cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2014.1.25.26 - Nicolas Coolman (25/01/2014)
~ Lancé par Paméla (06/02/2014 16:56:55)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Désactivée par l'utilisateur
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.16476
MFIE: Mozilla Firefox 26.0 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 8.1, 64-bit (Build 9600)
Windows Server License Manager Script : OK
~ ion : Windows(R) Operating System, OEM_DM channel
Windows ID Activation : OK
~ Windows Partial Key : 6FYQ6
Windows License : OK
~ Windows Remaining Initializations Number : 999
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection du système
Malwarebytes Anti-Malware version 1.75.0.1300
McAfee Security Scan Plus v3.8.130.10
Windows Defender W8

---\\ Logiciels d'optimisation du système
CCleaner v4.10 =>Piriform Ltd

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 12 Plugin
Java 7 Update 17

---\\ Informations sur le système
~ Processor: AMD64 Family 20 Model 2 Stepping 0, AuthenticAMD
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3810 MB (47% free)
System Restore: Activé (Enable)
System drive C: has 144 GB (64%) free of 221 GB

---\\ Mode de connexion au système
~ Computer Name: PC-PAM-GREG
~ User Name: Paméla
~ All Users Names: Paméla, gregory, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Paméla\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Paméla\AppData\Roaming\
~ %Desktop% : C:\Users\Paméla\Desktop\
~ %Favorites% : C:\Users\Paméla\Favorites\
~ %LocalAppData% : C:\Users\Paméla\AppData\Local\
~ %StartMenu% : C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 144 Go of 221 Go)
D: Hard drive, Flash drive, Thumb drive (Free 222 Go of 222 Go)
E: Floppy drive, Flash card reader, USB Key (Free 2 Go of 2 Go)
F: CD-ROM drive (Free 0 Go of 4 Go)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: 49 Scanned in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.63DC38C3E4564B2405D562855643ABA2] - (.Microsoft Corporation - Explorateur Windows.) (.14/11/2013 - 08:37:16.) -- C:\Windows\Explorer.exe [2328872]
[MD5.48CFA7BE561A7BE144C29BB912055016] - (.Microsoft Corporation - Application de démarrage de Windows.) (.22/08/2013 - 10:58:29.) -- C:\Windows\System32\Wininit.exe [144384]
[MD5.9B6678DB9C6A232C5A84D2FDFFF8B0E1] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.18/01/2014 - 14:21:11.) -- C:\Windows\System32\wininet.dll [2334208]
[MD5.7C94FDA3809015B8F2208D2E1C221F17] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.22/08/2013 - 10:55:08.) -- C:\Windows\System32\Winlogon.exe [564736]
[MD5.2F18065618E39AA2E656EE737B71E791] - (.Microsoft Corporation - Bibliothèque de licences.) (.22/08/2013 - 11:39:40.) -- C:\Windows\System32\sppcomapi.dll [447488]
[MD5.239268BAB58EAE9A3FF4E08334C00451] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.22/08/2013 - 14:25:35.) -- C:\Windows\system32\Drivers\AFD.sys [567296]
[MD5.74B14192CF79A72F7536B27CB8814FBD] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.22/08/2013 - 13:43:41.) -- C:\Windows\system32\Drivers\atapi.sys [26464]
[MD5.2FA6510E33F7DEFEC03658B74101A9B9] - (.Microsoft Corporation - CD-ROM File System Driver.) (.22/08/2013 - 12:40:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [88576]
[MD5.C6796EA22B513E3457514D92DCDB1A3D] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.22/08/2013 - 09:46:35.) -- C:\Windows\system32\Drivers\Cdrom.sys [164352]
[MD5.5DB26D7E0216D0BF364A81D3829AD7B9] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.22/08/2013 - 12:38:00.) -- C:\Windows\system32\Drivers\DfsC.sys [134656]
[MD5.03909BDBFF0DCACCABF2B2D4ADEE44DC] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.22/08/2013 - 12:38:38.) -- C:\Windows\system32\Drivers\HDAudBus.sys [78336]
[MD5.84CFC5EFA97D0C965EDE1D56F116A541] - (.Microsoft Corporation - Pilote de port i8042.) (.22/08/2013 - 12:39:15.) -- C:\Windows\system32\Drivers\i8042prt.sys [107520]
[MD5.E23D32BAF152FBE35F18C6A2AB8EF271] - (.Microsoft Corporation - IP Network Address Translator.) (.14/11/2013 - 08:31:09.) -- C:\Windows\system32\Drivers\IpNat.sys [141824]
[MD5.6129EDB793A4255B1E2FB41773AC9D9A] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.14/11/2013 - 08:31:06.) -- C:\Windows\system32\Drivers\MRxSmb.sys [404992]
[MD5.0217532E19A748F0E5D569307363D5FD] - (.Microsoft Corporation - MBT Transport driver.) (.22/08/2013 - 12:37:02.) -- C:\Windows\system32\Drivers\netBT.sys [282624]
[MD5.4412D565C0278C401575E11072C7DCE3] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.22/08/2013 - 14:25:41.) -- C:\Windows\system32\Drivers\ntfs.sys [2011488]
[MD5.764B1121867B2D9B31C491668AC72B2B] - (.Microsoft Corporation - Pilote de port parallèle.) (.22/08/2013 - 12:40:02.) -- C:\Windows\system32\Drivers\Parport.sys [94208]
[MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.22/08/2013 - 12:35:51.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [120832]
[MD5.680C1DAE268B6FB67FA21B389A8B79EF] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.14/11/2013 - 08:16:40.) -- C:\Windows\system32\Drivers\rdpdr.sys [195584]
[MD5.FFF28F9F6823EB1756C60F1649560BBF] - (.Microsoft Corporation - TDI Translation Driver.) (.22/08/2013 - 14:25:35.) -- C:\Windows\system32\Drivers\tdx.sys [107520]
[MD5.9F9CE33B50611A1C61A46B8911E0B30B] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.22/08/2013 - 13:39:15.) -- C:\Windows\system32\Drivers\volsnap.sys [312160]
~ Generic Processes: Scanned in 00mn 01s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/251
~ Mes musiques (My Musics) : 1/7
~ Mes Favoris (My Favorites) : 1/7
~ Mes Documents (My Documents) : 1/75
~ Mon Bureau (My Desktop) : 1/1559
~ Menu demarrer (Programs) : 1/37
~ Hidden Files: Scanned in 00mn 03s



---\\ Processus lancés
[MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.3908]
[MD5.5640B4C10682FBC39C86C8C7A8392B5E] - (.Google Inc. - Google Chrome.) -- C:\Users\Paméla\AppData\Local\Google\Chrome\Application\chrome.exe [866632] [PID.3028]
[MD5.BB4CEE22CFE1C259F5C4279349EB879C] - (.Orange - Assistance Livebox.) -- C:\Program Files (x86)\Orange\Assistance Livebox\AssistanceLivebox.exe [149824] [PID.3544]
[MD5.7A5E3B9111A2253BAE627E2BC9893108] - (.Acer Incorporated - Hotkey Utility.) -- C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe [553616] [PID.2944]
[MD5.F30BD702688CA1F2C28122132D3ECF1A] - (.Microsoft Corporation - Send to OneNote Tool.) -- C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.exe [194224] [PID.2004]
[MD5.12916E0642E92561C98B18A2A2D01B14] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848] [PID.4116]
[MD5.D3AC38E80E928CC61A22650E04423BB8] - (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328] [PID.4124]
[MD5.749949494676218FFA99501F4AA22ECC] - (.OpenOffice.org - OpenOffice.org 3.4.1.) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe [10376704] [PID.4144]
[MD5.4EE367B8B1964160A1F1B80095183D3A] - (.OpenOffice.org - OpenOffice.org 3.4.1.) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin [10368512] [PID.4284]
[MD5.7AE4D6C70C2D7912AB2B4651DF595575] - (.CyberLink - MediaEspresso DeviceDetector.) -- C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [990320] [PID.4876]
[MD5.9EDFB86FAA07BFED3C3D00211FAB6D82] - (.Orange - Assistance Livebox.) -- C:\Program Files (x86)\Orange\Assistance Livebox\dist\ST2.exe [13446464] [PID.3640]
[MD5.CA25CAEEBDBE25D85565877219F684F8] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8339968] [PID.2920]
~ Processes Running: Scanned in 00mn 01s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Preferences
G1 - GCS: Preference [User Data\Default] None
G0 - GCSP: Preference [User Data\Default][HomePage] http://home.sweetim.com =>PUP.SweetIM
G2 - GCE: Preference [User Data\Default] [ahfgeienlihckogmohjhadlkjgocpleb] Store v.0.2 (Activé)
G2 - GCE: Preference [User Data\Default] [booedmolknjekdopkepjjeckmjkdpfgl] Extutil v.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [eemcgdkfndhakfknompkggombfjjjeno] Bookmark Manager v.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [ejdfidgapfiokiphmcjpmmjbdndepoja] Re-Markable v.1.150 (Activé) =>PUP.Re-Markable
G2 - GCE: Preference [User Data\Default] [ennkphjdgehloodpbhlhldgbnhmacadg] Settings v.0.2 (Activé)
G2 - GCE: Preference [User Data\Default] [eooncjejnppfjjklapaamhcdmjbilmde] Delta Toolbar v.1.1 (Désactivé) =>Toolbar.DeltaSearch
G2 - GCE: Preference [User Data\Default] [flpcjncodpafbgdpnkljologafpionhb] Managera v.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [gfdkimpbcpahaombhbimeihdjnejgicl] Feedback v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [jpmbfleldcgkldadpdinhjjopdfpjfjp] Wajam v.1.34 (Activé) =>PUP.Wajam
G2 - GCE: Preference [User Data\Default] [mfehgcgbbipciphmccgaenjidiccnmng] Cloud Print v.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [mgndgikekgjfcpckkfioiadnlibdjbkf] Chrome v.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [mkfokfffehpeedafpekjeddnmnjhmcmk] Norton Identity Protection v.2013.2.1.36 (Désactivé)
G2 - GCE: Preference [User Data\Default] [nkeimhogjdpnpccoofpliimaahmaaome] Hangout Services v.1.0 (Activé)
G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.0 (Activé)
G2 - GCE: Preference [User Data\Default] [npfkoakaabdallkcdbpkkhfilkkngakh] Deezer v.1.3.2 (Activé)
~ Google Browser: 17 Scanned in 00mn 32s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Paméla\AppData\Roaming\Mozilla\Firefox\Profiles\koicdr2x.default\prefs.js
C:\Users\Paméla\AppData\Roaming\Mozilla\Firefox\Profiles\koicdr2x.default\user.js
M3 - MFPP: Plugins - [Paméla] -- C:\Users\Paméla\AppData\Roaming\Mozilla\Firefox\Profiles\koicdr2x.default\searchplugins\conduit-search.xml =>Toolbar.Conduit
M0 - MFSP: prefs.js [Paméla - koicdr2x.default] http://search.conduit.com
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll
P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Users\Paméla\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll
P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Users\Paméla\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll
~ Firefox Browser: 5 Scanned in 00mn 01s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (11.00.9600.16412 (winblue_gdr.130925-1958)) -- C:\Windows\SysWOW64\ieframe.dll
~ IE Browser: 16 Scanned in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: MSS+ Identifier [64Bits] - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} . (.McAfee, Inc. - Quick Browser Identifier for MSS+ Tool.) -- C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll
O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Wajam IE BHO [64Bits] - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} . (.Wajam - Wajam Internet Explorer Add-on.) -- C:\Program Files (x86)\Wajam\IE\priam_bho.dll =>PUP.Wajam
O2 - BHO: URLRedirectionBHO [64Bits] - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.dll
O2 - BHO: Re-Markable [64Bits] - {cc9f5197-891e-4e08-9aaf-bc5e27015495} . (...) -- C:\Program Files (x86)\Re-Markable\150.dll =>PUP.Re-Markable
O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Lync Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} Clé orpheline
O2 - BHO: (no name) [64Bits] - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} Clé orpheline
O2 - BHO: (no name) [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} Clé orpheline
~ BHO: 10 Scanned in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Easy Photo Print - [HKLM]{9421DD08-935F-4701-A9CA-22DF90AC4EA6} . (.SEIKO EPSON CORPORATION / CyCom Technology - Epson Easy Photo Print (TBL x64).) -- C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll
~ Toolbar: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: Acheter en ligne.lnk . (...) -- C:\Program Files (x86)\Accessory Store\StartUrl.exe (.not file.)
O4 - GS\Desktop [Public]: Adobe Download Assistant.lnk . (...) -- C:\Program Files (x86)\Adobe Download Assistant\Adobe Download Assistant.exe
O4 - GS\Desktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>Piriform Ltd
O4 - GS\Desktop [Public]: CyberLink PowerDVD 10.lnk . (.CyberLink Corp. - PowerDVD 10.0.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVDLaunchPolicy.exe
O4 - GS\Desktop [Public]: Epson Easy Photo Print.lnk . (.SEIKO EPSON CORPORATION - Pas de description.) -- C:\Program Files (x86)\Epson Software\Easy Photo Print\EPQuicker.exe
O4 - GS\Desktop [Public]: EPSON Scan.lnk . (.SEIKO EPSON CORP. - EPSON Scan.) -- C:\Windows\twain_32\escndv\escndv.exe
O4 - GS\Desktop [Public]: Google Earth.lnk . (.Google - Google Earth.) -- C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe =>.Google Inc
O4 - GS\Desktop [Public]: Guide d'utilisation EPSON SX235 Series.lnk . (...) -- C:\Program Files (x86)\Epson Software\Epson Manual\EPSON SX235 Series\fr\Useg\index.htm
O4 - GS\Desktop [Public]: Guide réseau EPSON SX235 Series.lnk . (...) -- C:\Program Files (x86)\Epson Software\Epson Manual\EPSON SX235 Series\fr\Netg\index.htm
O4 - GS\Desktop [Public]: Help and Support.lnk - Clé orpheline
O4 - GS\Desktop [Public]: iTunes.lnk . (.Apple Inc. - iTunes.) -- C:\Program Files (x86)\iTunes\iTunes.exe
O4 - GS\Desktop [Public]: Malwarebytes Anti-Malware.lnk . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
O4 - GS\Desktop [Public]: OpenOffice.org 3.4.1.lnk . (.OpenOffice.org - OpenOffice.org 3.4.1.) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
O4 - GS\Desktop [Public]: Skype.lnk . (...) -- C:\WINDOWS\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe
O4 - GS\Desktop [Public]: WildTangent Games App - packardbell.lnk . (.WildTangent - WildTangent Games App.) -- C:\Program Files (x86)\WildTangent Games\App\GameConsole-wt.exe
O4 - GS\Desktop [Public]: Zune.lnk . (...) -- C:\Program Files (x86)\Zune\Zune.exe (.not file.)
O4 - GS\Program [Public]: Adobe Download Assistant.lnk . (...) -- C:\Program Files (x86)\Adobe Download Assistant\Adobe Download Assistant.exe
O4 - GS\Program [Public]: Camera.lnk . (.Microsoft Corporation - Camera.) -- C:\WINDOWS\Camera\Camera.exe
O4 - GS\Program [Public]: Desktop.lnk - Clé orpheline
O4 - GS\Program [Public]: FileManager.lnk . (.Microsoft Corporation - SkyDrive.) -- C:\WINDOWS\FileManager\FileManager.exe
O4 - GS\Program [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\Program [Public]: Packard bell User's Manual.lnk . (...) -- C:\OEM\Preload\Autorun\GUI\Packard bell User's Manual\00\User_Manual.pdf
O4 - GS\Program [Public]: PhotosApp.lnk . (.Microsoft Corporation - Photos.) -- C:\WINDOWS\FileManager\PhotosApp.exe
O4 - GS\Program [Public]: Spotify.lnk . (...) -- C:\Program Files (x86)\Spotify\SpotifyLauncher.exe
O4 - GS\Program [Public]: WildTangent Games App - packardbell.lnk . (.WildTangent - WildTangent Games App.) -- C:\Program Files (x86)\WildTangent Games\App\GameConsole-wt.exe
O4 - GS\Program [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O4 - GS\Program [Public]: Windows Store.lnk . (...) -- C:\WINDOWS\WinStore\WinStore.htm
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Calculatrice de Windows.) -- C:\WINDOWS\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (...) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe (.not file.)
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) -- C:\WINDOWS\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) -- C:\WINDOWS\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture d’écran.) -- C:\WINDOWS\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Magnétophone Windows.) -- C:\WINDOWS\system32\SoundRecorder.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Enregistreur d’actions.) -- C:\WINDOWS\system32\psr.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Pense-bête.) -- C:\WINDOWS\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) -- C:\WINDOWS\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) -- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visionneuse XPS.) -- C:\WINDOWS\system32\xpsrchvw.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) -- C:\WINDOWS\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\QuickLaunch [Paméla]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Users\Paméla\AppData\Local\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch [Paméla]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch [Paméla]: MonAlbumPhoto.lnk . (.monAlbumPhoto - monAlbumPhoto.) -- C:\Program Files (x86)\MonAlbumPhoto\monAlbumphoto.exe
O4 - GS\TaskBar [Paméla]: File Explorer.lnk - Clé orpheline
O4 - GS\TaskBar [Paméla]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Users\Paméla\AppData\Local\Google\Chrome\Application\chrome.exe
O4 - GS\TaskBar [Paméla]: Packard Bell Power Button.lnk . (...) -- C:\Program Files (x86)\Packard Bell\Packard Bell Power Management\ePowerButton.exe (.not file.)
O4 - GS\Program [Paméla]: Create Amazing Presentations.lnk - Clé orpheline
O4 - GS\Program [Paméla]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Accessories [Paméla]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) -- C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\SendTo [Paméla]: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - GS\Desktop [Paméla]: Create Amazing Presentations.lnk - Clé orpheline
O4 - GS\Desktop [Paméla]: PhotoFiltre.lnk . (.Antonio Da Cruz - PhotoFiltre.) -- C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe
O4 - GS\Desktop [Paméla]: Play Free Games.lnk . (...) -- C:\Program Files (x86)\Free Video Converter\fantastic\fantasticInst.exe
O4 - GS\Desktop [Paméla]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Program Files (x86)\ZHPDiag\ZHPhep.exe =>.Nicolas Coolman
O4 - GS\Desktop [Paméla]: ZHPFix.lnk . (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Program Files (x86)\ZHPDiag\ZHPFix\ZHPhep.exe =>.Nicolas Coolman
O4 - GS\QuickLaunch [gregory]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\TaskBar [gregory]: File Explorer.lnk . (...) -- C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Libraries
O4 - GS\TaskBar [gregory]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\TaskBar [gregory]: Packard Bell Power Button.lnk . (...) -- C:\Program Files (x86)\Packard Bell\Packard Bell Power Management\ePowerButton.exe (.not file.)
O4 - GS\Accessories [gregory]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) -- C:\WINDOWS\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Desktop [gregory]: PhotoFiltre.lnk . (.Antonio Da Cruz - PhotoFiltre.) -- C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe
~ Global Startup: 64 Scanned in 00mn 25s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - GS\Startup [Public]: McAfee Security Scan Plus.lnk . (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
O4 - GS\Startup [Paméla]: Envoyer à OneNote.lnk . (.Microsoft Corporation - Send to OneNote Tool.) -- C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.exe
O4 - GS\Startup [Paméla]: OpenOffice.org 3.4.1.lnk . (...) -- C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp
O4 - HKLM\..\Run: [Zune Launcher] . (.Microsoft Corporation - Zune Auto-Launcher.) -- C:\Program Files\Zune\ZuneLauncher.exe
O4 - HKLM\..\Run: [CamserviceExchange] . (.Guillemot Corporation S.A. - Hercules Xtra Controller Main Application.) -- C:\Program Files (x86)\Hercules\Hercules HD Twist\XtrCtrlEx.exe
O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Paméla\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHLE.exe =>.Epson Seiko Corporation
O4 - HKCU\..\Run: [EPLTarget\P0000000000000001] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHLE.exe =>.Epson Seiko Corporation
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =>.Advanced Micro Devices, Inc
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation
O4 - HKLM\..\Wow6432Node\Run: [EEventManager] . (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKUS\S-1-5-21-1682419926-403432926-433631104-1002\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Paméla\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc
O4 - HKUS\S-1-5-21-1682419926-403432926-433631104-1002\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =>.Skype Technologies S.A.
O4 - HKUS\S-1-5-21-1682419926-403432926-433631104-1002\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHLE.exe =>.Epson Seiko Corporation
O4 - HKUS\S-1-5-21-1682419926-403432926-433631104-1002\..\Run: [EPLTarget\P0000000000000001] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHLE.exe =>.Epson Seiko Corporation
~ Application: Scanned in 00mn 00s



---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ IE Control Panel: 1 Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Se&nd to OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll =>.Microsoft Corporation
O9 - Extra button: Lync Click to Call [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\lync.exe (.not file.)
O9 - Extra button: OneNote Lin&ked Notes [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll =>.Microsoft Corporation
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\WINDOWS\system32\napinsp.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\WINDOWS\system32\pnrpnsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\WINDOWS\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\WINDOWS\system32\NLAapi.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll =>.Microsoft Corporation
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
O10 - WLSP:\000000000007\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files (x86)\Bonjour\mdnsNSP.dll
~ Winsock: 7 Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{2F1726DF-2C55-496B-9DAC-85A8AE2BAAB0}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{6EC7F1A4-BCCC-4F34-8914-DFD25FABDEE0}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{2F1726DF-2C55-496B-9DAC-85A8AE2BAAB0}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{6EC7F1A4-BCCC-4F34-8914-DFD25FABDEE0}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - AppInit_DLLs: . (.Conduit - Search Protect by Conduit.) - C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll =>Toolbar.Conduit
~ AppInit DLL: Scanned in 00mn 00s



---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ SSODL: 1 Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY - ABBYY network license server.) - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\System32\atiesrxx.exe
O23 - Service: AMD FUEL Service (AMD FUEL Service) . (.Advanced Micro Devices, Inc. - Service Fusion Utility.) - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: EpsonBidirectionalService (EpsonBidirectionalService) . (.SEIKO EPSON CORPORATION - eEBAPI Core Process module.) - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: MBAMScheduler (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero Update (NAUpdate) . (.Nero AG - NeroUpdate.) - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: Orange update Core Service (Orange update Core Service) . (.Orange SA - Orange Upd@te.) - C:\Program Files (x86)\Orange\OrangeUpdate\Service\OUCore.exe
~ Services: 8 Scanned in 00mn 09s



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Desktop Component: 4 Scanned in 00mn 00s



---\\ Enumère les données de BootExecute (BEX) (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ BEX: 1 Scanned in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1088]
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1092]
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1682419926-403432926-433631104-1002Core.job [1054]
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1682419926-403432926-433631104-1002UA.job [1106]
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Re-Markable Update.job [420] =>PUP.Re-Markable
[MD5.C8C6C0D659734FDBF63F6F421A5416BC] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [257928]
[MD5.97D186CEEDDBBE013AF9309CF778AEEC] [APT] [ALU] (...) -- C:\Program Files (x86)\Packard Bell\Live Updater\updater.exe [3331216]
[MD5.BD0BA490E0300E859DB99DA3AB024371] [APT] [ALUAgent] (...) -- C:\Program Files (x86)\Packard Bell\Live Updater\liveupdater_agent.exe [39568]
[MD5.BB4CEE22CFE1C259F5C4279349EB879C] [APT] [AssistanceLivebox] (.Orange.) -- C:\Program Files (x86)\Orange\Assistance Livebox\AssistanceLivebox.exe [149824]
[MD5.5B1AA494C27CF0BC3B03E8666ACB225E] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [4455704] =>Piriform Ltd
[MD5.7AE4D6C70C2D7912AB2B4651DF595575] [APT] [DeviceDetector] (.CyberLink.) -- C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [990320]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskUserS-1-5-21-1682419926-403432926-433631104-1002Core] (.Google Inc..) -- C:\Users\Paméla\AppData\Local\Google\Update\GoogleUpdate.exe [116648]
[MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskUserS-1-5-21-1682419926-403432926-433631104-1002UA] (.Google Inc..) -- C:\Users\Paméla\AppData\Local\Google\Update\GoogleUpdate.exe [116648]
[MD5.7A5E3B9111A2253BAE627E2BC9893108] [APT] [Hotkey Utility] (.Acer Incorporated.) -- C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe [553616]
[MD5.5659ADFFA101D3AC0C62CED889991357] [APT] [Power Management] (.Acer Incorporated.) -- C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [5294736]
[MD5.C5BC7EA85343DE263A9177A3CC7D4E8F] [APT] [Re-Markable Update] (...) -- C:\Program Files (x86)\Re-Markable\ReMarkableup.exe [251904] =>PUP.Re-Markable
[MD5.00000000000000000000000000000000] [APT] [Test TimeTrigger] (...) -- C:\Users\Paméla\AppData\Local\Temp\Runner.exe (.not file.) [0]
[MD5.8604A437D7D02F522957F69A381CFC26] [APT] [Notification] (.Acer Incorporated.) -- C:\Program Files\Packard Bell\Packard Bell Recovery Management\Notification\Notification.exe [521872]
~ Scheduled Task: 23 Scanned in 00mn 09s



---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation
O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe =>.Microsoft Corporation
O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll
~ Active Setup: 9 Scanned in 00mn 00s



---\\ Pilotes lancés au démarrage du système (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: C:\Windows\System32\drivers\ahcache.sys (ahcache) . (.Microsoft Corporation - Application Compatibility Cache.) - C:\Windows\System32\DRIVERS\ahcache.sys
O41 - Driver: (BasicDisplay) . (.Microsoft Corporation - Microsoft Basic Display Driver.) - C:\Windows\system32\drivers\BasicDisplay.sys
O41 - Driver: (BasicRender) . (.Microsoft Corporation - Microsoft Basic Render Driver.) - C:\Windows\system32\drivers\BasicRender.sys
O41 - Driver: cdrom.inf (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys
O41 - Driver: C:\Windows\System32\drivers\dam.sys (dam) . (.Microsoft Corporation - DAM Kernel Driver.) - C:\Windows\System32\drivers\dam.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (Dfsc) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: mssmbios.inf (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: netnb.inf (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: npsvctrig.inf (npsvctrig) . (.Microsoft Corporation - Named pipe service triggers.) - C:\Windows\system32\drivers\npsvctrig.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\system32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys
~ Drivers: 30 Scanned in 00mn 00s



