Rapport de ZHPDiag v2013.3.29.112 par Nicolas Coolman, Update du 29/03/2013 Run by COUTURIER at 01/04/2013 13:01:59 State : Nouvelle version disponible High Elevated Privileges : OK UAC : Not Found ---\\ Web Browser MSIE: Internet Explorer v8.0.6001.18702 MFIE: Mozilla Firefox 19.0.2 v19.0.2 (Defaut) ---\\ Windows Product Information ~ Langage: Français Windows XP Home Edition Service Pack 3 (Build 2600) Windows Automatic Updates : OK Windows Genuine Advantage : OK ---\\ System Information ~ Processor: x86 Family 6 Model 23 Stepping 10, GenuineIntel ~ Operating System: 32 Bits Boot mode: Normal (Normal boot) Total RAM: 2046 MB (57% free) System Restore: Activé (Enable) System drive C: has 411 GB (88%) free of 466 GB ---\\ Logged in mode ~ Computer Name: COUTURIE-79673E ~ User Name: COUTURIER ~ All Users Names: SUPPORT_388945a0, HelpAssistant, COUTURIER, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Environnement Variables ~ System Unit : C:\ ~ %AppData% : C:\Documents and Settings\COUTURIER\Application Data\ ~ %Desktop% : C:\Documents and Settings\COUTURIER\Bureau\ ~ %Favorites% : C:\Documents and Settings\COUTURIER\Favoris\ ~ %LocalAppData% : C:\Documents and Settings\COUTURIER\Local Settings\Application Data\ ~ %StartMenu% : C:\Documents and Settings\COUTURIER\Menu Démarrer\ ~ %Windir% : C:\WINDOWS\ ~ %System% : C:\WINDOWS\system32\ ---\\ DOS/Devices A:\ Floppy drive, Flash card reader, USB Key (Not Inserted) C:\ Hard drive, Flash drive, Thumb drive (Free 411 Go of 466 Go) D:\ CD-ROM drive (Not Inserted) ---\\ Security Center & Tools Informations [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Security Center: Scanned in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\Explorer.exe [1037824] [MD5.FCDD66EE148885E900285ADE8417E40B] - (.Microsoft Corporation - Internet Extensions for Win32.) (.05/02/2013 - 20:56:42.) -- C:\WINDOWS\system32\wininet.dll [916480] [MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Winlogon.exe [512000] [MD5.1E44BC1E83D8FD2305F8D452DB109CF9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.17/08/2011 - 14:49:54.) -- C:\WINDOWS\system32\Drivers\AFD.sys [138496] [MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.13/04/2008 - 11:40:32.) -- C:\WINDOWS\system32\Drivers\atapi.sys [96512] [MD5.C885B02847F5D2FD45A24E219ED93B32] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Cdfs.sys [63744] [MD5.1F4260CC5B42272D71F79E570A27A4FE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Cdrom.sys [62976] [MD5.31F923EB2170FC172C81ABDA0045D18C] - (.Microsoft Corporation - Pilote de cryptographie FIPS.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Fips.sys [44672] [MD5.573C7D0A32852B48F3058CFD8026F511] - (.Windows (R) Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\HDAudBus.sys [144384] [MD5.A09BDC4ED10E3B2E0EC27BB94AF32516] - (.Microsoft Corporation - Pilote de port i8042.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\i8042prt.sys [54144] [MD5.083A052659F5310DD8B6A6CB05EDCF8E] - (.Microsoft Corporation - IMAPI Kernel Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Imapi.sys [42112] [MD5.CC748EA12C6EFFDE940EE98098BF96BB] - (.Microsoft Corporation - IP Network Address Translator.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\IpNat.sys [152832] [MD5.23C74D75E36E7158768DD63D92789A91] - (.Microsoft Corporation - IPSec Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\IPSec.sys [75264] [MD5.7D304A5EB4344EBEEAB53A2FE3FFB9F0] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.15/07/2011 - 14:29:31.) -- C:\WINDOWS\system32\Drivers\MRxSmb.sys [456320] [MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - (.Microsoft Corporation - MBT Transport driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\netBT.sys [162816] [MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\ntfs.sys [574976] [MD5.8FD0BDBEA875D06CCF6C945CA9ABAF75] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Parport.sys [80384] [MD5.11B4A627BC9614B885C4969BFA5FF8A6] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\Rasl2tp.sys [51328] [MD5.15CABD0F7C00C47C70124907916AF3F1] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.13/04/2008 - 11:32:52.) -- C:\WINDOWS\system32\Drivers\rdpdr.sys [196224] [MD5.D8EB2A7904DB6C916EB5361878DDCBAE] - (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) (.13/04/2008 - 19:57:36.) -- C:\WINDOWS\system32\Drivers\redbook.sys [58752] [MD5.46DE1126684369BACE4849E4FC8C43CA] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.14/04/2008 - 13:00:00.) -- C:\WINDOWS\system32\Drivers\volsnap.sys [53376] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 3/4910 ~ Mes musiques (My Musics) : 1/98 ~ Mes Favoris (My Favorites) : 1/9 ~ Mes Documents (My Documents) : 3/5275 ~ Mon Bureau (My Desktop) : 2/842 ~ Menu demarrer (Programs) : 1/35 ~ Hidden Files: Scanned in 00mn 07s ---\\ Processus lancés [MD5.A03F8B3BF819A1C8C9661A71FE53F09F] - (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) -- C:\WINDOWS\system32\Ati2evxx.exe [573440] [PID.1136] [MD5.C1F19D2BACBEE9AB64D9AE69E9859AC0] - (.Microsoft Corporation - Antimalware Service Executable.) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe [20456] [PID.1372] [MD5.4FE5C6D40664AE07BE5105874357D2ED] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [57008] [PID.236] [MD5.DB5BEA73EDAF19AC68B2C0FAD0F92B1A] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [390504] [PID.380] [MD5.346086A99E6347C11E20D3FCBAEEAB77] - (.Teruten - FsUsbDevice.) -- C:\WINDOWS\system32\FsUsbExService.exe [238952] [PID.472] [MD5.999DB5F88C8E145CCA9D471E33227143] - (.Oracle Corporation - Java(TM) Quick Starter Service.) -- C:\Program Files\Java\jre7\bin\jqs.exe [170912] [PID.708] [MD5.44C5824B3DC3543FB861C73FC5832427] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 285.6.) -- C:\WINDOWS\system32\nvsvc32.exe [298304] [PID.744] [MD5.07C0A803658AAD1A235DC656AF81563D] - (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.exe [16862208] [PID.3472] [MD5.A8E2FA5409EE33B9348B997F83298316] - (.CANON INC. - Canon My Printer.) -- C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1848648] [PID.3524] [MD5.93AD0B78C7357A05F50E594EC7C22300] - (...) -- ystem32\RUNDLL32.exe [0] [PID.3816] [MD5.12916E0642E92561C98B18A2A2D01B14] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe [252848] [PID.3832] [MD5.8E2A7F1F62467A7DCB8AB2C0642F47CA] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [152392] [PID.3844] [MD5.E13EA4860E8F2AA845B53BFD2B6FEC5B] - (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe [1695232] [PID.3880] [MD5.39AF1CDEAFA4FC9D5185FBD9F4D141C4] - (.Octoshape ApS - Main program for Octoshape client.) -- C:\Documents and Settings\COUTURIER\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [107800] [PID.3952] [MD5.E46B17060D3962A384AE484094614788] - (.Apple Inc. - iPodService Module (32-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [553288] [PID.760] [MD5.497F27E279C0F921E2130BB89C1CB5CA] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe [18705664] [PID.360] [MD5.6B4CEA7F9DE3014D714324F8FE9F8E0C] - (.BitTorrent Inc. - µTorrent.) -- C:\Documents and Settings\COUTURIER\Bureau\uTorrent.exe [1037648] [PID.368] [MD5.52936062E7218068BC887DA1230BD21B] - (.Samsung Electronics Co., Ltd. - NPSAgent.) -- C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [95576] [PID.1468] [MD5.A2C1288BD3DEDE03B2327E5972678C2E] - (.McAfee, Inc. - McAfee Security Scanner Scheduler.) -- C:\Program Files\McAfee Security Scan\3.0.285\SSScheduler.exe [271808] [PID.3044] [MD5.D0291BD17EDAB65C4725B0CCF0745F09] - (.Sony Corporation - Media Check Tool.) -- C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [368640] [PID.3084] [MD5.BF2F2717C13A4BD4FD73F2788534E86B] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [917400] [PID.3544] [MD5.854563425495A29FB4B198A6ABEBE06D] - (.Apple Inc. - iTunes.) -- C:\Program Files\iTunes\iTunes.exe [9789256] [PID.3808] [MD5.AA6844A5127ED4B20DF6D313467B929D] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [17304] [PID.4088] [MD5.170D6CA6B5619FADCB25B3C3C12B17C3] - (.Apple Inc. - MobileDeviceHelper.