Rapport de ZHPDiag v2013.4.18.101 par Nicolas Coolman, Update du 18/04/2013 Run by serge at 19/04/2013 17:05:20 State : Version à jour. WhiteList : Disable High Elevated Privileges : OK UAC : Activate by user ---\\ Web Browser MSIE: Internet Explorer v9.0.8112.16421 MFIE: Mozilla Firefox 20.0.1 v20.0.1 (Defaut) ---\\ Windows Product Information ~ Langage: Français Windows Vista Home Premium Edition, 32-bit Service Pack 2 (Build 6002) Windows Server License Manager Script : OK Windows Automatic Updates : OK ---\\ System Protection avast! Free Antivirus v8.0.1483.0 Malwarebytes Anti-Malware version 1.75.0.1300 ---\\ System Optimizer CCleaner v3.27 ---\\ Software Update Adobe Flash Player 11 Plugin Adobe Reader XI Java 7 Update 21 ---\\ System Information ~ Processor: x86 Family 6 Model 15 Stepping 13, GenuineIntel ~ Operating System: 32 Bits Boot mode: Normal (Normal boot) Total RAM: 2037 MB (52% free) System Restore: Activé (Enable) System drive C: has 111 GB (61%) free of 179 GB ---\\ Logged in mode ~ Computer Name: PC-DE-SERGE ~ User Name: serge ~ All Users Names: serge, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Environnement Variables ~ System Unit : C:\ ~ %AppData% : C:\Users\serge\AppData\Roaming\ ~ %Desktop% : C:\Users\serge\Desktop\ ~ %Favorites% : C:\Users\serge\Favorites\ ~ %LocalAppData% : C:\Users\serge\AppData\Local\ ~ %StartMenu% : C:\Users\serge\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ DOS/Devices C:\ Hard drive, Flash drive, Thumb drive (Free 111 Go of 179 Go) D:\ Floppy drive, Flash card reader, USB Key (Not Inserted) E:\ Floppy drive, Flash card reader, USB Key (Not Inserted) F:\ CD-ROM drive (Not Inserted) ---\\ Security Center & Tools Informations [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyComputer: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Security Center: Scanned in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.D07D4C3038F3578FFCE1C0237F2A1253] - (.Microsoft Corporation - Explorateur Windows.) (.11/04/2009 - 07:27:36.) -- C:\Windows\Explorer.exe [2926592] [MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de démarrage de Windows.) (.19/01/2008 - 08:33:37.) -- C:\Windows\System32\Wininit.exe [96768] [MD5.C5B6468422DB1C8AA36C32CBB0197E5E] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.22/02/2013 - 04:38:00.) -- C:\Windows\System32\wininet.dll [1129472] [MD5.898E7C06A350D4A1A64A9EA264D55452] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.11/04/2009 - 07:28:13.) -- C:\Windows\System32\Winlogon.exe [314368] [MD5.3911B972B55FEA0478476B2E777B29FA] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.21/04/2011 - 14:58:27.) -- C:\Windows\system32\Drivers\AFD.sys [273408] [MD5.1F05B78AB91C9075565A9D8A4B880BC4] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.11/04/2009 - 07:32:26.) -- C:\Windows\system32\Drivers\atapi.sys [19944] [MD5.7ADD03E75BEB9E6DD102C3081D29840A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.19/01/2008 - 06:28:02.) -- C:\Windows\system32\Drivers\Cdfs.sys [70144] [MD5.6B4BFFB9BECD728097024276430DB314] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.11/04/2009 - 05:39:17.) -- C:\Windows\system32\Drivers\Cdrom.sys [67072] [MD5.622C41A07CA7E6DD91770F50D532CB6C] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.14/04/2011 - 15:59:03.) -- C:\Windows\system32\Drivers\DfsC.sys [75264] [MD5.062452B7FFD68C8C042A6261FE8DFF4A] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.11/04/2009 - 05:42:42.) -- C:\Windows\system32\Drivers\HDAudBus.sys [561152] [MD5.22D56C8184586B7A1F6FA60BE5F5A2BD] - (.Microsoft Corporation - Pilote de port i8042.) (.19/01/2008 - 06:49:18.) -- C:\Windows\system32\Drivers\i8042prt.sys [54784] [MD5.8793643A67B42CEC66490B2A0CF92D68] - (.Microsoft Corporation - IP Network Address Translator.) (.19/01/2008 - 06:56:28.) -- C:\Windows\system32\Drivers\IpNat.sys [100864] [MD5.1E94971C4B446AB2290DEB71D01CF0C2] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.29/04/2011 - 14:24:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [106496] [MD5.ECD64230A59CBD93C85F1CD1CAB9F3F6] - (.Microsoft Corporation - MBT Transport driver.) (.11/04/2009 - 05:45:37.) -- C:\Windows\system32\Drivers\netBT.sys [185856] [MD5.2C1121F2B87E9A6B12485DF53CD848C7] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.03/03/2013 - 20:07:52.) -- C:\Windows\system32\Drivers\ntfs.sys [1082232] [MD5.0FA9B5055484649D63C303FE404E5F4D] - (.Microsoft Corporation - Pilote de port parallèle.) (.02/11/2006 - 