 Stepping 2, GenuineIntel
Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 1013 MB (53% free)
System drive C: has 74 GB (60%) free of 123 GB

---\\ Logged in mode
Computer Name: SYLVIE
User Name: Goumon Sylvie
All Users Names: SUPPORT_388945a0, HelpAssistant, Goumon Sylvie, Coco, ASPNET, Administrateur,
Unselected Option: O1,O45,O61,O65,O82
Logged in as Administrator

---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 74 Go of 123 Go)
D:\ Hard drive, Flash drive, Thumb drive (Free 20 Go of 26 Go)
E:\ Floppy drive, Flash card reader, USB Key (Not Inserted)


---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: Modified
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableTaskMgr: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableRegistryTools: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] NoDispScrSavPage: OK


---\\ Processus lancés
[MD5.9015BC03F62940527EC92D45EE89E46F] - (.Avira GmbH - Antivirus Scheduler.) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe [108289]
[MD5.E807CD642092A82A23615E2BC5C95579] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe [752184]
[MD5.8B333E7FF3147A63B15975B512364466] - (.Acronis - File Level CDP Manager Service.) -- C:\Program Files\Fichiers communs\Acronis\CDP\afcdpsrv.exe [2480048]
[MD5.B8720A787C1223492E6F319465E996CE] - (.Avira GmbH - Antivirus On-Access Service.) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe [185089]
[MD5.A06EFD4965F8A3F97A8C9A291D032678] - (.Pas de propriétaire - Inkjet Printer/Scanner/Fax Extended Servey.) -- C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104]
[MD5.FEF6D2D708CCEEA9FE7A335A745F8F5C] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\System Control Manager\MSIService.exe [159744]
[MD5.64E413BA0C529AA40C3924BBCC4153DB] - (.Pas de propriétaire - nTitles PSIService.) -- C:\WINDOWS\system32\PSIService.exe [174656]
[MD5.7548066DF68A8A1A56B043359F915F37] - (.Intel Corporation - RAID Monitor.) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [354840]
[MD5.8B0DE4B972DB725FB9D591E69CD236FB] - (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe [159744]
[MD5.CC632EB3A7D106464E933E7D53883550] - (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe [131072]
[MD5.6E0B205042FC3AF5DE84F90F875AFFDA] - (.Intel Corporation - igfxsrvc Module.) -- C:\WINDOWS\system32\igfxsrvc.exe [249856]
[MD5.07C0A803658AAD1A235DC656AF81563D] - (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.EXE [16862208]
[MD5.BB14D4F9F2452487CA11D6FB3921C372] - (.Mirco-Star International CO., LTD. - System Control Manager.) -- C:\Program Files\System Control Manager\MGSysCtrl.exe [782336]
[MD5.29680A793F690EEF4AAA68479D2A6DF8] - (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [209153]
[MD5.5AF1E9600E3FF841E522703A4993ED0C] - (.Intel Corporation - Event Monitor User Notification Tool.) -- C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904]
[MD5.6681780074ADAADECF0CE500C446D464] - (.CANON INC. - Canon My Printer.) -- C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1983816]
[MD5.223AD0CA4092AEFFE0D0DE25502A3DB6] - (.CANON INC. - CNSLMAIN.) -- C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [767312]
[MD5.E2724029D3648C2EB226D16678727FA9] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [202256]
[MD5.1324D84AF2961FACCE94A0BE7476AA2F] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [5140848]
[MD5.F9E34A3D0F07CE3CFE728B6579EDE976] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe [362968]
[MD5.5D61BE7DB55B026A5D61A3EED09D0EAD] - (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408]
[MD5.CC0D9AC0AD3AA394BBA42B0B304BCF13] - (.Nokia - Nokia Launch Application.) -- C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [1451520]
[MD5.87C345806EA8C572DFD17A63F3349F0F] - (.Nokia - PC Sync.) -- C:\Program Files\Nokia\Nokia PC Suite 7\PcSync2.exe [753664]
[MD5.B624202660474516E73AA95238FD9843] - (.Logitech, Inc. - Logitech SetPoint Event Manager (UNICODE).) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe [813584]
[MD5.BB7CA0EA29A18BB3BF190E0BF198D7DF] - (.Ralink Technology, Corp. - RaUI MFC Application.) -- C:\Program Files\RALINK\Common\RaUI.exe [1643808]
[MD5.8988D1F32F56B3CD3F0F6C39F8A91A98] - (.Nokia - ServiceLayer Module.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [657408]
[MD5.E96BC31E0114F0999FB0F92FC65D61CA] - (.Logitech, Inc. - Logitech KHAL Main Process.) -- C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE [55824]
[MD5.C538021B867C129458A3E73352B8638D] - (.Nokia - USB Media Server.) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe [132608]
[MD5.46A9D1FCC55EC6A62FE1D2ACE79C6CA8] - (.Nokia - Serial Media Server.) -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe [120832]
[MD5.57A6F9C77D22A01735075BEAE21BF26B] - (.Nokia Corporation - Mobile Phone API.) -- C:\Program Files\Fichiers communs\Nokia\MPAPI\MPAPI3s.exe [474624]
[MD5.385806015ADB90796A529201DBFF15A5] - (.Microsoft Corporation - Windows Live Call.) -- C:\Program Files\Windows Live\Messenger\wlcsdk.exe [583024]
[MD5.0411F7EE63AE48D2918AB4F2C79AB6C4] - (.Microsoft Corporation - Windows® installer.) -- C:\WINDOWS\system32\msiexec.exe [78848]
[MD5.EDD2A45C6D5885B050E428CE43810BBD] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [481792]


---\\ Plugins de navigateurs Opera/Firefox(P1/P2)
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
P2 - FPN: [HKLM] [@adobe.com/ShockwavePlayer] - (.Adobe Systems, Inc. - Adobe Shockwave for Director Netscape plug-in, version 11.0.) -- C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
P2 - FPN: [HKLM] [@canon.com/EPPEX] - (.CANON INC. - CANON iMAGE GATEWAY Album Plugin Utility Module.) -- C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.dll
P2 - FPN: [HKLM] [@ma-config.com/HardwareDetection] - (.Cybelsoft - Plugin NPAPI Ma-Config.com.) -- C:\Program Files\ma-config.com\nphardwaredetection.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.50524.0.) -- C:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/OfficeLive,version=1.3] - (.Microsoft Corp. - Office Live Update v1.3.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8081.0709] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
P2 - FPN: [HKLM] [@real.com/nppl3260;version=6.0.12.732] - (.RealNetworks, Inc. - RealPlayer(tm) LiveConnect-Enabled Plug-In.) -- c:\program files\real\realplayer\Netscape6\nppl3260.dll
P2 - FPN: [HKLM] [@real.com/nprjplug;version=1.0.3.732] - (.RealNetworks, Inc. - RealJukebox Netscape Plugin.) -- c:\program files\real\realplayer\Netscape6\nprjplug.dll
P2 - FPN: [HKLM] [@real.com/nprphtml5videoshim;version=1.0.0.0] - (.RealNetworks, Inc. - RealPlayer(tm) HTML5VideoShim Plug-In.) -- C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
P2 - FPN: [HKLM] [@real.com/nprpjplug;version=6.0.12.732] - (.RealNetworks, Inc. - 6.0.12.732.) -- c:\program files\real\realplayer\Netscape6\nprpjplug.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=8] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
P2 - FPN: [HKCU] [@facebook.com/FBPlugin,version=1.0.1] - (.Pas de propriétaire - Provides additional functionality on Facebook. See <a href="http://www.) -- C:\Documents and Settings\Goumon Sylvie\Application Data\Facebook\npfbplugin_1_0_1.dll


---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"


---\\ Pages de recherche d'Internet Explorer (R1)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie


---\\ Internet Explorer URLSearchHook (R3)
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (8.00.6001.18928 (longhorn_ie8_gdr.100503-1700)) -- C:\WINDOWS\system32\ieframe.dll


---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} . (.RealPlayer - RealPlayer Download and Record Plugin.) -- C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} . (.CANON INC. - Easy-WebPrint EX.) -- C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} . (.Microsoft Corporation - Search Helper for Internet Explorer.) -- C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} . (.Pas de propriétaire - Pas de description.) -- (.not file.)