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe [57008] [PID.2060] [MD5.5DBDC85A9AB1C338E82DB4F118C04D6E] - (.Apple Inc. - distnoted.) -- C:\Program Files\Fichiers communs\Apple\Apple Application Support\distnoted.exe [13712] [PID.2268] [MD5.46DA8E7484AC7A52CE1D6E428398724B] - (.Apple Inc. - Apple Push.) -- C:\Program Files\Fichiers communs\Apple\Apple Application Support\APSDaemon.exe [59720] [PID.1520] [MD5.F3069D7809F3C39CDF0EB982C6C45D95] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [6223360] [PID.2012] [MD5.5E9A6658A2A69AE7EB195113B7A2E7A9] - (.Microsoft Corporation - Application Layer Gateway Service.) -- C:\WINDOWS\System32\alg.exe [44544] [PID.1756] ~ Processes Running: Scanned in 00mn 01s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\prefs.js M3 - MFPP: Plugins - [COUTURIER] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml M3 - MFPP: Plugins - [COUTURIER] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml M3 - MFPP: Plugins - [COUTURIER] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml M3 - MFPP: Plugins - [COUTURIER] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml M3 - MFPP: Plugins - [COUTURIER] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml M3 - MFPP: Plugins - [COUTURIER] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml M3 - MFPP: Plugins - [COUTURIER] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll P2 - FPN: [HKLM] [@canon.com/EPPEX] - (.CANON INC. - CANON iMAGE GATEWAY Album Plugin Utility Module.) -- C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.dll P2 - FPN: [HKLM] [@java.com/DTPlugin,version=10.17.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\WINDOWS\system32\npDeployJava1.dll P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=10.17.2] - (.Oracle Corporation - Next Generation Java Plug-in 10.17.2 for Mozilla browsers.) -- C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.0.4] - (.VideoLAN - VLC media player Web Plugin 2.0.2.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.0.5] - (.VideoLAN - VLC media player Web Plugin 2.0.2.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.02.) -- C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll P2 - FPN: [HKCU] [@octoshape.com/Octoshape Streaming Services,version=1.0] - (.Octoshape ApS - Octoshape embedded video plugin.) -- C:\Documents and Settings\COUTURIER\Application Data\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll P2 - FPN: [HKCU] [@Skype Limited.com/Facebook Video Calling Plugin] - (.Skype Limited - Facebook Video Calling Plugin.) -- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll ~ Firefox Browser: Scanned in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Skype Limited - Facebook Video Calling Plugin.) (No version) -- (.not file.) ~ IE Browser: Scanned in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\WINDOWS\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl" ~ Keys: Scanned in 00mn 00s ---\\ Redirection du fichier Hosts (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Hosts File: Scanned in 00mn 00s ~ Nombre de lignes (Lines number): 20 ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre7\bin\jp2ssv.dll ~ BHO: Scanned in 00mn 00s ---\\ Applications démarrées par registre & par dossier (O4) O4 - HKLM\..\Run: [RTHDCPL] . (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.exe O4 - HKLM\..\Run: [Alcmtr] . (.Realtek Semiconductor Corp. - Realtek Azalia Audio - Event Monitor.) -- C:\WINDOWS\ALCMTR.exe O4 - HKLM\..\Run: [GEST] Clé orpheline O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe O4 - HKLM\..\Run: [CanonSolutionMenu] . (.CANON INC. - CNSLMAIN.) -- C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe O4 - HKLM\..\Run: [CanonMyPrinter] . (.CANON INC. - Canon My Printer.) -- C:\Program Files\Canon\MyPrinter\BJMyPrt.exe O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Fichiers communs\Apple\Apple Application Support\APSDaemon.exe O4 - HKLM\..\Run: [NvCplDaemon] . (.NVIDIA Corporation - NVIDIA Display Properties Extension.) -- C:\WINDOWS\system32\NvCpl.dll O4 - HKLM\..\Run: [NvMediaCenter] . (.NVIDIA Corporation - NVIDIA Media Center Library.) -- C:\WINDOWS\system32\NvMcTray.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe O4 - HKLM\..\Run: [NPSStartup] Clé orpheline O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe O4 - HKCU\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe O4 - HKCU\..\Run: [Octoshape Streaming Services] . (.Octoshape ApS - Main program for Octoshape client.) -- C:\Documents and Settings\COUTURIER\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe O4 - HKCU\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Documents and Settings\COUTURIER\Bureau\uTorrent.exe O4 - HKCU\..\Run: [AutoStartNPSAgent] . (.Samsung Electronics Co., Ltd. - NPSAgent.) -- C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe O4 - HKUS\S-1-5-21-606747145-1409082233-682003330-1004\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-21-606747145-1409082233-682003330-1004\..\Run: [MSMSGS] . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe O4 - HKUS\S-1-5-21-606747145-1409082233-682003330-1004\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe O4 - HKUS\S-1-5-21-606747145-1409082233-682003330-1004\..\Run: [Octoshape Streaming Services] . (.Octoshape ApS - Main program for Octoshape client.) -- C:\Documents and Settings\COUTURIER\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe O4 - HKUS\S-1-5-21-606747145-1409082233-682003330-1004\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe O4 - HKUS\S-1-5-21-606747145-1409082233-682003330-1004\..\Run: [uTorrent] . (.BitTorrent Inc. - µTorrent.) -- C:\Documents and Settings\COUTURIER\Bureau\uTorrent.exe O4 - HKUS\S-1-5-21-606747145-1409082233-682003330-1004\..\Run: [AutoStartNPSAgent] . (.Samsung Electronics Co., Ltd. - NPSAgent.) -- C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe ~ Application: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\Programs: Adobe Reader XI.lnk . (...) -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-AB0000000001}\SC_Reader.ico O4 - GS\Programs: Apple Software Update.lnk . (...) -- C:\WINDOWS\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe O4 - GS\Programs: Audacity.lnk . (.The Audacity Team - Audacity®, the Free, Cross-Platform Sound E.) -- C:\Program Files\Audacity\audacity.exe O4 - GS\Programs: Microsoft Security Essentials.lnk . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- C:\Program Files\Microsoft Security Client\msseces.exe O4 - GS\Programs: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O4 - GS\Programs: Windows Messenger.lnk . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe O4 - GS\Programs: Windows Movie Maker.lnk . (.Microsoft Corporation - Windows Movie Maker.) -- C:\Program Files\Movie Maker\moviemk.exe O4 - GS\Programs: Assistance à distance.lnk . (.Microsoft Corporation - Assistance à distance Microsoft.) -- C:\WINDOWS\system32\rcimlby.exe O4 - GS\Programs: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O4 - GS\Programs: Lecteur Windows Media.lnk . (.