cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2014.1.16.17 - Nicolas Coolman (17/01/2014)
~ Lancé par alain (17/01/2014 10:32:59)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by program


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.16476
MFIE: Mozilla Firefox 26.0 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 7 Home Premium, 32-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_COA_NSLP channel
Windows ID Activation : OK
~ Windows Partial Key : VDKDX
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection du système
avast! Free Antivirus v9.0.2011
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Security Client v4.4.0304.0
Windows Defender W7

---\\ Logiciels d'optimisation du système
CCleaner v4.09 =>Piriform Ltd

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 12 Plugin
Adobe Reader XI

---\\ Informations sur le système
~ Processor: x86 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3549 MB (73% free)
System Restore: Activé (Enable)
System drive C: has 376 GB (80%) free of 466 GB

---\\ Mode de connexion au système
~ Computer Name: ALAIN-PC
~ User Name: alain
~ All Users Names: HomeGroupUser$, alain, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\alain\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\alain\AppData\Roaming\
~ %Desktop% : C:\Users\alain\Desktop\
~ %Favorites% : C:\Users\alain\Favorites\
~ %LocalAppData% : C:\Users\alain\AppData\Local\
~ %StartMenu% : C:\Users\alain\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 376 Go of 466 Go)
D: CD-ROM drive (Not Inserted)
E: Hard drive, Flash drive, Thumb drive (Free 62 Go of 298 Go)
F: Floppy drive, Flash card reader, USB Key (Free 0 Go of 4 Go)
G: Floppy drive, Flash card reader, USB Key (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 38 Scanned in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.927FA6456AD6D7630F6854828D2FD16B] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.26/11/2013 - 07:33:33.) -- C:\Windows\System32\wininet.dll [1820160]
[MD5.6D13E1406F50C66E2A95D97F22C47560] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.20/11/2010 - 13:17:54.) -- C:\Windows\System32\Winlogon.exe [286720]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.F81BB7E487EDCEAB630A7EE66CF23913] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.14/09/2013 - 01:48:58.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.5E43D2B0EE64123D4880DFA6626DEFDE] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 14:45:29.) -- C:\Windows\system32\Drivers\ntfs.sys [1211752]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.B459575348C20E8121D6039DA063C704] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 09:39:17.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
Mes images (My Pictures) : 2/2 (Modified)
~ Mes musiques (My Musics) : 1/4
Mes Videos (My Videos) : 2/2 (Modified)
~ Mes Favoris (My Favorites) : 1/33
~ Mes Documents (My Documents) : 2/4184
~ Mon Bureau (My Desktop) : 1/97
~ Menu demarrer (Programs) : 1/24
~ Hidden Files: Scanned in 00mn 02s



---\\ Processus lancés
[MD5.01D92A226791867F2DED688F25271905] - (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files\EPSON Software\Event Manager\EEventManager.exe [1058400] [PID.1912]
[MD5.AFEBF9E0B223FF04709F747C172D3540] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024] [PID.2024]
[MD5.564CB6EACE4064BB4C7815435D035D6A] - (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files\Garmin\Express Tray\ExpressTray.exe [1093976] [PID.368]
[MD5.9770F360F1C520E02AA35E5D241BE65C] - (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\w32x86\3\E_FATIINE.exe [246368] [PID.408]
[MD5.8E71207844F9CB3ED9D6D44881A30998] - (.Edimax Technology Co., Ltd. - RaUI MFC Application.) -- C:\Program Files\Edimax\Common\RaUI.exe [1572864] [PID.920]
[MD5.137BB82253BC95BDA9DC42F2A20B6830] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8335360] [PID.5160]
~ Processes Running: Scanned in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\alain\AppData\Roaming\Mozilla\Firefox\Profiles\1sno9imx.default\prefs.js
C:\Users\alain\AppData\Roaming\Mozilla\Firefox\Profiles\1sno9imx.default\user.js
M3 - MFPP: Plugins - [alain] -- C:\Users\alain\AppData\Roaming\Mozilla\Firefox\Profiles\1sno9imx.default\searchplugins\dalesearch.xml =>Hijacker.Dalesearch
M3 - MFPP: Plugins - [alain] -- C:\Users\alain\AppData\Roaming\Mozilla\Firefox\Profiles\1sno9imx.default\searchplugins\Mysearchdial.xml =>Adware.MyWebSearch
M0 - MFSP: prefs.js [alain - 1sno9imx.default] http://www.google.fr
M2 - MFEP: prefs.js [alain - 1sno9imx.default\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}] [] MySearchDial NewTab v (..) =>Adware.MyWebSearch
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll
P2 - FPN: [HKLM] [@microsoft.com/GENUINE] - (.Microsoft Corporation - Windows Activation Technologies Plugin for Mozilla.) -- C:\Windows\system32\Wat\npWatWeb.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.20913.0.) -- c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.06.) -- C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
~ Firefox Browser: 8 Scanned in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://recherche.neuf.fr
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://recherche.neuf.fr
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = http://start.mysearchdial.com =>Adware.MyWebSearch
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.06.) (No version) -- (.not file.)
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ IE Browser: 14 Scanned in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.offerbox.com =>PUP.OfferBox
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:56847 =>Hijacker.Proxy
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} . (.Orbiscom Ltd. All rights reserved. - FTO CMB.) -- C:\Windows\system32\BhoECart.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} . (.SEIKO EPSON CORPORATION - Epson Easy Photo Print (TBL).) -- C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
~ BHO: 6 Scanned in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Easy Photo Print - [HKLM]{9421DD08-935F-4701-A9CA-22DF90AC4EA6} . (.SEIKO EPSON CORPORATION - Epson Easy Photo Print (TBL).) -- C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: avast! Online Security - [HKLM]{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
~ Toolbar: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Program [Public]: Adobe Reader XI.lnk . (...) -- C:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-AB0000000001}\SC_Reader.ico
O4 - GS\Program [Public]: Media Center.lnk . (.Microsoft Corporation - Windows Media Center.) -- C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation
O4 - GS\Program [Public]: Microsoft Excel.lnk . (...) -- C:\Windows\Installer\{0003040C-78E1-11D2-B60F-006097C998E7}\xlicons.exe
O4 - GS\Program [Public]: Microsoft Outlook.lnk . (...) -- C:\Windows\Installer\{0003040C-78E1-11D2-B60F-006097C998E7}\outicon.exe
O4 - GS\Program [Public]: Microsoft Security Essentials.lnk . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- C:\Program Files\Microsoft Security Client\msseces.exe
O4 - GS\Program [Public]: Microsoft Word.lnk . (...) -- C:\Windows\Installer\{0003040C-78E1-11D2-B60F-006097C998E7}\wordicon.exe
O4 - GS\Program [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O4 - GS\Program [Public]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) -- C:\Program Files\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation
O4 - GS\Program [Public]: Sidebar.lnk . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - GS\Program [Public]: Windows Anytime Upgrade.lnk . (.Microsoft Corporation - Interface utilisateur de Mise à niveau expr.) -- C:\Windows\system32\WindowsAnytimeUpgradeUI.exe
O4 - GS\Program [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - Création de DVD Windows.) -- C:\Program Files\DVD Maker\DVDMaker.exe =>.Microsoft Corporation
O4 - GS\Program [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) -- C:\Windows\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Program [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O4 - GS\Program [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visionneuse XPS.) -- C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Calculatrice de Windows.) -- C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Afficher le commutateur.) -- C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Accessoire du panneau de saisie mathématiqu.) -- C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Centre de mobilité Windows.) -- C:\Windows\system32\mblctr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) -- C:\Windows\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) -- C:\Windows\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture.) -- C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Magnétophone Windows.) -- C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Pense-bête.) -- C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) -- C:\Windows\System32\mobsync.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Mise en route.) -- C:\Windows\system32\OobeFldr.dll =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) -- C:\Program Files\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) -- C:\Windows\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Défragmenteur de disque Microsoft®.) -- C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Gestionnaire de nettoyage de disque pour Wi.) -- C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Moniteur de ressources et de performances.) -- C:\Windows\system32\perfmon.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - Informations système.) -- C:\Windows\system32\msinfo32.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Restauration du système de Microsoft® Windo.) -- C:\Windows\system32\rstrui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) -- C:\Windows\system32\taskschd.msc
O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Application post-migration de transfert de.) -- C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Application Transfert de fichiers et paramè.) -- C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation
O4 - GS\QuickLaunch [alain]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch [alain]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) -- C:\Program Files\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation
O4 - GS\TaskBar [alain]: EPSON Scan.lnk . (.SEIKO EPSON CORP. - EPSON Scan.) -- C:\Windows\twain_32\escndv\escndv.exe
O4 - GS\TaskBar [alain]: Microsoft Excel.lnk . (...) -- C:\Windows\Installer\{0003040C-78E1-11D2-B60F-006097C998E7}\xlicons.exe
O4 - GS\TaskBar [alain]: Microsoft Word.lnk . (...) -- C:\Windows\Installer\{0003040C-78E1-11D2-B60F-006097C998E7}\wordicon.exe
O4 - GS\TaskBar [alain]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O4 - GS\TaskBar [alain]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) -- C:\Program Files\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation
O4 - GS\TaskBar [alain]: Virtualis.lnk . (.Orbiscom Ltd. All rights reserved. - FTO CMB.) -- C:\Program Files\Virtualis\virtualis.exe
O4 - GS\TaskBar [alain]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\TaskBar [alain]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O4 - GS\Program [alain]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\Accessories [alain]: Command Prompt.lnk . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\system32\cmd.exe =>.Microsoft Corporation
O4 - GS\Accessories [alain]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) -- C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [alain]: Run.lnk - Clé orpheline
O4 - GS\Accessories [alain]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\SystemTools [alain]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\SystemTools [alain]: Private Character Editor.lnk . (.Microsoft Corporation - Éditeur de caractères privés.) -- C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation
O4 - GS\Desktop [alain]: Iomega_HDD (E) - Raccourci.lnk . (...) -- E:\
O4 - GS\Desktop [alain]: Mes documents.lnk . (...) -- C:\Users\alain\Documents
O4 - GS\Desktop [alain]: Windows Update.lnk . (.Microsoft Corporation - Windows Update Application Launcher.) -- C:\Windows\system32\wuapp.exe
~ Global Startup: 58 Scanned in 00mn 00s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - GS\Startup [Public]: Adobe Gamma Loader.exe.lnk . (.Adobe Systems, Inc. - Adobe Gamma Loader.) -- C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - GS\Startup [Public]: Microsoft Office.lnk . (.Microsoft Corporation - Microsoft Office 2000 component.) -- C:\Program Files\Microsoft Office\Office\OSA9.exe
O4 - GS\Startup [Public]: Wireless Utility.lnk . (.Edimax Technology Co., Ltd. - RaUI MFC Application.) -- C:\Program Files\Edimax\Common\RaUI.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKLM\..\Run: [EEventManager] . (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files\Epson Software\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O4 - HKLM\..\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe (.not file.)
O4 - HKCU\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files\Garmin\Express Tray\ExpressTray.exe
O4 - HKCU\..\Run: [EPLTarget\P0000000000000001] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIINE.exe =>.Epson Seiko Corporation
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIINE.exe =>.Epson Seiko Corporation
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] . (.Microsoft Corporation - SP Reviewer.) -- C:\Windows\System32\SPReview\SPReview.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-1362066309-1000944786-474304479-1000\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files\Garmin\Express Tray\ExpressTray.exe
O4 - HKUS\S-1-5-21-1362066309-1000944786-474304479-1000\..\Run: [EPLTarget\P0000000000000001] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIINE.exe =>.Epson Seiko Corporation
O4 - HKUS\S-1-5-21-1362066309-1000944786-474304479-1000\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIINE.exe =>.Epson Seiko Corporation
~ Application: Scanned in 00mn 00s



---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
~ Winsock: 6 Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{A1C9F915-1F55-4AB4-80EC-55588388C666}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC8724E4-699D-457B-8088-00CA15366A11}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{A1C9F915-1F55-4AB4-80EC-55588388C666}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{BC8724E4-699D-457B-8088-00CA15366A11}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{A1C9F915-1F55-4AB4-80EC-55588388C666}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{BC8724E4-699D-457B-8088-00CA15366A11}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY - ABBYY network license server.) - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: avast! Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Epson Scanner Service (EpsonScanSvc) . (.Seiko Epson Corporation - Epson Scanner Service (32bit).) - C:\Windows\system32\EscSvc.exe
O23 - Service: EPSON V5 Service4(04) (EPSON_EB_RPCV4_04) . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.exe =>.Epson Seiko Corporation
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.exe =>.Epson Seiko Corporation
O23 - Service: Garmin Core Update Service (Garmin Core Update Service) . (.Garmin Ltd or its subsidiaries - Garmin Core Update Service.) - C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) . (.Ralink Technology, Corp. - RalinkRegistryWriter.) - C:\Program Files\Edimax\Common\RaRegistry.exe
~ Services: 8 Scanned in 00mn 03s



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s



---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
[MD5.8D268693A6DCE3D7319DF14834841BAF] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [257928]
[MD5.24DC2A6F110B79787D6C5D5FF52A0235] [APT] [avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [765176]
[MD5.E7CDBC01674477840A64965E784374DE] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [4370712] =>Piriform Ltd
[MD5.00000000000000000000000000000000] [APT] [Run RoboForm TaskBar Icon] (...) -- C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (.not file.) [0]
[MD5.C155A13687144076286989EF078112C2] [APT] [{9DAADEF3-0896-49E4-A2BE-78B7B3719E13}] (.Nicolas Coolman.) -- C:\Program Files\ZHPDiag\ZHPFix\ZHPhep.exe [1917440]
~ Scheduled Task: 8 Scanned in 00mn 01s



---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Internet Explorer - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\system32\cmd.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
O40 - ASIC: Macromedia Shockwave Flash - {D27CDB6E-AE6D-11CF-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 11.9 r900.) -- C:\Windows\system32\Macromed\Flash\Flash32_11_9_900_170.ocx
~ Active Setup: 11 Scanned in 00mn 00s



---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (aswRdr) . (.AVAST Software - avast! WFP Redirect Driver.) - C:\Windows\system32\drivers\aswRdr2.sys
O41 - Driver: (aswSnx) . (.AVAST Software - avast! Virtualization Driver.) - C:\Windows\system32\drivers\aswSnx.sys
O41 - Driver: (aswSP) . (.AVAST Software - avast! self protection module.) - C:\Windows\system32\drivers\aswSP.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\Windows\System32\DRIVERS\serial.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
~ Drivers: 72 Scanned in 00mn 00s