---\\ Logiciels installés (O42)
O42 - Logiciel: ABBYY FineReader 9.0 Sprint - (.ABBYY.) [HKLM][64Bits] -- ABBYY FineReader 9.0 Sprint
O42 - Logiciel: ABBYY FineReader 9.0 Sprint - (.ABBYY.) [HKLM][64Bits] -- {F9000000-0018-0000-0000-074957833700}
O42 - Logiciel: AMD APP SDK Runtime - (.Advanced Micro Devices Inc..) [HKLM][64Bits] -- {503F672D-6C84-448A-8F8F-4BC35AC83441}
O42 - Logiciel: AMD AVIVO64 Codecs - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {5073FD73-33B5-5056-D2F1-3CECCEE76E37}
O42 - Logiciel: AMD Accelerated Video Transcoding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {E429154B-6C65-2BE9-AC80-60DF73CB9774}
O42 - Logiciel: AMD Catalyst Install Manager - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {19CB64EB-ACFE-681D-B571-A8A3398F1943}
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe AIR
O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {B92C2C6C-F70E-497B-88A7-1FEF9888272B}
O42 - Logiciel: Adobe Download Assistant - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- com.adobe.downloadassistant.AdobeDownloadAssistant
O42 - Logiciel: Adobe Download Assistant - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {5E21B617-F52E-BB10-92F9-C8AB2C799A8A}
O42 - Logiciel: Adobe Flash Player 12 Plugin - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player Plugin
O42 - Logiciel: Agatha Christie - Death on the Nile - (.WildTangent.) [HKLM][64Bits] -- WTA-c88903a3-c66b-4db7-9ddb-dbcf72b0c425
O42 - Logiciel: Aloha TriPeaks - (.WildTangent.) [HKLM][64Bits] -- WTA-8407cb0b-b530-4e8c-90a2-57f45d8a1a5c
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM][64Bits] -- {46F044A5-CE8B-4196-984E-5BD6525E361D}
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM][64Bits] -- {2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}
O42 - Logiciel: Assistance Livebox - (.Orange.) [HKLM][64Bits] -- Assistance Livebox
O42 - Logiciel: Bejeweled 3 - (.WildTangent.) [HKLM][64Bits] -- WTA-e8b8fc2b-1cab-42ff-bba6-60593e92296d
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM][64Bits] -- {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>Piriform Ltd
O42 - Logiciel: Canaux de jeu - (.WildTangent, Inc..) [HKLM][64Bits] -- WildTangentGameProvider-packardbell-main
O42 - Logiciel: Catalyst Control Center - Branding - (.Advanced Micro Devices, Inc..) [HKLM][64Bits] -- {182728B1-8727-4AB3-A1AE-F1ED2C8B1BAC}
O42 - Logiciel: CyberLink MediaEspresso 6.5 - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}
O42 - Logiciel: CyberLink MediaEspresso 6.5 - (.CyberLink Corp..) [HKLM][64Bits] -- {E3739848-5329-48E3-8D28-5BBD6E8BE384}
O42 - Logiciel: CyberLink PowerDVD 10 - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}
O42 - Logiciel: CyberLink PowerDVD 10 - (.CyberLink Corp..) [HKLM][64Bits] -- {DEC235ED-58A4-4517-A278-C41E8DAEAB3B}
O42 - Logiciel: Delicious: Emily's True Love Premium Edition - (.WildTangent.) [HKLM][64Bits] -- WTA-45b9a14b-9979-44fc-a23f-8362d094b013
O42 - Logiciel: EPSON SX235 Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM][64Bits] -- EPSON SX235 Series
O42 - Logiciel: EPSON Scan - (.Seiko Epson Corporation.) [HKLM][64Bits] -- EPSON Scanner
O42 - Logiciel: Epson Easy Photo Print 2 - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {A02D7029-C4EF-44C1-9FD4-C0D3CA518113}
O42 - Logiciel: Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {B2D55EB8-32C5-4B43-9006-9E97DECBA178}
O42 - Logiciel: Epson Event Manager - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {8ED43F7E-A8F6-4898-AF11-B6158F2EDF94}
O42 - Logiciel: EpsonNet Print - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {3E31400D-274E-4647-916C-2CACC3741799}
O42 - Logiciel: Final Drive: Nitro - (.WildTangent.) [HKLM][64Bits] -- WTA-3d8296e0-0cf0-4ac8-ac40-51ae8f4bec5c
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKCU][64Bits] -- Google Chrome
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: Google Earth - (.Google.) [HKLM][64Bits] -- {4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
O42 - Logiciel: Governor of Poker 2 Premium Edition - (.WildTangent.) [HKLM][64Bits] -- WTA-353bd2a3-20f5-4080-8e4d-4fb193f394a1
O42 - Logiciel: Guide d'utilisation EPSON SX235 Series - (...) [HKLM][64Bits] -- EPSON SX235 Series Useg
O42 - Logiciel: Guide réseau EPSON SX235 Series - (...) [HKLM][64Bits] -- EPSON SX235 Series Netg
O42 - Logiciel: Hercules HD Twist - (.Hercules.) [HKLM][64Bits] -- {C4A295C7-E787-48BA-AA35-26781B3D8007}
O42 - Logiciel: Hotkey Utility - (.Packard Bell.) [HKLM][64Bits] -- {A6DC88AD-501A-44BC-884D-57435F972E2C}
O42 - Logiciel: Identity Card - (.Packard Bell.) [HKLM][64Bits] -- {3D9CB654-99AD-4301-89C6-0D12A790767C}
O42 - Logiciel: Java 7 Update 17 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83217017FF}
O42 - Logiciel: Jewel Match 3 - (.WildTangent.) [HKLM][64Bits] -- WTA-db4e8b17-c0d2-4aef-ae7b-0c45826f5b57
O42 - Logiciel: John Deere Drive Green - (.WildTangent.) [HKLM][64Bits] -- WTA-6bcdf05e-cf9c-4ed2-9b9e-9d3b687ead8b
O42 - Logiciel: Live Updater - (.Packard Bell.) [HKLM][64Bits] -- {EE26E302-876A-48D9-9058-3129E5B99999}
O42 - Logiciel: Magic Academy - (.WildTangent.) [HKLM][64Bits] -- WTA-ab8f6b58-a5c5-4b8f-9628-d135d77c4fbf
O42 - Logiciel: Malwarebytes Anti-Malware version 1.75.0.1300 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes' Anti-Malware_is1
O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM][64Bits] -- McAfee Security Scan
O42 - Logiciel: Microsoft SkyDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- SkyDriveSetup.exe =>.Microsoft Corporation
O42 - Logiciel: MonAlbumPhoto - (.MonAlbumPhoto.) [HKLM][64Bits] -- MonAlbumPhoto_is1
O42 - Logiciel: Mozilla Firefox 26.0 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 26.0 (x86 fr)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService
O42 - Logiciel: Nero 12 Essentials OEM.a01 - (.Nero AG.) [HKLM][64Bits] -- {9BF0D9FE-9893-4647-81B9-17B7BEA4E6FD}
O42 - Logiciel: Nero BackItUp - (.Nero AG.) [HKLM][64Bits] -- {E70B2F2C-94D1-4287-B5B0-CBBE618E2652}
O42 - Logiciel: Nero BackItUp 12 Essentials OEM.a01 - (.Nero AG.) [HKLM][64Bits] -- {B2B0EC73-AD4A-4716-A3DE-CEA8440B309B}
O42 - Logiciel: Nero BackItUp Help (CHM) - (.Nero AG.) [HKLM][64Bits] -- {EF0D1292-8FC1-41BE-9740-DBC134F66415}
O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM][64Bits] -- {ABC88553-8770-4B97-B43E-5A90647A5B63}
O42 - Logiciel: Nero ControlCenter Help (CHM) - (.Nero AG.) [HKLM][64Bits] -- {C994C746-C6D0-4EBA-B09E-DF7B18381B69}
O42 - Logiciel: Nero Core Components - (.Nero AG.) [HKLM][64Bits] -- {BEBEE34D-84A2-4EDD-8BEA-96CC54371263}
O42 - Logiciel: Nero Express - (.Nero AG.) [HKLM][64Bits] -- {848A7C68-0ADC-4193-8A89-2CEA78E56A0C}
O42 - Logiciel: Nero Express Help (CHM) - (.Nero AG.) [HKLM][64Bits] -- {0708FF30-78C0-47B0-81F0-C84604DC769C}
O42 - Logiciel: Nero Launcher - (.Nero AG.) [HKLM][64Bits] -- {0E4630AF-0AB7-440E-A978-1A78FC4F43B9}
O42 - Logiciel: Nero RescueAgent - (.Nero AG.) [HKLM][64Bits] -- {A2D43081-CF7B-4637-A9F3-E2651AA5C4A8}
O42 - Logiciel: Nero RescueAgent Help (CHM) - (.Nero AG.) [HKLM][64Bits] -- {0B311221-05A5-4766-8D03-7A6446794156}
O42 - Logiciel: Nero Update - (.Nero AG.) [HKLM][64Bits] -- {65BB0407-4CC8-4DC7-952E-3EEFDF05602A}
O42 - Logiciel: Office 15 Click-to-Run Extensibility Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008C-0000-0000-0000000FF1CE}
O42 - Logiciel: Office 15 Click-to-Run Licensing Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008F-0000-1000-0000000FF1CE}
O42 - Logiciel: Office 15 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-008C-040C-0000-0000000FF1CE}
O42 - Logiciel: OpenOffice.org 3.4.1 - (.Apache Software Foundation.) [HKLM][64Bits] -- {7DA1C06F-C913-46C7-8A0F-DA2CBA17EA1D}
O42 - Logiciel: Orange update - (.Orange.) [HKLM][64Bits] -- OrangeUpdateManager
O42 - Logiciel: Packard Bell Power Management - (.Packard Bell.) [HKLM][64Bits] -- {91F52DE4-B789-42B0-9311-A349F10E5479}
O42 - Logiciel: Packard Bell Recovery Management - (.Packard Bell.) [HKLM][64Bits] -- {07F2005A-8CAC-4A4B-83A2-DA98A722CA61}
O42 - Logiciel: Penguins! - (.WildTangent.) [HKLM][64Bits] -- WTA-4d3be20a-33c3-45fd-b41e-8d41f83b7a1c
O42 - Logiciel: PhotoFiltre - (...) [HKCU][64Bits] -- PhotoFiltre
O42 - Logiciel: Plants vs. Zombies - Game of the Year - (.WildTangent.) [HKLM][64Bits] -- WTA-ef03db26-06df-460e-88ac-dca5d8de0bdd
O42 - Logiciel: Polar Bowler - (.WildTangent.) [HKLM][64Bits] -- WTA-54ec1bf9-3c12-4360-9ecd-2fc76c04bad9
O42 - Logiciel: Re-Markable - (.Re-Markable Software.) [HKLM][64Bits] -- ff0a387a-a0e9-4be8-8758-c80d49bbdb14 =>PUP.Re-Markable
O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: Realtek USB 2.0 Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {96AE7E41-E34E-47D0-AC07-1091A8127911}
O42 - Logiciel: RentASoft Image Converter v2.3 - (.RentASoft.com.) [HKLM][64Bits] -- RentASoft Image Converter_is1
O42 - Logiciel: Search Protect - (.Conduit.) [HKLM][64Bits] -- SearchProtect =>Toolbar.Conduit
O42 - Logiciel: Skype™ 6.5 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}
O42 - Logiciel: Spotify - (.Spotify AB.) [HKLM][64Bits] -- Spotify
O42 - Logiciel: Tales of Lagoona - (.WildTangent.) [HKLM][64Bits] -- WTA-46f65947-ac2f-4628-b599-b50b4c26021e
O42 - Logiciel: Update Installer for WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App
O42 - Logiciel: VisualBee for Microsoft PowerPoint - (.VisualBee.com.) [HKCU][64Bits] -- VisualBee for Microsoft PowerPoint =>Adware.VisualBeeToolbar
O42 - Logiciel: Wajam - (.Wajam.) [HKLM][64Bits] -- Wajam =>PUP.Wajam
O42 - Logiciel: WildTangent Games - (.WildTangent.) [HKLM][64Bits] -- WildTangent wildgames Master Uninstall
O42 - Logiciel: WildTangent Games App - (.WildTangent.) [HKLM][64Bits] -- {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-packardbell
O42 - Logiciel: WinRAR 5.01 (32-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver
O42 - Logiciel: Windows Mobile Device Updater Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {F2CB8C3C-9C9E-4FAB-9067-655601C5F748}
O42 - Logiciel: Zuma's Revenge - (.WildTangent.) [HKLM][64Bits] -- WTA-f37f31dd-383b-4566-a6c7-2f8d45a37a1d
O42 - Logiciel: Zune - (.Microsoft Corporation.) [HKLM][64Bits] -- Zune
O42 - Logiciel: Zune - (.Microsoft Corporation.) [HKLM][64Bits] -- {9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}
O42 - Logiciel: Zune Language Pack (CHS) - (.Microsoft Corporation.) [HKLM][64Bits] -- {2A9DFFD8-4E09-4B91-B957-454805B0D7C4}
O42 - Logiciel: Zune Language Pack (CHT) - (.Microsoft Corporation.) [HKLM][64Bits] -- {A5A53EA8-A11E-49F0-BDF5-AE536426A31A}
O42 - Logiciel: Zune Language Pack (CSY) - (.Microsoft Corporation.) [HKLM][64Bits] -- {A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}
O42 - Logiciel: Zune Language Pack (DAN) - (.Microsoft Corporation.) [HKLM][64Bits] -- {8B112338-2B08-4851-AF84-E7CAD74CEB32}
O42 - Logiciel: Zune Language Pack (DEU) - (.Microsoft Corporation.) [HKLM][64Bits] -- {BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}
O42 - Logiciel: Zune Language Pack (ELL) - (.Microsoft Corporation.) [HKLM][64Bits] -- {3589A659-F732-4E65-A89A-5438C332E59D}
O42 - Logiciel: Zune Language Pack (ESP) - (.Microsoft Corporation.) [HKLM][64Bits] -- {6B33492E-FBBC-4EC3-8738-09E16E395A10}
O42 - Logiciel: Zune Language Pack (FIN) - (.Microsoft Corporation.) [HKLM][64Bits] -- {B4870774-5F3A-46D9-9DFE-06FB5599E26B}
O42 - Logiciel: Zune Language Pack (FRA) - (.Microsoft Corporation.) [HKLM][64Bits] -- {C68D33B1-0204-4EBE-BC45-A6E432B1D13A}
O42 - Logiciel: Zune Language Pack (HUN) - (.Microsoft Corporation.) [HKLM][64Bits] -- {C6BE19C6-B102-4038-B2A6-1C313872DBB4}
O42 - Logiciel: Zune Language Pack (IND) - (.Microsoft Corporation.) [HKLM][64Bits] -- {92ECE3F9-591E-4C12-8A62-B9FCE38BF646}
O42 - Logiciel: Zune Language Pack (ITA) - (.Microsoft Corporation.) [HKLM][64Bits] -- {C5D37FFA-7483-410B-982B-91E93FD3B7DA}
O42 - Logiciel: Zune Language Pack (JPN) - (.Microsoft Corporation.) [HKLM][64Bits] -- {D8A781C9-3892-4E2E-9320-480CF896CFBB}
O42 - Logiciel: Zune Language Pack (KOR) - (.Microsoft Corporation.) [HKLM][64Bits] -- {51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}
O42 - Logiciel: Zune Language Pack (MSL) - (.Microsoft Corporation.) [HKLM][64Bits] -- {76BA306B-2AA0-47C0-AB6B-F313AB56C136}
O42 - Logiciel: Zune Language Pack (NLD) - (.Microsoft Corporation.) [HKLM][64Bits] -- {6740BCB0-5863-47F4-80F4-44F394DE4FE2}
O42 - Logiciel: Zune Language Pack (NOR) - (.Microsoft Corporation.) [HKLM][64Bits] -- {5DEFD397-4012-46C3-B6DA-E8013E660772}
O42 - Logiciel: Zune Language Pack (PLK) - (.Microsoft Corporation.) [HKLM][64Bits] -- {8960A0A1-BB5A-479E-92CF-65AB9D684B43}
O42 - Logiciel: Zune Language Pack (PTB) - (.Microsoft Corporation.) [HKLM][64Bits] -- {07EEE598-5F21-4B57-B40B-46592625B3D9}
O42 - Logiciel: Zune Language Pack (PTG) - (.Microsoft Corporation.) [HKLM][64Bits] -- {5C93E291-A1CC-4E51-85C6-E194209FCDB4}
O42 - Logiciel: Zune Language Pack (RUS) - (.Microsoft Corporation.) [HKLM][64Bits] -- {57C51D56-B287-4C11-9192-EC3C46EF76A4}
O42 - Logiciel: Zune Language Pack (SVE) - (.Microsoft Corporation.) [HKLM][64Bits] -- {6EB931CD-A7DA-4A44-B74A-89C8EB50086F}
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM][64Bits] -- {D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}
~ Logic: 74 Scanned in 00mn 01s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\ABBYY]
[HKCU\Software\ATI]
[HKCU\Software\AppDataLow\Software\JavaSoft]
[HKCU\Software\AppDataLow\Software\Re_Markable] =>PUP.Re-Markable
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Conduit] =>Toolbar.Conduit
[HKCU\Software\CyberLink]
[HKCU\Software\EPSON]
[HKCU\Software\Facebook]
[HKCU\Software\Google]
[HKCU\Software\Hercules]
[HKCU\Software\IM Providers]
[HKCU\Software\InstallCore] =>Adware.InstallCore
[HKCU\Software\JavaSoft]
[HKCU\Software\KasperskyLab]
[HKCU\Software\Lake]
[HKCU\Software\Local AppWizard-Generated Applications]
[HKCU\Software\MAP-DN]
[HKCU\Software\MCAFEE]
[HKCU\Software\Macromedia]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\ODBC]
[HKCU\Software\OEM]
[HKCU\Software\OpenOffice.org]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\Realtek]
[HKCU\Software\RegisteredApplications]
[HKCU\Software\Skype]
[HKCU\Software\Softonic] =>Toolbar.Conduit
[HKCU\Software\Symantec]
[HKCU\Software\TeleCharger]
[HKCU\Software\Trolltech]
[HKCU\Software\VB and VBA Program Settings]
[HKCU\Software\Visualbee] =>Adware.VisualBeeToolbar
[HKCU\Software\Wajam] =>PUP.Wajam
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\Wow6432Node]
[HKCU\Software\ZebHelpProcess Helper]
[HKCU\Software\mozilla]
[HKLM\Software\AMD]
[HKLM\Software\ATI Technologies]
[HKLM\Software\ATI]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Cyberlink]
[HKLM\Software\DTS]
[HKLM\Software\Dolby]
[HKLM\Software\EPSON]
[HKLM\Software\EnigmaSoftwareGroup]
[HKLM\Software\EpsonNet]
[HKLM\Software\GEAR Software]
[HKLM\Software\Hercules]
[HKLM\Software\IM Providers]
[HKLM\Software\Intel]
[HKLM\Software\Khronos]
[HKLM\Software\Knowles]
[HKLM\Software\Macromedia]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\ODBC]
[HKLM\Software\OEM]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\RTLSetup]
[HKLM\Software\Realtek Semiconductor Corp.]
[HKLM\Software\Realtek]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\SRS Labs]
[HKLM\Software\SonicFocus]
[HKLM\Software\Waves Audio]
[HKLM\Software\Wow6432Node\ABBYY]
[HKLM\Software\Wow6432Node\AMD]
[HKLM\Software\Wow6432Node\ATI Technologies]
[HKLM\Software\Wow6432Node\ATI]
[HKLM\Software\Wow6432Node\Adobe]
[HKLM\Software\Wow6432Node\AdwCleaner]
[HKLM\Software\Wow6432Node\Apple Computer, Inc.]
[HKLM\Software\Wow6432Node\Apple Inc.]
[HKLM\Software\Wow6432Node\Bunndle]
[HKLM\Software\Wow6432Node\Classes]
[HKLM\Software\Wow6432Node\Clients]
[HKLM\Software\Wow6432Node\CyberLink]
[HKLM\Software\Wow6432Node\EPSON]
[HKLM\Software\Wow6432Node\EpsonNet]
[HKLM\Software\Wow6432Node\Google]
[HKLM\Software\Wow6432Node\Hercules]
[HKLM\Software\Wow6432Node\IM Providers]
[HKLM\Software\Wow6432Node\Intel]
[HKLM\Software\Wow6432Node\JavaSoft]
[HKLM\Software\Wow6432Node\JreMetrics]
[HKLM\Software\Wow6432Node\KasperskyLab]
[HKLM\Software\Wow6432Node\Khronos]
[HKLM\Software\Wow6432Node\Lake]
[HKLM\Software\Wow6432Node\MAP-DN]
[HKLM\Software\Wow6432Node\Macromedia]
[HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware]
[HKLM\Software\Wow6432Node\McAfee.com]
[HKLM\Software\Wow6432Node\MozillaPlugins]
[HKLM\Software\Wow6432Node\Mozilla]
[HKLM\Software\Wow6432Node\Nero]
[HKLM\Software\Wow6432Node\ODBC]
[HKLM\Software\Wow6432Node\OEM]
[HKLM\Software\Wow6432Node\OpenOffice.org]
[HKLM\Software\Wow6432Node\Orange]
[HKLM\Software\Wow6432Node\Policies]
[HKLM\Software\Wow6432Node\Realtek Semiconductor Corp.]
[HKLM\Software\Wow6432Node\Realtek]
[HKLM\Software\Wow6432Node\RegisteredApplications]
[HKLM\Software\Wow6432Node\RentASoft]
[HKLM\Software\Wow6432Node\SEIKO EPSON CORPORATION]
[HKLM\Software\Wow6432Node\Skype]
[HKLM\Software\Wow6432Node\Sony Corporation]
[HKLM\Software\Wow6432Node\Symantec]
[HKLM\Software\Wow6432Node\VBMZ] =>PUP.Duuqu
[HKLM\Software\Wow6432Node\Visualbee] =>Adware.VisualBeeToolbar
[HKLM\Software\Wow6432Node\WildTangent]
[HKLM\Software\Wow6432Node\WinRAR]
[HKLM\Software\Wow6432Node\Wow6432Node]
[HKLM\Software\Wow6432Node\mozilla.org]
[HKLM\Software\Wow6432Node]
~ Key Software: 330 Scanned in 00mn 01s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 16/03/2013 - 09:56:21 - [173,313] ----D C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
O43 - CFD: 03/04/2013 - 14:47:55 - [0,079] ----D C:\Program Files (x86)\Adobe
O43 - CFD: 03/04/2013 - 14:47:57 - [2,913] ----D C:\Program Files (x86)\Adobe Download Assistant
O43 - CFD: 13/09/2012 - 14:20:33 - [2,145] ----D C:\Program Files (x86)\AMD APP
O43 - CFD: 13/09/2012 - 14:20:34 - [0,389] ----D C:\Program Files (x86)\AMD AVT
O43 - CFD: 13/09/2012 - 14:20:27 - [55,273] ----D C:\Program Files (x86)\ATI Technologies
O43 - CFD: 15/12/2013 - 09:13:26 - [0,602] ----D C:\Program Files (x86)\Bonjour
O43 - CFD: 18/01/2014 - 14:47:49 - [278,033] ----D C:\Program Files (x86)\Common Files
O43 - CFD: 13/09/2012 - 14:31:59 - [348,979] ----D C:\Program Files (x86)\CyberLink
O43 - CFD: 16/03/2013 - 09:47:33 - [7,906] ----D C:\Program Files (x86)\epson
O43 - CFD: 16/03/2013 - 09:50:27 - [177,186] ----D C:\Program Files (x86)\Epson Software
O43 - CFD: 27/05/2013 - 10:33:30 - [1,995] ----D C:\Program Files (x86)\Free Video Converter
O43 - CFD: 18/12/2013 - 21:55:39 - [253,488] ----D C:\Program Files (x86)\Google
O43 - CFD: 15/07/2013 - 09:19:42 - [69,273] ----D C:\Program Files (x86)\Hercules
O43 - CFD: 15/07/2013 - 09:19:42 - [79,337] --H-D C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 18/01/2014 - 14:21:38 - [6,104] ----D C:\Program Files (x86)\Internet Explorer
O43 - CFD: 07/01/2014 - 21:28:02 - [184,756] ----D C:\Program Files (x86)\iTunes
O43 - CFD: 14/03/2013 - 11:56:12 - [121,972] ----D C:\Program Files (x86)\Java
O43 - CFD: 03/05/2013 - 08:57:22 - [13,376] ----D C:\Program Files (x86)\Malwarebytes' Anti-Malware
O43 - CFD: 24/02/2013 - 09:10:26 - [0,262] ----D C:\Program Files (x86)\Microsoft Office
O43 - CFD: 24/02/2013 - 09:11:06 - [5,397] ----D C:\Program Files (x86)\Microsoft SkyDrive =>.Microsoft Corporation
O43 - CFD: 18/01/2014 - 14:47:49 - [7,797] ----D C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 03/01/2014 - 11:52:43 - [102,166] ----D C:\Program Files (x86)\MonAlbumPhoto
O43 - CFD: 30/12/2013 - 18:35:35 - [51,044] ----D C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 30/12/2013 - 18:35:38 - [0,216] ----D C:\Program Files (x86)\Mozilla Maintenance Service
O43 - CFD: 18/01/2014 - 14:15:37 - [0,025] ----D C:\Program Files (x86)\MSBuild
O43 - CFD: 02/08/2012 - 14:19:52 - [318,437] ----D C:\Program Files (x86)\Nero
O43 - CFD: 08/04/2013 - 13:54:04 - [288,773] ----D C:\Program Files (x86)\OpenOffice.org 3
O43 - CFD: 15/12/2013 - 09:13:35 - [147,887] ----D C:\Program Files (x86)\Orange
O43 - CFD: 13/09/2012 - 14:48:06 - [7,604] ----D C:\Program Files (x86)\Packard Bell
O43 - CFD: 17/04/2013 - 07:24:27 - [3,529] ----D C:\Program Files (x86)\PhotoFiltre
O43 - CFD: 28/01/2014 - 15:26:08 - [1,145] ----D C:\Program Files (x86)\Re-Markable =>PUP.Re-Markable
O43 - CFD: 13/09/2012 - 14:24:37 - [34,354] ----D C:\Program Files (x86)\Realtek
O43 - CFD: 18/01/2014 - 14:15:37 - [36,661] ----D C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 25/03/2013 - 10:37:48 - [3,668] ----D C:\Program Files (x86)\RentASoft
O43 - CFD: 16/01/2014 - 06:19:51 - [35,729] ----D C:\Program Files (x86)\SearchProtect =>Toolbar.Conduit
O43 - CFD: 06/07/2013 - 17:25:41 - [18,985] R---D C:\Program Files (x86)\Skype
O43 - CFD: 13/09/2012 - 14:28:53 - [42,601] ----D C:\Program Files (x86)\Spotify
O43 - CFD: 13/09/2012 - 14:47:55 - [0] ----D C:\Program Files (x86)\Symantec
O43 - CFD: 02/08/2012 - 14:22:27 - [2,444] ----D C:\Program Files (x86)\SymSilent
O43 - CFD: 13/09/2012 - 14:25:16 - [0] --H-D C:\Program Files (x86)\Temp
O43 - CFD: 26/12/2013 - 15:55:56 - [1,336] ----D C:\Program Files (x86)\Wajam =>PUP.Wajam
O43 - CFD: 02/08/2012 - 14:18:01 - [533,370] ----D C:\Program Files (x86)\WildGames
O43 - CFD: 18/01/2014 - 13:10:33 - [18,070] ----D C:\Program Files (x86)\WildTangent Games
O43 - CFD: 14/11/2013 - 08:54:00 - [1,011] ----D C:\Program Files (x86)\Windows Defender
O43 - CFD: 14/11/2013 - 08:13:28 - [5,449] ----D C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 18/01/2014 - 14:47:55 - [3,148] ----D C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 22/08/2013 - 16:36:33 - [0,211] ----D C:\Program Files (x86)\Windows Multimedia Platform
O43 - CFD: 22/08/2013 - 16:36:30 - [7,175] ----D C:\Program Files (x86)\Windows NT
O43 - CFD: 14/11/2013 - 08:13:28 - [5,118] ----D C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 22/08/2013 - 16:36:33 - [0,211] ----D C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 18/01/2014 - 14:47:55 - [0] -SH-D C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 22/08/2013 - 16:36:30 - [0] ----D C:\Program Files (x86)\WindowsPowerShell
O43 - CFD: 03/01/2014 - 12:47:50 - [4,614] ----D C:\Program Files (x86)\WinRAR
O43 - CFD: 06/02/2014 - 16:56:29 - [17,260] ----D C:\Program Files (x86)\ZHPDiag =>.Nicolas Coolman
O43 - CFD: 16/03/2013 - 09:53:21 - [7,724] ----D C:\Program Files (x86)\Common Files\ABBYY
O43 - CFD: 30/01/2014 - 12:48:15 - [46,039] ----D C:\Program Files (x86)\Common Files\Adobe AIR
O43 - CFD: 07/01/2014 - 21:27:28 - [96,844] ----D C:\Program Files (x86)\Common Files\Apple
O43 - CFD: 13/09/2012 - 14:20:34 - [2,238] ----D C:\Program Files (x86)\Common Files\ATI Technologies
O43 - CFD: 24/02/2013 - 09:09:26 - [0,013] ----D C:\Program Files (x86)\Common Files\DESIGNER
O43 - CFD: 16/03/2013 - 10:15:06 - [4,129] ----D C:\Program Files (x86)\Common Files\EPSON
O43 - CFD: 18/01/2014 - 14:28:25 - [3,665] ----D C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 14/03/2013 - 11:57:14 - [1,184] ----D C:\Program Files (x86)\Common Files\Java
O43 - CFD: 18/01/2014 - 14:47:48 - [42,559] ----D C:\Program Files (x86)\Common Files\Microsoft Shared
O43 - CFD: 02/08/2012 - 14:19:36 - [20,044] ----D C:\Program Files (x86)\Common Files\Nero
O43 - CFD: 22/08/2013 - 16:36:33 - [0,003] ----D C:\Program Files (x86)\Common Files\Services
O43 - CFD: 01/04/2013 - 19:23:08 - [1,904] ----D C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 16/04/2013 - 06:46:23 - [0] ----D C:\Program Files (x86)\Common Files\Symantec Shared
O43 - CFD: 14/11/2013 - 08:13:28 - [8,924] ----D C:\Program Files (x86)\Common Files\System
O43 - CFD: 03/03/2013 - 19:54:31 - [42,763] ----D C:\Program Files (x86)\Common Files\Wise Installation Wizard
O43 - CFD: 07/01/2014 - 21:28:04 - [2,774] ----D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
O43 - CFD: 16/03/2013 - 09:53:21 - [1,837] ----D C:\ProgramData\ABBYY
O43 - CFD: 03/04/2013 - 14:48:02 - [0] ----D C:\ProgramData\Adobe
O43 - CFD: 03/01/2014 - 11:53:55 - [43,326] ----D C:\ProgramData\albumphoto
O43 - CFD: 13/09/2012 - 14:20:35 - [0,835] ----D C:\ProgramData\AMD
O43 - CFD: 07/01/2014 - 21:23:56 - [34,570] ----D C:\ProgramData\Apple
O43 - CFD: 07/01/2014 - 21:27:28 - [67,828] ----D C:\ProgramData\Apple Computer
O43 - CFD: 22/08/2013 - 15:45:52 - [0] -SH-D C:\ProgramData\Application Data
O43 - CFD: 14/03/2013 - 11:57:22 - [0] ----D C:\ProgramData\Ask
O43 - CFD: 13/09/2012 - 14:23:19 - [0] ----D C:\ProgramData\ATI
O43 - CFD: 19/01/2014 - 20:48:28 - [9,649] ----D C:\ProgramData\AVAST Software
O43 - CFD: 13/09/2012 - 14:47:56 - [0,040] ----D C:\ProgramData\boost_interprocess
O43 - CFD: 11/02/2013 - 20:19:02 - [0] -SH-D C:\ProgramData\Bureau
O43 - CFD: 13/09/2012 - 14:34:49 - [0] ----D C:\ProgramData\CLSK
O43 - CFD: 10/03/2013 - 09:12:15 - [0,071] ----D C:\ProgramData\CyberLink
O43 - CFD: 22/08/2013 - 15:45:52 - [0] -SH-D C:\ProgramData\Desktop
O43 - CFD: 22/08/2013 - 15:45:52 - [0] -SH-D C:\ProgramData\Documents
O43 - CFD: 15/05/2013 - 21:08:35 - [8,379] ----D C:\ProgramData\EPSON
O43 - CFD: 19/01/2014 - 16:52:41 - [177,002] ----D C:\ProgramData\Kaspersky Lab Setup Files
O43 - CFD: 04/03/2013 - 07:03:52 - [22,277] ----D C:\ProgramData\Malwarebytes
O43 - CFD: 30/12/2013 - 18:43:10 - [0,008] ----D C:\ProgramData\McAfee
O43 - CFD: 30/12/2013 - 18:43:10 - [0,001] ----D C:\ProgramData\McAfee Security Scan
O43 - CFD: 11/02/2013 - 20:19:02 - [0] -SH-D C:\ProgramData\Menu Démarrer
O43 - CFD: 18/01/2014 - 14:48:05 - [697,440] -S--D C:\ProgramData\Microsoft
O43 - CFD: 24/02/2013 - 09:10:29 - [0] ----D C:\ProgramData\Microsoft SkyDrive =>.Microsoft Corporation
O43 - CFD: 11/02/2013 - 20:19:02 - [0] -SH-D C:\ProgramData\Modèles
O43 - CFD: 30/12/2013 - 18:35:37 - [0] ----D C:\ProgramData\Mozilla
O43 - CFD: 11/03/2013 - 18:16:57 - [2,354] ----D C:\ProgramData\Nero
O43 - CFD: 20/04/2013 - 06:03:52 - [0,023] ----D C:\ProgramData\Norton
O43 - CFD: 16/04/2013 - 06:44:22 - [16,152] ----D C:\ProgramData\NortonInstaller
O43 - CFD: 12/02/2013 - 05:46:20 - [2,322] ----D C:\ProgramData\OEM
O43 - CFD: 15/12/2013 - 09:18:39 - [0,993] ----D C:\ProgramData\Orange
O43 - CFD: 02/08/2012 - 14:18:34 - [0,009] ----D C:\ProgramData\Packard Bell
O43 - CFD: 18/01/2014 - 14:48:06 - [0,038] ----D C:\ProgramData\PRICache
O43 - CFD: 18/01/2014 - 14:54:34 - [0,004] ----D C:\ProgramData\regid.1991-06.com.microsoft
O43 - CFD: 26/12/2013 - 16:11:13 - [7,763] ----D C:\ProgramData\Samsung
O43 - CFD: 19/01/2014 - 21:33:06 - [31,540] ----D C:\ProgramData\Skype
O43 - CFD: 22/08/2013 - 15:45:52 - [0] -SH-D C:\ProgramData\Start Menu
O43 - CFD: 14/03/2013 - 11:57:16 - [0] ----D C:\ProgramData\Sun
O43 - CFD: 13/09/2012 - 14:47:55 - [0] ----D C:\ProgramData\Symantec
O43 - CFD: 13/09/2012 - 14:32:13 - [0,702] ----D C:\ProgramData\Temp
O43 - CFD: 22/08/2013 - 15:45:52 - [0] -SH-D C:\ProgramData\Templates
O43 - CFD: 16/03/2013 - 09:51:14 - [0,003] ----D C:\ProgramData\UDL
O43 - CFD: 28/01/2014 - 15:31:27 - [28,243] ----D C:\ProgramData\VisualBee =>Adware.VisualBeeToolbar
O43 - CFD: 24/09/2013 - 14:56:32 - [1700,515] ----D C:\ProgramData\WildTangent
O43 - CFD: 03/04/2013 - 14:46:55 - [0,128] ----D C:\Users\Paméla\AppData\Roaming\Adobe
O43 - CFD: 08/01/2014 - 12:51:14 - [67,785] ----D C:\Users\Paméla\AppData\Roaming\Apple Computer
O43 - CFD: 23/12/2013 - 12:58:56 - [0] ----D C:\Users\Paméla\AppData\Roaming\ATI
O43 - CFD: 27/01/2014 - 16:46:20 - [0,057] ----D C:\Users\Paméla\AppData\Roaming\BankPerfect
O43 - CFD: 08/01/2014 - 19:34:12 - [0,011] ----D C:\Users\Paméla\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
O43 - CFD: 19/02/2013 - 15:13:10 - [0,002] ----D C:\Users\Paméla\AppData\Roaming\CyberLink
O43 - CFD: 24/06/2013 - 14:09:14 - [0,008] ----D C:\Users\Paméla\AppData\Roaming\Epson
O43 - CFD: 15/12/2013 - 09:14:51 - [0,008] ----D C:\Users\Paméla\AppData\Roaming\fr.orange.assistancelivebox =>.Orange Corporation
O43 - CFD: 28/04/2013 - 12:58:16 - [0,001] ----D C:\Users\Paméla\AppData\Roaming\FreeVideoConverter
O43 - CFD: 11/02/2013 - 20:26:30 - [0] ----D C:\Users\Paméla\AppData\Roaming\Identities
O43 - CFD: 16/03/2013 - 09:44:37 - [0] ----D C:\Users\Paméla\AppData\Roaming\InstallShield
O43 - CFD: 11/02/2013 - 20:31:10 - [0,072] ----D C:\Users\Paméla\AppData\Roaming\Macromedia
O43 - CFD: 04/03/2013 - 07:03:57 - [2,198] ----D C:\Users\Paméla\AppData\Roaming\Malwarebytes
O43 - CFD: 06/02/2014 - 14:14:52 - [43,158] -S--D C:\Users\Paméla\AppData\Roaming\Microsoft
O43 - CFD: 30/12/2013 - 18:36:03 - [18,941] ----D C:\Users\Paméla\AppData\Roaming\Mozilla
O43 - CFD: 11/03/2013 - 18:18:05 - [0,041] ----D C:\Users\Paméla\AppData\Roaming\Nero
O43 - CFD: 08/04/2013 - 13:55:49 - [12,396] ----D C:\Users\Paméla\AppData\Roaming\OpenOffice.org
O43 - CFD: 17/04/2013 - 10:02:50 - [0,001] ----D C:\Users\Paméla\AppData\Roaming\PhotoFiltre
O43 - CFD: 27/07/2013 - 08:58:31 - [5,203] ----D C:\Users\Paméla\AppData\Roaming\Skype
O43 - CFD: 19/01/2014 - 15:54:44 - [0] ----D C:\Users\Paméla\AppData\Roaming\uTorrent =>P2P.µTorrent
O43 - CFD: 18/01/2014 - 13:09:52 - [4,768] ----D C:\Users\Paméla\AppData\Roaming\WildTangent
O43 - CFD: 03/03/2013 - 13:48:50 - [0] ----D C:\Users\Paméla\AppData\Roaming\WinRAR
O43 - CFD: 06/02/2014 - 16:58:18 - [0,017] ----D C:\Users\Paméla\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 16/03/2013 - 09:55:10 - [1,866] ----D C:\Users\Paméla\AppData\Local\ABBYY
O43 - CFD: 30/12/2013 - 19:10:30 - [0,004] ----D C:\Users\Paméla\AppData\Local\Adobe
O43 - CFD: 23/12/2013 - 12:59:14 - [0] ----D C:\Users\Paméla\AppData\Local\AMD
O43 - CFD: 07/01/2014 - 21:24:10 - [0] ----D C:\Users\Paméla\AppData\Local\Apple
O43 - CFD: 07/01/2014 - 21:28:15 - [9,324] ----D C:\Users\Paméla\AppData\Local\Apple Computer
O43 - CFD: 18/01/2014 - 14:36:28 - [0] -SH-D C:\Users\Paméla\AppData\Local\Application Data
O43 - CFD: 23/12/2013 - 12:58:56 - [0,058] ----D C:\Users\Paméla\AppData\Local\ATI
O43 - CFD: 27/01/2014 - 16:11:10 - [0] ----D C:\Users\Paméla\AppData\Local\CrashDumps
O43 - CFD: 19/02/2013 - 15:12:12 - [0,105] ----D C:\Users\Paméla\AppData\Local\Cyberlink
O43 - CFD: 16/01/2014 - 07:56:22 - [0] ----D C:\Users\Paméla\AppData\Local\Diagnostics
O43 - CFD: 26/12/2013 - 16:00:54 - [116,569] ----D C:\Users\Paméla\AppData\Local\Downloaded Installations
O43 - CFD: 28/01/2014 - 15:25:34 - [0,029] ----D C:\Users\Paméla\AppData\Local\emaze
O43 - CFD: 27/01/2014 - 17:02:04 - [9,843] ----D C:\Users\Paméla\AppData\Local\Facebook
O43 - CFD: 02/04/2013 - 15:28:57 - [979,861] ----D C:\Users\Paméla\AppData\Local\Google
O43 - CFD: 18/01/2014 - 14:36:28 - [0] -SH-D C:\Users\Paméla\AppData\Local\Historique
O43 - CFD: 30/12/2013 - 19:11:13 - [0] ----D C:\Users\Paméla\AppData\Local\Macromedia
O43 - CFD: 02/02/2014 - 10:56:22 - [421,038] ----D C:\Users\Paméla\AppData\Local\Microsoft
O43 - CFD: 30/12/2013 - 18:36:03 - [132,982] ----D C:\Users\Paméla\AppData\Local\Mozilla
O43 - CFD: 24/01/2014 - 23:16:40 - [454,730] ----D C:\Users\Paméla\AppData\Local\Packages
O43 - CFD: 18/02/2013 - 08:55:54 - [0,001] ----D C:\Users\Paméla\AppData\Local\Programs
O43 - CFD: 22/09/2013 - 13:06:47 - [0,144] ----D C:\Users\Paméla\AppData\Local\SearchProtect =>Toolbar.Conduit
O43 - CFD: 06/02/2014 - 16:58:06 - [24,332] ----D C:\Users\Paméla\AppData\Local\Temp
O43 - CFD: 18/01/2014 - 14:36:28 - [0] -SH-D C:\Users\Paméla\AppData\Local\Temporary Internet Files
O43 - CFD: 01/03/2013 - 13:07:39 - [0,001] ----D C:\Users\Paméla\AppData\Local\VirtualStore
O43 - CFD: 28/01/2014 - 15:35:13 - [66,863] ----D C:\Users\Paméla\AppData\Local\VisualBeeClient =>Adware.VisualBeeToolbar
O43 - CFD: 28/01/2014 - 15:31:37 - [58,420] ----D C:\Users\Paméla\AppData\Local\VisualBeeExe =>Adware.VisualBeeToolbar
O43 - CFD: 26/12/2013 - 15:55:37 - [0,054] ----D C:\Users\Paméla\AppData\Local\Wajam =>PUP.Wajam
O43 - CFD: 22/08/2013 - 16:36:32 - [0,004] R---D C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
O43 - CFD: 22/08/2013 - 16:36:32 - [0,001] R---D C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 18/01/2014 - 21:11:20 - [0] R---D C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 26/02/2013 - 13:51:19 - [0] ----D C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
O43 - CFD: 18/01/2014 - 14:54:32 - [0,002] ----D C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
O43 - CFD: 22/08/2013 - 16:36:32 - [0] ----D C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 18/01/2014 - 14:39:07 - [0,003] ----D C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Orange
O43 - CFD: 17/04/2013 - 07:24:27 - [0] ----D C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre
O43 - CFD: 27/01/2014 - 16:44:38 - [0,002] R---D C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 18/01/2014 - 14:39:08 - [0,006] R---D C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
O43 - CFD: 18/01/2014 - 14:54:32 - [0,006] ----D C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam =>PUP.Wajam
O43 - CFD: 18/01/2014 - 14:54:32 - [0,004] ----D C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
~ Program Folder: 177 Scanned in 00mn 39s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.4AF18C0564DCC589B49EA045A87D5769] - 06/02/2014 - 14:39:26 ---A- . (...) -- C:\Windows\PFRO.log [3540]
O44 - LFC:[MD5.7F41DDDE7B765656C6E5EBC0D8428056] - 06/02/2014 - 14:41:40 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.A4955BC3696B0FB4C5FF7322B0F67A62] - 06/02/2014 - 14:44:10 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1824010]
O44 - LFC:[MD5.B560562D1AE4B63656FE06CDDD210C06] - 06/02/2014 - 14:44:10 ---A- . (...) -- C:\Windows\System32\perfc009.dat [135394]
O44 - LFC:[MD5.3329072F455356565669B3DA7D8538A6] - 06/02/2014 - 14:44:10 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [159206]
O44 - LFC:[MD5.B47DA8763BD9DC4CF8353B50C1544330] - 06/02/2014 - 14:44:10 ---A- . (...) -- C:\Windows\System32\perfh009.dat [722278]
O44 - LFC:[MD5.1597ADC3EF6EB2F9331733F5508801BC] - 06/02/2014 - 14:44:10 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [811108]
O44 - LFC:[MD5.65C4DFCC4318C7C8A409DF029B5D6D82] - 06/02/2014 - 16:55:10 ---A- . (...) -- C:\Windows\WindowsUpdate.log [998644]
~ Files: 8 Scanned in 00mn 08s



