cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2014.1.25.26 - Nicolas Coolman (25/01/2014)
~ Lancé par Max (03/02/2014 12:51:25)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Not Found


---\\ Navigateurs Internet
MSIE: Internet Explorer v8.0.6001.18702
MFIE: Mozilla Firefox 26.0 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Microsoft Windows XP, 32-bit Service Pack 3 (Build 2600)
Windows Automatic Updates : OK
Windows Genuine Advantage : KO

---\\ Logiciels de protection du système
Avira Free Antivirus v14.0.2.286
Malwarebytes Anti-Malware version 1.75.0.1300

---\\ Logiciels d'optimisation du système
CCleaner v4.03 =>Piriform Ltd

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin
Adobe Reader XI

---\\ Informations sur le système
~ Processor: x86 Family 15 Model 6 Stepping 5, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2046 MB (64% free)
System Restore: Activé (Enable)
System drive C: has 42 GB (54%) free of 78 GB

---\\ Mode de connexion au système
~ Computer Name: MAX-8807BC345EE
~ User Name: Max
~ All Users Names: SUPPORT_388945a0, Max, HelpAssistant, ASPNET, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Documents and Settings\Max\Application Data\ZHP\
~ %AppData% : C:\Documents and Settings\Max\Application Data\
~ %Desktop% : C:\Documents and Settings\Max\Bureau\
~ %Favorites% : C:\Documents and Settings\Max\Favoris\
~ %LocalAppData% : C:\Documents and Settings\Max\Local Settings\Application Data\
~ %StartMenu% : C:\Documents and Settings\Max\Menu Démarrer\
~ %Windir% : C:\WINDOWS\
~ %System% : C:\WINDOWS\system32\

---\\ Enumération des unités disques
A: Floppy drive, Flash card reader, USB Key (Not Inserted)
C: Hard drive, Flash drive, Thumb drive (Free 42 Go of 78 Go)
D: Hard drive, Flash drive, Thumb drive (Free 7 Go of 155 Go)
E: Floppy drive, Flash card reader, USB Key (Not Inserted)
F: Floppy drive, Flash card reader, USB Key (Not Inserted)
G: Floppy drive, Flash card reader, USB Key (Not Inserted)
H: Floppy drive, Flash card reader, USB Key (Not Inserted)
I: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : Out Of Date
~ Security Center: 38 Scanned in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\Explorer.exe [1037824]
[MD5.897CA9DA6F568E24549719D5676385A1] - (.Microsoft Corporation - Internet Extensions for Win32.) (.29/10/2013 - 08:57:02.) -- C:\WINDOWS\system32\wininet.dll [920064]
[MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Winlogon.exe [512000]
[MD5.1E44BC1E83D8FD2305F8D452DB109CF9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.17/08/2011 - 14:49:54.) -- C:\WINDOWS\system32\Drivers\AFD.sys [138496]
[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\atapi.sys [96512]
[MD5.C885B02847F5D2FD45A24E219ED93B32] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Cdfs.sys [63744]
[MD5.1F4260CC5B42272D71F79E570A27A4FE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Cdrom.sys [62976]
[MD5.31F923EB2170FC172C81ABDA0045D18C] - (.Microsoft Corporation - Pilote de cryptographie FIPS.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Fips.sys [44672]
[MD5.573C7D0A32852B48F3058CFD8026F511] - (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\HDAudBus.sys [144384]
[MD5.A09BDC4ED10E3B2E0EC27BB94AF32516] - (.Microsoft Corporation - Pilote de port i8042.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\i8042prt.sys [54144]
[MD5.083A052659F5310DD8B6A6CB05EDCF8E] - (.Microsoft Corporation - IMAPI Kernel Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Imapi.sys [42112]
[MD5.CC748EA12C6EFFDE940EE98098BF96BB] - (.Microsoft Corporation - IP Network Address Translator.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\IpNat.sys [152832]
[MD5.23C74D75E36E7158768DD63D92789A91] - (.Microsoft Corporation - IPSec Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\IPSec.sys [75264]
[MD5.7D304A5EB4344EBEEAB53A2FE3FFB9F0] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.15/07/2011 - 14:29:31.) -- C:\WINDOWS\system32\Drivers\MRxSmb.sys [456320]
[MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - (.Microsoft Corporation - MBT Transport driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\netBT.sys [162816]
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\ntfs.sys [574976]
[MD5.8FD0BDBEA875D06CCF6C945CA9ABAF75] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Parport.sys [80384]
[MD5.11B4A627BC9614B885C4969BFA5FF8A6] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Rasl2tp.sys [51328]
[MD5.15CABD0F7C00C47C70124907916AF3F1] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.13/04/2008 - 11:32:52.) -- C:\WINDOWS\system32\Drivers\rdpdr.sys [196224]
[MD5.D8EB2A7904DB6C916EB5361878DDCBAE] - (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) (.13/04/2008 - 19:57:36.) -- C:\WINDOWS\system32\Drivers\redbook.sys [58752]
[MD5.46DE1126684369BACE4849E4FC8C43CA] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\volsnap.sys [53376]
~ Generic Processes: Scanned in 00mn 01s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/4904
~ Mes musiques (My Musics) : 0/2023
~ Mes Videos (My Videos) : 0/0
~ Mes Favoris (My Favorites) : 1/31
~ Mes Documents (My Documents) : 0/13256
~ Mon Bureau (My Desktop) : 0/43
~ Menu demarrer (Programs) : 1/26
~ Hidden Files: Scanned in 00mn 07s



---\\ Processus lancés
[MD5.CE8CCE2B9F96ACA02E5DED4298A7796D] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 186.1.) -- C:\WINDOWS\system32\nvsvc32.exe [168004] [PID.1092]
[MD5.FE79366FECD444A16CCA9979134DBEA8] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376] [PID.1828]
[MD5.FDE9C7030FB1E9E2715E113EE6A10F90] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376] [PID.2000]
[MD5.30E3850F303EAE5C364782EA78579CC9] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55624] [PID.120]
[MD5.DB5BEA73EDAF19AC68B2C0FAD0F92B1A] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [390504] [PID.244]
[MD5.934BB0D23A25C8C136570800A5A149B6] - (.Nero AG - NeroUpdate.) -- C:\Program Files\Nero\Update\NASvc.exe [687400] [PID.480]
[MD5.DF4A7E1E2BA788E28747F1EF49692ED6] - (.TeamViewer GmbH - TeamViewer 9.) -- C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe [5341536] [PID.1148]
[MD5.C15285A425CE3A39E1977494F3B5A98D] - (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.exe [16050176] [PID.524]
[MD5.93AD0B78C7357A05F50E594EC7C22300] - (...) -- ystem32\RUNDLL32.exe [0] [PID.1400]
[MD5.F0431C490F124A8CC874163E6A38DD28] - (.Logitech Inc. - LVCom Server.) -- C:\WINDOWS\system32\LVCOMSX.exe [221184] [PID.1480]
[MD5.E558CDE2913DAA077D4E25732D1AA176] - (.Hewlett-Packard Company - hpwuSchd.) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152] [PID.1524]
[MD5.DD231039B13EC2ABDE315D76E658EF0E] - (.Avira Operations GmbH & Co. KG - Antivirus System Tray Tool (Desktop).) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600] [PID.1544]
[MD5.B2387FD351A3D4780A917E4C00A83310] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [152392] [PID.744]
[MD5.F7D68D8E70EA376713A39395664793CA] - (.Pinnacle Systems GmbH - Pinnacle USB Tip - for Multi Media eXtensio.) -- C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe [199752] [PID.1944]
[MD5.C519CEC624CF9BCBA3059F32266C8FFF] - (.Hewlett-Packard Co. - HP Digital Imaging Monitor.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [258048] [PID.2164]
[MD5.6B2B9B46D7DA5C67397412DEA6CF9A14] - (.Hewlett-Packard Co. - Pas de description.) -- C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe [425984] [PID.2540]
[MD5.6F1E9AB820B3DD8BD38C0190A206205D] - (.Avira Operations GmbH & Co. KG - AntiVir shadow copy service.) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe [431672] [PID.3140]
[MD5.C00149A7027081539A66DC5A46695EAD] - (.Apple Inc. - iPodService Module (32-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [553288] [PID.3928]
[MD5.0DAD93BB0FECF5016AE3C06CBB0A873B] - (.Microsoft Corporation - COM Surrogate.) -- C:\WINDOWS\system32\dllhost.exe [5120] [PID.2952]
[MD5.0E3F332A0092E14401D1117126DDACA2] - (.TeamViewer GmbH - TeamViewer 9.) -- C:\Program Files\TeamViewer\Version9\TeamViewer.exe [13543264] [PID.1608]
[MD5.428360DE895B0D80BE90A088C3E10E14] - (.TeamViewer GmbH - TeamViewer 9.) -- C:\Program Files\TeamViewer\Version9\tv_w32.exe [199520] [PID.3328]
[MD5.2602A0B5319AE6EA59B20BED11E3D51E] - (.TeamViewer GmbH - TeamViewer 9.) -- c:\program files\teamviewer\version9\TeamViewer_Desktop.exe [4671328] [PID.2544]
[MD5.1A42F95615006278BC60D88118A1B696] - (.FireStarter - PrtScr.) -- C:\Program Files\PrtScr\PrtScr.exe [1700864] [PID.708]
[MD5.CA25CAEEBDBE25D85565877219F684F8] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [8339968] [PID.3852]
~ Processes Running: Scanned in 00mn 02s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\prefs.js
M0 - MFSP: prefs.js [Max - uqigf7ie.default] http://www.google.fr
M2 - MFEP: prefs.js [Max - uqigf7ie.default\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}] [WOT] WOT v20131118 (..)
M2 - MFEP: prefs.js [Max - uqigf7ie.default\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}] [dwhelper] DownloadHelper v4.9.21 (..)
M2 - MFEP: prefs.js [Max - uqigf7ie.default\{C8F7F1EC-D409-D37F-2671-B3418528A740}] [] New tab v5.0.0.10781 (..)
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
P2 - FPN: [HKLM] [@Nero.com/KM] - (.Nero AG - Plug-in for detecting Nero Kwik Media..) -- C:\Program Files\Fichiers communs\Nero\BrowserPlugin\npBrowserPlugin.dll
P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.0.6] - (.VideoLAN - VLC media player Web Plugin 2.0.6.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll =>.VideoLAN
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.06.) -- C:\Reader\AIR\nppdf32.dll
~ Firefox Browser: 10 Scanned in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.fr
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.06.) (No version) -- (.not file.)
~ IE Browser: 14 Scanned in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\WINDOWS\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 20



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{01E04581-4EEE-11D0-BFE9-00AA005B4383} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{0E5CBF21-D15F-11D0-8301-00AA005B4383} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - GS\Program [AllUsers]: Démarrage rapide du logiciel HP Image Zone.lnk . (.Hewlett-Packard Co. - HP Image Zone.) -- C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - GS\Program [AllUsers]: HP Digital Imaging Monitor.lnk . (.Hewlett-Packard Co. - HP Digital Imaging Monitor.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe =>.Hewlett-Packard Co
O4 - HKLM\..\Run: [RTHDCPL] . (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.exe =>.Realtek Semiconductor Corp
O4 - HKLM\..\Run: [SkyTel] . (.Realtek Semiconductor Corp. - Realtek Voice Manager.) -- C:\WINDOWS\SkyTel.exe =>.Realtek Semiconductor Corp
O4 - HKLM\..\Run: [Alcmtr] . (.Realtek Semiconductor Corp. - Realtek Azalia Audio - Event Monitor.) -- C:\WINDOWS\ALCMTR.exe
O4 - HKLM\..\Run: [nwiz] . (...) -- C:\WINDOWS\system32\nwiz.exe
O4 - HKLM\..\Run: [NvMediaCenter] . (.NVIDIA Corporation - NVIDIA Media Center Library.) -- C:\WINDOWS\system32\NvMcTray.dll
O4 - HKLM\..\Run: [NvCplDaemon] . (.NVIDIA Corporation - NVIDIA Display Properties Extension.) -- C:\WINDOWS\system32\NvCpl.dll =>.NVIDIA Corporation
O4 - HKLM\..\Run: [LVCOMSX] . (.Logitech Inc. - LVCom Server.) -- C:\WINDOWS\system32\LVCOMSX.exe
O4 - HKLM\..\Run: [HP Software Update] . (.Hewlett-Packard Company - hpwuSchd.) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe =>.Hewlett-Packard Co
O4 - HKLM\..\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Antivirus System Tray Tool (Desktop).) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Fichiers communs\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [NBAgent] . (.Nero AG - Nero BackItUp.) -- C:\Program Files\Nero\Nero 11\Nero BackItUp\NBAgent.exe
O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [USBToolTip] . (.Pinnacle Systems GmbH - Pinnacle USB Tip - for Multi Media eXtensio.) -- C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKCU\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-21-527237240-573735546-1644491937-1004\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
~ Application: Scanned in 00mn 01s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -- Clé orpheline
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000004\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll
~ Winsock: 4 Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{17DE7637-887C-4989-86E7-63C66B39EB3A}: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{17DE7637-887C-4989-86E7-63C66B39EB3A}: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{17DE7637-887C-4989-86E7-63C66B39EB3A}: DhcpNameServer = 192.168.0.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINDOWS\system32\wiascr.dll
O18 - Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\WINDOWS\system32\crypt32.dll
O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\WINDOWS\system32\cryptnet.dll
O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\WINDOWS\system32\cscdll.dll
O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\system32\dimsntfy.dll
O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\WINDOWS\system32\sclgntfy.dll
O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\WlNotify.dll
O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll
~ Winlogon: Scanned in 00mn 00s



---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\system32\stobject.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll
~ SSODL: 5 Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Avira Planificateur (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Protection temps réel (AntiVirService) . (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Nero Update (NAUpdate) . (.Nero AG - NeroUpdate.) - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 186.1.) - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 (Pml Driver HPZ12) . (.HP - PML Driver.) - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: TeamViewer 9 (TeamViewer9) . (.TeamViewer GmbH - TeamViewer 9.) - C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: (vToolbarUpdater15.3.0) . (...) - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe (.not file.) =>Toolbar.AVGSearch
~ Services: 9 Scanned in 00mn 06s



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
O24 - Desktop General: WallPaper - .(...) - D:\Mes Documents\FOND ECRAN\PrtScr capture.png
~ Desktop Component: 4 Scanned in 00mn 00s



---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AppleSoftwareUpdate.job [284]
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\HPpromotions journeysoftware.job [362]
~ Scheduled Task: 3 Scanned in 00mn 00s



---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Mise à jour de la version d’Internet Explorer - <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} . (.Microsoft Corporation - IE Per User Active Setup Uninstall Utility.) -- C:\WINDOWS\system32\ieudinit.exe
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Utilitaire d'installation du Lecteur Windows Media de Microsoft.) -- C:\WINDOWS\inf\unregmp2.exe =>.Microsoft Corporation
O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitaire d’initialisation d’Internet Explorer par utilisateur.) -- C:\WINDOWS\system32\ie4uinit.exe.mui
O40 - ASIC: Browser Customizations - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - IEAK branding.) -- C:\WINDOWS\system32\iedkcs32.dll
O40 - ASIC: Outlook Express - >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} . (.Microsoft Corporation - Windows NT User Data Migration Tool.) -- C:\WINDOWS\system32\shmgrate.exe =>.Microsoft Corporation
O40 - ASIC: Microsoft NetShow Player - {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\WINDOWS\system32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player 6.4 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\WINDOWS\system32\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\WINDOWS\system32\themeui.dll
O40 - ASIC: Microsoft Outlook Express 6 - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Bibliothèque d'installation Outlook Express.) -- C:\Program Files\Outlook Express\setup50.exe =>.Microsoft Corporation
O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (...) -- C:\WINDOWS\INF\msnetmtg.inf
O40 - ASIC: Windows Messenger 4.7 - {5945c046-1e7d-11d1-bc44-00c04fd912be} . (...) -- C:\WINDOWS\INF\msmsgs.inf
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\WINDOWS\system32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (...) -- C:\WINDOWS\INF\wmp11.inf =>.Microsoft Corporation
O40 - ASIC: Carnet d'adresses 6 - {7790769C-0471-11d2-AF11-00C04FA35D02} . (.Microsoft Corporation - Bibliothèque d'installation Outlook Express.) -- C:\Program Files\Outlook Express\setup50.exe =>.Microsoft Corporation
O40 - ASIC: Mise à jour du Bureau Windows - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll
O40 - ASIC: Internet Explorer - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d’initialisation d’Internet Explorer par utilisateur.) -- C:\WINDOWS\system32\ie4uinit.exe.mui
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- c:\WINDOWS\system32\mscories.dll
O40 - ASIC: Macromedia Shockwave Flash - {D27CDB6E-AE6D-11cf-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 11.7 r700.) -- C:\WINDOWS\system32\Macromed\Flash\Flash32_11_7_700_224.ocx
O40 - ASIC: Installed Component - S-1-5-21-527237240-573735546-1644491937-1004 - <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} -- Not Hexadécimal CLSID
O40 - ASIC: Installed Component - S-1-5-21-527237240-573735546-1644491937-1004 - >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS -- Not Hexadécimal CLSID
~ Active Setup: 20 Scanned in 00mn 00s



---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys
O41 - Driver: (avgtp) . (.AVG Technologies - Pas de description.) - C:\WINDOWS\system32\drivers\avgtpx86.sys
O41 - Driver: (avipbb) . (.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) - C:\WINDOWS\system32\DRIVERS\avipbb.sys
O41 - Driver: (avkmgr) . (.Avira Operations GmbH & Co. KG - Avira Manager Driver.) - C:\WINDOWS\system32\DRIVERS\avkmgr.sys
O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\WINDOWS\system32\DRIVERS\cdrom.sys
O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\WINDOWS\system32\DRIVERS\i8042prt.sys
O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\WINDOWS\system32\DRIVERS\imapi.sys
O41 - Driver: (intelppm) . (.Microsoft Corporation - Pilote de périphérique processeur.) - C:\WINDOWS\system32\DRIVERS\intelppm.sys
O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\WINDOWS\system32\DRIVERS\ipsec.sys
O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\WINDOWS\system32\DRIVERS\kbdclass.sys
O41 - Driver: (kbdhid) . (.Microsoft Corporation - Pilote de filtre souris HID.) - C:\WINDOWS\system32\DRIVERS\kbdhid.sys
O41 - Driver: (Mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\WINDOWS\system32\DRIVERS\mouclass.sys
O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\WINDOWS\system32\DRIVERS\netbios.sys
O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\WINDOWS\system32\DRIVERS\netbt.sys
O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\WINDOWS\system32\DRIVERS\rasacd.sys
O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\WINDOWS\system32\DRIVERS\rdbss.sys
O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
O41 - Driver: (redbook) . (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) - C:\WINDOWS\system32\DRIVERS\redbook.sys
O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\WINDOWS\system32\DRIVERS\serial.sys
O41 - Driver: (ssmdrv) . (.Avira GmbH - AVIRA SnapShot Driver.) - C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\WINDOWS\system32\DRIVERS\tcpip.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\WINDOWS\system32\DRIVERS\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys
~ Drivers: 72 Scanned in 00mn 00s