---\\ Logiciels installés (O42)
O42 - Logiciel: ABBYY FineReader 9.0 Sprint - (.ABBYY.) [HKLM] -- ABBYY FineReader 9.0 Sprint
O42 - Logiciel: ABBYY FineReader 9.0 Sprint - (.ABBYY.) [HKLM] -- {F9000000-0018-0000-0000-074957833700}
O42 - Logiciel: Adobe Flash Player 11 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 12 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
O42 - Logiciel: Adobe Photoshop 5.5 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Photoshop 5.5
O42 - Logiciel: Adobe Reader XI (11.0.06) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AB0000000001}
O42 - Logiciel: Aff Packages - (...) [HKCU] -- Aff Packages
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner =>Piriform Ltd
O42 - Logiciel: Cisco EAP-FAST Module - (.Cisco Systems, Inc..) [HKLM] -- {415B2719-AD3A-4944-B404-C472DB6085B3}
O42 - Logiciel: Cisco LEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {83770D14-21B9-44B3-8689-F7B523F94560}
O42 - Logiciel: Cisco PEAP Module - (.Cisco Systems, Inc..) [HKLM] -- {669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}
O42 - Logiciel: DaleSearch Chrome Toolbar - (.DaleSearch.) [HKLM] -- DaleSearch Chrome Toolbar =>Hijacker.Dalesearch
O42 - Logiciel: Download Navigator - (.SEIKO EPSON CORPORATION.) [HKLM] -- {E728441A-7820-4B1C-87C9-DE7BE37B2953}
O42 - Logiciel: EPSON Scan - (.Seiko Epson Corporation.) [HKLM] -- EPSON Scanner
O42 - Logiciel: EPSON XP-102 103 Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM] -- EPSON XP-102 103 Series
O42 - Logiciel: Edimax Wireless LAN Card - (.Edimax.) [HKLM] -- {28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}
O42 - Logiciel: Elevated Installer - (.Garmin Ltd or its subsidiaries.) [HKLM] -- {3615560A-3601-4727-B44D-853BEF395F5C}
O42 - Logiciel: Epson Easy Photo Print 2 - (.SEIKO EPSON CORPORATION.) [HKLM] -- {30E01116-5666-4807-8EF1-D80E9FF16717}
O42 - Logiciel: Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) - (.SEIKO EPSON CORPORATION2.) [HKLM] -- {B2D55EB8-32C5-4B43-9006-9E97DECBA178}
O42 - Logiciel: Epson Event Manager - (.Seiko Epson Corporation.) [HKLM] -- {BECE9CCD-83F6-4BAA-9B26-227DF7D2E932}
O42 - Logiciel: File Opener Pro - (.FileOpenerPro.) [HKLM] -- fileopenerpro
O42 - Logiciel: Garmin Express - (.Garmin Ltd or its subsidiaries.) [HKLM] -- {7D3A7C2E-DC30-4726-AF81-9DFCCF88DC1E} =>.Garmin Corporation
O42 - Logiciel: Garmin Express - (.Garmin Ltd or its subsidiaries.) [HKLM] -- {9471d6bd-67a9-40f6-a420-2ae4f08ef003} =>.Garmin Corporation
O42 - Logiciel: Garmin Express Tray - (.Garmin Ltd or its subsidiaries.) [HKLM] -- {712C9875-89BA-44E4-966A-106DF3141740} =>.Garmin Corporation
O42 - Logiciel: Guide d'utilisation EPSON XP-102 103 Series - (...) [HKLM] -- EPSON XP-102 103 Series Useg
O42 - Logiciel: Malwarebytes Anti-Malware version 1.75.0.1300 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM] -- {0CD47142-BA4F-46B0-AA92-2675864928B8}
O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM] -- Microsoft Security Client
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Mozilla Firefox 26.0 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 26.0 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: Mozilla Thunderbird 24.2.0 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Thunderbird 24.2.0 (x86 fr) =>.Mozilla Corporation
O42 - Logiciel: Neuf - Kit de connexion - (.Neuf.) [HKLM] -- Neuf_Kit
O42 - Logiciel: Suppress plus 1.8 - (.Perrysoft.) [HKLM] -- Suppress plus_is1
O42 - Logiciel: Virtualis Crédit Mutuel - (...) [HKLM] -- Virtualis Crédit Mutuel
O42 - Logiciel: Vittalia Installer - (.www.TELECHARGERSTOP.com.) [HKLM] -- Vittalia =>PUP.Vittalia
O42 - Logiciel: avast! Free Antivirus v9.0.2011 - (.Avast Software.) [HKLM] -- avast
O42 - Logiciel: dalesearch toolbar - (.dalesearch.) [HKLM] -- dalesearch =>Hijacker.Dalesearch
~ Logic: 35 Scanned in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\ABBYY]
[HKCU\Software\AVAST Software]
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow\Software\LyricsMonkey-1] =>Adware.AddLyrics
[HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}]
[HKCU\Software\AppDataLow]
[HKCU\Software\Appscion]
[HKCU\Software\Classes]
[HKCU\Software\ClickConnect]
[HKCU\Software\Clients]
[HKCU\Software\Epson]
[HKCU\Software\Garmin]
[HKCU\Software\Google]
[HKCU\Software\InstalledThirdPartyPrograms]
[HKCU\Software\Macromedia]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Netscape]
[HKCU\Software\Neuf]
[HKCU\Software\Novell]
[HKCU\Software\ODBC]
[HKCU\Software\Perrysoft]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\SEIKO EPSON CORPORATION]
[HKCU\Software\SSPrint]
[HKCU\Software\Siber Systems]
[HKCU\Software\Software]
[HKCU\Software\Thunderbird] =>.Mozilla Corporation
[HKCU\Software\Trolltech]
[HKCU\Software\ZebHelpProcess Helper]
[HKCU\Software\kde.org]
[HKLM\Software\ABBYY]
[HKLM\Software\ASUS]
[HKLM\Software\ATI Technologies]
[HKLM\Software\AVAST Software]
[HKLM\Software\Adobe]
[HKLM\Software\AdwCleaner]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\EPSON]
[HKLM\Software\Edimax]
[HKLM\Software\Garmin]
[HKLM\Software\Google]
[HKLM\Software\InstalledThirdPartyPrograms]
[HKLM\Software\Intel]
[HKLM\Software\Kodak]
[HKLM\Software\Licenses]
[HKLM\Software\Macromedia]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Neuf]
[HKLM\Software\ODBC]
[HKLM\Software\Perrysoft]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\SEIKO EPSON CORPORATION2]
[HKLM\Software\Siber Systems]
[HKLM\Software\Software]
[HKLM\Software\Sonic]
[HKLM\Software\Sony Corporation]
[HKLM\Software\Wow6432Node]
[HKLM\Software\mozilla.org]
~ Key Software: 141 Scanned in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 08/10/2013 - 22:00:50 - [172,897] ----D C:\Program Files\ABBYY FineReader 9.0 Sprint
O43 - CFD: 03/10/2013 - 07:50:53 - [207,040] ----D C:\Program Files\Adobe
O43 - CFD: 25/09/2013 - 17:28:28 - [328,584] ----D C:\Program Files\AVAST Software
O43 - CFD: 14/01/2014 - 09:11:45 - [6,489] ----D C:\Program Files\CCleaner =>Piriform Ltd
O43 - CFD: 01/01/2002 - 01:52:55 - [2,957] ----D C:\Program Files\Cisco
O43 - CFD: 02/10/2013 - 07:04:50 - [149,702] ----D C:\Program Files\Common Files
O43 - CFD: 31/12/2001 - 23:21:06 - [79,371] ----D C:\Program Files\DVD Maker
O43 - CFD: 01/01/2002 - 01:52:37 - [14,977] ----D C:\Program Files\Edimax
O43 - CFD: 01/01/2002 - 00:43:09 - [8,471] ----D C:\Program Files\epson
O43 - CFD: 13/01/2014 - 10:41:56 - [108,400] ----D C:\Program Files\EPSON Software
O43 - CFD: 23/09/2013 - 03:40:21 - [0] -SH-D C:\Program Files\Fichiers communs
O43 - CFD: 25/09/2013 - 17:40:22 - [0,918] ----D C:\Program Files\FileOpenerPro
O43 - CFD: 08/10/2013 - 03:14:52 - [17,198] ----D C:\Program Files\Garmin
O43 - CFD: 23/12/2013 - 06:22:29 - [0] ----D C:\Program Files\Google
O43 - CFD: 01/01/2002 - 00:46:03 - [11,058] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 15/01/2014 - 09:50:11 - [21,573] ----D C:\Program Files\Internet Explorer
O43 - CFD: 13/01/2014 - 10:45:05 - [13,264] ----D C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 14/07/2009 - 10:00:58 - [140,966] ----D C:\Program Files\Microsoft Games
O43 - CFD: 01/01/2002 - 00:44:53 - [64,592] ----D C:\Program Files\Microsoft Office
O43 - CFD: 13/01/2014 - 12:05:43 - [22,337] ----D C:\Program Files\Microsoft Security Client
O43 - CFD: 10/10/2013 - 09:04:01 - [40,851] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 01/01/2002 - 00:02:07 - [0,015] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 14/01/2014 - 09:12:41 - [1,224] ----D C:\Program Files\Mobogenie
O43 - CFD: 14/01/2014 - 09:21:38 - [51,043] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 16/01/2014 - 07:36:46 - [0,216] ----D C:\Program Files\Mozilla Maintenance Service
O43 - CFD: 16/01/2014 - 07:14:06 - [49,024] ----D C:\Program Files\Mozilla Thunderbird =>.Mozilla Corporation
O43 - CFD: 14/07/2009 - 05:52:30 - [0,025] ----D C:\Program Files\MSBuild
O43 - CFD: 25/09/2013 - 06:31:40 - [15,606] ----D C:\Program Files\Neuf
O43 - CFD: 14/07/2009 - 05:52:30 - [37,357] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 01/01/2002 - 00:40:26 - [19,698] ----D C:\Program Files\Siber Systems
O43 - CFD: 25/09/2013 - 17:42:12 - [4,152] ----D C:\Program Files\splus
O43 - CFD: 13/01/2014 - 09:46:20 - [2,795] ----D C:\Program Files\SUPERAntiSpyware
O43 - CFD: 14/07/2009 - 05:53:23 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 18/10/2013 - 09:42:37 - [0,306] ----D C:\Program Files\Virtualis
O43 - CFD: 30/09/2013 - 08:32:13 - [0,179] ----D C:\Program Files\Vittalia =>PUP.Vittalia
O43 - CFD: 02/10/2013 - 05:22:15 - [2,909] ----D C:\Program Files\Windows Defender
O43 - CFD: 02/10/2013 - 05:22:21 - [6,688] ----D C:\Program Files\Windows Journal
O43 - CFD: 31/12/2001 - 23:21:06 - [5,895] ----D C:\Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 14/01/2014 - 08:26:41 - [6,298] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 23/09/2013 - 03:40:21 - [11,632] ----D C:\Program Files\Windows NT
O43 - CFD: 31/12/2001 - 23:21:05 - [4,213] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 31/12/2001 - 23:21:06 - [0,181] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 31/12/2001 - 23:21:06 - [6,575] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 17/01/2014 - 10:32:50 - [17,257] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 01/01/2002 - 00:48:59 - [7,728] ----D C:\Program Files\Common Files\ABBYY
O43 - CFD: 03/10/2013 - 07:50:53 - [14,363] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 01/01/2002 - 00:46:15 - [0,082] ----D C:\Program Files\Common Files\Designer
O43 - CFD: 01/01/2002 - 01:24:00 - [0,296] ----D C:\Program Files\Common Files\EPSON
O43 - CFD: 13/01/2014 - 10:45:05 - [68,278] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 14/07/2009 - 03:37:05 - [0,003] ----D C:\Program Files\Common Files\Services
O43 - CFD: 14/07/2009 - 03:37:05 - [39,200] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 31/12/2001 - 23:21:05 - [19,752] ----D C:\Program Files\Common Files\System
O43 - CFD: 01/01/2002 - 00:48:59 - [1,530] ----D C:\ProgramData\ABBYY
O43 - CFD: 02/10/2013 - 07:13:00 - [147,431] ----D C:\ProgramData\Adobe
O43 - CFD: 14/07/2009 - 05:53:55 - [0] -SH-D C:\ProgramData\Application Data
O43 - CFD: 22/10/2013 - 00:43:54 - [26,562] ----D C:\ProgramData\AVAST Software
O43 - CFD: 23/09/2013 - 03:40:21 - [0] -SH-D C:\ProgramData\Bureau
O43 - CFD: 14/07/2009 - 05:53:55 - [0] -SH-D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 05:53:55 - [0] -SH-D C:\ProgramData\Documents
O43 - CFD: 01/01/2002 - 01:52:58 - [2,340] ----D C:\ProgramData\Edimax Driver
O43 - CFD: 13/01/2014 - 10:42:17 - [6,353] ----D C:\ProgramData\EPSON
O43 - CFD: 23/09/2013 - 03:40:21 - [0] -SH-D C:\ProgramData\Favoris
O43 - CFD: 14/07/2009 - 05:53:55 - [0] -SH-D C:\ProgramData\Favorites
O43 - CFD: 08/10/2013 - 03:14:28 - [701,726] ----D C:\ProgramData\Garmin
O43 - CFD: 01/01/2002 - 01:30:23 - [6,577] ----D C:\ProgramData\Malwarebytes
O43 - CFD: 23/09/2013 - 03:40:21 - [0] -SH-D C:\ProgramData\Menu Démarrer
O43 - CFD: 01/01/2002 - 01:47:06 - [615,268] -S--D C:\ProgramData\Microsoft
O43 - CFD: 23/09/2013 - 03:40:21 - [0] -SH-D C:\ProgramData\Modèles
O43 - CFD: 31/12/2001 - 23:30:56 - [0,035] ----D C:\ProgramData\Mozilla
O43 - CFD: 25/09/2013 - 18:14:38 - [0,002] ----D C:\ProgramData\Office Genuine Advantage
O43 - CFD: 08/10/2013 - 03:13:52 - [13,775] ----D C:\ProgramData\Package Cache
O43 - CFD: 01/01/2002 - 02:00:51 - [0,001] ----D C:\ProgramData\Ralink
O43 - CFD: 01/01/2002 - 00:41:01 - [0] ----D C:\ProgramData\RoboForm
O43 - CFD: 14/07/2009 - 05:53:55 - [0] -SH-D C:\ProgramData\Start Menu
O43 - CFD: 18/12/2013 - 05:34:55 - [134,303] ----D C:\ProgramData\SUPERAntiSpyware.com
O43 - CFD: 14/01/2014 - 09:09:28 - [0] ----D C:\ProgramData\TEMP
O43 - CFD: 14/07/2009 - 05:53:55 - [0] -SH-D C:\ProgramData\Templates
O43 - CFD: 01/01/2002 - 00:46:45 - [0,004] ----D C:\ProgramData\UDL
O43 - CFD: 14/01/2014 - 09:05:03 - [1,063] ----D C:\Users\alain\AppData\Roaming\1H1Q
O43 - CFD: 02/10/2013 - 07:12:21 - [2,838] ----D C:\Users\alain\AppData\Roaming\Adobe
O43 - CFD: 23/10/2013 - 06:20:23 - [0,004] ----D C:\Users\alain\AppData\Roaming\AVAST Software
O43 - CFD: 13/01/2014 - 10:42:40 - [0,006] ----D C:\Users\alain\AppData\Roaming\Epson
O43 - CFD: 01/01/2002 - 03:36:31 - [0] ----D C:\Users\alain\AppData\Roaming\FreeSoftwareUpdater =>PUP.Eorezo
O43 - CFD: 08/10/2013 - 03:20:20 - [0] ----D C:\Users\alain\AppData\Roaming\Garmin
O43 - CFD: 23/09/2013 - 03:40:37 - [0] ----D C:\Users\alain\AppData\Roaming\Identities
O43 - CFD: 01/01/2002 - 01:52:17 - [0] ----D C:\Users\alain\AppData\Roaming\InstallShield
O43 - CFD: 25/09/2013 - 16:42:55 - [0,011] ----D C:\Users\alain\AppData\Roaming\Macromedia
O43 - CFD: 01/01/2002 - 01:31:12 - [92,805] ----D C:\Users\alain\AppData\Roaming\Malwarebytes
O43 - CFD: 14/07/2009 - 10:00:22 - [0] ----D C:\Users\alain\AppData\Roaming\Media Center Programs
O43 - CFD: 16/01/2014 - 07:48:45 - [2,938] -S--D C:\Users\alain\AppData\Roaming\Microsoft
O43 - CFD: 01/01/2002 - 00:44:53 - [0] ----D C:\Users\alain\AppData\Roaming\Microsoft Web Folders
O43 - CFD: 25/09/2013 - 16:28:26 - [19,247] ----D C:\Users\alain\AppData\Roaming\Mozilla
O43 - CFD: 18/12/2013 - 05:35:05 - [0,585] ----D C:\Users\alain\AppData\Roaming\SUPERAntiSpyware.com
O43 - CFD: 25/09/2013 - 16:47:26 - [167,659] ----D C:\Users\alain\AppData\Roaming\Thunderbird =>.Mozilla Corporation
O43 - CFD: 17/01/2014 - 10:33:13 - [0,245] ----D C:\Users\alain\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 01/01/2002 - 00:50:25 - [0] ----D C:\Users\alain\AppData\Local\ABBYY
O43 - CFD: 17/01/2014 - 08:34:47 - [17,637] ----D C:\Users\alain\AppData\Local\Adobe
O43 - CFD: 23/09/2013 - 03:40:27 - [0] -SH-D C:\Users\alain\AppData\Local\Application Data
O43 - CFD: 25/09/2013 - 17:40:02 - [0,077] ----D C:\Users\alain\AppData\Local\avgchrome
O43 - CFD: 14/01/2014 - 08:56:19 - [2,409] ----D C:\Users\alain\AppData\Local\cache
O43 - CFD: 02/12/2013 - 09:30:04 - [0] ----D C:\Users\alain\AppData\Local\Diagnostics
O43 - CFD: 16/01/2014 - 08:08:41 - [0,951] ----D C:\Users\alain\AppData\Local\ElevatedDiagnostics
O43 - CFD: 08/10/2013 - 03:15:02 - [0,002] ----D C:\Users\alain\AppData\Local\Garmin
O43 - CFD: 14/01/2014 - 09:05:01 - [1,224] ----D C:\Users\alain\AppData\Local\genienext
O43 - CFD: 14/01/2014 - 08:55:33 - [0] ----D C:\Users\alain\AppData\Local\Google
O43 - CFD: 23/09/2013 - 03:40:27 - [0] -SH-D C:\Users\alain\AppData\Local\Historique
O43 - CFD: 25/09/2013 - 16:46:14 - [0] ----D C:\Users\alain\AppData\Local\Macromedia
O43 - CFD: 13/01/2014 - 10:42:21 - [265,651] ----D C:\Users\alain\AppData\Local\Microsoft
O43 - CFD: 30/09/2013 - 08:38:21 - [0,524] ----D C:\Users\alain\AppData\Local\Microsoft Games
O43 - CFD: 14/01/2014 - 09:12:41 - [0,003] ----D C:\Users\alain\AppData\Local\Mobogenie
O43 - CFD: 25/09/2013 - 16:33:39 - [41,319] ----D C:\Users\alain\AppData\Local\Mozilla
O43 - CFD: 31/12/2001 - 23:58:52 - [0] ----D C:\Users\alain\AppData\Local\Programs
O43 - CFD: 31/12/2001 - 23:27:18 - [0] ----D C:\Users\alain\AppData\Local\Software
O43 - CFD: 17/01/2014 - 10:32:15 - [421,120] ----D C:\Users\alain\AppData\Local\Temp
O43 - CFD: 23/09/2013 - 03:40:27 - [0] -SH-D C:\Users\alain\AppData\Local\Temporary Internet Files
O43 - CFD: 14/01/2014 - 09:26:08 - [14,958] ----D C:\Users\alain\AppData\Local\Thunderbird =>.Mozilla Corporation
O43 - CFD: 18/10/2013 - 12:44:42 - [0,758] ----D C:\Users\alain\AppData\Local\VirtualStore
O43 - CFD: 14/07/2009 - 05:42:04 - [0,014] R---D C:\Users\alain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 02/10/2013 - 05:29:21 - [0] R---D C:\Users\alain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 13/01/2014 - 10:45:09 - [0,001] ----D C:\Users\alain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EPSON Software
O43 - CFD: 14/07/2009 - 05:37:42 - [0,001] R---D C:\Users\alain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 02/10/2013 - 05:29:21 - [0] R---D C:\Users\alain\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
~ Program Folder: 122 Scanned in 00mn 01s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.CC09E0C9A2D89C6E71D093DC8BD121B7] - 13/01/2014 - 11:12:57 ---A- . (.Microsoft Corporation - Crypto API32.) -- C:\Windows\System32\crypt32.dll [1168384]
O44 - LFC:[MD5.5A775CAE7CCCAC581C05B8D2C92C0DF1] - 13/01/2014 - 11:12:59 ---A- . (.Microsoft Corporation - GDI Client DLL.) -- C:\Windows\System32\gdi32.dll [305152]
O44 - LFC:[MD5.F0D0E883EBBDC7615DC9EDEA0FFB2817] - 13/01/2014 - 11:13:00 ---A- . (.Microsoft Corporation - API en mode utilisateur FWP/IPsec.) -- C:\Windows\System32\FWPUCLNT.DLL [216576]
O44 - LFC:[MD5.CE2A48CD0D2B39FB77FA4797C6434E71] - 13/01/2014 - 11:13:00 ---A- . (.Microsoft Corporation - Application d’assistance Netsh de la platef.) -- C:\Windows\System32\nshwfp.dll [656896]
O44 - LFC:[MD5.B9C54120F46392100478F58F374E5709] - 13/01/2014 - 11:13:01 ---A- . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [679424]
O44 - LFC:[MD5.9842041E2F5ACE1E2F5FB4EF02053DC8] - 13/01/2014 - 11:13:02 ---A- . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\Drivers\drmk.sys [81408]
O44 - LFC:[MD5.EB6137D696A9B4E9718AC6F8641CB4C9] - 13/01/2014 - 11:13:02 ---A- . (.Microsoft Corporation - Port Class (Class Driver for Port/Miniport.) -- C:\Windows\System32\Drivers\portcls.sys [177152]
O44 - LFC:[MD5.E9504E484076585F6DA3C59F0E20E122] - 13/01/2014 - 11:13:16 ---A- . (.Microsoft Corporation - Codec pour photographie Windows Media Photo.) -- C:\Windows\System32\WMPhoto.dll [417792]
O44 - LFC:[MD5.A3A35EE79C64A640152B3113E6E254E2] - 13/01/2014 - 11:13:16 ---A- . (.Microsoft Corporation - Microsoft ® Console Based Script Host.) -- C:\Windows\System32\cscript.exe [126976]
O44 - LFC:[MD5.A3B1D1312602280839A4A2AFBDFD066E] - 13/01/2014 - 11:13:16 ---A- . (.Microsoft Corporation - Microsoft ® Script Runtime.) -- C:\Windows\System32\scrrun.dll [163840]