---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.5AA5B9BA8DDBD543ACE7CD9E73D9EC68] - 01/02/2014 - 01:08:18 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-9F989E84.pf
O45 - LFCP:[MD5.AEA510A38768B1493594BB99E32D612F] - 01/02/2014 - 06:40:22 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-1FF3403D.pf
O45 - LFCP:[MD5.1876AD358ED53369D7760E893AE1CDFB] - 02/02/2014 - 11:01:36 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-A3EE2396.pf
O45 - LFCP:[MD5.4FF414649A50FA3E6D3975F5838ED36D] - 02/02/2014 - 12:01:28 ---A- - C:\Windows\Prefetch\CLEANMGR.EXE-413FC387.pf
O45 - LFCP:[MD5.8286D05563BD45DF79E2A8CB19013632] - 02/02/2014 - 12:01:30 ---A- - C:\Windows\Prefetch\DISMHOST.EXE-EFF6A7C2.pf
O45 - LFCP:[MD5.FF26EC77E3382F64C33D161867B74444] - 02/02/2014 - 12:01:33 ---A- - C:\Windows\Prefetch\DISMHOST.EXE-A90A224F.pf
O45 - LFCP:[MD5.008883006B71B3AF72C5A4C8E62D3AC6] - 02/02/2014 - 12:13:55 ---A- - C:\Windows\Prefetch\WERFAULT.EXE-9D32D7FF.pf
O45 - LFCP:[MD5.9075D6F0DBAB641989A4786AE0F92E6B] - 02/02/2014 - 12:17:49 ---A- - C:\Windows\Prefetch\WERMGR.EXE-326255D1.pf
O45 - LFCP:[MD5.D494F58914E74E48039EB4635F888AD6] - 02/02/2014 - 13:45:56 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-B4921C3D.pf
O45 - LFCP:[MD5.5E5B70EDA3652A9D2FF5D3DD9D2785AF] - 02/02/2014 - 17:15:18 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-448C3B90.pf
O45 - LFCP:[MD5.B7C2C621306F1A2582E96CFEA9F288DA] - 02/02/2014 - 20:11:31 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-04D1BC96.pf
O45 - LFCP:[MD5.A7B74AAF640DC8249AB251F94284B5B3] - 02/02/2014 - 20:12:05 ---A- - C:\Windows\Prefetch\Op-EXPLORER.EXE-03C49D11-000000F5.pf
O45 - LFCP:[MD5.310B390E4FFC3BDC7A4080958B317BB2] - 02/02/2014 - 20:13:11 ---A- - C:\Windows\Prefetch\CONTROL.EXE-5BCB0217.pf
O45 - LFCP:[MD5.709EA5BEFA5EBDB2935095628F1E5030] - 02/02/2014 - 20:13:53 ---A- - C:\Windows\Prefetch\DFRGUI.EXE-9271D6BF.pf
O45 - LFCP:[MD5.251FEB90A1EF03D5ACB7BBDFB58368D2] - 03/02/2014 - 10:24:33 ---A- - C:\Windows\Prefetch\E_IUCHLE.EXE-CA0F76D5.pf
O45 - LFCP:[MD5.D84EFA1034D2986FFEBE1B28593B3A14] - 03/02/2014 - 10:24:33 ---A- - C:\Windows\Prefetch\PCAUI.EXE-A64155AC.pf
O45 - LFCP:[MD5.DEF63A5D33EEF8AD57427F62D48414F9] - 03/02/2014 - 10:37:30 ---A- - C:\Windows\Prefetch\EPOWERBUTTON.EXE-80D380BE.pf
O45 - LFCP:[MD5.CC3BD4B9279B601C8E768A573CCC34DE] - 03/02/2014 - 10:54:18 ---A- - C:\Windows\Prefetch\DELEGATE_EXECUTE.EXE-B5E985EB.pf
O45 - LFCP:[MD5.ACF7368D136F06C7907EF5430C713F7C] - 03/02/2014 - 10:54:24 ---A- - C:\Windows\Prefetch\OUSOFTWAREMANAGER.EXE-CC5E0AE9.pf
O45 - LFCP:[MD5.33C6277CEB78BC428B78622D531BF0EF] - 03/02/2014 - 10:54:28 ---A- - C:\Windows\Prefetch\OUINDICATOR.EXE-F9467004.pf
O45 - LFCP:[MD5.0EF67B0B7AC9E375BC05FBEED8731AA8] - 03/02/2014 - 10:59:07 ---A- - C:\Windows\Prefetch\JUCHECK.EXE-3F4853CB.pf
O45 - LFCP:[MD5.8D62BAE2008C230A636E601638E93F92] - 03/02/2014 - 11:22:23 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-FB1CDFA7.pf
O45 - LFCP:[MD5.58D8925C2683DCEE8DB3CB4019429839] - 03/02/2014 - 11:22:23 ---A- - C:\Windows\Prefetch\SKYDRIVE.EXE-0DBB4667.pf
O45 - LFCP:[MD5.7388E4DED4757DB504FBFC0239305BF8] - 03/02/2014 - 11:22:27 ---A- - C:\Windows\Prefetch\SDIAGNHOST.EXE-D8BC1DC6.pf
O45 - LFCP:[MD5.511B85DAA0C44768CFBCA2D6B0AC44D7] - 03/02/2014 - 17:48:46 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-E5221F10.pf
O45 - LFCP:[MD5.92A95D906C19A6E42FFCC33186CAF688] - 03/02/2014 - 19:51:20 ---A- - C:\Windows\Prefetch\AgCx_SC1.db.trx
O45 - LFCP:[MD5.09837C8FFB1C066CAF4EA64F24E414B4] - 03/02/2014 - 19:52:20 ---A- - C:\Windows\Prefetch\AgCx_SC1.db
O45 - LFCP:[MD5.0FB2EB4CF3E54584BDDC56695C58811D] - 03/02/2014 - 21:48:58 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-465FAC7E.pf
O45 - LFCP:[MD5.031BF891937EEFBDCFD420C0885240DF] - 04/02/2014 - 04:09:50 ---A- - C:\Windows\Prefetch\SETUP.EXE-F3FBBF71.pf
O45 - LFCP:[MD5.532AF120C0C7ED53876368D4175D286C] - 04/02/2014 - 04:09:58 ---A- - C:\Windows\Prefetch\32.0.1700.107_32.0.1700.102_C-CC3BD970.pf
O45 - LFCP:[MD5.F2817DF79641C77E900331B7F5B9496A] - 04/02/2014 - 04:10:03 ---A- - C:\Windows\Prefetch\SETUP.EXE-D2B9B8C7.pf
O45 - LFCP:[MD5.B9D5A02ED305824C1778CAD77C9BC11F] - 04/02/2014 - 06:26:44 ---A- - C:\Windows\Prefetch\FLASHPLAYERPLUGIN_11_9_900_17-195BD8CE.pf
O45 - LFCP:[MD5.7912B18500365277AB8266F2FC5B5BC8] - 04/02/2014 - 12:42:15 ---A- - C:\Windows\Prefetch\JAVAWS.EXE-596738CE.pf
O45 - LFCP:[MD5.68CB19651CC696C71F48BC182E3BFC80] - 04/02/2014 - 12:42:17 ---A- - C:\Windows\Prefetch\JAVAW.EXE-9BCFFCC7.pf
O45 - LFCP:[MD5.CB4C649F38F4F927988FB41E0C49DDE9] - 04/02/2014 - 15:37:44 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-65953559.pf
O45 - LFCP:[MD5.565211A5705543965B18A758638B2973] - 04/02/2014 - 21:20:20 ---A- - C:\Windows\Prefetch\FLASHPLAYERINSTALLER.EXE-A1BAE93B.pf
O45 - LFCP:[MD5.88D37D8A950D6BC76DDD6E52DF8CD82D] - 05/02/2014 - 06:48:07 ---A- - C:\Windows\Prefetch\PLUGIN-CONTAINER.EXE-E510713D.pf
O45 - LFCP:[MD5.3605F6EDA13CC2495F114D04DF178E95] - 05/02/2014 - 06:48:08 ---A- - C:\Windows\Prefetch\FLASHPLAYERPLUGIN_12_0_0_44.E-6ECC2BF9.pf
O45 - LFCP:[MD5.9FF2D678D347ACB09BFF657539DA7265] - 05/02/2014 - 06:51:01 ---A- - C:\Windows\Prefetch\JAVA.EXE-4EF2C834.pf
O45 - LFCP:[MD5.8499704C6B74C81F062005A3A847BCB4] - 05/02/2014 - 12:55:01 ---A- - C:\Windows\Prefetch\PHOTOSAPP.EXE-8FE95EC8.pf
O45 - LFCP:[MD5.3AAF19B9E6CB7AF02DFE73BDB9CDD6D4] - 05/02/2014 - 14:06:37 ---A- - C:\Windows\Prefetch\BULKOPERATIONHOST.EXE-1D031CC3.pf
O45 - LFCP:[MD5.C7AC760E67F6BDD68A327CDD1D8D4F12] - 05/02/2014 - 14:07:07 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-C39C2E02.pf
O45 - LFCP:[MD5.C1E6D7FB1E592703995BFA7DE1C8CF8A] - 05/02/2014 - 14:09:52 ---A- - C:\Windows\Prefetch\FILEMANAGER.EXE-D7E24B17.pf
O45 - LFCP:[MD5.067901900CCD4B97A4007F21B16F58C0] - 05/02/2014 - 14:11:59 ---A- - C:\Windows\Prefetch\MSOXMLED.EXE-DC070A79.pf
O45 - LFCP:[MD5.0E6A4075AEDA119064AB57F2A3A3C9FD] - 05/02/2014 - 17:04:33 ---A- - C:\Windows\Prefetch\dynreservedpri.db
O45 - LFCP:[MD5.15383D636BD41F30E7D20BE355A11455] - 06/02/2014 - 05:44:56 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-92CB0A79.pf
O45 - LFCP:[MD5.E9CFE5FCAC56A2E21EA19796E66B510F] - 06/02/2014 - 05:44:56 ---A- - C:\Windows\Prefetch\W32TM.EXE-78C041DB.pf
O45 - LFCP:[MD5.B07593D9E347DD32D8FCC0F7A4354ECA] - 06/02/2014 - 05:45:02 ---A- - C:\Windows\Prefetch\PING.EXE-167FE968.pf
O45 - LFCP:[MD5.E30BEE36350A947C1F8AA56F3258FFB2] - 06/02/2014 - 05:53:17 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-78073FE4.pf
O45 - LFCP:[MD5.5FA2621E71B53A032CE5854DBF61B701] - 06/02/2014 - 06:19:02 ---A- - C:\Windows\Prefetch\MCUICNT.EXE-FA222868.pf
O45 - LFCP:[MD5.AD6E39AB9A04AAA23157D601D8F24AC7] - 06/02/2014 - 06:31:04 ---A- - C:\Windows\Prefetch\FFCERT.EXE-787932D0.pf
O45 - LFCP:[MD5.E96C523CCBE09673CCBF54059CE59DD2] - 06/02/2014 - 06:31:14 ---A- - C:\Windows\Prefetch\FIREFOX.EXE-528BC649.pf
O45 - LFCP:[MD5.DAEC052B47E3B94D791EB521AE4AE818] - 06/02/2014 - 07:56:44 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-82CF0F0F.pf
O45 - LFCP:[MD5.204EA243CE5F0915D0CE341837D13683] - 06/02/2014 - 11:04:48 ---A- - C:\Windows\Prefetch\PICKERHOST.EXE-103A256A.pf
O45 - LFCP:[MD5.C7C1C65821827F2092BA995946401DDE] - 06/02/2014 - 11:51:14 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-05B3EDF6.pf
O45 - LFCP:[MD5.EC574AF1938046B24BA529B299B69A3D] - 06/02/2014 - 11:51:14 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-F2C7AEBC.pf
O45 - LFCP:[MD5.5D647B19AEEE4DA653E039F760F326A6] - 06/02/2014 - 13:34:42 ---A- - C:\Windows\Prefetch\WSHOST.EXE-05F0A3AF.pf
O45 - LFCP:[MD5.C3F5CA6DAC41310DF05069D7908F4A7C] - 06/02/2014 - 14:02:20 ---A- - C:\Windows\Prefetch\SETUP.EXE-64895B8A.pf
O45 - LFCP:[MD5.4AFD8BC2A9548B6DD31A8DE29DD9CB98] - 06/02/2014 - 14:04:31 ---A- - C:\Windows\Prefetch\CHROME.EXE-21B521AF.pf
O45 - LFCP:[MD5.8D59C5F5AC2BFE3B3430DD7F40D0FABF] - 06/02/2014 - 14:12:45 ---A- - C:\Windows\Prefetch\SRTASKS.EXE-29C2E869.pf
O45 - LFCP:[MD5.7B568AC8716CBE4A8B02AE37462D8EFF] - 06/02/2014 - 14:12:53 ---A- - C:\Windows\Prefetch\SOFTWAREUPDATE.EXE-2ED64A89.pf
O45 - LFCP:[MD5.908C5CE574C6B3CD2EF463F29CF208C7] - 06/02/2014 - 14:12:58 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-A35E3FA4.pf
O45 - LFCP:[MD5.5500F2156CA9494E81EB2CC4FEF0F543] - 06/02/2014 - 14:13:57 ---A- - C:\Windows\Prefetch\TRACKMAKER.EXE-5C858686.pf
O45 - LFCP:[MD5.3F4F57ECF28FF112FEE03253C79EB496] - 06/02/2014 - 14:14:09 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-F8F2B7B0.pf
O45 - LFCP:[MD5.6963B75980C74D9C86FA0A9F3F837CBF] - 06/02/2014 - 14:15:04 ---A- - C:\Windows\Prefetch\AVPUI.EXE-CBE774B7.pf
O45 - LFCP:[MD5.6030CC293418B6BAAA50DD67417BCF11] - 06/02/2014 - 14:15:38 ---A- - C:\Windows\Prefetch\UNINSTALL.EXE-BBB6FCF0.pf
O45 - LFCP:[MD5.F63199AFA4BD0630B095FA2E777861BE] - 06/02/2014 - 14:15:39 ---A- - C:\Windows\Prefetch\AU_.EXE-A10CB829.pf
O45 - LFCP:[MD5.B7F9C7E639AEB9BE3D79975E8F5C2120] - 06/02/2014 - 14:15:46 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-8BE5CE86.pf
O45 - LFCP:[MD5.746D2F2C4288E791F45047FC93BB9E5C] - 06/02/2014 - 14:15:49 ---A- - C:\Windows\Prefetch\MCUICNT.EXE-7E771CED.pf
O45 - LFCP:[MD5.F4F6F1051026D39058669FF272D01A8F] - 06/02/2014 - 14:16:48 ---A- - C:\Windows\Prefetch\CTFMON.EXE-286F3259.pf
O45 - LFCP:[MD5.A27625FDFD7A310ECC82A7F0E830A0E9] - 06/02/2014 - 14:16:51 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-A432434E.pf
O45 - LFCP:[MD5.E1FCA92666BD730D766DC85BD4C5B7C4] - 06/02/2014 - 14:16:52 ---A- - C:\Windows\Prefetch\MSIEXEC.EXE-BAE57A74.pf
O45 - LFCP:[MD5.40DA247A04D1BD8843AD19AE6AB44C41] - 06/02/2014 - 14:17:39 ---A- - C:\Windows\Prefetch\AVP.EXE-7AF5E119.pf
O45 - LFCP:[MD5.CB07362C4C24D8E71620346A8817A802] - 06/02/2014 - 14:18:15 ---A- - C:\Windows\Prefetch\MSMPENG.EXE-F9080403.pf
O45 - LFCP:[MD5.6F88139BDFE1A354F755F45B93A64154] - 06/02/2014 - 14:18:55 ---A- - C:\Windows\Prefetch\WMI64.EXE-9D9605B7.pf
O45 - LFCP:[MD5.8F5C13D8CFFA196B14C716F409CC4D14] - 06/02/2014 - 14:18:58 ---A- - C:\Windows\Prefetch\KLWTBLFS.EXE-437DCEE9.pf
O45 - LFCP:[MD5.E6E4235AD824EFB493AA73B388F01BCA] - 06/02/2014 - 14:18:58 ---A- - C:\Windows\Prefetch\KLWTBLFS.EXE-740A3A53.pf
O45 - LFCP:[MD5.534AC71A8402C011E39828919359459F] - 06/02/2014 - 14:18:58 ---A- - C:\Windows\Prefetch\KLWTBWS.EXE-C5A077BA.pf
O45 - LFCP:[MD5.FDEA53657042A542BF6600C5D8FF71FB] - 06/02/2014 - 14:18:58 ---A- - C:\Windows\Prefetch\KLWTBWS.EXE-F2EA6F34.pf
O45 - LFCP:[MD5.10B724328A8D44B45F60F66C2FC9631C] - 06/02/2014 - 14:19:00 ---A- - C:\Windows\Prefetch\MSIEXEC.EXE-7D20CFB0.pf
O45 - LFCP:[MD5.64C5CDB0E6CCEF0C3F06CF937163CC0B] - 06/02/2014 - 14:19:16 ---A- - C:\Windows\Prefetch\DRVINST.EXE-26FFA444.pf
O45 - LFCP:[MD5.605BE8420324C5F51F13ECF33EEA54BC] - 06/02/2014 - 14:20:25 ---A- - C:\Windows\Prefetch\NIS_DELTA_PATCH.EXE-C3DFCBAC.pf
O45 - LFCP:[MD5.1AA065A987CCFF4B8B38AAE680A17B1A] - 06/02/2014 - 14:20:35 ---A- - C:\Windows\Prefetch\AM_DELTA.EXE-3A6EE7FD.pf
O45 - LFCP:[MD5.DBF0273E3DEF1AC13C697563CA5CAEDB] - 06/02/2014 - 14:20:35 ---A- - C:\Windows\Prefetch\MPSIGSTUB.EXE-4D562760.pf
O45 - LFCP:[MD5.E77413F24130F6C5C9CCC2D905A94AC9] - 06/02/2014 - 14:20:35 ---A- - C:\Windows\Prefetch\WUAUCLT.EXE-4A7CF88B.pf
O45 - LFCP:[MD5.EAC4C709398723EEAD843E5CB9761C87] - 06/02/2014 - 14:38:45 ---A- - C:\Windows\Prefetch\CLI.EXE-278FDBBC.pf
O45 - LFCP:[MD5.89FFA58F15012A9B3911531F4841E070] - 06/02/2014 - 14:38:51 ---A- - C:\Windows\Prefetch\LOGONUI.EXE-E35F76FB.pf
O45 - LFCP:[MD5.3A2B8AED94909716ED98A63ABD56DFEA] - 06/02/2014 - 14:38:51 ---A- - C:\Windows\Prefetch\PfSvPerfStats.bin
O45 - LFCP:[MD5.1EC2E1E111FC62E61954FE01CBFA29B6] - 06/02/2014 - 14:42:13 ---A- - C:\Windows\Prefetch\NASVC.EXE-314DC6C9.pf
O45 - LFCP:[MD5.2FF657B1C62CD75C65007AC2F392BF41] - 06/02/2014 - 14:44:11 ---A- - C:\Windows\Prefetch\WMIADAP.EXE-7D63BB4C.pf
O45 - LFCP:[MD5.165F6EA0A986C9F74B20EA6DDA53BD0C] - 06/02/2014 - 14:50:26 ---A- - C:\Windows\Prefetch\NGEN.EXE-383F81D5.pf
O45 - LFCP:[MD5.FB0DFAD7FA44E3894825CBC7FC7F9947] - 06/02/2014 - 14:50:32 ---A- - C:\Windows\Prefetch\NGENTASK.EXE-CD4E002C.pf
O45 - LFCP:[MD5.B9B69F413B7D0EA3F3EEF20C6749498C] - 06/02/2014 - 14:50:38 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-93798CD2.pf
O45 - LFCP:[MD5.EE4467ECA8D0A89AC775705FA12EA997] - 06/02/2014 - 14:50:42 ---A- - C:\Windows\Prefetch\MSCORSVW.EXE-D593A5D9.pf
O45 - LFCP:[MD5.89603DE2A0741A0FEB6B280370E0F38B] - 06/02/2014 - 14:51:06 ---A- - C:\Windows\Prefetch\ATBROKER.EXE-8B8F7F7C.pf
O45 - LFCP:[MD5.F56300D3E2BD70C21866BC597AABE226] - 06/02/2014 - 14:51:17 ---A- - C:\Windows\Prefetch\EXPLORER.EXE-03C49D11.pf
O45 - LFCP:[MD5.212D9D2FB256A3058780CBCB536C033F] - 06/02/2014 - 14:51:17 ---A- - C:\Windows\Prefetch\MBAMGUI.EXE-9FF23AE2.pf
O45 - LFCP:[MD5.7D92647F82EEFD7357B8F22C915B5D9A] - 06/02/2014 - 14:51:17 ---A- - C:\Windows\Prefetch\USERINIT.EXE-7FD17ED1.pf
O45 - LFCP:[MD5.95BB1E981E69682296BF265EA02AE2EC] - 06/02/2014 - 14:51:19 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-6E31253B.pf
O45 - LFCP:[MD5.B64AC2AB6B5B6B317F7F6DA4EEA0BD57] - 06/02/2014 - 14:51:54 ---A- - C:\Windows\Prefetch\CLISTART.EXE-02DB8E02.pf
O45 - LFCP:[MD5.915A38842CA1B6F55B0B0AE37D838685] - 06/02/2014 - 14:51:54 ---A- - C:\Windows\Prefetch\E_IATIHLE.EXE-9A67F39B.pf
O45 - LFCP:[MD5.5C5783B341E67223ED2D51E606C632C2] - 06/02/2014 - 14:51:54 ---A- - C:\Windows\Prefetch\RAVCPL64.EXE-C0BB540D.pf
O45 - LFCP:[MD5.28A59C1313D1D8E684EB6ED29FD29D2F] - 06/02/2014 - 14:51:54 ---A- - C:\Windows\Prefetch\RUNONCE.EXE-E874B0D0.pf
O45 - LFCP:[MD5.20474634C7AC02AB57308220CA560427] - 06/02/2014 - 14:51:54 ---A- - C:\Windows\Prefetch\SSSCHEDULER.EXE-EADC2BAA.pf
O45 - LFCP:[MD5.119FA3456387FCB84A44E1FA054FC84C] - 06/02/2014 - 14:51:54 ---A- - C:\Windows\Prefetch\ZUNELAUNCHER.EXE-E7AA2156.pf
O45 - LFCP:[MD5.3074F86A762318BEDC6B3F96ED8A568B] - 06/02/2014 - 14:51:55 ---A- - C:\Windows\Prefetch\SOFFICE.BIN-72E915F8.pf
O45 - LFCP:[MD5.D801ABBCF7F85E69DFA46BC763946128] - 06/02/2014 - 14:52:12 ---A- - C:\Windows\Prefetch\AgCx_SC4.db
O45 - LFCP:[MD5.FEAB065600497DC03A08098A753457B1] - 06/02/2014 - 14:52:16 ---A- - C:\Windows\Prefetch\EPOWERSVC.EXE-76E124E6.pf
O45 - LFCP:[MD5.AF329C56ADAD4F85E54F800011540AB8] - 06/02/2014 - 14:52:17 ---A- - C:\Windows\Prefetch\RUNTIMEBROKER.EXE-17E2786F.pf
O45 - LFCP:[MD5.FC361EE0C19CF095D1A5147D8CF7668D] - 06/02/2014 - 14:52:53 ---A- - C:\Windows\Prefetch\MOM.EXE-AF39B199.pf
O45 - LFCP:[MD5.43F9D1AA8DE1200437F5E3F1B8C6C1FB] - 06/02/2014 - 14:52:56 ---A- - C:\Windows\Prefetch\CCC.EXE-22878179.pf
O45 - LFCP:[MD5.4D320B34E5A90CEBD6C4B93452C1F298] - 06/02/2014 - 14:54:19 ---A- - C:\Windows\Prefetch\SETTINGSYNCHOST.EXE-DD400067.pf
O45 - LFCP:[MD5.D67ACD64430E46E961F99300DF79DF7E] - 06/02/2014 - 14:55:02 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-985C34E6.pf
O45 - LFCP:[MD5.A46720C77E7F425B5C8477686496655F] - 06/02/2014 - 14:56:15 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-5CFABC16.pf
O45 - LFCP:[MD5.41F68C9A2D1CCDD71AAE62572ABC8A35] - 06/02/2014 - 15:01:26 ---A- - C:\Windows\Prefetch\NOTIFICATION.EXE-D7317444.pf
O45 - LFCP:[MD5.6C768D0E6F458E173829E752C6BA41F8] - 06/02/2014 - 15:04:15 ---A- - C:\Windows\Prefetch\WERFAULT.EXE-44194444.pf
O45 - LFCP:[MD5.C527A3451179A120C00B6FF47B70AC8F] - 06/02/2014 - 15:16:05 ---A- - C:\Windows\Prefetch\REMARKABLEUP.EXE-41CA0A69.pf
O45 - LFCP:[MD5.FEADD9A0EA0D8CD76515FB1EE88320FA] - 06/02/2014 - 15:36:41 ---A- - C:\Windows\Prefetch\E_SAG4ST.EXE-98DD0B19.pf
O45 - LFCP:[MD5.6D5F95BB98EF56515FC00B7AA30798DB] - 06/02/2014 - 15:36:41 ---A- - C:\Windows\Prefetch\MSASCUI.EXE-4ED47FD9.pf
O45 - LFCP:[MD5.24C85BF8B85431E080A7FED66043191B] - 06/02/2014 - 15:39:28 ---A- - C:\Windows\Prefetch\DELEGATE_EXECUTE.EXE-9B31479C.pf
O45 - LFCP:[MD5.E31BB28D53D928570FC603175F50EC0D] - 06/02/2014 - 16:06:14 ---A- - C:\Windows\Prefetch\SCHTASKS.EXE-BA1E321E.pf
O45 - LFCP:[MD5.8E90A2AD7FF22DC73BD227F162D0D6C4] - 06/02/2014 - 16:06:32 ---A- - C:\Windows\Prefetch\INTEGRATEDOFFICE.EXE-DFB67DA0.pf
O45 - LFCP:[MD5.903973F5AB8576A1DB24AB1CD1899B4C] - 06/02/2014 - 16:09:08 ---A- - C:\Windows\Prefetch\GOOGLEUPDATE.EXE-D4E2846D.pf
O45 - LFCP:[MD5.B38A18F24A27E0F758B139164A78DFA2] - 06/02/2014 - 16:15:02 ---A- - C:\Windows\Prefetch\FLASHPLAYERUPDATESERVICE.EXE-E0E5E52F.pf
O45 - LFCP:[MD5.AE29B848CF737A4FF1F249CF52110354] - 06/02/2014 - 16:39:19 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-D687BE54.pf
O45 - LFCP:[MD5.A5BA0AFB2D33E5AC62DFA62EA8BF9968] - 06/02/2014 - 16:39:33 ---A- - C:\Windows\Prefetch\VSSVC.EXE-206E55B3.pf
O45 - LFCP:[MD5.18F8346422F325AA382AC04D272654D6] - 06/02/2014 - 16:39:34 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-38BE90DD.pf
O45 - LFCP:[MD5.6E7631F23FC4F93DF343F0054529D056] - 06/02/2014 - 16:39:38 ---A- - C:\Windows\Prefetch\Layout.ini
O45 - LFCP:[MD5.ED6144454AB6C5C0EE587013971154DA] - 06/02/2014 - 16:39:48 ---A- - C:\Windows\Prefetch\DEFRAG.EXE-22AD8A37.pf
O45 - LFCP:[MD5.1EA57BD33ECF1B832187FCC2D46205EE] - 06/02/2014 - 16:39:48 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-576FFE64.pf
O45 - LFCP:[MD5.3FEF89AA2086F4C8ABFD93069080109E] - 06/02/2014 - 16:40:39 ---A- - C:\Windows\Prefetch\TIWORKER.EXE-103DCE51.pf
O45 - LFCP:[MD5.B9D6B461A74D7B08040BBBA794497952] - 06/02/2014 - 16:40:43 ---A- - C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-B018CCBF.pf
O45 - LFCP:[MD5.01EB90F075E554BC7E9B9AC9040CEFFE] - 06/02/2014 - 16:41:17 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-0F905C08.pf
O45 - LFCP:[MD5.AAB4D94685B6A03D9C1DA49BB00933D8] - 06/02/2014 - 16:41:23 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-5C68AAB7.pf
O45 - LFCP:[MD5.4EE0D03D1979FB68C249A47F01CFFA30] - 06/02/2014 - 16:41:23 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-3C5D03F7.pf
O45 - LFCP:[MD5.64B09F8EE97DBBF6C871244B63F8689A] - 06/02/2014 - 16:41:26 ---A- - C:\Windows\Prefetch\WMIPRVSE.EXE-BB49B536.pf
O45 - LFCP:[MD5.A6878A7DB3A691D3617C6516A1E96861] - 06/02/2014 - 16:41:34 ---A- - C:\Windows\Prefetch\NGEN.EXE-A8DBB043.pf
O45 - LFCP:[MD5.47EE23FE697C98B61279C532CD3A75D6] - 06/02/2014 - 16:41:39 ---A- - C:\Windows\Prefetch\NGENTASK.EXE-4DB88ADA.pf
O45 - LFCP:[MD5.D5678502C2AE414634C5F62527C8F3B3] - 06/02/2014 - 16:42:07 ---A- - C:\Windows\Prefetch\MSCORSVW.EXE-55FE3087.pf
O45 - LFCP:[MD5.E5C755976B51157D343F2D59BD3CB8D8] - 06/02/2014 - 16:42:41 ---A- - C:\Windows\Prefetch\MAKECAB.EXE-E962779E.pf
O45 - LFCP:[MD5.5CBEB3C36F3B5EDE328D44A84EA33D00] - 06/02/2014 - 16:47:19 ---A- - C:\Windows\Prefetch\MPCMDRUN.EXE-6520183E.pf
O45 - LFCP:[MD5.FC0A6E32FA81DC7A32658C1F0F1DBE6B] - 06/02/2014 - 16:51:58 ---A- - C:\Windows\Prefetch\PfPre_d48dd95b.db
O45 - LFCP:[MD5.E4DD9A09669D54DA9065642627E7E9CF] - 06/02/2014 - 16:52:21 ---A- - C:\Windows\Prefetch\THUMBNAILEXTRACTIONHOST.EXE-C3FB8861.pf
O45 - LFCP:[MD5.D833578970042816FF290FB6354969CA] - 06/02/2014 - 16:53:15 ---A- - C:\Windows\Prefetch\TASKENG.EXE-23205583.pf
O45 - LFCP:[MD5.75ED0232E1EAD81191B978AF7B32F749] - 06/02/2014 - 16:53:37 ---A- - C:\Windows\Prefetch\GOOGLEUPDATE.EXE-62E5E10F.pf
O45 - LFCP:[MD5.4D47E34FE90891A1F3B0BA8B93ED0668] - 06/02/2014 - 16:54:10 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-29D61DAB.pf
O45 - LFCP:[MD5.A5D908B29C0D46D83D08C5A5B002C6F2] - 06/02/2014 - 16:54:12 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-3830BC72.pf
O45 - LFCP:[MD5.58C676BAFF50243BB2A49677439DD280] - 06/02/2014 - 16:55:22 ---A- - C:\Windows\Prefetch\CONSENT.EXE-2D674CE4.pf
O45 - LFCP:[MD5.E19CEA1D30B6E98CDBDEADE4DE7CC95C] - 06/02/2014 - 16:55:27 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-829F390C.pf
O45 - LFCP:[MD5.F5C68E2958D490C72171FAC9649C4077] - 06/02/2014 - 16:55:28 ---A- - C:\Windows\Prefetch\ZHPDIAG2.TMP-E0EF548D.pf
O45 - LFCP:[MD5.0E4BF2CF603685C6A770BC1D81272D84] - 06/02/2014 - 16:55:29 ---A- - C:\Windows\Prefetch\AUDIODG.EXE-9848A323.pf
O45 - LFCP:[MD5.1319517FB138854D52709AA2AC261FBB] - 06/02/2014 - 16:55:30 ---A- - C:\Windows\Prefetch\TASKHOSTEX.EXE-7356AAC0.pf
O45 - LFCP:[MD5.4F89F8001A961C73D69F7868C29D7F3D] - 06/02/2014 - 16:55:32 ---A- - C:\Windows\Prefetch\ZHPDIAG2.EXE-9AEAE8FF.pf
O45 - LFCP:[MD5.BBA379E80D51169947379EA50B81B2E3] - 06/02/2014 - 16:55:32 ---A- - C:\Windows\Prefetch\ZHPDIAG2.TMP-964C9510.pf
O45 - LFCP:[MD5.367A5C0D5F209017EAEE29D4169B72B1] - 06/02/2014 - 16:56:01 ---A- - C:\Windows\Prefetch\CHROME.EXE-C24079B2.pf
O45 - LFCP:[MD5.3A53B6BB3BBF9E11435DE2DC99C7482E] - 06/02/2014 - 16:56:04 ---A- - C:\Windows\Prefetch\AgRobust.db
O45 - LFCP:[MD5.B09723A2DBDA11E55E5BA81E0F3433D1] - 06/02/2014 - 16:56:05 ---A- - C:\Windows\Prefetch\AgGlGlobalHistory.db
O45 - LFCP:[MD5.CBFBF6FCB5DCC1AFCBC5A44E90675046] - 06/02/2014 - 16:56:08 ---A- - C:\Windows\Prefetch\AgGlFaultHistory.db
O45 - LFCP:[MD5.D28CEABA96F8A783E05595EFE2F40EA2] - 06/02/2014 - 16:56:09 ---A- - C:\Windows\Prefetch\AgGlFgAppHistory.db
O45 - LFCP:[MD5.458FC1134A80CBD24A3A8B4B059C523B] - 06/02/2014 - 16:56:09 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-6A829A47.pf
O45 - LFCP:[MD5.5439CCBAA5018341A31A755013182C60] - 06/02/2014 - 16:56:09 ---A- - C:\Windows\Prefetch\WERMGR.EXE-D948C216.pf
O45 - LFCP:[MD5.5109EF11C92166AAE74A81C0B699DCF9] - 06/02/2014 - 16:56:20 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-210D3DBE.pf
O45 - LFCP:[MD5.7AA13975D97BB050A150BF2023ED866F] - 06/02/2014 - 16:56:28 ---A- - C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-1682419926-403432926-433631104-1002.db
O45 - LFCP:[MD5.575BE45651D796FEE7C374AC9A94E487] - 06/02/2014 - 16:56:28 ---A- - C:\Windows\Prefetch\AgGlUAD_S-1-5-21-1682419926-403432926-433631104-1002.db
O45 - LFCP:[MD5.EE544D58F6A6838ECC3B290391CB4ED1] - 06/02/2014 - 16:56:29 ---A- - C:\Windows\Prefetch\ZHPHEP.EXE-5F2753B1.pf
O45 - LFCP:[MD5.4EC84060A3F9C4BD15A001DCE8782B3F] - 06/02/2014 - 16:56:37 ---A- - C:\Windows\Prefetch\ZHPDIAG.EXE-C7289479.pf
O45 - LFCP:[MD5.271F810A71A10C0EA0908B5C54DF73F4] - 06/02/2014 - 16:56:58 ---A- - C:\Windows\Prefetch\CONHOST.EXE-F98A1078.pf
O45 - LFCP:[MD5.8BAC0E9C14943B2C3DB72368BE9073F1] - 06/02/2014 - 16:56:58 ---A- - C:\Windows\Prefetch\CSCRIPT.EXE-E9FF6526.pf
O45 - LFCP:[MD5.152EEBD6A7A98A32655B9B0B3D887D25] - 06/02/2014 - 16:57:05 ---A- - C:\Windows\Prefetch\PV.EXE-D9D90B9C.pf
O45 - LFCP:[MD5.BD67946786620AD814E09EBA23B7F4C1] - 06/02/2014 - 16:57:06 ---A- - C:\Windows\Prefetch\SPPSVC.EXE-7B160CA5.pf
O45 - LFCP:[MD5.E31DD0247F0C39027EFEE132AD731239] - 06/02/2014 - 16:57:06 ---A- - C:\Windows\Prefetch\WMIPRVSE.EXE-0C8A533A.pf
O45 - LFCP:[MD5.486EFD9156021F8499FF8DA20FFA94DD] - 06/02/2014 - 16:57:12 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-FEA1FDBE.pf
O45 - LFCP:[MD5.A5F2741BD5A7EFD47F3636C1A25B4EAA] - 06/02/2014 - 16:58:10 ---A- - C:\Windows\Prefetch\CMD.EXE-2EB3E6E2.pf
O45 - LFCP:[MD5.89F9071878BE0AFBA2B3F832F949F87B] - 06/02/2014 - 16:58:10 ---A- - C:\Windows\Prefetch\SUBINACL.EXE-D08B2113.pf
O45 - LFCP:[MD5.67E37495E1B1B2F9532EF63A180DCB93] - 06/02/2014 - 16:58:27 ---A- - C:\Windows\Prefetch\SCHTASKS.EXE-0AD36442.pf
O45 - LFCP:[MD5.38447A5FEB63EE9297058030BA352E07] - 18/01/2014 - 14:27:31 ---A- - C:\Windows\Prefetch\AgAppLaunch.db
O45 - LFCP:[MD5.6F46C09CA1548A2924580F65D592F324] - 18/01/2014 - 15:22:39 ---A- - C:\Windows\Prefetch\MIGHOST.EXE-EC0ABC91.pf
O45 - LFCP:[MD5.90E8038F36A3CC5E0D9FF68812A61302] - 18/01/2014 - 21:10:51 ---A- - C:\Windows\Prefetch\FIRSTLOGONANIM.EXE-8CCB11F3.pf
O45 - LFCP:[MD5.4E635C26889DB8D01EB981DAB46B0613] - 18/01/2014 - 21:11:21 ---A- - C:\Windows\Prefetch\UNREGMP2.EXE-800E8C32.pf
O45 - LFCP:[MD5.3575847B53260CE973A60D0026A5889C] - 18/01/2014 - 21:12:47 ---A- - C:\Windows\Prefetch\IE4UINIT.EXE-97F7E751.pf
O45 - LFCP:[MD5.2A21FFD29A1326F2EABBBB3806C462FB] - 18/01/2014 - 21:16:18 ---A- - C:\Windows\Prefetch\ASSISTANCELIVEBOX.EXE-B79ACA79.pf
O45 - LFCP:[MD5.62E17C0D17EDDED9AA64057B3CDBBBED] - 19/01/2014 - 15:37:49 ---A- - C:\Windows\Prefetch\FACEBOOK.EXE-3F08B1F2.pf
O45 - LFCP:[MD5.A259DB190BE51EB43E2F4D4759CE0E84] - 19/01/2014 - 15:50:07 ---A- - C:\Windows\Prefetch\AVBUGREPORT.EXE-E4EA699E.pf
O45 - LFCP:[MD5.C937B5BEADF13EAE2583CBA263CD0BDF] - 19/01/2014 - 15:53:21 ---A- - C:\Windows\Prefetch\MSN.FR RSS READER.EXE-6F550C2B.pf
O45 - LFCP:[MD5.C138F0C8577E1F98DD579FAD5D50BF03] - 19/01/2014 - 15:53:39 ---A- - C:\Windows\Prefetch\WWAHOST.EXE-B0C19A90.pf
O45 - LFCP:[MD5.F53B223592F68CB57935BA63B12E76CE] - 19/01/2014 - 15:54:41 ---A- - C:\Windows\Prefetch\UTORRENT.EXE-8A211021.pf =>P2P.µTorrent
O45 - LFCP:[MD5.28AA2ED23E4001A40F52EC16C4E1139C] - 19/01/2014 - 15:54:58 ---A- - C:\Windows\Prefetch\INSTUP.EXE-3AF05CB9.pf
O45 - LFCP:[MD5.932E82190F77B0CBA207E2DE9993BCA6] - 19/01/2014 - 15:56:52 ---A- - C:\Windows\Prefetch\SETUPINF64.EXE-3D0A5259.pf
O45 - LFCP:[MD5.F3EF4542BC87D9778921B5F1FCB974F6] - 19/01/2014 - 16:56:03 ---A- - C:\Windows\Prefetch\TEST_WPF.EXE-78BBDEA8.pf
O45 - LFCP:[MD5.F047106C12128FC26BEAF0F59831D9AF] - 19/01/2014 - 16:56:07 ---A- - C:\Windows\Prefetch\KASPERSKY-INTERNET-SECURITY-2-33C12E98.pf
O45 - LFCP:[MD5.C598E55588EAFE48CB8D0241BB110FA6] - 19/01/2014 - 19:44:15 ---A- - C:\Windows\Prefetch\PICKERHOST.EXE-03F09186.pf
O45 - LFCP:[MD5.DE7C5584E531F40C9C65689A2D3AD075] - 19/01/2014 - 21:10:38 ---A- - C:\Windows\Prefetch\WWAHOST.EXE-5DE0BF65.pf
O45 - LFCP:[MD5.1179CB7D498F4DF94AE5C44692965822] - 19/01/2014 - 21:24:58 ---A- - C:\Windows\Prefetch\PATCH_C_KIS2014.EXE-3AEA3CF1.pf
O45 - LFCP:[MD5.C5728C6B1906F4DE88A8DB5AAA75897D] - 19/01/2014 - 22:02:02 ---A- - C:\Windows\Prefetch\BYTECODEGENERATOR.EXE-9C808144.pf
O45 - LFCP:[MD5.CC48C86818CBA2C6217B68B1F73CB7B2] - 19/01/2014 - 22:41:44 ---A- - C:\Windows\Prefetch\WWAHOST.EXE-04E54F5A.pf
O45 - LFCP:[MD5.133EE5C12729124FCC26241DBCF92A80] - 20/01/2014 - 07:16:38 ---A- - C:\Windows\Prefetch\FACEBOOKTOUCH.EXE-1332872F.pf
O45 - LFCP:[MD5.FE8DB9D003CDA5B80AAE012612CAF454] - 21/01/2014 - 10:04:08 ---A- - C:\Windows\Prefetch\SPRINT.EXE-6113E6AA.pf
O45 - LFCP:[MD5.8B1602622884F55E0C2093E1C0CE2FB5] - 21/01/2014 - 17:28:13 ---A- - C:\Windows\Prefetch\WINRAR.EXE-72513729.pf
O45 - LFCP:[MD5.E530BF994FA696B777C56186CC96E1B6] - 22/01/2014 - 20:49:29 ---A- - C:\Windows\Prefetch\UTILMAN.EXE-3520356C.pf
O45 - LFCP:[MD5.48C3E0E6D70F957288DFEEEA0384AD21] - 22/01/2014 - 22:27:50 ---A- - C:\Windows\Prefetch\OPENWITH.EXE-BA0DC300.pf
O45 - LFCP:[MD5.D0888D7A9A8ABD9420092003207F7659] - 23/01/2014 - 06:48:23 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-CEFAA268.pf
O45 - LFCP:[MD5.DEA4C5A3D5741D8820CA9CCE012777C8] - 23/01/2014 - 06:48:25 ---A- - C:\Windows\Prefetch\BYTECODEGENERATOR.EXE-353D57C0.pf
O45 - LFCP:[MD5.BAEE046030B2804047C6F5EE6873EAB2] - 23/01/2014 - 12:16:27 ---A- - C:\Windows\Prefetch\DSMUSERTASK.EXE-D4A83970.pf
O45 - LFCP:[MD5.F05C44ACA12A05F5B2E39CADA3D01AFA] - 23/01/2014 - 12:49:57 ---A- - C:\Windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf
O45 - LFCP:[MD5.C6320B267F6F402E2B0D7855E77D8492] - 23/01/2014 - 12:49:57 ---A- - C:\Windows\Prefetch\IEXPLORE.EXE-F4FB5D2F.pf
O45 - LFCP:[MD5.696369EB1A3303BC51C5F3D240C44E98] - 23/01/2014 - 12:58:44 ---A- - C:\Windows\Prefetch\RICONBOY.EXE-A045F34B.pf
O45 - LFCP:[MD5.5F64B4D63E3CF83097AA3CAD5C9A2BCA] - 23/01/2014 - 16:04:57 ---A- - C:\Windows\Prefetch\ITUNES.EXE-07AC1693.pf
O45 - LFCP:[MD5.9C7A8231E6E39690AD7037B6CCD75D0A] - 23/01/2014 - 16:05:01 ---A- - C:\Windows\Prefetch\APPLEMOBILEDEVICEHELPER.EXE-B90BEA1C.pf
O45 - LFCP:[MD5.B30437CBB6AECDE66D1A0DA7FDE4F266] - 23/01/2014 - 16:05:01 ---A- - C:\Windows\Prefetch\DISTNOTED.EXE-DE72C2C6.pf
O45 - LFCP:[MD5.96D474B7823A73040588CD0C7F199AFF] - 23/01/2014 - 16:05:14 ---A- - C:\Windows\Prefetch\SYNCSERVER.EXE-261E368E.pf
O45 - LFCP:[MD5.7DD68334F5F4B36B5C8F06C6C210D190] - 23/01/2014 - 16:05:31 ---A- - C:\Windows\Prefetch\APPLEMOBILEBACKUP.EXE-3A92388A.pf
O45 - LFCP:[MD5.03F08614B385EF007C96DBD7D5051BC0] - 23/01/2014 - 16:05:53 ---A- - C:\Windows\Prefetch\MDCRASHREPORTTOOL.EXE-3BC35FEE.pf
O45 - LFCP:[MD5.690A7B1021D0A45F4F98C2998B4DDDA9] - 24/01/2014 - 06:17:26 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-C16C9C4E.pf
O45 - LFCP:[MD5.7BB980005EC3DB020F4923122F7D8180] - 24/01/2014 - 06:17:26 ---A- - C:\Windows\Prefetch\WINSAT.EXE-A854C4D0.pf
O45 - LFCP:[MD5.ED634105889CB55EEE698E1B46BFD214] - 24/01/2014 - 10:35:54 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-B6DA4AC7.pf
O45 - LFCP:[MD5.0CA0096D31A67C30E3D5FD7378E91768] - 24/01/2014 - 13:41:45 ---A- - C:\Windows\Prefetch\E_FBCSHLE.EXE-CD8C5E86.pf
O45 - LFCP:[MD5.3851F59F7796899C744580108088600E] - 24/01/2014 - 13:41:47 ---A- - C:\Windows\Prefetch\E_IARNHLE.EXE-1CCD7DF2.pf
O45 - LFCP:[MD5.0651280CBC4F44637A6EAF0E39404FAF] - 24/01/2014 - 23:16:51 ---A- - C:\Windows\Prefetch\WINWORD.EXE-2437DA78.pf
O45 - LFCP:[MD5.63E91594ECF46ADC6C741FE1A5B09950] - 24/01/2014 - 23:17:00 ---A- - C:\Windows\Prefetch\MAVINJECT32.EXE-A39D6437.pf
O45 - LFCP:[MD5.880B744462B1C9C68960C8386A0F39DE] - 24/01/2014 - 23:17:04 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-E0A642E8.pf
O45 - LFCP:[MD5.90F12A89DE1597A0CCC70BF0EDF5F8BA] - 24/01/2014 - 23:17:10 ---A- - C:\Windows\Prefetch\DW20.EXE-E6E0E11E.pf
O45 - LFCP:[MD5.E78A59DF6B27E3FC945F71636F0F01F5] - 24/01/2014 - 23:17:10 ---A- - C:\Windows\Prefetch\DWWIN.EXE-E356B6C3.pf
O45 - LFCP:[MD5.6D72B4506CED152DA0787ED0446FA6AB] - 27/01/2014 - 16:05:16 ---A- - C:\Windows\Prefetch\PING.EXE-CF0A440C.pf
O45 - LFCP:[MD5.DD5F2A05861D59E0DF5BB420B73F7E3E] - 27/01/2014 - 16:05:17 ---A- - C:\Windows\Prefetch\CCSETUP410.EXE-FD561476.pf
O45 - LFCP:[MD5.21FAB1688DE0ACEA7B771C000F241BED] - 27/01/2014 - 16:05:35 ---A- - C:\Windows\Prefetch\CCLEANER64.EXE-1137D9AC.pf =>Piriform Ltd
O45 - LFCP:[MD5.11B690D57E641DC012100D17B862CCDC] - 27/01/2014 - 16:44:34 ---A- - C:\Windows\Prefetch\TASKKILL.EXE-3D8A2F61.pf
O45 - LFCP:[MD5.5101AC2F11C5E110BC8D18FC24B89FCA] - 27/01/2014 - 16:45:37 ---A- - C:\Windows\Prefetch\UNINST.EXE-E7FDC1A8.pf
O45 - LFCP:[MD5.13BBBB096F000FB9993F69022FDF7BD6] - 27/01/2014 - 16:45:55 ---A- - C:\Windows\Prefetch\UNINSTALL.EXE-19039A4C.pf
O45 - LFCP:[MD5.B0DB7AD38F8C4DBADD715D97716BF9EE] - 27/01/2014 - 16:45:58 ---A- - C:\Windows\Prefetch\NET.EXE-C3772C91.pf
O45 - LFCP:[MD5.C6E30084615B6F4121F66B5B92CE0541] - 27/01/2014 - 16:45:58 ---A- - C:\Windows\Prefetch\NET1.EXE-D513025E.pf
O45 - LFCP:[MD5.7CEB02AB05F3934030E35D35236F30C6] - 27/01/2014 - 16:46:16 ---A- - C:\Windows\Prefetch\UNINSTALL.EXE-9BD9AC6E.pf
O45 - LFCP:[MD5.B73D1693BB462C790AC9710EBA58CE0C] - 27/01/2014 - 17:02:05 ---A- - C:\Windows\Prefetch\FACEBOOKUPDATE.EXE-FC73A44F.pf
O45 - LFCP:[MD5.5D25C730BB2E1A5D73C5F4E933B6AB67] - 27/01/2014 - 20:11:23 ---A- - C:\Windows\Prefetch\REGSVR32.EXE-3290E8FC.pf
O45 - LFCP:[MD5.A0729AC2DA050A82FB408FD33FD1A477] - 27/01/2014 - 20:11:32 ---A- - C:\Windows\Prefetch\MBAM.EXE-125A28F9.pf
O45 - LFCP:[MD5.5699F302D1D5B4254F19A099E13BD626] - 28/01/2014 - 05:53:32 ---A- - C:\Windows\Prefetch\TIWORKER.EXE-3F06142E.pf
O45 - LFCP:[MD5.5D3F5DA4BA62C6891E5F1FB96EECD9F6] - 28/01/2014 - 10:36:54 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-65BDA682.pf
O45 - LFCP:[MD5.94A3C15031EE2CF6E384E31E0E4FF064] - 28/01/2014 - 12:32:54 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-7682DD6F.pf
O45 - LFCP:[MD5.8138B959B650B040E07ED82AFCE198F5] - 28/01/2014 - 14:11:19 ---A- - C:\Windows\Prefetch\LAUNCHTM.EXE-B444BC8E.pf
O45 - LFCP:[MD5.A66C731C0A520EDFE33CC0D89C6D81AC] - 28/01/2014 - 14:11:29 ---A- - C:\Windows\Prefetch\TASKMGR.EXE-39AABA37.pf
O45 - LFCP:[MD5.76ADCE857A057D77108EE1F341279974] - 28/01/2014 - 14:17:23 ---A- - C:\Windows\Prefetch\MMC.EXE-C252543C.pf
O45 - LFCP:[MD5.C2DDEA394450DB6972B58750F948A714] - 28/01/2014 - 14:18:14 ---A- - C:\Windows\Prefetch\EVENTVWR.EXE-44EFA5CF.pf
O45 - LFCP:[MD5.E095BB033D2BA93ADEA2471CEBD11427] - 28/01/2014 - 14:18:24 ---A- - C:\Windows\Prefetch\MMC.EXE-3B8FE58D.pf
O45 - LFCP:[MD5.E0934B9EE7AE74A8161DD89E4A9D9B44] - 28/01/2014 - 15:18:06 ---A- - C:\Windows\Prefetch\WUDFHOST.EXE-0D78D366.pf
O45 - LFCP:[MD5.AE450904CCAB934CE8B333C5FEB24CDE] - 28/01/2014 - 15:18:28 ---A- - C:\Windows\Prefetch\MSCONFIG.EXE-97CC4E38.pf
O45 - LFCP:[MD5.4A5A3E320424FEA231F27BC8537F7148] - 28/01/2014 - 15:24:49 ---A- - C:\Windows\Prefetch\SLOWIN KILLER.EXE-02E048C5.pf
O45 - LFCP:[MD5.CB1EC1B4E94B45A0732D1AAA7CDF53D7] - 28/01/2014 - 15:24:50 ---A- - C:\Windows\Prefetch\INS164.EXE-6FE90539.pf
O45 - LFCP:[MD5.14FC96AAA9504488689E707DFB31187C] - 28/01/2014 - 15:25:25 ---A- - C:\Windows\Prefetch\LAUNCHER.EXE-DE82D562.pf
O45 - LFCP:[MD5.F93B168A8077E73790B0A527BEF3F06D] - 28/01/2014 - 15:25:25 ---A- - C:\Windows\Prefetch\VISUALBEESILENT_2506-8EA7FD25-2F92AE7E.pf =>Adware.VisualBeeToolbar
O45 - LFCP:[MD5.F591178BE9BFAA3BA158AC24FE14FCB4] - 28/01/2014 - 15:25:53 ---A- - C:\Windows\Prefetch\VBMZ16.EXE-D1CF7E0B.pf =>PUP.Duuqu
O45 - LFCP:[MD5.92A17F7A4CAD321DF77E27245D143E36] - 28/01/2014 - 15:26:15 ---A- - C:\Windows\Prefetch\RE-MARKABLE_2040-4040.EXE-55F19556.pf =>PUP.Re-Markable
O45 - LFCP:[MD5.AA36586AF199BD44479554CFF73D8A68] - 28/01/2014 - 15:31:33 ---A- - C:\Windows\Prefetch\VISUALBEESOFTWARE.EXE-8E9257BA.pf =>Adware.VisualBeeToolbar
O45 - LFCP:[MD5.BA307574BFECAC8B70950FC15FEC8763] - 28/01/2014 - 15:35:21 ---A- - C:\Windows\Prefetch\VISUALBEEDB.EXE-BA1E0661.pf =>Adware.VisualBeeToolbar
O45 - LFCP:[MD5.C3E67F9DB0AB50576DCECCF942AFFC49] - 28/01/2014 - 21:15:17 ---A- - C:\Windows\Prefetch\DELEGATE_EXECUTE.EXE-90C2D90D.pf
O45 - LFCP:[MD5.D13A78BABE3C6D22F854D93EF6A8667D] - 29/01/2014 - 01:09:51 ---A- - C:\Windows\Prefetch\SETUP.EXE-91688D63.pf
O45 - LFCP:[MD5.9D4EC0789EB60B53EA71B28DDE314A9D] - 29/01/2014 - 01:10:00 ---A- - C:\Windows\Prefetch\32.0.1700.102_32.0.1700.76_CH-303A9D48.pf
O45 - LFCP:[MD5.BCBB1FF5C343DFD975EE63236B477824] - 29/01/2014 - 01:10:02 ---A- - C:\Windows\Prefetch\SETUP.EXE-032E9C8A.pf
O45 - LFCP:[MD5.0C13D7A1A49D482ADA38F2097F544245] - 29/01/2014 - 12:25:22 ---A- - C:\Windows\Prefetch\BACKGROUNDTASKHOST.EXE-8C0D8201.pf
O45 - LFCP:[MD5.69600BCE16AB14E283A8A96EE594B1F2] - 29/01/2014 - 12:25:23 ---A- - C:\Windows\Prefetch\LIVECOMM.EXE-90010E4F.pf
O45 - LFCP:[MD5.341C2B297C875AD881FC0AD375752303] - 29/01/2014 - 21:37:12 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-B51A0D95.pf
O45 - LFCP:[MD5.2C83B1020212F6E30850254D6D109FE7] - 30/01/2014 - 06:45:54 ---A- - C:\Windows\Prefetch\UPDATE.EXE-46733ABF.pf
O45 - LFCP:[MD5.BA5FBF88C9E6E8EBBB4B1AFEF79D9BB3] - 30/01/2014 - 12:23:23 ---A- - C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-C6CFE2A8.pf
O45 - LFCP:[MD5.7B018584220C376693DE486B1244A9B2] - 30/01/2014 - 12:23:24 ---A- - C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-10E4267C.pf
O45 - LFCP:[MD5.69E85F52C38BE887CA76CF6EA1B79910] - 30/01/2014 - 12:42:01 ---A- - C:\Windows\Prefetch\AVPUI.EXE-CBE774B8.pf
O45 - LFCP:[MD5.8226F0B3F01AF2ADA73F750AEA8F9E1E] - 30/01/2014 - 12:42:12 ---A- - C:\Windows\Prefetch\OULOOKUP.EXE-BEB9F285.pf
O45 - LFCP:[MD5.5F0CF0905847DAD89E4D31F364471120] - 30/01/2014 - 12:42:24 ---A- - C:\Windows\Prefetch\OUDOWNLOAD.EXE-FA110A2B.pf
O45 - LFCP:[MD5.00D19072C137DF0E8EC1A9AB6F404953] - 30/01/2014 - 12:42:42 ---A- - C:\Windows\Prefetch\ITUNESHELPER.EXE-722A54DB.pf
O45 - LFCP:[MD5.5D6EA531D4ABC0B7668ED229EC04D4E7] - 30/01/2014 - 12:42:42 ---A- - C:\Windows\Prefetch\SOFFICE.EXE-7F5AFD1D.pf
O45 - LFCP:[MD5.852201574A09ABE6FAAB40C178B7A079] - 30/01/2014 - 12:42:42 ---A- - C:\Windows\Prefetch\WIAWOW64.EXE-35DF33E2.pf
O45 - LFCP:[MD5.4D659A17DACFA6694CD03F1BFFCC0F78] - 30/01/2014 - 12:42:44 ---A- - C:\Windows\Prefetch\APSDAEMON.EXE-8C865900.pf
O45 - LFCP:[MD5.80BE82516E5CD03FFF05331E2DE43DED] - 30/01/2014 - 12:42:45 ---A- - C:\Windows\Prefetch\OUNOTIFICATION.EXE-74F61CA0.pf
O45 - LFCP:[MD5.2C05AAB2586DE1D700C3A8C1BF64FF7C] - 30/01/2014 - 12:45:58 ---A- - C:\Windows\Prefetch\WWAHOST.EXE-9178D9A9.pf
O45 - LFCP:[MD5.07E3C2F23F4D0B25DD5B68D1CBF32E7D] - 30/01/2014 - 12:49:27 ---A- - C:\Windows\Prefetch\INSTALL_FLASHPLAYER12X32AU_LT-7D8CFEE8.pf
O45 - LFCP:[MD5.C9D26FAF91B9D7C30E328FED10E2E71C] - 30/01/2014 - 13:41:13 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-CA57A442.pf
O45 - LFCP:[MD5.AEAA0695E01641DDE8FDF5813B84D875] - 30/01/2014 - 13:41:14 ---A- - C:\Windows\Prefetch\GLCND.EXE-02A191A6.pf
O45 - LFCP:[MD5.2AAE1DCEBA568006B2AA1034BDB48734] - 30/01/2014 - 15:50:46 ---A- - C:\Windows\Prefetch\SETHC.EXE-D1EC56ED.pf
O45 - LFCP:[MD5.091792D28020C9F401D628DFCB0AC363] - 30/01/2014 - 15:50:56 ---A- - C:\Windows\Prefetch\EASEOFACCESSDIALOG.EXE-E54B6BCB.pf
O45 - LFCP:[MD5.A352B9791DF6EFF0D716B9EE4CD25FA3] - 30/01/2014 - 17:07:41 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-5CF63FAB.pf
O45 - LFCP:[MD5.0426343BCD0E44C35BA5CBD4895C5C95] - 31/01/2014 - 06:53:00 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-B7DB5223.pf
O45 - LFCP:[MD5.D3F016BDFFD9A064D01B340B736A5FED] - 31/01/2014 - 10:35:47 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-8CB4FF16.pf
O45 - LFCP:[MD5.1EB4923F0144042907D1D0B767FEBDFA] - 31/01/2014 - 20:18:36 ---A- - C:\Windows\Prefetch\SNDVOL.EXE-276AC160.pf
~ Prefetcher: 280 Scanned in 00mn 05s