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe O4 - GS\Programs: Outlook Express.lnk . (.Microsoft Corporation - Outlook Express.) -- C:\Program Files\Outlook Express\msimn.exe ~ Global Startup: Scanned in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -- Clé orpheline O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) ~ Winsock: 4 Legitimates Scanned in 00mn 00s ---\\ Objets ActiveX (Downloaded Program Files)(O16) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} ((no name)) - http://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1354203536703 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} ((no name)) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1354261852781 ~ Objets ActiveX: Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{20C88213-BBF7-4F4E-A16E-B0F32AD049CA}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{20C88213-BBF7-4F4E-A16E-B0F32AD049CA}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{20C88213-BBF7-4F4E-A16E-B0F32AD049CA}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINDOWS\system32\wiascr.dll O18 - Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: AtiExtEvent . (.ATI Technologies Inc. - ATI External Event Utility DLL Module.) -- C:\WINDOWS\system32\Ati2evxx.dll O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\WINDOWS\system32\crypt32.dll O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\WINDOWS\system32\cryptnet.dll O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\WINDOWS\system32\cscdll.dll O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\system32\dimsntfy.dll O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\WINDOWS\system32\sclgntfy.dll O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\WlNotify.dll O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\WINDOWS\system32\wlnotify.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - AppInit_DLLs: . (...) - c:\docume~1\alluse~1\applic~1\browse~1\261040~1.25\{c16c1~1\browse~1.dll (.not file.) ~ AppInit DLL: Scanned in 00mn 00s ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) ~ SSODL: 4 Legitimates Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: NVIDIA Driver Helper Service (NVSvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 285.6.) - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe ~ Services: 8 Legitimates Scanned in 00mn 01s ---\\ Enumération Active Desktop & MHTML Editor (O24) O24 - Desktop General: BackupWallPaper - .(...) - C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop General: WallPaper - .(...) - C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Microsoft\Wallpaper1.bmp ~ Desktop Component: 1 Legitimates Scanned in 00mn 00s ---\\ BootExecute (O34) ~ BEX: 1 Legitimates Scanned in 00mn 00s ---\\ Tâches planifiées en automatique (O39) O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Adobe Flash Player Updater.job [1002] O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AppleSoftwareUpdate.job [284] O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-606747145-1409082233-682003330-1004Core.job [992] O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-606747145-1409082233-682003330-1004UA.job [1014] O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job [400] O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\MpIdleTask.job [366] O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\User_Feed_Synchronization-{AA66391B-2C85-45A7-8B0B-34EA08155D0C}.job [440] ~ Scheduled Task: Scanned in 00mn 00s ---\\ Composants installés (ActiveSetup Installed Components) (O40) O40 - ASIC: Installed Component - S-1-5-21-606747145-1409082233-682003330-1004 - <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} -- Not Hexadécimal CLSID O40 - ASIC: Installed Component - S-1-5-21-606747145-1409082233-682003330-1004 - >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS -- Not Hexadécimal CLSID ~ Active Setup: 18 Legitimates Scanned in 00mn 01s ---\\ Pilotes lancés au démarrage (O41) ~ Drivers: 60 Legitimates Scanned in 00mn 00s ---\\ Logiciels installés (O42) O42 - Logiciel: Adobe Flash Player 11 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin O42 - Logiciel: Adobe Reader XI (11.0.02) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AB0000000001} O42 - Logiciel: Java 7 Update 17 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83217017FF} O42 - Logiciel: McAfee Security Scan Plus - (.McAfee, Inc..) [HKLM] -- McAfee Security Scan O42 - Logiciel: Octoshape Streaming Services - (.Octoshape ApS.) [HKCU] -- Octoshape Streaming Services O42 - Logiciel: Warcraft III: All Products - (...) [HKCU] -- Warcraft III O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKLM] -- uTorrent ~ Logic: 89 Legitimates Scanned in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\BitTorrent] [HKCU\Software\IncrediMail] [HKCU\Software\Octoshape] [HKLM\Software\DEVGURU] [HKLM\Software\IncrediMail] ~ Key Software: 137 Legitimates Scanned in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 19/02/2013 - 12:15:42 - [2,647] ----D C:\Program Files\McAfee Security Scan O43 - CFD: 01/04/2013 - 13:00:52 - [1658,428] ----D C:\Program Files\Warcraft III O43 - CFD: 31/12/2012 - 20:31:06 - [2,753] ----D C:\Documents and Settings\COUTURIER\Application Data\Octoshape O43 - CFD: 01/04/2013 - 13:00:10 - [3,369] ----D C:\Documents and Settings\COUTURIER\Application Data\uTorrent O43 - CFD: 31/12/2012 - 20:31:07 - [0,085] ----D C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Octoshape O43 - CFD: 31/12/2012 - 20:31:06 - [0,005] ----D C:\Documents and Settings\COUTURIER\Menu Démarrer\Programmes\Octoshape Streaming Services O43 - CFD: 24/01/2013 - 21:43:51 - [0,010] ----D C:\Documents and Settings\COUTURIER\Menu Démarrer\Programmes\Warcraft III ~ Program Folder: 115 Legitimates Scanned in 00mn 35s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.51FDB80EA8F00E1DDFB1E5411360093F] - 01/04/2013 - 11:06:34 ---A- . (...) -- C:\WINDOWS\wiadebug.log [159] O44 - LFC:[MD5.594625B47BE1C49FA96E84AF30003A45] - 01/04/2013 - 11:06:33 ---A- . (...) -- C:\WINDOWS\wiaservc.log [50] O44 - LFC:[MD5.E31579CD2E1E7081C7C60E2DE421113F] - 01/04/2013 - 11:04:44 ---A- . (...) -- C:\AdwCleaner[S1].txt [45994] O44 - LFC:[MD5.6E330CB4EA9126157CE7C5C06C7983CA] - 30/03/2013 - 15:56:22 ---A- . (...) -- C:\WINDOWS\system32\nvdrsdb0.bin [285176] O44 - LFC:[MD5.08CC8B856F33C99B7C1C0103403869BB] - 30/03/2013 - 15:56:22 ---A- . (...) -- C:\WINDOWS\system32\nvdrsdb1.bin [285176] O44 - LFC:[MD5.55A54008AD1BA589AA210D2629C1DF41] - 30/03/2013 - 15:56:22 ---A- . (...) -- C:\WINDOWS\system32\nvdrssel.bin [1] O44 - LFC:[MD5.F3415B56A338252C68DF72FCC23ECAD1] - 25/03/2013 - 16:50:30 ---A- . (...) -- C:\WINDOWS\msxml4-KB973688-enu.LOG [314772] O44 - LFC:[MD5.2CF9C2F21B6393AFECF821F26AFCE36D] - 24/03/2013 - 15:56:38 ---A- . (...) -- C:\WINDOWS\msxml4-KB954430-enu.LOG [315958] O44 - LFC:[MD5.3F0164FBC0BD1ADBD02DF9759181451A] - 23/03/2013 - 11:30:10 ---A- . (.MCCI - SAMSUNG USB Mobile Device.) -- C:\WINDOWS\system32\Drivers\ss_bbus.sys [98432] O44 - LFC:[MD5.F9F4BC8A7EC80F39DE8323D0D1BC85FE] - 23/03/2013 - 11:30:10 ---A- . (.MCCI Corporation - SAMSUNG USB Mobile Device (Windows 2000/XP.) -- C:\WINDOWS\system32\Drivers\ss_bwh.sys [12288] O44 - LFC:[MD5.F9F4BC8A7EC80F39DE8323D0D1BC85FE] - 23/03/2013 - 11:30:10 ---A- . (.MCCI Corporation - SAMSUNG USB Mobile Device (Windows 2000/XP.) -- C:\WINDOWS\system32\Drivers\ss_bwhnt.sys [12288] O44 - LFC:[MD5.B89D62206034E5FE573C80A24DD55675] - 23/03/2013 - 11:30:10 ---A- . (.MCCI Corporation - SAMSUNG USB Mobile Modem Filter.) -- C:\WINDOWS\system32\Drivers\ss_bmdfl.sys [14848] O44 - LFC:[MD5.1ED0FCEA586FE2A416EE15196E5631DD] - 23/03/2013 - 11:30:10 ---A- . (.MCCI Corporation - SAMSUNG USB Mobile Modem.) -- C:\WINDOWS\system32\Drivers\ss_bmdm.sys [123648] O44 - LFC:[MD5.2DD4E8844F8F094659DD695A80FED36E] - 23/03/2013 - 11:30:10 ---A- . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\WINDOWS\system32\Drivers\ss_bcm.sys [12416] O44 - LFC:[MD5.2DD4E8844F8F094659DD695A80FED36E] - 23/03/2013 - 11:30:10 ---A- . (.MCCI Corporation - Windows 2000/XP support functions.) -- C:\WINDOWS\system32\Drivers\ss_bcmnt.sys [12416] O44 - LFC:[MD5.80A5A11D5DE10D96793AE8D25F8E97DF] - 23/03/2013 - 11:23:47 ---A- . (...) -- C:\aqua_bitmap.cpp [2898] O44 - LFC:[MD5.A0EE3744C64ABD5A92587606D0BF9052] - 23/03/2013 - 11:23:22 ---A- . (...) -- C:\WINDOWS\system32\AitVCSetup.log [1334] O44 - LFC:[MD5.48C949A2F4A54F082E882CFD16DC047A] - 23/03/2013 - 11:23:14 ---A- . (.Nokia - Wireless Communication Device Class Install.) -- C:\WINDOWS\system32\nmwcdcls.dll [90624] O44 - LFC:[MD5.D5322DC5F12A22724FAC635EDD3912F0] - 23/03/2013 - 11:23:10 ---A- . (...) -- C:\WINDOWS\DPINST.LOG [17720] O44 - LFC:[MD5.175CC28DCF819F78CAA3FBD44AD9E52A] - 23/03/2013 - 11:23:10 ---A- . (.Nokia - PCCS Mode Change Filter Driver.) -- C:\WINDOWS\system32\Drivers\pccsmcfd.sys [21632] O44 - LFC:[MD5.C83C84DAE3B901BF404D36F304B00FA0] - 23/03/2013 - 11:22:28 ---A- . (.Pas de propriétaire - EjectDisk DLL.) -- C:\WINDOWS\system32\FsUsbExDevice.Dll [110592] O44 - LFC:[MD5.346086A99E6347C11E20D3FCBAEEAB77] - 23/03/2013 - 11:22:28 ---A- . (.Teruten - FsUsbDevice.) -- C:\WINDOWS\system32\FsUsbExService.Exe [238952] O44 - LFC:[MD5.5F5DA8398F16B8134203568FC5C3ADFF] - 23/03/2013 - 11:22:08 ---A- . (...) -- C:\WINDOWS\wmsetup.log [27854] O44 - LFC:[MD5.DC17DD0189B0C36D863B4DD0A036C10F] - 23/03/2013 - 11:22:07 ---A- . (...) -- C:\WINDOWS\WMSysPr9.prx [316640] O44 - LFC:[MD5.63A12E1EB8469AEB5E4AC991610F6AC2] - 15/03/2013 - 05:48:30 ---A- . (...) -- C:\WINDOWS\FaxSetup.log [909269] O44 - LFC:[MD5.9D52A877A9F5A28456A6FF7DFAD8E10E] - 15/03/2013 - 05:48:30 ---A- . (...) -- C:\WINDOWS\comsetup.log [310989] O44 - LFC:[MD5.6B98D32FA157D060DE562E296E06E405] - 15/03/2013 - 05:48:30 ---A- . (...) -- C:\WINDOWS\iis6.log [144463] O44 - LFC:[MD5.5B52E93148CC68A0AAC6C2E4AD50419B] - 15/03/2013 - 05:48:30 ---A- . (...) -- C:\WINDOWS\imsins.log [1374] O44 - LFC:[MD5.BA274BAAD60A7C917C9513FAC224DCE6] - 15/03/2013 - 05:48:30 ---A- . (...) -- C:\WINDOWS\msgsocm.log [46016] O44 - LFC:[MD5.82A240ED886D4112D690A9B04286960C] - 15/03/2013 - 05:48:30 ---A- . (...) -- C:\WINDOWS\ntdtcsetup.log [187013] O44 - LFC:[MD5.9D92C7CF55C01FE2EDE87C70A9FAE972] - 15/03/2013 - 05:48:30 ---A- . (...) -- C:\WINDOWS\ocgen.log [448971] O44 - LFC:[MD5.C957BC3AE6A50AA6174A2DDC1BAE539B] - 15/03/2013 - 05:48:30 ---A- . (...) -- C:\WINDOWS\ocmsn.log [50729] O44 - LFC:[MD5.523A2C57877D55541DAF17A04030C787] - 15/03/2013 - 05:48:30 ---A- . (...) -- C:\WINDOWS\tsoc.log [354197] O44 - LFC:[MD5.973EB2A74ACD81CEC83D44B6CAFA339C] - 14/03/2013 - 05:14:56 ---A- . (...) -- C:\WINDOWS\imsins.BAK [1374] O44 - LFC:[MD5.9BF60D3607131874B8ED5986973FE14E] - 14/03/2013 - 05:14:48 ---A- . (...) -- C:\WINDOWS\updspapi.log [80685] O44 - LFC:[MD5.255D5F7F3337E691C34B845679D11FF5] - 04/03/2013 - 10:00:56 ---A- . (...) -- C:\WINDOWS\system32\dmwu.exe [1052976] O44 - LFC:[MD5.C8C4D71AAEA301BBF555717F5A200239] - 04/03/2013 - 09:58:40 ---A- . (...) -- C:\WINDOWS\system32\ImHttpComm.dll [28160] O44 - LFC:[MD5.188E68005ED62F32248032C65CB4DE96] - 04/03/2013 - 09:07:24 ---A- . (...) -- C:\WINDOWS\system32\Microsoft.VC80.CRT.manifest [1870] O44 - LFC:[MD5.CBE5F69A5E5B918225F420BA748F3742] - 14/06/2010 - 01:32:54 ---A- . (...) -- C:\WINDOWS\system32\FsUsbExDisk.Sys [36608] ~ Files: 65 Legitimates Scanned in 01mn 16s ---\\ Derniers fichiers créés dans Windows Prefetcher (O45) O45 - LFCP:[MD5.E9B834A868A49F5B24E704891208DD8F] - 01/04/2013 - 09:03:30 ---A- - C:\WINDOWS\Prefetch\UPDATE_CHECKER.EXE-24C31ACB.pf O45 - LFCP:[MD5.528BE9F7C7FDC73BDD27B38E900318A7] - 01/04/2013 - 09:03:35 ---A- - C:\WINDOWS\Prefetch\REBATE~1.EXE-315FD07D.pf O45 - LFCP:[MD5.0E85F1918C790B0253B0F4A0F4FEFAB4] - 01/04/2013 - 09:03:35 ---A- - C:\WINDOWS\Prefetch\WMIAPSRV.EXE-1E2270A5.pf O45 - LFCP:[MD5.39B13D7A9D8CEB205EB4934FD8E49326] - 01/04/2013 - 09:24:27 ---A- - C:\WINDOWS\Prefetch\SIMPRESS.EXE-00EA51E6.pf O45 - LFCP:[MD5.3C7D0A3F1F81AC55AFD41B501DC07AD6] - 01/04/2013 - 09:38:20 ---A- - C:\WINDOWS\Prefetch\CRASHREPORTER.EXE-29951F6F.pf O45 - LFCP:[MD5.065066FE15AC20A29FF93866DB550902] - 01/04/2013 - 09:49:05 ---A- - C:\WINDOWS\Prefetch\SOFFICE.BIN-04056A25.pf O45 - LFCP:[MD5.0D6A1ECC2E51518FD35F3D7E40FAEE8F] - 01/04/2013 - 09:49:15 ---A- - C:\WINDOWS\Prefetch\SOFFICE.EXE-03EA2B02.pf O45 - LFCP:[MD5.D701A7E2C41E2742B21E68FB320DBDDF] - 01/04/2013 - 09:49:15 ---A- - C:\WINDOWS\Prefetch\SWRITER.EXE-00CDC7C1.pf O45 - LFCP:[MD5.638E81B0734E5B09B30F7C7EBC0F9D56] - 01/04/2013 - 10:52:03 ---A- - C:\WINDOWS\Prefetch\SPUDCFIMPORTER.EXE-26A9408A.pf O45 - LFCP:[MD5.B5B27E51A404715299A39012742795FB] - 01/04/2013 - 11:02:54 ---A- - C:\WINDOWS\Prefetch\WRTC.EXE-0AF668BC.pf O45 - LFCP:[MD5.2CE9BC7371325FD4B743996B3DE791B7] - 01/04/2013 - 11:08:23 ---A- - C:\WINDOWS\Prefetch\CNSLMAIN.EXE-18EDD5BC.pf O45 - LFCP:[MD5.1EE046F9DDFCD3A3BFEE980D4597BFFB] - 01/04/2013 - 11:08:34 ---A- - C:\WINDOWS\Prefetch\BJMYPRT.EXE-18781E4F.pf O45 - LFCP:[MD5.7E9A793CC841448D46F9FC6A2149B2F9] - 01/04/2013 - 11:08:34 ---A- - C:\WINDOWS\Prefetch\MSSECES.EXE-14257906.pf O45 - LFCP:[MD5.09C3AEF9E90692C8A9CCCF68A034F0C4] - 01/04/2013 - 11:08:36 ---A- - C:\WINDOWS\Prefetch\OCTOSHAPECLIENT.EXE-35C9EAD8.pf O45 - LFCP:[MD5.56B9470E71E324B70A8E891B5CFDD0B9] - 01/04/2013 - 11:08:45 ---A- - C:\WINDOWS\Prefetch\SSSCHEDULER.EXE-064281F2.pf O45 - LFCP:[MD5.58D4E26D5A690E00AD900D4F4509E42C] - 01/04/2013 - 11:08:46 ---A- - C:\WINDOWS\Prefetch\SPUVOLUMEWATCHER.EXE-1D8656A0.pf O45 - LFCP:[MD5.5529D79B4DCEEF899237AD0DFC4D2D81] - 01/04/2013 - 11:09:37 ---A- - C:\WINDOWS\Prefetch\DISTNOTED.EXE-0645EB3C.pf O45 - LFCP:[MD5.812E69BCA0ECC182BC2DB060116BD6BA] - 01/04/2013 - 11:25:47 ---A- - C:\WINDOWS\Prefetch\TEEWORLDS_PACK.EXE-33527CDE.pf O45 - LFCP:[MD5.EDA625D1953C333890F777976A988F92] - 01/04/2013 - 11:36:08 ---A- - C:\WINDOWS\Prefetch\WAR3.EXE-1A47B30C.pf O45 - LFCP:[MD5.E099AC70A9544BA9301FE6DD40DF456A] - 01/04/2013 - 11:36:09 ---A- - C:\WINDOWS\Prefetch\FROZEN THRONE.EXE-1468083C.pf O45 - LFCP:[MD5.0C48BE1824C040685047CADCBD34CBD3] - 28/03/2013 - 22:10:45 ---A- - C:\WINDOWS\Prefetch\SDRAW.EXE-33738E71.pf O45 - LFCP:[MD5.6A3FF9238D872407752979D2DE832EAD] - 29/03/2013 - 12:12:49 ---A- - C:\WINDOWS\Prefetch\ALG.EXE-0F138680.pf O45 - LFCP:[MD5.6DF36F3D56479109A392D54F55EAED1B] - 30/03/2013 - 14:56:53 ---A- - C:\WINDOWS\Prefetch\DEMO32.EXE-256B94FD.pf O45 - LFCP:[MD5.4E01108F0C8784C8AC7BB00CE9869FB1] - 30/03/2013 - 15:11:03 ---A- - C:\WINDOWS\Prefetch\RUNONCE.EXE-2803F297.pf O45 - LFCP:[MD5.8771DD1BC33850B15A6D0DBBF7ABF1FE] - 30/03/2013 - 15:15:59 ---A- - C:\WINDOWS\Prefetch\HELPCTR.EXE-3862B6F5.pf O45 - LFCP:[MD5.6232A89DD9F61C2259293350DAD0A166] - 30/03/2013 - 15:16:01 ---A- - C:\WINDOWS\Prefetch\HELPSVC.EXE-2878DDA2.pf O45 - LFCP:[MD5.28B3C3F03B0930EC6D7C8846AA868A48] - 30/03/2013 - 15:16:02 ---A- - C:\WINDOWS\Prefetch\HELPHOST.EXE-247D2792.pf O45 - LFCP:[MD5.5B5CD36BDC74877F7F61D64A710E433C] - 30/03/2013 - 15:23:09 ---A- - C:\WINDOWS\Prefetch\NVCPLUI.EXE-29E783D7.pf O45 - LFCP:[MD5.17C12D2AA80B38C50920DBC307B5E77F] - 30/03/2013 - 15:49:27 ---A- - C:\WINDOWS\Prefetch\NVCOLOR.EXE-0F67EC09.pf O45 - LFCP:[MD5.91FD8F7E43C7FB71F04871A2B7D3F8BD] - 30/03/2013 - 16:14:13 ---A- - C:\WINDOWS\Prefetch\SNDVOL32.EXE-383480B7.pf O45 - LFCP:[MD5.2CA0A651A2888F2CECBCE3D7415FBCD5] - 30/03/2013 - 16:42:02 ---A- - C:\WINDOWS\Prefetch\DUMPREP.EXE-1B46F901.pf O45 - LFCP:[MD5.D2FDAA3BFB0CF1A57EDE7B6808CD0E76] - 30/03/2013 - 16:42:11 ---A- - C:\WINDOWS\Prefetch\DWWIN.EXE-30875ADC.pf O45 - LFCP:[MD5.C6BB995E131BA85FBC87D5E1CDC82941] - 30/03/2013 - 16:44:18 ---A- - C:\WINDOWS\Prefetch\LADS.EXE-06335087.pf O45 - LFCP:[MD5.21C9B8FE0AD92992E4E7B778E0C49087] - 30/03/2013 - 16:45:23 ---A- - C:\WINDOWS\Prefetch\MBR.EXE-313604BE.pf O45 - LFCP:[MD5.6852FFC4E258AD309AC5C0577D2F9BE4] - 30/03/2013 - 16:49:50 ---A- - C:\WINDOWS\Prefetch\NSLOOKUP.EXE-160B1221.pf O45 - LFCP:[MD5.4A870EF746BC0629A3E01F16B4E18225] - 30/03/2013 - 19:52:39 ---A- - C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf O45 - LFCP:[MD5.C5953A7622BFDC2764CFE66C1494EDDA] - 31/03/2013 - 18:40:10 ---A- - C:\WINDOWS\Prefetch\BROWSERPROTECT.EXE-0D00CCBD.pf O45 - LFCP:[MD5.E84DBE106BB55A9D50D5BAB3BACA041A] - 31/03/2013 - 18:40:22 ---A- - C:\WINDOWS\Prefetch\UTORRENT.EXE-039D91B8.pf O45 - LFCP:[MD5.0BFDF1DC738BE9F3B8749BEEB8F3BC5D] - 31/03/2013 - 19:08:09 ---A- - C:\WINDOWS\Prefetch\CNMSE9I.EXE-0FB60A0D.pf O45 - LFCP:[MD5.557E7206CE5CC9DFBBEA11B65DEFC15B] - 31/03/2013 - 19:41:54 ---A- - C:\WINDOWS\Prefetch\SSMYPICS.SCR-01C62024.pf ~ Prefetcher: 126 Legitimates Scanned in 00mn 01s ---\\ Opérations et fonctions au démarrage de Windows Explorer (O46) O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll ~ ShellExecuteHooks: Scanned in 00mn 00s ---\\ Export de clé d'application autorisée (O47) O47 - AAKE:Key Export SP - "C:\Program Files\Bonjour\mDNSResponder.exe" [Enabled] .