O44 - LFC:[MD5.979D74799EA6C8B8167869A68DF5204A] - 13/01/2014 - 11:13:17 ---A- . (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe [141824]
O44 - LFC:[MD5.09F65975C1C9793B923BB52A7FA83453] - 13/01/2014 - 11:13:17 ---A- . (.Microsoft Corporation - Windows Script Host Runtime Library.) -- C:\Windows\System32\wshom.ocx [121856]
O44 - LFC:[MD5.E7B9D5FF20FFDD4AAE2EF1D1B8C27A37] - 13/01/2014 - 11:13:18 ---A- . (.Microsoft Corporation - Windows NT Image Helper.) -- C:\Windows\System32\imagehlp.dll [159232]
O44 - LFC:[MD5.D89077E2E1C88A29C57F21FAD28DAC45] - 13/01/2014 - 11:13:24 ---A- . (.Microsoft Corporation - LSA SSPI RPC interface DLL.) -- C:\Windows\System32\sspisrv.dll [15872]
O44 - LFC:[MD5.372948BB5E41CE42341C4398DE572E56] - 13/01/2014 - 11:13:24 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\secur32.dll [22016]
O44 - LFC:[MD5.AD7FB087A238883D1618F29F7BBBD584] - 13/01/2014 - 11:13:25 ---A- . (.Microsoft Corporation - Bibliothèque de chiffrement Windows.) -- C:\Windows\System32\ncrypt.dll [220160]
O44 - LFC:[MD5.EF6950D7B24AAF4E477065F5455DD4F8] - 13/01/2014 - 11:13:25 ---A- . (.Microsoft Corporation - DLL serveur LSA.) -- C:\Windows\System32\lsasrv.dll [1038848]
O44 - LFC:[MD5.85449EEBE8F8EBD6481EFBF0F352B4EB] - 13/01/2014 - 11:13:25 ---A- . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\Windows\System32\Drivers\cng.sys [369848]
O44 - LFC:[MD5.F286830298323272260332D6ABC905C1] - 13/01/2014 - 11:13:25 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecdd.sys [67520]
O44 - LFC:[MD5.D7C760D57B1656DD748B9E4AB6CB5A51] - 13/01/2014 - 11:13:25 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecpkg.sys [136640]
O44 - LFC:[MD5.803B370865D907EA21DC0C2B6A8936B5] - 13/01/2014 - 11:13:25 ---A- . (.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\System32\lsass.exe [22016]
O44 - LFC:[MD5.BD6B9BC84D004C6BEE89CF7BDB95E1FC] - 13/01/2014 - 11:13:25 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\sspicli.dll [99840]
O44 - LFC:[MD5.AA6F6457116B559B76BC6A012CB4C293] - 13/01/2014 - 11:13:25 ---A- . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll [247808]
O44 - LFC:[MD5.AFA53BD631FB0509A91A99391209BB70] - 13/01/2014 - 11:13:29 ---A- . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Inter.) -- C:\Windows\System32\msieftp.dll [301568]
O44 - LFC:[MD5.4BCC63ED1C3D15B2635A8AE2B854B3EB] - 13/01/2014 - 11:13:39 ---A- . (.Microsoft Corporation - Fournisseur d’informations d’identification.) -- C:\Windows\System32\SmartcardCredentialProvider.dll [152576]
O44 - LFC:[MD5.E9BB0CD09DA17C71FD1B9954D75AEEF7] - 13/01/2014 - 11:13:39 ---A- . (.Microsoft Corporation - Interface utilisateur du gestionnaire d’inf.) -- C:\Windows\System32\credui.dll [168960]
O44 - LFC:[MD5.EE7CB55F77465CDAC4C80F587FF7C278] - 13/01/2014 - 11:13:39 ---A- . (.Microsoft Corporation - Interface utilisateur d’authentification Wi.) -- C:\Windows\System32\authui.dll [1796096]
O44 - LFC:[MD5.F7B6E341F4B1947BEC0E14EEBE3C627E] - 13/01/2014 - 11:59:27 ---A- . (.Microsoft Corporation - ADVPACK.) -- C:\Windows\System32\IEAdvpack.dll [111616]
O44 - LFC:[MD5.AE6A2C5ECD3E96556E22F12816842F60] - 13/01/2014 - 11:59:27 ---A- . (.Microsoft Corporation - DLL de ressource du composant d'édition HTM.) -- C:\Windows\System32\mshtmler.dll [48640]
O44 - LFC:[MD5.83F49FD1BC0A999B006D564C540C7258] - 13/01/2014 - 11:59:27 ---A- . (.Microsoft Corporation - IE Sysprep Provider.) -- C:\Windows\System32\iesysprep.dll [86016]
O44 - LFC:[MD5.887055A3C8DD6C87D200D11EAFDBD45B] - 13/01/2014 - 11:59:27 ---A- . (.Microsoft Corporation - Sets the date that IE was installed.) -- C:\Windows\System32\SetIEInstalledDate.exe [74240]
O44 - LFC:[MD5.6A92CEC8532056791C6832B2725D170D] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Auto-extracteur de fichier CAB Win32.) -- C:\Windows\System32\wextract.exe [139264]
O44 - LFC:[MD5.03B3541AE6986602CF9CB5B3AD169C33] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Contrôleur de site Web.) -- C:\Windows\System32\webcheck.dll [208384]
O44 - LFC:[MD5.5EC13202430A3EB68DFF44CF1FEEA2BE] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - DAC for Trident DOM.) -- C:\Windows\System32\MshtmlDac.dll [61952]
O44 - LFC:[MD5.AB3B2CA52AFB695AFCDD2620A21E5B21] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - DLL du Gestionnaire de licences Microsoft®.) -- C:\Windows\System32\licmgr10.dll [24576]
O44 - LFC:[MD5.ABDFC692D9FE43E2BA8FE6CB5A8CB95A] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Hôte des applications HTML de Microsoft(R).) -- C:\Windows\System32\mshta.exe [13312]
O44 - LFC:[MD5.4BCC7EB5F20840DA67943BD86AE95735] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - IE PNG plugin image decoder.) -- C:\Windows\System32\pngfilt.dll [56832]
O44 - LFC:[MD5.6EB0B7301E00F717BD68A742D1391FAF] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - IE plugin image decoder support DLL.) -- C:\Windows\System32\imgutil.dll [36352]
O44 - LFC:[MD5.779E142FE2159935E78C0FA2E190FF1E] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Microsoft (R) JScript.) -- C:\Windows\System32\jscript.dll [610304]
O44 - LFC:[MD5.71144A47CD02FDDC77DDF5EB5315767F] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Microsoft Feeds Manager.) -- C:\Windows\System32\msfeeds.dll [523776]
O44 - LFC:[MD5.53FC62C51CB18C9100A7DFAF2D2A6C47] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Microsoft Feeds Synchronization.) -- C:\Windows\System32\msfeedssync.exe [12800]
O44 - LFC:[MD5.6A794439B6612E43FEDE0217C919B652] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Microsoft ® VBScript.) -- C:\Windows\System32\vbscript.dll [454656]
O44 - LFC:[MD5.64831CAD496A073398853A34A5813675] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Microsoft® HTML Editing Component.) -- C:\Windows\System32\mshtmled.dll [69632]
O44 - LFC:[MD5.EC7038154490E50ACD405A022F51B204] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Moteur d'installation.) -- C:\Windows\System32\inseng.dll [83456]
O44 - LFC:[MD5.1200D9C7DB0ADC1B8143A0A9921BF7DA] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Object Control Viewer.) -- C:\Windows\System32\occache.dll [127488]
O44 - LFC:[MD5.1AFBAA54BDF637F69B8E02A5578286B0] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Objets homologues Internet Explorer.) -- C:\Windows\System32\iepeers.dll [116736]
O44 - LFC:[MD5.6922D7ED84AE102504174922D5D42F49] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Personnalisation d’IEAK.) -- C:\Windows\System32\iedkcs32.dll [238288]
O44 - LFC:[MD5.55969AADF0210A614700F89B48976F68] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Synchronisation en arrière-plan des flux Mi.) -- C:\Windows\System32\msfeedsbs.dll [43008]
O44 - LFC:[MD5.9A33FDDD687A836A1FD478B43C5A95FD] - 13/01/2014 - 11:59:28 ---A- . (.Microsoft Corporation - Wizard.) -- C:\Windows\System32\iexpress.exe [151552]
O44 - LFC:[MD5.F862CD08F1AD4EE39BD506853F3C6103] - 13/01/2014 - 11:59:29 ---A- . (...) -- C:\Windows\System32\ieuinit.inf [16284]
O44 - LFC:[MD5.D9F12F54E3B5A092F1D5F191F5286E53] - 13/01/2014 - 11:59:29 ---A- . (.Microsoft Corporation - Convertisseur Microsoft HTML.) -- C:\Windows\System32\html.iec [337408]
O44 - LFC:[MD5.44D5C650C971910827EA65B4D989ED94] - 13/01/2014 - 11:59:29 ---A- . (.Microsoft Corporation - DLL de gestion d'utilisateur local et de co.) -- C:\Windows\System32\msrating.dll [164864]
O44 - LFC:[MD5.CFCE4EFF1D6D909EE2EA3AFCB8F1E677] - 13/01/2014 - 11:59:29 ---A- . (.Microsoft Corporation - Internet Shortcut Shell Extension DLL.) -- C:\Windows\System32\url.dll [233472]
O44 - LFC:[MD5.FB0D1CC2911A0645DDA6C0608473EB55] - 13/01/2014 - 11:59:29 ---A- . (.Microsoft Corporation - JavaScript Performance Collection Agent.) -- C:\Windows\System32\JavaScriptCollectionAgent.dll [34816]
O44 - LFC:[MD5.2AF48780D879AFC43733159CB29CD8BD] - 13/01/2014 - 11:59:29 ---A- . (.Microsoft Corporation - Microsoft (R) HTML Media DLL.) -- C:\Windows\System32\mshtmlmedia.dll [1051136]
O44 - LFC:[MD5.4F032F1FDEFEA5EC8EEA3562643B5EE8] - 13/01/2014 - 11:59:29 ---A- . (.Microsoft Corporation - Microsoft Information Card IE Helper.) -- C:\Windows\System32\icardie.dll [69120]
O44 - LFC:[MD5.298FDE634538B62CEEEC266D8773B21A] - 13/01/2014 - 11:59:29 ---A- . (.Microsoft Corporation - Microsoft Line Services library file.) -- C:\Windows\System32\msls31.dll [182272]
O44 - LFC:[MD5.C17139EAF939964142C7A1AEEE02DC81] - 13/01/2014 - 11:59:29 ---A- . (.Microsoft Corporation - Microsoft SmartScreen Filter Data File.) -- C:\Windows\System32\ieapfltr.dat [616104]
O44 - LFC:[MD5.C1A6E565B2782C09BC40AD749B46D9ED] - 13/01/2014 - 11:59:29 ---A- . (.Microsoft Corporation - Registers custom PKEYs for IE.) -- C:\Windows\System32\RegisterIEPKEYs.exe [71680]
O44 - LFC:[MD5.9E170B0AF156B478BD2B1FD6A2250C9E] - 13/01/2014 - 11:59:29 ---A- . (.Microsoft Corporation - TDC ActiveX Control.) -- C:\Windows\System32\tdc.ocx [62464]
O44 - LFC:[MD5.9B8701A380CEE1B05D651B4ED4048C8F] - 13/01/2014 - 11:59:29 ---A- . (.Microsoft Corporation - Windows Globalization.) -- C:\Windows\System32\jsIntl.dll [645120]
O44 - LFC:[MD5.AD27563BC16AB1EAACAE3033E99C2F78] - 13/01/2014 - 11:59:30 ---A- . (.Microsoft Corporation - ELS Hyphenation Service.) -- C:\Windows\System32\elshyph.dll [194048]
O44 - LFC:[MD5.C611C6ED5ECFE4608BA79472DFE3D49C] - 13/01/2014 - 11:59:30 ---A- . (.Microsoft Corporation - Microsoft Spell Checking Facility.) -- C:\Windows\System32\MsSpellCheckingFacility.exe [646144]
O44 - LFC:[MD5.5B9B016EAD19B0FFA487995CCE065ADA] - 13/01/2014 - 12:01:54 ---A- . (...) -- C:\Windows\IE11_main.log [9900]
O44 - LFC:[MD5.02DF0628BE8B64B84D50FBE53549AA3B] - 13/01/2014 - 12:02:40 ---A- . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.DLL [12625408]
O44 - LFC:[MD5.6C4B2E1A25841077084EB9F76FF6FFA7] - 13/01/2014 - 12:02:41 ---A- . (.Microsoft Corporation - Windows Media Player.) -- C:\Windows\System32\wmp.dll [11410432]
O44 - LFC:[MD5.E185BDA84E5F03F4E1D8DCA30E209277] - 13/01/2014 - 12:06:00 ---A- . (...) -- C:\Windows\epplauncher.mif [1912]
O44 - LFC:[MD5.A60A222D3126DD9E380F9D8B651BC13D] - 14/01/2014 - 10:20:25 ---A- . (.Microsoft Corporation - Microsoft (R) JScript.) -- C:\Windows\System32\jscript9.dll [4243968]
O44 - LFC:[MD5.BFAFE990C4A191E83843362B5AC64A9B] - 14/01/2014 - 10:20:25 ---A- . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [17112576]
O44 - LFC:[MD5.4B638CE3DAA3A082E576C0DDF9D635D4] - 14/01/2014 - 10:20:26 ---A- . (.Microsoft Corporation - Navigateur Internet.) -- C:\Windows\System32\ieframe.dll [11221504]
O44 - LFC:[MD5.84EAF0A08C7742697816E148C066D757] - 14/01/2014 - 10:20:27 ---A- . (.Microsoft Corporation - Panneau de configuration Internet.) -- C:\Windows\System32\inetcpl.cpl [1928192]
O44 - LFC:[MD5.927FA6456AD6D7630F6854828D2FD16B] - 14/01/2014 - 10:20:28 ---A- . (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [1820160]
O44 - LFC:[MD5.0763C5D8660436D4D961F72609E33BBE] - 14/01/2014 - 10:20:28 ---A- . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [1157632]
O44 - LFC:[MD5.B2E1F7B212502BB49AAD4EFAD37C5CF5] - 14/01/2014 - 10:20:28 ---A- . (.Microsoft Corporation - Run time utility for Internet Explorer.) -- C:\Windows\System32\iertutil.dll [2166784]
O44 - LFC:[MD5.C8AF3CF3030C3962B978FA3871D759FF] - 14/01/2014 - 10:20:29 ---A- . (.Microsoft Corporation - IE ETW Collector Service.) -- C:\Windows\System32\ieetwcollector.exe [108032]
O44 - LFC:[MD5.7C7FF72C48AF9DD8CA7ABA2EA97A6670] - 14/01/2014 - 10:20:30 ---A- . (.Microsoft Corporation - IE ETW Collector Proxy Stub Resources.) -- C:\Windows\System32\ieetwproxystub.dll [51200]
O44 - LFC:[MD5.35DE59C975A0C97E8DBBE095BCC3644E] - 14/01/2014 - 10:20:30 ---A- . (.Microsoft Corporation - Microsoft ® JScript Diagnostics.) -- C:\Windows\System32\jscript9diag.dll [553472]
O44 - LFC:[MD5.3DE9521C90F7CC4413CBF6569A8B85B5] - 14/01/2014 - 10:20:30 ---A- . (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) -- C:\Windows\System32\ieUnatt.exe [112128]
O44 - LFC:[MD5.BE8480727660354B93E32B0ED709BF0E] - 14/01/2014 - 10:20:31 ---A- . (.Microsoft Corporation - IE ETW Collector Service Resources.) -- C:\Windows\System32\ieetwcollectorres.dll [4096]
O44 - LFC:[MD5.491B4F34BA2CD7EFCAC934C7EFF48F52] - 14/01/2014 - 10:20:31 ---A- . (.Microsoft Corporation - IOD Version Map.) -- C:\Windows\System32\iesetup.dll [61952]
O44 - LFC:[MD5.355BF103E2CF862B00EEB3731E25E802] - 14/01/2014 - 10:20:31 ---A- . (.Microsoft Corporation - Moteur de l’interface utilisateur d’Interne.) -- C:\Windows\System32\ieui.dll [440832]
O44 - LFC:[MD5.36D150C4F80DF88ED97D14598C24692F] - 14/01/2014 - 10:20:31 ---A- . (.Microsoft Corporation - Traitement de RunOnce complet avec interfac.) -- C:\Windows\System32\iernonce.dll [32768]
O44 - LFC:[MD5.3D43EAC957F2F797BE82CF6B04A933F8] - 14/01/2014 - 10:20:32 ---A- . (.Microsoft Corporation - JScript Proxy Auto-Configuration.) -- C:\Windows\System32\jsproxy.dll [43008]
O44 - LFC:[MD5.A6B0B7F006F1CB84B48981499F6B7210] - 14/01/2014 - 10:20:33 ---A- . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe [208896]
O44 - LFC:[MD5.C74500A1BCB4113A7310295DD3FA4440] - 14/01/2014 - 10:20:34 ---A- . (.Microsoft Corporation - Microsoft® MSHTML Typelib.) -- C:\Windows\System32\mshtml.tlb [2724864]
O44 - LFC:[MD5.EDF2DF71C4F1E13A6AC75F5224DE655A] - 15/01/2014 - 09:57:00 ---A- . (.Microsoft Corporation - Default Hub Driver for USB.) -- C:\Windows\System32\Drivers\usbhub.sys [258560]
O44 - LFC:[MD5.D40855F89B69305140BBD7E9A3BA2DA6] - 15/01/2014 - 09:57:00 ---A- . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) -- C:\Windows\System32\Drivers\usbehci.sys [43520]
O44 - LFC:[MD5.9828C8D14CC2676421778F0DE638CF97] - 15/01/2014 - 09:57:00 ---A- . (.Microsoft Corporation - OHCI USB Miniport Driver.) -- C:\Windows\System32\Drivers\usbohci.sys [20480]
O44 - LFC:[MD5.EC2C5AF37B76D7B58C642CB74423DB7A] - 15/01/2014 - 09:57:00 ---A- . (.Microsoft Corporation - Pilote de port USB 1.1 & 2.0.) -- C:\Windows\System32\Drivers\usbport.sys [284672]
O44 - LFC:[MD5.800AABFD625EEFF899F7E5496BDE37AB] - 15/01/2014 - 09:57:00 ---A- . (.Microsoft Corporation - UHCI USB Miniport Driver.) -- C:\Windows\System32\Drivers\usbuhci.sys [24064]
O44 - LFC:[MD5.0803FBA9FE829D61AE26EC0BCC910C46] - 15/01/2014 - 09:57:00 ---A- . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\Windows\System32\Drivers\usbccgp.sys [76288]
O44 - LFC:[MD5.74F805AB12EB0E3E49E469F19FF02640] - 15/01/2014 - 09:57:00 ---A- . (.Microsoft Corporation - Universal Serial Bus Driver.) -- C:\Windows\System32\Drivers\usbd.sys [6016]
O44 - LFC:[MD5.5DBD4F73E2A52FEED61DBAB3752E329C] - 15/01/2014 - 09:57:01 ---A- . (.Microsoft Corporation - Network I/O Subsystem.) -- C:\Windows\System32\Drivers\netio.sys [240576]
O44 - LFC:[MD5.1E882889A4314D6DF5DED4F6EC994E72] - 15/01/2014 - 09:57:01 ---A- . (.Microsoft Corporation - Pilote Win32 multi-utilisateurs.) -- C:\Windows\System32\win32k.sys [2349056]
O44 - LFC:[MD5.4D5FD79A075B9BD9ACEFD6FAA753318A] - 15/01/2014 - 11:12:21 ---A- . (.AVAST Software - avast! Screen Saver stub.) -- C:\Windows\avastSS.scr [43152]
O44 - LFC:[MD5.A46118A8987612525FC548AE33222DE4] - 15/01/2014 - 11:12:21 ---A- . (.AVAST Software - avast! start-up scanner.) -- C:\Windows\System32\aswBoot.exe [270240]
O44 - LFC:[MD5.6F1505608202BBD179095A6A150D103F] - 15/01/2014 - 11:12:22 ---A- . (.AVAST Software - avast! File System Minifilter for Windows 2.) -- C:\Windows\System32\Drivers\aswMonFlt.sys [67824]
O44 - LFC:[MD5.1B0662514A68C3A42E60D240C5ABEF28] - 15/01/2014 - 11:12:23 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [180248]
O44 - LFC:[MD5.0F639D0526820BA7872C963813E0EB8D] - 15/01/2014 - 11:12:23 ---A- . (.AVAST Software - avast! Virtualization Driver.) -- C:\Windows\System32\Drivers\aswSnx.sys [775952]
O44 - LFC:[MD5.7BA7543EA7936A7ADA615F6DE7C95494] - 15/01/2014 - 11:12:23 ---A- . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\Drivers\aswsp.sys [410528]
O44 - LFC:[MD5.37A6A39C1792BA961EE6172A0F3CA236] - 15/01/2014 - 11:12:49 ---A- . (.AVAST Software - Stream Filter.) -- C:\Windows\System32\Drivers\aswstm.sys [64168]
O44 - LFC:[MD5.D5AD6FE415664BFD94384A30AAC5488B] - 15/01/2014 - 12:16:34 ---A- . (.Microsoft Corporation - Outil de suppression de logiciels malveilla.) -- C:\Windows\System32\MRT.exe [83425928]
O44 - LFC:[MD5.001C0A8B4E6880DEAB6D24DB8323CD65] - 16/01/2014 - 07:08:47 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [283808]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 16/01/2014 - 08:30:16 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [0]
O44 - LFC:[MD5.6B643FBB7179A5E5EA6E3D9B75834902] - 16/01/2014 - 09:42:17 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1549700]
O44 - LFC:[MD5.B3A850E7BED9D9E7BA49A78C1F6C9508] - 16/01/2014 - 09:42:17 ---A- . (...) -- C:\Windows\System32\perfc009.dat [106190]
O44 - LFC:[MD5.AE75482688C46F3135CB2D2BAA3742A3] - 16/01/2014 - 09:42:17 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [130548]
O44 - LFC:[MD5.23A8FC3D95C988B36FFC22D23B8795E6] - 16/01/2014 - 09:42:17 ---A- . (...) -- C:\Windows\System32\perfh009.dat [615810]
O44 - LFC:[MD5.11C4B32D793C8C26AB3A563BCE203F91] - 16/01/2014 - 09:42:17 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [704242]
O44 - LFC:[MD5.97D5475C85D236D20A01CD8775BF031F] - 16/01/2014 - 14:11:31 ---A- . (...) -- C:\Windows\PFRO.log [164134]
O44 - LFC:[MD5.4A31086A5FA5A3FCA54CE7A540D46D6C] - 17/01/2014 - 08:35:30 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerApp.exe [692616]
O44 - LFC:[MD5.4C48B264BF1CDAB5914D819DF9124C92] - 17/01/2014 - 08:35:30 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [71048]
O44 - LFC:[MD5.68302A1F61A0F1EE614BEC793D576977] - 17/01/2014 - 09:01:44 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.74C9137883A93343AD75CC8FC92E86BF] - 17/01/2014 - 09:01:49 ---A- . (...) -- C:\Windows\setupact.log [29068]
O44 - LFC:[MD5.F8EBB39D5BF6139299830B17501ADA59] - 17/01/2014 - 09:53:37 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1369545]
~ Files: 117 Scanned in 00mn 22s