---\\ Logiciels installés (O42)
O42 - Logiciel: Adobe Flash Player 11 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
O42 - Logiciel: Adobe Reader XI (11.0.06) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AB0000000001}
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {46F044A5-CE8B-4196-984E-5BD6525E361D}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {0592EF96-69D8-4E4B-9CC9-88F58EA86F01}
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE} =>.Apple Inc
O42 - Logiciel: Avira Free Antivirus v14.0.2.286 - (.Avira.) [HKLM] -- Avira AntiVir Desktop
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {79155F2B-9895-49D7-8612-D92580E0DE5B}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner =>Piriform Ltd
O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKCU] -- Dropbox
O42 - Logiciel: Efficient WMA MP3 Converter version 0.99.9.1 - (...) [HKLM] -- Efficient WMA MP3 Converter_is1
O42 - Logiciel: HFX Volume 1 - (.Pinnacle Systems.) [HKLM] -- {468B359F-BAEF-466F-BB82-5EDEA1D8B2FB}
O42 - Logiciel: HFX Volume 2 - (.Pinnacle Systems.) [HKLM] -- {37F79692-6F8A-487E-BF5A-A1E3227D9830}
O42 - Logiciel: HP Extended Capabilities 4.7 - (.HP.) [HKLM] -- HPExtendedCapabilities
O42 - Logiciel: HP Image Zone 4.7 - (.HP.) [HKLM] -- HP Photo & Imaging
O42 - Logiciel: HP PSC & OfficeJet 4.7 - (.HP.) [HKLM] -- {342C7C88-D335-4bc2-8CF1-281857629CE2}
O42 - Logiciel: HP Software Update - (.Hewlett-Packard.) [HKLM] -- {64FC0C98-B035-4530-B15D-3D30610B6DF1} =>.Hewlett-Packard Co
O42 - Logiciel: High-Definition Video Playback - (.Nero AG.) [HKLM] -- {9193490D-5229-4FC4-9BB9-A6D63C09574A}
O42 - Logiciel: Hotfix for Windows Media Format 11 SDK (KB929399) - (.Microsoft Corporation.) [HKLM] -- KB929399
O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5
O42 - Logiciel: Hotfix for Windows XP (KB976002-v5) - (.Microsoft Corporation.) [HKLM] -- KB976002-v5
O42 - Logiciel: ImageScanTool V2.0.2 - (.Nom de votre société.) [HKLM] -- {F0ACDDA3-1DC3-43C0-84E6-43E927C3E2F7}
O42 - Logiciel: K-Lite Codec Pack 5.6.1 (Full) - (...) [HKLM] -- KLiteCodecPack_is1
O42 - Logiciel: Lecteur Windows Media 11 - (...) [HKLM] -- Windows Media Player =>.Microsoft Corporation
O42 - Logiciel: MSN - (.Microsoft Corporation.) [HKLM] -- MSNINST
O42 - Logiciel: Malwarebytes Anti-Malware version 1.75.0.1300 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
O42 - Logiciel: Micro Application - Super Kit CD-DVD 3 - (...) [HKLM] -- {5CE925BD-83DA-4E34-A833-ACB340867791}
O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM] -- MSCompPackV1
O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- Wudf01000
O42 - Logiciel: Mozilla Firefox 26.0 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 26.0 (x86 fr)
O42 - Logiciel: NVIDIA Drivers - (.NVIDIA Corporation.) [HKLM] -- NVIDIA Drivers
O42 - Logiciel: Nero 11 Cliparts - (.Nero AG.) [HKLM] -- {B160A672-F326-4414-9BB0-A056C61B357C}
O42 - Logiciel: Nero 11 Disc Menus 1 - (.Nero AG.) [HKLM] -- {A0F34849-D9AB-46DD-B1BE-BB0DB60B1FE8}
O42 - Logiciel: Nero 11 Disc Menus 2 - (.Nero AG.) [HKLM] -- {7DF2B5EE-2C16-4E86-9C71-8678068AD805}
O42 - Logiciel: Nero 11 Disc Menus 3 - (.Nero AG.) [HKLM] -- {5E98FDD6-3672-4DBE-AB8B-2C9A0BED1382}
O42 - Logiciel: Nero 11 Disc Menus Basic - (.Nero AG.) [HKLM] -- {F49EF443-B2BD-4F10-8A46-87AFCDB90EDD}
O42 - Logiciel: Nero 11 Effects Basic - (.Nero AG.) [HKLM] -- {E51BC4B0-EA5E-49CC-AF3B-93B5C627EC22}
O42 - Logiciel: Nero 11 Image Samples - (.Nero AG.) [HKLM] -- {F3743A2C-5D5F-4456-8F98-5DF36A954C50}
O42 - Logiciel: Nero 11 Kwik Themes 1 - (.Nero AG.) [HKLM] -- {B1F69AF3-B5B5-4CA5-ADC5-8A738EB6E574}
O42 - Logiciel: Nero 11 Kwik Themes 2 - (.Nero AG.) [HKLM] -- {A4F6BE36-4826-45BA-A396-04F265A3B61D}
O42 - Logiciel: Nero 11 Kwik Themes 3 - (.Nero AG.) [HKLM] -- {BA499CC0-12C0-4BA5-9007-76844B721158}
O42 - Logiciel: Nero 11 Kwik Themes 4 - (.Nero AG.) [HKLM] -- {ACD6B383-EC5B-4000-A455-CCB308B447FE}
O42 - Logiciel: Nero 11 Kwik Themes Basic - (.Nero AG.) [HKLM] -- {5A212B2D-140D-46F4-B625-2D1CA5A00594}
O42 - Logiciel: Nero 11 PiP Effects 1 - (.Nero AG.) [HKLM] -- {3B418709-D688-4E3A-BE0E-7D71FA84C948}
O42 - Logiciel: Nero 11 PiP Effects Basic - (.Nero AG.) [HKLM] -- {2CA7225D-CB12-462A-9DD1-50319E158BA5}
O42 - Logiciel: Nero 11 Platinum - (.Nero AG.) [HKLM] -- {79B3E8EE-35F2-4CCD-82D9-4A57F408E449}
O42 - Logiciel: Nero 11 Video Samples - (.Nero AG.) [HKLM] -- {A2CDC001-F8B3-4C64-9E74-2E3FA0FAC9D9}
O42 - Logiciel: Nero 11 Video Transitions 1 - (.Nero AG.) [HKLM] -- {4382FC76-8100-4951-8658-31834E625E88}
O42 - Logiciel: Nero Audio Pack 1 - (.Nero AG.) [HKLM] -- {A7A0BF2E-31CC-49E3-9913-52C503EB969D}
O42 - Logiciel: Nero BackItUp 11 - (.Nero AG.) [HKLM] -- {AB2BBC64-8AC8-4E66-BBF3-E22D5EACEECA}
O42 - Logiciel: Nero BackItUp 11 Help (CHM) - (.Nero AG.) [HKLM] -- {6AB2427E-A18F-4809-9A12-29F5EBABBB3A}
O42 - Logiciel: Nero Backup Drivers - (.Nero AG.) [HKLM] -- {F8EF9B71-53E7-41F5-8E54-47B4C979CB38}
O42 - Logiciel: Nero Burning ROM 11 - (.Nero AG.) [HKLM] -- {B1846721-A8E6-46C7-83B6-0DCF7ADB4267}
O42 - Logiciel: Nero Burning ROM 11 Help (CHM) - (.Nero AG.) [HKLM] -- {53F7746A-96AA-49A5-86B8-59989680DAC5}
O42 - Logiciel: Nero ControlCenter 11 - (.Nero AG.) [HKLM] -- {11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}
O42 - Logiciel: Nero ControlCenter 11 Help (CHM) - (.Nero AG.) [HKLM] -- {D4D66270-9147-4BDF-9946-FCA2B303AA8F}
O42 - Logiciel: Nero Core Components 11 - (.Nero AG.) [HKLM] -- {BEBEE34D-84A2-4EDD-8BEA-96CC54371263}
O42 - Logiciel: Nero CoverDesigner 11 - (.Nero AG.) [HKLM] -- {FF44BCE5-5A18-4051-85F0-BC172D7B4695}
O42 - Logiciel: Nero CoverDesigner 11 Help (CHM) - (.Nero AG.) [HKLM] -- {55C2143E-FBA5-442F-9AFA-726FF068F39D}
O42 - Logiciel: Nero Express 11 - (.Nero AG.) [HKLM] -- {E10AAE4A-98B8-420A-BD93-E0520C23D624}
O42 - Logiciel: Nero Express 11 Help (CHM) - (.Nero AG.) [HKLM] -- {D2CBEFA4-F2D3-4E97-A171-8BFD6A31A5EC}
O42 - Logiciel: Nero Kwik Media - (.Nero AG.) [HKLM] -- {BE814218-3919-4EA3-868A-2F60BC135CB4}
O42 - Logiciel: Nero Kwik Media Help (CHM) - (.Nero AG.) [HKLM] -- {B9B1BA7F-7E07-49DD-A713-5B397A5BB66B}
O42 - Logiciel: Nero Recode 11 - (.Nero AG.) [HKLM] -- {0320AB41-0926-4218-A8A6-68AC84E6BB93}
O42 - Logiciel: Nero Recode 11 Help (CHM) - (.Nero AG.) [HKLM] -- {57F80ECF-E27C-4EEE-AB58-E971BACE2639}
O42 - Logiciel: Nero RescueAgent 11 - (.Nero AG.) [HKLM] -- {034DCAF9-96E7-4936-9A07-712F80B5181E}
O42 - Logiciel: Nero RescueAgent 11 Help (CHM) - (.Nero AG.) [HKLM] -- {D01CE99A-8802-483C-A79F-298B691EB432}
O42 - Logiciel: Nero SharedVideoCodecs - (.Nero AG.) [HKLM] -- {2432E589-6256-4513-B0BF-EFA8E325D5F0}
O42 - Logiciel: Nero SoundTrax 11 - (.Nero AG.) [HKLM] -- {0713D1F9-DD77-42C1-8C7D-54D479E2E743}
O42 - Logiciel: Nero SoundTrax 11 Help (CHM) - (.Nero AG.) [HKLM] -- {390757AA-8830-43DC-AEE0-4E5B6F8439EB}
O42 - Logiciel: Nero Update - (.Nero AG.) [HKLM] -- {65BB0407-4CC8-4DC7-952E-3EEFDF05602A}
O42 - Logiciel: Nero Video 11 - (.Nero AG.) [HKLM] -- {0D7A4289-99CF-4B8D-B812-86BE50A54552}
O42 - Logiciel: Nero Video 11 Help (CHM) - (.Nero AG.) [HKLM] -- {FAC3C37E-EDAB-4F3A-A173-A7C70CC88F09}
O42 - Logiciel: Nero WaveEditor 11 - (.Nero AG.) [HKLM] -- {8014FACB-1D1D-48C2-94AA-E29EE2E6B9CE}
O42 - Logiciel: Nero WaveEditor 11 Help (CHM) - (.Nero AG.) [HKLM] -- {EB8DED20-A887-4A9C-BB5A-F3E7523DFB44}
O42 - Logiciel: Pilote vidéo Pinnacle - (.Pinnacle Systems.) [HKLM] -- {6DE721A5-5E89-4D74-994C-652BB3C0672E}
O42 - Logiciel: Pinnacle Studio 14 - (.Pinnacle Systems.) [HKLM] -- {AADD1C8F-D59F-4D55-A726-768C71A205A8}
O42 - Logiciel: Pinnacle Studio Ultimate Collection Plugins - (.Pinnacle Systems.) [HKLM] -- {F5C372A1-40F3-49DA-A049-F75CDE9177DC}
O42 - Logiciel: Programme de gestion Camera de Logitech® - (...) [HKLM] -- QcDrv
O42 - Logiciel: PrtScr 1.5 - (.FireStarter.) [HKLM] -- PrtScr_is1
O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {B67BAFBA-4C9F-48FA-9496-933E3B255044}
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: Skype™ 6.9 - (.Skype Technologies S.A..) [HKLM] -- {4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}
O42 - Logiciel: TeamViewer 9 - (.TeamViewer.) [HKLM] -- TeamViewer 9
O42 - Logiciel: VLC media player 2.0.6 - (.VideoLAN.) [HKLM] -- VLC media player =>.VideoLAN
O42 - Logiciel: Visionneuse Microsoft PowerPoint - (.Microsoft Corporation.) [HKLM] -- {95140000-00AF-040C-0000-0000000FF1CE}
O42 - Logiciel: Welcome App (Start-up experience) - (.Nero AG.) [HKLM] -- {51865D9D-8F63-46F2-87AB-9E72F93B618C}
O42 - Logiciel: Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray - (.Microsoft Corporation.) [HKLM] -- KB952011
O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM] -- ie8
O42 - Logiciel: Windows Media Format 11 runtime - (...) [HKLM] -- Windows Media Format Runtime
O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11
O42 - Logiciel: Windows Media Player 11 - (.Microsoft Corporation.) [HKLM] -- wmp11 =>.Microsoft Corporation
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {DF9C119C-7F26-45B9-93D4-7C372CBBBA11}
~ Logic: 59 Scanned in 00mn 00s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\ASUS]
[HKCU\Software\Adobe]
[HKCU\Software\Ahead]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Avira]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Cyberlink]
[HKCU\Software\DivXNetworks]
[HKCU\Software\ESET]
[HKCU\Software\EffectMgr]
[HKCU\Software\Free Video Converter]
[HKCU\Software\GNU]
[HKCU\Software\Gabest]
[HKCU\Software\Google]
[HKCU\Software\Haali]
[HKCU\Software\Hewlett-Packard]
[HKCU\Software\IM Providers]
[HKCU\Software\Intel]
[HKCU\Software\Iris]
[HKCU\Software\Local AppWizard-Generated Applications]
[HKCU\Software\Logitech]
[HKCU\Software\MONOGRAM]
[HKCU\Software\Macromedia]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MediaInfo]
[HKCU\Software\Micro Application]
[HKCU\Software\MicroVision]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\NVIDIA Corporation]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\ORL]
[HKCU\Software\Pinnacle Systems]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\PrtScr]
[HKCU\Software\Realtek]
[HKCU\Software\Red Giant Software]
[HKCU\Software\Skype]
[HKCU\Software\Software]
[HKCU\Software\TeamViewer]
[HKCU\Software\TeleCharger]
[HKCU\Software\VOB]
[HKCU\Software\WMA-MP3-Converter.org]
[HKCU\Software\madFlac]
[HKCU\Software\nuevos-programas.com]
[HKLM\Software\ASUS]
[HKLM\Software\Adobe]
[HKLM\Software\AdwCleaner]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\Avira]
[HKLM\Software\C07ft5Y]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Codec Tweak Tool]
[HKLM\Software\Cyberlink]
[HKLM\Software\Datamngr] =>PUP.Datamngr
[HKLM\Software\DivXNetworks]
[HKLM\Software\DivX]
[HKLM\Software\Dropbox]
[HKLM\Software\Eset]
[HKLM\Software\FAST Multimedia]
[HKLM\Software\GEAR Software]
[HKLM\Software\GNU]
[HKLM\Software\Gabest]
[HKLM\Software\Gemplus]
[HKLM\Software\Google]
[HKLM\Software\HP]
[HKLM\Software\HaaliMkx]
[HKLM\Software\Hewlett-Packard]
[HKLM\Software\ICE]
[HKLM\Software\IM Providers]
[HKLM\Software\InstallShield]
[HKLM\Software\Intel]
[HKLM\Software\InterVideo]
[HKLM\Software\KLCodecPack]
[HKLM\Software\LEAD Technologies, Inc.]
[HKLM\Software\LibreOffice]
[HKLM\Software\Licenses]
[HKLM\Software\Logitech]
[HKLM\Software\Macromedia]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\Micro Application]
[HKLM\Software\MicroVision]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\NVIDIA Corporation]
[HKLM\Software\Nero]
[HKLM\Software\ODBC]
[HKLM\Software\Pegasus Imaging]
[HKLM\Software\PegasusImaging]
[HKLM\Software\Pinnacle Systems]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Program Groups]
[HKLM\Software\RTLSetup]
[HKLM\Software\Realtek Semiconductor Corp.]
[HKLM\Software\Realtek]
[HKLM\Software\Red Giant Software]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Schlumberger]
[HKLM\Software\Secure]
[HKLM\Software\Skype]
[HKLM\Software\Software]
[HKLM\Software\Sonix]
[HKLM\Software\TeamViewer]
[HKLM\Software\The Document Foundation]
[HKLM\Software\VideoLAN]
[HKLM\Software\Windows 3.1 Migration Status]
[HKLM\Software\Wow6432Node]
[HKLM\Software\X-AVCSD]
[HKLM\Software\mozilla.org]
[HKLM\Software\proDAD]
~ Key Software: 272 Scanned in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 05/01/2014 - 06:22:37 - [1,805] ----D C:\Program Files\35mm Film Scanner
O43 - CFD: 04/04/2013 - 11:14:22 - [2,316] ----D C:\Program Files\Apple Software Update =>.Apple Inc
O43 - CFD: 29/03/2013 - 12:28:24 - [271,749] ----D C:\Program Files\Avira
O43 - CFD: 04/04/2013 - 11:13:38 - [0,602] ----D C:\Program Files\Bonjour
O43 - CFD: 01/07/2013 - 16:16:04 - [5,594] ----D C:\Program Files\CCleaner =>Piriform Ltd
O43 - CFD: 29/03/2013 - 09:57:42 - [0] ----D C:\Program Files\ComPlus Applications
O43 - CFD: 05/06/2013 - 17:47:35 - [64,588] ----D C:\Program Files\Dropbox
O43 - CFD: 05/06/2013 - 18:09:18 - [26,889] ----D C:\Program Files\Efficient WMA MP3 Converter
O43 - CFD: 08/11/2013 - 10:13:16 - [0,117] ----D C:\Program Files\ESET
O43 - CFD: 29/09/2013 - 13:31:39 - [335,218] ----D C:\Program Files\Fichiers communs
O43 - CFD: 02/02/2014 - 10:10:02 - [1,917] ----D C:\Program Files\Free Video Converter
O43 - CFD: 29/10/2013 - 06:52:23 - [62,663] ----D C:\Program Files\Google
O43 - CFD: 29/03/2013 - 11:53:51 - [3,949] ----D C:\Program Files\Hewlett-Packard
O43 - CFD: 29/03/2013 - 11:56:05 - [281,381] ----D C:\Program Files\HP
O43 - CFD: 08/10/2013 - 09:48:07 - [7,148] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 12/12/2013 - 17:17:07 - [5,328] ----D C:\Program Files\Internet Explorer
O43 - CFD: 23/09/2013 - 21:51:15 - [1,884] ----D C:\Program Files\iPod
O43 - CFD: 23/09/2013 - 21:51:41 - [176,741] ----D C:\Program Files\iTunes
O43 - CFD: 05/06/2013 - 18:11:30 - [45,417] ----D C:\Program Files\K-Lite Codec Pack
O43 - CFD: 08/11/2013 - 12:20:27 - [331,711] ----D C:\Program Files\LibreOffice 4
O43 - CFD: 12/08/2013 - 12:13:27 - [9,617] ----D C:\Program Files\LooksBuilderSE
O43 - CFD: 06/01/2014 - 10:30:17 - [13,251] ----D C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 29/03/2013 - 12:43:00 - [2,073] ----D C:\Program Files\Messenger
O43 - CFD: 06/08/2013 - 10:00:49 - [406,870] ----D C:\Program Files\Micro Application
O43 - CFD: 29/03/2013 - 10:00:20 - [0] ----D C:\Program Files\microsoft frontpage
O43 - CFD: 26/06/2013 - 10:59:34 - [32,621] ----D C:\Program Files\Microsoft Office
O43 - CFD: 25/06/2013 - 04:30:11 - [0,015] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 29/03/2013 - 12:32:07 - [9,894] ----D C:\Program Files\Movie Maker
O43 - CFD: 23/12/2013 - 13:56:19 - [51,049] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 06/06/2013 - 09:28:48 - [0,025] ----D C:\Program Files\MSBuild
O43 - CFD: 26/06/2013 - 10:59:01 - [63,464] ----D C:\Program Files\MSECache
O43 - CFD: 28/08/2013 - 18:43:39 - [20,784] ----D C:\Program Files\MSN
O43 - CFD: 29/03/2013 - 09:57:03 - [8,341] ----D C:\Program Files\MSN Gaming Zone
O43 - CFD: 04/07/2013 - 12:53:39 - [-1745,273] ----D C:\Program Files\Nero
O43 - CFD: 29/03/2013 - 09:58:37 - [3,133] ----D C:\Program Files\NetMeeting
O43 - CFD: 29/03/2013 - 09:57:11 - [0,002] ----D C:\Program Files\Online Services
O43 - CFD: 29/03/2013 - 12:32:30 - [4,176] ----D C:\Program Files\Outlook Express =>.Microsoft Corporation
O43 - CFD: 29/09/2013 - 13:42:20 - [1282,695] ----D C:\Program Files\Pinnacle
O43 - CFD: 04/08/2013 - 09:42:20 - [0] ----D C:\Program Files\proDAD
O43 - CFD: 08/11/2013 - 05:39:25 - [13,301] ----D C:\Program Files\PrtScr
O43 - CFD: 12/06/2013 - 16:37:16 - [73,545] ----D C:\Program Files\QuickTime
O43 - CFD: 08/10/2013 - 09:48:06 - [44,990] ----D C:\Program Files\Realtek
O43 - CFD: 06/06/2013 - 09:28:41 - [34,730] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 29/03/2013 - 09:59:03 - [0,001] ----D C:\Program Files\Services en ligne
O43 - CFD: 28/10/2013 - 11:27:43 - [19,821] R---D C:\Program Files\Skype
O43 - CFD: 06/01/2014 - 12:00:20 - [28,109] ----D C:\Program Files\TeamViewer
O43 - CFD: 29/03/2013 - 10:05:15 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 01/07/2013 - 16:15:56 - [0,046] ----D C:\Program Files\Uninstaller
O43 - CFD: 29/03/2013 - 10:12:31 - [0,269] ----D C:\Program Files\VIA
O43 - CFD: 15/07/2013 - 11:06:19 - [102,898] ----D C:\Program Files\VideoLAN
O43 - CFD: 01/07/2013 - 16:15:42 - [3,415] ----D C:\Program Files\Windows Media Connect 2
O43 - CFD: 01/07/2013 - 16:15:42 - [7,895] ----D C:\Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 29/03/2013 - 09:56:55 - [3,760] ----D C:\Program Files\Windows NT
O43 - CFD: 29/03/2013 - 09:59:06 - [0] --H-D C:\Program Files\WindowsUpdate
O43 - CFD: 29/03/2013 - 10:00:20 - [0] ----D C:\Program Files\xerox
O43 - CFD: 03/02/2014 - 12:50:57 - [17,261] ----D C:\Program Files\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 28/06/2013 - 15:53:48 - [6,311] ----D C:\Program Files\Fichiers communs\Adobe
O43 - CFD: 23/09/2013 - 21:51:14 - [104,602] ----D C:\Program Files\Fichiers communs\Apple
O43 - CFD: 29/03/2013 - 11:53:09 - [0,271] ----D C:\Program Files\Fichiers communs\Hewlett-Packard
O43 - CFD: 29/03/2013 - 11:55:17 - [3,743] ----D C:\Program Files\Fichiers communs\HP
O43 - CFD: 29/03/2013 - 11:06:33 - [4,669] ----D C:\Program Files\Fichiers communs\InstallShield
O43 - CFD: 29/03/2013 - 11:14:12 - [20,549] ----D C:\Program Files\Fichiers communs\Logitech
O43 - CFD: 26/06/2013 - 10:59:33 - [116,015] ----D C:\Program Files\Fichiers communs\Microsoft Shared
O43 - CFD: 29/03/2013 - 09:58:33 - [0,271] ----D C:\Program Files\Fichiers communs\MSSoap
O43 - CFD: 04/07/2013 - 12:48:39 - [62,148] ----D C:\Program Files\Fichiers communs\Nero
O43 - CFD: 29/03/2013 - 10:49:54 - [0] ----D C:\Program Files\Fichiers communs\ODBC
O43 - CFD: 29/09/2013 - 13:31:39 - [0,383] ----D C:\Program Files\Fichiers communs\Pegasus Imaging
O43 - CFD: 04/07/2013 - 15:51:31 - [3,696] ----D C:\Program Files\Fichiers communs\Pinnacle
O43 - CFD: 29/03/2013 - 09:58:36 - [0,008] ----D C:\Program Files\Fichiers communs\Services
O43 - CFD: 01/07/2013 - 16:14:38 - [1,904] ----D C:\Program Files\Fichiers communs\Skype
O43 - CFD: 29/03/2013 - 10:49:50 - [3,612] ----D C:\Program Files\Fichiers communs\SpeechEngines
O43 - CFD: 05/08/2013 - 10:01:15 - [0,238] ----D C:\Program Files\Fichiers communs\SureThing Shared
O43 - CFD: 29/03/2013 - 09:58:01 - [6,496] ----D C:\Program Files\Fichiers communs\System
O43 - CFD: 29/09/2013 - 13:31:39 - [0,302] ----D C:\Program Files\Fichiers communs\Yahoo!
O43 - CFD: 07/11/2013 - 09:32:49 - [2,442] ----D C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
O43 - CFD: 07/11/2013 - 09:32:49 - [0,004] ----D C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1(2)
O43 - CFD: 12/06/2013 - 19:05:58 - [146,880] ----D C:\Documents and Settings\All Users\Application Data\Adobe
O43 - CFD: 04/04/2013 - 11:14:19 - [115,878] ----D C:\Documents and Settings\All Users\Application Data\Apple
O43 - CFD: 04/04/2013 - 11:14:41 - [91,063] ----D C:\Documents and Settings\All Users\Application Data\Apple Computer
O43 - CFD: 29/03/2013 - 12:28:24 - [192,731] ----D C:\Documents and Settings\All Users\Application Data\Avira
O43 - CFD: 04/04/2013 - 10:50:05 - [0] --H-D C:\Documents and Settings\All Users\Application Data\Common Files
O43 - CFD: 29/03/2013 - 11:56:05 - [0,003] ----D C:\Documents and Settings\All Users\Application Data\HP
O43 - CFD: 06/01/2014 - 10:30:15 - [6,731] ----D C:\Documents and Settings\All Users\Application Data\Malwarebytes
O43 - CFD: 11/01/2014 - 19:06:58 - [1,568] -S--D C:\Documents and Settings\All Users\Application Data\Microsoft
O43 - CFD: 29/03/2013 - 12:59:04 - [0,001] ----D C:\Documents and Settings\All Users\Application Data\Mozilla
O43 - CFD: 04/07/2013 - 12:57:10 - [6,706] ----D C:\Documents and Settings\All Users\Application Data\Nero
O43 - CFD: 29/09/2013 - 13:31:38 - [0,685] ----D C:\Documents and Settings\All Users\Application Data\Pinnacle
O43 - CFD: 29/09/2013 - 13:31:38 - [0] ----D C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Plus
O43 - CFD: 04/07/2013 - 16:54:10 - [0,160] ----D C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Ultimate Collection
O43 - CFD: 28/10/2013 - 11:27:47 - [32,313] ----D C:\Documents and Settings\All Users\Application Data\Skype
O43 - CFD: 29/09/2013 - 13:31:38 - [-640,797] ----D C:\Documents and Settings\All Users\Application Data\Studio 14
O43 - CFD: 25/06/2013 - 10:46:00 - [0] ----D C:\Documents and Settings\All Users\Application Data\TEMP
O43 - CFD: 29/01/2014 - 22:35:34 - [0] ----D C:\Documents and Settings\All Users\Application Data\Wincert
O43 - CFD: 27/06/2013 - 16:38:02 - [0,011] ----D C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
O43 - CFD: 10/06/2013 - 15:51:47 - [0,977] ----D C:\Documents and Settings\Max\Application Data\Adobe
O43 - CFD: 24/06/2013 - 04:28:19 - [1173,505] ----D C:\Documents and Settings\Max\Application Data\Apple Computer
O43 - CFD: 29/03/2013 - 12:34:12 - [0] ----D C:\Documents and Settings\Max\Application Data\Avira
O43 - CFD: 18/11/2013 - 15:23:21 - [68,523] ----D C:\Documents and Settings\Max\Application Data\Dropbox
O43 - CFD: 22/08/2013 - 16:05:57 - [0] ----D C:\Documents and Settings\Max\Application Data\dvdcss
O43 - CFD: 16/01/2014 - 15:16:22 - [0,002] ----D C:\Documents and Settings\Max\Application Data\FreeVideoConverter
O43 - CFD: 29/03/2013 - 10:05:17 - [0] ----D C:\Documents and Settings\Max\Application Data\Identities
O43 - CFD: 08/11/2013 - 12:24:59 - [2,248] ----D C:\Documents and Settings\Max\Application Data\LibreOffice
O43 - CFD: 04/04/2013 - 10:52:56 - [0,001] ----D C:\Documents and Settings\Max\Application Data\Macromedia
O43 - CFD: 06/01/2014 - 10:30:23 - [68,394] ----D C:\Documents and Settings\Max\Application Data\Malwarebytes
O43 - CFD: 02/02/2014 - 10:36:17 - [0] ----D C:\Documents and Settings\Max\Application Data\Media Player Classic
O43 - CFD: 28/08/2013 - 19:43:43 - [13,638] -S--D C:\Documents and Settings\Max\Application Data\Microsoft
O43 - CFD: 29/03/2013 - 12:59:20 - [72,817] ----D C:\Documents and Settings\Max\Application Data\Mozilla
O43 - CFD: 28/08/2013 - 18:45:05 - [0,033] ----D C:\Documents and Settings\Max\Application Data\MSNInstaller
O43 - CFD: 05/07/2013 - 10:27:07 - [0,671] ----D C:\Documents and Settings\Max\Application Data\Nero
O43 - CFD: 12/08/2013 - 11:51:11 - [0] ----D C:\Documents and Settings\Max\Application Data\proDAD
O43 - CFD: 08/11/2013 - 11:15:09 - [3,436] ----D C:\Documents and Settings\Max\Application Data\Skype
O43 - CFD: 05/06/2013 - 14:56:38 - [14,011] ----D C:\Documents and Settings\Max\Application Data\Thunderbird =>.Mozilla Corporation
O43 - CFD: 02/02/2014 - 12:07:23 - [0,077] ----D C:\Documents and Settings\Max\Application Data\vlc
O43 - CFD: 03/02/2014 - 12:51:45 - [19,738] ----D C:\Documents and Settings\Max\Application Data\ZHP =>.Nicolas Coolman
O43 - CFD: 29/11/2013 - 06:02:37 - [17,384] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Adobe
O43 - CFD: 04/04/2013 - 11:14:23 - [0] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Apple
O43 - CFD: 19/01/2014 - 18:58:41 - [94,655] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Apple Computer
O43 - CFD: 03/02/2014 - 07:55:44 - [0,033] ----D C:\Documents and Settings\Max\Local Settings\Application Data\ApplicationHistory
O43 - CFD: 23/06/2013 - 19:27:49 - [0] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Deployment
O43 - CFD: 04/07/2013 - 15:51:06 - [12,348] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Downloaded Installations
O43 - CFD: 29/10/2013 - 06:54:14 - [325,188] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Google
O43 - CFD: 29/03/2013 - 11:59:16 - [0,281] ----D C:\Documents and Settings\Max\Local Settings\Application Data\HP
O43 - CFD: 05/06/2013 - 14:22:45 - [280,207] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Identities
O43 - CFD: 05/06/2013 - 17:32:09 - [0,001] ----D C:\Documents and Settings\Max\Local Settings\Application Data\IsolatedStorage
O43 - CFD: 03/01/2014 - 05:57:05 - [89,570] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Microsoft
O43 - CFD: 05/08/2013 - 10:01:31 - [0,056] ----D C:\Documents and Settings\Max\Local Settings\Application Data\MicroVision Applications
O43 - CFD: 29/03/2013 - 12:59:14 - [379,740] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla
O43 - CFD: 28/11/2013 - 14:12:27 - [0,337] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Nero
O43 - CFD: 05/08/2013 - 08:13:16 - [0,004] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Nero_AG
O43 - CFD: 21/01/2014 - 16:17:03 - [0,177] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Pinnacle
O43 - CFD: 24/06/2013 - 16:46:00 - [0] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Temp
O43 - CFD: 05/06/2013 - 14:56:38 - [1,296] ----D C:\Documents and Settings\Max\Local Settings\Application Data\Thunderbird =>.Mozilla Corporation
O43 - CFD: 05/06/2013 - 18:09:35 - [0] ----D C:\Documents and Settings\Max\Local Settings\Application Data\WmaMp3-Converter.com
O43 - CFD: 29/03/2013 - 12:53:10 - [0,014] R---D C:\Documents and Settings\Max\Menu Démarrer\Programmes\Accessoires
O43 - CFD: 05/06/2013 - 15:12:16 - [0,005] ----D C:\Documents and Settings\Max\Menu Démarrer\Programmes\Communications
O43 - CFD: 08/11/2013 - 11:14:29 - [0] R---D C:\Documents and Settings\Max\Menu Démarrer\Programmes\Démarrage
O43 - CFD: 29/03/2013 - 13:07:08 - [0] R---D C:\Documents and Settings\Max\Menu Démarrer\Programmes\Outils d'administration
O43 - CFD: 08/11/2013 - 11:46:11 - [0,002] ----D C:\Documents and Settings\Max\Menu Démarrer\Programmes\Video
~ Program Folder: 138 Scanned in 00mn 43s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.6F5387DADF1649FDED76CF1054F19AEB] - 02/02/2014 - 08:16:53 ---A- . (...) -- C:\WINDOWS\system32\wpa.dbl [13646]
O44 - LFC:[MD5.D7FADEF1D89C9B0F5822D94A10D36984] - 02/02/2014 - 10:24:20 ---A- . (...) -- C:\WINDOWS\win.ini [1119]
O44 - LFC:[MD5.41CAE3640E78BC1481A9F991F1BA1498] - 02/02/2014 - 20:38:56 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]
O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 03/02/2014 - 04:00:36 -S-A- . (...) -- C:\WINDOWS\bootstat.dat [2048]
O44 - LFC:[MD5.DA537C2BE810C8C0A3D86FB007CF9958] - 03/02/2014 - 04:00:43 ---A- . (...) -- C:\WINDOWS\wiaservc.log [50]
O44 - LFC:[MD5.6FF0EF26820BDE41734C380E4CB21774] - 03/02/2014 - 04:01:10 ---A- . (...) -- C:\WINDOWS\system32\NvApps.xml [235289]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 03/02/2014 - 04:02:44 ---A- . (...) -- C:\WINDOWS\0.log [0]
O44 - LFC:[MD5.72615AAFC97E285112A654DC28631AD1] - 03/02/2014 - 04:05:14 ---A- . (...) -- C:\WINDOWS\system32\PerfStringBackup.INI [1225418]
O44 - LFC:[MD5.65A0037F5DA6003C163E62F86F671424] - 03/02/2014 - 04:05:14 ---A- . (...) -- C:\WINDOWS\system32\perfc009.dat [79880]
O44 - LFC:[MD5.F00153AD05B0E1B4C23F04D5AEC7BEC7] - 03/02/2014 - 04:05:14 ---A- . (...) -- C:\WINDOWS\system32\perfc00C.dat [94712]
O44 - LFC:[MD5.62C807A71F86E4DA20411C227A402A47] - 03/02/2014 - 04:05:14 ---A- . (...) -- C:\WINDOWS\system32\perfh009.dat [481806]
O44 - LFC:[MD5.2220DBF9A290AE7EC289AA771105C233] - 03/02/2014 - 04:05:14 ---A- . (...) -- C:\WINDOWS\system32\perfh00C.dat [553012]
O44 - LFC:[MD5.322231FF268F919C8E1F8A49C3D2D0F3] - 03/02/2014 - 08:02:39 ---A- . (...) -- C:\WINDOWS\wiadebug.log [263]
O44 - LFC:[MD5.8AFBCB068318A5698760045E5F98A0B5] - 03/02/2014 - 08:09:58 ---A- . (...) -- C:\WINDOWS\WindowsUpdate.log [1626508]
~ Files: 15 Scanned in 01mn 20s