---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} . (.CANON INC. - Easy-WebPrint EX.) -- C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll


---\\ Applications démarrées par registre & par dossier(O4)
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] . (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\Windows\RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] . (.Realtek Semiconductor Corp. - Realtek Azalia Audio - Event Monitor.) -- C:\Windows\ALCMTR.EXE
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UCam_Menu] . (.CyberLink Corp. - StartMen Application.) -- C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe
O4 - HKLM\..\Run: [MGSysCtrl] . (.Mirco-Star International CO., LTD. - System Control Manager.) -- C:\Program Files\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
O4 - HKLM\..\Run: [OM2_Monitor] . (.OLYMPUS IMAGING CORP. - resident module - First Starter.) -- C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe
O4 - HKLM\..\Run: [IAAnotif] . (.Intel Corporation - Event Monitor User Notification Tool.) -- C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] . (.Logitech, Inc. - Logitech KHAL Main Process.) -- C:\Windows\KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [CanonMyPrinter] . (.CANON INC. - Canon My Printer.) -- C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] . (.CANON INC. - CNSLMAIN.) -- C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe
O4 - HKLM\..\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [Service Scheduler2 Acronis] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Philips Intelligent Agent] . (.Philips Consumer Electronics - Philips Intelligent Agent.) -- C:\Program Files\Philips Intelligent Agent\Philips Intelligent Agent.exe
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [OM2_Monitor] . (.OLYMPUS IMAGING CORP. - resident module.) -- C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
O4 - HKCU\..\Run: [PC Suite Tray] . (.Nokia - Nokia Launch Application.) -- C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
O4 - HKCU\..\Run: [Nokia.PCSync] . (.Nokia - PC Sync.) -- C:\Program Files\Nokia\Nokia PC Suite 7\PcSync2.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.exe.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; OfficeLiveConnector.1.3; OfficeLivePatch.0.0) -http:\\www.miniclip.com\games\gutterball\fr\ (.not file.)
O4 - HKLM\..\policies\Explorer: [HonorAutoRunSetting] Data=1
O4 - HKCU\..\policies\Explorer: [NoDriveTypeAutoRun] Data=145
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-21-365965377-449381060-1485562393-1007\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-365965377-449381060-1485562393-1007\..\Run: [Philips Intelligent Agent] . (.Philips Consumer Electronics - Philips Intelligent Agent.) -- C:\Program Files\Philips Intelligent Agent\Philips Intelligent Agent.exe
O4 - HKUS\S-1-5-21-365965377-449381060-1485562393-1007\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-365965377-449381060-1485562393-1007\..\Run: [OM2_Monitor] . (.OLYMPUS IMAGING CORP. - resident module.) -- C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
O4 - HKUS\S-1-5-21-365965377-449381060-1485562393-1007\..\Run: [PC Suite Tray] . (.Nokia - Nokia Launch Application.) -- C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
O4 - HKUS\S-1-5-21-365965377-449381060-1485562393-1007\..\Run: [Nokia.PCSync] . (.Nokia - PC Sync.) -- C:\Program Files\Nokia\Nokia PC Suite 7\PcSync2.exe
O4 - HKUS\S-1-5-21-365965377-449381060-1485562393-1007\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.exe.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.2; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; OfficeLiveConnector.1.3; OfficeLivePatch.0.0) -http:\\www.miniclip.com\games\gutterball\fr\ (.not file.)
O4 - Global Startup: Logitech SetPoint.lnk . (.Logitech, Inc. - Logitech SetPoint Event Manager (UNICODE).) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Ralink Wireless Utility.lnk . (.Ralink Technology, Corp. - RaUI MFC Application.) -- C:\Program Files\RALINK\Common\RaUI.exe


---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~2\Office12\EXCEL.exe
O8 - Extra context menu item: Google Sidewiki... . (.Google Inc. - Google Toolbar for Internet Explorer.) -- C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll


---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} . (.not file.) - (.not file.)
O9 - Extra button: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} . (.not file.) - (.not file.)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~1\MICROS~2\Office12\REFBARH.ICO
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.not file.) - (.not file.)
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe


---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll


---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: CabBuilder (CabBuilder) - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {50DC58D0-C870-4BE6-BC41-971ED2D5F022} (HookWlmEx Control) - http://www.super-messenger.fr/tab/HookWlmEx.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211958002140
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233080893249
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (Ma-Config control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_4_0_2_0.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab


---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254


---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\System32\dimsntfy.dll
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\WINDOWS\System32\igfxdev.dll


---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSODL) (O21)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\system32\stobject.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll


---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll


---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Service Scheduler2 Acronis (AcrSch2Svc) . (.Pas de propriétaire - Pas de description.) - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) . (.Acronis - File Level CDP Manager Service.) - C:\Program Files\Fichiers communs\Acronis\CDP\afcdpsrv.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) . (.Intel Corporation - RAID Monitor.) - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) . (.Pas de propriétaire - Inkjet Printer/Scanner/Fax Extended Servey.) - C:\Program Files\Canon\IJPLM\IJPLMSVC.exe
O23 - Service: Micro Star SCM (Micro Star SCM) . (.Pas de propriétaire - Pas de description.) - C:\Program Files\System Control Manager\MSIService.exe
O23 - Service: ProtexisLicensing (ProtexisLicensing) . (.Pas de propriétaire - nTitles PSIService.) - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) . (.Ralink Technology, Corp. - RalinkRegistryWriter.) - C:\Program Files\RALINK\Common\RaRegistry.exe


---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Maintenance en 1 clic.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-365965377-449381060-1485562393-1007.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-365965377-449381060-1485562393-1007.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\User_Feed_Synchronization-{CA0E0FC4-662B-4544-A702-2E827DBE41FF}.job


---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Personnalisation du navigateur - >{DFB17AA8-042A-429D-987C-26CE244A4189} . (.Pas de propriétaire - Pas de description.) -- RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
O40 - ASIC: Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.6.0_05\bin\regutils.dll
O40 - ASIC: Adobe Shockwave Director 10.4 - {233C1507-6A77-46A4-9443-F871F945D258} . (.Adobe Systems, Inc. - Shockwave ActiveX Control.) -- C:\WINDOWS\system32\Adobe\Director\swdir.dll
O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msnetmtg.inf
O40 - ASIC: Windows Messenger 4.7 - {5945c046-1e7d-11d1-bc44-00c04fd912be} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msmsgs.inf
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\wmp11.inf
O40 - ASIC: Fax - {8b15971b-5355-4c82-8c07-7e181ea07608} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\fxsocm.inf
O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11cf-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 10.1 r53.) -- C:\WINDOWS\system32\Macromed\Flash\Flash10h.ocx


---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: avgio (avgio) . (.Avira GmbH - Avira AntiVir Support for Minifilter.) - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
O41 - Driver: avipbb (avipbb) . (.Avira GmbH - Avira Driver for RootKit Detection.) - C:\Windows\system32\DRIVERS\avipbb.sys
O41 - Driver: SASDIFSV (SASDIFSV) . (.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASDIFSV.SYS.) - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.sys
O41 - Driver: SASKUTIL (SASKUTIL) . (.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASKUTIL.SYS.) - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys
O41 - Driver: ssmdrv (ssmdrv) . (.Avira GmbH - AVIRA SnapShot Driver.) - C:\Windows\system32\DRIVERS\ssmdrv.sys