---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.5EFAEBB49D66EFAB4E52C1F70994EEFD] - 01/01/2014 - 08:32:58 ---A- - C:\Windows\Prefetch\Layout.ini
O45 - LFCP:[MD5.0F29BA4D9391197490F32FE99B629C83] - 01/01/2014 - 08:33:09 ---A- - C:\Windows\Prefetch\DEFRAG.EXE-588F90AD.pf
O45 - LFCP:[MD5.F83AFB58DC2F3D48D479E5AF996F1B31] - 01/01/2014 - 08:33:09 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-7AC6742A.pf
O45 - LFCP:[MD5.E7D73952B8E5F92F0955B4D716566222] - 11/01/2014 - 07:26:41 ---A- - C:\Windows\Prefetch\NTOSBOOT-B00DFAAD.pf
O45 - LFCP:[MD5.5EB2EA0A4503F46D0D10F5578BB99DC5] - 14/01/2014 - 08:26:53 ---A- - C:\Windows\Prefetch\POQEXEC.EXE-69592829.pf
O45 - LFCP:[MD5.AB05325A5FC237EC2AF11435F5F409D7] - 14/01/2014 - 08:29:36 ---A- - C:\Windows\Prefetch\ATBROKER.EXE-2E15A492.pf
O45 - LFCP:[MD5.63CF0F37AE191E97B084A907C14ED185] - 14/01/2014 - 08:29:41 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-46A5F75F.pf
O45 - LFCP:[MD5.5C045970FDFE4A57B83DC32158B6CA44] - 14/01/2014 - 08:29:44 ---A- - C:\Windows\Prefetch\UNREGMP2.EXE-2294B148.pf
O45 - LFCP:[MD5.AE3748464FCA06A186CA128A6A1584E6] - 14/01/2014 - 08:29:46 ---A- - C:\Windows\Prefetch\DWM.EXE-6FFD3DA8.pf
O45 - LFCP:[MD5.067B0811D8C09B5AED9EA2005A38E625] - 14/01/2014 - 08:29:46 ---A- - C:\Windows\Prefetch\USERINIT.EXE-2257A3E7.pf
O45 - LFCP:[MD5.967A317E972A509F48D1D7B84F42DB36] - 14/01/2014 - 08:29:50 ---A- - C:\Windows\Prefetch\IE4UINIT.EXE-3A7E0C67.pf
O45 - LFCP:[MD5.2D2F8B1173325AC033122A95B5FF9081] - 14/01/2014 - 08:30:50 ---A- - C:\Windows\Prefetch\AgCx_SC4.db
O45 - LFCP:[MD5.FD0DDB41D568777D62045B008B91174E] - 14/01/2014 - 08:59:58 ---A- - C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf
O45 - LFCP:[MD5.B96B2293687F6F69A050532013B9265B] - 14/01/2014 - 09:05:03 ---A- - C:\Windows\Prefetch\TASKKILL.EXE-8F5B2253.pf
O45 - LFCP:[MD5.E24861B005AE152F3820F79256EDF2F1] - 14/01/2014 - 09:35:25 ---A- - C:\Windows\Prefetch\RUNONCE.EXE-D0649312.pf
O45 - LFCP:[MD5.013C768E4942970399DED27B25C5E75C] - 15/01/2014 - 09:54:11 ---A- - C:\Windows\Prefetch\SC.EXE-945D79AE.pf
O45 - LFCP:[MD5.DF8B3ED125E85EC687B2AB82288E148E] - 15/01/2014 - 10:04:10 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-A3E35360.pf
O45 - LFCP:[MD5.AE6DBDFDEEC34D771968F6858D213C48] - 15/01/2014 - 11:10:33 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-B2EB1806.pf
O45 - LFCP:[MD5.0777DFE664A039E0D990E4FF81E789A1] - 15/01/2014 - 12:16:01 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-7CFEDEA3.pf
O45 - LFCP:[MD5.33F17B865DA56CFCDB2D59DEEAEE70AF] - 15/01/2014 - 12:16:01 ---A- - C:\Windows\Prefetch\VSSVC.EXE-B8AFC319.pf
O45 - LFCP:[MD5.FC11981E02B01F39DD7489994C9B18B6] - 16/01/2014 - 07:10:21 ---A- - C:\Windows\Prefetch\WLANEXT.EXE-D2CEDC57.pf
O45 - LFCP:[MD5.87B57D171C2A70E5E776AC9D824D4A5B] - 16/01/2014 - 07:12:49 ---A- - C:\Windows\Prefetch\WMPNETWK.EXE-D9F2A96F.pf
O45 - LFCP:[MD5.1B46B28E5E597E9D0E080A5F3E88EE7D] - 16/01/2014 - 07:40:33 ---A- - C:\Windows\Prefetch\MAKECAB.EXE-0F1704A4.pf
O45 - LFCP:[MD5.2C66E1BA0B350AE8F5100FD2800D950F] - 16/01/2014 - 07:59:11 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-C871F054.pf
O45 - LFCP:[MD5.A0ABE11ED3FA1DA742F1A5829E896666] - 16/01/2014 - 07:59:28 ---A- - C:\Windows\Prefetch\HELPPANE.EXE-FEDC965B.pf
O45 - LFCP:[MD5.AFA8282F33A7474ACA2272A9CE3EDE6D] - 16/01/2014 - 08:15:42 ---A- - C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
O45 - LFCP:[MD5.B49E787EF281976463FA82C29128778F] - 16/01/2014 - 09:24:45 ---A- - C:\Windows\Prefetch\CONTROL.EXE-817F8F1D.pf
O45 - LFCP:[MD5.6BB983CEFCFE8540A8A0CD5CE4369409] - 16/01/2014 - 09:31:12 ---A- - C:\Windows\Prefetch\CSC.EXE-A3B8D95D.pf
O45 - LFCP:[MD5.9B695CD085120A1245671D5104F06F90] - 16/01/2014 - 09:31:12 ---A- - C:\Windows\Prefetch\CVTRES.EXE-069169FB.pf
O45 - LFCP:[MD5.EC847722D641ECD53A224E3D5D71627D] - 16/01/2014 - 09:31:12 ---A- - C:\Windows\Prefetch\DEVICEDISPLAYOBJECTPROVIDER.E-17410B90.pf
O45 - LFCP:[MD5.0123922CD73EDBA4EF15F977A50902E6] - 16/01/2014 - 09:31:23 ---A- - C:\Windows\Prefetch\SDIAGNHOST.EXE-8D72177C.pf
O45 - LFCP:[MD5.E1B60108E00807F9625B80F6019A3BE6] - 16/01/2014 - 09:39:12 ---A- - C:\Windows\Prefetch\DRVINST.EXE-4CB4314A.pf
O45 - LFCP:[MD5.51C0F33EFA0D00C70A775ADE95FC6194] - 16/01/2014 - 11:44:22 ---A- - C:\Windows\Prefetch\MSIEXEC.EXE-A2D55CB6.pf
O45 - LFCP:[MD5.EE0332ADA4EB8F72B7DB6B8F9923C236] - 16/01/2014 - 11:45:27 ---A- - C:\Windows\Prefetch\SEARCHINDEXER.EXE-4A6353B9.pf
O45 - LFCP:[MD5.867A3B43B2F5801318DE2AD670B14A06] - 16/01/2014 - 11:47:46 ---A- - C:\Windows\Prefetch\REGSVR32.EXE-8461DBEE.pf
O45 - LFCP:[MD5.99B899766D7284A2C29769A718BDC88F] - 16/01/2014 - 11:48:27 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-DE9673F9.pf
O45 - LFCP:[MD5.E3E2169A726BC98EC4358D20398115DC] - 16/01/2014 - 11:54:05 ---A- - C:\Windows\Prefetch\WUAUCLT.EXE-70318591.pf
O45 - LFCP:[MD5.95AEF2DDBB5C29232052944C24CBCF1C] - 16/01/2014 - 14:03:05 ---A- - C:\Windows\Prefetch\AgCx_SC1.db.trx
O45 - LFCP:[MD5.AD864EA7A2552EC6094403169B6D06A8] - 16/01/2014 - 14:04:05 ---A- - C:\Windows\Prefetch\AgCx_SC1.db
O45 - LFCP:[MD5.C389E8C2F28BF25EE3F05252BE418596] - 16/01/2014 - 14:09:39 ---A- - C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-1362066309-1000944786-474304479-1000.db
O45 - LFCP:[MD5.0618E3949D3443BC0417E2ECF4719B7A] - 16/01/2014 - 14:09:39 ---A- - C:\Windows\Prefetch\AgGlUAD_S-1-5-21-1362066309-1000944786-474304479-1000.db
O45 - LFCP:[MD5.1152FFF8C5D2E751E5580B8D0A55120A] - 16/01/2014 - 14:09:49 ---A- - C:\Windows\Prefetch\AUDIODG.EXE-BDFD3029.pf
O45 - LFCP:[MD5.2AD2904443D43059015093831A9B83E3] - 16/01/2014 - 14:10:41 ---A- - C:\Windows\Prefetch\LOGONUI.EXE-09140401.pf
O45 - LFCP:[MD5.8EAAA4121C17AD2BEE99782925EAD148] - 17/01/2014 - 08:15:44 ---A- - C:\Windows\Prefetch\OSA9.EXE-A6161934.pf
O45 - LFCP:[MD5.12F0B72E6CF49666261A4116EB139CFA] - 17/01/2014 - 08:15:44 ---A- - C:\Windows\Prefetch\RAUI.EXE-F5F6EB4C.pf
O45 - LFCP:[MD5.FE85DDE5331F6E313A8A096AABBD105B] - 17/01/2014 - 08:15:54 ---A- - C:\Windows\Prefetch\AVBUGREPORT.EXE-3B5B9E84.pf
O45 - LFCP:[MD5.2C92E8E4C91CFD3652071137FD0D70B4] - 17/01/2014 - 08:16:03 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-40DD444D.pf
O45 - LFCP:[MD5.B63E8973E9F112DDAF7406867382CDC6] - 17/01/2014 - 08:18:19 ---A- - C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-3CC531E5.pf
O45 - LFCP:[MD5.E3134E50B57B62F4480879E72B177882] - 17/01/2014 - 08:19:48 ---A- - C:\Windows\Prefetch\SDCLT.EXE-E10B972A.pf
O45 - LFCP:[MD5.2D22E811CD0D765D01FFB7467A28AA07] - 17/01/2014 - 08:36:09 ---A- - C:\Windows\Prefetch\PfSvPerfStats.bin
O45 - LFCP:[MD5.9C90C94067525DC6C718C3E02AD90FD8] - 17/01/2014 - 09:03:29 ---A- - C:\Windows\Prefetch\AVASTEMUPDATE.EXE-6EF4B603.pf
O45 - LFCP:[MD5.848C7889B370B5E9A5F288DA41CDF397] - 17/01/2014 - 09:03:29 ---A- - C:\Windows\Prefetch\RAREGISTRY.EXE-BB682DAB.pf
O45 - LFCP:[MD5.DB2973988BFF0254EAB1210004077F74] - 17/01/2014 - 09:03:36 ---A- - C:\Windows\Prefetch\WMPNSCFG.EXE-FC0D39BF.pf
O45 - LFCP:[MD5.AB970FBD95A8E41288E0D2F0AEBDCA02] - 17/01/2014 - 09:06:47 ---A- - C:\Windows\Prefetch\WMIADAP.EXE-F8DFDFA2.pf
O45 - LFCP:[MD5.947AD1C83938F43CC10C010D13A92C76] - 17/01/2014 - 09:09:36 ---A- - C:\Windows\Prefetch\AGENTSVR.EXE-1ADDF55B.pf
O45 - LFCP:[MD5.C7B35624FDA74F41AD3962D6DBB63E84] - 17/01/2014 - 09:15:09 ---A- - C:\Windows\Prefetch\WERMGR.EXE-0F2AC88C.pf
O45 - LFCP:[MD5.FBFDB6D28971BE32AF3E70D931811FF9] - 17/01/2014 - 10:13:34 ---A- - C:\Windows\Prefetch\AgGlFaultHistory.db
O45 - LFCP:[MD5.7138C3350AFE8DC98B6A4B04CF133CC8] - 17/01/2014 - 10:13:34 ---A- - C:\Windows\Prefetch\AgGlFgAppHistory.db
O45 - LFCP:[MD5.A27A89F6BF796FD887FCB03EB6A0DF12] - 17/01/2014 - 10:13:34 ---A- - C:\Windows\Prefetch\AgGlGlobalHistory.db
O45 - LFCP:[MD5.A0AA09734071CC7D433F7A716E01158D] - 17/01/2014 - 10:13:34 ---A- - C:\Windows\Prefetch\AgRobust.db
O45 - LFCP:[MD5.D2BF72C48497068C97F84F1640E8F7E6] - 17/01/2014 - 10:31:01 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-7238F31D.pf
O45 - LFCP:[MD5.A969D42F1CD434742B7D1773BF3AD92C] - 17/01/2014 - 10:31:08 ---A- - C:\Windows\Prefetch\PLUGIN-CONTAINER.EXE-7226D1F8.pf
O45 - LFCP:[MD5.23935F29FDF11ADAF205CE29F423ECC0] - 17/01/2014 - 10:31:16 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-5E46FA0D.pf
O45 - LFCP:[MD5.29C9BA554B132420B011AB3061A16C82] - 17/01/2014 - 10:31:17 ---A- - C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-77482212.pf
O45 - LFCP:[MD5.E7556221F2EF668211501CD99A5CFD98] - 17/01/2014 - 10:31:17 ---A- - C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf
O45 - LFCP:[MD5.543AEF7C0F12071AC60B8993BD998072] - 17/01/2014 - 10:32:00 ---A- - C:\Windows\Prefetch\CONHOST.EXE-1F3E9D7E.pf
O45 - LFCP:[MD5.10BFDEB9F12CEC33F22F7EF03136257E] - 17/01/2014 - 10:32:00 ---A- - C:\Windows\Prefetch\FLASHPLAYERUPDATESERVICE.EXE-ECAD9571.pf
O45 - LFCP:[MD5.6DA2F1ADEDF13715FB49E50DE9989CA3] - 17/01/2014 - 10:32:47 ---A- - C:\Windows\Prefetch\CONSENT.EXE-531BD9EA.pf
O45 - LFCP:[MD5.499DA3CF560DC6AF9BA80FA8BC1F8718] - 17/01/2014 - 10:32:52 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-766398D2.pf
O45 - LFCP:[MD5.5D951BBB22A3C86769831EC1153A3920] - 17/01/2014 - 10:32:57 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-A8DE6D5B.pf
O45 - LFCP:[MD5.BDEB04E09C241850D9063FC924FB70CC] - 17/01/2014 - 10:33:04 ---A- - C:\Windows\Prefetch\CMD.EXE-4A81B364.pf
O45 - LFCP:[MD5.B6E848416698947B7884D008BB1D8AAD] - 17/01/2014 - 10:33:10 ---A- - C:\Windows\Prefetch\SPPSVC.EXE-B0F8131B.pf
O45 - LFCP:[MD5.027B0A8279BE7F6690F66CE85C0AD550] - 17/01/2014 - 10:33:10 ---A- - C:\Windows\Prefetch\WMIPRVSE.EXE-1628051C.pf
O45 - LFCP:[MD5.F0E48E554BA9D6AC029241C6422F7BF8] - 17/01/2014 - 10:33:13 ---A- - C:\Windows\Prefetch\SCHTASKS.EXE-5CA45734.pf
O45 - LFCP:[MD5.A29F7443BCC944A93C86DFDB1DEA2EBC] - 17/01/2014 - 10:33:29 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-80F4A784.pf
O45 - LFCP:[MD5.BCD242F6FA765C2830B7FF7EDA3FF633] - 17/01/2014 - 10:33:34 ---A- - C:\Windows\Prefetch\FIREFOX.EXE-A606B53C.pf
O45 - LFCP:[MD5.57AB8C5BB4BEA1827D66E566264D3E30] - 18/12/2013 - 04:09:56 ---A- - C:\Windows\Prefetch\AVASTUI.EXE-56B29A08.pf
O45 - LFCP:[MD5.255A1F7E230A96F83CC8B5D515303C0A] - 27/12/2013 - 03:50:42 ---A- - C:\Windows\Prefetch\SLUI.EXE-724E99D9.pf
~ Prefetcher: 78 Scanned in 00mn 02s