---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)
O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll
~ ShellExecuteHooks: Scanned in 00mn 00s



---\\ Export de clé d'application autorisée (O47)
O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export SP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation.) -- C:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export SP - "C:\Documents and Settings\Max\Application Data\Dropbox\bin\Dropbox.exe" [Enabled] .(.Dropbox, Inc..) -- C:\Documents and Settings\Max\Application Data\Dropbox\bin\Dropbox.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Bonjour\mDNSResponder.exe" [Enabled] .(.Apple Inc..) -- C:\Program Files\Bonjour\mDNSResponder.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Pinnacle\Studio 14\Programs\RM.exe" [Enabled] .(.Pinnacle Systems.) -- C:\Program Files\Pinnacle\Studio 14\Programs\RM.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Pinnacle\Studio 14\Programs\Studio.exe" [Enabled] .(.Pinnacle Systems.) -- C:\Program Files\Pinnacle\Studio 14\Programs\Studio.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Pinnacle\Studio 14\Programs\umi.exe" [Enabled] .(.Pinnacle Systems.) -- C:\Program Files\Pinnacle\Studio 14\Programs\umi.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Messenger\msmsgs.exe" [Enabled] .(.Microsoft Corporation.) -- C:\Program Files\Messenger\msmsgs.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Fichiers communs\Apple\Apple Application Support\WebKit2WebProcess.exe" [Enabled] .(.Apple Inc..) -- C:\Program Files\Fichiers communs\Apple\Apple Application Support\WebKit2WebProcess.exe
O47 - AAKE:Key Export SP - "C:\Program Files\iTunes\iTunes.exe" [Enabled] .(.Apple Inc..) -- C:\Program Files\iTunes\iTunes.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Skype\Phone\Skype.exe" [Enabled] .(.Skype Technologies S.A..) -- C:\Program Files\Skype\Phone\Skype.exe
O47 - AAKE:Key Export SP - "C:\Program Files\TeamViewer\Version9\TeamViewer.exe" [Enabled] .(.TeamViewer GmbH.) -- C:\Program Files\TeamViewer\Version9\TeamViewer.exe
O47 - AAKE:Key Export SP - "C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe" [Enabled] .(.TeamViewer GmbH.) -- C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
O47 - AAKE:Key Export DP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export DP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation.) -- C:\WINDOWS\system32\sessmgr.exe
~ Keys Export: 15 Scanned in 00mn 02s



---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\system32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\WINDOWS\system32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Kerberos Security Package.) -- C:\WINDOWS\system32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\system32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\WINDOWS\system32\wdigest.dll
~ LSA: 6 Scanned in 00mn 00s



---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmboot.sys . (.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disque NT.) -- C:\WINDOWS\system32\Drivers\dmboot.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmio.sys . (.Microsoft Corp., Veritas Software - Pilote E/S du Gestionnaire de disques NT.) -- C:\WINDOWS\system32\Drivers\dmio.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (...) -- C:\WINDOWS\system32\Drivers\sermouse.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sr.sys . (.Microsoft Corporation - Pilote de filtre de système de fichiers pour la restauration du système.) -- C:\WINDOWS\system32\Drivers\sr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmboot.sys . (.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disque NT.) -- C:\WINDOWS\system32\Drivers\dmboot.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmio.sys . (.Microsoft Corp., Veritas Software - Pilote E/S du Gestionnaire de disques NT.) -- C:\WINDOWS\system32\Drivers\dmio.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ip6fw.sys . (.Microsoft Corporation - IPv6 Windows Firewall Driver.) -- C:\WINDOWS\system32\Drivers\ip6fw.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\system32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpcdd.sys . (.Microsoft Corporation - RDP Miniport.) -- C:\WINDOWS\system32\Drivers\rdpcdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpdd.sys . (...) -- C:\WINDOWS\system32\Drivers\rdpdd.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpwd.sys . (.Microsoft Corporation - RDP Terminal Stack Driver (US/Canada Only, Not for Export).) -- C:\WINDOWS\system32\Drivers\rdpwd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (...) -- C:\WINDOWS\system32\Drivers\sermouse.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sr.sys . (.Microsoft Corporation - Pilote de filtre de système de fichiers pour la restauration du système.) -- C:\WINDOWS\system32\Drivers\sr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdpipe.sys . (.Microsoft Corporation - Named Pipe Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdpipe.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdtcp.sys . (.Microsoft Corporation - TCP Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdtcp.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.)
~ CSB: 21 Scanned in 00mn 00s



---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.trspch"="tssoft32.acm" . (.DSP GROUP, INC. - Codec audio TrueSpeech(TM) DSP Group pour MSACM V3.50.) -- C:\WINDOWS\system32\tssoft32.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\system32\iccvid.dll
O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (...) -- C:\WINDOWS\system32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (...) -- C:\WINDOWS\system32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv41"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\WINDOWS\system32\ir41_32.ax
O52 - TDSD: \Drivers32\"msacm.sl_anet"="sl_anet.acm" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\system32\sl_anet.acm
O52 - TDSD: \Drivers32\"msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax
O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\WINDOWS\system32\ir50_32.dll
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm
O52 - TDSD: \Drivers32\"VIDC.XVID"="xvidvfw.dll" . (...) -- C:\WINDOWS\system32\xvidvfw.dll
O52 - TDSD: \Drivers32\"VIDC.YV12"="yv12vfw.dll" . (.www.helixcommunity.org - Helix YV12 YUV Codec.) -- C:\WINDOWS\system32\yv12vfw.dll
O52 - TDSD: \Drivers32\"msacm.ac3acm"="ac3acm.acm" . (.fccHandler - AC-3 ACM Codec.) -- C:\WINDOWS\system32\ac3acm.acm
O52 - TDSD: \Drivers32\"msacm.lameacm"="lameACM.acm" . (.http://www.mp3dev.org/ - Lame MP3 codec engine.) -- C:\WINDOWS\system32\lameACM.acm
O52 - TDSD: \Drivers32\"VIDC.FFDS"="ff_vfw.dll" . (...) -- C:\WINDOWS\system32\ff_vfw.dll
O52 - TDSD: \drivers.desc\"sl_anet.acm"="Sipro Lab Telecom Audio Codec" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\system32\sl_anet.acm
O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax
O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm
O52 - TDSD: \drivers.desc\"ac3acm.acm"="AC-3 ACM Codec" . (.fccHandler - AC-3 ACM Codec.) -- C:\WINDOWS\system32\ac3acm.acm
O52 - TDSD: \drivers.desc\"ff_vfw.dll"="ffdshow video encoder" . (...) -- C:\WINDOWS\system32\ff_vfw.dll
~ TDSD: 19 Scanned in 00mn 00s