---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Fournisseur de sécurité TLS/SSL.) -- C:\Windows\System32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Live Security Package.) -- C:\Windows\System32\livessp.dll
~ LSA: 9 Scanned in 00mn 00s



---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\BasicDisplay.sys . (.Microsoft Corporation - Microsoft Basic Display Driver.) -- C:\Windows\System32\Drivers\BasicDisplay.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\BasicRender.sys . (.Microsoft Corporation - Microsoft Basic Render Driver.) -- C:\Windows\System32\Drivers\BasicRender.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dxgkrnl.sys . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\Drivers\dxgkrnl.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\FsDepends.sys . (.Microsoft Corporation - File System Dependency Manager Mini Filter Driver.) -- C:\Windows\System32\Drivers\FsDepends.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\BasicDisplay.sys . (.Microsoft Corporation - Microsoft Basic Display Driver.) -- C:\Windows\System32\Drivers\BasicDisplay.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\BasicRender.sys . (.Microsoft Corporation - Microsoft Basic Render Driver.) -- C:\Windows\System32\Drivers\BasicRender.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dxgkrnl.sys . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\Drivers\dxgkrnl.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\FsDepends.sys . (.Microsoft Corporation - File System Dependency Manager Mini Filter Driver.) -- C:\Windows\System32\Drivers\FsDepends.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (...) -- C:\Windows\System32\Drivers\rdpencdd.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
~ CSB: 17 Scanned in 00mn 00s



---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
~ TDSD: 2 Scanned in 00mn 00s