---\\ Logiciels installés (O42)
O42 - Logiciel: Acronis True Image Home - (.Acronis.) [HKLM]
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe Flash Player Plugin - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe Reader 8.2.3 - Français - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe Shockwave Player - (.Adobe Systems, Inc..) [HKLM]
O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Auslogics Disk Defrag - (.Auslogics Software Pty Ltd.) [HKLM]
O42 - Logiciel: Avira AntiVir Personal - Free Antivirus - (.Avira GmbH.) [HKLM]
O42 - Logiciel: Azurewave Wireless LAN - (.Azurewave.) [HKLM]
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM]
O42 - Logiciel: CDDRV_Installer - (.Logitech.) [HKLM]
O42 - Logiciel: Canon Easy-WebPrint EX - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Canon Inkjet Printer/Scanner/Fax Extended Survey Program - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Canon MP Navigator EX 3.0 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Canon MP250 series MP Drivers - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Canon Utilities Easy-PhotoPrint EX - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Canon Utilities My Printer - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Canon Utilities Solution Menu - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM]
O42 - Logiciel: Enregistrement utilisateur de Canon MP250 series - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Facebook Plug-In - (.Facebook, Inc..) [HKCU]
O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM]
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM]
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Intel® Matrix Storage Manager - (.Intel Corporation.) [HKLM]
O42 - Logiciel: Java(TM) 6 Update 5 - (.Sun Microsystems, Inc..) [HKLM]
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: KhalInstallWrapper - (.Logitech.) [HKLM]
O42 - Logiciel: Lecteur Windows Media 11 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Logitech SetPoint - (.Logitech.) [HKLM]
O42 - Logiciel: MSN - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: MSVC80_x86 - (.Nokia.) [HKLM]
O42 - Logiciel: MSVC80_x86_v2 - (.Nokia.) [HKLM]
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM]
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: MSXML 4.0 SP2 Parser and SDK - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Ma-Config.com - (.Cybelsoft.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Microsoft.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 1.1 French Language Pack - (.Microsoft.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB979906) - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 3.5 Language Pack SP1 - fra - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Internationalized Domain Names Mitigation APIs - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft National Language Support Downlevel APIs - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM]
O42 - Logiciel: Microsoft Office Access MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Excel MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office InfoPath MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Live Add-in 1.3 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Outlook Connector - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Outlook MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (German) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proofing (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM]
O42 - Logiciel: Microsoft Office Publisher MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Office Word MUI (French) 2007 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Search Enhancement Pack - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Sync Framework Runtime Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Sync Framework Services Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Nokia Connectivity Cable Driver - (.Nokia.) [HKLM]
O42 - Logiciel: Nokia PC Suite - (.Nokia.) [HKLM]
O42 - Logiciel: Nokia Software Updater - (.Nokia Corporation.) [HKLM]
O42 - Logiciel: OLYMPUS Master 2 - (.OLYMPUS IMAGING CORP..) [HKLM]
O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: PC Connectivity Solution - (.Nokia.) [HKLM]
O42 - Logiciel: Package de pilotes Windows - Nokia Modem (06/01/2009 7.01.0.4) - (.Nokia.) [HKLM]
O42 - Logiciel: Package de pilotes Windows - Nokia Modem (10/05/2009 4.2) - (.Nokia.) [HKLM]
O42 - Logiciel: Package de pilotes Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0) - (.Nokia.) [HKLM]
O42 - Logiciel: Philips Intelligent Agent - (.Philips.) [HKLM]
O42 - Logiciel: REALTEK GbE & FE Ethernet PCI-E NIC Driver - (.Realtek.) [HKLM]
O42 - Logiciel: Ralink RT2860 Wireless LAN Card - (.Ralink.) [HKLM]
O42 - Logiciel: RealPlayer - (.RealNetworks.) [HKLM]
O42 - Logiciel: RealUpgrade 1.0 - (.RealNetworks, Inc..) [HKLM]
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM]
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB982312) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB982331) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB982308) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Outlook 2007 (KB980376) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB982158) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Publisher 2007 (KB982124) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB982135) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB969613) - (.Microsoft.) [HKLM]
O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM]
O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM]
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics.) [HKLM]
O42 - Logiciel: System Control Manager - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: TuneUp Utilities 2008 - (.TuneUp Software.) [HKLM]
O42 - Logiciel: USB 2.0 Card Reader - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM]
O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Update for Outlook 2007 Junk Email Filter (kb2202131) - (.Microsoft.) [HKLM]
O42 - Logiciel: Utilitaire de sauvegarde Windows - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: VLC media player 1.0.3 - (.VideoLAN Team.) [HKLM]
O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Contrôle parental - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live FolderShare - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Toolbar - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Media Format 11 runtime - (.Pas de propriétaire.) [HKLM]

---\\ HKCU & HKLM Software Keys
[HKCU\Software\AVS4YOU]
[HKCU\Software\Acronis]
[HKCU\Software\Adobe]
[HKCU\Software\Ahead]
[HKCU\Software\AppDataLow\Software\Adobe]
[HKCU\Software\AppDataLow\Software\Macromedia]
[HKCU\Software\AppDataLow\Software]
[HKCU\Software\AppDataLow]
[HKCU\Software\Aurigma]
[HKCU\Software\Auslogics]
[HKCU\Software\Avira]
[HKCU\Software\Binary Noise]
[HKCU\Software\Canon]
[HKCU\Software\Classes]
[HKCU\Software\Conduit]
[HKCU\Software\Corel]
[HKCU\Software\Cyberlink]
[HKCU\Software\DT Soft]
[HKCU\Software\EASEUS]
[HKCU\Software\GameHouse]
[HKCU\Software\Google]
[HKCU\Software\Hewlett-Packard]
[HKCU\Software\HookNetwork]
[HKCU\Software\IM Providers]
[HKCU\Software\IncrediMail]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\Lake]
[HKCU\Software\Logitech]
[HKCU\Software\Macromedia]
[HKCU\Software\Magentic]
[HKCU\Software\Monitored]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\Nokia]
[HKCU\Software\ODBC]
[HKCU\Software\OLYMPUS]
[HKCU\Software\Philips]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\PowerQuest]
[HKCU\Software\RealNetworks]
[HKCU\Software\Realtek]
[HKCU\Software\Serif]
[HKCU\Software\Shareware.Pro-FR]
[HKCU\Software\Softonic]
[HKCU\Software\SweetIM]
[HKCU\Software\Synaptics]
[HKCU\Software\TomTom]
[HKCU\Software\Trolltech]
[HKCU\Software\TuneUp]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\cybelsoft]
[HKCU\Software\dog fork stupid]
[HKCU\Software\fcn]
[HKCU\Software\settings]
[HKLM\Software\AVS4YOU]
[HKLM\Software\Acronis]
[HKLM\Software\Adobe]
[HKLM\Software\Avira]
[HKLM\Software\Azurewave]
[HKLM\Software\Borland]
[HKLM\Software\C07ft5Y]
[HKLM\Software\Canon]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Conduit]
[HKLM\Software\CyberLink]
[HKLM\Software\DT Soft]
[HKLM\Software\DivXNetworks]
[HKLM\Software\Excid.com]
[HKLM\Software\GameHouse]
[HKLM\Software\Gemplus]
[HKLM\Software\Google]
[HKLM\Software\Hewlett-Packard]
[HKLM\Software\InstallShield]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\JavaSoft]
[HKLM\Software\Kodak]
[HKLM\Software\Lake]
[HKLM\Software\Licenses]
[HKLM\Software\Logitech]
[HKLM\Software\MSI]
[HKLM\Software\Macromedia]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nero]
[HKLM\Software\Nokia Mobile Phones]
[HKLM\Software\Nokia]
[HKLM\Software\ODBC]
[HKLM\Software\OLYMPUS]
[HKLM\Software\OMSI]
[HKLM\Software\PC Connectivity Solution]
[HKLM\Software\PCSuite]
[HKLM\Software\Policies]
[HKLM\Software\PowerQuest]
[HKLM\Software\Program Groups]
[HKLM\Software\Python]
[HKLM\Software\RALINK]
[HKLM\Software\RTLSetup]
[HKLM\Software\RealNetworks]
[HKLM\Software\Realtek Semiconductor Corp.]
[HKLM\Software\Realtek]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\RichFX]
[HKLM\Software\SUPERAntiSpyware.com]
[HKLM\Software\Schlumberger]
[HKLM\Software\Serif]
[HKLM\Software\Skunkstudios]
[HKLM\Software\SweetIM]
[HKLM\Software\Synaptics]
[HKLM\Software\System Control Manager]
[HKLM\Software\SystemCheck]
[HKLM\Software\TuneUp]
[HKLM\Software\USB 2.0 Card Reader]
[HKLM\Software\Ulead Systems]
[HKLM\Software\Vid_0471]
[HKLM\Software\VideoLAN]
[HKLM\Software\Windows 3.1 Migration Status]
[HKLM\Software\X-AVCSD]
[HKLM\Software\Xing Technology Corp.]
[HKLM\Software\ahead]
[HKLM\Software\cybelsoft]
[HKLM\Software\lameme]
[HKLM\Software\mozilla.org]