---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
~ LSA: 8 Scanned in 00mn 00s



---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
~ CSB: 13 Scanned in 00mn 00s



---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
~ TDSD: 3 Scanned in 00mn 00s



---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ MSCP: 2 Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Scanned in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.21E785EBD7DC90A06391141AAC7892FB] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976]
O58 - SDL:[MD5.0C676BC278D5B59FF5ABD57BBE9123F2] - 14/07/2009 - 02:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [297552]
O58 - SDL:[MD5.7C7B5EE4B7B822EC85321FE23A27DB33] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\Drivers\adpu320.sys [146512]
O58 - SDL:[MD5.0D40BCF52EA90FC7DF2AEAB6503DEA44] - 14/07/2009 - 02:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [14400]
O58 - SDL:[MD5.D320BF87125326F996D4904FE24300FC] - 11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256]
O58 - SDL:[MD5.EA43AF0C423FF267355F74E7A53BDABA] - 14/07/2009 - 02:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\System32\Drivers\amdsbs.sys [159312]
O58 - SDL:[MD5.46387FB17B086D16DEA267D5BE23A2F2] - 11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400]
O58 - SDL:[MD5.2932004F49677BD84DBC72EDB754FFB3] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [76368]
O58 - SDL:[MD5.5D6F36C46FD283AE1B57BD2E9FEB0BC7] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [86608]
O58 - SDL:[MD5.D48659BB24C48345D926ECB45C1EBDF5] - 13/08/2004 - 09:56:20 ---A- . (.Pas de propriétaire - ATK0110 ACPI Utility.) -- C:\Windows\System32\Drivers\ASACPI.sys [5810]
O58 - SDL:[MD5.6F1505608202BBD179095A6A150D103F] - 15/01/2014 - 11:12:22 ---A- . (.AVAST Software - avast! File System Minifilter for Windows 2003/Vista.) -- C:\Windows\System32\Drivers\aswMonFlt.sys [67824]
O58 - SDL:[MD5.2206985EF126AB90F3D7F1A020589DC9] - 22/10/2013 - 00:46:24 ---A- . (.AVAST Software - avast! WFP Redirect Driver.) -- C:\Windows\System32\Drivers\aswRdr2.sys [79720]
O58 - SDL:[MD5.F385467DF95D0A73775CB3B076B8B969] - 22/10/2013 - 00:46:25 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [49944]
O58 - SDL:[MD5.0F639D0526820BA7872C963813E0EB8D] - 15/01/2014 - 11:12:23 ---A- . (.AVAST Software - avast! Virtualization Driver.) -- C:\Windows\System32\Drivers\aswSnx.sys [775952]
O58 - SDL:[MD5.7BA7543EA7936A7ADA615F6DE7C95494] - 15/01/2014 - 11:12:23 ---A- . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\Drivers\aswsp.sys [410528]
O58 - SDL:[MD5.37A6A39C1792BA961EE6172A0F3CA236] - 15/01/2014 - 11:12:49 ---A- . (.AVAST Software - Stream Filter.) -- C:\Windows\System32\Drivers\aswstm.sys [64168]
O58 - SDL:[MD5.1B0662514A68C3A42E60D240C5ABEF28] - 15/01/2014 - 11:12:23 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [180248]
O58 - SDL:[MD5.BD8869EB9CDE6BBE4508D869929869EE] - 13/07/2009 - 23:02:49 ---A- . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gigabit Ethernet..) -- C:\Windows\System32\Drivers\b57nd60x.sys [229888]
O58 - SDL:[MD5.9F9ACC7F7CCDE8A15C282D3F88B43309] - 13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [13568]
O58 - SDL:[MD5.56801AD62213A41F6497F96DEE83755A] - 13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [5248]
O58 - SDL:[MD5.845B8CE732E67F3B4133164868C666EA] - 14/07/2009 - 01:57:25 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [272128]
O58 - SDL:[MD5.203F0B1E73ADADBBB7B7B1FABD901F6B] - 13/07/2009 - 23:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [62336]
O58 - SDL:[MD5.BD456606156BA17E60A04E18016AE54B] - 13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [12160]
O58 - SDL:[MD5.AF72ED54503F717A43268B3CC5FAEC2E] - 13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [11904]
O58 - SDL:[MD5.1A231ABEC60FD316EC54C66715543CEC] - 13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbdx.sys [430080]
O58 - SDL:[MD5.C537B1DB64D495B9B4717B4D6D9EDBF2] - 14/07/2009 - 02:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [15952]
O58 - SDL:[MD5.8B30250D573A8F6B4BD23195160D8707] - 14/07/2009 - 02:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\Drivers\djsvs.sys [70720]
O58 - SDL:[MD5.0ED67910C8C326796FAA00B2BF6D9D3C] - 14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:[MD5.024E1B5CAC09731E4D868E64DBFB4AB0] - 13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbdx.sys [3100160]
O58 - SDL:[MD5.C44E3C2BAB6837DB337DDEE7544736DB] - 13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624]
O58 - SDL:[MD5.295FDC419039090EB8B49FFDBB374549] - 14/07/2009 - 02:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [67152]
O58 - SDL:[MD5.5CD5F9A5444E6CDCB0AC89BD62D8B76E] - 11/03/2011 - 06:38:51 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160]
O58 - SDL:[MD5.AD626F6964F4D364D226C39E06872DD3] - 10/06/2009 - 22:19:30 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\Drivers\igdkmd32.sys [4756480]
O58 - SDL:[MD5.4173FF5708F3236CF25195FECD742915] - 14/07/2009 - 02:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [41040]
O58 - SDL:[MD5.EB119A53CCF2ACC000AC71B065B78FEF] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [95824]
O58 - SDL:[MD5.8ADE1C877256A22E49B75D1CC9161F9C] - 14/07/2009 - 02:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [89168]
O58 - SDL:[MD5.DC9DC3D3DAA0E276FD2EC262E38B11E9] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [54864]
O58 - SDL:[MD5.0A036C7D7CAB643A7F07135AC47E0524] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [96848]
O58 - SDL:[MD5.4470E3C1E0C3378E4CAB137893C12C3A] - 04/04/2013 - 14:50:32 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [22856]
O58 - SDL:[MD5.0FFF5B045293002AB38EB1FD1FC2FB74] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\System32\Drivers\megasas.sys [30800]
O58 - SDL:[MD5.DCBAB2920C75F390CAF1D29F675D03D6] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [235584]
O58 - SDL:[MD5.370887E0E0DBD2B31164EDADB95C99DF] - 03/07/2009 - 17:31:28 ---A- . (.Ralink Technology Corp. - Ralink 802.11n Wireless Adapter Driver.) -- C:\Windows\System32\Drivers\netr28u.sys [746496]
O58 - SDL:[MD5.1D85C4B390B0EE09C7A46B91EFB2C097] - 14/07/2009 - 02:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [44624]
O58 - SDL:[MD5.B3E25EE28883877076E0E1FF877D02E0] - 11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120]
O58 - SDL:[MD5.4380E59A170D88C4F1022EFF6719A8A4] - 11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744]
O58 - SDL:[MD5.AB95ECF1F6659A60DDC166D8315B0751] - 14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1383488]
O58 - SDL:[MD5.B4DD51DD25182244B86737DC51AF2270] - 14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [106064]
O58 - SDL:[MD5.7DFD48E24479B68B258D8770121155A0] - 13/07/2009 - 23:02:52 ---A- . (.Realtek Corporation - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Driver.) -- C:\Windows\System32\Drivers\Rt86win7.sys [139776]
O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 13/07/2009 - 21:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [20480]
O58 - SDL:[MD5.A9F0486851BECB6DDA1D89D381E71055] - 14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [40016]
O58 - SDL:[MD5.3727097B55738E2F554972C3BE5BC1AA] - 14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [77888]
O58 - SDL:[MD5.DB32D325C192B801DF274BFD12A7E72B] - 14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072]
O58 - SDL:[MD5.E43574F6A56A0EE11809B48C09E4FD3C] - 14/07/2009 - 02:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [16976]
O58 - SDL:[MD5.9DFA0CC2F8855A04816729651175B631] - 14/07/2009 - 02:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [141904]
O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:[MD5.E6BC0F98FECEF245A0010D350C1A0B9B] - 13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:[MD5.492090267B9608C62B956CD29BE3AFB7] - 13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:[MD5.FFFF296A08DBF2AC0126C62E3778AC0D] - 13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:[MD5.2E4112FB7D1B76E11ADFD7487B5D0E95] - 13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:[MD5.A98EBD4C2DF983665BF2D1AF49949974] - 13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:[MD5.3F7E6406EDEF197C5CAAB2240EEF6F48] - 13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:[MD5.3E64D681B776CC57BDC38A46D881F85B] - 13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:[MD5.D86B6435729231C171432B4E77801BDB] - 13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
~ Drivers: 16 Scanned in 00mn 01s