---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ MSCP: 2 Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableCursorSuppression"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLinkedConnections"=1
~ MWPS: 18 Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1
~ MWPE Keys: 3 Scanned in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.E1832BD9FD7E0FC2DC9FA5935DE3E8C1] - 22/08/2013 - 12:38:15 ---A- . (.Microsoft Corporation - 1394 OpenHCI Driver.) -- C:\Windows\System32\Drivers\1394ohci.sys [231424]
O58 - SDL:[MD5.AD508A1A46EC21B740AB31C28EFDFDB1] - 22/08/2013 - 13:43:41 ---A- . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\Drivers\3ware.sys [108896]
O58 - SDL:[MD5.3D30878A269D934100FA5F972E53AF39] - 14/11/2013 - 08:37:14 ---A- . (.Microsoft Corporation - Pilote ACPI pour NT.) -- C:\Windows\System32\Drivers\acpi.sys [523096]
O58 - SDL:[MD5.AC8279D229398BCF05C3154ADCA86813] - 22/08/2013 - 13:49:54 ---A- . (.Microsoft Corporation - ACPIEx Driver.) -- C:\Windows\System32\Drivers\acpiex.sys [79712]
O58 - SDL:[MD5.A8970D9BF23CD309E0403978A1B58F3F] - 22/08/2013 - 12:38:48 ---A- . (.Microsoft Corporation - ACPI Processor Aggregator Device Driver.) -- C:\Windows\System32\Drivers\acpipagr.sys [10240]
O58 - SDL:[MD5.111A89C99C5B4F1A7BCE5F643DD86F65] - 22/08/2013 - 12:38:53 ---A- . (.Microsoft Corporation - ACPI Power Metering Driver.) -- C:\Windows\System32\Drivers\acpipmi.sys [12288]
O58 - SDL:[MD5.5758387D68A20AE7D3245011B07E36E7] - 22/08/2013 - 12:38:58 ---A- . (.Microsoft Corporation - ACPI Wake Alarm.) -- C:\Windows\System32\Drivers\acpitime.sys [10752]
O58 - SDL:[MD5.7C1FDF1B48298CBA7CE4BDD4978951AD] - 22/08/2013 - 13:43:41 ---A- . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS/SATA controller.) -- C:\Windows\System32\Drivers\adp80xx.sys [782176]
O58 - SDL:[MD5.239268BAB58EAE9A3FF4E08334C00451] - 22/08/2013 - 14:25:35 ---A- . (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\Windows\System32\Drivers\afd.sys [567296]
O58 - SDL:[MD5.55FE43112F61836D0581D615C72AA113] - 14/11/2013 - 08:31:09 ---A- . (.Microsoft Corporation - RAS Agile Vpn Miniport Call Manager.) -- C:\Windows\System32\Drivers\agilevpn.sys [97280]
O58 - SDL:[MD5.7DFAEBA9AD62D20102B576D5CAC45EC8] - 22/08/2013 - 13:43:40 ---A- . (.Microsoft Corporation - Filtre AGP 440 NT.) -- C:\Windows\System32\Drivers\AGP440.sys [62304]
O58 - SDL:[MD5.8E8E34B7BA059050EED827410D0697A2] - 22/08/2013 - 12:39:54 ---A- . (.Microsoft Corporation - Application Compatibility Cache.) -- C:\Windows\System32\Drivers\ahcache.sys [76800]
O58 - SDL:[MD5.7589DE749DB6F71A68489DCE04158729] - 22/08/2013 - 09:46:34 ---A- . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\Drivers\amdk8.sys [95744]
O58 - SDL:[MD5.B46D2D89AFF8A9490FA8C98C7A5616E3] - 22/08/2013 - 09:46:35 ---A- . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\Drivers\amdppm.sys [98816]
O58 - SDL:[MD5.D2BF2F94A47D332814910FD47C6BBCD2] - 22/08/2013 - 13:43:41 ---A- . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [79200]
O58 - SDL:[MD5.A8E04943C7BBA7219AA50400272C3C6E] - 22/08/2013 - 13:43:41 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows -.) -- C:\Windows\System32\Drivers\amdsbs.sys [259424]
O58 - SDL:[MD5.CEA5F4F27CFC08E3A44D576811B35F50] - 22/08/2013 - 13:43:40 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [25952]
O58 - SDL:[MD5.04951A9A937CBE28A2D3FEEA360B6D1F] - 14/11/2013 - 08:31:09 ---A- . (.Microsoft Corporation - AppID Driver.) -- C:\Windows\System32\Drivers\appid.sys [83456]
O58 - SDL:[MD5.65045784366F7EC5FB4E71BCF923187B] - 22/08/2013 - 13:43:41 ---A- . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [114016]
O58 - SDL:[MD5.0E27000220635C2D831B0A4689AFF6E9] - 08/01/2014 - 12:33:52 ---A- . (.AVAST Software - avast! Filtering NDIS driver.) -- C:\Windows\System32\Drivers\aswNdisFlt.sys [439648]
O58 - SDL:[MD5.3DB7721F06BC2FEDB25029EA23AB27DA] - 22/08/2013 - 12:38:53 ---A- . (.Microsoft Corporation - MS Remote Access serial network driver.) -- C:\Windows\System32\Drivers\asyncmac.sys [26624]
O58 - SDL:[MD5.74B14192CF79A72F7536B27CB8814FBD] - 22/08/2013 - 13:43:41 ---A- . (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\Drivers\atapi.sys [26464]
O58 - SDL:[MD5.38E1F4E0148A24C65D215F14D57B0711] - 22/08/2013 - 13:43:41 ---A- . (.Microsoft Corporation - ATAPI Driver Extension.) -- C:\Windows\System32\Drivers\ataport.sys [199520]
O58 - SDL:[MD5.506907D2E7F3A5B67DBD39C00A788B7C] - 17/07/2012 - 01:59:12 ---A- . (.Advanced Micro Devices - AMD High Definition Audio Function Driver.) -- C:\Windows\System32\Drivers\AtihdW86.sys [98472]
O58 - SDL:[MD5.FBB35875FEFE53D4280259842069ED72] - 13/12/2013 - 10:23:36 ---A- . (.Advanced Micro Devices, Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\System32\Drivers\atikmdag.sys [13207552]
O58 - SDL:[MD5.A32BCAD9377E3B75D034CAFBA463A0AE] - 13/12/2013 - 10:23:36 ---A- . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\System32\Drivers\atikmpag.sys [626176]
O58 - SDL:[MD5.8CC7F7E4AFCBA605921B137ED7992C68] - 22/08/2013 - 12:39:31 ---A- . (.Microsoft Corporation - Microsoft Basic Display Driver.) -- C:\Windows\System32\Drivers\BasicDisplay.sys [50688]
O58 - SDL:[MD5.2748E116F8621A4DB0D39FCDD7318C01] - 22/08/2013 - 12:39:28 ---A- . (.Microsoft Corporation - Microsoft Basic Render Driver.) -- C:\Windows\System32\Drivers\BasicRender.sys [33792]
O58 - SDL:[MD5.99387C515F80270F097F6DD9B5315649] - 22/08/2013 - 13:49:53 ---A- . (.Microsoft Corporation - Battery Class Driver.) -- C:\Windows\System32\Drivers\battc.sys [35168]
O58 - SDL:[MD5.C1ABB0F7E3BEA48A0417BDF6FF14AB21] - 13/08/2013 - 00:25:46 ---A- . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\Drivers\bcmfn2.sys [17624]
O58 - SDL:[MD5.EC19013E4CF87609534165DF897274D6] - 22/08/2013 - 12:40:24 ---A- . (.Microsoft Corporation - BEEP Driver.) -- C:\Windows\System32\Drivers\beep.sys [7680]
O58 - SDL:[MD5.6B4FFFDDC618FCF64473CAA86E305697] - 22/08/2013 - 12:38:38 ---A- . (.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) -- C:\Windows\System32\Drivers\bowser.sys [102912]
O58 - SDL:[MD5.4E888019078AC363076A5433E89AA4F8] - 22/08/2013 - 12:35:50 ---A- . (.Microsoft Corporation - MAC Bridge Driver.) -- C:\Windows\System32\Drivers\bridge.sys [115712]
O58 - SDL:[MD5.6E0EC0555D22CF81730848DE57EB3D66] - 14/11/2013 - 08:31:05 ---A- . (.Microsoft Corporation - Microsoft Bluetooth Audio Multiprofile Manager.) -- C:\Windows\System32\Drivers\BtaMPM.sys [19456]
O58 - SDL:[MD5.A8F23D453A424FF4DE04989C4727ECC7] - 22/08/2013 - 12:38:39 ---A- . (.Microsoft Corporation - HID de contrôle à distance audio/vidéo Bluetooth.) -- C:\Windows\System32\Drivers\BthAvrcpTg.sys [36992]
O58 - SDL:[MD5.746B9F94214915AECDE4B7FEA5FF9664] - 22/08/2013 - 12:37:42 ---A- . (.Microsoft Corporation - Bluetooth Hands-Free Audio and Call Control HID Enumerator.) -- C:\Windows\System32\Drivers\bthhfenum.sys [57856]
O58 - SDL:[MD5.71FE2A48E4C93DDB9798C024880B6C07] - 22/08/2013 - 12:38:16 ---A- . (.Microsoft Corporation - Minipilote HID mains libres Bluetooth.) -- C:\Windows\System32\Drivers\BthhfHid.sys [30720]
O58 - SDL:[MD5.07E33226AD218A2A162662A05CAFB52F] - 22/08/2013 - 12:36:44 ---A- . (.Microsoft Corporation - Bluetooth Communications Driver.) -- C:\Windows\System32\Drivers\bthmodem.sys [63488]
O58 - SDL:[MD5.A4A73F631FE2AA2826FBE4A399B04DEF] - 22/08/2013 - 13:43:41 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbda.sys [531296]
O58 - SDL:[MD5.2FA6510E33F7DEFEC03658B74101A9B9] - 22/08/2013 - 12:40:15 ---A- . (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\Drivers\cdfs.sys [88576]
O58 - SDL:[MD5.C6796EA22B513E3457514D92DCDB1A3D] - 22/08/2013 - 09:46:35 ---A- . (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\Drivers\cdrom.sys [164352]
O58 - SDL:[MD5.BE9936EDD3267FAAFF94A7835867F00B] - 22/08/2013 - 12:38:25 ---A- . (.Microsoft Corporation - Consumer IR Class Driver for eHome.) -- C:\Windows\System32\Drivers\circlass.sys [44032]
O58 - SDL:[MD5.E18B615257E80E4A1EC6148943CED42B] - 22/08/2013 - 14:25:40 ---A- . (.Microsoft Corporation - SCSI Class System Dll.) -- C:\Windows\System32\Drivers\Classpnp.sys [337760]
O58 - SDL:[MD5.7F006813C2AFE622C13D7AF94F56CD07] - 22/08/2013 - 13:39:44 ---A- . (.Microsoft Corporation - Common Log File System Driver.) -- C:\Windows\System32\Drivers\clfs.sys [377696]
O58 - SDL:[MD5.EF6EF85DADC3184A10D8F2F7159973CB] - 22/08/2013 - 12:39:43 ---A- . (.Microsoft Corporation - Control Method Battery Driver.) -- C:\Windows\System32\Drivers\CmBatt.sys [25472]
O58 - SDL:[MD5.825BE21E6395E00698D8A23955A87972] - 22/08/2013 - 13:41:39 ---A- . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\Windows\System32\Drivers\cng.sys [564520]
O58 - SDL:[MD5.03AAED827C36F35D70900558B8274905] - 22/08/2013 - 12:38:48 ---A- . (.Microsoft Corporation - Multi-Transport Composite Bus Enumerator.) -- C:\Windows\System32\Drivers\CompositeBus.sys [36352]
O58 - SDL:[MD5.A1FF7DFBFBE164CF92603C651D304DD2] - 22/08/2013 - 14:25:40 ---A- . (.Microsoft Corporation - Console Driver.) -- C:\Windows\System32\Drivers\condrv.sys [43008]
O58 - SDL:[MD5.FA47B0AA255B7CF4519E995C6404AE22] - 22/08/2013 - 13:43:41 ---A- . (.Microsoft Corporation - Crash Dump Driver.) -- C:\Windows\System32\Drivers\crashdmp.sys [68960]
O58 - SDL:[MD5.315BA4BC19316D72B2E037534E048B93] - 22/08/2013 - 13:50:19 ---A- . (.Microsoft Corporation - DAM Kernel Driver.) -- C:\Windows\System32\Drivers\dam.sys [57696]
O58 - SDL:[MD5.5DB26D7E0216D0BF364A81D3829AD7B9] - 22/08/2013 - 12:38:00 ---A- . (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\Drivers\dfsc.sys [134656]
O58 - SDL:[MD5.4D40C9B33F738797CF50E77CB7C53E85] - 22/08/2013 - 13:39:44 ---A- . (.Microsoft Corporation - PnP Disk Driver.) -- C:\Windows\System32\Drivers\disk.sys [100192]
O58 - SDL:[MD5.224C2CB37497472C345CB2A02DF11363] - 22/08/2013 - 13:43:40 ---A- . (.Microsoft Corporation - Crash Dump Disk Driver.) -- C:\Windows\System32\Drivers\Diskdump.sys [36192]
O58 - SDL:[MD5.407B4FC1AEE5C19AC2ED7118CBB271E9] - 22/08/2013 - 12:40:38 ---A- . (.Microsoft Corporation - Boot Over USB Dump Driver.) -- C:\Windows\System32\Drivers\Dmpusbstor.sys [13312]
O58 - SDL:[MD5.EB70A894708D1BC176AFD690FF06085F] - 22/08/2013 - 12:37:14 ---A- . (.Microsoft Corporation - Dynamic Memory.) -- C:\Windows\System32\Drivers\dmvsc.sys [29696]
O58 - SDL:[MD5.3103BBAB41F0C75BE6FA302439C9B9D6] - 22/08/2013 - 12:39:24 ---A- . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\Drivers\drmk.sys [88576]
O58 - SDL:[MD5.DDC11A202207C0400CBE07315B8FDE5E] - 22/08/2013 - 13:40:31 ---A- . (.Microsoft Corporation - Microsoft Trusted Audio Drivers.) -- C:\Windows\System32\Drivers\drmkaud.sys [14560]
O58 - SDL:[MD5.05F5C162881BE293956C60456EDB0092] - 22/08/2013 - 13:39:46 ---A- . (.Microsoft Corporation - ATAPI Dump Driver.) -- C:\Windows\System32\Drivers\Dumpata.sys [33632]
O58 - SDL:[MD5.05C674A72412E6400D5A2684C867402D] - 22/08/2013 - 13:45:59 ---A- . (.Microsoft Corporation - Bitlocker Drive Encryption Crashdump Filter.) -- C:\Windows\System32\Drivers\dumpfve.sys [71896]
O58 - SDL:[MD5.E194BE41AE3C80CFBBEBAC3394160091] - 14/11/2013 - 08:31:05 ---A- . (.Microsoft Corporation - SD Crashdump Port Driver.) -- C:\Windows\System32\Drivers\dumpsd.sys [151384]
O58 - SDL:[MD5.A3D1CB64DF885ACE126543E6D7067348] - 18/01/2014 - 14:19:44 ---A- . (.Microsoft Corporation - DirectX Graphics Kernel.) -- C:\Windows\System32\Drivers\dxgkrnl.sys [1530200]
O58 - SDL:[MD5.9E167CDB2AEEF7994434543D0543AEEB] - 18/01/2014 - 14:19:44 ---A- . (.Microsoft Corporation - DirectX Graphics MMS.) -- C:\Windows\System32\Drivers\dxgmms1.sys [382808]
O58 - SDL:[MD5.43531A5993380CC5113242C29D265FD9] - 22/08/2013 - 13:43:40 ---A- . (.Microsoft Corporation - Enhanced Storage Class driver for IEEE 1667 devices.) -- C:\Windows\System32\Drivers\EhStorClass.sys [82784]
O58 - SDL:[MD5.6F8E738A9505A388B1157FDDE7B3101B] - 22/08/2013 - 13:43:40 ---A- . (.Microsoft Corporation - Microsoft driver for storage devices supporting IEEE 1667 and T.) -- C:\Windows\System32\Drivers\EhStorTcgDrv.sys [114016]
O58 - SDL:[MD5.DFFFAE1442BA4076E18EED5E406FA0D3] - 22/08/2013 - 12:38:45 ---A- . (.Microsoft Corporation - Error Device Driver.) -- C:\Windows\System32\Drivers\errdev.sys [10240]
O58 - SDL:[MD5.114BCFDF367FF37C3F1B0A96AF542E4D] - 22/08/2013 - 13:43:45 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbda.sys [3357024]
O58 - SDL:[MD5.7729D294A555C7AEB281ED8E4D0E01E4] - 22/08/2013 - 12:40:18 ---A- . (.Microsoft Corporation - Microsoft Extended FAT File System.) -- C:\Windows\System32\Drivers\exfat.sys [200704]
O58 - SDL:[MD5.7C4E0D5900B2A1D11EDD626D6DDB937B] - 22/08/2013 - 13:49:30 ---A- . (.Microsoft Corporation - Fast FAT File System Driver.) -- C:\Windows\System32\Drivers\fastfat.sys [217952]
O58 - SDL:[MD5.5D8402613E778B3BD45E687A8372710B] - 22/08/2013 - 12:40:18 ---A- . (.Microsoft Corporation - Floppy Disk Controller Driver.) -- C:\Windows\System32\Drivers\fdc.sys [30720]
O58 - SDL:[MD5.957A7A8F5ACCAF23DD9DFF6DAA393CE5] - 22/08/2013 - 13:49:30 ---A- . (.Microsoft Corporation - FileInfo Filter Driver.) -- C:\Windows\System32\Drivers\fileinfo.sys [79200]
O58 - SDL:[MD5.A1A66C4FDAFD6B0289523232AFB7D8AF] - 22/08/2013 - 12:39:41 ---A- . (.Microsoft Corporation - File Trace Filter Driver.) -- C:\Windows\System32\Drivers\filetrace.sys [34816]
O58 - SDL:[MD5.BE743083CF7063C486A4398E3AEFE59A] - 22/08/2013 - 12:40:18 ---A- . (.Microsoft Corporation - Floppy Driver.) -- C:\Windows\System32\Drivers\flpydisk.sys [25088]
O58 - SDL:[MD5.60D5067FCE6D9433D35E04C01D8538B3] - 22/08/2013 - 14:25:41 ---A- . (.Microsoft Corporation - Gestionnaire de filtres de système de fichiers Microsoft.) -- C:\Windows\System32\Drivers\fltMgr.sys [358752]
O58 - SDL:[MD5.35005534E600E993A90B036E4E599F2B] - 22/08/2013 - 13:49:30 ---A- . (.Microsoft Corporation - File System Dependency Manager Mini Filter Driver.) -- C:\Windows\System32\Drivers\fsdepends.sys [56672]
O58 - SDL:[MD5.09F460AFEDCA03F3BF6E07D1CCC9AC42] - 22/08/2013 - 14:25:40 ---A- . (.Microsoft Corporation - File System Recognizer Driver.) -- C:\Windows\System32\Drivers\fs_rec.sys [30048]
O58 - SDL:[MD5.83E1F0983B02A6F8EC764D18E24ECF10] - 14/11/2013 - 08:31:23 ---A- . (.Microsoft Corporation - BitLocker Drive Encryption Driver.) -- C:\Windows\System32\Drivers\fvevol.sys [579416]
O58 - SDL:[MD5.9ED04A7137B4451303407DFBAB15457A] - 22/08/2013 - 14:25:35 ---A- . (.Microsoft Corporation - FWP/IPsec Kernel-Mode API.) -- C:\Windows\System32\Drivers\FWPKCLNT.SYS [428896]
O58 - SDL:[MD5.9591D0B9351ED489EAFD9D1CE52A8015] - 22/08/2013 - 09:46:33 ---A- . (.Microsoft Corporation - Processor Driver.) -- C:\Windows\System32\Drivers\fxppm.sys [27136]
O58 - SDL:[MD5.FC3EF65EE20D39F8749C2218DBA681CA] - 22/08/2013 - 13:43:45 ---A- . (.Microsoft Corporation - Filtre AGPv3.0 générique Microsoft pour plateformes de processe.) -- C:\Windows\System32\Drivers\GAGP30KX.SYS [65888]
O58 - SDL:[MD5.8E98D21EE06192492A5671A6144D092F] - 21/08/2012 - 13:01:20 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys [33240]
O58 - SDL:[MD5.464EA5B89667AECA4E50BCC6EF835886] - 18/01/2012 - 16:41:44 ---A- . (.Guillemot Corp S.A. - Guillemot USB Audio Processing Filter.) -- C:\Windows\System32\Drivers\guillflt.sys [71024]
O58 - SDL:[MD5.03909BDBFF0DCACCABF2B2D4ADEE44DC] - 22/08/2013 - 12:38:38 ---A- . (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\Drivers\hdaudbus.sys [78336]
O58 - SDL:[MD5.10A70BC1871CD955D85CD88372724906] - 22/08/2013 - 12:39:01 ---A- . (.Microsoft Corporation - Hid Battery Driver.) -- C:\Windows\System32\Drivers\hidbatt.sys [26624]
O58 - SDL:[MD5.1EA1B4FABB8CC348E73CA90DBA22E104] - 22/08/2013 - 12:38:39 ---A- . (.Microsoft Corporation - Pilote de miniport Bluetooth pour les périphériques HID.) -- C:\Windows\System32\Drivers\hidbth.sys [96768]
O58 - SDL:[MD5.ADB26481D4D247C1D6986EC45FFDAB53] - 22/08/2013 - 12:39:14 ---A- . (.Microsoft Corporation - Bibliothèque Hid Class.) -- C:\Windows\System32\Drivers\hidclass.sys [111616]
O58 - SDL:[MD5.C241A8BAFBBFC90176EA0F5240EACC17] - 22/08/2013 - 12:37:28 ---A- . (.Microsoft Corporation - I2C HID Miniport Driver.) -- C:\Windows\System32\Drivers\hidi2c.sys [41472]
O58 - SDL:[MD5.9BDDEE26255421017E161CCB9D5EDA95] - 22/08/2013 - 12:39:16 ---A- . (.Microsoft Corporation - Infrared Miniport Driver for Input Devices.) -- C:\Windows\System32\Drivers\hidir.sys [45568]
O58 - SDL:[MD5.7FFB24B4A54B1ACD46CF6899D879CC9F] - 22/08/2013 - 12:40:26 ---A- . (.Microsoft Corporation - Hid Parsing Library.) -- C:\Windows\System32\Drivers\hidparse.sys [32512]
O58 - SDL:[MD5.F31397220D9687E11EB448649AA6E038] - 22/08/2013 - 12:38:58 ---A- . (.Microsoft Corporation - USB Miniport Driver for Input Devices.) -- C:\Windows\System32\Drivers\hidusb.sys [33792]
O58 - SDL:[MD5.A6AACEA4C785789BDA5912AD1FEDA80D] - 22/08/2013 - 13:43:45 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [64352]
O58 - SDL:[MD5.3502776E366C913D49C0DA928AE3E6CB] - 22/08/2013 - 13:32:16 ---A- . (.Microsoft Corporation - HTTP Pile du protocole.) -- C:\Windows\System32\Drivers\http.sys [994144]
O58 - SDL:[MD5.90656C0B3864804B090434EFC582404F] - 22/08/2013 - 13:39:47 ---A- . (.Microsoft Corporation - Hardware Policy Driver.) -- C:\Windows\System32\Drivers\hwpolicy.sys [24416]
O58 - SDL:[MD5.34F79FF9253EB2F219B1CE3292503A98] - 29/12/2011 - 13:56:22 ---A- . (.Guillemot Corporation - Filter Driver for the Hercules Webcams (MJPG).) -- C:\Windows\System32\Drivers\hxctlflt.sys [117104]
O58 - SDL:[MD5.6D6F9E3BF0484967E52F7E846BFF1CA1] - 22/08/2013 - 12:37:49 ---A- . (.Microsoft Corporation - Microsoft VMBus Synthetic Keyboard Driver.) -- C:\Windows\System32\Drivers\hyperkbd.sys [13824]
O58 - SDL:[MD5.907C870F8C31F8DDD6F090857B46AB25] - 22/08/2013 - 12:39:20 ---A- . (.Microsoft Corporation - Microsoft VMBus Video Device Miniport Driver.) -- C:\Windows\System32\Drivers\HyperVideo.sys [22016]
O58 - SDL:[MD5.84CFC5EFA97D0C965EDE1D56F116A541] - 22/08/2013 - 12:39:15 ---A- . (.Microsoft Corporation - Pilote de port i8042.) -- C:\Windows\System32\Drivers\i8042prt.sys [107520]
O58 - SDL:[MD5.5D90E32E36CE5D4C535D17CE08AEAF05] - 30/07/2013 - 19:47:35 ---A- . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\Drivers\iaLPSSi_GPIO.sys [24568]
O58 - SDL:[MD5.DD05E7E80F52ADE9AEB292819920F32C] - 25/07/2013 - 20:05:39 ---A- . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\Windows\System32\Drivers\iaLPSSi_I2C.sys [99320]
O58 - SDL:[MD5.08BFE413B0B4AA8DFA4B5684CE06D3DC] - 10/08/2013 - 01:39:30 ---A- . (.Intel Corporation - Intel Rapid Storage Technology driver (inbox) - x64.) -- C:\Windows\System32\Drivers\iaStorAV.sys [651248]
O58 - SDL:[MD5.A2200C3033FA4EF249FC096A7A7D02A2] - 22/08/2013 - 13:43:45 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\Drivers\iaStorV.sys [412000]
O58 - SDL:[MD5.4E448FCFFD00E8D657CD9E48D3E47157] - 22/08/2013 - 13:43:44 ---A- . (.Microsoft Corporation - Intel PCI IDE Driver.) -- C:\Windows\System32\Drivers\intelide.sys [18272]
O58 - SDL:[MD5.139CFCDCD36B1B1782FD8C0014AC9B0E] - 18/01/2014 - 14:19:43 ---A- . (.Microsoft Corporation - Intel Power Engine Plugin.) -- C:\Windows\System32\Drivers\intelpep.sys [39768]
O58 - SDL:[MD5.47E74A8E53C7C24DCE38311E1451C1D9] - 22/08/2013 - 09:46:35 ---A- . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\Drivers\intelppm.sys [98816]
O58 - SDL:[MD5.9DB76D7F9E4E53EFE5DD8C53DE837514] - 22/08/2013 - 12:35:51 ---A- . (.Microsoft Corporation - IP FILTER DRIVER.) -- C:\Windows\System32\Drivers\ipfltdrv.sys [84992]
O58 - SDL:[MD5.9949A3C7590B8C536C05312205079A82] - 22/08/2013 - 12:38:56 ---A- . (.Microsoft Corporation - PILOT IPMI WMI.) -- C:\Windows\System32\Drivers\IPMIDrv.sys [79360]
O58 - SDL:[MD5.E23D32BAF152FBE35F18C6A2AB8EF271] - 14/11/2013 - 08:31:09 ---A- . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys [141824]
O58 - SDL:[MD5.D826F4874A372FAE2F42478E0975EA02] - 22/08/2013 - 12:37:35 ---A- . (.Microsoft Corporation - IRDA Protocol Driver.) -- C:\Windows\System32\Drivers\irda.sys [118784]
O58 - SDL:[MD5.AE44C526AB5F8A487D941CEB57B10C97] - 22/08/2013 - 12:38:30 ---A- . (.Microsoft Corporation - Infra-Red Bus Enumerator.) -- C:\Windows\System32\Drivers\irenum.sys [17920]
O58 - SDL:[MD5.8AFEEA3955AA43616A60F133B1D25F21] - 22/08/2013 - 13:43:45 ---A- . (.Microsoft Corporation - Pilote de bus PNP ISA.) -- C:\Windows\System32\Drivers\isapnp.sys [21856]
O58 - SDL:[MD5.8BE92376799B6B44D543E8D07CDCF885] - 22/08/2013 - 13:43:45 ---A- . (.Microsoft Corporation - Pilote de la classe Clavier.) -- C:\Windows\System32\Drivers\kbdclass.sys [58208]
O58 - SDL:[MD5.FB6E47E569D4872ABEB506BE03A45FBA] - 22/08/2013 - 12:39:13 ---A- . (.Microsoft Corporation - Pilote de filtre clavier HID.) -- C:\Windows\System32\Drivers\kbdhid.sys [32256]
O58 - SDL:[MD5.813871C7D402A05F2E3A7075F9584A05] - 22/08/2013 - 12:38:26 ---A- . (.Microsoft Corporation - Microsoft Kernel Debugger Network Miniport.) -- C:\Windows\System32\Drivers\kdnic.sys [19456]
O58 - SDL:[MD5.65EBBB459B66C818E809DD8135DCFFA2] - 14/11/2013 - 08:31:08 ---A- . (.Microsoft Corporation - Kernel CSA Library.) -- C:\Windows\System32\Drivers\ks.sys [285696]
O58 - SDL:[MD5.ADDECBCC777665BD113BED437E602AB0] - 14/11/2013 - 08:31:05 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecdd.sys [101208]
O58 - SDL:[MD5.7296EA420134EAC390798B3232D066A4] - 22/08/2013 - 13:44:43 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface Packages.) -- C:\Windows\System32\Drivers\ksecpkg.sys [192864]
O58 - SDL:[MD5.11AFB527AA370B1DAFD5C36F35F6D45F] - 22/08/2013 - 12:39:31 ---A- . (.Microsoft Corporation - Kernel Streaming WOW Thunk Service.) -- C:\Windows\System32\Drivers\ksthunk.sys [21248]
O58 - SDL:[MD5.C09010B3680860131631F53E8FE7BAD8] - 22/08/2013 - 12:36:18 ---A- . (.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) -- C:\Windows\System32\Drivers\lltdio.sys [59392]
O58 - SDL:[MD5.C755AE4635457AA2A11F79C0DF857ABC] - 22/08/2013 - 13:43:44 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [109408]
O58 - SDL:[MD5.ADAC09CBE7A2040B7F68B5E5C9A75141] - 22/08/2013 - 13:43:45 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [93536]
O58 - SDL:[MD5.04D1274BB9BBCCF12BD12374002AA191] - 22/08/2013 - 13:43:44 ---A- . (.LSI Corporation - LSI SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas3.sys [81760]
O58 - SDL:[MD5.327469EEF3833D0C584B7E88A76AEC0C] - 22/08/2013 - 13:43:45 ---A- . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sss.sys [82784]
O58 - SDL:[MD5.5EF604B0698F4FA962778285E8C5F1F2] - 22/08/2013 - 12:39:36 ---A- . (.Microsoft Corporation - Pilote de filtre de virtualisation de fichier LUA.) -- C:\Windows\System32\Drivers\luafv.sys [123904]
O58 - SDL:[MD5.0BB97D43299910CBFBA59C461B99B910] - 04/04/2013 - 13:50:32 ---A- . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Windows\System32\Drivers\mbam.sys [25928]
O58 - SDL:[MD5.C895E3FAE8628EAA4ADE0F52862CA575] - 22/08/2013 - 12:39:38 ---A- . (.Microsoft Corporation - Medium changer class driver.) -- C:\Windows\System32\Drivers\mcd.sys [22016]
O58 - SDL:[MD5.EB5C03A070F30D64A6DF80E53B22F53F] - 22/08/2013 - 13:43:45 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\Drivers\megasas.sys [56672]
O58 - SDL:[MD5.F6F13533196DE7A582D422B0241E4363] - 22/08/2013 - 13:43:45 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\megasr.sys [575840]
O58 - SDL:[MD5.8B38C44F69259987C95135C9627E2378] - 22/08/2013 - 12:40:15 ---A- . (.Microsoft Corporation - Pilote de périphérique modem.) -- C:\Windows\System32\Drivers\modem.sys [40960]
O58 - SDL:[MD5.601589000CC90F0DF8DA2CC254A3CCC9] - 22/08/2013 - 12:36:37 ---A- . (.Microsoft Corporation - Monitor Driver.) -- C:\Windows\System32\Drivers\monitor.sys [30208]
O58 - SDL:[MD5.CEAC6D40FE887CE8406C2393CF97DE06] - 22/08/2013 - 13:43:45 ---A- . (.Microsoft Corporation - Pilote de la classe Souris.) -- C:\Windows\System32\Drivers\mouclass.sys [51040]
O58 - SDL:[MD5.02D98BF804084E9A0D69D1C69B02CCA9] - 22/08/2013 - 12:39:13 ---A- . (.Microsoft Corporation - Pilote de filtre souris HID.) -- C:\Windows\System32\Drivers\mouhid.sys [30208]
O58 - SDL:[MD5.515549560D481138E6E21AF7C6998E56] - 22/08/2013 - 14:25:40 ---A- . (.Microsoft Corporation - Gestionnaire des points de montage.) -- C:\Windows\System32\Drivers\mountmgr.sys [101728]
O58 - SDL:[MD5.F170510BE94CF45E3C6274578F6204B2] - 22/08/2013 - 12:36:06 ---A- . (.Microsoft Corporation - Microsoft Protection Service Driver.) -- C:\Windows\System32\Drivers\mpsdrv.sys [74240]
O58 - SDL:[MD5.59DCEC7499095DE5AED741358037AE2D] - 22/08/2013 - 12:37:19 ---A- . (.Microsoft Corporation - Windows NT WebDav Minirdr.) -- C:\Windows\System32\Drivers\mrxdav.sys [140288]
O58 - SDL:[MD5.6129EDB793A4255B1E2FB41773AC9D9A] - 14/11/2013 - 08:31:06 ---A- . (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\Windows\System32\Drivers\mrxsmb.sys [404992]
O58 - SDL:[MD5.295771B092D4F7FCF2B62F80CCD14320] - 22/08/2013 - 12:35:42 ---A- . (.Microsoft Corporation - Longhorn SMB Downlevel SubRdr.) -- C:\Windows\System32\Drivers\mrxsmb10.sys [283648]
O58 - SDL:[MD5.AAF56E4E84D35411B4E446C445732DFE] - 14/11/2013 - 08:31:06 ---A- . (.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) -- C:\Windows\System32\Drivers\mrxsmb20.sys [207360]
O58 - SDL:[MD5.D13329FBF8345B28AB30F44CC247DC08] - 22/08/2013 - 14:25:41 ---A- . (.Microsoft Corporation - Mailslot driver.) -- C:\Windows\System32\Drivers\msfs.sys [30208]
O58 - SDL:[MD5.FDA72810CA2F8409D9B31E833C448E34] - 22/08/2013 - 13:43:48 ---A- . (.Microsoft Corporation - GPIO Class Extension Driver.) -- C:\Windows\System32\Drivers\msgpioclx.sys [146272]
O58 - SDL:[MD5.C6B474E46F9E543B875981ED3FFE6ADD] - 22/08/2013 - 13:43:48 ---A- . (.Microsoft Corporation - GPIO Button Driver.) -- C:\Windows\System32\Drivers\msgpiowin32.sys [41824]
O58 - SDL:[MD5.65C92EB9D08DB5C69F28C7FFD4E84E31] - 22/08/2013 - 12:39:06 ---A- . (.Microsoft Corporation - Pass-through HID to KMDF Filter Driver.) -- C:\Windows\System32\Drivers\mshidkmdf.sys [8192]
O58 - SDL:[MD5.52299F086AC2DAFD100DD5DC4A8614BA] - 22/08/2013 - 12:39:06 ---A- . (.Microsoft Corporation - Pilote direct pour interface HID-UMDF.) -- C:\Windows\System32\Drivers\mshidumdf.sys [9728]
O58 - SDL:[MD5.36D92AF3343C3A3E57FEF11C449AEA4C] - 22/08/2013 - 13:43:49 ---A- . (.Microsoft Corporation - ISA Driver.) -- C:\Windows\System32\Drivers\msisadrv.sys [17248]
O58 - SDL:[MD5.034D4BD9DC67C64F3A4C8A049B5173BF] - 22/08/2013 - 13:43:49 ---A- . (.Microsoft Corporation - Microsoft iSCSI Initiator Driver.) -- C:\Windows\System32\Drivers\msiscsi.sys [274784]
O58 - SDL:[MD5.A9BBBD2BAE6142253B9195E949AC2E8D] - 22/08/2013 - 12:39:31 ---A- . (.Microsoft Corporation - MS KS Server.) -- C:\Windows\System32\Drivers\mskssrv.sys [10624]
O58 - SDL:[MD5.375E44168F2DFB91A68B8A3F619C5A7C] - 22/08/2013 - 12:36:07 ---A- . (.Microsoft Corporation - Pilote de protocole LLDP (Link Layer Discovery Protocol) Micros.) -- C:\Windows\System32\Drivers\mslldp.sys [66560]
O58 - SDL:[MD5.7B2128EB875DCBC006E6A913211006D6] - 22/08/2013 - 12:39:30 ---A- . (.Microsoft Corporation - MS Proxy Clock.) -- C:\Windows\System32\Drivers\mspclock.sys [7040]
O58 - SDL:[MD5.1E88171579B218115C7A772F8DE04BD8] - 22/08/2013 - 12:39:31 ---A- . (.Microsoft Corporation - MS Proxy Quality Manager.) -- C:\Windows\System32\Drivers\mspqm.sys [6784]
O58 - SDL:[MD5.BBE2A455053E63BECBF42C2F9B21FAE0] - 22/08/2013 - 14:25:35 ---A- . (.Microsoft Corporation - Kernel Remote Procedure Call Provider.) -- C:\Windows\System32\Drivers\msrpc.sys [366432]
O58 - SDL:[MD5.8D6B7D515C5CBCDB75B928A0B73C3C5E] - 22/08/2013 - 13:49:29 ---A- . (.Microsoft Corporation - System Management BIOS Driver.) -- C:\Windows\System32\Drivers\mssmbios.sys [37728]
O58 - SDL:[MD5.115019AE01E0EB9C048530D2928AB4A2] - 22/08/2013 - 12:38:38 ---A- . (.Microsoft Corporation - WDM Tee/Communication Transform Filter.) -- C:\Windows\System32\Drivers\mstee.sys [7936]
O58 - SDL:[MD5.96D604A35070360F0DD4A7A8AF410B5E] - 22/08/2013 - 12:37:36 ---A- . (.Microsoft Corporation - Pilote HID multipoint Microsoft.) -- C:\Windows\System32\Drivers\MTConfig.sys [13312]
O58 - SDL:[MD5.619CA29326B82372621DB2C0964D8365] - 22/08/2013 - 13:49:29 ---A- . (.Microsoft Corporation - Multiple UNC Provider Driver.) -- C:\Windows\System32\Drivers\mup.sys [78688]
O58 - SDL:[MD5.B8C35C94DCB2DFEAF03BB42131F2F77F] - 22/08/2013 - 13:43:49 ---A- . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\Drivers\mvumis.sys [63840]
O58 - SDL:[MD5.AD9086052A5E5153AF43FE74138A4B27] - 14/11/2013 - 08:31:05 ---A- . (.Microsoft Corporation - NDIS (Network Driver Interface Specification).) -- C:\Windows\System32\Drivers\ndis.sys [1119576]
O58 - SDL:[MD5.C6BB12BC35D1637CA17AE16D3A4725EB] - 22/08/2013 - 12:38:06 ---A- . (.Microsoft Corporation - Microsoft NDIS Packet Capture Filter Driver.) -- C:\Windows\System32\Drivers\ndiscap.sys [43008]
O58 - SDL:[MD5.9F1DA20E943BE7AA4ED5F3E1EBA78B37] - 22/08/2013 - 12:36:17 ---A- . (.Microsoft Corporation - Microsoft Network Adapter Multiplexor.) -- C:\Windows\System32\Drivers\NdisImPlatform.sys [124928]
O58 - SDL:[MD5.9423421E735BD5394351E0C47C76BB92] - 22/08/2013 - 12:39:16 ---A- . (.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) -- C:\Windows\System32\Drivers\ndistapi.sys [24576]
O58 - SDL:[MD5.B832B35055BA2B7B4181861FF94D8E59] - 22/08/2013 - 12:37:34 ---A- . (.Microsoft Corporation - Pilote d’E/S du mode utilisateur NDIS.) -- C:\Windows\System32\Drivers\ndisuio.sys [60416]
O58 - SDL:[MD5.1F58E48EF75F34C35D8E93A0DC535CFE] - 22/08/2013 - 12:36:25 ---A- . (.Microsoft Corporation - Énumérateur de cartes réseau virtuelles Microsoft.) -- C:\Windows\System32\Drivers\NdisVirtualBus.sys [16384]
O58 - SDL:[MD5.DEC29080202D4F9F17F55E18BCFCC41A] - 22/08/2013 - 12:35:56 ---A- . (.Microsoft Corporation - MS PPP Framing Driver (Strong Encryption).) -- C:\Windows\System32\Drivers\ndiswan.sys [220672]
O58 - SDL:[MD5.A5BD69A8812FA79D1A487691DD3FB244] - 22/08/2013 - 12:38:16 ---A- . (.Microsoft Corporation - NDIS Proxy.) -- C:\Windows\System32\Drivers\ndproxy.sys [72192]
O58 - SDL:[MD5.5A072F0B90C29C5233D78BE33EF5ED78] - 22/08/2013 - 12:35:42 ---A- . (.Microsoft Corporation - Windows Network Data Usage Monitoring Driver.) -- C:\Windows\System32\Drivers\Ndu.sys [103424]
O58 - SDL:[MD5.A83D67D347A684F10B7D3019C8A6380C] - 22/08/2013 - 12:38:58 ---A- . (.Microsoft Corporation - NetBIOS interface driver.) -- C:\Windows\System32\Drivers\netbios.sys [48128]
O58 - SDL:[MD5.0217532E19A748F0E5D569307363D5FD] - 22/08/2013 - 12:37:02 ---A- . (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\Drivers\netbt.sys [282624]
O58 - SDL:[MD5.9E900970FEDF9AF53687940F44E05227] - 22/08/2013 - 14:25:35 ---A- . (.Microsoft Corporation - Network I/O Subsystem.) -- C:\Windows\System32\Drivers\netio.sys [478048]
O58 - SDL:[MD5.70414DB660BFBB7BD58FCE8EA4364E1B] - 22/08/2013 - 12:36:43 ---A- . (.Microsoft Corporation - Virtual NDIS6.3 Miniport.) -- C:\Windows\System32\Drivers\netvsc63.sys [87040]
O58 - SDL:[MD5.8F44A2F57C9F1A19AC9C6288C10FB351] - 22/08/2013 - 14:25:41 ---A- . (.Microsoft Corporation - NPFS Driver.) -- C:\Windows\System32\Drivers\npfs.sys [58880]
O58 - SDL:[MD5.CBDB4F0871C88DF930FC0E8588CA67FC] - 22/08/2013 - 12:38:22 ---A- . (.Microsoft Corporation - Named pipe service triggers.) -- C:\Windows\System32\Drivers\npsvctrig.sys [23040]
O58 - SDL:[MD5.E490B459978CB87779E84C761D22B827] - 22/08/2013 - 14:25:35 ---A- . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys [39936]
O58 - SDL:[MD5.4412D565C0278C401575E11072C7DCE3] - 22/08/2013 - 14:25:41 ---A- . (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\Drivers\ntfs.sys [2011488]
O58 - SDL:[MD5.EF1B290FC9F0E47CC0B537292BEE5904] - 22/08/2013 - 14:25:41 ---A- . (.Microsoft Corporation - NULL Driver.) -- C:\Windows\System32\Drivers\null.sys [5632]
O58 - SDL:[MD5.BC6B5942AFF25EBAF62DE43C3807EDF8] - 22/08/2013 - 13:43:31 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [150368]
O58 - SDL:[MD5.1F43ABFFAC3D6CA356851D517392966E] - 22/08/2013 - 13:43:32 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [168288]
O58 - SDL:[MD5.6934A936A7369DFE37B7DBA93F5E5E49] - 22/08/2013 - 13:43:32 ---A- . (.Microsoft Corporation - Filtre AGP NForce NT.) -- C:\Windows\System32\Drivers\NV_AGP.SYS [124768]
O58 - SDL:[MD5.CF8B989D89D6807B887690F2CF24EFD9] - 14/11/2013 - 08:31:09 ---A- . (.Microsoft Corporation - Pilote de miniport WiFi natif.) -- C:\Windows\System32\Drivers\nwifi.sys [442368]
O58 - SDL:[MD5.8528BB05E4D4E25945F78B00B2555FB7] - 22/08/2013 - 12:36:07 ---A- . (.Microsoft Corporation - Planificateur de paquets QoS.) -- C:\Windows\System32\Drivers\pacer.sys [151552]
O58 - SDL:[MD5.764B1121867B2D9B31C491668AC72B2B] - 22/08/2013 - 12:40:02 ---A- . (.Microsoft Corporation - Pilote de port parallèle.) -- C:\Windows\System32\Drivers\parport.sys [94208]
O58 - SDL:[MD5.EF0C1749C9A8CEE9A457473D433CC00F] - 22/08/2013 - 14:25:40 ---A- . (.Microsoft Corporation - Partition Management Driver.) -- C:\Windows\System32\Drivers\partmgr.sys [88928]
O58 - SDL:[MD5.C0D3F3BC1C84B4BA746D9847314C1164] - 22/08/2013 - 13:43:32 ---A- . (.Microsoft Corporation - Énumérateur Plug-and-Play PCI pour NT.) -- C:\Windows\System32\Drivers\pci.sys [285536]
O58 - SDL:[MD5.346E38FCC6859A727DD28AFAD1F0AFF4] - 22/08/2013 - 13:43:31 ---A- . (.Microsoft Corporation - Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\pciide.sys [14688]
O58 - SDL:[MD5.5D4D6146346B82EB3CA4EE0C5573193C] - 22/08/2013 - 13:43:32 ---A- . (.Microsoft Corporation - PCI IDE Bus Driver Extension.) -- C:\Windows\System32\Drivers\pciidex.sys [48992]
O58 - SDL:[MD5.4D3BDCC1C7B40C9D7B6AD990E6DEC397] - 22/08/2013 - 13:49:30 ---A- . (.Microsoft Corporation - Pilote de bus PCMCIA.) -- C:\Windows\System32\Drivers\pcmcia.sys [114528]
O58 - SDL:[MD5.BF28771D1436C88BE1D297D3098B0F7D] - 22/08/2013 - 13:39:15 ---A- . (.Microsoft Corporation - Performance Counters for Windows Driver.) -- C:\Windows\System32\Drivers\pcw.sys [50016]
O58 - SDL:[MD5.B9D968D8E2B0F9C6301CEB39CFC9B9E4] - 18/01/2014 - 14:19:43 ---A- . (.Microsoft Corporation - Power Dependency Coordinator Driver.) -- C:\Windows\System32\Drivers\pdc.sys [86872]
O58 - SDL:[MD5.BA50CC0BD19004AAB88BE37338B6FA0D] - 22/08/2013 - 12:36:07 ---A- . (.Microsoft Corporation - Protected Environment Authentication and Authorization Export D.) -- C:\Windows\System32\Drivers\PEAuth.sys [663040]
O58 - SDL:[MD5.486F21443BD82029284AE82F238DA44C] - 14/11/2013 - 08:37:14 ---A- . (.Microsoft Corporation - Port Class (Class Driver for Port/Miniport Devices).) -- C:\Windows\System32\Drivers\portcls.sys [270848]
O58 - SDL:[MD5.ECD373F9571C745894367CC2635EA44F] - 22/08/2013 - 09:46:34 ---A- . (.Microsoft Corporation - Processor Device Driver.) -- C:\Windows\System32\Drivers\processr.sys [92160]
O58 - SDL:[MD5.3FB466684609A4329858CF2EBD62E0FD] - 22/08/2013 - 12:39:27 ---A- . (.Microsoft Corporation - Pilote du support de Microsoft Quality Windows Audio Video Expe.) -- C:\Windows\System32\Drivers\qwavedrv.sys [47104]
O58 - SDL:[MD5.2C56F0EE27E4EF70CA4B4983D3638905] - 22/08/2013 - 12:40:01 ---A- . (.Microsoft Corporation - RAS Automatic Connection Driver.) -- C:\Windows\System32\Drivers\rasacd.sys [17408]
O58 - SDL:[MD5.BBB6272B7F46C4640A8CDB8A70C3450F] - 22/08/2013 - 12:35:51 ---A- . (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\Drivers\rasl2tp.sys [120832]
O58 - SDL:[MD5.5247F308C4103CDC4FE12AE1D235800A] - 22/08/2013 - 12:36:37 ---A- . (.Microsoft Corporation - RAS PPPoE mini-port/call-manager driver.) -- C:\Windows\System32\Drivers\raspppoe.sys [84992]
O58 - SDL:[MD5.E075CC071022BD4E9BE7C024717C0E0A] - 22/08/2013 - 12:35:51 ---A- . (.Microsoft Corporation - Peer-to-Peer Tunneling Protocol.) -- C:\Windows\System32\Drivers\raspptp.sys [107520]
O58 - SDL:[MD5.2B0F1677CDD08967005F34488559BC6F] - 22/08/2013 - 12:36:11 ---A- . (.Microsoft Corporation - RAS SSTP Miniport Call Manager.) -- C:\Windows\System32\Drivers\rassstp.sys [96256]
O58 - SDL:[MD5.B939A2A0F9D6C6C186721E268EB6FA93] - 22/08/2013 - 12:37:50 ---A- . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire tampon de lecteur red.) -- C:\Windows\System32\Drivers\rdbss.sys [408576]
O58 - SDL:[MD5.6B21EBF892CD8CACB71669B35AB5DE32] - 22/08/2013 - 12:38:52 ---A- . (.Microsoft Corporation - Microsoft RDP Bus Device driver.) -- C:\Windows\System32\Drivers\rdpbus.sys [22528]
O58 - SDL:[MD5.680C1DAE268B6FB67FA21B389A8B79EF] - 14/11/2013 - 08:16:40 ---A- . (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) -- C:\Windows\System32\Drivers\rdpdr.sys [195584]
O58 - SDL:[MD5.858776908AF838E3790F3261B799CDA6] - 14/11/2013 - 08:16:41 ---A- . (.Microsoft Corporation - Microsoft RDP Video Miniport driver.) -- C:\Windows\System32\Drivers\rdpvideominiport.sys [27488]
O58 - SDL:[MD5.847C6A08912C3515807049C93E526D65] - 14/11/2013 - 08:37:15 ---A- . (.Microsoft Corporation - ReadyBoost Driver.) -- C:\Windows\System32\Drivers\rdyboost.sys [258904]
O58 - SDL:[MD5.036746D54347FD2D0385668E2A4064E4] - 22/08/2013 - 13:39:15 ---A- . (.Microsoft Corporation - Pilote du système de fichiers ReFS NT.) -- C:\Windows\System32\Drivers\refs.sys [924512]
O58 - SDL:[MD5.47008A9CF5F5D550B6ABDA3BDBC891CE] - 22/08/2013 - 12:36:23 ---A- . (.Microsoft Corporation - Reliable Multicast Transport.) -- C:\Windows\System32\Drivers\rmcast.sys [144384]
O58 - SDL:[MD5.4A24C61ED665DB4D13B93FACA06350CA] - 22/08/2013 - 12:38:44 ---A- . (.Microsoft Corporation - Remote NDIS Miniport.) -- C:\Windows\System32\Drivers\RNDISMP.sys [32256]
O58 - SDL:[MD5.A0AF9EBF560FDD0E044E04C0AF9FF9E6] - 22/08/2013 - 12:40:26 ---A- . (.Microsoft Corporation - Legacy Non-Pnp Modem Device Driver.) -- C:\Windows\System32\Drivers\rootmdm.sys [11776]
O58 - SDL:[MD5.2D05A5508F4685412F2B89E8C2189ABC] - 22/08/2013 - 12:36:34 ---A- . (.Microsoft Corporation - Link-Layer Topology Responder Driver for NDIS 6.) -- C:\Windows\System32\Drivers\rspndr.sys [80384]
O58 - SDL:[MD5.19764658C1468C2C0CEF133D28414A6B] - 18/06/2013 - 15:46:17 ---A- . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.30 64-bit Driver.) -- C:\Windows\System32\Drivers\Rt630x64.sys [591360]
O58 - SDL:[MD5.F1A3ECE3809AF333810ED0A872200226] - 10/07/2012 - 11:30:44 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function Driver.) -- C:\Windows\System32\Drivers\RTKVHD64.sys [4083600]
O58 - SDL:[MD5.7291CC1B5ECA448B0B9C15E7E987A6B3] - 05/07/2012 - 04:18:06 ---A- . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/Vista/Win7/Win8.) -- C:\Windows\System32\Drivers\RtsUStor.sys [252048]
O58 - SDL:[MD5.AF4ADF4F93C3DE5978E3F1E6E3E979ED] - 29/12/2011 - 13:56:10 ---A- . (.Realtek Semiconductor Corp. - Realtek UVC Driver for XP/Vista/Win7.) -- C:\Windows\System32\Drivers\rtsuvc.sys [8213360]
O58 - SDL:[MD5.C624A1B32211C3166EDB3F4AB02A30B7] - 22/08/2013 - 13:39:15 ---A- . (.Microsoft Corporation - SBP-2 Protocol Driver.) -- C:\Windows\System32\Drivers\sbp2port.sys [107872]
O58 - SDL:[MD5.ABD0237B15DBD2B4695F4B7D734A58F7] - 22/08/2013 - 12:38:07 ---A- . (.Microsoft Corporation - Pilote de filtre de lecteur de carte à puce Microsoft.) -- C:\Windows\System32\Drivers\scfilter.sys [40960]
O58 - SDL:[MD5.1C4EB3ACEA98CAD8FC7CF50F629FF0C6] - 22/08/2013 - 13:43:32 ---A- . (.Microsoft Corporation - SCSI Port Driver.) -- C:\Windows\System32\Drivers\scsiport.sys [170848]
O58 - SDL:[MD5.2F9A3380B8C0380E5608E29C7AA66899] - 14/11/2013 - 08:31:05 ---A- . (.Microsoft Corporation - Pilote du bus numérique sécurisé (SD).) -- C:\Windows\System32\Drivers\sdbus.sys [236376]
O58 - SDL:[MD5.4EAF4DCF9DBD9A56952A58F56D61C005] - 22/08/2013 - 13:43:32 ---A- . (.Microsoft Corporation - Pilote de classe de stockage SD.) -- C:\Windows\System32\Drivers\sdstor.sys [78688]
O58 - SDL:[MD5.3EA8A16169C26AFBEB544E0E48421186] - 22/08/2013 - 16:35:09 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [23040]
O58 - SDL:[MD5.DB2FF24CE0BDD15FE75870AFE312BA89] - 22/08/2013 - 13:43:31 ---A- . (.Microsoft Corporation - Serial Class Extension.) -- C:\Windows\System32\Drivers\SerCx.sys [69472]
O58 - SDL:[MD5.0044B31F93946D5D41982314381FE431] - 18/01/2014 - 14:19:43 ---A- . (.Microsoft Corporation - Serial Class Extension V2.) -- C:\Windows\System32\Drivers\SerCx2.sys [146776]
O58 - SDL:[MD5.3CD600C089C1251BEEB4CD4CD5164F9E] - 22/08/2013 - 12:40:17 ---A- . (.Microsoft Corporation - Serial Port Enumerator.) -- C:\Windows\System32\Drivers\serenum.sys [23040]
O58 - SDL:[MD5.D864381BC9C725FAB01D94C060660166] - 22/08/2013 - 12:40:08 ---A- . (.Microsoft Corporation - Pilote de périphérique série.) -- C:\Windows\System32\Drivers\serial.sys [83456]
O58 - SDL:[MD5.0BD2B65DCE756FDE95A2E5CCCBF7705D] - 22/08/2013 - 12:40:02 ---A- . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys [26112]
O58 - SDL:[MD5.472B7A5AC181C050888DB454663DD764] - 22/08/2013 - 12:40:00 ---A- . (.Microsoft Corporation - SCSI Floppy Driver.) -- C:\Windows\System32\Drivers\sfloppy.sys [17408]
O58 - SDL:[MD5.2F518D13DD6F3053837FE606F1A2EA1F] - 22/08/2013 - 13:43:31 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [44896]
O58 - SDL:[MD5.1AC9A200A9C49C4508F04AAFFCA34A3F] - 22/08/2013 - 13:43:32 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [81760]
O58 - SDL:[MD5.8C0773703184485D57975B6C1ED48730] - 22/08/2013 - 12:40:16 ---A- . (.Microsoft Corporation - Smart Card Driver Library.) -- C:\Windows\System32\Drivers\smclib.sys [19968]
O58 - SDL:[MD5.F6EBE514D13ECE7EDC23440039CDF9AB] - 18/01/2014 - 14:19:43 ---A- . (.Microsoft Corporation - Storage Spaces Driver.) -- C:\Windows\System32\Drivers\spaceport.sys [372568]
O58 - SDL:[MD5.F337BE11071818FC3F5DC2940B6BDE34] - 22/08/2013 - 13:43:31 ---A- . (.Microsoft Corporation - SPB Class Extension.) -- C:\Windows\System32\Drivers\SpbCx.sys [72032]
O58 - SDL:[MD5.2B78788A1485F9B99A578A299DF42C02] - 14/11/2013 - 08:37:14 ---A- . (.Microsoft Corporation - Server driver.) -- C:\Windows\System32\Drivers\srv.sys [454656]
O58 - SDL:[MD5.C1AE59C0B0817236EC083A91C396005A] - 14/11/2013 - 08:31:06 ---A- . (.Microsoft Corporation - Pilote de serveur SMB 2.0.) -- C:\Windows\System32\Drivers\srv2.sys [675328]
O58 - SDL:[MD5.77195C32175FC63D6054EBA5A066D727] - 14/11/2013 - 08:31:06 ---A- . (.Microsoft Corporation - Server Network driver.) -- C:\Windows\System32\Drivers\srvnet.sys [244224]
O58 - SDL:[MD5.366DEA74BBA65B362BCCFC6FC2ADFD8B] - 22/08/2013 - 13:43:32 ---A- . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Windows x64.) -- C:\Windows\System32\Drivers\stexstor.sys [31072]
O58 - SDL:[MD5.0ED2E318ABB68C1A35A8B8038BDB4C90] - 22/08/2013 - 13:43:31 ---A- . (.Microsoft Corporation - MS AHCI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\storahci.sys [107872]
O58 - SDL:[MD5.6B06E2D11E604BE2B1A406C4CB3B90DE] - 14/11/2013 - 08:37:14 ---A- . (.Microsoft Corporation - Microsoft NVM Express Storport Miniport Driver.) -- C:\Windows\System32\Drivers\stornvme.sys [57176]
O58 - SDL:[MD5.A5764EE0625ACD6F010460B5200FE687] - 22/08/2013 - 13:43:32 ---A- . (.Microsoft Corporation - Microsoft Storage Port Driver.) -- C:\Windows\System32\Drivers\storport.sys [374112]
O58 - SDL:[MD5.548759755BC73DAD663250239D7E0B9F] - 22/08/2013 - 13:36:48 ---A- . (.Microsoft Corporation - Storage VSC Driver.) -- C:\Windows\System32\Drivers\storvsc.sys [45888]
O58 - SDL:[MD5.FF184501F8F556147BBBDE571315C137] - 22/08/2013 - 12:39:26 ---A- . (.Microsoft Corporation - WDM CODEC Class Device Driver 2.0.) -- C:\Windows\System32\Drivers\stream.sys [67584]
O58 - SDL:[MD5.84E0F5D41C138C5CC975137A2A98F6D3] - 22/08/2013 - 13:43:33 ---A- . (.Microsoft Corporation - Plug and Play Software Device Enumerator.) -- C:\Windows\System32\Drivers\swenum.sys [14176]
O58 - SDL:[MD5.B13A57CE2F17B8C789E895E15F115DB0] - 22/08/2013 - 12:39:50 ---A- . (.Microsoft Corporation - SCSI Tape Class Driver.) -- C:\Windows\System32\Drivers\tape.sys [29696]
O58 - SDL:[MD5.DAD68FB30EFC58E322EADF01F013A99B] - 22/08/2013 - 13:49:33 ---A- . (.Microsoft Corporation - Export driver for kernel mode TPM API.) -- C:\Windows\System32\Drivers\tbs.sys [21856]
O58 - SDL:[MD5.6617F44D2432C529B2249A0498B6B40A] - 14/11/2013 - 08:37:14 ---A- . (.Microsoft Corporation - Pilote TCP/IP.) -- C:\Windows\System32\Drivers\tcpip.sys [2551640]
O58 - SDL:[MD5.33A7D83EEB15431773A6E186CFAABA21] - 22/08/2013 - 12:36:03 ---A- . (.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) -- C:\Windows\System32\Drivers\tcpipreg.sys [48640]
O58 - SDL:[MD5.3C7361E0A5A6966DB957B94ECF924A9E] - 22/08/2013 - 14:25:35 ---A- . (.Microsoft Corporation - TDI Wrapper.) -- C:\Windows\System32\Drivers\tdi.sys [30208]
O58 - SDL:[MD5.FFF28F9F6823EB1756C60F1649560BBF] - 22/08/2013 - 14:25:35 ---A- . (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\Drivers\tdx.sys [107520]
O58 - SDL:[MD5.232D185D2337F141311D0CF1983E1431] - 14/11/2013 - 08:16:36 ---A- . (.Microsoft Corporation - Terminal Server Input Driver.) -- C:\Windows\System32\Drivers\terminpt.sys [37216]
O58 - SDL:[MD5.E8D2721972B8A2C3A4F6DE5C43D163E5] - 22/08/2013 - 13:39:14 ---A- . (.Microsoft Corporation - Kernel Transaction Manager Driver.) -- C:\Windows\System32\Drivers\tm.sys [121184]
O58 - SDL:[MD5.82F909359600D3603FE852DB7F135626] - 22/08/2013 - 13:49:33 ---A- . (.Microsoft Corporation - Pilote de périphérique TPM.) -- C:\Windows\System32\Drivers\tpm.sys [159584]
O58 - SDL:[MD5.BF8F54CA37E9C9D6582C31C5761F8C93] - 22/08/2013 - 12:37:28 ---A- . (.Microsoft Corporation - Pilote de filtre pour concentrateur USB du Bureau à distance.) -- C:\Windows\System32\Drivers\TsUsbFlt.sys [56320]
O58 - SDL:[MD5.E0088068DCE2EE82897027DDB8E05254] - 22/08/2013 - 12:37:46 ---A- . (.Microsoft Corporation - Remote Desktop Generic USB Driver.) -- C:\Windows\System32\Drivers\TsUsbGD.sys [29696]
O58 - SDL:[MD5.C8E0E78B5D284C2FF59BDFFDAF997242] - 22/08/2013 - 12:35:45 ---A- . (.Microsoft Corporation - Pilote d’interface de tunnel Microsoft.) -- C:\Windows\System32\Drivers\tunnel.sys [154112]
O58 - SDL:[MD5.F6EEAD052943B5A3104C1405BB856C54] - 22/08/2013 - 13:43:33 ---A- . (.Microsoft Corporation - Filtre MS AGPv3.5.) -- C:\Windows\System32\Drivers\UAGP35.SYS [64864]
O58 - SDL:[MD5.FE6067B1FD4E63650C667B33D080565B] - 22/08/2013 - 13:43:33 ---A- . (.Microsoft Corporation - Microsoft Uasp Driver.) -- C:\Windows\System32\Drivers\uaspstor.sys [74080]
O58 - SDL:[MD5.5D1B430EA11064C56E7C8F84B90DEB6A] - 22/08/2013 - 13:43:33 ---A- . (.Microsoft Corporation - USB Controller Extension.) -- C:\Windows\System32\Drivers\UCX01000.SYS [189792]
O58 - SDL:[MD5.1EC649F112896FAE33250F0B97AC5D0B] - 22/08/2013 - 12:40:20 ---A- . (.Microsoft Corporation - UDF File System Driver.) -- C:\Windows\System32\Drivers\udfs.sys [316928]
O58 - SDL:[MD5.9578691F297E1B1F519970FE6D47CB21] - 22/08/2013 - 13:39:15 ---A- . (.Microsoft Corporation - UEFI Driver for NT.) -- C:\Windows\System32\Drivers\uefi.sys [26976]
O58 - SDL:[MD5.5EAB5117DDB24FC4D39E6FFFCF1837B9] - 22/08/2013 - 13:43:33 ---A- . (.Microsoft Corporation - Filtre ULi AGPv3.0 pour plateformes à processeur K8/9.) -- C:\Windows\System32\Drivers\ULIAGPKX.SYS [65888]
O58 - SDL:[MD5.DA34C39A18E60E7C3FA0630566408034] - 22/08/2013 - 12:38:59 ---A- . (.Microsoft Corporation - User-Mode Bus Enumerator.) -- C:\Windows\System32\Drivers\umbus.sys [46080]
O58 - SDL:[MD5.AE8294875E5446E359B1E8035D40C05E] - 22/08/2013 - 12:38:58 ---A- . (.Microsoft Corporation - Generic pass-through driver.) -- C:\Windows\System32\Drivers\umpass.sys [11776]
O58 - SDL:[MD5.A5A402FE30B5E0831F4EB6A112104811] - 22/08/2013 - 12:38:16 ---A- . (.Microsoft Corporation - Remote NDIS USB Driver.) -- C:\Windows\System32\Drivers\usb8023.sys [20992]
O58 - SDL:[MD5.C9E9D59C0099A9FF51697E9306A44240] - 13/12/2012 - 14:50:36 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\Drivers\usbaapl64.sys [54784]
O58 - SDL:[MD5.755A90F1C949B8260D7670AEF6DB4912] - 22/08/2013 - 12:37:34 ---A- . (.Microsoft Corporation - USB Audio Class Driver.) -- C:\Windows\System32\Drivers\USBAUDIO.sys [121088]
O58 - SDL:[MD5.5D45329A96B1A417DC7F59FDEABC0DDE] - 22/08/2013 - 12:39:27 ---A- . (.Microsoft Corporation - Universal Serial Bus Camera Driver.) -- C:\Windows\System32\Drivers\USBCAMD2.sys [32512]
O58 - SDL:[MD5.433ECDE01A52691FA7ACA51C10C09B70] - 14/11/2013 - 08:37:14 ---A- . (.Microsoft Corporation - USB Common Class Generic Parent Driver.) -- C:\Windows\System32\Drivers\usbccgp.sys [155480]
O58 - SDL:[MD5.B3D6457D841A0CAEF4C52D88621715F2] - 22/08/2013 - 12:38:26 ---A- . (.Microsoft Corporation - USB Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\usbcir.sys [98304]
O58 - SDL:[MD5.882222A9961418A75A08CB68671679D5] - 22/08/2013 - 13:43:33 ---A- . (.Microsoft Corporation - Universal Serial Bus Driver.) -- C:\Windows\System32\Drivers\usbd.sys [28000]
O58 - SDL:[MD5.5477D6E27C7D266EF8C152B9A25ADE5E] - 22/08/2013 - 13:43:33 ---A- . (.Microsoft Corporation - EHCI eUSB Miniport Driver.) -- C:\Windows\System32\Drivers\usbehci.sys [89952]
O58 - SDL:[MD5.DF56C2C04EFA328D7A66B69007130266] - 22/08/2013 - 13:43:34 ---A- . (.Microsoft Corporation - Pilote de concentrateur USB par défaut.) -- C:\Windows\System32\Drivers\usbhub.sys [422240]
O58 - SDL:[MD5.C0E33820326199CE3CFD3B9F27F81D99] - 14/11/2013 - 08:31:05 ---A- . (.Microsoft Corporation - Pilote de concentrateur USB3.) -- C:\Windows\System32\Drivers\USBHUB3.SYS [467800]
O58 - SDL:[MD5.3019097FB6C985EF24C058090FF3BDBD] - 22/08/2013 - 12:39:27 ---A- . (.Microsoft Corporation - OHCI USB Miniport Driver.) -- C:\Windows\System32\Drivers\usbohci.sys [30208]
O58 - SDL:[MD5.32F2E6BAD9FA8E14B55E97280661801E] - 22/08/2013 - 13:43:34 ---A- . (.Microsoft Corporation - Pilote de port USB 1.1 & 2.0.) -- C:\Windows\System32\Drivers\usbport.sys [439136]
O58 - SDL:[MD5.4D655E3B684BE9B0F7FFD8A2935C348C] - 22/08/2013 - 12:36:33 ---A- . (.Microsoft Corporation - USB Printer driver.) -- C:\Windows\System32\Drivers\usbprint.sys [26112]
O58 - SDL:[MD5.3431FBFAC156EB7FEF9B936EC2A77AF6] - 22/08/2013 - 12:39:39 ---A- . (.Microsoft Corporation - Gestionnaire de stratégie de redirection USB Windows.) -- C:\Windows\System32\Drivers\usbrpm.sys [30720]
O58 - SDL:[MD5.B1230E9813B5C7E762DF27756AA23917] - 22/08/2013 - 13:43:34 ---A- . (.Microsoft Corporation - Pilote de classe de stockage de masse USB.) -- C:\Windows\System32\Drivers\USBSTOR.SYS [142688]
O58 - SDL:[MD5.BA4FA655E0FC577DB7436FC963932CE4] - 22/08/2013 - 12:39:28 ---A- . (.Microsoft Corporation - UHCI USB Miniport Driver.) -- C:\Windows\System32\Drivers\usbuhci.sys [34816]
O58 - SDL:[MD5.3B44CB989757428208CCFCC028C13110] - 18/01/2014 - 14:19:43 ---A- . (.Microsoft Corporation - Pilote XHCI USB.) -- C:\Windows\System32\Drivers\USBXHCI.SYS [325464]
O58 - SDL:[MD5.FEB26E3B8345A7E8D62F945C4AE86562] - 22/08/2013 - 13:37:27 ---A- . (.Microsoft Corporation - Virtual Drive Root Enumerator.) -- C:\Windows\System32\Drivers\vdrvroot.sys [37728]
O58 - SDL:[MD5.A026EDEAA5EECAE0B08E2748B616D4BD] - 14/11/2013 - 08:31:05 ---A- . (.Microsoft Corporation - Driver Verifier Extension.) -- C:\Windows\System32\Drivers\VerifierExt.sys [175960]
O58 - SDL:[MD5.041D3EF364E624DBB2703A64A5AADF89] - 22/08/2013 - 13:37:27 ---A- . (.Microsoft Corporation - VHD Miniport Driver.) -- C:\Windows\System32\Drivers\vhdmp.sys [551776]
O58 - SDL:[MD5.06D38968028E9AB19DE9B618C7B6D199] - 22/08/2013 - 13:43:34 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [19808]
O58 - SDL:[MD5.608BD5400EFD2307A5F8DDDC87775734] - 22/08/2013 - 12:39:31 ---A- . (.Microsoft Corporation - Video Port Driver.) -- C:\Windows\System32\Drivers\videoprt.sys [49152]
O58 - SDL:[MD5.B600C96614BC7F890A6F2A4C93FA15EC] - 22/08/2013 - 13:36:48 ---A- . (.Microsoft Corporation - Hyper-V VMBus KMCL.) -- C:\Windows\System32\Drivers\vmbkmcl.sys [90944]
O58 - SDL:[MD5.C6305BDFC4F7CE51F72BB072C03D4ACE] - 22/08/2013 - 13:36:51 ---A- . (.Microsoft Corporation - Microsoft Hyper-V Virtual Machine Bus Child Driver.) -- C:\Windows\System32\Drivers\vmbus.sys [97088]
O58 - SDL:[MD5.DA40BEA0A863CE768C940CA9723BF81F] - 22/08/2013 - 12:37:50 ---A- . (.Microsoft Corporation - Microsoft VMBus HID Miniport.) -- C:\Windows\System32\Drivers\VMBusHID.sys [21760]
O58 - SDL:[MD5.0BF5CAD281E25F1418E5B8875DC5ADD1] - 22/08/2013 - 12:38:23 ---A- . (.Microsoft Corporation - Virtual Machine Generation Counter.) -- C:\Windows\System32\Drivers\vmgencounter.sys [11264]
O58 - SDL:[MD5.1A063730F221B2746FF00457AE17E4F0] - 22/08/2013 - 12:38:37 ---A- . (.Microsoft Corporation - Microsoft S3 Emulated Device Cap Driver.) -- C:\Windows\System32\Drivers\vms3cap.sys [7168]
O58 - SDL:[MD5.7A08CEE1535F5A448215634C5EA74E50] - 22/08/2013 - 13:36:48 ---A- . (.Microsoft Corporation - Virtual Storage Filter Driver.) -- C:\Windows\System32\Drivers\vmstorfl.sys [49984]
O58 - SDL:[MD5.55D7D963DE85162F1C49721E502F9744] - 22/08/2013 - 13:39:15 ---A- . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys [73568]
O58 - SDL:[MD5.CCB9E901F7254BF96D28EB1B0E5329B7] - 22/08/2013 - 13:39:15 ---A- . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys [377696]
O58 - SDL:[MD5.9F9CE33B50611A1C61A46B8911E0B30B] - 22/08/2013 - 13:39:15 ---A- . (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\Windows\System32\Drivers\volsnap.sys [312160]
O58 - SDL:[MD5.01355C98B5C3ED1EC446743CDA848FCE] - 22/08/2013 - 13:37:27 ---A- . (.Microsoft Corporation - Virtual PCI Bus.) -- C:\Windows\System32\Drivers\vpci.sys [69472]
O58 - SDL:[MD5.4539F45F9F4C9757A86A56C949421E07] - 22/08/2013 - 13:43:34 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [168800]
O58 - SDL:[MD5.0849B7260F26FE05EA56DED0672E2F4B] - 22/08/2013 - 13:43:34 ---A- . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\Drivers\VSTXRAID.SYS [305504]
O58 - SDL:[MD5.BE970C369E43B509C1EDA2B8FA7CECB0] - 22/08/2013 - 12:39:00 ---A- . (.Microsoft Corporation - Pilote de bus WiFi virtuel.) -- C:\Windows\System32\Drivers\vwifibus.sys [24576]
O58 - SDL:[MD5.6B26AD573CCDD5209DF4397438B76354] - 22/08/2013 - 12:38:05 ---A- . (.Microsoft Corporation - Virtual WiFi Filter Driver.) -- C:\Windows\System32\Drivers\vwififlt.sys [71680]
O58 - SDL:[MD5.0B48E0DFB44EE475F4FD8A8EE599AF30] - 22/08/2013 - 12:36:15 ---A- . (.Microsoft Corporation - Virtual WiFi Miniport Driver.) -- C:\Windows\System32\Drivers\vwifimp.sys [36864]
O58 - SDL:[MD5.0910AB9ED404C1434E2D0376C2AD5D8B] - 22/08/2013 - 12:39:15 ---A- . (.Microsoft Corporation - Wacom Serial Pen Tablet HID Driver.) -- C:\Windows\System32\Drivers\wacompen.sys [26752]
O58 - SDL:[MD5.AFCD4054D61BD708B82991348ED1C763] - 22/08/2013 - 12:35:46 ---A- . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) -- C:\Windows\System32\Drivers\wanarp.sys [79872]
O58 - SDL:[MD5.602811E8AAE68030C151345C84A0CDAF] - 22/08/2013 - 12:39:48 ---A- . (.Microsoft Corporation - Watchdog Driver.) -- C:\Windows\System32\Drivers\watchdog.sys [54272]
O58 - SDL:[MD5.694B28DE12AD47031FFB4B052662131A] - 22/08/2013 - 13:31:28 ---A- . (.Microsoft Corporation - Microsoft antimalware boot driver.) -- C:\Windows\System32\Drivers\WdBoot.sys [34760]
O58 - SDL:[MD5.CB6C63FF8342B467E2EF76E98D5B934D] - 22/08/2013 - 14:25:41 ---A- . (.Microsoft Corporation - Runtime de l’infrastructure de pilotes en mode noyau.) -- C:\Windows\System32\Drivers\Wdf01000.sys [839488]
O58 - SDL:[MD5.0B99529A3BECC3528D865DDECB62503B] - 22/08/2013 - 13:34:22 ---A- . (.Microsoft Corporation - Microsoft antimalware file system filter driver.) -- C:\Windows\System32\Drivers\WdFilter.sys [265056]
O58 - SDL:[MD5.42C23552FC0BF2BAB9053BE6E4DC3D13] - 22/08/2013 - 14:25:41 ---A- . (.Microsoft Corporation - Kernel Mode Driver Framework Loader.) -- C:\Windows\System32\Drivers\WdfLdr.sys [60224]
O58 - SDL:[MD5.282E7D46310338FF4A6B7680440EB0DA] - 22/08/2013 - 13:34:22 ---A- . (.Microsoft Corporation - Microsoft Network Realtime Inspection Driver.) -- C:\Windows\System32\Drivers\WdNisDrv.sys [124256]
O58 - SDL:[MD5.2E0AF5B354ED1BB10314353B6A625B68] - 22/08/2013 - 13:39:04 ---A- . (.Microsoft Corporation - Windows Error Reporting Kernel Driver.) -- C:\Windows\System32\Drivers\werkernel.sys [38240]
O58 - SDL:[MD5.2E3E82D7B1076B90F4E228A8EF17B261] - 14/11/2013 - 08:27:26 ---A- . (.Microsoft Corporation - WFP NDIS 6.30 Lightweight Filter Driver.) -- C:\Windows\System32\Drivers\wfplwfs.sys [136536]
O58 - SDL:[MD5.867BCC69ED9C31C501465EB0E8BA9DFA] - 22/08/2013 - 13:45:37 ---A- . (.Microsoft Corporation - Wim file system Driver.) -- C:\Windows\System32\Drivers\wimmount.sys [33632]
O58 - SDL:[MD5.54BAF0C6639AF707D00BB6C1ACA8837A] - 22/08/2013 - 13:36:48 ---A- . (.Microsoft Corporation - Windows Hypervisor Interface Driver.) -- C:\Windows\System32\Drivers\winhv.sys [61248]
O58 - SDL:[MD5.AC263C2F66405589528995AA41040599] - 22/08/2013 - 12:37:55 ---A- . (.Microsoft Corporation - Windows WinUSB Class Driver.) -- C:\Windows\System32\Drivers\winusb.sys [78848]
O58 - SDL:[MD5.2834D9D3B4F554A39C72F00EA3F0E128] - 22/08/2013 - 12:40:04 ---A- . (.Microsoft Corporation - Windows Management Interface for ACPI.) -- C:\Windows\System32\Drivers\wmiacpi.sys [16384]
O58 - SDL:[MD5.1FE5DDC32243469E6FA4440C02775A34] - 22/08/2013 - 14:25:41 ---A- . (.Microsoft Corporation - WMILIB WMI support library Dll.) -- C:\Windows\System32\Drivers\wmilib.sys [18272]
O58 - SDL:[MD5.E746BCDBA2E02CF6B8D6B26FB167FBE0] - 22/08/2013 - 13:41:08 ---A- . (.Microsoft Corporation - Family Safety Filter Driver.) -- C:\Windows\System32\Drivers\wpcfltr.sys [54304]
O58 - SDL:[MD5.9F2904B55F6CECCD1A8D986B5CE2609A] - 22/08/2013 - 13:36:12 ---A- . (.Microsoft Corporation - Windows Portable Device Upper Class Filter Driver.) -- C:\Windows\System32\Drivers\WpdUpFltr.sys [26976]
O58 - SDL:[MD5.38CAE0D33091C6F3B542F230E70ED44B] - 22/08/2013 - 14:25:41 ---A- . (.Microsoft Corporation - WPP Trace Recorder.) -- C:\Windows\System32\Drivers\WppRecorder.sys [23392]
O58 - SDL:[MD5.AE072B0339D0A18E455DC21666CAD572] - 22/08/2013 - 12:40:03 ---A- . (.Microsoft Corporation - Couche IFS Winsock2.) -- C:\Windows\System32\Drivers\ws2ifsl.sys [21504]
O58 - SDL:[MD5.F586F3F1BF962FE9AE4316E0D896B22F] - 22/08/2013 - 12:39:58 ---A- . (.Microsoft Corporation - Web Services Print Device Driver.) -- C:\Windows\System32\Drivers\WSDPrint.sys [20992]
O58 - SDL:[MD5.D38297814FB6E33655342D869996E617] - 22/08/2013 - 12:39:50 ---A- . (.Microsoft Corporation - Web Service Based Scan Device Driver.) -- C:\Windows\System32\Drivers\WSDScan.sys [23040]
O58 - SDL:[MD5.2FEAE33E9B2B56104596E1BA444405A9] - 22/08/2013 - 12:37:21 ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Driver Framework Platform.) -- C:\Windows\System32\Drivers\WUDFPf.sys [117760]
O58 - SDL:[MD5.19240C13F526125554B5370566F21A0A] - 22/08/2013 - 12:36:50 ---A- . (.Microsoft Corporation - Windows Driver Foundation - User-mode Driver Framework Reflecto.) -- C:\Windows\System32\Drivers\WUDFRd.sys [230912]
O58 - SDL:[MD5.288D15FEA82F67E57D57ACFCE087CC20] - 18/01/2014 - 14:20:22 ---A- . (.Microsoft Corporation - Pilote Win32 multi-utilisateurs.) -- C:\Windows\System32\win32k.sys [4191744]
O58 - SDL:[MD5.93E9D905C90F8C3112C4DAFD1E92EC73] - 22/08/2013 - 10:26:02 ---A- . (.Microsoft Corporation - Windows Background System Events Broker API Server.) -- C:\Windows\System32\Windows.ApplicationModel.Background.SystemEventsBroker.dll [29184]
O58 - SDL:[MD5.BEC416C94F914C379E1A2BC5752EF763] - 22/08/2013 - 10:53:40 ---A- . (.Microsoft Corporation - DLL d’exécution de l’affichage système Windows.) -- C:\Windows\System32\Windows.System.Display.dll [25600]
O58 - SDL:[MD5.C352CC3A499712E4E919385B74E1C8C0] - 22/08/2013 - 10:09:22 ---A- . (.Microsoft Corporation - DLL d’ID matériel du profil du système Windows.) -- C:\Windows\System32\Windows.System.Profile.HardwareId.dll [210944]
O58 - SDL:[MD5.E91F19CF5E4B73AB2ECA7E362A206920] - 22/08/2013 - 10:53:16 ---A- . (.Microsoft Corporation - Windows.System.Profile.SystemManufacturers.) -- C:\Windows\System32\Windows.System.Profile.SystemManufacturers.dll [25600]
O58 - SDL:[MD5.BEBFC818CCF0057A84456A35A1E7AFF2] - 22/08/2013 - 10:53:53 ---A- . (.Microsoft Corporation - Windows System RemoteDesktop Runtime DLL.) -- C:\Windows\System32\Windows.System.RemoteDesktop.dll [21504]
O58 - SDL:[MD5.EC5B17B8036FAC9DFF8BAC94E30799B1] - 22/08/2013 - 03:27:50 ---A- . (.Microsoft Corporation - Windows Background System Events Broker API Server.) -- C:\Windows\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll [24064]
O58 - SDL:[MD5.7084BCD3A95C278D38C9EBDF413DF29F] - 22/08/2013 - 03:47:07 ---A- . (.Microsoft Corporation - DLL d’exécution de l’affichage système Windows.) -- C:\Windows\SysWOW64\Windows.System.Display.dll [22016]
O58 - SDL:[MD5.FC01DFD0046CD6121B92C377C2A9C2AB] - 22/08/2013 - 03:18:25 ---A- . (.Microsoft Corporation - DLL d’ID matériel du profil du système Windows.) -- C:\Windows\SysWOW64\Windows.System.Profile.HardwareId.dll [169984]
O58 - SDL:[MD5.433A9B4E0DB68C176F9AF34BF6441D59] - 22/08/2013 - 03:46:48 ---A- . (.Microsoft Corporation - Windows.System.Profile.SystemManufacturers.) -- C:\Windows\SysWOW64\Windows.System.Profile.SystemManufacturers.dll [22016]
O58 - SDL:[MD5.BB4F2BCF02F0E98E8EA5CB45EC0285A6] - 22/08/2013 - 03:47:23 ---A- . (.Microsoft Corporation - Windows System RemoteDesktop Runtime DLL.) -- C:\Windows\SysWOW64\Windows.System.RemoteDesktop.dll [18432]
~ Drivers: 18 Scanned in 00mn 11s