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
 philou83  Posté le 01/08/2010 à 19:31  
Petit astucien

528 Messages

et le deuxieme

---\\ Contenu des dossiers Program Files (O43)
O43 - CFD:Common File Directory ----D- C:\Program Files\Acronis
O43 - CFD:Common File Directory ----D- C:\Program Files\Adobe
O43 - CFD:Common File Directory ----D- C:\Program Files\AGI
O43 - CFD:Common File Directory ----D- C:\Program Files\Auslogics
O43 - CFD:Common File Directory ----D- C:\Program Files\Avira
O43 - CFD:Common File Directory ----D- C:\Program Files\Canon
O43 - CFD:Common File Directory --H-D- C:\Program Files\CanonBJ
O43 - CFD:Common File Directory ----D- C:\Program Files\CCleaner
O43 - CFD:Common File Directory ----D- C:\Program Files\Cirle Developement
O43 - CFD:Common File Directory ----D- C:\Program Files\ComPlus Applications
O43 - CFD:Common File Directory ----D- C:\Program Files\Cyberlink
O43 - CFD:Common File Directory ----D- C:\Program Files\DIFX
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers communs
O43 - CFD:Common File Directory ----D- C:\Program Files\GameHouse
O43 - CFD:Common File Directory ----D- C:\Program Files\Google
O43 - CFD:Common File Directory ----D- C:\Program Files\Hewlett-Packard
O43 - CFD:Common File Directory ----D- C:\Program Files\HomeCinema
O43 - CFD:Common File Directory ----D- C:\Program Files\Incredijeux
O43 - CFD:Common File Directory --H-D- C:\Program Files\InstallShield Installation Information
O43 - CFD:Common File Directory ----D- C:\Program Files\Intel
O43 - CFD:Common File Directory ----D- C:\Program Files\Internet Explorer
O43 - CFD:Common File Directory ----D- C:\Program Files\Java
O43 - CFD:Common File Directory ----D- C:\Program Files\List Coal Find
O43 - CFD:Common File Directory ----D- C:\Program Files\Logitech
O43 - CFD:Common File Directory ----D- C:\Program Files\ma-config.com
O43 - CFD:Common File Directory ----D- C:\Program Files\Messenger
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft
O43 - CFD:Common File Directory ----D- C:\Program Files\microsoft frontpage
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Office
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Office Outlook Connector
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Silverlight
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Sync Framework
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Visual Studio
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Visual Studio 8
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Works
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft.NET
O43 - CFD:Common File Directory ----D- C:\Program Files\Movie Maker
O43 - CFD:Common File Directory ----D- C:\Program Files\Mozilla Firefox
O43 - CFD:Common File Directory ----D- C:\Program Files\MSBuild
O43 - CFD:Common File Directory ----D- C:\Program Files\MSN
O43 - CFD:Common File Directory ----D- C:\Program Files\MSN Gaming Zone
O43 - CFD:Common File Directory ----D- C:\Program Files\MSXML 4.0
O43 - CFD:Common File Directory ----D- C:\Program Files\Nero
O43 - CFD:Common File Directory ----D- C:\Program Files\NetMeeting
O43 - CFD:Common File Directory ---AD- C:\Program Files\Neuf Cegetel
O43 - CFD:Common File Directory ----D- C:\Program Files\Nokia
O43 - CFD:Common File Directory ----D- C:\Program Files\Oberon Media
O43 - CFD:Common File Directory ----D- C:\Program Files\OLYMPUS
O43 - CFD:Common File Directory ----D- C:\Program Files\Online Services
O43 - CFD:Common File Directory ----D- C:\Program Files\Outlook Express
O43 - CFD:Common File Directory ----D- C:\Program Files\PC Connectivity Solution
O43 - CFD:Common File Directory ----D- C:\Program Files\Philips Intelligent Agent
O43 - CFD:Common File Directory ----D- C:\Program Files\RALINK
O43 - CFD:Common File Directory ----D- C:\Program Files\Real
O43 - CFD:Common File Directory ----D- C:\Program Files\Realtek
O43 - CFD:Common File Directory ----D- C:\Program Files\Reference Assemblies
O43 - CFD:Common File Directory ----D- C:\Program Files\Services en ligne
O43 - CFD:Common File Directory ----D- C:\Program Files\Synaptics
O43 - CFD:Common File Directory ----D- C:\Program Files\System Control Manager
O43 - CFD:Common File Directory ----D- C:\Program Files\TuneUp Utilities 2008
O43 - CFD:Common File Directory --H-D- C:\Program Files\Uninstall Information
O43 - CFD:Common File Directory ----D- C:\Program Files\USB 2.0 Card Reader
O43 - CFD:Common File Directory ----D- C:\Program Files\VideoLAN
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Live
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Live SkyDrive
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Media Connect 2
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Media Player
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows NT
O43 - CFD:Common File Directory ----D- C:\Program Files\WordPerfect Office X3
O43 - CFD:Common File Directory ----D- C:\Program Files\xerox
O43 - CFD:Common File Directory ----D- C:\Program Files\ZHPDiag
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Acronis
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Adobe
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Ahead
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\AVSMedia
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\CANON
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\DESIGNER
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\InstallShield
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Java
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Logishrd
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Microsoft Shared
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\MSSoap
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Nokia
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Oberon Media
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\ODBC
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\PCSuite
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Real
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Services
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\SpeechEngines
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\System
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Windows Live
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Wise Installation Wizard
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\xing shared


---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.00000000000000000000000000000000] - 01/08/2010 - 20:50:20 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\WindowsUpdate.log [1802309]
O44 - LFC:[MD5.BB42AF42B2B998CBB37EC1C6499290E4] - 01/08/2010 - 20:49:23 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\setupapi.log [7017]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 01/08/2010 - 20:48:52 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\0.log [0]
O44 - LFC:[MD5.00000000000000000000000000000000] - 01/08/2010 - 20:48:37 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\wiadebug.log [159]
O44 - LFC:[MD5.00000000000000000000000000000000] - 01/08/2010 - 20:48:36 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\wiaservc.log [50]
O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 01/08/2010 - 20:48:31 -S-A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\bootstat.dat [2048]
O44 - LFC:[MD5.00000000000000000000000000000000] - 01/08/2010 - 09:26:40 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\SchedLgU.Txt [32512]
O44 - LFC:[MD5.EF80272D0FE5D982AD23AF219CE91381] - 31/07/2010 - 08:03:20 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\wpa.dbl [1158]
O44 - LFC:[MD5.3238AF84D805BDE2FE14BD4D6FD37132] - 23/07/2010 - 13:15:45 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\AutoPartNt.let [1024]
O44 - LFC:[MD5.17ED48968AD3BFD96ED7E2A52459E95C] - 23/07/2010 - 13:14:28 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\AutoPartNt.exe [2487136]
O44 - LFC:[MD5.4FA0CA536DAB995BAF48BD41B4E2ED00] - 23/07/2010 - 12:57:25 ---A- . (.Acronis - File Level CDP Kernel Helper.) -- C:\WINDOWS\System32\drivers\afcdp.sys [160704]
O44 - LFC:[MD5.8DE3E45000BA8C9EBB16737D3F83E216] - 23/07/2010 - 12:57:21 ---A- . (.Acronis - Acronis Try&Decide Volume Filter Driver.) -- C:\WINDOWS\System32\drivers\tdrpm258.sys [911680]
O44 - LFC:[MD5.3E06987FEDBCDFBFF8E85EF8108565F9] - 23/07/2010 - 12:57:20 ---A- . (.Acronis - Acronis Backup Archive Explorer.) -- C:\WINDOWS\System32\drivers\timntr.sys [581984]
O44 - LFC:[MD5.4F7ED0C2F594F1B8E9CAFAB21EB86126] - 23/07/2010 - 12:57:13 ---A- . (.Acronis - Acronis Snapshot API.) -- C:\WINDOWS\System32\drivers\snapman.sys [166272]
O44 - LFC:[MD5.5866F5AC5FA90002CC1275789B715A60] - 22/07/2010 - 14:14:12 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\NeroDigital.ini [116]
O44 - LFC:[MD5.FDEC276302B6E2D735DBBCEAE3316486] - 10/07/2010 - 17:26:30 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\PerfStringBackup.INI [1133996]
O44 - LFC:[MD5.E0ABF2AA256C4F662E9D4937F1065165] - 10/07/2010 - 17:26:30 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\perfc009.dat [73224]
O44 - LFC:[MD5.9643C072C62773F0DA658BFADD185ECB] - 10/07/2010 - 17:26:30 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\perfc00C.dat [87024]
O44 - LFC:[MD5.2A997BF33EF04258100EA1A9792009FA] - 10/07/2010 - 17:26:30 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\perfh009.dat [446018]
O44 - LFC:[MD5.CFF273088E3DE6C959F91C441BED044D] - 10/07/2010 - 17:26:30 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\perfh00C.dat [515530]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 10/07/2010 - 13:10:42 --HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf [0]