---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 14/01/2014 - 10:33:45 ---A- . (...) -- C:\Users\alain\.android\adbkey [1704]
O61 - LFC: 14/01/2014 - 10:33:45 ---A- . (...) -- C:\Users\alain\.android\adbkey.pub [716]
O61 - LFC: 14/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\Mobogenie\Data\mobogenie_u_user_dl.mg [3072]
O61 - LFC: 14/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\Mobogenie\client.time [10]
O61 - LFC: 14/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\Mobogenie\mobo.uuid [32]
O61 - LFC: 14/01/2014 - 10:33:51 ---A- . (.Setup ©.) -- C:\Users\alain\AppData\Local\Temp\39909uninstall.exe [647680]
O61 - LFC: 14/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\chlink.lnk [144]
O61 - LFC: 14/01/2014 - 10:33:57 --HA- . (...) -- C:\Users\alain\AppData\Local\Temp\etilqs_8vonXDjqml3RB3d [262176]
O61 - LFC: 14/01/2014 - 10:34:01 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098563_stp.EXE.part [241]
O61 - LFC: 14/01/2014 - 10:34:01 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098597_stp.CIS [9735]
O61 - LFC: 14/01/2014 - 10:34:01 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098597_stp.CIS.part [20]
O61 - LFC: 14/01/2014 - 10:34:01 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098635_stp.CIS [218183]
O61 - LFC: 14/01/2014 - 10:34:01 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098635_stp.CIS.part [22]
O61 - LFC: 14/01/2014 - 10:34:01 ---A- . (.Mozilla.) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098563_stp.EXE [22710720]
O61 - LFC: 14/01/2014 - 10:34:05 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098705_stp.CIS [19435632]
O61 - LFC: 14/01/2014 - 10:34:05 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098705_stp.CIS.part [209]
O61 - LFC: 14/01/2014 - 10:34:08 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098745_stp.EXE [2355200]
O61 - LFC: 14/01/2014 - 10:34:08 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098745_stp.EXE.part [54]
O61 - LFC: 14/01/2014 - 10:34:08 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098875_stp.CIS [6511327]
O61 - LFC: 14/01/2014 - 10:34:08 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098875_stp.CIS.part [83]
O61 - LFC: 14/01/2014 - 10:34:10 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098902_stp.CIS [501103]
O61 - LFC: 14/01/2014 - 10:34:10 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2098902_stp.CIS.part [24]
O61 - LFC: 14/01/2014 - 10:34:10 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2099324_stp.CIS [43763]
O61 - LFC: 14/01/2014 - 10:34:10 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\is1242154493\2099324_stp.CIS.part [20]
O61 - LFC: 14/01/2014 - 10:34:14 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\nsf872A.tmp\BgWorker.dll [2560]
O61 - LFC: 14/01/2014 - 10:34:14 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\nsf872A.tmp\KillProcDLL.dll [4096]
O61 - LFC: 14/01/2014 - 10:34:14 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\nsf872A.tmp\SkinBtn.dll [4608]
O61 - LFC: 14/01/2014 - 10:34:14 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\nsf872A.tmp\System.dll [11264]
O61 - LFC: 14/01/2014 - 10:34:14 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\nsi732D.tmp\BgWorker.dll [2560]
O61 - LFC: 14/01/2014 - 10:34:14 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\nsi732D.tmp\KillProcDLL.dll [4096]
O61 - LFC: 14/01/2014 - 10:34:14 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\nsi732D.tmp\SkinBtn.dll [4608]
O61 - LFC: 14/01/2014 - 10:34:14 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\nsi732D.tmp\System.dll [11264]
O61 - LFC: 14/01/2014 - 10:34:14 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\nsi732D.tmp\inetc.dll [20992]
O61 - LFC: 14/01/2014 - 10:34:14 ---A- . (.Igor Pavlov.) -- C:\Users\alain\AppData\Local\Temp\nsf872A.tmp\nsis7z.dll [175104]
O61 - LFC: 14/01/2014 - 10:34:14 ---A- . (.Igor Pavlov.) -- C:\Users\alain\AppData\Local\Temp\nsi732D.tmp\nsis7z.dll [175104]
O61 - LFC: 14/01/2014 - 10:34:15 ---A- . (.Afrow Soft Ltd..) -- C:\Users\alain\AppData\Local\Temp\nsv1DBE.tmp\nsJSON.dll [7168]
O61 - LFC: 14/01/2014 - 10:34:18 ---A- . (.Smart PC Solutions.) -- C:\Users\alain\AppData\Local\Temp\pcspeedmaxsetup.exe [3450792]
O61 - LFC: 14/01/2014 - 10:34:19 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\Sqlite3.dll [599419]
O61 - LFC: 14/01/2014 - 10:34:24 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\{2313EE42-CADE-4310-8819-29496DEB01C4}\setup.exe [6426328]
O61 - LFC: 14/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\daemonprocess.txt [0]
O61 - LFC: 14/01/2014 - 10:35:14 ---A- . (.Mozilla.) -- C:\Users\alain\Downloads\Firefox [1].exe [22240760]
O61 - LFC: 15/01/2014 - 10:34:27 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Adobe\Acrobat\11.0\JSCache\GlobSettings [24]
O61 - LFC: 15/01/2014 - 10:34:27 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Adobe\Acrobat\11.0\Security\CRLCache\48B76449F3D5FEFA1133AA805E420F0FCA643651.crl [898]
O61 - LFC: 15/01/2014 - 10:34:27 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Adobe\Acrobat\11.0\Security\CRLCache\A9B8213768ADC68AF64FCC6409E8BE414726687F.crl [37213]
O61 - LFC: 15/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Excel.pip [1432]
O61 - LFC: 15/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\COMPTES.lnk [439]
O61 - LFC: 15/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\CREDIT MUTUEL 2013.lnk [626]
O61 - LFC: 15/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\CREDIT MUTUEL 2014.lnk [626]
O61 - LFC: 15/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\LOTO.lnk [446]
O61 - LFC: 16/01/2014 - 10:33:45 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.000\DeviceCenterDiagnostic.0.debugreport.xml [3081]
O61 - LFC: 16/01/2014 - 10:33:45 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.000\DeviceDiagnostic.0.debugreport.xml [1344]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.000\NetworkDiagnostics.0.debugreport.xml [1317]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.000\PrinterDiagnostic.0.debugreport.xml [1311]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.000\ResultReport.xml [55603]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.000\results.xml [220]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.000\results.xsl [49097]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.001\DeviceCenterDiagnostic.0.debugreport.xml [3080]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.001\DeviceDiagnostic.0.debugreport.xml [1344]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.001\NetworkDiagnostics.0.debugreport.xml [1317]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.001\PrinterDiagnostic.0.debugreport.xml [1311]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.001\ResultReport.xml [55603]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.001\results.xml [220]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.001\results.xsl [49097]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.002\DeviceCenterDiagnostic.0.debugreport.xml [3463]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.002\DeviceDiagnostic.0.debugreport.xml [1344]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.002\NetworkDiagnostics.0.debugreport.xml [1317]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.002\PrinterDiagnostic.0.debugreport.xml [19076]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.002\ResultReport.xml [55927]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.002\results.xml [220]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.002\results.xsl [49097]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.003\DeviceCenterDiagnostic.0.debugreport.xml [3079]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.003\DeviceDiagnostic.0.debugreport.xml [1344]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.003\NetworkDiagnostics.0.debugreport.xml [1317]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.003\PrinterDiagnostic.0.debugreport.xml [1311]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.003\ResultReport.xml [55603]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.003\results.xml [220]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.003\results.xsl [49097]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.004\DeviceCenterDiagnostic.0.debugreport.xml [3079]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.004\DeviceDiagnostic.0.debugreport.xml [1344]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.004\NetworkDiagnostics.0.debugreport.xml [1317]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.004\PrinterDiagnostic.0.debugreport.xml [1311]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.004\ResultReport.xml [55603]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.004\results.xml [220]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.004\results.xsl [49097]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.005\DeviceCenterDiagnostic.0.debugreport.xml [3079]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.005\DeviceDiagnostic.0.debugreport.xml [1344]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.005\NetworkDiagnostics.0.debugreport.xml [1317]
O61 - LFC: 16/01/2014 - 10:33:46 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.005\PrinterDiagnostic.0.debugreport.xml [1311]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.005\ResultReport.xml [55603]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.005\results.xml [220]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011607.005\results.xsl [49097]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.000\DeviceCenterDiagnostic.0.debugreport.xml [3466]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.000\DeviceDiagnostic.0.debugreport.xml [1344]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.000\NetworkDiagnostics.0.debugreport.xml [1317]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.000\PrinterDiagnostic.0.debugreport.xml [19005]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.000\ResultReport.xml [55896]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.000\results.xml [220]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.000\results.xsl [49097]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.001\DeviceCenterDiagnostic.0.debugreport.xml [3807]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.001\DeviceCenterDiagnostic.1.debugreport.xml [3160]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.001\DeviceDiagnostic.0.debugreport.xml [1344]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.001\DeviceDiagnostic.1.debugreport.xml [1344]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.001\NetworkDiagnostics.0.debugreport.xml [1317]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.001\NetworkDiagnostics.1.debugreport.xml [1317]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.001\PrinterDiagnostic.0.debugreport.xml [22057]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.001\PrinterDiagnostic.1.debugreport.xml [19077]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.001\ResultReport.xml [56496]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.001\results.xml [220]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\2014011608.001\results.xsl [49097]
O61 - LFC: 16/01/2014 - 10:33:47 ---A- . (...) -- C:\Users\alain\AppData\Local\ElevatedDiagnostics\3493975886\latest.cab [16986]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_0.inf [2796]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_1.inf [1160]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_10.inf [50802]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_11.inf [5278]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_12.inf [2862]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_13.inf [15050]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_14.inf [1176]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_15.inf [11706]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_16.inf [2814]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_17.inf [1878]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_18.inf [2378]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_19.inf [7682]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_2.inf [1864]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_20.inf [1918]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_21.inf [1174]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_22.inf [33514]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_23.inf [11880]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_24.inf [11098]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_25.inf [1286]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_26.inf [6142]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_27.inf [3176]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_28.inf [41148]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_29.inf [1616]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_3.inf [6354]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_30.inf [1294]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_31.inf [15790]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_32.inf [1222]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_33.inf [36284]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_34.inf [2066]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_35.inf [1180]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_36.inf [1208]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_37.inf [1164]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_38.inf [1122]
O61 - LFC: 16/01/2014 - 10:33:54 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_39.inf [1408]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_4.inf [36396]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_40.inf [14614]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_41.inf [41736]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_42.inf [22512]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_43.inf [55252]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_44.inf [1388]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_45.inf [9888]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_46.inf [1394]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_47.inf [1140]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_48.inf [1688]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_49.inf [7862]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_5.inf [1186]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_50.inf [2980]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_51.inf [34728]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_52.inf [1720]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_53.inf [8556]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_54.inf [1712]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_55.inf [427298]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_56.inf [1182]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_57.inf [1156]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_58.inf [10174]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_59.inf [3328]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_6.inf [2690]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_60.inf [1198]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_61.inf [1458]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_62.inf [2250]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_63.inf [2770]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_64.inf [1198]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_65.inf [19164]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_66.inf [1262]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_67.inf [1144]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_68.inf [1280]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_69.inf [1800]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_7.inf [66534]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_70.inf [1272]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_71.inf [1658]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_72.inf [20054]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_73.inf [49500]
O61 - LFC: 16/01/2014 - 10:33:55 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_74.inf [1780]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_75.inf [30558]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_76.inf [13092]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_77.inf [36730]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_78.inf [13338]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_79.inf [2576]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_8.inf [1346]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_80.inf [1260]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_81.inf [1424]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_82.inf [1408]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_83.inf [1460]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_84.inf [1880]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_85.inf [2490]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_86.inf [6786]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_87.inf [2428]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_88.inf [1352]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_89.inf [12164]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_9.inf [11794]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_90.inf [36120]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_91.inf [2146]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_92.inf [83582]
O61 - LFC: 16/01/2014 - 10:33:56 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\CDM\PList\PList_93.inf [26938]
O61 - LFC: 16/01/2014 - 10:34:24 ---A- . (...) -- C:\Users\alain\AppData\Local\Thunderbird\Mozilla Thunderbird\active-update.xml [57] =>.Mozilla Corporation
O61 - LFC: 16/01/2014 - 10:34:24 ---A- . (...) -- C:\Users\alain\AppData\Local\Thunderbird\Mozilla Thunderbird\updates.xml [1581] =>.Mozilla Corporation
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2014-01-16 (11-47-57).txt [47310]
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Excel\Excel.xlb [22]
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\HTML Help\hh.dat [8678]
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\Bureau.lnk [333]
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\EUROTOOL.lnk [1191]
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\Macrolib.lnk [1054]
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\Mes documents.lnk [897]
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\Mon Asus est.lnk [613]
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\Répar Blue Screen.lnk [638]
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\Suis à la lettre les instructions que je te donnerai et ne prends aucune initiative avec les outils de désinfection.lnk [1712]
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\mots.lnk [1010]
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\ZHP\ZHPADSReport.txt [351] =>.Nicolas Coolman
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\ZHP\ZHPDiag.txt [206515] =>.Nicolas Coolman
O61 - LFC: 16/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\Documents\bluescreenview\BlueScreenView.cfg [951]
O61 - LFC: 16/01/2014 - 10:34:33 -SHA- . (...) -- C:\Users\alain\Documents\Mes photos persos\Thumbs.db [1051136]
O61 - LFC: 16/01/2014 - 10:35:14 ---A- . (.alain.) -- C:\Users\alain\Documents\tous les trucs\Suis à la lettre les instructions que je te donnerai et ne prends aucune initiative avec les outils de désinfection.doc [189440]
O61 - LFC: 17/01/2014 - 10:33:47 --HA- . (...) -- C:\Users\alain\AppData\Local\IconCache.db [3766976]
O61 - LFC: 17/01/2014 - 10:34:15 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\o0a9cgU5.part [349]
O61 - LFC: 17/01/2014 - 10:34:20 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\Twain001.Mtx [4]
O61 - LFC: 17/01/2014 - 10:34:20 ---A- . (...) -- C:\Users\alain\AppData\Local\Temp\Twunk001.MTX [156]
O61 - LFC: 17/01/2014 - 10:34:27 ---A- . (...) -- C:\Users\alain\AppData\Roaming\AVAST Software\Avast\Cache\HTMLayout.xml [4216]
O61 - LFC: 17/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\FineReaderLite.Word.Tmpl.lnk [1501]
O61 - LFC: 17/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\Héberger le rapport.lnk [1232]
O61 - LFC: 17/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\Integration.lnk [1284]
O61 - LFC: 17/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\Trucs ordi.lnk [456]
O61 - LFC: 17/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\dernière réponse.lnk [633]
O61 - LFC: 17/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Récents\tous les trucs.lnk [1040]
O61 - LFC: 17/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Office\Word.pip [1504]
O61 - LFC: 17/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\ZHP\Log.txt [50554] =>.Nicolas Coolman
O61 - LFC: 17/01/2014 - 10:34:28 ---A- . (...) -- C:\Users\alain\AppData\Roaming\ZHP\TestsZHPDiag.txt [2810] =>.Nicolas Coolman
O61 - LFC: 17/01/2014 - 10:34:28 --HA- . (...) -- C:\Users\alain\AppData\Roaming\Microsoft\Modèles\~$Normal.dot [162]
O61 - LFC: 17/01/2014 - 10:35:13 ---A- . (.alain.) -- C:\Users\alain\Documents\tous les trucs\Héberger le rapport.doc [142336]
~ 131 Fichiers temporaires (Temporary files)
~ Files: 238 Scanned in 01mn 29s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 14/09/2013 - C:\Windows\system32\drivers\afd.sys (AFD) .(.Microsoft Corporation - Ancillary Function Driver for WinSock.) - LEGACY_AFD
O64 - Services: CurCS - 15/01/2014 - C:\Windows\system32\drivers\aswMonFlt.sys (aswMonFlt) .(.AVAST Software - avast! File System Minifilter for Windows 2.) - LEGACY_ASWMONFLT
O64 - Services: CurCS - 22/10/2013 - C:\Windows\system32\drivers\aswRdr2.sys (aswRdr) .(.AVAST Software - avast! WFP Redirect Driver.) - LEGACY_ASWRDR
O64 - Services: CurCS - 22/10/2013 - C:\Windows\System32\Drivers\aswRvrt.sys (aswRvrt) .(...) - LEGACY_ASWRVRT
O64 - Services: CurCS - 15/01/2014 - C:\Windows\system32\drivers\aswSnx.sys (aswSnx) .(.AVAST Software - avast! Virtualization Driver.) - LEGACY_ASWSNX
O64 - Services: CurCS - 15/01/2014 - C:\Windows\system32\drivers\aswSP.sys (aswSP) .(.AVAST Software - avast! self protection module.) - LEGACY_ASWSP
O64 - Services: CurCS - 15/01/2014 - C:\Windows\system32\drivers\aswStm.sys (aswStm) .(.AVAST Software - Stream Filter.) - LEGACY_ASWSTM
O64 - Services: CurCS - 15/01/2014 - C:\Windows\System32\Drivers\aswVmm.sys (aswVmm) .(...) - LEGACY_ASWVMM
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\Drivers\Beep.sys (Beep) .(.Microsoft Corporation - BEEP Driver.) - LEGACY_BEEP
O64 - Services: CurCS - 04/07/2012 - C:\Windows\system32\browser.dll (bowser) .(.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) - LEGACY_BOWSER
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\clfs.sys (CLFS) .(.Microsoft Corporation - Common Log File System Driver.) - LEGACY_CLFS
O64 - Services: CurCS - 04/07/2013 - C:\Windows\System32\Drivers\cng.sys (CNG) .(.Microsoft Corporation - Kernel Cryptography, Next Generation.) - LEGACY_CNG
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\dfsc.sys (DfsC) .(.Microsoft Corporation - DFS Namespace Client Driver.) - LEGACY_DFSC
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\discache.sys (discache) .(.Microsoft Corporation - System Indexer/Cache Driver.) - LEGACY_DISCACHE
O64 - Services: CurCS - 01/08/2013 - C:\Windows\system32\drivers\dxgkrnl.sys (DXGKrnl) .(.Microsoft Corporation - DirectX Graphics Kernel.) - LEGACY_DXGKRNL
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\Drivers\fastfat.sys (fastfat) .(.Microsoft Corporation - Fast FAT File System Driver.) - LEGACY_FASTFAT
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\fileinfo.sys (FileInfo) .(.Microsoft Corporation - FileInfo Filter Driver.) - LEGACY_FILEINFO
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\fltmgr.sys (FltMgr) .(.Microsoft Corporation - Gestionnaire de filtres de système de fichi.) - LEGACY_FLTMGR
O64 - Services: CurCS - 24/01/2013 - C:\Windows\system32\drivers\fvevol.sys (fvevol) .(.Microsoft Corporation - BitLocker Drive Encryption Driver.) - LEGACY_FVEVOL
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\http.sys (HTTP) .(.Microsoft Corporation - HTTP Pile du protocole.) - LEGACY_HTTP
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\hwpolicy.sys (hwpolicy) .(.Microsoft Corporation - Hardware Policy Driver.) - LEGACY_HWPOLICY
O64 - Services: CurCS - 25/09/2013 - C:\Windows\System32\Drivers\ksecdd.sys (KSecDD) .(.Microsoft Corporation - Kernel Security Support Provider Interface.) - LEGACY_KSECDD
O64 - Services: CurCS - 25/09/2013 - C:\Windows\System32\Drivers\ksecpkg.sys (KSecPkg) .(.Microsoft Corporation - Kernel Security Support Provider Interface.) - LEGACY_KSECPKG
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\lltdio.sys (lltdio) .(.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) - LEGACY_LLTDIO
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\luafv.sys (luafv) .(.Microsoft Corporation - Pilote de filtre de virtualisation de fichi.) - LEGACY_LUAFV
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\mountmgr.sys (mountmgr) .(.Microsoft Corporation - Gestionnaire des points de montage.) - LEGACY_MOUNTMGR
O64 - Services: CurCS - 27/09/2013 - C:\Windows\System32\DRIVERS\MpFilter.sys (MpFilter) .(.Microsoft Corporation - Microsoft antimalware file system filter dr.) - LEGACY_MPFILTER
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\FirewallAPI.dll (mpsdrv) .(.Microsoft Corporation - API du Pare-feu Windows.) - LEGACY_MPSDRV
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\wkssvc.dll (mrxsmb) .(.Microsoft Corporation - DLL du service Station de travail.) - LEGACY_MRXSMB
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\wkssvc.dll (mrxsmb10) .(.Microsoft Corporation - DLL du service Station de travail.) - LEGACY_MRXSMB10
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\wkssvc.dll (mrxsmb20) .(.Microsoft Corporation - DLL du service Station de travail.) - LEGACY_MRXSMB20
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\drivers\msisadrv.sys (msisadrv) .(.Microsoft Corporation - ISA Driver.) - LEGACY_MSISADRV
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\mup.sys (Mup) .(.Microsoft Corporation - Multiple UNC Provider Driver.) - LEGACY_MUP
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\nwifi.sys (NativeWifiP) .(.Microsoft Corporation - Pilote de miniport WiFi natif.) - LEGACY_NATIVEWIFIP
O64 - Services: CurCS - 22/08/2012 - C:\Windows\system32\drivers\ndis.sys (NDIS) .(.Microsoft Corporation - Pilote NDIS 6.20.) - LEGACY_NDIS
O64 - Services: CurCS - 20/11/2010 - C:\Windows\System32\DRIVERS\ndisuio.sys (Ndisuio) .(.Microsoft Corporation - Pilote d’E/S du mode utilisateur NDIS.) - LEGACY_NDISUIO
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\netbios.sys (NetBIOS) .(.Microsoft Corporation - NetBIOS interface driver.) - LEGACY_NETBIOS
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\netbt.sys (NetBT) .(.Microsoft Corporation - MBT Transport driver.) - LEGACY_NETBT
O64 - Services: CurCS - 27/09/2013 - C:\Windows\System32\DRIVERS\NisDrvWFP.sys (NisDrv) .(.Microsoft Corporation - Microsoft Network Realtime Inspection Drive.) - LEGACY_NISDRV
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\nsiproxy.sys (nsiproxy) .(.Microsoft Corporation - NSI Proxy.) - LEGACY_NSIPROXY
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\parvdm.sys (Parvdm) .(.Microsoft Corporation - Pilote parallèle VDM.) - LEGACY_PARVDM
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\drivers\pcw.sys (pcw) .(.Microsoft Corporation - Performance Counters for Windows Driver.) - LEGACY_PCW
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\drivers\peauth.sys (PEAUTH) .(.Microsoft Corporation - Protected Environment Authentication and Au.) - LEGACY_PEAUTH
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\drivers\pacer.sys (Psched) .(.Microsoft Corporation - Planificateur de paquets QoS.) - LEGACY_PSCHED
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\wkssvc.dll (rdbss) .(.Microsoft Corporation - DLL du service Station de travail.) - LEGACY_RDBSS
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\DRIVERS\RDPCDD.sys (RDPCDD) .(.Microsoft Corporation - RDP Miniport.) - LEGACY_RDPCDD
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\RDPENCDD.sys (RDPENCDD) .(.Microsoft Corporation - RDP Encoder Miniport.) - LEGACY_RDPENCDD
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\RdpRefMp.sys (RDPREFMP) .(.Microsoft Corporation - RDP Reflector Driver Miniport.) - LEGACY_RDPREFMP
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\rspndr.sys (rspndr) .(.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) - LEGACY_RSPNDR
O64 - Services: CurCS - 13/07/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\Drivers\spldr.sys (spldr) .(.Microsoft Corporation - loader for security processor.) - LEGACY_SPLDR
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\srvsvc.dll (srv) .(.Microsoft Corporation - DLL du service Serveur.) - LEGACY_SRV
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\srvsvc.dll (srv2) .(.Microsoft Corporation - DLL du service Serveur.) - LEGACY_SRV2
O64 - Services: CurCS - 29/04/2011 - C:\Windows\System32\DRIVERS\srvnet.sys (srvnet) .(.Microsoft Corporation - Server Network driver.) - LEGACY_SRVNET
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\tcpipcfg.dll (Tcpip) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_TCPIP
O64 - Services: CurCS - 03/10/2012 - C:\Windows\System32\drivers\tcpipreg.sys (tcpipreg) .(.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) - LEGACY_TCPIPREG
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\tcpipcfg.dll (tdx) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_TDX
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\vga.sys (VgaSave) .(.Microsoft Corporation - VGA/Super VGA Video Driver.) - LEGACY_VGASAVE
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\volmgrx.sys (volmgrx) .(.Microsoft Corporation - Pilote d’extension du gestionnaire de volum.) - LEGACY_VOLMGRX
O64 - Services: CurCS - 20/11/2010 - C:\Windows\System32\drivers\volsnap.sys (volsnap) .(.Microsoft Corporation - Pilote de cliché instantané du volume.) - LEGACY_VOLSNAP
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\vwififlt.sys (vwififlt) .(.Microsoft Corporation - Virtual WiFi Filter Driver.) - LEGACY_VWIFIFLT
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\rascfg.dll (Wanarpv6) .(.Microsoft Corporation - Objets de configuration RAS.) - LEGACY_WANARPV6
O64 - Services: CurCS - 25/06/2013 - C:\Windows\System32\drivers\Wdf01000.sys (Wdf01000) .(.Microsoft Corporation - Runtime de l’infrastructure de pilotes en m.) - LEGACY_WDF01000
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\wfplwf.sys (WfpLwf) .(.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - LEGACY_WFPLWF
O64 - Services: CurCS - 26/07/2012 - C:\Windows\system32\drivers\Wudfpf.sys (WudfPf) .(.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) - LEGACY_WUDFPF
~ Legacy: 118 Scanned in 00mn 00s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
~ FASS Keys: 11 Scanned in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("browser.search.defaultenginename", "Mysearchdial"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("browser.search.selectedEngine", "Mysearchdial"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.AL", 2); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.aflt", "irmsd0101"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtBtAyDyE0B0D0FyB0FyDtCyCtC0CtN0D0Tzu0SyByEyEtN1L2XzutBtFtBtFtCyDtFtCy[...] =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.cr", "182837737"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.dfltLng", ""); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.dfltSrch", true); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.dnsErr", true); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.excTlbr", false); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.hmpg", true); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.hmpgUrl", "http://start.mysearchdial.com/?f=1&a=irmsd0101&cd=2XzuyEtN2Y1L1QzutDtDtBtAyDyE0B0D0F[...] =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.id", "002354BDF7F5161C"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.instlDay", "16084"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.instlRef", ""); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.newTabUrl", "http://start.mysearchdial.com/?f=2&a=irmsd0101&cd=2XzuyEtN2Y1L1QzutDtDtBtAyDyE0B0D[...] =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.prdct", "mysearchdial"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.tlbrId", "base"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.tlbrSrchUrl", "http://start.mysearchdial.com/?f=3&a=irmsd0101&cd=2XzuyEtN2Y1L1QzutDtDtBtAyDyE0B[...] =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.vrsn", "1.8.21.0"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial.vrsni", "1.8.21.0"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial_i.hmpg", true); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial_i.newTab", false); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial_i.smplGrp", "none"); =>Adware.MyWebSearch
O69 - SBI: prefs.js [alain - 1sno9imx.default] user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.21.08:54:56"); =>Adware.MyWebSearch
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Mysearchdial) - http://start.mysearchdial.com =>Adware.MyWebSearch
O69 - SBI: SearchScopes [HKCU] {77AA745B-F4F8-45DA-9B14-61D2D95054C8} - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s