---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- C:\WINDOWS\system32\msapsspc.dll
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- C:\WINDOWS\system32\digest.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- C:\WINDOWS\system32\msapsspc.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- C:\WINDOWS\system32\digest.dll
~ MSCP: 6 Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLinkedConnections"=1
~ MWPS: 6 Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145
~ MWPE Keys: 1 Scanned in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.E5E6DBFC41EA8AAD005CB9A57A96B43B] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote ACPI pour NT.) -- C:\WINDOWS\system32\Drivers\acpi.sys [188672]
O58 - SDL:[MD5.E4ABC1212B70BB03D35E60681C447210] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de contrôleur intégré ACPI.) -- C:\WINDOWS\system32\Drivers\acpiec.sys [12032]
O58 - SDL:[MD5.8BED39E3C35D6A489438B8141717A557] - 13/04/2008 - 09:39:24 ----- . (.Microsoft Corporation - Microsoft Acoustic Echo Canceller.) -- C:\WINDOWS\system32\Drivers\aec.sys [142592]
O58 - SDL:[MD5.1E44BC1E83D8FD2305F8D452DB109CF9] - 17/08/2011 - 14:49:54 ----- . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\WINDOWS\system32\Drivers\afd.sys [138496]
O58 - SDL:[MD5.C6C0F974AB7E825813F8E6B4E5581750] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de périphérique processeur.) -- C:\WINDOWS\system32\Drivers\amdk6.sys [41472]
O58 - SDL:[MD5.D3DABC57BE6D456DFD4BC026CFA582FF] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de périphérique processeur.) -- C:\WINDOWS\system32\Drivers\amdk7.sys [41856]
O58 - SDL:[MD5.B5B8A80875C1DEDEDA8B02765642C32F] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - IP/1394 Arp Client.) -- C:\WINDOWS\system32\Drivers\arp1394.sys [60800]
O58 - SDL:[MD5.D48659BB24C48345D926ECB45C1EBDF5] - 13/08/2004 - 03:56:20 ----- . (.Pas de propriétaire - ATK0110 ACPI Utility.) -- C:\WINDOWS\system32\Drivers\ASACPI.sys [5810]
O58 - SDL:[MD5.DE91D0D73C3E61E6826D98FAC2FAC729] - 27/04/2004 - 08:26:48 ----- . (...) -- C:\WINDOWS\system32\Drivers\ASUSHWIO.SYS [5824]
O58 - SDL:[MD5.B153AFFAC761E7F5FCFA822B9C4E97BC] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - MS Remote Access serial network driver.) -- C:\WINDOWS\system32\Drivers\asyncmac.sys [14336]
O58 - SDL:[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - IDE/ATAPI Port Driver.) -- C:\WINDOWS\system32\Drivers\atapi.sys [96512]
O58 - SDL:[MD5.9916C1225104BA14794209CFA8012159] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - IP/ATM Arp Client.) -- C:\WINDOWS\system32\Drivers\atmarpc.sys [59904]
O58 - SDL:[MD5.39A0A59180F19946374275745B21AEBA] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - ATM Ethernet Encapsulation Intermediate Driver.) -- C:\WINDOWS\system32\Drivers\atmepvc.sys [31360]
O58 - SDL:[MD5.AE76348A2605FB197FA8FF1D6F547836] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - ATM Lan Emulation Driver.) -- C:\WINDOWS\system32\Drivers\atmlane.sys [55808]
O58 - SDL:[MD5.E7EF69B38D17BA01F914AE8F66216A38] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - ATM UNI Call Manager.) -- C:\WINDOWS\system32\Drivers\atmuni.sys [352256]
O58 - SDL:[MD5.D9F724AA26C010A217C97606B160ED68] - 17/08/2001 - 22:59:44 ----- . (.Microsoft Corporation - AudStub Driver.) -- C:\WINDOWS\system32\Drivers\audstub.sys [3072]
O58 - SDL:[MD5.B8C10FF9369394EB84993F331810CF29] - 19/12/2013 - 11:20:20 ---A- . (.Avira Operations GmbH & Co. KG - Avira Minifilter Driver.) -- C:\WINDOWS\system32\Drivers\avgntflt.sys [90400]
O58 - SDL:[MD5.18EDCBAB4EE8AA97070105EBC9555427] - 18/06/2013 - 14:55:14 ----- . (.AVG Technologies - Pas de description.) -- C:\WINDOWS\system32\Drivers\avgtpx86.sys [37664]
O58 - SDL:[MD5.4189E5AB2CAD6F395D87DAAE73EB090F] - 19/12/2013 - 11:20:20 ---A- . (.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) -- C:\WINDOWS\system32\Drivers\avipbb.sys [135648]
O58 - SDL:[MD5.D8C712305F73CD34D1B344810E522728] - 27/11/2013 - 10:06:07 ---A- . (.Avira Operations GmbH & Co. KG - Avira Manager Driver.) -- C:\WINDOWS\system32\Drivers\avkmgr.sys [37352]
O58 - SDL:[MD5.EBF36D658D0DA5B1EA667FA403919C26] - 17/07/2003 - 16:40:06 ----- . (.Broadcom Corporation - Broadcom Corporation NDIS 5.0 wireless driver.) -- C:\WINDOWS\system32\Drivers\BCMWL5.SYS [265728]
O58 - SDL:[MD5.DA1F27D85E0D1525F6621372E7B685E9] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - BEEP Driver.) -- C:\WINDOWS\system32\Drivers\beep.sys [4224]
O58 - SDL:[MD5.F934D1B230F84E1D19DD00AC5A7A83ED] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - MAC Bridge Driver.) -- C:\WINDOWS\system32\Drivers\bridge.sys [71552]
O58 - SDL:[MD5.EF26202FEE56F7607C6B794059DF347A] - 14/06/2008 - 18:33:37 ----- . (.Microsoft Corporation - Pilote de bus Bluetooth.) -- C:\WINDOWS\system32\Drivers\bthport.sys [272768]
O58 - SDL:[MD5.90A673FC8E12A79AFBED2576F6A7AAF9] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - CardBus/PCMCIA IDE Miniport Driver.) -- C:\WINDOWS\system32\Drivers\cbidf2k.sys [13952]
O58 - SDL:[MD5.0BE5AEF125BE881C4F854C554F2B025C] - 13/04/2008 - 11:46:24 ----- . (.Microsoft Corporation - WDM Closed Caption VBI Codec.) -- C:\WINDOWS\system32\Drivers\CCDECODE.sys [17024]
O58 - SDL:[MD5.C1B486A7658353D33A10CC15211A873B] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - CD-ROM Audio Filter Driver.) -- C:\WINDOWS\system32\Drivers\cdaudio.sys [18688]
O58 - SDL:[MD5.C885B02847F5D2FD45A24E219ED93B32] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\system32\Drivers\cdfs.sys [63744]
O58 - SDL:[MD5.1F4260CC5B42272D71F79E570A27A4FE] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\system32\Drivers\cdrom.sys [62976]
O58 - SDL:[MD5.C9B25AE9B8ABD983C5AD3F8CBFAB0F9C] - 14/04/2008 - 13:00:00 ----- . (.RAVISENT Technologies Inc. - Pilote principal CineMaster C 1.2 WDM.) -- C:\WINDOWS\system32\Drivers\cinemst2.sys [262528]
O58 - SDL:[MD5.FE47DD8FE6D7768FF94EBEC6C74B2719] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - SCSI Class System Dll.) -- C:\WINDOWS\system32\Drivers\classpnp.sys [49536]
O58 - SDL:[MD5.9624293E55AD405415862B504CA95B73] - 14/04/2008 - 13:00:00 ----- . (.Compaq Computer Corporation - Compaq PA-1 Player Driver.) -- C:\WINDOWS\system32\Drivers\cpqdap01.sys [11776]
O58 - SDL:[MD5.D68AE021109A74E491B83F3F69FB92CD] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de périphérique processeur.) -- C:\WINDOWS\system32\Drivers\crusoe.sys [40960]
O58 - SDL:[MD5.044452051F3E02E7963599FC8F4F3E25] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - PnP Disk Driver.) -- C:\WINDOWS\system32\Drivers\disk.sys [36352]
O58 - SDL:[MD5.E65E2353A5D74EA89971CB918EEEB2F6] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Crash Dump Disk Driver.) -- C:\WINDOWS\system32\Drivers\diskdump.sys [14208]
O58 - SDL:[MD5.F5DEADD42335FB33EDCA74ECB2F36CBA] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disque NT.) -- C:\WINDOWS\system32\Drivers\dmboot.sys [800256]
O58 - SDL:[MD5.5A7C47C9B3F9FB92A66410A7509F0C71] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corp., Veritas Software - Pilote E/S du Gestionnaire de disques NT.) -- C:\WINDOWS\system32\Drivers\dmio.sys [154496]
O58 - SDL:[MD5.E9317282A63CA4D188C0DF5E09C6AC5F] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys [5888]
O58 - SDL:[MD5.8A208DFCF89792A484E76C40E5F50B45] - 13/04/2008 - 11:45:02 ----- . (.Microsoft Corporation - Microsoft Kernel DLS Synthesizer.) -- C:\WINDOWS\system32\Drivers\DMusic.sys [52864]
O58 - SDL:[MD5.6CB08593487F5701D2D2254E693EAFCE] - 13/04/2008 - 11:45:16 ----- . (.Microsoft Corporation - Microsoft Kernel DRM Descrambler Filter.) -- C:\WINDOWS\system32\Drivers\drmk.sys [60160]
O58 - SDL:[MD5.8F5FCFF8E8848AFAC920905FBD9D33C8] - 13/04/2008 - 11:45:14 ----- . (.Microsoft Corporation - Microsoft Kernel DRM Audio Descrambler Filter.) -- C:\WINDOWS\system32\Drivers\drmkaud.sys [2944]
O58 - SDL:[MD5.FE97D0343ACFDEBDD578FC67CC91FA87] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - DirectX API Driver.) -- C:\WINDOWS\system32\Drivers\dxapi.sys [10496]
O58 - SDL:[MD5.AC7280566A7BB85CB3291F04DDC1198E] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - DirectX Graphics Driver.) -- C:\WINDOWS\system32\Drivers\dxg.sys [71168]
O58 - SDL:[MD5.A73F5D6705B1D820C19B18782E176EFD] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - DirectX Graphics Driver Thunk.) -- C:\WINDOWS\system32\Drivers\dxgthk.sys [3328]
O58 - SDL:[MD5.38D332A6D56AF32635675F132548343E] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Fast FAT File System Driver.) -- C:\WINDOWS\system32\Drivers\fastfat.sys [143744]
O58 - SDL:[MD5.92CDD60B6730B9F50F6A1A0C1F8CDC81] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Floppy Disk Controller Driver.) -- C:\WINDOWS\system32\Drivers\fdc.sys [27392]
O58 - SDL:[MD5.31F923EB2170FC172C81ABDA0045D18C] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de cryptographie FIPS.) -- C:\WINDOWS\system32\Drivers\fips.sys [44672]
O58 - SDL:[MD5.9D27E7B80BFCDF1CDD9B555862D5E7F0] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Floppy Driver.) -- C:\WINDOWS\system32\Drivers\flpydisk.sys [20480]
O58 - SDL:[MD5.B2CF4B0786F8212CB92ED2B50C6DB6B0] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Microsoft Filesystem Filter Manager.) -- C:\WINDOWS\system32\Drivers\fltMgr.sys [129792]
O58 - SDL:[MD5.B71A69BB9CC88803F455341BD3992E0C] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote vidéo plein écran.) -- C:\WINDOWS\system32\Drivers\fsvga.sys [12416]
O58 - SDL:[MD5.3E1E2BD4F39B0E2B7DC4F4D2BCC2779A] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - File System Recognizer Driver.) -- C:\WINDOWS\system32\Drivers\fs_rec.sys [7936]
O58 - SDL:[MD5.A86859B77B908C18C2657F284AA29FE3] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de disque à FT.) -- C:\WINDOWS\system32\Drivers\ftdisk.sys [126080]
O58 - SDL:[MD5.185ADA973B5020655CEE342059A86CBB] - 21/08/2012 - 12:01:22 ----- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys [26840]
O58 - SDL:[MD5.573C7D0A32852B48F3058CFD8026F511] - 14/04/2008 - 13:00:00 ----- . (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) -- C:\WINDOWS\system32\Drivers\hdaudbus.sys [144384]
O58 - SDL:[MD5.1AF592532532A402ED7C060F6954004F] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Hid Class Library.) -- C:\WINDOWS\system32\Drivers\hidclass.sys [36864]
O58 - SDL:[MD5.C569EF030B11F896E123A30AC92678DB] - 03/07/2013 - 03:12:52 ----- . (.Microsoft Corporation - Hid Parsing Library.) -- C:\WINDOWS\system32\Drivers\hidparse.sys [25088]
O58 - SDL:[MD5.CCF82C5EC8A7326C3066DE870C06DAF1] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - USB Miniport Driver for Input Devices.) -- C:\WINDOWS\system32\Drivers\hidusb.sys [10368]
O58 - SDL:[MD5.9F1D80908658EB7F1BF70809E0B51470] - 14/12/2004 - 17:06:28 ----- . (.HP - IEEE-1284.4-1999 Driver (Windows 2000).) -- C:\WINDOWS\system32\Drivers\HPZid412.sys [51120]
O58 - SDL:[MD5.F7E3E9D50F9CD3DE28085A8FDAA0A1C3] - 14/12/2004 - 17:06:28 ----- . (.HP - IEEE-1284.4-1999 Print Class Driver.) -- C:\WINDOWS\system32\Drivers\HPZipr12.sys [16496]
O58 - SDL:[MD5.CF1B7951B4EC8D13F3C93B74BB2B461B] - 14/12/2004 - 17:06:28 ----- . (.HP - 1284.4<->Usb Datalink Driver (Windows 2000).) -- C:\WINDOWS\system32\Drivers\HPZius12.sys [21744]
O58 - SDL:[MD5.F80A415EF82CD06FFAF0D971528EAD38] - 20/10/2009 - 17:20:16 ----- . (.Microsoft Corporation - HTTP Protocol Stack.) -- C:\WINDOWS\system32\Drivers\http.sys [265728]
O58 - SDL:[MD5.A09BDC4ED10E3B2E0EC27BB94AF32516] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de port i8042.) -- C:\WINDOWS\system32\Drivers\i8042prt.sys [54144]
O58 - SDL:[MD5.083A052659F5310DD8B6A6CB05EDCF8E] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - IMAPI Kernel Driver.) -- C:\WINDOWS\system32\Drivers\imapi.sys [42112]
O58 - SDL:[MD5.AD340800C35A42D4DE1641A37FEEA34C] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de périphérique processeur.) -- C:\WINDOWS\system32\Drivers\intelppm.sys [40576]
O58 - SDL:[MD5.3BB22519A194418D5FEC05D800A19AD0] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - IPv6 Windows Firewall Driver.) -- C:\WINDOWS\system32\Drivers\ip6fw.sys [36608]
O58 - SDL:[MD5.731F22BA402EE4B62748ADAF6363C182] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - IP FILTER DRIVER.) -- C:\WINDOWS\system32\Drivers\ipfltdrv.sys [32896]
O58 - SDL:[MD5.B87AB476DCF76E72010632B5550955F5] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - IP in IP Encapsulation Driver.) -- C:\WINDOWS\system32\Drivers\ipinip.sys [20864]
O58 - SDL:[MD5.CC748EA12C6EFFDE940EE98098BF96BB] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\system32\Drivers\ipnat.sys [152832]
O58 - SDL:[MD5.23C74D75E36E7158768DD63D92789A91] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - IPSec Driver.) -- C:\WINDOWS\system32\Drivers\ipsec.sys [75264]
O58 - SDL:[MD5.C93C9FF7B04D772627A3646D89F7BF89] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Infra-Red Bus Enumerator.) -- C:\WINDOWS\system32\Drivers\irenum.sys [11264]
O58 - SDL:[MD5.355836975A67B6554BCA60328CD6CB74] - 13/04/2008 - 19:04:36 ----- . (.Microsoft Corporation - Pilote de bus PNP ISA.) -- C:\WINDOWS\system32\Drivers\isapnp.sys [37632]
O58 - SDL:[MD5.16813155807C6881F4BFBF6657424659] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de la classe Clavier.) -- C:\WINDOWS\system32\Drivers\kbdclass.sys [25216]
O58 - SDL:[MD5.94C59CB884BA010C063687C3A50DCE8E] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de filtre souris HID.) -- C:\WINDOWS\system32\Drivers\kbdhid.sys [14720]
O58 - SDL:[MD5.692BCF44383D056AED41B045A323D378] - 13/04/2008 - 11:45:10 ----- . (.Microsoft Corporation - Kernel Mode Audio Mixer.) -- C:\WINDOWS\system32\Drivers\kmixer.sys [172416]
O58 - SDL:[MD5.0753515F78DF7F271A5E61C20BCD36A1] - 13/04/2008 - 12:16:38 ----- . (.Microsoft Corporation - Kernel CSA Library.) -- C:\WINDOWS\system32\Drivers\ks.sys [141056]
O58 - SDL:[MD5.B467646C54CC746128904E1654C750C1] - 24/06/2009 - 12:18:41 ----- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\WINDOWS\system32\Drivers\ksecdd.sys [92928]
O58 - SDL:[MD5.9A155D31B8E52F41B258282092CC93A7] - 27/05/2005 - 10:32:52 ----- . (...) -- C:\WINDOWS\system32\Drivers\lvcm.sys [1317152]
O58 - SDL:[MD5.93418CD2C3B544847C3CDF7DB66F1921] - 27/05/2005 - 10:23:38 ----- . (.Logitech Inc. - SmoothVision filter.) -- C:\WINDOWS\system32\Drivers\lvsvf2.sys [2180096]
O58 - SDL:[MD5.C5EFBD05A5195402121711A6EBBB271F] - 27/05/2005 - 10:31:28 ----- . (.Logitech Inc. - USB Statistic Driver.) -- C:\WINDOWS\system32\Drivers\LVUSBSta.sys [22016]
O58 - SDL:[MD5.A3E700D78EEC390F1208098CDCA5C6B6] - 23/09/2005 - 21:18:32 ---A- . (.Pinnacle Systems GmbH - Pinnacle Marvin Discrete Bus Enumerator.) -- C:\WINDOWS\system32\Drivers\MarvinBus.sys [171520]
O58 - SDL:[MD5.4470E3C1E0C3378E4CAB137893C12C3A] - 04/04/2013 - 14:50:32 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\WINDOWS\system32\Drivers\mbam.sys [22856]
O58 - SDL:[MD5.D1F8BE91ED4DDB671D42E473E3FE71AB] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Medium changer class driver.) -- C:\WINDOWS\system32\Drivers\mcd.sys [7680]
O58 - SDL:[MD5.A7DA20AB18A1BDAE28B0F349E57DA0D1] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Multifunction Enumerator.) -- C:\WINDOWS\system32\Drivers\mf.sys [63744]
O58 - SDL:[MD5.4AE068242760A1FB6E1A44BF4E16AFA6] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Frame buffer simulator.) -- C:\WINDOWS\system32\Drivers\mnmdd.sys [4224]
O58 - SDL:[MD5.510ADE9327FE84C10254E1902697E25F] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de périphérique modem.) -- C:\WINDOWS\system32\Drivers\modem.sys [30336]
O58 - SDL:[MD5.027C01BD7EF3349AAEBC883D8A799EFB] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de la classe Souris.) -- C:\WINDOWS\system32\Drivers\mouclass.sys [23680]
O58 - SDL:[MD5.124D6846040C79B9C997F78EF4B2A4E5] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de filtre souris HID.) -- C:\WINDOWS\system32\Drivers\mouhid.sys [12288]
O58 - SDL:[MD5.A80B9A0BAD1B73637DBCBBA7DF72D3FD] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Mount Manager.) -- C:\WINDOWS\system32\Drivers\mountmgr.sys [42368]
O58 - SDL:[MD5.11D42BB6206F33FBB3BA0288D3EF81BD] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\WINDOWS\system32\Drivers\mrxdav.sys [180608]
O58 - SDL:[MD5.7D304A5EB4344EBEEAB53A2FE3FFB9F0] - 15/07/2011 - 14:29:31 ----- . (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\WINDOWS\system32\Drivers\mrxsmb.sys [456320]
O58 - SDL:[MD5.C941EA2454BA8350021D774DAF0F1027] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Mailslot driver.) -- C:\WINDOWS\system32\Drivers\msfs.sys [19072]
O58 - SDL:[MD5.0A02C63C8B144BD8C86B103DEE7C86A2] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - MS General Packet Classifier.) -- C:\WINDOWS\system32\Drivers\msgpc.sys [35072]
O58 - SDL:[MD5.D1575E71568F4D9E14CA56B7B0453BF1] - 13/04/2008 - 11:39:54 ----- . (.Microsoft Corporation - MS KS Server.) -- C:\WINDOWS\system32\Drivers\MSKSSRV.sys [7552]
O58 - SDL:[MD5.325BB26842FC7CCC1FCCE2C457317F3E] - 13/04/2008 - 11:39:52 ----- . (.Microsoft Corporation - MS Proxy Clock.) -- C:\WINDOWS\system32\Drivers\MSPCLOCK.sys [5376]
O58 - SDL:[MD5.BAD59648BA099DA4A17680B39730CB3D] - 13/04/2008 - 11:39:52 ----- . (.Microsoft Corporation - MS Proxy Quality Manager.) -- C:\WINDOWS\system32\Drivers\MSPQM.sys [4992]
O58 - SDL:[MD5.AF5F4F3F14A8EA2C26DE30F7A1E17136] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - System Management BIOS Driver.) -- C:\WINDOWS\system32\Drivers\mssmbios.sys [15488]
O58 - SDL:[MD5.E53736A9E30C45FA9E7B5EAC55056D1D] - 13/04/2008 - 11:39:52 ----- . (.Microsoft Corporation - WDM Tee/Communication Transform Filter.) -- C:\WINDOWS\system32\Drivers\MSTEE.sys [5504]
O58 - SDL:[MD5.DE6A75F5C270E756C5508D94B6CF68F5] - 21/04/2011 - 14:37:43 ----- . (.Microsoft Corporation - Multiple UNC Provider driver.) -- C:\WINDOWS\system32\Drivers\mup.sys [105472]
O58 - SDL:[MD5.5B50F1B2A2ED47D560577B221DA734DB] - 13/04/2008 - 11:46:26 ----- . (.Microsoft Corporation - WDM NABTS/FEC VBI Codec.) -- C:\WINDOWS\system32\Drivers\NABTSFEC.sys [85248]
O58 - SDL:[MD5.0AE25530894A934C6CA600865C6E9D7C] - 01/12/2011 - 10:40:16 ----- . (.Nero AG - Nero Backup Volume Filter Driver for the Disk Stack.) -- C:\WINDOWS\system32\Drivers\NBVol.sys [56496]
O58 - SDL:[MD5.1DDCEF3039C9D90AF3529DEE6699967D] - 01/12/2011 - 10:40:16 ----- . (.Nero AG - Nero Backup Volume Upper Filter Driver for the Disk Stack.) -- C:\WINDOWS\system32\Drivers\NBVolUp.sys [12464]
O58 - SDL:[MD5.1DF7F42665C94B825322FAE71721130D] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - NDIS 5.1 wrapper driver.) -- C:\WINDOWS\system32\Drivers\ndis.sys [182656]
O58 - SDL:[MD5.7FF1F1FD8609C149AA432F95A8163D97] - 13/04/2008 - 11:46:24 ----- . (.Microsoft Corporation - Microsoft IP Driver.) -- C:\WINDOWS\system32\Drivers\NdisIP.sys [10880]
O58 - SDL:[MD5.0109C4F3850DFBAB279542515386AE22] - 08/07/2011 - 15:02:00 ----- . (.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) -- C:\WINDOWS\system32\Drivers\ndistapi.sys [10496]
O58 - SDL:[MD5.F927A4434C5028758A842943EF1A3849] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - NDIS User mode I/O Driver.) -- C:\WINDOWS\system32\Drivers\ndisuio.sys [14592]
O58 - SDL:[MD5.EDC1531A49C80614B2CFDA43CA8659AB] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - MS PPP Framing Driver (Strong Encryption).) -- C:\WINDOWS\system32\Drivers\ndiswan.sys [91520]
O58 - SDL:[MD5.2F597BB467E05B1FE3830EABD821B8E0] - 27/11/2013 - 21:21:06 ----- . (.Microsoft Corporation - NDIS Proxy.) -- C:\WINDOWS\system32\Drivers\ndproxy.sys [40960]
O58 - SDL:[MD5.5D81CF9A2F1A3A756B66CF684911CDF0] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - NetBIOS interface driver.) -- C:\WINDOWS\system32\Drivers\netbios.sys [34688]
O58 - SDL:[MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\system32\Drivers\netbt.sys [162816]
O58 - SDL:[MD5.E9E47CFB2D461FA0FC75B7A74C6383EA] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - IEEE1394 Ndis Miniport and Call Manager.) -- C:\WINDOWS\system32\Drivers\nic1394.sys [61824]
O58 - SDL:[MD5.BE984D604D91C217355CDD3737AAD25D] - 14/04/2008 - 13:00:00 ----- . (.S3/Diamond Multimedia Systems - NikeDrv Usb Driver.) -- C:\WINDOWS\system32\Drivers\nikedrv.sys [12032]
O58 - SDL:[MD5.1E421A6BCF2203CC61B821ADA9DE878B] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Netmon NT Driver.) -- C:\WINDOWS\system32\Drivers\nmnt.sys [40320]
O58 - SDL:[MD5.3182D64AE053D6FB034F44B6DEF8034A] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - NPFS Driver.) -- C:\WINDOWS\system32\Drivers\npfs.sys [30848]