---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)
O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll


---\\ Export de clé d'application autorisée (ECAA) (O47)
O47 - AAKE:Key Export SP - "C:\WINDOWS\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Messenger\msmsgs.exe" [Enabled] .(.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe
O47 - AAKE:Key Export SP - "C:\WINDOWS\system32\fxsclnt.exe" [Enabled] .(.Microsoft Corporation - Microsoft Fax Console.) -- C:\WINDOWS\system32\fxsclnt.exe
O47 - AAKE:Key Export SP - "C:\Program Files\NetMeeting\Conf.exe" [Enabled] .(.Microsoft Corporation - Windows® NetMeeting®.) -- C:\Program Files\NetMeeting\Conf.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" [Enabled] .(.Microsoft Corporation - Microsoft Office Outlook.) -- C:\Program Files\Microsoft Office\Office12\OUTLOOK.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Philips Intelligent Agent\Philips Intelligent Agent.exe" [Enabled] .(.Philips Consumer Electronics - Philips Intelligent Agent.) -- C:\Program Files\Philips Intelligent Agent\Philips Intelligent Agent.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Microsoft Corporation - Windows Live Call.) -- C:\Program Files\Windows Live\Messenger\wlcsdk.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.Microsoft Corporation - Windows Live Sync.) -- C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe
O47 - AAKE:Key Export SP - "C:\Program Files\RALINK\Common\RaUI.exe" [Enabled] .(.Ralink Technology, Corp. - RaUI MFC Application.) -- C:\Program Files\RALINK\Common\RaUI.exe
O47 - AAKE:Key Export SP - "C:\Program Files\ma-config.com\maconfservice.exe" [Enabled] .(.CybelSoft - Service de détection matériel.) -- C:\Program Files\ma-config.com\maconfservice.exe
O47 - AAKE:Key Export DP - "C:\WINDOWS\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export DP - "C:\Program Files\Messenger\msmsgs.exe" [Enabled] .(.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe
O47 - AAKE:Key Export DP - "C:\WINDOWS\system32\fxsclnt.exe" [Enabled] .(.Microsoft Corporation - Microsoft Fax Console.) -- C:\WINDOWS\system32\fxsclnt.exe
O47 - AAKE:Key Export DP - "C:\Program Files\NetMeeting\Conf.exe" [Enabled] .(.Microsoft Corporation - Windows® NetMeeting®.) -- C:\Program Files\NetMeeting\Conf.exe
O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Microsoft Corporation - Windows Live Call.) -- C:\Program Files\Windows Live\Messenger\wlcsdk.exe
O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.Microsoft Corporation - Windows Live Sync.) -- C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe


---\\ Déni du service (Local Security Authority) (LSA) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\WINDOWS\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\System32\msv1_0.dll


---\\ Image File Execution Options (IFEO) (O50)
O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - ntsd -d


---\\ MountPoints2 Shell Key (MPSK) (O51)
O51 - MPSK:{c3e7854a-2ca6-11dd-a36e-0015afb79adb}\Shell\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- F:\LaunchU3.exe -a (.not file.)
O51 - MPSK:{df7c0c48-a0ed-11dd-981f-0015afbc7e8c}\Shell\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- E:\InstallTomTomHOME.exe (.not file.)


---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.trspch"="tssoft32.acm" . (.DSP GROUP, INC. - Codec audio TrueSpeech(TM) DSP Group pour MSACM V3.50.) -- C:\WINDOWS\System32\tssoft32.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\System32\iccvid.dll
O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv41"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\WINDOWS\System32\ir41_32.ax
O52 - TDSD: \Drivers32\"msacm.sl_anet"="sl_anet.acm" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\System32\sl_anet.acm
O52 - TDSD: \Drivers32\"msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax
O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\WINDOWS\System32\ir50_32.dll
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm
O52 - TDSD: \drivers.desc\"sl_anet.acm"="Sipro Lab Telecom Audio Codec" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\System32\sl_anet.acm
O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax
O52 - TDSD: \drivers.desc\"ir50_32.dll"="Indeo® video 5.10" . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm
O52 - TDSD: \drivers.desc\"tssoft32.acm"="tssoft32.acm" . (.DSP GROUP, INC. - Codec audio TrueSpeech(TM) DSP Group pour MSACM V3.50.) -- C:\WINDOWS\System32\tssoft32.acm
O52 - TDSD: \drivers.desc\"iccvid.dll"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\System32\iccvid.dll
O52 - TDSD: \drivers.desc\"ir32_32.dll"="ir32_32.dll" . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ir32_32.dll
O52 - TDSD: \drivers.desc\"ir41_32.ax"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\WINDOWS\System32\ir41_32.ax


---\\ Microsoft Control Security Providers (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- C:\WINDOWS\system32\msapsspc.dll
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- C:\WINDOWS\system32\digest.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- C:\WINDOWS\system32\msapsspc.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- C:\WINDOWS\system32\digest.dll


---\\ Microsoft Windows Policies System (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1


---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145
O56 - MWPE:[HKLM\...\policies\Explorer] - "HonorAutoRunSetting"=1