---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [473600]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [521216]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [1933848]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164352]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [102912]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800]

~ Services: 32 Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.45E6002BC685564A7027A01D5D5BE1DA] [SPRF][14/01/2014] (.Setup © - Setup.) -- C:\Users\alain\AppData\Local\Temp\39909uninstall.exe [647680]
[MD5.32DCED18FFFEA0035E4FA975CA0AE8BE] [SPRF][22/04/2013] (.The Software Group - Software Update Setup.) -- C:\Users\alain\AppData\Local\Temp\BoxoreInstaller.exe [620656] =>Adware.Boxore
[MD5.61446FDD76788229D3EBAEABE84DF38C] [SPRF][31/12/2001] (.Microsoft Corporation - Microsoft .NET Framework 4 Client Profile Setup.) -- C:\Users\alain\AppData\Local\Temp\dotNetFx40_Client_setup.exe [887896]
[MD5.D720B11E0FCD829361087EAFFA641DF9] [SPRF][02/10/2013] (.Solid State Networks - Adobe Reader Installer.) -- C:\Users\alain\AppData\Local\Temp\install_reader11_fr_mssa_aaa_aih.exe [1071568]
[MD5.402F787B8615DD0ECC530C24A7B1E7E9] [SPRF][01/01/2002] (...) -- C:\Users\alain\AppData\Local\Temp\mpam-8a9777f6.exe [57065472]
[MD5.40D7B1C43B13F3AEB45908750C54BA2E] [SPRF][01/01/2002] (.Aedge Performance BCN SL - OfferBox setup.) -- C:\Users\alain\AppData\Local\Temp\OB.exe [3436816] =>PUP.OfferBox
[MD5.0CC68A28139B555BEFD99ECA0D695A2A] [SPRF][14/01/2014] (.Smart PC Solutions - PC Speed Maximizer.) -- C:\Users\alain\AppData\Local\Temp\pcspeedmaxsetup.exe [3450792] =>Rogue.PCSpeedMaximizer
[MD5.3BF79E6868B44D3ADB2796BA99521891] [SPRF][07/09/2013] (...) -- C:\Users\alain\AppData\Local\Temp\Quarantine.exe [344583]
[MD5.5405413FFF79B8D9C747AA900F60F082] [SPRF][14/01/2014] (...) -- C:\Users\alain\AppData\Local\Temp\Sqlite3.dll [599419]
[MD5.FBAB280D0CAC5E21C72F0A1A7B5B9608] [SPRF][04/09/2009] (.Macrovision Corporation - Setup.exe.) -- C:\Users\alain\AppData\Local\Temp\_is5D5D.exe [455600]
[MD5.FBAB280D0CAC5E21C72F0A1A7B5B9608] [SPRF][04/09/2009] (.Macrovision Corporation - Setup.exe.) -- C:\Users\alain\AppData\Local\Temp\_is9760.exe [455600]
[MD5.FBAB280D0CAC5E21C72F0A1A7B5B9608] [SPRF][04/09/2009] (.Macrovision Corporation - Setup.exe.) -- C:\Users\alain\AppData\Local\Temp\_isAE29.exe [455600]
[MD5.AAE2BA33607D8132735A5CAD0FB53C7F] [SPRF][17/01/2014] (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Users\alain\Desktop\ZHPDiag2.exe [6865600]
~ Files: 13 Scanned in 00mn 01s