O58 - SDL:[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - NT File System Driver.) -- C:\WINDOWS\system32\Drivers\ntfs.sys [574976]
O58 - SDL:[MD5.73C1E1F395918BC2C6DD67AF7591A3AD] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - NULL Driver.) -- C:\WINDOWS\system32\Drivers\null.sys [2944]
O58 - SDL:[MD5.BF506D232C5E6F2DAE80F5C11B45C60E] - 10/06/2009 - 11:33:00 ----- . (.NVIDIA Corporation - NVIDIA Compatible Windows 2000 Miniport Driver, Version 186.18.) -- C:\WINDOWS\system32\Drivers\nv4_mini.sys [8087712]
O58 - SDL:[MD5.B305F3FAD35083837EF46A0BBCE2FC57] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - NWLINK2 Traffic Filter Driver.) -- C:\WINDOWS\system32\Drivers\nwlnkflt.sys [12416]
O58 - SDL:[MD5.C99B3415198D1AAB7227F2C88FD664B9] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - NWLINK2 Forwarder Driver.) -- C:\WINDOWS\system32\Drivers\nwlnkfwd.sys [32512]
O58 - SDL:[MD5.8B8B1BE2DBA4025DA6786C645F77F123] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - NWLINK2 IPX Protocol Driver.) -- C:\WINDOWS\system32\Drivers\nwlnkipx.sys [88320]
O58 - SDL:[MD5.56D34A67C05E94E16377C60609741FF8] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - NWLINK2 IPX Netbios Protocol Driver.) -- C:\WINDOWS\system32\Drivers\nwlnknb.sys [63232]
O58 - SDL:[MD5.C0BB7D1615E1ACBDC99757F6CEAF8CF0] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - NWLINK2 SPX Protocol Driver.) -- C:\WINDOWS\system32\Drivers\nwlnkspx.sys [55936]
O58 - SDL:[MD5.4BB30DDC53EBC76895E38694580CDFE9] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - ACPI Operation Registration Driver.) -- C:\WINDOWS\system32\Drivers\oprghdlr.sys [3456]
O58 - SDL:[MD5.CECB679633523AC5EB7EB85F92DCD806] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de périphérique processeur.) -- C:\WINDOWS\system32\Drivers\p3.sys [46848]
O58 - SDL:[MD5.8FD0BDBEA875D06CCF6C945CA9ABAF75] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de port parallèle.) -- C:\WINDOWS\system32\Drivers\parport.sys [80384]
O58 - SDL:[MD5.BEB3BA25197665D82EC7065B724171C6] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Partition Manager.) -- C:\WINDOWS\system32\Drivers\partmgr.sys [19712]
O58 - SDL:[MD5.9575C5630DB8FB804649A6959737154C] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote parallèle VDM.) -- C:\WINDOWS\system32\Drivers\parvdm.sys [6912]
O58 - SDL:[MD5.043410877BDA580C528F45165F7125BC] - 13/04/2008 - 19:09:48 ----- . (.Microsoft Corporation - Énumérateur Plug-and-Play PCI pour NT.) -- C:\WINDOWS\system32\Drivers\pci.sys [68608]
O58 - SDL:[MD5.F4BFDE7209C14A07AAA61E4D6AE69EAC] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de bus générique PCI IDE.) -- C:\WINDOWS\system32\Drivers\pciide.sys [3328]
O58 - SDL:[MD5.52E60F29221D0D1AC16737E8DBF7C3E9] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - PCI IDE Bus Driver Extension.) -- C:\WINDOWS\system32\Drivers\pciidex.sys [24960]
O58 - SDL:[MD5.F0406CBC60BDB0394A0E17FFB04CDD3D] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de bus PCMCIA.) -- C:\WINDOWS\system32\Drivers\pcmcia.sys [120576]
O58 - SDL:[MD5.E82A496C3961EFC6828B508C310CE98F] - 13/04/2008 - 12:19:42 ----- . (.Microsoft Corporation - Port Class (Class Driver for Port/Miniport Devices).) -- C:\WINDOWS\system32\Drivers\portcls.sys [146048]
O58 - SDL:[MD5.E19C9632AC828F6F214391E2BDDA11CB] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de périphérique processeur.) -- C:\WINDOWS\system32\Drivers\processr.sys [40064]
O58 - SDL:[MD5.09298EC810B07E5D582CB3A3F9255424] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - MS QoS Packet Scheduler.) -- C:\WINDOWS\system32\Drivers\psched.sys [69120]
O58 - SDL:[MD5.80D317BD1C3DBC5D4FE7B1678C60CADD] - 14/04/2008 - 13:00:00 ----- . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Library.) -- C:\WINDOWS\system32\Drivers\ptilink.sys [17792]
O58 - SDL:[MD5.FE0D99D6F31E4FAD8159F690D68DED9C] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - RAS Automatic Connection Driver.) -- C:\WINDOWS\system32\Drivers\rasacd.sys [8832]
O58 - SDL:[MD5.11B4A627BC9614B885C4969BFA5FF8A6] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\system32\Drivers\rasl2tp.sys [51328]
O58 - SDL:[MD5.5BC962F2654137C9909C3D4603587DEE] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - RAS PPPoE mini-port/call-manager driver.) -- C:\WINDOWS\system32\Drivers\raspppoe.sys [41472]
O58 - SDL:[MD5.EFEEC01B1D3CF84F16DDD24D9D9D8F99] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Peer-to-Peer Tunneling Protocol.) -- C:\WINDOWS\system32\Drivers\raspptp.sys [48384]
O58 - SDL:[MD5.FDBB1D60066FCFBB7452FD8F9829B242] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - PTI DirectParallel(R) mini-port/call-manager driver.) -- C:\WINDOWS\system32\Drivers\raspti.sys [16512]
O58 - SDL:[MD5.01524CD237223B18ADBB48F70083F101] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Raw WAN Transport.) -- C:\WINDOWS\system32\Drivers\rawwan.sys [34432]
O58 - SDL:[MD5.7AD224AD1A1437FE28D89CF22B17780A] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) -- C:\WINDOWS\system32\Drivers\rdbss.sys [175744]
O58 - SDL:[MD5.4912D5B403614CE99C28420F75353332] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - RDP Miniport.) -- C:\WINDOWS\system32\Drivers\rdpcdd.sys [4224]
O58 - SDL:[MD5.15CABD0F7C00C47C70124907916AF3F1] - 13/04/2008 - 11:32:52 ----- . (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\WINDOWS\system32\Drivers\rdpdr.sys [196224]
O58 - SDL:[MD5.43AF5212BD8FB5BA6EED9754358BD8F7] - 04/07/2012 - 15:05:18 ----- . (.Microsoft Corporation - RDP Terminal Stack Driver (US/Canada Only, Not for Export).) -- C:\WINDOWS\system32\Drivers\rdpwd.sys [139784]
O58 - SDL:[MD5.D8EB2A7904DB6C916EB5361878DDCBAE] - 13/04/2008 - 19:57:36 ----- . (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) -- C:\WINDOWS\system32\Drivers\redbook.sys [58752]
O58 - SDL:[MD5.A56FE08EC7473E8580A390BB1081CDD7] - 14/04/2008 - 13:00:00 ----- . (.S3/Diamond Multimedia Systems - Rio8Drv.sys Usb Driver.) -- C:\WINDOWS\system32\Drivers\rio8drv.sys [12032]
O58 - SDL:[MD5.0A854DF84C77A0BE205BFEAB2AE4F0EC] - 14/04/2008 - 13:00:00 ----- . (.S3/Diamond Multimedia Systems - RioDrv Usb Driver.) -- C:\WINDOWS\system32\Drivers\riodrv.sys [12032]
O58 - SDL:[MD5.96F7A9A7BF0C9C0440A967440065D33C] - 08/05/2008 - 15:02:52 ----- . (.Microsoft Corporation - Reliable Multicast Transport.) -- C:\WINDOWS\system32\Drivers\rmcast.sys [203136]
O58 - SDL:[MD5.601844CBCF617FF8C868130CA5B2039D] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\WINDOWS\system32\Drivers\rndismp.sys [30592]
O58 - SDL:[MD5.D8B0B4ADE32574B2D9C5CC34DC0DBBE7] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Legacy Non-Pnp Modem Device Driver.) -- C:\WINDOWS\system32\Drivers\rootmdm.sys [5888]
O58 - SDL:[MD5.284BCB80391783D328A8D8163E97FD58] - 15/08/2006 - 07:41:16 ----- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\WINDOWS\system32\Drivers\RtkHDAud.Sys [4368896]
O58 - SDL:[MD5.C8B370B2B520AC1B8BC66203FCEC73DB] - 31/08/2006 - 04:54:44 ----- . (.Realtek Semiconductor Corporation - Realtek 10/100/1000 NDIS 5.1 Driver.) -- C:\WINDOWS\system32\Drivers\Rtnicxp.sys [81280]
O58 - SDL:[MD5.76C465F570E90C28942D52CCB2580A10] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - SCSI Port Driver.) -- C:\WINDOWS\system32\Drivers\scsiport.sys [96384]
O58 - SDL:[MD5.8D04819A3CE51B9EB47E5689B44D43C4] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - SecureDigital Bus Driver.) -- C:\WINDOWS\system32\Drivers\sdbus.sys [79232]
O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 14/04/2008 - 13:00:00 ----- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\WINDOWS\system32\Drivers\secdrv.sys [20480]
O58 - SDL:[MD5.0F29512CCD6BEAD730039FB4BD2C85CE] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Serial Port Enumerator.) -- C:\WINDOWS\system32\Drivers\serenum.sys [15744]
O58 - SDL:[MD5.93D313C31F7AD9EA2B75F26075413C7C] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de périphérique série.) -- C:\WINDOWS\system32\Drivers\serial.sys [66048]
O58 - SDL:[MD5.0FA803C64DF0914B41F807EA276BF2A6] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Small Form Factor Disk Driver.) -- C:\WINDOWS\system32\Drivers\sffdisk.sys [11904]
O58 - SDL:[MD5.D66D22D76878BF3483A6BE30183FB648] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Small Form Factor MMC Protocol Driver.) -- C:\WINDOWS\system32\Drivers\sffp_mmc.sys [10240]
O58 - SDL:[MD5.C17C331E435ED8737525C86A7557B3AC] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Small Form Factor SD Protocol Driver.) -- C:\WINDOWS\system32\Drivers\sffp_sd.sys [11008]
O58 - SDL:[MD5.8E6B8C671615D126FDC553D1E2DE5562] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - SCSI Floppy Driver.) -- C:\WINDOWS\system32\Drivers\sfloppy.sys [11392]
O58 - SDL:[MD5.866D538EBE33709A5C9F5C62B73B7D14] - 13/04/2008 - 11:46:24 ----- . (.Microsoft Corporation - Microsoft Slip Deframing Filter Minidriver.) -- C:\WINDOWS\system32\Drivers\SLIP.sys [11136]
O58 - SDL:[MD5.017DAECF0ED3AA731313433601EC40FA] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Smard Card Driver Library.) -- C:\WINDOWS\system32\Drivers\smclib.sys [14592]
O58 - SDL:[MD5.489703624DAC94ED943C2ABDA022A1CD] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - 1394 Desktop Camera Driver.) -- C:\WINDOWS\system32\Drivers\sonydcam.sys [25344]
O58 - SDL:[MD5.AB8B92451ECB048A4D1DE7C3FFCB4A9F] - 13/04/2008 - 11:45:08 ----- . (.Microsoft Corporation - Microsoft Kernel Audio Splitter.) -- C:\WINDOWS\system32\Drivers\splitter.sys [6272]
O58 - SDL:[MD5.39626E6DC1FB39434EC40C42722B660A] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de filtre de système de fichiers pour la restauration du.) -- C:\WINDOWS\system32\Drivers\sr.sys [73600]
O58 - SDL:[MD5.47DDFC2F003F7F9F0592C6874962A2E7] - 17/02/2011 - 14:18:03 ----- . (.Microsoft Corporation - Server driver.) -- C:\WINDOWS\system32\Drivers\srv.sys [357888]
O58 - SDL:[MD5.A36EE93698802CD899F98BFD553D8185] - 29/03/2013 - 12:25:47 ----- . (.Avira GmbH - AVIRA SnapShot Driver.) -- C:\WINDOWS\system32\Drivers\ssmdrv.sys [28520]
O58 - SDL:[MD5.3E5D89099DED9E86E5639F411693218F] - 13/04/2008 - 11:45:16 ----- . (.Microsoft Corporation - WDM CODEC Class Device Driver 2.0.) -- C:\WINDOWS\system32\Drivers\stream.sys [49408]
O58 - SDL:[MD5.77813007BA6265C4B6098187E6ED79D2] - 13/04/2008 - 11:46:22 ----- . (.Microsoft Corporation - Microsoft IP Test Driver.) -- C:\WINDOWS\system32\Drivers\StreamIP.sys [15232]
O58 - SDL:[MD5.3941D127AEF12E93ADDF6FE6EE027E0F] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Plug and Play Software Device Enumerator.) -- C:\WINDOWS\system32\Drivers\swenum.sys [4352]
O58 - SDL:[MD5.8CE882BCC6CF8A62F2B2323D95CB3D01] - 13/04/2008 - 11:45:10 ----- . (.Microsoft Corporation - Microsoft GS Wavetable Synthesizer.) -- C:\WINDOWS\system32\Drivers\swmidi.sys [56576]
O58 - SDL:[MD5.8B83F3ED0F1688B4958F77CD6D2BF290] - 13/04/2008 - 12:15:56 ----- . (.Microsoft Corporation - System Audio WDM Filter.) -- C:\WINDOWS\system32\Drivers\sysaudio.sys [60800]
O58 - SDL:[MD5.FD6093E3DECD925F1CFFC8A0DD539D72] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - SCSI Tape Class Driver.) -- C:\WINDOWS\system32\Drivers\tape.sys [14976]
O58 - SDL:[MD5.9AEFA14BD6B182D61E3119FA5F436D3D] - 20/06/2008 - 12:51:12 ----- . (.Microsoft Corporation - TCP/IP Protocol Driver.) -- C:\WINDOWS\system32\Drivers\tcpip.sys [361600]
O58 - SDL:[MD5.4E53BBCC4BE37D7A4BD6EF1098C89FF7] - 11/02/2010 - 13:02:15 ----- . (.Microsoft Corporation - IPv6 driver.) -- C:\WINDOWS\system32\Drivers\tcpip6.sys [226880]
O58 - SDL:[MD5.0539D5E53587F82D1B4FD74C5BE205CF] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - TDI Wrapper.) -- C:\WINDOWS\system32\Drivers\tdi.sys [19072]
O58 - SDL:[MD5.6471A66807F5E104E4885F5B67349397] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Named Pipe Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdpipe.sys [12040]
O58 - SDL:[MD5.C56B6D0402371CF3700EB322EF3AAF61] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - TCP Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdtcp.sys [21896]
O58 - SDL:[MD5.88155247177638048422893737429D9E] - 13/04/2008 - 19:34:54 ----- . (.Microsoft Corporation - Terminal Server Driver.) -- C:\WINDOWS\system32\Drivers\termdd.sys [40840]
O58 - SDL:[MD5.699450901C5CCFD82357CBC531CEDD23] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - TOSHIBA DVD Stream Minidriver.) -- C:\WINDOWS\system32\Drivers\tosdvd.sys [51712]
O58 - SDL:[MD5.D74A8EC75305F1D3CFDE7C7FC1BD62A9] - 14/04/2008 - 13:00:00 ----- . (.Toshiba Corporation - WDM Toshiba Tecra Video Capture Driver.) -- C:\WINDOWS\system32\Drivers\tsbvcap.sys [21376]
O58 - SDL:[MD5.8F861EDA21C05857EB8197300A92501C] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Microsoft Tunnel Interface Driver.) -- C:\WINDOWS\system32\Drivers\tunmp.sys [12288]
O58 - SDL:[MD5.D85938F272D1BCF3DB3A31FC0A048928] - 13/04/2008 - 12:36:42 ----- . (.Microsoft Corporation - MS AGPv3.5 Filter.) -- C:\WINDOWS\system32\Drivers\UAGP35.SYS [44672]
O58 - SDL:[MD5.5787B80C2E3C5E2F56C2A233D91FA2C9] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - UDF File System Driver.) -- C:\WINDOWS\system32\Drivers\udfs.sys [66048]
O58 - SDL:[MD5.402DDC88356B1BAC0EE3DD1580C76A31] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Update Driver.) -- C:\WINDOWS\system32\Drivers\update.sys [384768]
O58 - SDL:[MD5.2A7A8AD9D39A2FAF9D9293B5DAFF3A4B] - 12/02/2013 - 01:32:23 ----- . (.Microsoft Corporation - Remote NDIS USB Driver.) -- C:\WINDOWS\system32\Drivers\usb8023.sys [12928]
O58 - SDL:[MD5.6E421CCC57059B0186C6259CA3B6DFC9] - 13/12/2012 - 12:50:38 ----- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\WINDOWS\system32\Drivers\usbaapl.sys [45056]
O58 - SDL:[MD5.65898A183FBF1D1F7759D5CCB364DCD4] - 17/07/2013 - 01:58:03 ----- . (.Microsoft Corporation - USB Audio Class Driver.) -- C:\WINDOWS\system32\Drivers\usbaudio.sys [60160]
O58 - SDL:[MD5.1C1A47B40C23358245AA8D0443B6935E] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\WINDOWS\system32\Drivers\usbcamd.sys [25600]
O58 - SDL:[MD5.CE97845D2E3F0D274B8BAC1ED07C6149] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\WINDOWS\system32\Drivers\usbcamd2.sys [25728]
O58 - SDL:[MD5.1B611611C28D2DF25BC057D79C6F13FC] - 09/08/2013 - 01:55:07 ----- . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\WINDOWS\system32\Drivers\usbccgp.sys [32384]
O58 - SDL:[MD5.04FE5EF6ED4818EC4839EA5C611A6310] - 09/08/2013 - 01:55:06 ----- . (.Microsoft Corporation - Universal Serial Bus Driver.) -- C:\WINDOWS\system32\Drivers\usbd.sys [5376]
O58 - SDL:[MD5.4BAC8DF07F1D8434FC640E677A62204E] - 18/03/2009 - 12:02:23 ----- . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) -- C:\WINDOWS\system32\Drivers\usbehci.sys [30336]
O58 - SDL:[MD5.1AB3CDDE553B6E064D2E754EFE20285C] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Default Hub Driver for USB.) -- C:\WINDOWS\system32\Drivers\usbhub.sys [59520]
O58 - SDL:[MD5.290913DC4F1125E5A82DE52579A44C43] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\WINDOWS\system32\Drivers\usbintel.sys [15872]
O58 - SDL:[MD5.6DF35CA139C3BC15CC74390ABB114EFE] - 09/08/2013 - 01:55:08 ----- . (.Microsoft Corporation - USB 1.1 & 2.0 Port Driver.) -- C:\WINDOWS\system32\Drivers\usbport.sys [144128]
O58 - SDL:[MD5.A717C8721046828520C9EDF31288FC00] - 13/04/2008 - 11:47:38 ----- . (.Microsoft Corporation - USB Printer driver.) -- C:\WINDOWS\system32\Drivers\usbprint.sys [25856]
O58 - SDL:[MD5.F8EDE2B6928970DCE3D5614C27D9E7F6] - 03/07/2013 - 02:59:02 ----- . (.Microsoft Corporation - USB Scanner Driver.) -- C:\WINDOWS\system32\Drivers\usbscan.sys [14976]
O58 - SDL:[MD5.A32426D9B14A089EAA1D922E0C5801A9] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - USB Mass Storage Class Driver.) -- C:\WINDOWS\system32\Drivers\usbstor.sys [26368]
O58 - SDL:[MD5.26496F9DEE2D787FC3E61AD54821FFE6] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - UHCI USB Miniport Driver.) -- C:\WINDOWS\system32\Drivers\usbuhci.sys [20608]
O58 - SDL:[MD5.813236B1183CFCF289E367BD5DE6E29E] - 17/07/2013 - 01:58:17 ---A- . (.Microsoft Corporation - USB Video Class Driver.) -- C:\WINDOWS\system32\Drivers\usbvideo.sys [123008]
O58 - SDL:[MD5.55E01061C74A8CEFFF58DC36114A8D3F] - 14/04/2008 - 13:00:00 ----- . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINDOWS\system32\Drivers\vdmindvd.sys [58112]
O58 - SDL:[MD5.0D3A8FAFCEACD8B7625CD549757A7DF1] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys [20992]
O58 - SDL:[MD5.3B3EFCDA263B8AC14FDF9CBDD0791B2E] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Generic PCI IDE Bus Driver.) -- C:\WINDOWS\system32\Drivers\viaide.sys [5376]
O58 - SDL:[MD5.E28726B72C46821A28830E077D39A55B] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Video Port Driver.) -- C:\WINDOWS\system32\Drivers\videoprt.sys [81664]
O58 - SDL:[MD5.46DE1126684369BACE4849E4FC8C43CA] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\WINDOWS\system32\Drivers\volsnap.sys [53376]
O58 - SDL:[MD5.E20B95BAEDB550F32DD489265C1DA1F6] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) -- C:\WINDOWS\system32\Drivers\wanarp.sys [34560]
O58 - SDL:[MD5.6768ACF64B18196494413695F0C3A00F] - 13/04/2008 - 12:17:20 ----- . (.Microsoft Corporation - MMSYSTEM Wave/Midi API mapper.) -- C:\WINDOWS\system32\Drivers\wdmaud.sys [83072]
O58 - SDL:[MD5.E14FDC8F4FABBD55CAC6F35192232371] - 03/11/2006 - 15:13:50 ----- . (.Pinnacle Systems - Pinnacle Systems DVC130/170 AV Capture Driver..) -- C:\WINDOWS\system32\Drivers\wisgostrm.sys [226816]
O58 - SDL:[MD5.2F31B7F954BED437F2C75026C65CAF7B] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - WMILIB WMI support library Dll.) -- C:\WINDOWS\system32\Drivers\wmilib.sys [4352]
O58 - SDL:[MD5.CF4DEF1BF66F06964DC0D91844239104] - 18/10/2006 - 19:00:00 ----- . (.Microsoft Corporation - WPD USB Driver.) -- C:\WINDOWS\system32\Drivers\wpdusb.sys [38528]
O58 - SDL:[MD5.6ABE6E225ADB5A751622A9CC3BC19CE8] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Winsock2 IFS Layer.) -- C:\WINDOWS\system32\Drivers\ws2ifsl.sys [12032]
O58 - SDL:[MD5.C98B39829C2BBD34E454150633C62C78] - 13/04/2008 - 11:46:26 ----- . (.Microsoft Corporation - WDM WST Codec Driver.) -- C:\WINDOWS\system32\Drivers\WSTCODEC.SYS [19200]
O58 - SDL:[MD5.F15FEAFFFBB3644CCC80C5DA584E6311] - 28/09/2006 - 17:55:50 ----- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Driver Framework Platform.) -- C:\WINDOWS\system32\Drivers\WudfPf.sys [77568]
O58 - SDL:[MD5.28B524262BCE6DE1F7EF9F510BA3985B] - 28/09/2006 - 18:00:34 ----- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Driver Framework Reflecto.) -- C:\WINDOWS\system32\Drivers\WudfRd.sys [82944]
O58 - SDL:[MD5.6D3ADA4CE95CECA7BCE527A08C4C474E] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\ansi.sys [9037]
O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\country.sys [27097]
O58 - SDL:[MD5.C6D29F29DE7427B1B0775E53E577B623] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\himem.sys [4912]
O58 - SDL:[MD5.582BCDD47CF4B68B5CB528F18E3CB808] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\key01.sys [42809]
O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\keyboard.sys [42537]
O58 - SDL:[MD5.7D30A74B5FB9FE3B245A6CE5FBCD71D5] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\ntdos.sys [27916]
O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\ntdos404.sys [29146]
O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\ntdos411.sys [29370]
O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\ntdos412.sys [29274]
O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\ntdos804.sys [29146]
O58 - SDL:[MD5.CAAA108FD7BF71989946B39704323455] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\ntio.sys [34000]
O58 - SDL:[MD5.6F73F50162DEF60C84B725C18CD9140F] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\ntio404.sys [34560]
O58 - SDL:[MD5.0FDD5E69C1FF3B58043D44F2CC743D45] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\ntio411.sys [35648]
O58 - SDL:[MD5.8842837C4D8311BF8E72BEE8CCC42217] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\ntio412.sys [35424]
O58 - SDL:[MD5.6B56CEB3C6F9D5CD7293DBD9FE23B311] - 14/04/2008 - 13:00:00 ----- . (...) -- C:\WINDOWS\system32\ntio804.sys [34560]
O58 - SDL:[MD5.9A10AACBFDC4922715375FB4065EC930] - 14/04/2008 - 13:00:00 ----- . (.Microsoft Corporation - Watchdog Driver.) -- C:\WINDOWS\system32\watchdog.sys [17664]
O58 - SDL:[MD5.88C4A292F061D6F220EA13BACF7C1163] - 30/10/2013 - 03:51:58 ----- . (.Microsoft Corporation - Pilote Win32 multi-utilisateurs.) -- C:\WINDOWS\system32\win32k.sys [1879168]
~ Drivers: 6 Scanned in 00mn 02s