---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 03/02/2014 - 16:59:54 ---A- . (...) -- C:\Users\Paméla\AppData\Local\AMD\Fuel\ClientProxyLog_1.txt [2]
O61 - LFC: 03/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\cc1.midasplayer.com\##621C279D9A62B943\00000001.sol [14735]
O61 - LFC: 03/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\cc1.midasplayer.com\##7FF3C81F851C47AB\00000001.sol [14808]
O61 - LFC: 03/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\cc1.midasplayer.com\swf\CCMain.swf\#1018416723\pwf_movesPop.sol [87]
O61 - LFC: 03/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\macromedia.com\support\flashplayer\sys\#cc1.midasplayer.com\settings.sol [89]
O61 - LFC: 03/02/2014 - 17:00:36 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Packages\Facebook.Facebook_8xx8rvfyw5nnt\Settings\settings.dat [262144]
O61 - LFC: 03/02/2014 - 17:00:48 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Temp\au-descriptor-1.7.0_51-b13.xml [8894]
O61 - LFC: 03/02/2014 - 17:01:03 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Temp\WMZuneComm.etl.002 [4096]
O61 - LFC: 03/02/2014 - 17:01:08 ---A- . (...) -- C:\Users\Paméla\AppData\Roaming\Adobe\AIR\Updater\lastUpdateCheck [34]
O61 - LFC: 03/02/2014 - 17:01:19 ---A- . (...) -- C:\Users\Paméla\AppData\Roaming\fr.orange.assistancelivebox\#airversion\4.0.0.1390 [0] =>.Orange Corporation
O61 - LFC: 04/02/2014 - 16:59:59 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\Application\32.0.1700.107\Installer\chrome.7z [147431490]
O61 - LFC: 04/02/2014 - 16:59:59 ---A- . (.Google Inc..) -- C:\Users\Paméla\AppData\Local\Google\Chrome\Application\32.0.1700.107\Installer\setup.exe [1211720]
O61 - LFC: 04/02/2014 - 17:00:01 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\Application\VisualElementsManifest.xml [399]
O61 - LFC: 04/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\Paths\LOCK [0]
O61 - LFC: 04/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\Paths\LOG.old [142]
O61 - LFC: 04/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\000139.ldb [170]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_connexity.net_0.localstorage [3072]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_connexity.net_0.localstorage-journal [3608]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_lexpansion.lexpress.fr_0.localstorage [3072]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_lexpansion.lexpress.fr_0.localstorage-journal [3608]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bouyguestelecom.fr_0.localstorage [3072]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bouyguestelecom.fr_0.localstorage-journal [3608]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_connexity.net_0.localstorage [3072]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_connexity.net_0.localstorage-journal [3608]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_googleads.g.doubleclick.net_0.localstorage [3072]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_googleads.g.doubleclick.net_0.localstorage-journal [3608]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_plus.google.com_0.localstorage [3072]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_plus.google.com_0.localstorage-journal [3608]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_talkgadget.google.com_0.localstorage [3072]
O61 - LFC: 04/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_talkgadget.google.com_0.localstorage-journal [3608]
O61 - LFC: 04/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\a248.e.akamai.net\##4050BE024568D38E\00000001.sol [138]
O61 - LFC: 04/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\a248.e.akamai.net\##423F7B0FC677DE96\00000001.sol [146]
O61 - LFC: 04/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\a248.e.akamai.net\#com.junkbyte\Console\UserData.sol [105]
O61 - LFC: 04/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\a248.e.akamai.net\papapear.king.com\game\swf\PapaPearSocial.swf\welcomePopupX.sol [74]
O61 - LFC: 04/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\images-na.ssl-images-amazon.com\mercury.sol [69]
O61 - LFC: 04/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\macromedia.com\support\flashplayer\sys\#a248.e.akamai.net\settings.sol [87]
O61 - LFC: 04/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\macromedia.com\support\flashplayer\sys\#files.player.mediabong.com\settings.sol [96]
O61 - LFC: 04/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\macromedia.com\support\flashplayer\sys\#g-ec2.images-amazon.com\settings.sol [93]
O61 - LFC: 04/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\macromedia.com\support\flashplayer\sys\#static.rtl.fr\settings.sol [83]
O61 - LFC: 04/02/2014 - 17:00:19 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\32.0.1700.107\32.0.1700.107_32.0.1700.102_chrome_updater.exe [732888]
O61 - LFC: 04/02/2014 - 17:00:25 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Packages\55667CoolStoreDevsPandora.FacebookHD_fsgj3pht8nmqt\Settings\settings.dat [8192]
O61 - LFC: 04/02/2014 - 17:00:48 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Temp\CR_2B57B.tmp\SETUP_PATCH.PACKED.7Z [1799]
O61 - LFC: 04/02/2014 - 17:04:49 ---A- . (...) -- C:\Users\Paméla\Downloads\Cas de deblocage - cc-atc (1).pdf [270148]
O61 - LFC: 04/02/2014 - 17:04:49 ---A- . (...) -- C:\Users\Paméla\Downloads\Cas de deblocage - cc-atc.pdf [270148]
O61 - LFC: 04/02/2014 - 17:06:01 ---A- . (...) -- C:\Users\Paméla\Downloads\Turbo.2013.FRENCH.BRRiP.XviD.AC3-ZT.www.Zone-Telechargement.com.avi [460273550]
O61 - LFC: 05/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_apps.facebook.com_0.localstorage [7168]
O61 - LFC: 05/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_apps.facebook.com_0.localstorage-journal [7736]
O61 - LFC: 05/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_television.telerama.fr_0.localstorage [3072]
O61 - LFC: 05/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_television.telerama.fr_0.localstorage-journal [3608]
O61 - LFC: 05/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.amazon.fr_0.localstorage [3072]
O61 - LFC: 05/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.amazon.fr_0.localstorage-journal [3608]
O61 - LFC: 05/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.dailymotion.com_0.localstorage [3072]
O61 - LFC: 05/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.dailymotion.com_0.localstorage-journal [3608]
O61 - LFC: 05/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.inkage.fr_0.localstorage [479232]
O61 - LFC: 05/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.inkage.fr_0.localstorage-journal [5672]
O61 - LFC: 05/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.priceminister.com_0.localstorage [4096]
O61 - LFC: 05/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.priceminister.com_0.localstorage-journal [4640]
O61 - LFC: 05/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\broadcast.piximedia.fr\footerJS\v4\lib\so.swf\PmUI.sol [33]
O61 - LFC: 05/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\macromedia.com\support\flashplayer\sys\#broadcast.piximedia.fr\settings.sol [92]
O61 - LFC: 05/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\macromedia.com\support\flashplayer\sys\#www.dailymotion.com\settings.sol [89]
O61 - LFC: 05/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\www.dailymotion.com\com.dm.player.sol [59]
O61 - LFC: 05/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Session Storage\001755.ldb [61618]
O61 - LFC: 05/02/2014 - 17:00:37 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Packages\FileManager_cw5n1h2txyewy\LocalState\PhotosSessionState.dat [871]
O61 - LFC: 06/02/2014 - 16:59:54 ---A- . (...) -- C:\Users\Paméla\AppData\Local\AMD\Fuel\ClientProxyLog.txt [2]
O61 - LFC: 06/02/2014 - 16:59:54 ---A- . (...) -- C:\Users\Paméla\AppData\Local\ATI\ACE\Manifest.Bin [28015]
O61 - LFC: 06/02/2014 - 16:59:54 ---A- . (...) -- C:\Users\Paméla\AppData\Local\ATI\ACE\Manifest.xml [22069]
O61 - LFC: 06/02/2014 - 16:59:54 ---A- . (...) -- C:\Users\Paméla\AppData\Local\ATI\ACE\Profiles.xml [10627]
O61 - LFC: 06/02/2014 - 17:00:02 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Archived History [57344]
O61 - LFC: 06/02/2014 - 17:00:02 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Archived History-journal [16384]
O61 - LFC: 06/02/2014 - 17:00:02 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Cookies [1552384]
O61 - LFC: 06/02/2014 - 17:00:02 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal [16384]
O61 - LFC: 06/02/2014 - 17:00:02 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\CURRENT [16]
O61 - LFC: 06/02/2014 - 17:00:02 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG [148]
O61 - LFC: 06/02/2014 - 17:00:02 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG.old [148]
O61 - LFC: 06/02/2014 - 17:00:02 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\MANIFEST-000942 [1277]
O61 - LFC: 06/02/2014 - 17:00:02 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Extension State\CURRENT [16]
O61 - LFC: 06/02/2014 - 17:00:02 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG [151]
O61 - LFC: 06/02/2014 - 17:00:02 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old [151]
O61 - LFC: 06/02/2014 - 17:00:02 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Extension State\MANIFEST-001538 [520] =>.Google Inc
O61 - LFC: 06/02/2014 - 17:00:03 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Favicons [6363136]
O61 - LFC: 06/02/2014 - 17:00:03 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal [16384]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\.usage [24]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\Paths\CURRENT [16]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\Paths\LOG [142]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\Paths\MANIFEST-000008 [50]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\CURRENT [16]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\LOG [148]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\LOG.old [148]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\MANIFEST-000145 [244]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\History [9437184]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache [321510]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\History-journal [16384]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.fr_0.indexeddb.leveldb\CURRENT [16]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.fr_0.indexeddb.leveldb\LOG [148]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.fr_0.indexeddb.leveldb\LOG.old [148]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.fr_0.indexeddb.leveldb\MANIFEST-000113 [76]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Last Session [2724091]
O61 - LFC: 06/02/2014 - 17:00:07 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Last Tabs [57513]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ck.trigger-leads.fr_0.localstorage [3072]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ck.trigger-leads.fr_0.localstorage-journal [3608]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_f.rvzrjs.info_0.localstorage [48128]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_f.rvzrjs.info_0.localstorage-journal [16384]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_googleads.g.doubleclick.net_0.localstorage [3072]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_googleads.g.doubleclick.net_0.localstorage-journal [512]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ib.adnxs.com_0.localstorage [3072]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ib.adnxs.com_0.localstorage-journal [3608]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.live-lyrics.com_0.localstorage [2856960] =>Adware.AddLyrics
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.live-lyrics.com_0.localstorage-journal [16384] =>Adware.AddLyrics
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.chien-perdu.org_0.localstorage [3072]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.chien-perdu.org_0.localstorage-journal [3608]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_dev.leadplace.fr_0.localstorage [3072]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_dev.leadplace.fr_0.localstorage-journal [3608]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.facebook.com_0.localstorage [21504]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.facebook.com_0.localstorage-journal [16384]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.google.fr_0.localstorage [3072]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.google.fr_0.localstorage-journal [512]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage [3072]
O61 - LFC: 06/02/2014 - 17:00:08 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal [3608]
O61 - LFC: 06/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.laboutique.bouyguestelecom.fr_0.localstorage [4096]
O61 - LFC: 06/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.laboutique.bouyguestelecom.fr_0.localstorage-journal [3608]
O61 - LFC: 06/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage [5120]
O61 - LFC: 06/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal [4640]
O61 - LFC: 06/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.two-too.com_0.localstorage [3072]
O61 - LFC: 06/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.two-too.com_0.localstorage-journal [3608]
O61 - LFC: 06/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Login Data [32768]
O61 - LFC: 06/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal [10792]
O61 - LFC: 06/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor [442368]
O61 - LFC: 06/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor-journal [16384]
O61 - LFC: 06/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs [40960]
O61 - LFC: 06/02/2014 - 17:00:09 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Origin Bound Certs-journal [4640]
O61 - LFC: 06/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\macromedia.com\support\flashplayer\sys\settings.sol [1728]
O61 - LFC: 06/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\HGZHHS5B\www.ajaxcdn.org\swf.swf\dm_cookie.sol [414]
O61 - LFC: 06/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Preferences [222599]
O61 - LFC: 06/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\QuotaManager [20480]
O61 - LFC: 06/02/2014 - 17:00:10 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\QuotaManager-journal [8768]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Session Storage\001762.ldb [58543]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Session Storage\001764.ldb [1249581]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Session Storage\CURRENT [16]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG [276]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old [277]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-001759 [391] =>.Google Inc
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Shortcuts [737280]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Shortcuts-journal [16384]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Sync Data\SyncData.sqlite3 [3166208]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Sync Data\SyncData.sqlite3-journal [16384]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\ejdfidgapfiokiphmcjpmmjbdndepoja\CURRENT [16] =>PUP.Re-Markable
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\ejdfidgapfiokiphmcjpmmjbdndepoja\LOG [145] =>PUP.Re-Markable
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\ejdfidgapfiokiphmcjpmmjbdndepoja\LOG.old [145] =>PUP.Re-Markable
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\ejdfidgapfiokiphmcjpmmjbdndepoja\MANIFEST-000041 [77] =>PUP.Re-Markable
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Top Sites [212992]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal [16384]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity [3520]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Visited Links [131072]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Web Data [366592]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal [16384]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Local State [58598]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Safe Browsing Bloom [5530128]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Safe Browsing Bloom Prefix Set [1405842]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies [6144]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies-journal [2576]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Safe Browsing Csd Whitelist [135496]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Safe Browsing Download [942772]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Safe Browsing Download Whitelist [19504]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Safe Browsing Extension Blacklist [7864]
O61 - LFC: 06/02/2014 - 17:00:11 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Safe Browsing IP Blacklist [740]
O61 - LFC: 06/02/2014 - 17:00:19 --HA- . (...) -- C:\Users\Paméla\AppData\Local\IconCache.db [114132]
O61 - LFC: 06/02/2014 - 17:00:37 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Packages\FileManager_cw5n1h2txyewy\Settings\settings.dat [8192]
O61 - LFC: 06/02/2014 - 17:01:01 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Temp\Twain001.Mtx [3]
O61 - LFC: 06/02/2014 - 17:01:01 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Temp\Twunk001.MTX [156]
O61 - LFC: 06/02/2014 - 17:01:03 ---A- . (...) -- C:\Users\Paméla\AppData\Local\Temp\WMZuneComm.etl.003 [4096]
O61 - LFC: 06/02/2014 - 17:01:19 ---A- . (...) -- C:\Users\Paméla\AppData\Roaming\fr.orange.assistancelivebox\Local Store\ALB.db [8192] =>.Orange Corporation
O61 - LFC: 06/02/2014 - 17:01:20 -SHA- . (...) -- C:\Users\Paméla\AppData\Roaming\Microsoft\Protect\S-1-5-21-1682419926-403432926-433631104-1002\45b888f6-1488-4e8a-a808-44618edbff24 [468]
O61 - LFC: 06/02/2014 - 17:01:20 -SHA- . (...) -- C:\Users\Paméla\AppData\Roaming\Microsoft\Protect\S-1-5-21-1682419926-403432926-433631104-1002\dd7506d5-6c5e-4b86-9432-396f15a2fc45 [468]
O61 - LFC: 06/02/2014 - 17:01:20 -SHA- . (...) -- C:\Users\Paméla\AppData\Roaming\Microsoft\Protect\S-1-5-21-1682419926-403432926-433631104-1002\e61595c6-48d7-4fb7-b2a0-3d60d6c1f7f9 [468]
O61 - LFC: 06/02/2014 - 17:01:22 ---A- . (...) -- C:\Users\Paméla\AppData\Roaming\OpenOffice.org\3\.lock [144]
O61 - LFC: 06/02/2014 - 17:01:26 ---A- . (...) -- C:\Users\Paméla\AppData\Roaming\OpenOffice.org\3\user\registrymodifications.xcu [61847]
O61 - LFC: 06/02/2014 - 17:02:49 ---A- . (...) -- C:\Users\Paméla\AppData\Roaming\ZHP\Log.txt [17781] =>.Nicolas Coolman
O61 - LFC: 06/02/2014 - 17:02:49 ---A- . (...) -- C:\Users\Paméla\AppData\Roaming\ZHP\TestsZHPDiag.txt [2879] =>.Nicolas Coolman
O61 - LFC: 06/02/2014 - 17:06:03 ---A- . (.Nicolas Coolman.) -- C:\Users\Paméla\Downloads\ZHPDiag2.exe [6862845] =>.Nicolas Coolman
~ 6 Fichiers temporaires (Temporary files)
~ Files: 179 Scanned in 06mn 20s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
~ FASS Keys: 11 Scanned in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: prefs.js [Paméla - koicdr2x.default] user_pref("browser.newtab.url", "http://search.conduit.com/?ctid=CT3319415&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1[...]
O69 - SBI: prefs.js [Paméla - koicdr2x.default] user_pref("browser.search.defaultenginename", "Conduit Search");
O69 - SBI: prefs.js [Paméla - koicdr2x.default] user_pref("browser.search.selectedEngine", "Conduit Search");
O69 - SBI: prefs.js [Paméla - koicdr2x.default] user_pref("browser.startup.homepage", "http://search.conduit.com/?ctid=CT3319415&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&[...] =>PUP.SweetIM
O69 - SBI: SearchScopes [HKCU] {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} [DefaultScope] - (Conduit Search) - http://search.conduit.com
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s