(.Apple Inc..) -- C:\Program Files\Bonjour\mDNSResponder.exe O47 - AAKE:Key Export SP - "C:\WINDOWS\system32\dmwu.exe" [Enabled] .(.Pas de propriétaire.) -- C:\WINDOWS\system32\dmwu.exe O47 - AAKE:Key Export SP - "C:\WINDOWS\system32\ARFC\wrtc.exe" [Enabled] .(.Pas de propriétaire.) -- C:\WINDOWS\system32\ARFC\wrtc.exe O47 - AAKE:Key Export SP - "C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe" [Enabled] .(.Skype Limited.) -- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe O47 - AAKE:Key Export SP - "C:\Documents and Settings\COUTURIER\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [Enabled] .(.Octoshape ApS.) -- C:\Documents and Settings\COUTURIER\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe O47 - AAKE:Key Export SP - "C:\Documents and Settings\COUTURIER\Application Data\uTorrent\uTorrent.exe" [Enabled] .(.BitTorrent Inc..) -- C:\Documents and Settings\COUTURIER\Application Data\uTorrent\uTorrent.exe O47 - AAKE:Key Export SP - "C:\Documents and Settings\COUTURIER\Mes documents\Téléchargements\uTorrent.exe" [Enabled] .(...) -- C:\Documents and Settings\COUTURIER\Mes documents\Téléchargements\uTorrent.exe (.not file.) O47 - AAKE:Key Export SP - "C:\Documents and Settings\COUTURIER\Bureau\uTorrent.exe" [Enabled] .(.BitTorrent Inc..) -- C:\Documents and Settings\COUTURIER\Bureau\uTorrent.exe O47 - AAKE:Key Export SP - "C:\Program Files\iTunes\iTunes.exe" [Enabled] .(.Apple Inc..) -- C:\Program Files\iTunes\iTunes.exe ~ Keys Export: 17 Legitimates Scanned in 00mn 02s ---\\ Déni du service (Local Security Authority) (O48) ~ LSA: 6 Legitimates Scanned in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) ~ CBS: 21 Legitimates Scanned in 00mn 00s ---\\ Image File Execution Options (IFEO) (O50) O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - ntsd -d ~ IFEO: Scanned in 00mn 00s ---\\ Trojan Driver Search Data (HKLM) (O52) ~ TDSD: 12 Legitimates Scanned in 00mn 00s ---\\ Microsoft Control Security Providers (O54) ~ MSCP: 6 Legitimates Scanned in 00mn 00s ---\\ Microsoft Windows Policies System (O55) ~ MWPS: 5 Legitimates Scanned in 00mn 00s ---\\ Microsoft Windows Policies Explorer (O56) O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145 ~ Keys: Scanned in 00mn 00s ---\\ Liste des Drivers Système (O58) O58 - SDL:[MD5.7E682D97868CEFAE5D2BBD23EBBF7207] - 01/08/2008 - 07:38:20 ---A- . (.ATI Technologies Inc. - ATI Radeon WindowsNT Miniport Driver.) -- C:\WINDOWS\system32\Drivers\ati2mtag.sys [3266560] O58 - SDL:[MD5.6D3ADA4CE95CECA7BCE527A08C4C474E] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ansi.sys [9037] ~ Drivers: Scanned in 00mn 00s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 01/04/2013 - 09:02:56 -S-A- C:\Documents and Settings\COUTURIER\Application Data\Microsoft\Crypto\RSA\S-1-5-21-606747145-1409082233-682003330-1004\b155648df976b328472a19d42510dcab_f590c4b2-cf37-4bfe-8b94-7110679d7ff3 [1305] O61 - LFC: 01/04/2013 - 09:03:52 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\8dd3e550-e344-4a2d-aec8-53e2916e8690.dmp [21807] O61 - LFC: 01/04/2013 - 09:03:52 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\8dd3e550-e344-4a2d-aec8-53e2916e8690.extra [2733] O61 - LFC: 01/04/2013 - 09:05:21 ---A- C:\Documents and Settings\COUTURIER\Application Data\LibreOffice\3\user\gallery\serenite_When The Waves Dance.wav [263220] O61 - LFC: 01/04/2013 - 09:05:21 ---A- C:\Documents and Settings\COUTURIER\Application Data\LibreOffice\3\user\gallery\sg30.sdg [920] O61 - LFC: 01/04/2013 - 09:05:21 ---A- C:\Documents and Settings\COUTURIER\Application Data\LibreOffice\3\user\gallery\sg30.sdv [2048] O61 - LFC: 01/04/2013 - 09:05:21 ---A- C:\Documents and Settings\COUTURIER\Application Data\LibreOffice\3\user\gallery\sg30.thm [741] O61 - LFC: 01/04/2013 - 09:09:55 ---A- C:\Documents and Settings\COUTURIER\Mes documents\SAM_0508.JPG [2379360] O61 - LFC: 01/04/2013 - 09:09:55 ---A- C:\Documents and Settings\COUTURIER\Mes documents\Téléchargements\SAM_0508.JPG [2379360] O61 - LFC: 01/04/2013 - 09:10:58 ---A- C:\Documents and Settings\COUTURIER\Recent\SAM_0508.lnk [1148] O61 - LFC: 01/04/2013 - 09:11:24 ---A- C:\Documents and Settings\COUTURIER\Mes documents\Téléchargements\SAM_0512.JPG [2233971] O61 - LFC: 01/04/2013 - 09:11:24 ---A- C:\Documents and Settings\COUTURIER\Recent\Téléchargements.lnk [472] O61 - LFC: 01/04/2013 - 09:12:15 ---A- C:\Documents and Settings\COUTURIER\Recent\Mars 2013 Marseille-Lyon.lnk [895] O61 - LFC: 01/04/2013 - 09:12:15 ---A- C:\Documents and Settings\COUTURIER\Recent\SAM_0512.lnk [1148] O61 - LFC: 01/04/2013 - 09:38:15 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\LastCrash [10] O61 - LFC: 01/04/2013 - 09:38:15 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\cert8.db [229376] O61 - LFC: 01/04/2013 - 09:38:49 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\8fce3ade-d0b8-4859-b1ed-98a9ae993ecf.dmp [21807] O61 - LFC: 01/04/2013 - 09:38:50 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\8fce3ade-d0b8-4859-b1ed-98a9ae993ecf.extra [2733] O61 - LFC: 01/04/2013 - 09:42:28 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\addons.sqlite [524288] O61 - LFC: 01/04/2013 - 09:42:28 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\addons.sqlite-journal [295496] O61 - LFC: 01/04/2013 - 09:49:15 ---A- C:\Documents and Settings\COUTURIER\Application Data\LibreOffice\3\user\basic\dialog.xlc [406] O61 - LFC: 01/04/2013 - 09:49:15 ---A- C:\Documents and Settings\COUTURIER\Application Data\LibreOffice\3\user\basic\script.xlc [406] O61 - LFC: 01/04/2013 - 09:49:15 ---A- C:\Documents and Settings\COUTURIER\Application Data\LibreOffice\3\user\extensions\shared\log.txt [10547] O61 - LFC: 01/04/2013 - 09:49:15 ---A- C:\Documents and Settings\COUTURIER\Application Data\LibreOffice\3\user\registrymodifications.xcu [332554] O61 - LFC: 01/04/2013 - 09:49:15 ---A- C:\Documents and Settings\COUTURIER\Application Data\LibreOffice\3\user\uno_packages\cache\log.txt [25728] O61 - LFC: 01/04/2013 - 10:05:56 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\mimeTypes.rdf [9420] O61 - LFC: 01/04/2013 - 10:19:41 ---A- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\Temp\tmp-1364807981000-0.cache [79917] O61 - LFC: 01/04/2013 - 10:53:08 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\c6184dad-58d4-43e9-8caf-a98851b4330f.dmp [21807] O61 - LFC: 01/04/2013 - 10:53:08 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\c6184dad-58d4-43e9-8caf-a98851b4330f.extra [2733] O61 - LFC: 01/04/2013 - 11:02:38 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\formhistory.sqlite [327680] O61 - LFC: 01/04/2013 - 11:03:59 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\sessionstore.bak [67830] O61 - LFC: 01/04/2013 - 11:04:06 ---A- C:\Documents and Settings\COUTURIER\Mes documents\Téléchargements\AdwCleaner.exe [609993] O61 - LFC: 01/04/2013 - 11:04:09 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\localstore.rdf [8847] O61 - LFC: 01/04/2013 - 11:04:32 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\content-prefs.sqlite [229376] O61 - LFC: 01/04/2013 - 11:04:32 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\cookies.sqlite-wal [754248] O61 - LFC: 01/04/2013 - 11:04:32 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\permissions.sqlite [65536] O61 - LFC: 01/04/2013 - 11:08:13 -SHA- C:\Documents and Settings\COUTURIER\IETldCache\index.dat [262144] O61 - LFC: 01/04/2013 - 11:08:32 -S-A- C:\Documents and Settings\COUTURIER\Application Data\Microsoft\Crypto\RSA\S-1-5-21-606747145-1409082233-682003330-1004\fef293c15d4ba71e400a66c56c07e96a_f590c4b2-cf37-4bfe-8b94-7110679d7ff3 [1305] O61 - LFC: 01/04/2013 - 11:08:33 ---A- C:\Documents and Settings\COUTURIER\Application Data\uTorrent\settings.dat.old [33104] O61 - LFC: 01/04/2013 - 11:09:09 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\extensions.sqlite [458752] O61 - LFC: 01/04/2013 - 11:09:09 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\extensions.sqlite-journal [328272] O61 - LFC: 01/04/2013 - 11:09:09 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\places.sqlite-shm [32768] O61 - LFC: 01/04/2013 - 11:09:10 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\webapps\webapps.json [2] O61 - LFC: 01/04/2013 - 11:09:11 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\cookies.sqlite-shm [32768] O61 - LFC: 01/04/2013 - 11:09:11 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\pluginreg.dat [8018] O61 - LFC: 01/04/2013 - 11:09:11 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\search.json [10820] O61 - LFC: 01/04/2013 - 11:09:13 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\urlclassifierkey3.txt [154] O61 - LFC: 01/04/2013 - 11:09:39 ---A- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\Temp\tmp-index.cache [8908] O61 - LFC: 01/04/2013 - 11:09:41 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\prefs.js [7179] O61 - LFC: 01/04/2013 - 11:13:13 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\blocklist.xml [58746] O61 - LFC: 01/04/2013 - 11:22:09 ---A- C:\Documents and Settings\COUTURIER\Recent\blackangel.lnk [1293] O61 - LFC: 01/04/2013 - 11:22:10 ---A- C:\Documents and Settings\COUTURIER\Application Data\teeworlds-b122-r50edfd37-win32\data\skins\blackangel.png [14057] O61 - LFC: 01/04/2013 - 11:22:24 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\downloads.sqlite [262144] O61 - LFC: 01/04/2013 - 11:22:24 ---A- C:\Documents and Settings\COUTURIER\Application Data\teeworlds-b122-r50edfd37-win32\data\skins\deadninja.png [9934] O61 - LFC: 01/04/2013 - 11:22:24 ---A- C:\Documents and Settings\COUTURIER\Recent\deadninja.lnk [1288] O61 - LFC: 01/04/2013 - 11:22:24 ---A- C:\Documents and Settings\COUTURIER\Recent\skins.lnk [978] O61 - LFC: 01/04/2013 - 11:23:24 ---A- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\startupCache\startupCache.4.little [1012888] O61 - LFC: 01/04/2013 - 11:24:15 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\webappsstore.sqlite [1867776] O61 - LFC: 01/04/2013 - 11:25:42 ---A- C:\Documents and Settings\COUTURIER\Application Data\Teeworlds\masters.cfg [144] O61 - LFC: 01/04/2013 - 11:35:49 ---A- C:\Documents and Settings\COUTURIER\Application Data\Teeworlds\settings.cfg [6941] O61 - LFC: 01/04/2013 - 11:38:32 ---A- C:\Documents and Settings\COUTURIER\Application Data\uTorrent\settings.dat [33184] O61 - LFC: 01/04/2013 - 11:55:04 ---A- C:\Documents and Settings\COUTURIER\Application Data\uTorrent\resume.dat.old [27013] O61 - LFC: 01/04/2013 - 11:57:55 ---A- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Microsoft\Feeds\FeedsStore.feedsdb-ms [6144] O61 - LFC: 01/04/2013 - 11:57:55 ---A- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\Sites suggérés d’Internet Explorer~.feed-ms [28672] O61 - LFC: 01/04/2013 - 11:57:55 -SHA- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat [32768] O61 - LFC: 01/04/2013 - 12:00:10 ---A- C:\Documents and Settings\COUTURIER\Application Data\uTorrent\dht_feed.dat.old [2] O61 - LFC: 01/04/2013 - 12:01:18 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\places.sqlite [10485760] O61 - LFC: 01/04/2013 - 12:01:19 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\cookies.sqlite [2621440] O61 - LFC: 01/04/2013 - 12:01:23 ---A- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\_CACHE_CLEAN_ [1] O61 - LFC: 01/04/2013 - 12:01:29 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\sessionstore.js [423378] O61 - LFC: 01/04/2013 - 12:03:13 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\places.sqlite-wal [360744] O61 - LFC: 01/04/2013 - 12:05:04 ---A- C:\Documents and Settings\COUTURIER\Application Data\uTorrent\resume.dat [27013] O61 - LFC: 01/04/2013 - 12:05:11 ---A- C:\Documents and Settings\COUTURIER\Application Data\uTorrent\dht_feed.dat [2] O61 - LFC: 29/03/2013 - 12:12:21 -S-A- C:\Documents and Settings\COUTURIER\Application Data\Microsoft\Crypto\RSA\S-1-5-21-606747145-1409082233-682003330-1004\a916d864a909d691a1d95611fadc935c_f590c4b2-cf37-4bfe-8b94-7110679d7ff3 [1305] O61 - LFC: 29/03/2013 - 12:14:59 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\e79968c1-2c1b-4635-91ce-6284787967df.dmp [21807] O61 - LFC: 29/03/2013 - 12:14:59 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\e79968c1-2c1b-4635-91ce-6284787967df.extra [2733] O61 - LFC: 29/03/2013 - 12:18:58 ---A- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\shortcutCache\y0H09IPd5rPzA7OalHrzDg==.ico [4286] O61 - LFC: 29/03/2013 - 12:20:29 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\bookmarkbackups\bookmarks-2013-03-29.json [20554] O61 - LFC: 29/03/2013 - 12:21:46 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\879038b2-4044-4697-977e-853ff7a3225a.dmp [21807] O61 - LFC: 29/03/2013 - 12:21:46 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\879038b2-4044-4697-977e-853ff7a3225a.extra [2733] O61 - LFC: 29/03/2013 - 13:03:09 ---A- C:\Documents and Settings\COUTURIER\Recent\thym-linalol.lnk [734] O61 - LFC: 29/03/2013 - 13:03:17 ---A- C:\Documents and Settings\COUTURIER\Recent\Sapin baumier.lnk [739] O61 - LFC: 29/03/2013 - 13:03:32 ---A- C:\Documents and Settings\COUTURIER\Recent\Orange.lnk [702] O61 - LFC: 29/03/2013 - 13:03:42 ---A- C:\Documents and Settings\COUTURIER\Recent\Niaouli.lnk [707] O61 - LFC: 29/03/2013 - 13:03:54 ---A- C:\Documents and Settings\COUTURIER\Recent\citron2.lnk [707] O61 - LFC: 29/03/2013 - 13:04:13 ---A- C:\Documents and Settings\COUTURIER\Recent\Lavande fine.lnk [734] O61 - LFC: 29/03/2013 - 13:35:21 ---A- C:\Documents and Settings\COUTURIER\Recent\Précautions.lnk [576] O61 - LFC: 29/03/2013 - 16:25:16 ---A- C:\Documents and Settings\COUTURIER\Recent\Ajout HE (Philippe)-1.lnk [631] O61 - LFC: 29/03/2013 - 16:26:02 ---A- C:\Documents and Settings\COUTURIER\Recent\Précautions emploi HE.lnk [631] O61 - LFC: 29/03/2013 - 16:26:44 ---A- C:\Documents and Settings\COUTURIER\Recent\Démarrer he.lnk [581] O61 - LFC: 29/03/2013 - 16:57:16 ---A- C:\Documents and Settings\COUTURIER\Mes documents\Téléchargements\Ajout HE (Philippe).odt [23768] O61 - LFC: 29/03/2013 - 16:58:28 ---A- C:\Documents and Settings\COUTURIER\Recent\Ajout HE (Philippe).lnk [774] O61 - LFC: 29/03/2013 - 17:17:03 ---A- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Sun\Java\Deployment\SystemCache\6.0\32\6c34baa0-726a6b4b.idx [462] O61 - LFC: 29/03/2013 - 17:30:26 ---A- C:\Documents and Settings\COUTURIER\Mes documents\Sans nom 1.odt [11217] O61 - LFC: 29/03/2013 - 17:30:56 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\3f0b4c3b-b5a1-45d5-b16f-255f66315f86.dmp [21807] O61 - LFC: 29/03/2013 - 17:30:56 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\3f0b4c3b-b5a1-45d5-b16f-255f66315f86.extra [2733] O61 - LFC: 29/03/2013 - 20:11:10 ---A- C:\Documents and Settings\COUTURIER\Recent\Cours sur le pouls (PLS-S-129).lnk [367] O61 - LFC: 29/03/2013 - 20:11:10 ---A- C:\Documents and Settings\COUTURIER\Recent\Lecteur CD (3).lnk [191] O61 - LFC: 29/03/2013 - 21:45:34 ---A- C:\Documents and Settings\COUTURIER\Recent\graha.lnk [549] O61 - LFC: 29/03/2013 - 21:46:21 ---A- C:\Documents and Settings\COUTURIER\Mes documents\graha.docx [4914] O61 - LFC: 29/03/2013 - 21:46:53 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\03ec195f-f77d-4ca3-a6a9-810937540ccc.dmp [21807] O61 - LFC: 29/03/2013 - 21:46:53 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\03ec195f-f77d-4ca3-a6a9-810937540ccc.extra [2733] O61 - LFC: 30/03/2013 - 09:59:04 -S-A- C:\Documents and Settings\COUTURIER\Application Data\Microsoft\Crypto\RSA\S-1-5-21-606747145-1409082233-682003330-1004\29a305aa7605612bbfeb0c4a41f64ffe_f590c4b2-cf37-4bfe-8b94-7110679d7ff3 [1305] O61 - LFC: 30/03/2013 - 10:01:04 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\42536ddf-2cb2-4475-b9d2-a64c7f1616f0.dmp [21807] O61 - LFC: 30/03/2013 - 10:01:05 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\42536ddf-2cb2-4475-b9d2-a64c7f1616f0.extra [2733] O61 - LFC: 30/03/2013 - 10:56:33 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\bookmarkbackups\bookmarks-2013-03-30.json [20554] O61 - LFC: 30/03/2013 - 11:32:14 