---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
O87 - FAEL: "SNMPTRAP-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Interruption SNMP.) -- C:\Windows\system32\snmptrap.exe
O87 - FAEL: "SNMPTRAP-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Interruption SNMP.) -- C:\Windows\system32\snmptrap.exe
O87 - FAEL: "WMP-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMP-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMP-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-Out-UDP-NoScope" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-WMP-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-WMP-Out-UDP-NoScope" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-WMP-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-Out-UDP-NoScope" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-Out-UDP" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-SSDPSrv-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-SSDPSrv-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-WMP-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-WMP-Out-UDP" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-WMP-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-Out-UDP" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-UPnP-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Microsoft-Windows-HomeGroup-ProvSvc-TCP3587-In" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Microsoft-Windows-HomeGroup-ProvSvc-TCP3587-Out" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Microsoft-Windows-HomeGroup-ProvSvc-UDP3540-In" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Microsoft-Windows-HomeGroup-ProvSvc-UDP3540-Out" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Collab-P2PHost-In-TCP" | In - None - P6 - TRUE | .(.Microsoft Corporation - Voisinage immédiat.) -- C:\Windows\system32\p2phost.exe
O87 - FAEL: "Collab-P2PHost-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Voisinage immédiat.) -- C:\Windows\system32\p2phost.exe
O87 - FAEL: "Collab-P2PHost-WSD-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Voisinage immédiat.) -- C:\Windows\system32\p2phost.exe
O87 - FAEL: "Collab-P2PHost-WSD-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Voisinage immédiat.) -- C:\Windows\system32\p2phost.exe
O87 - FAEL: "Collab-PNRP-In-UDP" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Collab-PNRP-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Collab-PNRP-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Collab-PNRP-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-In-TCP-EdgeScope" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe
O87 - FAEL: "RemoteAssistance-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe
O87 - FAEL: "RemoteAssistance-PnrpSvc-UDP-In-EdgeScope" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-PnrpSvc-UDP-OUT" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-RAServer-In-TCP-NoScope-Active" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Serveur COM d’assistance à distance Windows.) -- C:\Windows\system32\raserver.exe
O87 - FAEL: "RemoteAssistance-RAServer-Out-TCP-NoScope-Active" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Serveur COM d’assistance à distance Windows.) -- C:\Windows\system32\raserver.exe
O87 - FAEL: "RemoteAssistance-DCOM-In-TCP-NoScope-Active" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-In-TCP-EdgeScope-Active" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe
O87 - FAEL: "RemoteAssistance-Out-TCP-Active" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe
O87 - FAEL: "RemoteAssistance-SSDPSrv-In-UDP-Active" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-SSDPSrv-Out-UDP-Active" | Out - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-SSDPSrv-In-TCP-Active" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-SSDPSrv-Out-TCP-Active" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-PnrpSvc-UDP-In-EdgeScope-Active" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-PnrpSvc-UDP-OUT-Active" | Out - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "FPS-SpoolSvc-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe
O87 - FAEL: "FPS-SpoolSvc-In-TCP" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe
O87 - FAEL: "FPS-LLMNR-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "FPS-LLMNR-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-DHCP-In" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-DHCP-Out" | Out - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-DHCPV6-In" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-DHCPV6-Out" | Out - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-Teredo-In" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-Teredo-Out" | Out - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-IPHTTPS-Out" | Out - None - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-GP-Out-TCP" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-DNS-Out-UDP" | Out - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-GP-LSASS-Out-TCP" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\system32\lsass.exe
O87 - FAEL: "NETDIS-SSDPSrv-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-SSDPSrv-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-UPnP-Out-TCP-Active" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDPHOST-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDPHOST-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-LLMNR-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-LLMNR-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDRESPUB-WSD-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDRESPUB-WSD-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-SSDPSrv-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-SSDPSrv-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-UPnP-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDPHOST-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDPHOST-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-LLMNR-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-LLMNR-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDRESPUB-WSD-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDRESPUB-WSD-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MsiScsi-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MsiScsi-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MsiScsi-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MsiScsi-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MSDTC-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) -- C:\Windows\system32\msdtc.exe
O87 - FAEL: "MSDTC-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) -- C:\Windows\system32\msdtc.exe
O87 - FAEL: "MSDTC-KTMRM-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MSDTC-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MSDTC-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) -- C:\Windows\system32\msdtc.exe
O87 - FAEL: "MSDTC-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) -- C:\Windows\system32\msdtc.exe
O87 - FAEL: "MSDTC-KTMRM-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MSDTC-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteSvcAdmin-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\Windows\system32\services.exe
O87 - FAEL: "RemoteSvcAdmin-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteSvcAdmin-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\Windows\system32\services.exe
O87 - FAEL: "RemoteSvcAdmin-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PerfLogsAlerts-PLASrv-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Performance Logs and Alerts DCOM Server.) -- C:\Windows\system32\plasrv.exe
O87 - FAEL: "PerfLogsAlerts-DCOM-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PerfLogsAlerts-PLASrv-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Performance Logs and Alerts DCOM Server.) -- C:\Windows\system32\plasrv.exe
O87 - FAEL: "PerfLogsAlerts-DCOM-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-WINMGMT-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-WINMGMT-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-ASYNC-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) -- C:\Windows\system32\wbem\unsecapp.exe
O87 - FAEL: "WMI-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-WINMGMT-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-WINMGMT-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-ASYNC-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) -- C:\Windows\system32\wbem\unsecapp.exe
O87 - FAEL: "PNRPMNRS-PNRP-In-UDP" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PNRPMNRS-PNRP-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PNRPMNRS-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PNRPMNRS-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteEventLogSvc-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteEventLogSvc-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteEventLogSvc-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteEventLogSvc-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteTask-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteTask-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteTask-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteTask-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteFwAdmin-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteFwAdmin-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteFwAdmin-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteFwAdmin-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RVM-VDS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Service de disque virtuel.) -- C:\Windows\system32\vds.exe
O87 - FAEL: "RVM-VDSLDR-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Virtual Disk Service Loader.) -- C:\Windows\system32\vdsldr.exe
O87 - FAEL: "RVM-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RVM-VDS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Service de disque virtuel.) -- C:\Windows\system32\vds.exe
O87 - FAEL: "RVM-VDSLDR-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Virtual Disk Service Loader.) -- C:\Windows\system32\vdsldr.exe
O87 - FAEL: "RVM-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WPDMTP-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\wudfhost.exe
O87 - FAEL: "WPDMTP-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\wudfhost.exe
O87 - FAEL: "WPDMTP-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WPDMTP-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WPDMTP-UPnPHost-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WPDMTP-UPnP-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NetPres-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-WSD-In-UDP" |In - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-WSD-Out-UDP" |Out - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "NetPres-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
O87 - FAEL: "MCX-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-In-TCP" | In - None - P6 - FALSE | .(.Microsoft Corporation - Windows Media Center.) -- C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Windows Media Center.) -- C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-QWave-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-QWave-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-QWave-In-TCP" | In - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-QWave-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Windows Media Center.) -- C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Windows Media Center.) -- C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-MCX2SVC-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-Prov-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - MCX2 Provisioning library.) -- C:\Windows\ehome\mcx2prov.exe
O87 - FAEL: "MCX-PlayTo-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-McrMgr-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Media Center Extender Manager.) -- C:\Windows\ehome\mcrmgr.exe
O87 - FAEL: "MCX-PlayTo-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-FDPHost-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{DC55DACF-81B0-44E1-A43B-8102AEBB4E20}" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "{85774628-8B55-4C88-8552-DCEC38D00538}" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "{59C97AF1-94E6-4C37-BE0E-01DD5227315E}" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "{C2601BA0-AA22-4744-B60F-D4188E2E06D1}" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{977AACC4-B731-4D41-B600-F66CB573B0D7}" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
O87 - FAEL: "{20DF898F-40E9-4CAB-A3CA-2106CCC455D8}" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
O87 - FAEL: "{D77EAF42-9A7F-4F41-99A5-F54B01F6F19E}" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
O87 - FAEL: "{C1701CE1-C969-4318-AF42-F3EA493DC110}" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
O87 - FAEL: "{9B0CD2A3-5218-4E34-A0CA-28000A31FE07}" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "{0E88987D-6608-427C-A25F-D4D7FFAE9C38}" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "{08A04AE5-C2B6-442D-AD70-3C6976029FE4}" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "{E09CF647-FD4F-493A-A1F7-3FDE75F3EDF5}" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{1AC8FA3F-2C3F-4025-8976-27D347026645}" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{50CC2F56-889B-4722-BCBC-3E09CCBAE6A4}" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{9DB99B64-FE3F-44F5-B70B-C90AB7EC01C5}" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{641374CE-79CF-4D34-A533-0FC4AABE352F}" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{2C8CE71C-BF29-4C6D-ABE9-5934E1C50867}" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{36C00DDA-51EA-4AB0-9EA9-0C1A0684A988}" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{874E3233-4A4A-4B7E-BB86-78213DFB8540}" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{FC9F5DF6-7E3D-4815-A1D9-03265AF8150D}" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe
O87 - FAEL: "TCP Query User{905CC38F-5262-4CCA-84AC-6D563FFBF862}C:\program files\epson software\event manager\eeventmanager.exe" | In - Private - P6 - TRUE | .(.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\program files\epson software\event manager\eeventmanager.exe
O87 - FAEL: "UDP Query User{1FC236A4-A7F3-44EB-A427-379997487830}C:\program files\epson software\event manager\eeventmanager.exe" | In - Private - P17 - TRUE | .(.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\program files\epson software\event manager\eeventmanager.exe
O87 - FAEL: "TCP Query User{88251A15-22BA-4D60-92FF-D2B113F15C98}C:\program files\epson software\event manager\eeventmanager.exe" | In - Public - P6 - TRUE | .(.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\program files\epson software\event manager\eeventmanager.exe
O87 - FAEL: "UDP Query User{8DE8C2C7-26C8-4AB6-92FE-277EAD002D9B}C:\program files\epson software\event manager\eeventmanager.exe" | In - Public - P17 - TRUE | .(.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\program files\epson software\event manager\eeventmanager.exe
O87 - FAEL: "{12BD720C-2B6A-432E-A9E9-89360466E0F1}" | Out - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{09377F96-B6AC-4868-A554-BDAC97CD404C}" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
~ Firewall: 193 Scanned in 00mn 01s



---\\ Enumère les codes produits des logiciels (PUC) (O90)
O90 - PUC: "0000009F810000000000709475387300" . (.ABBYY FineReader 9.0 Sprint.) -- C:\Windows\Installer\{F9000000-0018-0000-0000-074957833700}\ARPPRODUCTICON.exe
O90 - PUC: "5789C217AB984E4469A601D63F417104" . (.Garmin Express Tray.) -- C:\Windows\Installer\{712C9875-89BA-44E4-966A-106DF3141740}\express.ico =>.Garmin Corporation
O90 - PUC: "68AB67CA7DA76301B744BA0000000010" . (.Adobe Reader XI (11.0.06) - Français.) -- C:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-AB0000000001}\SC_Reader.ico
O90 - PUC: "A0655163106372744BD458B3FE93F5C5" . (.Elevated Installer.) -- C:\Windows\Installer\{3615560A-3601-4727-B44D-853BEF395F5C}\express.ico
O90 - PUC: "D7314F9862C648A4DB8BE2A5B47BE100" . (.Microsoft Silverlight.) -- c:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ARPIcon
O90 - PUC: "DCC9ECEB6F38AAB4B96222D77F2D9E23" . (.Epson Event Manager.) -- C:\Windows\Installer\{BECE9CCD-83F6-4BAA-9B26-227DF7D2E932}\icon.exe
O90 - PUC: "E2C7A3D703CD6274FA18D9CFFC88CDE1" . (.Garmin Express.) -- C:\Windows\Installer\{7D3A7C2E-DC30-4726-AF81-9DFCCF88DC1E}\Garmin.ico =>.Garmin Corporation
~ Update Products: 16 Scanned in 00mn 00s



---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
~ WIS: 17 Scanned in 00mn 02s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 17/01/2014 257928 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 05/12/2013 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

SR - | Auto 14/05/2009 759048 | (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY.) - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
SR - | Auto 21/12/2013 65432 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 15/01/2014 50344 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
SR - | Auto 12/12/2011 122000 | (EpsonScanSvc) . (.Seiko Epson Corporation.) - C:\Windows\system32\EscSvc.exe
SR - | Auto 02/11/2011 167520 | (EPSON_EB_RPCV4_04) . (.SEIKO EPSON CORPORATION.) - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.exe
SR - | Auto 02/11/2011 142432 | (EPSON_PM_RPCV4_04) . (.SEIKO EPSON CORPORATION.) - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.exe
SR - | Auto 19/09/2013 250200 | (Garmin Core Update Service) . (.Garmin Ltd or its subsidiaries.) - C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
SR - | Auto 23/10/2013 22208 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 14/07/2009 185632 | (RalinkRegistryWriter) . (.Ralink Technology, Corp..) - C:\Program Files\Edimax\Common\RaRegistry.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Services: Scanned in 00mn 03s



---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net

~ MBR: 1 Scanned in 00mn 02s



---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by alain at 17/01/2014 10:43:15

********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin

~ MBR: Scanned in 00mn 04s



---\\ Scan Additionnel (O88)
Database Version : 13024 - (17/01/2014)
Clés trouvées (Keys found) : 11
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 4
Fichiers trouvés (Files found) : 5

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\DaleSearch Chrome Toolbar] =>Hijacker.Dalesearch^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vittalia] =>PUP.Vittalia^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\dalesearch] =>Hijacker.Dalesearch^
[HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater] =>Toolbar.Wajam
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>PUP.Tarma
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>PUP.Tarma
[HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro
[HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}] =>PUP.OptimizerPro
[HKLM\Software\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}] =>Adware.BrowseFox
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411151146}] =>PUP.CrossRider
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] =>Adware.Boxore^
C:\Users\alain\AppData\Roaming\Mozilla\Firefox\Profiles\1sno9imx.default\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8} =>Adware.MyWebSearch^
C:\Program Files\Vittalia =>PUP.Vittalia^
C:\Users\alain\AppData\Roaming\FreeSoftwareUpdater =>PUP.Eorezo^
C:\Users\alain\AppData\Local\Software =>Adware.Boxore
[HKCU\Software\AppDataLow\Software\LyricsMonkey-1] =>Adware.AddLyrics^
C:\Users\alain\AppData\Local\Temp\BoxoreInstaller.exe =>Adware.Boxore^
C:\Users\alain\AppData\Local\Temp\OB.exe =>PUP.OfferBox^
C:\Users\alain\AppData\Local\Temp\pcspeedmaxsetup.exe =>Rogue.PCSpeedMaximizer^
~ Additionnel Scan: 173677 Items scanned in 00mn 19s



---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blog/show/32978102-hijacker-dalesearch =>Hijacker.Dalesearch
~ http://nicolascoolman.webs.com/apps/blog/show/27146838-adware-mywebsearch =>Adware.MyWebSearch
~ http://nicolascoolman.webs.com/apps/blog/show/28606910-pup-offerbox =>PUP.OfferBox
~ http://nicolascoolman.webs.com/apps/blog/show/27232411-hijacker-proxy =>Hijacker.Proxy
~ http://nicolascoolman.webs.com/apps/blog/show/35115580-pup-vittalia =>PUP.Vittalia
~ http://nicolascoolman.webs.com/apps/blog/show/26601058-adware-addlyrics =>Adware.AddLyrics
~ http://nicolascoolman.webs.com/apps/blog/show/27469224-pup-eorezo =>PUP.EoRezo
~ http://nicolascoolman.webs.com/apps/blog/show/26626977-adware-boxore =>Adware.Boxore
~ http://nicolascoolman.webs.com/apps/blog/show/33449013-rogue-pcspeedmaximizer =>Rogue.PCSpeedMaximizer
~ http://nicolascoolman.webs.com/apps/blog/show/29637859-toolbar-tarma =>PUP.Tarma
~ http://nicolascoolman.webs.com/apps/blog/show/28204239-pup-optimizerpro =>PUP.OptimizerPro
~ http://nicolascoolman.webs.com/apps/blog/show/32363262-adware-browsefox =>Adware.BrowseFox
~ http://nicolascoolman.webs.com/apps/blog/show/27583526-pup-crossrider =>PUP.CrossRider
~ MSI: 13 link(s) detected in 00mn 20s



End of the scan (1746 lines in 10mn 38s)(0)

Publicité


Signaler le contenu de ce document

Publicité