---\\ Liste des Drivers Système (SDL) (O58)
O58 - SDL:[MD5.4FA0CA536DAB995BAF48BD41B4E2ED00] - 23/07/2010 - 12:57:25 ---A- . (.Acronis - File Level CDP Kernel Helper.) -- C:\WINDOWS\system32\drivers\afcdp.sys
O58 - SDL:[MD5.5B44C214F9CD9F590BE9125347610380] - 13/02/2009 - 14:17:49 ---A- . (.Avira GmbH - Avira AntiVir File Filter Driver.) -- C:\WINDOWS\system32\drivers\avgntdd.sys
O58 - SDL:[MD5.14FE36D8F2C6A2435275338D061A0B66] - 10/12/2009 - 18:03:36 ---A- . (.Avira GmbH - Avira Minifilter Driver.) -- C:\WINDOWS\system32\drivers\avgntflt.sys
O58 - SDL:[MD5.2DAA8CC2670720DEDDCC74A20EDE2EE9] - 13/02/2009 - 14:28:39 ---A- . (.Avira GmbH - Avira AntiVir File Filter Driver Manager.) -- C:\WINDOWS\system32\drivers\avgntmgr.sys
O58 - SDL:[MD5.AD9BD66A862116E79CB45BB6BE46055F] - 30/03/2009 - 12:32:47 ---A- . (.Avira GmbH - Avira Driver for RootKit Detection.) -- C:\WINDOWS\system32\drivers\avipbb.sys
O58 - SDL:[MD5.C3963D85B721A7F80D8A55F4E2867A3A] - 26/02/2010 - 14:32:44 ---A- . (.Nokia - Nokia USB Phone Bus Driver.) -- C:\WINDOWS\system32\drivers\ccdcmb.sys
O58 - SDL:[MD5.3859C69A77793180548802DAC9F34A38] - 26/02/2010 - 14:32:44 ---A- . (.Nokia - Nokia USB Phone Bus Driver.) -- C:\WINDOWS\system32\drivers\ccdcmbo.sys
O58 - SDL:[MD5.C9B25AE9B8ABD983C5AD3F8CBFAB0F9C] - 14/04/2008 - 16:00:00 ---A- . (.RAVISENT Technologies Inc. - Pilote principal CineMaster C 1.2 WDM.) -- C:\WINDOWS\system32\drivers\cinemst2.sys
O58 - SDL:[MD5.9624293E55AD405415862B504CA95B73] - 14/04/2008 - 16:00:00 ---A- . (.Compaq Computer Corporation - Compaq PA-1 Player Driver.) -- C:\WINDOWS\system32\drivers\cpqdap01.sys
O58 - SDL:[MD5.573C7D0A32852B48F3058CFD8026F511] - 14/04/2008 - 16:00:00 ---A- . (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) -- C:\WINDOWS\system32\drivers\hdaudbus.sys
O58 - SDL:[MD5.D483687EACE0C065EE772481A96E05F5] - 04/06/2009 - 19:43:16 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\WINDOWS\system32\drivers\iaStor.sys
O58 - SDL:[MD5.0F68E2EC713F132FFB19E45415B09679] - 19/12/2007 - 13:32:12 ---A- . (.Intel Corporation - Intel Graphics Miniport Driver.) -- C:\WINDOWS\system32\drivers\igxpmp32.sys
O58 - SDL:[MD5.9FFD1CF2A782F2560E78EEC4B8B8689E] - 17/06/2009 - 20:55:34 ---A- . (.Logitech, Inc. - Logitech Consumer Control Filter Driver..) -- C:\WINDOWS\system32\drivers\LBeepKE.sys
O58 - SDL:[MD5.7F9C7B28CF1C859E1C42619EEA946DC8] - 17/06/2009 - 20:56:06 ---A- . (.Logitech, Inc. - Logitech HID Filter Driver..) -- C:\WINDOWS\system32\drivers\LHidFilt.Sys
O58 - SDL:[MD5.AB33792A87285344F43B5CE23421BAB0] - 17/06/2009 - 20:56:16 ---A- . (.Logitech, Inc. - Logitech Mouse Filter Driver..) -- C:\WINDOWS\system32\drivers\LMouFilt.Sys
O58 - SDL:[MD5.77030525CD86A93F1AF34FA9B96D33CE] - 17/06/2009 - 20:56:32 ---A- . (.Logitech, Inc. - Logitech USB Filter Driver..) -- C:\WINDOWS\system32\drivers\LUsbFilt.sys
O58 - SDL:[MD5.BE984D604D91C217355CDD3737AAD25D] - 14/04/2008 - 16:00:00 ---A- . (.S3/Diamond Multimedia Systems - NikeDrv Usb Driver.) -- C:\WINDOWS\system32\drivers\nikedrv.sys
O58 - SDL:[MD5.FD2041E9BA03DB7764B2248F02475079] - 26/08/2008 - 09:26:12 ---A- . (.Nokia - PCCS Mode Change Filter Driver.) -- C:\WINDOWS\system32\drivers\pccsmcfd.sys
O58 - SDL:[MD5.80D317BD1C3DBC5D4FE7B1678C60CADD] - 14/04/2008 - 16:00:00 ---A- . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Library.) -- C:\WINDOWS\system32\drivers\ptilink.sys
O58 - SDL:[MD5.A56FE08EC7473E8580A390BB1081CDD7] - 14/04/2008 - 16:00:00 ---A- . (.S3/Diamond Multimedia Systems - Rio8Drv.sys Usb Driver.) -- C:\WINDOWS\system32\drivers\rio8drv.sys
O58 - SDL:[MD5.0A854DF84C77A0BE205BFEAB2AE4F0EC] - 14/04/2008 - 16:00:00 ---A- . (.S3/Diamond Multimedia Systems - RioDrv Usb Driver.) -- C:\WINDOWS\system32\drivers\riodrv.sys
O58 - SDL:[MD5.E8022899C37F2F4E497CF65AF7B91052] - 26/11/2009 - 18:02:34 ---A- . (.Ralink Technology, Corp. - Ralink 802.11 Wireless Adapter Driver.) -- C:\WINDOWS\system32\drivers\rt2860.sys
O58 - SDL:[MD5.7174F20AD9B7B7878A51ECCA03C499C2] - 07/05/2008 - 21:31:16 ---A- . (.Realtek Semiconductor Corporation - Realtek 10/100/1000 NDIS 5.1 Driver.) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys
O58 - SDL:[MD5.12CD9F66B64B25CBE18F1BB2C6F54832] - 07/05/2008 - 21:21:40 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys
O58 - SDL:[MD5.680A7ABA84A7863C89B5440C9C1E0895] - 10/06/2008 - 19:08:00 ---A- . (.Realtek Semiconductor Corporation - Realtek USB Mass Storage Driver for 2K/XP/Vista.) -- C:\WINDOWS\system32\drivers\RTS5121.sys
O58 - SDL:[MD5.F34C06D1C706A6D9433570B087A18B02] - 26/11/2009 - 18:02:52 ---A- . (.Printing Communications Assoc., Inc. (PCAUS - PCAUSA NDIS 5.0 SPR Protocol Driver.) -- C:\WINDOWS\system32\drivers\Scutum50.sys
O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 14/04/2008 - 16:00:00 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\WINDOWS\system32\drivers\secdrv.sys
O58 - SDL:[MD5.4F7ED0C2F594F1B8E9CAFAB21EB86126] - 23/07/2010 - 12:57:13 ---A- . (.Acronis - Acronis Snapshot API.) -- C:\WINDOWS\system32\drivers\snapman.sys
O58 - SDL:[MD5.00000000000000000000000000000000] - 04/01/2009 - 23:50:41 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\drivers\sptd.sys
O58 - SDL:[MD5.3AD0362CF68DE3AC500E981700242CCA] - 28/07/2009 - 19:08:08 ---A- . (.Avira GmbH - AVIRA SnapShot Driver.) -- C:\WINDOWS\system32\drivers\ssmdrv.sys
O58 - SDL:[MD5.A9AD7FAD373975D4DBEABB0EAD240BB1] - 11/01/2008 - 13:04:00 ---A- . (.Synaptics, Inc. - Synaptics Touchpad Driver.) -- C:\WINDOWS\system32\drivers\SynTP.sys
O58 - SDL:[MD5.8DE3E45000BA8C9EBB16737D3F83E216] - 23/07/2010 - 12:57:21 ---A- . (.Acronis - Acronis Try&Decide Volume Filter Driver.) -- C:\WINDOWS\system32\drivers\tdrpm258.sys
O58 - SDL:[MD5.3E06987FEDBCDFBFF8E85EF8108565F9] - 23/07/2010 - 12:57:20 ---A- . (.Acronis - Acronis Backup Archive Explorer.) -- C:\WINDOWS\system32\drivers\timntr.sys
O58 - SDL:[MD5.D74A8EC75305F1D3CFDE7C7FC1BD62A9] - 14/04/2008 - 16:00:00 ---A- . (.Toshiba Corporation - WDM Toshiba Tecra Video Capture Driver.) -- C:\WINDOWS\system32\drivers\tsbvcap.sys
O58 - SDL:[MD5.0CCADC7391021376EDBB8AA649D04E68] - 26/02/2010 - 14:32:46 ---A- . (.Nokia - Filter Driver for Nokia USB Phone Bus Driver.) -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
O58 - SDL:[MD5.68B4F83CCCF70A2FF32EE142C234332A] - 26/02/2010 - 14:32:58 ---A- . (.Nokia - Filter Driver for Nokia USB Phone Bus Driver.) -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
O58 - SDL:[MD5.55E01061C74A8CEFFF58DC36114A8D3F] - 14/04/2008 - 16:00:00 ---A- . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINDOWS\system32\drivers\vdmindvd.sys
O58 - SDL:[MD5.6D3ADA4CE95CECA7BCE527A08C4C474E] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ansi.sys
O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\country.sys
O58 - SDL:[MD5.C6D29F29DE7427B1B0775E53E577B623] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\himem.sys
O58 - SDL:[MD5.582BCDD47CF4B68B5CB528F18E3CB808] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\key01.sys
O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\keyboard.sys
O58 - SDL:[MD5.6942692061C46F2AA4A1597A150D3006] - 02/01/2009 - 21:44:07 -SHA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\KGyGaAvL.sys
O58 - SDL:[MD5.7D30A74B5FB9FE3B245A6CE5FBCD71D5] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntdos.sys
O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntdos404.sys
O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntdos411.sys
O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntdos412.sys
O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntdos804.sys
O58 - SDL:[MD5.CAAA108FD7BF71989946B39704323455] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntio.sys
O58 - SDL:[MD5.6F73F50162DEF60C84B725C18CD9140F] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntio404.sys
O58 - SDL:[MD5.0FDD5E69C1FF3B58043D44F2CC743D45] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntio411.sys
O58 - SDL:[MD5.8842837C4D8311BF8E72BEE8CCC42217] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntio412.sys
O58 - SDL:[MD5.6B56CEB3C6F9D5CD7293DBD9FE23B311] - 14/04/2008 - 16:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntio804.sys