---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [207360]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [155136]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [155136]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [324608]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1311744]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [1104384]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [903168]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [109568]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [150528]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [107008]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1212416]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [220672]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [70656]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [134144]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [221184]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [326656]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [81408]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [97792]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [336896]
O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service d’infrastructure de localisation Windows.) -- C:\Windows\System32\GeofenceMonitorService.dll [491520]
O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [1555456]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [50688]
O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [201728]
O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Microsoft.) -- C:\Windows\System32\ncasvc.dll [164352]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [101376]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à distance.) -- C:\Windows\System32\rasmans.dll [534016]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [223744]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [71680]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [433664]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [306688]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [3532288]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [1017856]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [629760]

~ Services: 34 Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.A386BDF5519D34F0F2434C779BFD87CC] [SPRF][06/02/2014] (...) -- C:\ProgramData\ntuser.dat [262144]
[MD5.39955B34B26E332C4580FFDCA097630B] [SPRF][20/01/2014] (.Pas de propriétaire - GetCC.) -- C:\Users\Paméla\AppData\Local\Temp\GetCC.dll [4608]
[MD5.B29E83869C302164E81F3B3D1DC51A90] [SPRF][30/01/2014] (.Solid State Networks - Adobe Flash Player Installer.) -- C:\Users\Paméla\AppData\Local\Temp\install_flashplayer12x32au_ltr5x64d_awc_aih.exe [1069512]
[MD5.0B4029C7A12652F71893E348E13A7483] [SPRF][28/01/2014] (...) -- C:\Users\Paméla\AppData\Local\Temp\Re-Markable_2040-4040.exe [1054016] =>PUP.Re-Markable
[MD5.466C4732BC4B126B94B0E69C6B5A2348] [SPRF][20/01/2014] (.Pas de propriétaire - SendMsg.) -- C:\Users\Paméla\AppData\Local\Temp\SendMsg.dll [9216]
[MD5.77DF4B1613B9649A531C4F6419C79850] [SPRF][28/01/2014] (...) -- C:\Users\Paméla\AppData\Local\Temp\vbmz16.exe [93760] =>PUP.Duuqu
[MD5.34B34A09DBFC8E380FE9C7C37992B730] [SPRF][11/03/2013] (...) -- C:\Users\Paméla\Desktop\bp.exe [1188463]
[MD5.85DEEAD8F3AD064BF744AFA79FCBDA6A] [SPRF][13/04/2013] (.Facebook Inc. - Setup.) -- C:\Users\Paméla\Desktop\FacebookMessengerSetup-v1.2.205.0.exe [501240]
[MD5.5993DC9ADC31FD4101CE9DAA5D89A104] [SPRF][25/03/2013] (.RentASoft.com - RentASoft Image Converter Setup.) -- C:\Users\Paméla\Desktop\Image_Converter.exe [1338652]
[MD5.F34F761FFC7F627B5A2F70ED78D76B53] [SPRF][18/12/2013] (...) -- C:\Users\Paméla\Desktop\R4.dat [608256]
~ Files: 10 Scanned in 00mn 00s