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\14549eef-e9b0-445b-80f7-56b8655aedb8.dmp [21807] O61 - LFC: 30/03/2013 - 11:32:14 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\14549eef-e9b0-445b-80f7-56b8655aedb8.extra [2733] O61 - LFC: 30/03/2013 - 11:42:23 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\signons.sqlite [327680] O61 - LFC: 30/03/2013 - 11:48:15 ---A- C:\Documents and Settings\COUTURIER\Application Data\teeworlds-b122-r50edfd37-win32\data\skins\sky-master.png [15352] O61 - LFC: 30/03/2013 - 11:48:15 ---A- C:\Documents and Settings\COUTURIER\Recent\sky-master.lnk [1293] O61 - LFC: 30/03/2013 - 11:48:34 ---A- C:\Documents and Settings\COUTURIER\Recent\Bearli.lnk [1271] O61 - LFC: 30/03/2013 - 11:48:35 ---A- C:\Documents and Settings\COUTURIER\Application Data\teeworlds-b122-r50edfd37-win32\data\skins\Bearli.png [12895] O61 - LFC: 30/03/2013 - 12:51:05 ---A- C:\Documents and Settings\COUTURIER\Mes documents\Téléchargements\ZHPDiag2.exe [5485603] O61 - LFC: 30/03/2013 - 13:05:06 ---A- C:\Documents and Settings\COUTURIER\Recent\Fatals Picards.lnk [857] O61 - LFC: 30/03/2013 - 13:05:06 ---A- C:\Documents and Settings\COUTURIER\Recent\Les Fatals Picards.lnk [556] O61 - LFC: 30/03/2013 - 14:10:30 -S-A- C:\Documents and Settings\COUTURIER\Application Data\Microsoft\Crypto\RSA\S-1-5-21-606747145-1409082233-682003330-1004\660bba0fd333c3a3922bcd74a5bbbbfe_f590c4b2-cf37-4bfe-8b94-7110679d7ff3 [1305] O61 - LFC: 30/03/2013 - 14:11:39 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\37cc7b75-967e-4bb3-b857-c44824fb89f1.dmp [21807] O61 - LFC: 30/03/2013 - 14:11:39 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\37cc7b75-967e-4bb3-b857-c44824fb89f1.extra [2733] O61 - LFC: 30/03/2013 - 14:24:39 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\b6e16ea6-bd87-4999-adce-378450b5f4f9.dmp [21807] O61 - LFC: 30/03/2013 - 14:24:39 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\b6e16ea6-bd87-4999-adce-378450b5f4f9.extra [2733] O61 - LFC: 30/03/2013 - 15:10:50 -S-A- C:\Documents and Settings\COUTURIER\Application Data\Microsoft\Crypto\RSA\S-1-5-21-606747145-1409082233-682003330-1004\a2b8fb9f786ee14b841a0ea32fb2879b_f590c4b2-cf37-4bfe-8b94-7110679d7ff3 [1305] O61 - LFC: 30/03/2013 - 15:18:41 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\8b7be971-6077-4c92-89ff-905c1b01fc99.dmp [21807] O61 - LFC: 30/03/2013 - 15:18:41 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\8b7be971-6077-4c92-89ff-905c1b01fc99.extra [2733] O61 - LFC: 30/03/2013 - 15:20:15 ---A- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Microsoft\HelpCtr\HelpSessionHistory.dat [10374] O61 - LFC: 30/03/2013 - 15:27:03 ---A- C:\Documents and Settings\COUTURIER\Recent\South Park - 15x11 - Broadway Bro Down VOSTFR.lnk [599] O61 - LFC: 30/03/2013 - 15:27:03 ---A- C:\Documents and Settings\COUTURIER\Recent\South Park - Saison 15 - VOSTFR.lnk [329] O61 - LFC: 30/03/2013 - 15:56:25 ---A- C:\Documents and Settings\COUTURIER\Application Data\vlc\ml.xspf [304] O61 - LFC: 30/03/2013 - 15:56:25 ---A- C:\Documents and Settings\COUTURIER\Application Data\vlc\vlcrc [80082] O61 - LFC: 30/03/2013 - 16:05:05 -SHA- C:\Documents and Settings\COUTURIER\IECompatCache\index.dat [65536] O61 - LFC: 30/03/2013 - 16:05:05 -SHA- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\index.dat [32768] O61 - LFC: 30/03/2013 - 16:09:18 ---A- C:\Documents and Settings\COUTURIER\Application Data\Microsoft\Windows\Themes\Custom.theme [8533] O61 - LFC: 30/03/2013 - 16:21:02 ---A- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Microsoft\Wallpaper1.bmp [5828886] O61 - LFC: 30/03/2013 - 16:21:02 -SHA- C:\Documents and Settings\COUTURIER\Application Data\Microsoft\Internet Explorer\Desktop.htt [2706] O61 - LFC: 30/03/2013 - 16:47:50 ---A- C:\Documents and Settings\COUTURIER\Recent\ZHPDiag.lnk [483] O61 - LFC: 30/03/2013 - 16:57:26 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\saved-telemetry-pings\4fd7c4ad-3bf8-487b-b58c-f01cedd72a3c [68846] O61 - LFC: 30/03/2013 - 16:57:29 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\Telemetry.ShutdownTime.txt [6] O61 - LFC: 30/03/2013 - 17:10:10 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\d9c58d9e-50f7-432c-aee4-d0127b48e30e.dmp [21807] O61 - LFC: 30/03/2013 - 17:10:11 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\d9c58d9e-50f7-432c-aee4-d0127b48e30e.extra [2733] O61 - LFC: 30/03/2013 - 18:20:10 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\0a5ac45a-507c-425c-9117-270a0524b306.dmp [21807] O61 - LFC: 30/03/2013 - 18:20:10 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\0a5ac45a-507c-425c-9117-270a0524b306.extra [2733] O61 - LFC: 30/03/2013 - 18:51:51 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\1c79f7e0-f7b6-4ff5-8087-5604f7ecb956.dmp [21807] O61 - LFC: 30/03/2013 - 18:51:51 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\1c79f7e0-f7b6-4ff5-8087-5604f7ecb956.extra [2733] O61 - LFC: 30/03/2013 - 19:00:07 ---A- C:\Documents and Settings\COUTURIER\Bureau\Sans nom 1.odt [91850] O61 - LFC: 30/03/2013 - 19:25:06 ---A- C:\Documents and Settings\COUTURIER\Recent\Sans nom 1 (2).lnk [500] O61 - LFC: 30/03/2013 - 20:52:02 ---A- C:\Documents and Settings\COUTURIER\Recent\CV Spécific MA ZILAVEC (2).lnk [560] O61 - LFC: 30/03/2013 - 20:52:25 ---A- C:\Documents and Settings\COUTURIER\Recent\Mars 2013.lnk [495] O61 - LFC: 30/03/2013 - 20:53:22 ---A- C:\Documents and Settings\COUTURIER\Recent\Conseils aroma SPECIFIQUE.lnk [760] O61 - LFC: 30/03/2013 - 20:53:22 ---A- C:\Documents and Settings\COUTURIER\Recent\Spécific.lnk [437] O61 - LFC: 30/03/2013 - 21:00:44 ---A- C:\Documents and Settings\COUTURIER\Recent\COUTURIER_Philippe_protocole accord formateur AROMATHERAPIE.lnk [868] O61 - LFC: 30/03/2013 - 21:00:44 ---A- C:\Documents and Settings\COUTURIER\Recent\SPECIFIQUE.lnk [390] O61 - LFC: 30/03/2013 - 21:05:47 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\c1572236-8d48-4fd2-846e-e455895d4002.dmp [27909] O61 - LFC: 30/03/2013 - 21:05:47 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\c1572236-8d48-4fd2-846e-e455895d4002.extra [2733] O61 - LFC: 30/03/2013 - 21:43:32 ---A- C:\Documents and Settings\COUTURIER\Mes documents\plan generale de formation SPECIFIC.docx [13795] O61 - LFC: 30/03/2013 - 21:43:32 ---A- C:\Documents and Settings\COUTURIER\Recent\plan generale de formation SPECIFIC.lnk [701] O61 - LFC: 30/03/2013 - 21:44:35 ---A- C:\Documents and Settings\COUTURIER\Mes documents\Aromatherapie - ISL v02 avec petites corrections SA.ppt [4707840] O61 - LFC: 30/03/2013 - 21:44:35 ---A- C:\Documents and Settings\COUTURIER\Recent\Aromatherapie - ISL v02 avec petites corrections SA.lnk [934] O61 - LFC: 30/03/2013 - 21:45:36 ---A- C:\Documents and Settings\COUTURIER\Recent\Démarrer.lnk [566] O61 - LFC: 30/03/2013 - 21:45:46 ---A- C:\Documents and Settings\COUTURIER\Recent\précautions (2).lnk [581] O61 - LFC: 30/03/2013 - 21:45:58 ---A- C:\Documents and Settings\COUTURIER\Recent\Trousse 6he.lnk [581] O61 - LFC: 30/03/2013 - 22:02:27 ---A- C:\Documents and Settings\COUTURIER\Recent\Doses par voie d administration.lnk [681] O61 - LFC: 30/03/2013 - 22:13:04 ---A- C:\Documents and Settings\COUTURIER\Mes documents\Doses Voies.odt [21545] O61 - LFC: 30/03/2013 - 22:13:04 ---A- C:\Documents and Settings\COUTURIER\Recent\Doses Voies.lnk [576] O61 - LFC: 30/03/2013 - 22:13:32 ---A- C:\Documents and Settings\COUTURIER\Application Data\uTorrent\dht.dat.old [4222] O61 - LFC: 30/03/2013 - 22:13:32 ---A- C:\Documents and Settings\COUTURIER\Application Data\uTorrent\rss.dat.old [99] O61 - LFC: 31/03/2013 - 18:40:14 -S-A- C:\Documents and Settings\COUTURIER\Application Data\Microsoft\Crypto\RSA\S-1-5-21-606747145-1409082233-682003330-1004\43badec1d530cdd3c178b33e9dc9d91b_f590c4b2-cf37-4bfe-8b94-7110679d7ff3 [1305] O61 - LFC: 31/03/2013 - 18:44:40 ---A- C:\Documents and Settings\COUTURIER\Local Settings\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Galerie de composants Web Slice~.feed-ms [32768] O61 - LFC: 31/03/2013 - 18:47:01 ---A- C:\Documents and