---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 02/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52edf0ea [124]
O61 - LFC: 02/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ee06d9 [148]
O61 - LFC: 02/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ee11a9 [136]
O61 - LFC: 02/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ee2467 [148]
O61 - LFC: 02/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ee4096 [148]
O61 - LFC: 02/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ee4826 [124]
O61 - LFC: 02/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ee48d7 [136]
O61 - LFC: 02/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ee4978 [156]
O61 - LFC: 02/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ee98cc [124]
O61 - LFC: 02/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52eea0b7 [136]
O61 - LFC: 02/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#local\settings.sol [75]
O61 - LFC: 02/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#s.ytimg.com\settings.sol [81]
O61 - LFC: 02/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2014-02-02 (14-34-59).txt [2376]
O61 - LFC: 02/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\bookmarkbackups\bookmarks-2014-02-02_5.json [3693]
O61 - LFC: 02/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\mimeTypes.rdf [8517]
O61 - LFC: 02/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\search-metadata.json [724]
O61 - LFC: 02/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\ZHP\ZHPDiag.txt [309410] =>.Nicolas Coolman
O61 - LFC: 02/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\vlc\ml.xspf [304]
O61 - LFC: 02/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\vlc\vlcrc [80349]
O61 - LFC: 02/02/2014 - 12:55:11 ---A- . (...) -- C:\Documents and Settings\Max\Bureau\AdwCleaner[S0].txt [2398]
O61 - LFC: 02/02/2014 - 12:55:11 ---A- . (...) -- C:\Documents and Settings\Max\Bureau\ZHPDiag2.txt [309410] =>.Nicolas Coolman
O61 - LFC: 02/02/2014 - 12:55:11 ---A- . (...) -- C:\Documents and Settings\Max\Bureau\ZHPDiag3.txt [309410] =>.Nicolas Coolman
O61 - LFC: 02/02/2014 - 12:55:11 ---A- . (...) -- C:\Documents and Settings\Max\Bureau\ZhpFix pour Max.txt [4174] =>.Nicolas Coolman
O61 - LFC: 02/02/2014 - 12:55:11 ---A- . (...) -- C:\Documents and Settings\Max\Bureau\adwcleaner.exe [1166132]
O61 - LFC: 02/02/2014 - 12:55:12 ---A- . (...) -- C:\Documents and Settings\Max\Cookies\QFSU8UUR.txt [402]
O61 - LFC: 02/02/2014 - 12:55:13 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf [786]
O61 - LFC: 02/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\020ec1aea942d4cade06e8b5844da265.png [7582]
O61 - LFC: 02/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\81cd647c1573f09da6668e7d29b2510d.png [3458]
O61 - LFC: 02/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\8529d9e65bb69adfc961869e337cf2e0.png [15929]
O61 - LFC: 02/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\97a134dfd625cf3ad3124076b00fc235.png [21113]
O61 - LFC: 02/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\d27abbd24a1fbd9565f5334a732e2aef.png [62155]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\1395393_10151907845818680_334441317_n.jpg.lnk [631]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\AdwCleaner[S0].txt.lnk [513]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Echouyoukh H_SSOUNA _ BERRACHI ( Rahimahoum Allah) . Mise e-1.webm.lnk [708]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Echouyoukh H_SSOUNA _ BERRACHI ( Rahimahoum Allah) . Mise e-2.webm.lnk [708]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Echouyoukh H_SSOUNA _ BERRACHI ( Rahimahoum Allah) . Mise e-3.webm.lnk [708]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Echouyoukh H_SSOUNA _ BERRACHI ( Rahimahoum Allah) . Mise e-4.webm.lnk [708]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Echouyoukh H_SSOUNA _ BERRACHI ( Rahimahoum Allah) . Mise e.webm.lnk [702]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Echouyoukh H_SSOUNA _ BERRACHI ( Rahimahoum Allah) . Mise en-1.flv.lnk [708]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Echouyoukh H_SSOUNA _ BERRACHI ( Rahimahoum Allah) . Mise en.flv.lnk [702]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Malûf constanitnois (Ahmed Aouabdia) - YouTube-1.flv.lnk [666]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Malûf constanitnois (Ahmed Aouabdia) - YouTube.flv.lnk [660]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Malûf constanitnois (Ahmed Aouabdia) - YouTube.mp4.lnk [660]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Nouveau dossier.lnk [389]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Pourquoi l_immigration ne peut pas diminuer la pauvreté dans.flv.lnk [702]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Téléchargements.lnk [389]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\ZHPDiag3.txt.lnk [381] =>.Nicolas Coolman
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\renderimg(1).png.lnk [558]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\renderimg.png.lnk [549]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\‫מאור אדרי - תספרו לה maor edri - Tesapru La‬‎ - YouTube.mp4.lnk [875]
O61 - LFC: 02/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\▶ Cheikh Ahmed AOUABDIA Chante ريت القمر قد غاس و سلسلة رمل ماية Mise en ligne par Ammar BEGHDADI. - YouTube.htm.lnk [1148]
O61 - LFC: 03/02/2014 - 12:54:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Adobe\Acrobat\11.0\ReaderMessages [27648]
O61 - LFC: 03/02/2014 - 12:54:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Adobe\Acrobat\11.0\Security\CRLCache\48B76449F3D5FEFA1133AA805E420F0FCA643651.crl [898]
O61 - LFC: 03/02/2014 - 12:54:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Adobe\Acrobat\11.0\Security\CRLCache\A9B8213768ADC68AF64FCC6409E8BE414726687F.crl [37213]
O61 - LFC: 03/02/2014 - 12:54:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Adobe\Acrobat\11.0\Security\addressbook.acrodata [5486]
O61 - LFC: 03/02/2014 - 12:54:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Adobe\Acrobat\11.0\Security\services_rdr.dat [10240]
O61 - LFC: 03/02/2014 - 12:54:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Adobe\Acrobat\11.0\Security\services_rdri.dat [24152]
O61 - LFC: 03/02/2014 - 12:54:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Adobe\Acrobat\11.0\Security\services_rdrk.dat [180]
O61 - LFC: 03/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ef065c [124]
O61 - LFC: 03/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ef1242 [148]
O61 - LFC: 03/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ef1299 [172]
O61 - LFC: 03/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ef3d7c [156]
O61 - LFC: 03/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ef3f32 [148]
O61 - LFC: 03/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ef690a [148]
O61 - LFC: 03/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52ef7eb5 [136]
O61 - LFC: 03/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#audienceinsights.net\settings.sol [90]
O61 - LFC: 03/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#images.fandango.com\settings.sol [89]
O61 - LFC: 03/02/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol [594]
O61 - LFC: 03/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Media Player Classic\default.mpcpl [91]
O61 - LFC: 03/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Microsoft\Internet Explorer\UserData\BNRD8LEQ\oXMLStoreUnit[1].xml [56]
O61 - LFC: 03/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\adblockplus\elemhide.css [2662959]
O61 - LFC: 03/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\addons.json [22946]
O61 - LFC: 03/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\blocklist.xml [112563]
O61 - LFC: 03/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\bookmarkbackups\bookmarks-2014-02-03_5.json [3693]
O61 - LFC: 03/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\cert8.db [212992]
O61 - LFC: 03/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\content-prefs.sqlite [229376]
O61 - LFC: 03/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\cookies.sqlite [1048576]
O61 - LFC: 03/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\dh-media-lists.rdf [520]
O61 - LFC: 03/02/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\dh-smart-names.rdf [82238]
O61 - LFC: 03/02/2014 - 12:55:07 -SHA- . (...) -- C:\Documents and Settings\Max\Application Data\Microsoft\Credentials\S-1-5-21-527237240-573735546-1644491937-1004\Credentials [516]
O61 - LFC: 03/02/2014 - 12:55:07 -SHA- . (...) -- C:\Documents and Settings\Max\Application Data\Microsoft\Internet Explorer\Desktop.htt [2614]
O61 - LFC: 03/02/2014 - 12:55:07 -SHA- . (...) -- C:\Documents and Settings\Max\Application Data\Microsoft\Internet Explorer\UserData\index.dat [32768]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\extensions.json [35945]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\formhistory.sqlite [196608]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\healthreport.sqlite [1376256]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\healthreport\state.json [123]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\key3.db [16384]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\localstore.rdf [21251]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\parent.lock [0]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\permissions.sqlite [65536]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\places.sqlite [10485760]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\prefs.js [64815]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\search.json [14031]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\sessionstore.bak [157080]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\sessionstore.js [101139]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\signons.sqlite [327680]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\urlclassifierkey3.txt [154]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\webapps\webapps.json [2]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\webappsstore.sqlite [4489216]
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\ZHP\Log.txt [54532] =>.Nicolas Coolman
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\ZHP\TestsZHPDiag.txt [3118] =>.Nicolas Coolman
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\ZHP\ZHPFixQuarantine.txt [1984] =>.Nicolas Coolman
O61 - LFC: 03/02/2014 - 12:55:10 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\ZHP\ZHPFix[R1].txt [5711] =>.Nicolas Coolman
O61 - LFC: 03/02/2014 - 12:55:11 ---A- . (...) -- C:\Documents and Settings\Max\Bureau\ZHPFixReport.txt [5711] =>.Nicolas Coolman
O61 - LFC: 03/02/2014 - 12:55:11 ---A- . (...) -- C:\Documents and Settings\Max\Cookies\index.dat [196608]
O61 - LFC: 03/02/2014 - 12:55:12 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Adobe\Acrobat\11.0\Cache\AcroFnt11.lst [7572]
O61 - LFC: 03/02/2014 - 12:55:12 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Adobe\Acrobat\11.0\Cache\RdLang_AcroForm.FRA [1310720]
O61 - LFC: 03/02/2014 - 12:55:12 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Adobe\Acrobat\11.0\Cache\RdLang_Annots.FRA [3030528]
O61 - LFC: 03/02/2014 - 12:55:12 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Adobe\Acrobat\11.0\Cache\RdLang_DigSig.FRA [312320]
O61 - LFC: 03/02/2014 - 12:55:12 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Adobe\Acrobat\11.0\Cache\RdLang_EScript.FRA [73728]
O61 - LFC: 03/02/2014 - 12:55:12 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Adobe\Acrobat\11.0\Cache\RdLang_PPKLite.FRA [1125376]
O61 - LFC: 03/02/2014 - 12:55:12 -SHA- . (...) -- C:\Documents and Settings\Max\IETldCache\index.dat [262144]
O61 - LFC: 03/02/2014 - 12:55:13 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Adobe\Acrobat\11.0\Cache\RdLang_rdlang32.fra [12202496]
O61 - LFC: 03/02/2014 - 12:55:13 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Adobe\Acrobat\11.0\UserCache.bin [74620]
O61 - LFC: 03/02/2014 - 12:55:13 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\ApplicationHistory\hpqgalry.exe.cf8dd223.ini.inuse [0]
O61 - LFC: 03/02/2014 - 12:55:13 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\HP\Digital Imaging\all_skins.xml [181]
O61 - LFC: 03/02/2014 - 12:55:14 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt [0]
O61 - LFC: 03/02/2014 - 12:55:14 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\HP\Digital Imaging\handle.dat [178]
O61 - LFC: 03/02/2014 - 12:55:14 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Identities\{37C53578-45DC-44E0-933E-1D9757654B72}\Microsoft\Outlook Express\Boîte d'envoi.dbx [6744788] =>.Microsoft Corporation
O61 - LFC: 03/02/2014 - 12:55:14 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Identities\{37C53578-45DC-44E0-933E-1D9757654B72}\Microsoft\Outlook Express\Boîte de réception.dbx [106559216] =>.Microsoft Corporation
O61 - LFC: 03/02/2014 - 12:55:14 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Identities\{37C53578-45DC-44E0-933E-1D9757654B72}\Microsoft\Outlook Express\Folders.dbx [74720] =>.Microsoft Corporation
O61 - LFC: 03/02/2014 - 12:55:14 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Identities\{37C53578-45DC-44E0-933E-1D9757654B72}\Microsoft\Outlook Express\Offline.dbx [9656] =>.Microsoft Corporation
O61 - LFC: 03/02/2014 - 12:55:14 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Identities\{37C53578-45DC-44E0-933E-1D9757654B72}\Microsoft\Outlook Express\Pop3uidl.dbx [9404] =>.Microsoft Corporation
O61 - LFC: 03/02/2014 - 12:55:14 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Identities\{37C53578-45DC-44E0-933E-1D9757654B72}\Microsoft\Outlook Express\Éléments envoyés.dbx [25676656] =>.Microsoft Corporation
O61 - LFC: 03/02/2014 - 12:55:14 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Identities\{37C53578-45DC-44E0-933E-1D9757654B72}\Microsoft\Outlook Express\Éléments supprimés.dbx [153530608] =>.Microsoft Corporation
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\_CACHE_CLEAN_ [1]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\safebrowsing\goog-malware-shavar.cache [12]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\safebrowsing\goog-malware-shavar.pset [525738]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\safebrowsing\goog-malware-shavar.sbstore [378368]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\safebrowsing\goog-phish-shavar.cache [12]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\safebrowsing\goog-phish-shavar.pset [891164]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\safebrowsing\goog-phish-shavar.sbstore [661330]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\safebrowsing\test-malware-simple.cache [44]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\safebrowsing\test-malware-simple.pset [16]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\safebrowsing\test-malware-simple.sbstore [232]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\safebrowsing\test-phish-simple.cache [44]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\safebrowsing\test-phish-simple.pset [16]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\safebrowsing\test-phish-simple.sbstore [232]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\startupCache\startupCache.4.little [148624]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\16ff53ca46bb6bf0a947de35058c6d2a.png [67320]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\25da42242745deb9295fab61195348a1.png [3402]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\2d459f9ae3e154203966b3d0897dd821.png [66696]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\2e51b6c7d86cd3727bea46688da031a7.png [3374]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\60b5d17ebc40735b3902c005afd862cf.png [3433]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\639fccbe8f90f9fa003c1fb8d821d596.png [12126]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\737d34616168f50038e95169d5776e63.png [3374]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\b3e0f6621549545993822598d4d5f582.png [12126]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\dba51bcc527ba93f7fe03868747280d5.png [3374]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\thumbnails\e0ebb90a167110558ee7b210109a6d59.png [3433]
O61 - LFC: 03/02/2014 - 12:55:17 ---A- . (...) -- C:\Documents and Settings\Max\Local Settings\Historique\History.IE5\index.dat [786432]
O61 - LFC: 03/02/2014 - 12:55:17 -SHA- . (...) -- C:\Documents and Settings\Max\Local Settings\Historique\History.IE5\MSHist012014012720140203\index.dat [32768]
O61 - LFC: 03/02/2014 - 12:55:17 -SHA- . (...) -- C:\Documents and Settings\Max\Local Settings\Historique\History.IE5\MSHist012014020320140204\index.dat [32768]
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Echouyoukh H_SSOUNA _ BERRACHI ( Rahimahoum Allah) . Mise en-2.flv.lnk [708]
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Mes numérisations.lnk [395]
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Numériser.pdf.lnk [557]
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Pinhas Cohen Zine li tak Allah - YouTube-1.flv.lnk [648]
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Pinhas Cohen Zine li tak Allah - YouTube-2.flv.lnk [648]
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Pinhas Cohen Zine li tak Allah - YouTube.flv.lnk [642]
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\Telechargement Youtube.lnk [405]
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\ZHP.lnk [679] =>.Nicolas Coolman
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\ZHPFixReport.txt.lnk [497] =>.Nicolas Coolman
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\ZHPFix[R1].txt.lnk [906] =>.Nicolas Coolman
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\ZhpFix pour Max.txt.lnk [512] =>.Nicolas Coolman
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\dalma malouf - YouTube.flv.lnk [588]
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\‫מאור אדרי - לתקן את העולם maor edri - Letaken Et Haolam‬‎ -.mp4.lnk [895]
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\‫עומר אדם - מוזיקה‬‎ - YouTube.mp4.lnk [745]
O61 - LFC: 03/02/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\‫עומר אדם - שקט‬‎ - YouTube.mp4.lnk [731]
O61 - LFC: 31/01/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52eb5d2f [124]
O61 - LFC: 31/01/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52eb63fa [148]
O61 - LFC: 31/01/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52eb85cf [148]
O61 - LFC: 31/01/2014 - 12:55:06 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Dropbox\shellext\l\52eb981f [136]
O61 - LFC: 31/01/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2014-01-31 (12-13-24).txt [2338]
O61 - LFC: 31/01/2014 - 12:55:07 ---A- . (...) -- C:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\uqigf7ie.default\bookmarkbackups\bookmarks-2014-01-31_5.json [3693]
O61 - LFC: 31/01/2014 - 12:55:11 ---A- . (...) -- C:\Documents and Settings\Max\Bureau\ZHPDiag.lnk [1528] =>.Nicolas Coolman
O61 - LFC: 31/01/2014 - 12:55:11 ---A- . (...) -- C:\Documents and Settings\Max\Bureau\ZHPFix.lnk [1633] =>.Nicolas Coolman
O61 - LFC: 31/01/2014 - 12:55:14 -SHA- . (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat [32768]
O61 - LFC: 31/01/2014 - 12:55:18 ---A- . (...) -- C:\Documents and Settings\Max\Recent\ZHPDiag.txt.lnk [889] =>.Nicolas Coolman
~ 2 Fichiers cookies (Cookies files)
~ Files: 177 Scanned in 01mn 08s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 17/08/2011 - C:\WINDOWS\system32\drivers\afd.sys (AFD) .(.Microsoft Corporation - Ancillary Function Driver for WinSock.) - LEGACY_AFD
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\alg.exe (ALG) .(.Microsoft Corporation - Application Layer Gateway Service.) - LEGACY_ALG
O64 - Services: CurCS - 19/12/2013 - C:\Program Files\Avira\AntiVir Desktop\sched.exe (AntiVirSchedulerService) .(.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - LEGACY_ANTIVIRSCHEDULERSERVICE
O64 - Services: CurCS - 27/11/2013 - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (AntiVirService) .(.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) - LEGACY_ANTIVIRSERVICE
O64 - Services: CurCS - 07/09/2013 - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Mobile Device) .(.Apple Inc. - MobileDeviceService.) - LEGACY_APPLE_MOBILE_DEVICE
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (AudioSrv) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_AUDIOSRV
O64 - Services: CurCS - 19/12/2013 - C:\WINDOWS\system32\DRIVERS\avgntflt.sys (avgntflt) .(.Avira Operations GmbH & Co. KG - Avira Minifilter Driver.) - LEGACY_AVGNTFLT
O64 - Services: CurCS - 18/06/2013 - C:\WINDOWS\system32\drivers\avgtpx86.sys (avgtp) .(.AVG Technologies - Pas de description.) - LEGACY_AVGTP
O64 - Services: CurCS - 19/12/2013 - C:\WINDOWS\system32\DRIVERS\avipbb.sys (avipbb) .(.Avira Operations GmbH & Co. KG - Avira Driver for Security Enhancement.) - LEGACY_AVIPBB
O64 - Services: CurCS - 27/11/2013 - C:\WINDOWS\system32\DRIVERS\avkmgr.sys (avkmgr) .(.Avira Operations GmbH & Co. KG - Avira Manager Driver.) - LEGACY_AVKMGR
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (BITS) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_BITS
O64 - Services: CurCS - 30/08/2011 - C:\Program Files\Bonjour\mDNSResponder.exe (Bonjour Service) .(.Apple Inc. - Bonjour Service.) - LEGACY_BONJOUR_SERVICE
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\dllhost.exe (COMSysApp) .(.Microsoft Corporation - COM Surrogate.) - LEGACY_COMSYSAPP
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (CryptSvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_CRYPTSVC
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Dhcp) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_DHCP
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Dnscache) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_DNSCACHE
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (ERSvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_ERSVC
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (EventSystem) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_EVENTSYSTEM
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (FastUserSwitchingCompatibility) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_FASTUSERSWITCHINGCOMPATIBILITY
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\fltMgr.sys (FltMgr) .(.Microsoft Corporation - Microsoft Filesystem Filter Manager.) - LEGACY_FLTMGR
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\msgpc.sys (Gpc) .(.Microsoft Corporation - MS General Packet Classifier.) - LEGACY_GPC
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (helpsvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_HELPSVC
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (HidServ) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_HIDSERV
O64 - Services: CurCS - 20/10/2009 - C:\WINDOWS\system32\Drivers\HTTP.sys (HTTP) .(.Microsoft Corporation - HTTP Protocol Stack.) - LEGACY_HTTP
O64 - Services: CurCS - 29/07/2008 - c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (idsvc) .(.Microsoft Corporation - Windows CardSpace.) - LEGACY_IDSVC
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\ipnat.sys (IpNat) .(.Microsoft Corporation - IP Network Address Translator.) - LEGACY_IPNAT
O64 - Services: CurCS - 17/09/2013 - C:\Program Files\iPod\bin\iPodService.exe (iPod Service) .(.Apple Inc. - iPodService Module (32-bit).) - LEGACY_IPOD_SERVICE
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\ipsec.sys (IPSec) .(.Microsoft Corporation - IPSec Driver.) - LEGACY_IPSEC
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (LanmanServer) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_LANMANSERVER
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (LanmanWorkstation) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_LANMANWORKSTATION
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (LmHosts) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_LMHOSTS
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\mrxdav.sys (MRxDAV) .(.Microsoft Corporation - Windows NT WebDav Minirdr.) - LEGACY_MRXDAV
O64 - Services: CurCS - 15/07/2011 - C:\WINDOWS\system32\DRIVERS\mrxsmb.sys (MRxSmb) .(.Microsoft Corporation - Windows NT SMB Minirdr.) - LEGACY_MRXSMB
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\msdtc.exe (MSDTC) .(.Microsoft Corporation - MS DTC console program.) - LEGACY_MSDTC
O64 - Services: CurCS - 21/04/2011 - C:\WINDOWS\system32\Drivers\Mup.sys (Mup) .(.Microsoft Corporation - Multiple UNC Provider driver.) - LEGACY_MUP
O64 - Services: CurCS - 25/11/2011 - C:\Program Files\Nero\Update\NASvc.exe (NAUpdate) .(.Nero AG - NeroUpdate.) - LEGACY_NAUPDATE
O64 - Services: CurCS - 01/12/2011 - C:\WINDOWS\system32\DRIVERS\NBVol.sys (NBVol) .(.Nero AG - Nero Backup Volume Filter Driver for the Di.) - LEGACY_NBVOL
O64 - Services: CurCS - 01/12/2011 - C:\WINDOWS\system32\DRIVERS\NBVolUp.sys (NBVolUp) .(.Nero AG - Nero Backup Volume Upper Filter Driver for.) - LEGACY_NBVOLUP
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\Drivers\NDIS.sys (NDIS) .(.Microsoft Corporation - NDIS 5.1 wrapper driver.) - LEGACY_NDIS
O64 - Services: CurCS - 08/07/2011 - C:\WINDOWS\system32\DRIVERS\ndistapi.sys (NdisTapi) .(.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) - LEGACY_NDISTAPI
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\ndisuio.sys (Ndisuio) .(.Microsoft Corporation - NDIS User mode I/O Driver.) - LEGACY_NDISUIO
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\netbios.sys (NetBIOS) .(.Microsoft Corporation - NetBIOS interface driver.) - LEGACY_NETBIOS
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\netbt.sys (NetBT) .(.Microsoft Corporation - MBT Transport driver.) - LEGACY_NETBT
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Netman) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_NETMAN
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Nla) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_NLA
O64 - Services: CurCS - 10/06/2009 - C:\WINDOWS\system32\nvsvc32.exe (nvsvc) .(.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 186.1.) - LEGACY_NVSVC
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\lsass.exe (PolicyAgent) .(.Microsoft Corporation - LSA Shell (Export Version).) - LEGACY_POLICYAGENT
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\lsass.exe (ProtectedStorage) .(.Microsoft Corporation - LSA Shell (Export Version).) - LEGACY_PROTECTEDSTORAGE
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\rasacd.sys (RasAcd) .(.Microsoft Corporation - RAS Automatic Connection Driver.) - LEGACY_RASACD
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (RasMan) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_RASMAN
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\rdbss.sys (Rdbss) .(.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - LEGACY_RDBSS
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\RDPCDD.sys (RDPCDD) .(.Microsoft Corporation - RDP Miniport.) - LEGACY_RDPCDD
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\lsass.exe (SamSs) .(.Microsoft Corporation - LSA Shell (Export Version).) - LEGACY_SAMSS
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (seclogon) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SECLOGON
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (SENS) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SENS
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (SharedAccess) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SHAREDACCESS
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (ShellHWDetection) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SHELLHWDETECTION
O64 - Services: CurCS - 17/08/2010 - C:\WINDOWS\system32\spoolsv.exe (Spooler) .(.Microsoft Corporation - Spooler SubSystem App.) - LEGACY_SPOOLER
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\sr.sys (sr) .(.Microsoft Corporation - Pilote de filtre de système de fichiers pou.) - LEGACY_SR
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (srservice) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SRSERVICE
O64 - Services: CurCS - 17/02/2011 - C:\WINDOWS\system32\DRIVERS\srv.sys (Srv) .(.Microsoft Corporation - Server driver.) - LEGACY_SRV
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (SSDPSRV) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SSDPSRV
O64 - Services: CurCS - 29/03/2013 - C:\WINDOWS\system32\DRIVERS\ssmdrv.sys (ssmdrv) .(.Avira GmbH - AVIRA SnapShot Driver.) - LEGACY_SSMDRV
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (stisvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_STISVC
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (TapiSrv) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_TAPISRV
O64 - Services: CurCS - 20/06/2008 - C:\WINDOWS\system32\DRIVERS\tcpip.sys (Tcpip) .(.Microsoft Corporation - TCP/IP Protocol Driver.) - LEGACY_TCPIP
O64 - Services: CurCS - 17/12/2013 - C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer9) .(.TeamViewer GmbH - TeamViewer 9.) - LEGACY_TEAMVIEWER9
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (Themes) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_THEMES
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (TrkWks) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_TRKWKS
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\drivers\vga.sys (VgaSave) .(.Microsoft Corporation - VGA/Super VGA Video Driver.) - LEGACY_VGASAVE
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (W32Time) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_W32TIME
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\DRIVERS\wanarp.sys (Wanarp) .(.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - LEGACY_WANARP
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (WebClient) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WEBCLIENT
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (winmgmt) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WINMGMT
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (wuauserv) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WUAUSERV
O64 - Services: CurCS - 28/09/2006 - C:\WINDOWS\system32\DRIVERS\WudfPf.sys (WudfPf) .(.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) - LEGACY_WUDFPF
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (WudfSvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WUDFSVC
O64 - Services: CurCS - 14/04/2008 - C:\WINDOWS\system32\svchost.exe (WZCSVC) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WZCSVC
~ Legacy: 124 Scanned in 00mn 01s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
~ FASS Keys: 10 Scanned in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: <>[HKLM\..\Shell\open\Command] (.Not Key.)
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {8EFD7591-329F-400B-A9B5-6525D5520055} - (Google) - http://www.google.com
~ Keys: Scanned in 00mn 00s