---\\ Liste des exceptions du parefeu (FirewallRules) (O87)
O87 - FAEL: "vm-monitoring-rpc" | In - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "vm-monitoring-dcom" | In - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMP-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMP-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMP-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "SNMPTRAP-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Interruption SNMP.) -- C:\Windows\system32\snmptrap.exe
O87 - FAEL: "SNMPTRAP-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Interruption SNMP.) -- C:\Windows\system32\snmptrap.exe
O87 - FAEL: "Wininit-Shutdown-In-Rule-TCP-RPC" | In - None - P6 - FALSE | .(.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\system32\wininit.exe
O87 - FAEL: "Wininit-Shutdown-In-Rule-TCP-RPC-EPMapper" | In - None - P6 - FALSE | .(.Microsoft Corporation - Application de démarrage de Windows.) -- C:\Windows\system32\wininit.exe
O87 - FAEL: "PNRPMNRS-PNRP-In-UDP" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PNRPMNRS-PNRP-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PNRPMNRS-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PNRPMNRS-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MsiScsi-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MsiScsi-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MsiScsi-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MsiScsi-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "ProximityUxHost-Sharing-In-TCP-NoScope" | In - None - P6 - TRUE | .(.Microsoft Corporation - Hôte UX de proximité.) -- C:\Windows\system32\proximityuxhost.exe
O87 - FAEL: "ProximityUxHost-Sharing-Out-TCP-NoScope" | Out - None - P6 - TRUE | .(.Microsoft Corporation - Hôte UX de proximité.) -- C:\Windows\system32\proximityuxhost.exe
O87 - FAEL: "NETDIS-UPnPHost-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-WSDEVNTS-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-WSDEVNT-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-SSDPSrv-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-SSDPSrv-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-UPnPHost-Out-TCP-Active" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-UPnP-Out-TCP-Active" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDPHOST-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-DAS-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Device Association Framework Provider Host.) -- C:\Windows\system32\dashost.exe
O87 - FAEL: "NETDIS-FDPHOST-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-LLMNR-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-LLMNR-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDRESPUB-WSD-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDRESPUB-WSD-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-WSDEVNTS-Out-TCP-Active" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-WSDEVNT-Out-TCP-Active" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-SSDPSrv-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-SSDPSrv-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-UPnP-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-UPnPHost-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDPHOST-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-DAS-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Device Association Framework Provider Host.) -- C:\Windows\system32\dashost.exe
O87 - FAEL: "NETDIS-FDPHOST-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-LLMNR-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-LLMNR-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDRESPUB-WSD-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-FDRESPUB-WSD-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-WSDEVNTS-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "NETDIS-WSDEVNT-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "EventForwarder-In-TCP" | In - None - P6 - FALSE | .(.Microsoft Corporation - Event Forwarder.) -- C:\Windows\system32\NetEvtFwdr.exe
O87 - FAEL: "EventForwarder-RPCSS-In-TCP" | In - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteFwAdmin-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteFwAdmin-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteFwAdmin-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteFwAdmin-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "TPMVSCMGR-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "TPMVSCMGR-Server-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - TPM Virtual Smart Card Manager DCOM Server.) -- C:\Windows\system32\RmtTpmVscMgrSvr.exe
O87 - FAEL: "TPMVSCMGR-Server-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - TPM Virtual Smart Card Manager DCOM Server.) -- C:\Windows\system32\RmtTpmVscMgrSvr.exe
O87 - FAEL: "TPMVSCMGR-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "TPMVSCMGR-Server-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - TPM Virtual Smart Card Manager DCOM Server.) -- C:\Windows\system32\RmtTpmVscMgrSvr.exe
O87 - FAEL: "TPMVSCMGR-Server-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - TPM Virtual Smart Card Manager DCOM Server.) -- C:\Windows\system32\RmtTpmVscMgrSvr.exe
O87 - FAEL: "Netlogon-TCP-RPC-In" | In - None - P6 - FALSE | .(.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\System32\lsass.exe
O87 - FAEL: "Collab-PNRP-In-UDP" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Collab-PNRP-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Collab-PNRP-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Collab-PNRP-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WirelessDisplay-In-TCP" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\WUDFHost.exe
O87 - FAEL: "WirelessDisplay-Out-TCP" | Out - Public - P6 - TRUE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\WUDFHost.exe
O87 - FAEL: "WirelessDisplay-Out-UDP" | Out - Public - P17 - TRUE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\WUDFHost.exe
O87 - FAEL: "WMI-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-WINMGMT-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-WINMGMT-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-ASYNC-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) -- C:\Windows\system32\wbem\unsecapp.exe
O87 - FAEL: "WMI-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-WINMGMT-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-WINMGMT-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMI-ASYNC-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) -- C:\Windows\system32\wbem\unsecapp.exe
O87 - FAEL: "FPS-SpoolSvc-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe
O87 - FAEL: "FPS-SpoolSvc-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe
O87 - FAEL: "FPS-LLMNR-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "FPS-LLMNR-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Microsoft-Windows-HomeGroup-ProvSvc-TCP3587-In" | In - Private - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Microsoft-Windows-HomeGroup-ProvSvc-TCP3587-Out" | Out - Private - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Microsoft-Windows-HomeGroup-ProvSvc-UDP3540-In" | In - Private - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "Microsoft-Windows-HomeGroup-ProvSvc-UDP3540-Out" | Out - Private - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-In-TCP-EdgeScope" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe
O87 - FAEL: "RemoteAssistance-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe
O87 - FAEL: "RemoteAssistance-PnrpSvc-UDP-In-EdgeScope" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-PnrpSvc-UDP-OUT" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-RAServer-In-TCP-NoScope-Active" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Serveur COM d’assistance à distance Windows.) -- C:\Windows\system32\raserver.exe
O87 - FAEL: "RemoteAssistance-RAServer-Out-TCP-NoScope-Active" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Serveur COM d’assistance à distance Windows.) -- C:\Windows\system32\raserver.exe
O87 - FAEL: "RemoteAssistance-DCOM-In-TCP-NoScope-Active" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-In-TCP-EdgeScope-Active" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe
O87 - FAEL: "RemoteAssistance-Out-TCP-Active" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe
O87 - FAEL: "RemoteAssistance-SSDPSrv-In-UDP-Active" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-SSDPSrv-Out-UDP-Active" | Out - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-PnrpSvc-UDP-In-EdgeScope-Active" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteAssistance-PnrpSvc-UDP-OUT-Active" | Out - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MSDTC-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) -- C:\Windows\system32\msdtc.exe
O87 - FAEL: "MSDTC-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) -- C:\Windows\system32\msdtc.exe
O87 - FAEL: "MSDTC-KTMRM-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MSDTC-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MSDTC-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) -- C:\Windows\system32\msdtc.exe
O87 - FAEL: "MSDTC-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Service Microsoft Distributed Transaction Coordinator.) -- C:\Windows\system32\msdtc.exe
O87 - FAEL: "MSDTC-KTMRM-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MSDTC-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-Out-UDP-NoScope" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-WMP-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-WMP-Out-UDP-NoScope" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-WMP-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-In-UDP-NoScope" |In - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-Out-UDP-NoScope" |Out - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-Out-UDP" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-QWave-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-WMP-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-WMP-Out-UDP" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-WMP-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-In-UDP" |In - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-Out-UDP" |Out - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.) =>.Microsoft Corporation
O87 - FAEL: "WMPNSS-UPnP-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteEventLogSvc-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteEventLogSvc-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteEventLogSvc-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteEventLogSvc-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteTask-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteTask-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteTask-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteTask-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RVM-VDS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Service de disque virtuel.) -- C:\Windows\system32\vds.exe
O87 - FAEL: "RVM-VDSLDR-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Virtual Disk Service Loader.) -- C:\Windows\system32\vdsldr.exe
O87 - FAEL: "RVM-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RVM-VDS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Service de disque virtuel.) -- C:\Windows\system32\vds.exe
O87 - FAEL: "RVM-VDSLDR-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Virtual Disk Service Loader.) -- C:\Windows\system32\vdsldr.exe
O87 - FAEL: "RVM-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PlayTo-In-UDP-NoScope" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe
O87 - FAEL: "PlayTo-In-UDP-LocalSubnetScope" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe
O87 - FAEL: "PlayTo-In-UDP-PlayToScope" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe
O87 - FAEL: "PlayTo-Out-UDP-NoScope" | Out - Domain - P17 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe
O87 - FAEL: "PlayTo-Out-UDP-LocalSubnetScope" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe
O87 - FAEL: "PlayTo-Out-UDP-PlayToScope" | Out - Public - P17 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe
O87 - FAEL: "PlayTo-In-RTSP-NoScope" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe
O87 - FAEL: "PlayTo-In-RTSP-LocalSubnetScope" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe
O87 - FAEL: "PlayTo-In-RTSP-PlayToScope" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Serveur Lire sur.) -- C:\Windows\system32\mdeserver.exe
O87 - FAEL: "PlayTo-SSDP-Discovery-PlayToScope" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PlayTo-QWave-In-UDP-PlayToScope" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PlayTo-QWave-Out-UDP-PlayToScope" | Out - Public - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PlayTo-QWave-In-TCP-PlayToScope" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PlayTo-QWave-Out-TCP-PlayToScope" | Out - Public - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WFDPRINT-DAFWSD-In-Active" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Device Association Framework Provider Host.) -- C:\Windows\system32\dashost.exe
O87 - FAEL: "WFDPRINT-DAFWSD-Out-Active" | Out - Public - P6 - TRUE | .(.Microsoft Corporation - Device Association Framework Provider Host.) -- C:\Windows\system32\dashost.exe
O87 - FAEL: "WFDPRINT-SPOOL-In-Active" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe
O87 - FAEL: "WFDPRINT-SPOOL-Out-Active" | Out - Public - P6 - TRUE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe
O87 - FAEL: "WFDPRINT-SCAN-In-Active" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WFDPRINT-SCAN-Out-Active" | Out - Public - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-DHCP-In" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-DHCP-Out" | Out - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-DHCPV6-In" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-DHCPV6-Out" | Out - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-Teredo-In" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-Teredo-Out" | Out - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-IPHTTPS-Out" | Out - None - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-GP-Out-TCP" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-DNS-Out-UDP" | Out - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "CoreNet-GP-LSASS-Out-TCP" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\system32\lsass.exe
O87 - FAEL: "PerfLogsAlerts-PLASrv-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Performance Logs and Alerts DCOM Server.) -- C:\Windows\system32\plasrv.exe
O87 - FAEL: "PerfLogsAlerts-DCOM-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "PerfLogsAlerts-PLASrv-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Performance Logs and Alerts DCOM Server.) -- C:\Windows\system32\plasrv.exe
O87 - FAEL: "PerfLogsAlerts-DCOM-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteSvcAdmin-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\Windows\system32\services.exe
O87 - FAEL: "RemoteSvcAdmin-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "RemoteSvcAdmin-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\Windows\system32\services.exe
O87 - FAEL: "RemoteSvcAdmin-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WPDMTP-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\wudfhost.exe
O87 - FAEL: "WPDMTP-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\wudfhost.exe
O87 - FAEL: "WPDMTP-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WPDMTP-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WPDMTP-UPnPHost-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "WPDMTP-UPnP-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-SSDPSrv-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-SSDPSrv-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-QWave-In-UDP" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-QWave-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-QWave-In-TCP" | In - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-QWave-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-TERMSRV-In-TCP" | In - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-MCX2SVC-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-PlayTo-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-PlayTo-Out-UDP" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "MCX-FDPHost-Out-TCP" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{2F561D05-B292-4A3A-B144-8C78CAA99680}" | In - None - P6 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files (x86)\iTunes\iTunes.exe
O87 - FAEL: "{F9DB514B-A047-48A9-AA68-32B06931815B}" | In - None - P6 - TRUE | .(.Apple Inc. - WebKit2WebProcess.exe.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
O87 - FAEL: "UDP Query User{49F25144-8843-4772-B9B2-1A815509BBAB}C:\program files (x86)\orange\assistance livebox\dist\st2.exe" | In - Public - P17 - TRUE | .(.Orange - Assistance Livebox.) -- C:\program files (x86)\orange\assistance livebox\dist\st2.exe
O87 - FAEL: "TCP Query User{C98DDC07-3D5B-4236-972E-CF4D17FCCBDE}C:\program files (x86)\orange\assistance livebox\dist\st2.exe" | In - Public - P6 - TRUE | .(.Orange - Assistance Livebox.) -- C:\program files (x86)\orange\assistance livebox\dist\st2.exe
O87 - FAEL: "UDP Query User{CE2FCD57-CA70-4AC9-8C4E-6634F1FA0A8C}C:\program files (x86)\orange\assistance livebox\dist\st2.exe" | In - Private - P17 - TRUE | .(.Orange - Assistance Livebox.) -- C:\program files (x86)\orange\assistance livebox\dist\st2.exe
O87 - FAEL: "TCP Query User{8008BC44-CD73-4747-9066-86D40B9DBA52}C:\program files (x86)\orange\assistance livebox\dist\st2.exe" | In - Private - P6 - TRUE | .(.Orange - Assistance Livebox.) -- C:\program files (x86)\orange\assistance livebox\dist\st2.exe
O87 - FAEL: "{279D6C50-5579-4392-A346-69D2BBAC2D65}" | In - Private - P17 - TRUE | .(.Orange SA - Orange Upd@te.) -- C:\Program Files (x86)\Orange\OrangeUpdate\Service\OUCore.exe
O87 - FAEL: "{5C3A53BD-B2B8-4571-8DD9-762E8C7EC8D5}" | In - Private - P6 - TRUE | .(.Orange SA - Orange Upd@te.) -- C:\Program Files (x86)\Orange\OrangeUpdate\Service\OUCore.exe
O87 - FAEL: "{99CD85DF-38BA-4D8B-BE04-C4FC792D5E92}" | In - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Orange\Assistance Livebox\dedicarz\PluginLivebox.exe
O87 - FAEL: "{1037667D-57C0-4E4D-99DC-B7A486C4B10B}" | In - None - P6 - TRUE | .(...) -- C:\Program Files (x86)\Orange\Assistance Livebox\dedicarz\PluginLivebox.exe
O87 - FAEL: "{4788DF6C-A7C7-409F-858F-3C5920C9AEFA}" | In - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Orange\Assistance Livebox\dedicarz\LiveboxManager.exe
O87 - FAEL: "{BAF38272-202C-4D1E-B56F-0A2AB210DC1A}" | In - None - P6 - TRUE | .(...) -- C:\Program Files (x86)\Orange\Assistance Livebox\dedicarz\LiveboxManager.exe
O87 - FAEL: "{02D68F53-229C-47DE-9160-536C0E1DCCBB}" | In - None - P17 - TRUE | .(.Pas de propriétaire - DedicarzService.) -- C:\Program Files (x86)\Orange\Assistance Livebox\dedicarz\DedicarzService.exe
O87 - FAEL: "{D27618FD-A47D-4687-8CFB-E695C3C1E626}" | In - None - P6 - TRUE | .(.Pas de propriétaire - DedicarzService.) -- C:\Program Files (x86)\Orange\Assistance Livebox\dedicarz\DedicarzService.exe
O87 - FAEL: "{927E8C08-C455-4A58-85DC-548BF4C39F1D}" | In - None - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe
O87 - FAEL: "{51CD1852-D689-46F0-886A-27049DBE4664}" | In - None - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe
O87 - FAEL: "{A94A37BF-4929-4AD7-9781-524FBF0DB97D}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O87 - FAEL: "{58DFBFB5-0BB8-4FBE-91B3-11D7DA477F4B}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O87 - FAEL: "{6FC5C7D4-40F0-4EAE-ABA4-6D8253DE5759}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe
O87 - FAEL: "{F8D73136-F4A3-444C-8E59-3DDD9E7A051E}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe
O87 - FAEL: "{5770B3C0-4A74-4133-B083-2CC934853081}" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Microsoft Outlook.) -- C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
O87 - FAEL: "{18351FC8-A984-4F87-99A4-B3758DEED79F}" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{BE7C0CD2-EFBD-46BC-9A4B-089BF35B6A7C}" |Out - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Zune\ZuneNSS.exe (.not file.)
O87 - FAEL: "{849A212A-04A8-4F58-A06B-6529EA179E90}" |In - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Zune\ZuneNSS.exe (.not file.)
O87 - FAEL: "{19CE0902-7CF9-476A-93CA-B66016190E4D}" |Out - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Zune\ZuneNSS.exe (.not file.)
O87 - FAEL: "{6A2084D6-ADD5-4CDD-B64A-46CDA9481472}" |In - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Zune\ZuneNSS.exe (.not file.)
O87 - FAEL: "{40FE3CE4-C5DE-4805-AF58-E08EAE08C039}" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{B7E3CD1C-6E75-4031-8F77-90D5D82137CD}" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{9DB1B34A-86F9-4113-A38E-3AE866B913A8}" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{C5F9C25D-A7EA-43B3-98BB-63268B74AC48}" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{04314ABF-9269-4414-9BC8-D9C6CD216A00}" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{2917DB31-7AA0-4E30-9D50-1597A5DF7F3B}" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{EE6F235C-81D9-4824-B530-BCD5CD3674AE}" |Out - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Zune\ZuneNSS.exe (.not file.)
O87 - FAEL: "{625503B9-65B7-423D-8FDB-12EA3780EEF4}" |In - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Zune\ZuneNSS.exe (.not file.)
O87 - FAEL: "{C94C6231-83F2-4007-AE01-68888153EEF7}" |Out - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Zune\ZuneNSS.exe (.not file.)
O87 - FAEL: "{F1F5B891-F3A8-4FE3-889E-93D25C949C76}" |In - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Zune\ZuneNSS.exe (.not file.)
O87 - FAEL: "{12693F2A-4718-42AF-A51F-634267CF92B3}" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{F66EADBC-B7DC-4211-85B5-C7A53E6C17E9}" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{7B67E3D4-16F2-427B-A9A6-D0DE0AB2C956}" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{4D0DDF39-E606-4911-A408-9B5A1559AC3E}" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{6EEDF640-53CC-4B32-AA76-5ADE59D996B3}" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\wudfhost.exe
O87 - FAEL: "{143576A3-40BE-4E81-A1FB-D29B88B076AC}" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\wudfhost.exe
O87 - FAEL: "{937F0E29-9A8E-441B-A60C-83DB0441B93F}" | Out - None - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{A74B6519-85A1-4C55-AD02-5E87CAD8B3CD}" |In - None - P17 - FALSE | .(...) -- C:\Program Files (x86)\Zune\Zune.exe (.not file.)
O87 - FAEL: "{36C1A6F2-0FC9-4E66-9A55-4DEB4BACF61F}" | Out - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{BBD4D52B-5F3F-4A94-9EF3-F144994225C0}" | In - None - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "UDP Query User{8BED00B9-0112-4596-A58A-08E3F2DDBB4F}C:\program files (x86)\epson software\event manager\eeventmanager.exe" | In - Public - P17 - TRUE | .(.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\program files (x86)\epson software\event manager\eeventmanager.exe
O87 - FAEL: "TCP Query User{7A46BB2F-9C2E-4550-A58B-8307A9952439}C:\program files (x86)\epson software\event manager\eeventmanager.exe" | In - Public - P6 - TRUE | .(.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\program files (x86)\epson software\event manager\eeventmanager.exe
O87 - FAEL: "UDP Query User{56DE9AF1-304C-4AAC-9392-9251384A41A7}C:\program files (x86)\epson software\event manager\eeventmanager.exe" | In - Private - P17 - TRUE | .(.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\program files (x86)\epson software\event manager\eeventmanager.exe
O87 - FAEL: "TCP Query User{9ACC7F3D-DE53-412D-A46A-914A3778936D}C:\program files (x86)\epson software\event manager\eeventmanager.exe" | In - Private - P6 - TRUE | .(.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\program files (x86)\epson software\event manager\eeventmanager.exe
O87 - FAEL: "{41ADEFE1-7028-4F65-8068-E15E1084622E}" |In - Private - P17 - TRUE | .(...) -- F:\Network\EpsonNetSetup\ENEasyApp.exe (.not file.)
O87 - FAEL: "{846AE5BC-B1B9-4A9C-8616-12D79A1E0268}" |In - Private - P6 - TRUE | .(...) -- F:\Network\EpsonNetSetup\ENEasyApp.exe (.not file.)
O87 - FAEL: "UDP Query User{3FA88F44-CC55-42E9-85F4-2D822B89A945}C:\program files (x86)\skype\phone\skype.exe" | In - Public - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\program files (x86)\skype\phone\skype.exe =>.Skype Technologies S.A.
O87 - FAEL: "TCP Query User{7908CD50-68DA-42C1-A3C6-765D3F75C2FC}C:\program files (x86)\skype\phone\skype.exe" | In - Public - P6 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\program files (x86)\skype\phone\skype.exe =>.Skype Technologies S.A.
O87 - FAEL: "UDP Query User{3AE46B41-CFE9-42D9-89D9-B801BA9D998F}C:\program files (x86)\skype\phone\skype.exe" | In - Private - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\program files (x86)\skype\phone\skype.exe =>.Skype Technologies S.A.
O87 - FAEL: "TCP Query User{A00C8AF2-A338-42D7-ABD5-42322496D143}C:\program files (x86)\skype\phone\skype.exe" | In - Private - P6 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\program files (x86)\skype\phone\skype.exe =>.Skype Technologies S.A.
O87 - FAEL: "{B6C5564B-B3B6-4E07-B59D-2F5E06EEE4AB}" | In - None - P6 - TRUE | .(.CyberLink Corp. - PowerDVD 10.0.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.exe
O87 - FAEL: "{2CEEEBA5-FEEF-40BB-AA54-5DD0E86E0875}" | In - Public - P17 - TRUE | .(...) -- C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
O87 - FAEL: "{EB202F75-1E93-4374-9545-2710951CC98B}" | In - Public - P6 - TRUE | .(...) -- C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
O87 - FAEL: "{6164B03C-EB89-4B04-B3B0-F7A234E45082}" | In - Public - P17 - TRUE | .(.Spotify Ltd - Spotify.) -- C:\Program Files (x86)\Spotify\spotify.exe
O87 - FAEL: "{598F2853-8632-4650-A8F4-CB048D7835C7}" | In - Public - P6 - TRUE | .(.Spotify Ltd - Spotify.) -- C:\Program Files (x86)\Spotify\spotify.exe
O87 - FAEL: "{6418F5F2-B4F6-48E0-A684-AA541294DC7B}" | In - Public - P6 - TRUE | .(.Nero AG - Nero BackItUp.) -- C:\program files (x86)\nero\nero 12\nero backitup\backitup.exe
O87 - FAEL: "{3F3C86CF-7295-47AB-B327-41702A2F54A5}" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{B682CD87-48AE-4411-8D90-D7798F67C6E1}" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe =>.Microsoft Corporation
O87 - FAEL: "{3979A6EC-BE63-4AF2-A925-876FE80F25FB}" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe
~ Firewall: 264 Scanned in 00mn 04s



---\\ Enumère les codes produits des logiciels (PUC) (O90)
O90 - PUC: "0000009F810000000000709475387300" . (.ABBYY FineReader 9.0 Sprint.) -- C:\Windows\Installer\{F9000000-0018-0000-0000-074957833700}\ARPPRODUCTICON.exe
O90 - PUC: "0336A2D4B8F23E11C9048BCAF6798BE8" . (.Google Earth.) -- C:\Windows\Installer\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}\ARPPRODUCTICON.exe
O90 - PUC: "03FF80700C870B74180F8C6440CD67C9" . (.Nero Express Help (CHM).) -- C:\Windows\Installer\{0708FF30-78C0-47B0-81F0-C84604DC769C}\NeroHelpIcon.A2EDDB31_726D_4D40_8014_5D5F2D3EF945
O90 - PUC: "122113B05A506674D830A74664971465" . (.Nero RescueAgent Help (CHM).) -- c:\Windows\Installer\{0B311221-05A5-4766-8D03-7A6446794156}\NeroHelpIcon.A2EDDB31_726D_4D40_8014_5D5F2D3EF945
O90 - PUC: "18034D2AB7FC73649A3F2E56A15A4C8A" . (.Nero RescueAgent.) -- c:\Windows\Installer\{A2D43081-CF7B-4637-A9F3-E2651AA5C4A8}\ARPPRODUCTICON.exe
O90 - PUC: "1B82728172783BA41AEA1FDEC2B8B1CA" . (.Catalyst Control Center - Branding.) -- C:\Windows\Installer\{182728B1-8727-4AB3-A1AE-F1ED2C8B1BAC}\ARPPRODUCTICON.exe
O90 - PUC: "203E62EEA6789D84098513925E9B9999" . (.Live Updater.) -- C:\Windows\Installer\{EE26E302-876A-48D9-9058-3129E5B99999}\icon.ico
O90 - PUC: "2921D0FE1CF8EB147904BD1C436F4651" . (.Nero BackItUp Help (CHM).) -- c:\Windows\Installer\{EF0D1292-8FC1-41BE-9740-DBC134F66415}\NeroHelpIcon.A2EDDB31_726D_4D40_8014_5D5F2D3EF945
O90 - PUC: "2B0163E6D0340BE4183EB2758E9BEDD8" . (.Bonjour.) -- C:\Windows\Installer\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}\Bonjour.ico
O90 - PUC: "35588CBA077879B44BE3A50946A7B536" . (.Nero ControlCenter.) -- C:\Windows\Installer\{ABC88553-8770-4B97-B43E-5A90647A5B63}\ARPPRODUCTICON.exe
O90 - PUC: "37CE0B2BA4DA61743AEDEC8A44B003B9" . (.Nero BackItUp 12 Essentials OEM.a01.) -- c:\Windows\Installer\{B2B0EC73-AD4A-4716-A3DE-CEA8440B309B}\ARPPRODUCTICON.exe
O90 - PUC: "37DF37055B3365052D1FC3CEEC7EE673" . (.AMD AVIVO64 Codecs.) -- C:\Windows\Installer\{5073FD73-33B5-5056-D2F1-3CECCEE76E37}\ARPPRODUCTICON.exe
O90 - PUC: "3A80BAA3921F5DB44B90EA76F43957D9" . (.Prerequisite installer.) -- C:\Windows\Installer\{3AAB08A3-F129-4BD5-B409-AE674F93759D}\ARPPRODUCTICON.exe
O90 - PUC: "456BC9D3DA991034986CD0217A0967C7" . (.Identity Card.) -- C:\Windows\Installer\{3D9CB654-99AD-4301-89C6-0D12A790767C}\icon.ico
O90 - PUC: "5A440F64B8EC691489E4B56D25E563D1" . (.Apple Application Support.) -- C:\Windows\Installer\{46F044A5-CE8B-4196-984E-5BD6525E361D}\WinInstall.ico
O90 - PUC: "647C499C0D6CABE40BE9FDB78183B196" . (.Nero ControlCenter Help (CHM).) -- C:\Windows\Installer\{C994C746-C6D0-4EBA-B09E-DF7B18381B69}\NeroHelpIcon.8BC7562A_6065_4ED9_8502_C368ECC0724D
O90 - PUC: "7040BB568CC47CD459E2E3FEFD5006A2" . (.Nero Update.) -- C:\Windows\Installer\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}\ARPPRODUCTICON.exe
O90 - PUC: "8489373E92353E84D882B5DBE6B83E48" . (.MediaEspresso.) -- C:\Windows\Installer\{E3739848-5329-48E3-8D28-5BBD6E8BE384}\ARPPRODUCTICON.exe
O90 - PUC: "86C7A848CDA03914A898C2AE875EA6C0" . (.Nero Express.) -- C:\Windows\Installer\{848A7C68-0ADC-4193-8A89-2CEA78E56A0C}\ARPPRODUCTICON.exe
O90 - PUC: "8D6F18B56AFA4DBBB04743E21E594CFF" . (.Catalyst Control Center InstallProxy.) -- C:\Windows\Installer\{5B81F6D8-AFA6-BBD4-0B74-342EE195C4FF}\ARPPRODUCTICON.exe
O90 - PUC: "A5002F70CAC8B4A4382AAD897A22AC16" . (.Recovery Management.) -- C:\Windows\Installer\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}\Bitmaps\eRecoveryicon.ico
O90 - PUC: "B412068E7D67131BBBB7757ACB31C081" . (.AMD VISION Engine Control Center.) -- C:\Windows\Installer\{E860214B-76D7-B131-BB7B-57A7BC130C18}\ARPPRODUCTICON.exe
O90 - PUC: "B451924E56C69EB2CA0806FD37BC7947" . (.AMD Accelerated Video Transcoding.) -- C:\Windows\Installer\{E429154B-6C65-2BE9-AC80-60DF73CB9774}\ARPPRODUCTICON.exe
O90 - PUC: "BE46BC91EFCAD1865B178A3A93F89134" . (.AMD Catalyst Install Manager.) -- C:\Windows\Installer\{19CB64EB-ACFE-681D-B571-A8A3398F1943}\ARPPRODUCTICON.exe
O90 - PUC: "C2F2B07E1D4978245B0BBCEB16E86225" . (.Nero BackItUp.) -- c:\Windows\Installer\{E70B2F2C-94D1-4287-B5B0-CBBE618E2652}\ARPPRODUCTICON.exe
O90 - PUC: "D276F30548C6A844F8F8B43CA58C4314" . (.AMD APP SDK Runtime.) -- C:\Windows\Installer\{503F672D-6C84-448A-8F8F-4BC35AC83441}\ARPPRODUCTICON.exe
O90 - PUC: "D2FF8212431731E3E4086F7DA15FB99A" . (.Catalyst Control Center Localization All.) -- C:\Windows\Installer\{2128FF2D-7134-3E13-4E80-F6D71AF59BA9}\ARPPRODUCTICON.exe
O90 - PUC: "D90E08BDADACF51E2FA652915995CF82" . (.AMD Fuel.) -- C:\Windows\Installer\{DB80E09D-CADA-E15F-F26A-25199559FC28}\ARPPRODUCTICON.exe
O90 - PUC: "DAEC106DF4E2BBB458CC2CA9C46E3A0C" . (.iTunes.) -- C:\Windows\Installer\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}\Installer.ico
O90 - PUC: "DE532CED4A8571542A874CE1D8EABAB3" . (.PowerDVD.) -- C:\Windows\Installer\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\ARPPRODUCTICON.exe
O90 - PUC: "E508E5CF51230A156B8568DCAF44C074" . (.ccc-utility64.) -- C:\Windows\Installer\{FC5E805E-3215-51A0-B658-86CDFA440C47}\ARPPRODUCTICON.exe
O90 - PUC: "E78D5FE2DB7BF85448824E0D8B4B6EC5" . (.Apple Mobile Device Support.) -- C:\Windows\Installer\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}\Installer.ico
O90 - PUC: "E7F34DE86F8A8984FA116B51F8E2FD49" . (.Epson Event Manager.) -- C:\Windows\Installer\{8ED43F7E-A8F6-4898-AF11-B6158F2EDF94}\icon.exe
O90 - PUC: "E7FF67E4ABEA78C47B88DC745E24B5D9" . (.Skype™ 6.5.) -- C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe
O90 - PUC: "EF9D0FB939897464189B717BEB4A6EDF" . (.Nero 12 Essentials OEM.a01.) -- C:\Windows\Installer\{9BF0D9FE-9893-4647-81B9-17B7BEA4E6FD}\ARPPRODUCTICON.exe
O90 - PUC: "F60C1AD7319C7C64A8F0ADC2AB71AED1" . (.OpenOffice.org 3.4.1.) -- C:\Windows\Installer\{7DA1C06F-C913-46C7-8A0F-DA2CBA17EA1D}\soffice.ico
O90 - PUC: "FA0364E07BA0E0449A87A187CFF4349B" . (.Nero Launcher.) -- C:\Windows\Installer\{0E4630AF-0AB7-440E-A978-1A78FC4F43B9}\ARPPRODUCTICON.exe
~ Update Products: 104 Scanned in 00mn 00s



---\\ Enumère les données de la clé NameSpace (MNS) (O92)
O92 - MNS: - {1CF1260C-4DD0-4ebb-811F-33C572699FDE}
O92 - MNS: - {374DE290-123F-4565-9164-39C4925E467B}
O92 - MNS: - {3ADD1653-EB32-4cb0-BBD7-DFA0ABB5ACCA}
O92 - MNS: - {A0953C92-50DC-43bf-BE83-3742FED03C9C}
O92 - MNS: - {A8CDFF1C-4878-43be-B5FD-F8091C1C60D0}
O92 - MNS: - {B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
~ MNS: 6 Scanned in 00mn 00s



---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.69951AD933BA41B04835C7A2A33E927A] [WIS][06/07/2013] (.Skype Technologies S.A. - Skype.) -- C:\Windows\Installer\20a84060.msi [21565440]
~ WIS: 103 Scanned in 00mn 12s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 04/02/2014 257928 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Disabled 07/09/2013 55624 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SS - | Disabled 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SS - | Disabled 10/06/2013 1966960 | (Dedicarz Service) . (...) - C:\Program Files (x86)\Orange\Assistance Livebox\dedicarz\DedicarzService.exe
SS - | Disabled 18/01/2014 227904 | (GamesAppIntegrationService) . (.WildTangent.) - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
SS - | Disabled 12/10/2010 206072 | (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
SS - | Disabled 02/04/2013 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Disabled 02/04/2013 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Disabled 13/07/2012 2451456 | (IconMan_R) . (.Realsil Microelectronics Inc..) - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
SS - | Disabled 02/11/2013 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Disabled 06/09/2013 288776 | (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe
SS - | Disabled 05/12/2013 119408 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Auto 29/08/2013 1073160 | (Orange update Core Service) . (.Orange SA.) - C:\Program Files (x86)\Orange\OrangeUpdate\Service\OUCore.exe
SS - | Disabled 03/06/2013 162408 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SS - | Disabled 11/11/2013 114176 | (WajamUpdaterV3) . (.Wajam.) - C:\Program Files (x86)\Wajam\Updater\WajamUpdaterV3.exe =>PUP.Wajam
SS - | Demand 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SS - | Demand 22/08/2013 37768 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

SR - | Auto 14/05/2009 759048 | (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY.) - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
SR - | Auto 13/12/2013 239616 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Auto 19/07/2012 361984 | (AMD FUEL Service) . (.Advanced Micro Devices, Inc..) - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
SR - | Demand 22/08/2012 658576 | (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
SR - | Auto 19/12/2006 94208 | (EpsonBidirectionalService) . (.SEIKO EPSON CORPORATION.) - C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
SR - | Auto 04/04/2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
SR - | Auto 04/04/2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
SR - | Auto 26/11/2011 687400 | (NAUpdate) . (.Nero AG.) - C:\Program Files (x86)\Nero\Update\NASvc.exe
SR - | Demand 10/07/1658 0 | (WdNisSvc) . (...) - C:\Program Files (x86)\Windows Defender\NisSrv.exe
SR - | Auto 10/07/1658 0 | (WinDefend) . (...) - C:\Program Files (x86)\Windows Defender\MsMpEng.exe

~ Services: Scanned in 00mn 15s



---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Run by Paméla at 06/02/2014 17:07:46
~ OS 64 not supported by MBR tool

~ MBR: 0 Scanned in 00mn 00s



---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Paméla at 06/02/2014 17:07:48

********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin

~ MBR: Scanned in 00mn 02s



---\\ Scan Additionnel (O88)
Database Version : 13030 - (25/01/2014)
Clés trouvées (Keys found) : 37
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 13
Fichiers trouvés (Files found) : 9

[HKLM\Software\Google\Chrome\Extensions\ejdfidgapfiokiphmcjpmmjbdndepoja] =>PUP.Re-Markable^
[HKLM\Software\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde] =>Toolbar.DeltaSearch^
[HKLM\Software\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp] =>PUP.Wajam^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}] =>PUP.Wajam^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC9F5197-891E-4E08-9AAF-BC5E27015495}] =>PUP.Re-Markable^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ff0a387a-a0e9-4be8-8758-c80d49bbdb14] =>PUP.Re-Markable^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect] =>Toolbar.Conduit^
[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\VisualBee for Microsoft PowerPoint] =>Adware.VisualBeeToolbar^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Wajam] =>PUP.Wajam^
[HKLM\Software\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}] =>Toolbar.Wajam
[HKLM\Software\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}] =>Toolbar.Wajam
[HKLM\Software\Wow6432Node\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}] =>Toolbar.Wajam
[HKLM\Software\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}] =>Toolbar.Wajam
[HKLM\Software\Wow6432Node\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}] =>Toolbar.Wajam
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}] =>Toolbar.Agent
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}] =>Toolbar.Agent
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}] =>Toolbar.Agent
[HKLM\Software\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}] =>Toolbar.Wajam
[HKLM\Software\Wow6432Node\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}] =>Toolbar.Wajam
[HKLM\Software\Wow6432Node\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp] =>Toolbar.Wajam
[HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater] =>Toolbar.Wajam
[HKCU\Software\Softonic] =>Toolbar.Conduit
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect] =>Toolbar.Conduit
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211181110}] =>Adware.VidSaver
[HKLM\Software\Classes\AppID\priam_bho.DLL] =>Toolbar.Wajam
[HKLM\Software\Wow6432Node\VBMZ] =>Toolbar.Conduit
[HKCU\Software\InstallCore] =>Adware.InstallCore
[HKLM\Software\Classes\wajam.WajamBHO] =>PUP.Wajam
[HKLM\Software\Classes\wajam.WajamBHO.1] =>PUP.Wajam
[HKLM\Software\Classes\wajam.WajamDownloader] =>PUP.Wajam
[HKLM\Software\Classes\wajam.WajamDownloader.1] =>PUP.Wajam
[HKLM\Software\Wow6432Node\Classes\wajam.WajamBHO] =>PUP.Wajam
[HKLM\Software\Wow6432Node\Classes\wajam.WajamBHO.1] =>PUP.Wajam
[HKLM\Software\Wow6432Node\Classes\wajam.WajamDownloader] =>PUP.Wajam
[HKLM\Software\Wow6432Node\Classes\wajam.WajamDownloader.1] =>PUP.Wajam
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211181110}] =>PUP.CrossRider
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211181110}] =>PUP.CrossRider
C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejdfidgapfiokiphmcjpmmjbdndepoja =>PUP.Re-Markable^
C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde =>Toolbar.DeltaSearch^
C:\Users\Paméla\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp =>PUP.Wajam^
C:\Program Files (x86)\Re-Markable =>PUP.Re-Markable^
C:\Program Files (x86)\SearchProtect =>Toolbar.Conduit^
C:\Program Files (x86)\Wajam =>PUP.Wajam^
C:\ProgramData\VisualBee =>Adware.VisualBeeToolbar^
C:\Users\Paméla\AppData\Roaming\uTorrent =>P2P.µTorrent^
C:\Users\Paméla\AppData\Local\SearchProtect =>Toolbar.Conduit^
C:\Users\Paméla\AppData\Local\VisualBeeClient =>Adware.VisualBeeToolbar^
C:\Users\Paméla\AppData\Local\VisualBeeExe =>Adware.VisualBeeToolbar^
C:\Users\Paméla\AppData\Local\Wajam =>PUP.Wajam^
C:\Users\Paméla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam =>PUP.Wajam^
C:\Windows\Tasks\Re-Markable Update.job =>PUP.Re-Markable^
C:\Program Files (x86)\Re-Markable\ReMarkableup.exe =>PUP.Re-Markable^
[HKCU\Software\AppDataLow\Software\Re_Markable] =>PUP.Re-Markable^
[HKCU\Software\Conduit] =>Toolbar.Conduit^
[HKCU\Software\Visualbee] =>Adware.VisualBeeToolbar^
[HKCU\Software\Wajam] =>PUP.Wajam^
[HKLM\Software\Wow6432Node\Visualbee] =>Adware.VisualBeeToolbar^
C:\Users\Paméla\AppData\Local\Temp\Re-Markable_2040-4040.exe =>PUP.Re-Markable^
C:\Users\Paméla\AppData\Local\Temp\vbmz16.exe =>PUP.Duuqu^
~ Additionnel Scan: 271655 Items scanned in 00mn 51s



---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blog/show/29216159-pup-sweetim =>PUP.SweetIM
~ http://nicolascoolman.webs.com/apps/blog/show/40060228-pup-re-markable =>PUP.Re-Markable
~ http://nicolascoolman.webs.com/apps/blog/show/27875657-toolbar-deltasearch =>Toolbar.DeltaSearch
~ http://nicolascoolman.webs.com/apps/blog/show/27379491-toolbar-wajam =>PUP.Wajam
~ http://nicolascoolman.webs.com/apps/blog/show/29507721-toolbar-conduit =>Toolbar.Conduit
~ http://nicolascoolman.webs.com/apps/blog/show/29058830-adware-visualbeetoolbar =>Adware.VisualBeeToolbar
~ http://nicolascoolman.webs.com/apps/blog/show/29790567-adware-installcore =>Adware.InstallCore
~ http://nicolascoolman.webs.com/apps/blog/show/37752731-pup-duuqu =>PUP.Duuqu
~ http://nicolascoolman.webs.com/apps/blog/show/26601058-adware-addlyrics =>Adware.AddLyrics
~ http://nicolascoolman.webs.com/apps/blog/show/27557062-adware-vidsaver =>Adware.VidSaver
~ http://nicolascoolman.webs.com/apps/blog/show/27583526-pup-crossrider =>PUP.CrossRider
~ MSI: 11 link(s) detected in 00mn 53s



End of the scan (2377 lines in 11mn 57s)(0)

Publicité


Signaler le contenu de ce document

Publicité