Settings\COUTURIER\Recent\Download.lnk [714] O61 - LFC: 31/03/2013 - 18:47:01 ---A- C:\Documents and Settings\COUTURIER\Recent\Mes images.lnk [477] O61 - LFC: 31/03/2013 - 18:50:38 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\f8102da9-eb48-43d4-bc31-e297e93930ea.dmp [21807] O61 - LFC: 31/03/2013 - 18:50:38 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\f8102da9-eb48-43d4-bc31-e297e93930ea.extra [2733] O61 - LFC: 31/03/2013 - 18:51:23 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\bookmarkbackups\bookmarks-2013-03-31.json [21638] O61 - LFC: 31/03/2013 - 18:56:24 ---A- C:\Documents and Settings\COUTURIER\Recent\Portrait Lucie 2008.lnk [542] O61 - LFC: 31/03/2013 - 18:56:24 ---A- C:\Documents and Settings\COUTURIER\Recent\TOUTES les Photos.lnk [378] O61 - LFC: 31/03/2013 - 18:57:07 ---A- C:\Documents and Settings\COUTURIER\Recent\MICROSOFT OFFICE.lnk [399] O61 - LFC: 31/03/2013 - 19:07:17 ---A- C:\Documents and Settings\COUTURIER\Recent\REFLEXO PLANTAIRE.lnk [613] O61 - LFC: 31/03/2013 - 19:07:17 ---A- C:\Documents and Settings\COUTURIER\Recent\carte-reflexologie-plantaire.lnk [986] O61 - LFC: 31/03/2013 - 19:07:41 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\e1a7f761-c1cd-418d-9cc0-642a3ded01b4.dmp [27909] O61 - LFC: 31/03/2013 - 19:07:41 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Crash Reports\pending\e1a7f761-c1cd-418d-9cc0-642a3ded01b4.extra [2733] O61 - LFC: 31/03/2013 - 20:24:56 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\key3.db [16384] O61 - LFC: 31/03/2013 - 20:24:57 ---A- C:\Documents and Settings\COUTURIER\Application Data\Mozilla\Firefox\Profiles\7eopajap.default\Invalidprefs.js [756856] O61 - LFC: 31/03/2013 - 20:25:02 ---A- C:\Documents and Settings\COUTURIER\Recent\ACER (E).lnk [279] O61 - LFC: 31/03/2013 - 20:25:02 ---A- C:\Documents and Settings\COUTURIER\Recent\terpènes lipides stéroides.lnk [432] O61 - LFC: 31/03/2013 - 20:25:15 ---A- C:\Documents and Settings\COUTURIER\Application Data\uTorrent\dht.dat [111] O61 - LFC: 31/03/2013 - 20:25:15 ---A- C:\Documents and Settings\COUTURIER\Application Data\uTorrent\rss.dat [99] ~ 15 Fichiers temporaires (Temporary files) ~ 9 Fichiers cookies (Cookies files) ~ Files: 577 Legitimates Scanned in 04mn 21s ---\\ Liste des outils de nettoyage (O63) O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 ~ ADS: Scanned in 00mn 00s ---\\ Liste des services Legacy (O64) O64 - Services: CurCS - 30/08/2011 - C:\Program Files\Bonjour\mDNSResponder.exe (Bonjour Service) .(.Apple Inc. - Bonjour Service.) - LEGACY_BONJOUR_SERVICE O64 - Services: CurCS - 29/07/2010 - C:\WINDOWS\system32\FsUsbExService.exe (FsUsbExService) .(.Teruten - FsUsbDevice.) - LEGACY_FSUSBEXSERVICE O64 - Services: CurCS - 29/11/2012 - C:\WINDOWS\gdrv.sys (gdrv) .(.Windows (R) 2000 DDK provider - GIGABYTE Tools.) - LEGACY_GDRV O64 - Services: CurCS - 05/09/2012 - C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe (McComponentHostService) .(.McAfee, Inc. - Component Host Service.) - LEGACY_MCCOMPONENTHOSTSERVICE O64 - Services: CurCS - 07/04/2008 - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (ServiceLayer) .(.Nokia. - ServiceLayer Module.) - LEGACY_SERVICELAYER ~ Legacy: 115 Legitimates Scanned in 00mn 00s ---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.bat> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKCR\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll O67 - Shell Spawning: <.cmd> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.exe> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.js> [HKCR\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe O67 - Shell Spawning: <.reg> [HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe ~ Keys: Scanned in 00mn 00s ---\\ Start Menu Internet (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Search Browser Infection (O69) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (@ieframe.dll,-12512) - http://www.bing.com ~ Keys: Scanned in 00mn 00s ---\\ Recherche des services démarrés par Svchost (O83) ~ Services: 39 Legitimates Scanned in 00mn 00s ---\\ Recherche particuliere à la racine de certains dossiers (O84) [MD5.A192627877A1B5A41AE1DE58C4EBE60F] [SPRF][22/12/2012] (...) -- C:\Documents and Settings\COUTURIER\Bureau\Manny Bot 2012 [Totoro].exe [294507] [MD5.B63CCB43F2779CBEA5D8D3CE2E3D90FB] [SPRF][06/12/2012] (...) -- C:\Documents and Settings\COUTURIER\Bureau\Minecraft.exe [263186] [MD5.6B4CEA7F9DE3014D714324F8FE9F8E0C] [SPRF][14/03/2013] (.BitTorrent Inc. - µTorrent.) -- C:\Documents and Settings\COUTURIER\Bureau\uTorrent.exe [1037648] ~ Files: Scanned in 00mn 00s ---\\ Scan Additionnel (O88) Database Version : v2.11340 - (29/03/2013) Clés trouvées (Keys found) : 12 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 0 Fichiers trouvés (Files found) : 0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403a-B9D2-65C292C39087}] =>Adware.IncrediBar [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}] =>Adware.IncrediBar [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{856E12B5-22D7-4E22-9ACA-EA9A008DD65B}] =>Toolbar.Minibar [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AA74D58F-ACD0-450D-A85E-6C04B171C044}] =>Toolbar.Minibar [HKLM\Software\Classes\CLSID\{efb46ed3-8fd8-4051-8fd6-dd9ce7e63bef}] =>PUP.AppGraffiti [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9639E4A-801B-4843-AEE3-03D9DA199E77}] =>Adware.IncrediBar [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AppGraffiti] =>PUP.AppGraffiti [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\FilesFrog Update Checker] =>Adware.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Inbox Toolbar] =>Adware.WebAdSystem [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403A-B9D2-65C292C39087}] =>Adware.IncrediBar [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =>Toolbar.Bing [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =>Toolbar.Bing ~ Additionnel: Scanned in 00mn 18s ---\\ Product Upgrade Codes (O90) ~ Update Products: 25 Legitimates Scanned in 00mn 00s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 13/03/2013 253656 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe SR - | Auto 01/08/2008 573440 | (Ati HotKey Poller) . (.ATI Technologies Inc..) - C:\WINDOWS\system32\Ati2evxx.exe SS - | Auto 593920 | (ATI Smart) . (...) - C:\WINDOWS\system32\ati2sgag.exe SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe SS - | Demand 14/04/2008 225280 | (dmadmin) . (.Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\dmadmin.exe SR - | Auto 29/07/2010 238952 | (FsUsbExService) . (.Teruten.) - C:\WINDOWS\system32\FsUsbExService.exe SR - | Demand 20/02/2013 553288 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe SR - | Auto 13/03/2013 170912 | (JavaQuickStarterService) . (.Oracle Corporation.) - C:\Program Files\Java\jre7\bin\jqs.exe SS - | Demand 05/09/2012 234776 | (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe SS - | Demand 08/03/2013 115608 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe SR - | Auto 15/10/2011 298304 | (NVSvc) . (.NVIDIA Corporation.) - C:\WINDOWS\system32\nvsvc32.exe SS - | Demand 07/04/2008 430592 | (ServiceLayer) . (.Nokia..) - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe SS - | Auto 08/01/2013 161536 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe ~ Services: Scanned in 00mn 00s ---\\ Recherche Master Boot Record Infection (MBR)(O80) Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net Run by COUTURIER at 01/04/2013 13:09:30 device: opened successfully user: MBR read successfully Disk trace: called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys 1 ntkrnlpa!IofCallDriver[0x804EF1F0] => \Device\Harddisk0\DR0[0x89DEBAB8] kernel: MBR read successfully user & kernel MBR OK ~ MBR: 13 Legitimates Scanned in 00mn 02s ---\\ Recherche Master Boot Record Infection (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by COUTURIER at 01/04/2013 13:09:32 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 04s End of the scan (877 lines in 07mn 32s)(0)