---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (...) -- C:\WINDOWS\system32\appmgmts.dll [0]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\WINDOWS\system32\audiosrv.dll [42496]
O83 - Search Svchost Services: Browser (Browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\system32\browser.dll [78336]
O83 - Search Svchost Services: CryptSvc (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) -- C:\WINDOWS\system32\cryptsvc.dll [62464]
O83 - Search Svchost Services: DMServer (DMServer) . (.Microsoft Corp. - DLL Service gestionnaire de disque logique.) -- C:\WINDOWS\system32\dmserver.dll [24576]
O83 - Search Svchost Services: DHCP (DHCP) . (.Microsoft Corporation - Service client DHCP.) -- C:\WINDOWS\system32\dhcpcsvc.dll [127488]
O83 - Search Svchost Services: ERSvc (ERSvc) . (.Microsoft Corporation - Windows Error Reporting Service.) -- C:\WINDOWS\system32\ersvc.dll [23040]
O83 - Search Svchost Services: EventSystem (EventSystem) . (.Microsoft Corporation - Pas de description.) -- C:\WINDOWS\system32\es.dll [253952]
O83 - Search Svchost Services: FastUserSwitchingCompatibility (FastUserSwitchingCompatibility) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680]
O83 - Search Svchost Services: HidServ (HidServ) . (.Microsoft Corporation - HID Audio Service.) -- C:\WINDOWS\system32\hidserv.dll [21504]
O83 - Search Svchost Services: LanmanServer (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\system32\srvsvc.dll [99840]
O83 - Search Svchost Services: LanmanWorkstation (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) -- C:\WINDOWS\system32\wkssvc.dll [132096]
O83 - Search Svchost Services: Messenger (Messenger) . (.Microsoft Corporation - NT Messenger Service.) -- C:\WINDOWS\system32\msgsvc.dll [33792]
O83 - Search Svchost Services: Netman (Netman) . (.Microsoft Corporation - Gestionnaire de connexions réseau.) -- C:\WINDOWS\system32\netman.dll [198144]
O83 - Search Svchost Services: Nla (Nla) . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll [247808] =>.Microsoft Corporation
O83 - Search Svchost Services: Ntmssvc (Ntmssvc) . (.Microsoft Corporation - Gestionnaire de stockage amovible.) -- C:\WINDOWS\system32\ntmssvc.dll [438272]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\system32\rasauto.dll [88576]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\system32\rasmans.dll [186368]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINDOWS\system32\mprdim.dll [53248]
O83 - Search Svchost Services: Schedule (Schedule) . (.Microsoft Corporation - Moteur du Planificateur de tâches.) -- C:\WINDOWS\system32\schedsvc.dll [194560]
O83 - Search Svchost Services: Seclogon (Seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\WINDOWS\system32\seclogon.dll [18944]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\system32\sens.dll [39424]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\WINDOWS\system32\ipnathlp.dll [332800]
O83 - Search Svchost Services: SRService (SRService) . (.Microsoft Corporation - Service de restauration du système.) -- C:\WINDOWS\system32\srsvc.dll [171520]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\WINDOWS\system32\tapisrv.dll [249856]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680]
O83 - Search Svchost Services: TrkWks (TrkWks) . (.Microsoft Corporation - Distributed Link Tracking Client.) -- C:\WINDOWS\system32\trkwks.dll [90112]
O83 - Search Svchost Services: W32Time (W32Time) . (.Microsoft Corporation - Service de temps Windows.) -- C:\WINDOWS\system32\w32time.dll [178176]
O83 - Search Svchost Services: WZCSVC (WZCSVC) . (.Microsoft Corporation - Service configuration automatique sans fil.) -- C:\WINDOWS\system32\wzcsvc.dll [483840]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [145408]
O83 - Search Svchost Services: wscsvc (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) -- C:\WINDOWS\system32\wscsvc.dll [80896]
O83 - Search Svchost Services: xmlprov (xmlprov) . (.Microsoft Corporation - Network Provisioning Service.) -- C:\WINDOWS\system32\xmlprov.dll [129024]
O83 - Search Svchost Services: napagent (napagent) . (.Microsoft Corporation - Exécution du service Agent de quarantaine.) -- C:\WINDOWS\system32\qagentrt.dll [293376]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\WINDOWS\system32\kmsvc.dll [61440]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\WINDOWS\system32\qmgr.dll [409088]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update AutoUpdate Service.) -- C:\WINDOWS\system32\wuauserv.dll [6656]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\WINDOWS\system32\shsvcs.dll [135680]
O83 - Search Svchost Services: helpsvc (helpsvc) . (.Microsoft Corporation - Microsoft PCHealth Service Holder.) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [38400]
O83 - Search Svchost Services: WmdmPmSN (WmdmPmSN) . (.Microsoft Corporation - Microsoft Media Device Service Provider.) -- C:\WINDOWS\system32\MsPMSNSv.dll [27136]