---\\ Recherche heuristique Magic.control (HSMI) (O59)
O59 - HSMI:Heuristic Search MagicControl Infection - C:\Documents and Settings\Goumon Sylvie\Local Settings\Application Data\gciymms_nav.dat
O59 - HSMI:Heuristic Search MagicControl Infection - C:\Documents and Settings\Goumon Sylvie\Local Settings\Application Data\gciymms_navps.dat


---\\ Alternate Data Stream File (ADS) (O62)
O62 - ADS:Alternate Data Stream File - C:\WINDOWS\System32\Thumbs.db:encryptable


---\\ Liste des outils de nettoyage (LATC) (O63)
O63 - Logiciel: ZHPDiag 1.26 - (.Nicolas Coolman.)
O63 - Logiciel: Dial-a-fix - (.Djlizard.)


---\\ Liste des services Legacy (LALS) (O64)
O64 - Services: CurCS - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe - Service Scheduler2 Acronis (AcrSch2Svc) .(.Pas de propriétaire - Pas de description.) - LEGACY_ACRSCH2SVC
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\afcdp.sys - afcdp (afcdp) .(.Acronis - File Level CDP Kernel Helper.) - LEGACY_AFCDP
O64 - Services: CurCS - C:\Program Files\Fichiers communs\Acronis\CDP\afcdpsrv.exe - Acronis Nonstop Backup service (afcdpsrv) .(.Acronis - File Level CDP Manager Service.) - LEGACY_AFCDPSRV
O64 - Services: CurCS - C:\Program Files\Avira\AntiVir Desktop\sched.exe - Avira AntiVir Planificateur (AntiVirSchedulerService) .(.Avira GmbH - Antivirus Scheduler.) - LEGACY_ANTIVIRSCHEDULERSERVICE
O64 - Services: CurCS - C:\Program Files\Avira\AntiVir Desktop\avguard.exe - Avira AntiVir Guard (AntiVirService) .(.Avira GmbH - Antivirus On-Access Service.) - LEGACY_ANTIVIRSERVICE
O64 - Services: CurCS - C:\Program Files\Avira\AntiVir Desktop\avgio.sys - avgio (avgio) .(.Avira GmbH - Avira AntiVir Support for Minifilter.) - LEGACY_AVGIO
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\avgntflt.sys - avgntflt (avgntflt) .(.Avira GmbH - Avira Minifilter Driver.) - LEGACY_AVGNTFLT
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\avipbb.sys - avipbb (avipbb) .(.Avira GmbH - Avira Driver for RootKit Detection.) - LEGACY_AVIPBB
O64 - Services: CurCS - (.not file.) - BullGuard File Monitor Driver (BdFileSpy) .(.Pas de propriétaire - Pas de description.) - LEGACY_BDFILESPY
O64 - Services: CurCS - (.not file.) - Lanceur de processus serveur DCOM (DcomLaunch) .(.Pas de propriétaire - Pas de description.) - LEGACY_DCOMLAUNCH
O64 - Services: CurCS - C:\Program Files\Google\Update\GoogleUpdate.exe - Service Google Update (gupdate) (gupdate) .(.Google Inc. - Programme d'installation de Google.) - LEGACY_GUPDATE
O64 - Services: CurCS - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe - Google Software Updater (gusvc) .(.Google - gusvc.) - LEGACY_GUSVC
O64 - Services: CurCS - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe - Intel(R) Matrix Storage Event Monitor (IAANTMON) .(.Intel Corporation - RAID Monitor.) - LEGACY_IAANTMON
O64 - Services: CurCS - C:\Program Files\Canon\IJPLM\IJPLMSVC.exe - Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) .(.Pas de propriétaire - Inkjet Printer/Scanner/Fax Extended Servey.) - LEGACY_IJPLMSVC
O64 - Services: CurCS - C:\Program Files\ma-config.com\maconfservice.exe - Ma-Config Service (maconfservice) .(.CybelSoft - Service de détection matériel.) - LEGACY_MACONFSERVICE
O64 - Services: CurCS - C:\Program Files\System Control Manager\MSIService.exe - Micro Star SCM (Micro Star SCM) .(.Pas de propriétaire - Pas de description.) - LEGACY_MICRO_STAR_SCM
O64 - Services: CurCS - (.not file.) - Mup (Mup) .(.Pas de propriétaire - Pas de description.) - LEGACY_MUP
O64 - Services: CurCS - (.not file.) - Pilote système NDIS (NDIS) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDIS
O64 - Services: CurCS - C:\WINDOWS\system32\PSIService.exe - ProtexisLicensing (ProtexisLicensing) .(.Pas de propriétaire - nTitles PSIService.) - LEGACY_PROTEXISLICENSING
O64 - Services: CurCS - C:\Program Files\RALINK\Common\RaRegistry.exe - Ralink Registry Writer (RalinkRegistryWriter) .(.Ralink Technology, Corp. - RalinkRegistryWriter.) - LEGACY_RALINKREGISTRYWRITER
O64 - Services: CurCS - (.not file.) - RDPNP (RDPNP) .(.Pas de propriétaire - Pas de description.) - LEGACY_RDPNP
O64 - Services: CurCS - (.not file.) - BullGuard Email Monitor (Reconn) .(.Pas de propriétaire - Pas de description.) - LEGACY_RECONN
O64 - Services: CurCS - (.not file.) - Appel de procédure distante (RPC) (RpcSs) .(.Pas de propriétaire - Pas de description.) - LEGACY_RPCSS
O64 - Services: CurCS - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.sys - SASDIFSV (SASDIFSV) .(.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASDIFSV.SYS.) - LEGACY_SASDIFSV
O64 - Services: CurCS - (.not file.) - SASENUM (SASENUM) .(.Pas de propriétaire - Pas de description.) - LEGACY_SASENUM
O64 - Services: CurCS - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys - SASKUTIL (SASKUTIL) .(.SUPERAdBlocker.com and SUPERAntiSpyware.com - SASKUTIL.SYS.) - LEGACY_SASKUTIL
O64 - Services: CurCS - C:\Windows\system32\Drivers\Scutum50.sys - Scutum50 NDIS Protocol Driver (Scutum50) .(.Printing Communications Assoc., Inc. (PCAUS - PCAUSA NDIS 5.0 SPR Protocol Driver.) - LEGACY_SCUTUM50
O64 - Services: CurCS - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe - ServiceLayer (ServiceLayer) .(.Nokia - ServiceLayer Module.) - LEGACY_SERVICELAYER
O64 - Services: CurCS - C:\Windows\system32\Drivers\sptd.sys - sptd (sptd) .(.Pas de propriétaire - Pas de description.) - LEGACY_SPTD
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\ssmdrv.sys - ssmdrv (ssmdrv) .(.Avira GmbH - AVIRA SnapShot Driver.) - LEGACY_SSMDRV
O64 - Services: CurCS - (.not file.) - Services Terminal Server (TermService) .(.Pas de propriétaire - Pas de description.) - LEGACY_TERMSERVICE
O64 - Services: CurCS - C:\WINDOWS\System32\TuneUpDefragService.exe - TuneUp Drive Defrag Service (TuneUp.Defrag) .(.TuneUp Software GmbH - TuneUp Drive Defrag-Dienst.) - LEGACY_TUNEUP.DEFRAG