~ Services: 39 Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.06C7B4716A213B3C927BB64FB4E5F3FB] [SPRF][29/03/2013] (...) -- C:\Documents and Settings\Max\Local Settings\Application Data\fusioncache.dat [126]
[MD5.54DB2B8C60F04C5ADE6D711D47EABA75] [SPRF][02/02/2014] (...) -- C:\Documents and Settings\Max\Bureau\adwcleaner.exe [1166132]
~ Files: 2 Scanned in 00mn 00s



---\\ Enumère les codes produits des logiciels (PUC) (O90)
O90 - PUC: "02DED8BE788AC9A4BBA53F7E25D3BF44" . (.Nero WaveEditor 11 Help (CHM).) -- C:\WINDOWS\Installer\{EB8DED20-A887-4A9C-BB5A-F3E7523DFB44}\NeroHelpIcon.8BC7562A_6065_4ED9_8502_C368ECC0724D
O90 - PUC: "07266D4D7419FDB49964CF2A3B30AAF8" . (.Nero ControlCenter 11 Help (CHM).) -- C:\WINDOWS\Installer\{D4D66270-9147-4BDF-9946-FCA2B303AA8F}\NeroHelpIcon.8BC7562A_6065_4ED9_8502_C368ECC0724D
O90 - PUC: "0B4CB15EE5AECC94FAB3395B6C72CE22" . (.Nero 11 Effects Basic.) -- C:\WINDOWS\Installer\{E51BC4B0-EA5E-49CC-AF3B-93B5C627EC22}\ARPPRODUCTICON.exe
O90 - PUC: "0CC994AB0C215AB409706748B4271185" . (.Nero 11 Kwik Themes 3.) -- C:\WINDOWS\Installer\{BA499CC0-12C0-4BA5-9007-76844B721158}\ARPPRODUCTICON.exe
O90 - PUC: "100CDC2A3B8F46C4E947E2F30AAF9C9D" . (.Nero 11 Video Samples.) -- C:\WINDOWS\Installer\{A2CDC001-F8B3-4C64-9E74-2E3FA0FAC9D9}\ARPPRODUCTICON.exe
O90 - PUC: "1276481B6E8A7C64386BD0FCA7BD2476" . (.Nero Burning ROM 11.) -- C:\WINDOWS\Installer\{B1846721-A8E6-46C7-83B6-0DCF7ADB4267}\ARPPRODUCTICON.exe
O90 - PUC: "14BA0230629081248A6A86CA486EBB39" . (.Nero Recode 11.) -- C:\WINDOWS\Installer\{0320AB41-0926-4218-A8A6-68AC84E6BB93}\ARPPRODUCTICON.exe
O90 - PUC: "17B9FE8F7E355F14E845744B9C97BC83" . (.Nero Backup Drivers.) -- C:\WINDOWS\Installer\{F8EF9B71-53E7-41F5-8E54-47B4C979CB38}\ARPPRODUCTICON.exe
O90 - PUC: "1A273C5F3F04AD940A947FC5ED1977CD" . (.Pinnacle Studio Ultimate Collection Plugins.) -- C:\WINDOWS\Installer\{F5C372A1-40F3-49DA-A049-F75CDE9177DC}\ARPPRODUCTICON.exe
O90 - PUC: "243493A986A4ABE4586A555B954F7E00" . (.Microsoft .NET Framework 1.1 French Language Pack.) -- C:\WINDOWS\Installer\{9A394342-4A68-4EBA-85A6-55B559F4E700}\ndpsetup.ico
O90 - PUC: "276A061B623F4144B90B0A656CB153C7" . (.Nero 11 Cliparts.) -- C:\WINDOWS\Installer\{B160A672-F326-4414-9BB0-A056C61B357C}\ARPPRODUCTICON.exe
O90 - PUC: "344FE94FDB2B01F4A86478FADC9BE0DD" . (.Nero 11 Disc Menus Basic.) -- C:\WINDOWS\Installer\{F49EF443-B2BD-4F10-8A46-87AFCDB90EDD}\ARPPRODUCTICON.exe
O90 - PUC: "383B6DCAB5CE00044A55CC3B804B74EF" . (.Nero 11 Kwik Themes 4.) -- C:\WINDOWS\Installer\{ACD6B383-EC5B-4000-A455-CCB308B447FE}\ARPPRODUCTICON.exe
O90 - PUC: "3ADDCA0F3CD10C34486E349E723C2E7F" . (.ImageScanTool V2.0.2.) -- C:\WINDOWS\Installer\{F0ACDDA3-1DC3-43C0-84E6-43E927C3E2F7}\ARPPRODUCTICON.exe
O90 - PUC: "3FA96F1B5B5B5AC4DA5CA837E86B5E47" . (.Nero 11 Kwik Themes 1.) -- C:\WINDOWS\Installer\{B1F69AF3-B5B5-4CA5-ADC5-8A738EB6E574}\ARPPRODUCTICON.exe
O90 - PUC: "46B5A9879DD95AB419A50FCFA0B1B7EF" . (.Apple Software Update.) -- C:\WINDOWS\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\Installer.ico =>.Apple Inc
O90 - PUC: "46CBB2BA8CA866E4BB3F2ED2E5CAEEAC" . (.Nero BackItUp 11.) -- C:\WINDOWS\Installer\{AB2BBC64-8AC8-4E66-BBF3-E22D5EACEECA}\ARPPRODUCTICON.exe
O90 - PUC: "4AFEBC2D3D2F79E41A17B8DFA6135ACE" . (.Nero Express 11 Help (CHM).) -- C:\WINDOWS\Installer\{D2CBEFA4-F2D3-4E97-A171-8BFD6A31A5EC}\NeroHelpIcon.8BC7562A_6065_4ED9_8502_C368ECC0724D
O90 - PUC: "58FE3D111E364EA47A1C2914DB1BB615" . (.Nero ControlCenter 11.) -- C:\WINDOWS\Installer\{11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}\ARPPRODUCTICON.exe
O90 - PUC: "5A440F64B8EC691489E4B56D25E563D1" . (.Apple Application Support.) -- C:\WINDOWS\Installer\{46F044A5-CE8B-4196-984E-5BD6525E361D}\WinInstall.ico
O90 - PUC: "5ECB44FF81A51504580FCB71D2B76459" . (.Nero CoverDesigner 11.) -- C:\WINDOWS\Installer\{FF44BCE5-5A18-4051-85F0-BC172D7B4695}\ARPPRODUCTICON.exe
O90 - PUC: "63EB6F4A6284AB543A69402F563A6BD1" . (.Nero 11 Kwik Themes 2.) -- C:\WINDOWS\Installer\{A4F6BE36-4826-45BA-A396-04F265A3B61D}\ARPPRODUCTICON.exe
O90 - PUC: "67CF28340018159468851338E426E588" . (.Nero 11 Video Transitions 1.) -- C:\WINDOWS\Installer\{4382FC76-8100-4951-8658-31834E625E88}\ARPPRODUCTICON.exe
O90 - PUC: "68AB67CA7DA76301B744BA0000000010" . (.Adobe Reader XI (11.0.06) - Français.) -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-AB0000000001}\SC_Reader.ico
O90 - PUC: "69FE29508D96B4E4C99C885FE88AF610" . (.Apple Mobile Device Support.) -- C:\WINDOWS\Installer\{0592EF96-69D8-4E4B-9CC9-88F58EA86F01}\Installer.ico
O90 - PUC: "6DDF89E52763EBD4BAB8C2A9B0DE3128" . (.Nero 11 Disc Menus 3.) -- C:\WINDOWS\Installer\{5E98FDD6-3672-4DBE-AB8B-2C9A0BED1382}\ARPPRODUCTICON.exe
O90 - PUC: "7040BB568CC47CD459E2E3FEFD5006A2" . (.Nero Update.) -- C:\WINDOWS\Installer\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}\ARPPRODUCTICON.exe
O90 - PUC: "812418EB91933AE468A8F206CB31C54B" . (.Nero Kwik Media.) -- C:\WINDOWS\Installer\{BE814218-3919-4EA3-868A-2F60BC135CB4}\NeroKwikMedia._63C8A7B0BBE5459F9AC436392B2FF50D.exe
O90 - PUC: "907814B3886DA3E4EBE0D717AF489C84" . (.Nero 11 PiP Effects 1.) -- C:\WINDOWS\Installer\{3B418709-D688-4E3A-BE0E-7D71FA84C948}\ARPPRODUCTICON.exe
O90 - PUC: "94843F0ABA9DDD641BEBBBD06BB0F18E" . (.Nero 11 Disc Menus 1.) -- C:\WINDOWS\Installer\{A0F34849-D9AB-46DD-B1BE-BB0DB60B1FE8}\ARPPRODUCTICON.exe
O90 - PUC: "9824A7D0FC99D8B48B2168EB055A5425" . (.Nero Video 11.) -- C:\WINDOWS\Installer\{0D7A4289-99CF-4B8D-B812-86BE50A54552}\ARPPRODUCTICON.exe
O90 - PUC: "985E2342652631540BFBFE8A3E525D0F" . (.Nero SharedVideoCodecs.) -- C:\WINDOWS\Installer\{2432E589-6256-4513-B0BF-EFA8E325D5F0}\ARPPRODUCTICON.exe
O90 - PUC: "9F1D317077DD1C24C8D7454D972E7E34" . (.Nero SoundTrax 11.) -- C:\WINDOWS\Installer\{0713D1F9-DD77-42C1-8C7D-54D479E2E743}\ARPPRODUCTICON.exe
O90 - PUC: "9FACD4307E696394A97017F2085B81E1" . (.Nero RescueAgent 11.) -- C:\WINDOWS\Installer\{034DCAF9-96E7-4936-9A07-712F80B5181E}\ARPPRODUCTICON.exe
O90 - PUC: "A4EAA01E8B89A024DB390E25C0326D42" . (.Nero Express 11.) -- C:\WINDOWS\Installer\{E10AAE4A-98B8-420A-BD93-E0520C23D624}\ARPPRODUCTICON.exe
O90 - PUC: "A6477F35AA695A94688B95896908AD5C" . (.Nero Burning ROM 11 Help (CHM).) -- C:\WINDOWS\Installer\{53F7746A-96AA-49A5-86B8-59989680DAC5}\NeroHelpIcon.8BC7562A_6065_4ED9_8502_C368ECC0724D
O90 - PUC: "A99EC10D2088C3847AF992B896E14B23" . (.Nero RescueAgent 11 Help (CHM).) -- C:\WINDOWS\Installer\{D01CE99A-8802-483C-A79F-298B691EB432}\NeroHelpIcon.8BC7562A_6065_4ED9_8502_C368ECC0724D
O90 - PUC: "AA7570930388CD34EA0EE4B5F64893BE" . (.Nero SoundTrax 11 Help (CHM).) -- C:\WINDOWS\Installer\{390757AA-8830-43DC-AEE0-4E5B6F8439EB}\NeroHelpIcon.8BC7562A_6065_4ED9_8502_C368ECC0724D
O90 - PUC: "ABFAB76BF9C4AF84496939E3B3520544" . (.QuickTime.) -- C:\WINDOWS\Installer\{B67BAFBA-4C9F-48FA-9496-933E3B255044}\Installer.ico
O90 - PUC: "B2F5519759897D9468219D52080EEDB5" . (.Bonjour.) -- C:\WINDOWS\Installer\{79155F2B-9895-49D7-8612-D92580E0DE5B}\Bonjour.ico
O90 - PUC: "BCAF4108D1D12C8449AA2EE92E6E9BEC" . (.Nero WaveEditor 11.) -- C:\WINDOWS\Installer\{8014FACB-1D1D-48C2-94AA-E29EE2E6B9CE}\ARPPRODUCTICON.exe
O90 - PUC: "C2A3473FF5D56544F889D53FA659C405" . (.Nero 11 Image Samples.) -- C:\WINDOWS\Installer\{F3743A2C-5D5F-4456-8F98-5DF36A954C50}\ARPPRODUCTICON.exe
O90 - PUC: "C911C9FD62F79B54394DC773C2BBAB11" . (.iTunes.) -- C:\WINDOWS\Installer\{DF9C119C-7F26-45B9-93D4-7C372CBBBA11}\Installer.ico
O90 - PUC: "D094391992254CF4B99B6A6DC39075A4" . (.High-Definition Video Playback.) -- C:\WINDOWS\Installer\{9193490D-5229-4FC4-9BB9-A6D63C09574A}\ARPPRODUCTICON.exe
O90 - PUC: "D2B212A5D0414F646B52D2C15A0A5049" . (.Nero 11 Kwik Themes Basic.) -- C:\WINDOWS\Installer\{5A212B2D-140D-46F4-B625-2D1CA5A00594}\ARPPRODUCTICON.exe
O90 - PUC: "D5227AC221BCA264D91D0513E951B85A" . (.Nero 11 PiP Effects Basic.) -- C:\WINDOWS\Installer\{2CA7225D-CB12-462A-9DD1-50319E158BA5}\ARPPRODUCTICON.exe
O90 - PUC: "DA2273F4D791BBD4DBBF2D0F6D773645" . (.LibreOffice 4.1.3.2.) -- C:\WINDOWS\Installer\{4F3722AD-197D-4DBB-BDFB-D2F0D6776354}\soffice.ico
O90 - PUC: "E2FB0A7ACC133E949931255C30BE69D9" . (.Nero Audio Pack 1.) -- C:\WINDOWS\Installer\{A7A0BF2E-31CC-49E3-9913-52C503EB969D}\ARPPRODUCTICON.exe
O90 - PUC: "E3412C555ABFF244A9AF27F60F863FD9" . (.Nero CoverDesigner 11 Help (CHM).) -- C:\WINDOWS\Installer\{55C2143E-FBA5-442F-9AFA-726FF068F39D}\NeroHelpIcon.8BC7562A_6065_4ED9_8502_C368ECC0724D
O90 - PUC: "E7242BA6F81A9084A921925FBEBABBA3" . (.Nero BackItUp 11 Help (CHM).) -- C:\WINDOWS\Installer\{6AB2427E-A18F-4809-9A12-29F5EBABBB3A}\NeroHelpIcon.8BC7562A_6065_4ED9_8502_C368ECC0724D
O90 - PUC: "E73C3CAFBADEA3F41A377A7CC08CF890" . (.Nero Video 11 Help (CHM).) -- C:\WINDOWS\Installer\{FAC3C37E-EDAB-4F3A-A173-A7C70CC88F09}\NeroHelpIcon.8BC7562A_6065_4ED9_8502_C368ECC0724D
O90 - PUC: "E7FF67E4ABEA78C47B88DC745E24B5D9" . (.Skype™ 6.9.) -- C:\WINDOWS\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe
O90 - PUC: "EE5B2FD761C268E4C917688760A88D50" . (.Nero 11 Disc Menus 2.) -- C:\WINDOWS\Installer\{7DF2B5EE-2C16-4E86-9C71-8678068AD805}\ARPPRODUCTICON.exe
O90 - PUC: "EE8E3B972F53DCC4289DA4754F804E94" . (.Nero 11 Platinum.) -- C:\WINDOWS\Installer\{79B3E8EE-35F2-4CCD-82D9-4A57F408E449}\ARPPRODUCTICON.exe
O90 - PUC: "F7AB1B9B70E7DD947A31B593A7B56BB6" . (.Nero Kwik Media Help (CHM).) -- C:\WINDOWS\Installer\{B9B1BA7F-7E07-49DD-A713-5B397A5BB66B}\NeroHelpIcon.BBDB24D3_07A5_496B_AA18_6A3ED03D6698
O90 - PUC: "F8C1DDAAF95D55D47A6267C8172A508A" . (.Pinnacle Studio 14.) -- C:\WINDOWS\Installer\{AADD1C8F-D59F-4D55-A726-768C71A205A8}\Studio.exe
O90 - PUC: "FCE08F75C72EEEE4BA859E17ABEC6293" . (.Nero Recode 11 Help (CHM).) -- C:\WINDOWS\Installer\{57F80ECF-E27C-4EEE-AB58-E971BACE2639}\NeroHelpIcon.8BC7562A_6065_4ED9_8502_C368ECC0724D
O90 - PUC: "FF2B9E104FAD9254C99C12102655717C" . (.nero.prerequisites.msi.) -- C:\WINDOWS\Installer\{01E9B2FF-DAF4-4529-9CC9-2101625517C7}\ARPPRODUCTICON.exe
~ Update Products: 107 Scanned in 00mn 00s



---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.625B300F7E1A9893508C0F1B3A933FEF] [WIS][05/01/2014] (.35mm Film Scanner - ImageScanTool V2.0.2.) -- C:\Windows\Installer\2cab9f.msi [828928]
[MD5.DA40FE1F63394A3D63A271BC18081B6C] [WIS][28/10/2013] (.Skype Technologies S.A. - Skype.) -- C:\Windows\Installer\33ec4.msi [1616896]
~ WIS: 111 Scanned in 00mn 17s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 13/12/2013 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 14/04/2008 225280 | (dmadmin) . (.Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\dmadmin.exe
SS - | Demand 09/05/2011 136120 | (gusvc) . (.Google.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Auto 29/09/2004 69632 | (Pml Driver HPZ12) . (.HP.) - C:\WINDOWS\system32\HPZipm12.exe
SS - | Auto 05/09/2013 171680 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SS - | Auto 10/07/1658 0 | (vToolbarUpdater15.3.0) . (...) - C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe =>Toolbar.AVGSearch

SR - | Auto 19/12/2013 440376 | (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe
SR - | Auto 27/11/2013 440376 | (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
SR - | Auto 07/09/2013 55624 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Demand 17/09/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 25/11/2011 687400 | (NAUpdate) . (.Nero AG.) - C:\Program Files\Nero\Update\NASvc.exe
SR - | Auto 10/06/2009 168004 | (nvsvc) . (.NVIDIA Corporation.) - C:\WINDOWS\system32\nvsvc32.exe
SR - | Auto 17/12/2013 5341536 | (TeamViewer9) . (.TeamViewer GmbH.) - C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe

~ Services: Scanned in 00mn 18s



---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Run by Max at 03/02/2014 12:56:17

device: opened successfully
user: MBR read successfully

Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
1 ntkrnlpa!IofCallDriver[0x804EF200] >> \Device\Harddisk0\DR0[0x89D3CAB8]
3 CLASSPNP[0xB80E8FD7] >> ntkrnlpa!IofCallDriver[0x804EF200] >> \Device\00000066[0x89DB7F18]
5 ACPI[0xB7F7E620] >> ntkrnlpa!IofCallDriver[0x804EF200] >> \Device\Ide\IdeDeviceP0T0L0-3[0x89D3E940]
kernel: MBR read successfully
user & kernel MBR OK

~ MBR: 13 Scanned in 00mn 02s



---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Max at 03/02/2014 12:56:19

********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin

~ MBR: Scanned in 00mn 04s



---\\ Scan Additionnel (O88)
Database Version : 13030 - (25/01/2014)
Clés trouvées (Keys found) : 2
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 1

[HKLM\SYSTEM\CurrentControlSet\Services\vToolbarUpdater15.3.0] =>Toolbar.AVGSearch^
[HKLM\Software\DataMngr] =>Adware.Bandoo
[HKLM\Software\Datamngr] =>PUP.Datamngr^
~ Additionnel Scan: 326768 Items scanned in 00mn 38s



---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blog/show/27583992-pup-datamngr =>PUP.Datamngr
~ http://nicolascoolman.webs.com/apps/blog/show/26611092-adware-bandoo =>Adware.Bandoo
~ MSI: 2 link(s) detected in 00mn 38s



End of the scan (1624 lines in 05mn 37s)(0)

Publicité


Signaler le contenu de ce document

Publicité