---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <htmlfile>[HKCR\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe
O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe


---\\ Start Menu Internet (SMI) (O68)
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe


---\\ Search Browser Infection (SBI) (O69)
[HKCU\Software\Microsoft\Internet Explorer\MenuExt\E&xporter vers Microsoft Excel]
[HKCU\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...]
O69 - SBI: SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A}- (Bing) - http://www.bing.com
O69 - SBI: SearchScopes {105E99FF-8B9A-4492-B155-06194B9056D2}- (Bing) - http://www.bing.com
O69 - SBI: SearchScopes {19F2B849-4ADE-4d4b-85F9-C31C643DBDE9}- (Fast Browser Search) - http://www.fastbrowsersearch.com
O69 - SBI: SearchScopes {67A2568C-7A0A-4EED-AECC-B5405DE63B64} [DefaultScope] - (Google) - http://www.google.com
O69 - SBI: SearchScopes {afdbddaa-5d3f-42ee-b79c-185a7020515b}- (Messenger Plus Live Customized Web Search) - http://search.conduit.com
O69 - SBI: SearchScopes {CD10120B-C165-4f8d-8C74-639629E238FF}- (MyStart Rechercher) - http://mystart.magentic.com
O69 - SBI: SearchScopes {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}- (MyStart Rechercher) - http://mystart.incredimail.com
O69 - SBI: SearchScopes {FCCBD633-EC65-4BD4-8A38-41F660945297}- (Bing) - http://www.bing.com


---\\ Search Master Boot Record Infection (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
Run by Goumon Sylvie at 01/08/2010 21:20:21
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys spds.sys hal.dll >>UNKNOWN [0x8678A938]<<
kernel: MBR read successfully
user & kernel MBR OK


---\\ Recherche des services démarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\WINDOWS\System32\audiosrv.dll [42496]
O83 - Search Svchost Services: Browser (Browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\System32\browser.dll [77824]
O83 - Search Svchost Services: CryptSvc (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) -- C:\WINDOWS\System32\cryptsvc.dll [62464]
O83 - Search Svchost Services: DMServer (DMServer) . (.Microsoft Corp. - DLL Service gestionnaire de disque logique.) -- C:\WINDOWS\System32\dmserver.dll [24576]
O83 - Search Svchost Services: DHCP (DHCP) . (.Microsoft Corporation - Service client DHCP.) -- C:\WINDOWS\System32\dhcpcsvc.dll [127488]
O83 - Search Svchost Services: ERSvc (ERSvc) . (.Microsoft Corporation - Windows Error Reporting Service.) -- C:\WINDOWS\System32\ersvc.dll [23040]
O83 - Search Svchost Services: EventSystem (EventSystem) . (.Microsoft Corporation - Pas de description.) -- C:\WINDOWS\system32\es.dll [253952]
O83 - Search Svchost Services: FastUserSwitchingCompatibility (FastUserSwitchingCompatibility) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\System32\shsvcs.dll [135680]
O83 - Search Svchost Services: LanmanServer (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\System32\srvsvc.dll [96768]
O83 - Search Svchost Services: LanmanWorkstation (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) -- C:\WINDOWS\System32\wkssvc.dll [132096]
O83 - Search Svchost Services: Messenger (Messenger) . (.Microsoft Corporation - NT Messenger Service.) -- C:\WINDOWS\System32\msgsvc.dll [33792]
O83 - Search Svchost Services: Netman (Netman) . (.Microsoft Corporation - Gestionnaire de connexions réseau.) -- C:\WINDOWS\System32\netman.dll [198144]
O83 - Search Svchost Services: Nla (Nla) . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\System32\mswsock.dll [247808]
O83 - Search Svchost Services: Ntmssvc (Ntmssvc) . (.Microsoft Corporation - Gestionnaire de stockage amovible.) -- C:\WINDOWS\system32\ntmssvc.dll [438272]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\System32\rasauto.dll [88576]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\System32\rasmans.dll [186368]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINDOWS\System32\mprdim.dll [53248]
O83 - Search Svchost Services: Schedule (Schedule) . (.Microsoft Corporation - Moteur du Planificateur de tâches.) -- C:\WINDOWS\system32\schedsvc.dll [194560]
O83 - Search Svchost Services: Seclogon (Seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\WINDOWS\System32\seclogon.dll [18944]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\system32\sens.dll [39424]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\WINDOWS\System32\ipnathlp.dll [332800]
O83 - Search Svchost Services: SRService (SRService) . (.Microsoft Corporation - Service de restauration du système.) -- C:\WINDOWS\system32\srsvc.dll [171520]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\WINDOWS\System32\tapisrv.dll [249856]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\System32\shsvcs.dll [135680]
O83 - Search Svchost Services: TrkWks (TrkWks) . (.Microsoft Corporation - Distributed Link Tracking Client.) -- C:\WINDOWS\system32\trkwks.dll [90112]
O83 - Search Svchost Services: UxTuneUp (UxTuneUp) . (.TuneUp Software GmbH - TuneUp Theme Extension.) -- C:\WINDOWS\System32\uxtuneup.dll [29440]
O83 - Search Svchost Services: W32Time (W32Time) . (.Microsoft Corporation - Service de temps Windows.) -- C:\WINDOWS\system32\w32time.dll [178176]
O83 - Search Svchost Services: WZCSVC (WZCSVC) . (.Microsoft Corporation - Service configuration automatique sans fil.) -- C:\WINDOWS\System32\wzcsvc.dll [483840]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [145408]
O83 - Search Svchost Services: wscsvc (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) -- C:\WINDOWS\system32\wscsvc.dll [80896]
O83 - Search Svchost Services: xmlprov (xmlprov) . (.Microsoft Corporation - Network Provisioning Service.) -- C:\WINDOWS\System32\xmlprov.dll [129024]
O83 - Search Svchost Services: napagent (napagent) . (.Microsoft Corporation - Exécution du service Agent de quarantaine.) -- C:\WINDOWS\System32\qagentrt.dll [293376]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\WINDOWS\System32\kmsvc.dll [61440]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\WINDOWS\system32\qmgr.dll [409088]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update AutoUpdate Service.) -- C:\WINDOWS\system32\wuauserv.dll [6656]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\System32\shsvcs.dll [135680]
O83 - Search Svchost Services: helpsvc (helpsvc) . (.Microsoft Corporation - Microsoft PCHealth Service Holder.) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [38400]
O83 - Search Svchost Services: WmdmPmSN (WmdmPmSN) . (.Microsoft Corporation - Microsoft Media Device Service Provider.) -- C:\WINDOWS\system32\MsPMSNSv.dll [27136]


---\\ Infection BT - BHO/Toolbar (Possible)
O69 - SBI: SearchScopes {19F2B849-4ADE-4d4b-85F9-C31C643DBDE9}- (Fast Browser Search) - http://www.fastbrowsersearch.com

End of the scan (945 lines in 01mn 10s)(0)

  Aller en bas de la page Revenir au message précédent Revenir en haut de la page
Haut de la page 
2 pages : [1] 2 ... Fin
Haut de la page Page Précédente Page Suivante 

 > Tous les forumsSécurité

 
Forum PC Astuces© 1997-2014 WebastucesAller en haut de la page