09:51:30.) -- C:\Windows\system32\Drivers\Parport.sys [79360] [MD5.A214ADBAF4CB47DD2728859EF31F26B0] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.19/01/2008 - 06:56:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [76288] [MD5.E8BD98D46F2ED77132BA927FCCB47D8B] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.02/11/2006 - 10:03:00.) -- C:\Windows\system32\Drivers\rdpdr.sys [242688] [MD5.7B75299A4D201D6A6533603D6914AB04] - (.Microsoft Corporation - SMB Transport driver.) (.11/04/2009 - 05:45:22.) -- C:\Windows\system32\Drivers\smb.sys [66560] [MD5.76B06EB8A01FC8624D699E7045303E54] - (.Microsoft Corporation - TDI Translation Driver.) (.11/04/2009 - 05:45:56.) -- C:\Windows\system32\Drivers\tdx.sys [72192] [MD5.786DB5771F05EF300390399F626BF30A] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21/08/2012 - 12:47:42.) -- C:\Windows\system32\Drivers\volsnap.sys [224640] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 1/305 ~ Mes musiques (My Musics) : 1/32 ~ Mes Videos (My Videos) : 1/6 ~ Mes Favoris (My Favorites) : 1/39 ~ Mes Documents (My Documents) : 1/704 ~ Mon Bureau (My Desktop) : 1/304 ~ Menu demarrer (Programs) : 1/31 ~ Hidden Files: Scanned in 00mn 01s ---\\ Processus lancés [MD5.15698CEFF3FBFA6DE2D8ADAC952B54EC] - (.Sony Corporation - VAIO Update.) -- C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe [551032] [PID.2592] [MD5.6FC8ECA367679C2AEBBA09A416B4C18D] - (.Alps Electric Co., Ltd. - Alps Pointing-device Driver.) -- C:\Program Files\Apoint\Apoint.exe [118784] [PID.3136] [MD5.148C545849C1379A3D4448F5DE768E86] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [4767304] [PID.3152] [MD5.D63797E8E7781EE1500A810CB6194FA6] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816] [PID.3200] [MD5.B5ADEB3FCFFAE8094611DD04D09D2450] - (.Duuqu Group - FrameFox Extensions.) -- C:\Program Files\FrameFox\Extensions\InternetExplorer\framefox.exe [224240] [PID.3244] [MD5.BF08674925F151BD4537B89A493E3E0C] - (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehtray.exe [125952] [PID.3276] [MD5.0F4195B9B348DE5CF9B822F81704B20E] - (.Microsoft Corporation - Media Center Media Status Aggregator Servic.) -- C:\Windows\ehome\ehmsas.exe [37376] [PID.3372] [MD5.42370C1DE2B83844B253478DB8A907D5] - (.Alps Electric Co., Ltd. - ApMsgFwd.) -- C:\Program Files\Apoint\ApMsgFwd.exe [50736] [PID.812] [MD5.99A7B10500920E5CC79B700927B18BC1] - (.Alps Electric Co., Ltd. - Alps Pointing-device Driver for Windows NT/.) -- C:\Program Files\Apoint\Apntex.exe [40960] [PID.3988] [MD5.6080A176D09435FC8E6E800996656E18] - (.Microsoft Corporation - Console IME.) -- C:\Windows\system32\conime.exe [69120] [PID.2784] [MD5.A778E395D5481138169D233AAE92757A] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [6861312] [PID.4108] [MD5.862BB4CBC05D80C5B45BE430E5EF872F] - (.Microsoft Corporation - Service de gestion des licences Microsoft.) -- C:\Windows\system32\SLsvc.exe [3408896] [PID.1380] [MD5.41735B82DB57E4EBE9504EC400FD120E] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [45248] [PID.1756] [MD5.3927397AC60D943DAF8808AFFED582B7] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [65192] [PID.900] [MD5.9044795E9D1A912D5F1B8DF6211850FD] - (.Secunia - Secunia PSI Agent.) -- C:\Program Files\Secunia\PSI\PSIA.exe [1326176] [PID.2844] [MD5.4D6644132F26EF055A1F754B1C38C084] - (.Sony Corporation - VAIO Entertainment UPnP Client Adapter.) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [274432] [PID.3432] [MD5.15A317674A08DF26BE65164D959E9203] - (.Conexant Systems, Inc. - Modem Audio Service.) -- C:\Windows\system32\DRIVERS\xaudio.exe [386560] [PID.4060] [MD5.0B3244BAB1FA37CF15FA7243504391A6] - (.Sony Corporation - VAIO Entertainment Database Service.) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [188416] [PID.2052] [MD5.938FBFA83148DADD7DB0B1303DCCFA00] - (.Sony Corporation - VAIO Entertainment File Import Service.) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe [184320] [PID.1696] ~ Processes Running: Scanned in 00mn 01s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\serge\AppData\Roaming\Mozilla\Firefox\Profiles\gr9voc6h.default\prefs.js C:\Users\serge\AppData\Roaming\Mozilla\Firefox\Profiles\gr9voc6h.default\user.js M3 - MFPP: Plugins - [serge] -- C:\Users\serge\AppData\Roaming\Mozilla\Firefox\Profiles\gr9voc6h.default\searchplugins\delta.xml M3 - MFPP: Plugins - [serge] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml M3 - MFPP: Plugins - [serge] -- C:\Program Files\Mozilla FireFox\searchplugins\babylon.xml =>Toolbar.Babylon M3 - MFPP: Plugins - [serge] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml M3 - MFPP: Plugins - [serge] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml M3 - MFPP: Plugins - [serge] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml M3 - MFPP: Plugins - [serge] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml M3 - MFPP: Plugins - [serge] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml M3 - MFPP: Plugins - [serge] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml M2 - MFEP: prefs.js [serge - gr9voc6h.default\donottrackplus@abine.com] [] DoNotTrackMe v2.2.8.307 (..) M2 - MFEP: prefs.js [serge - gr9voc6h.default\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}] [] PriceGong v2.6.11 (..) =>Adware.PriceGong M2 - MFEP: prefs.js [serge - gr9voc6h.default\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}] [WOT] WOT v20130402 (..) M2 - MFEP: prefs.js [serge - gr9voc6h.default\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}] [dwhelper] DownloadHelper v4.9.14 (..) P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files\Mozilla Firefox\Plugins\np-mswmp.dll P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFFICE.DLL P2 - FPN:Firefox Plugin Navigator . (.UNISYS France - UNISYS NAP Win 32 Plugin Version 51.) -- C:\Program Files\Mozilla Firefox\Plugins\npornap.dll P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.02.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll P2 - FPN: [HKLM] [@divx.com/DivX Player Plugin,version=1.0.0] - (.DivX, Inc - npdivxplayerplugin.) -- C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll P2 - FPN: [HKLM] [@google.com/npPicasa3,version=3.0.0] - (.Google, Inc. - Picasa plugin.) -- C:\Program Files\Picasa2\npPicasa3.dll P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=10.21.2] - (.Oracle Corporation - Next Generation Java Plug-in 10.21.2 for Mozilla browsers.) -- C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.20125.0.) -- c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3508.1109] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3538.0513] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3555.0308] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll P2 - FPN: [HKLM] [@videolan.org/vlc,version=1.0.5] - (...) -- C:\Users\serge\Desktop\VLC\npvlc.dll (.not file.) P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.0.4] - (.VideoLAN - VLC media player Web Plugin 2.0.6.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll P2 - FPN: [HKLM] [@www.duuqu.com/omaha/tools//Duuqu Update;version=3] - (.Duuqu Group - Duuqu Update.) -- C:\Program Files\Duuqu\Update\1.3.37.0\npDuuquUpdate3.dll P2 - FPN: [HKLM] [@www.duuqu.com/omaha/tools//Duuqu Update;version=9] - (.Duuqu Group - Duuqu Update.) -- C:\Program Files\Duuqu\Update\1.3.37.0\npDuuquUpdate3.dll P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.02.) -- C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll ~ Firefox Browser: 38 Scanned in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.google.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2 ~ IE Browser: 11 Scanned in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\Userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl" ~ Keys: Scanned in 00mn 00s ---\\ Redirection du fichier Hosts (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Hosts File: Scanned in 00mn 05s ~ Nombre de lignes (Lines number): 13087 ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} . (.PriceGong - PriceGong - Price Comparison.) -- C:\Program Files\PriceGong\2.6.11\PriceGongIE.dll =>Adware.PriceGong O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - avast! WebRep Plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre7\bin\jp2ssv.dll ~ BHO: 5 Scanned in 00mn 00s ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: Bing Bar - [HKLM]{8dcb7100-df86-4384-8842-8fa844297b3f} . (.Microsoft Corporation. - Extensions du client Bing.) -- C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll O3 - Toolbar: avast! WebRep - [HKLM]{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - avast! WebRep Plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ~ Toolbar: Scanned in 00mn 00s ---\\ Applications démarrées par registre & par dossier (O4) O4 - HKLM\..\Run: [Apoint] . (.Alps Electric Co., Ltd. - Alps Pointing-device Driver.) -- C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [avast] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastUI.exe O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe O4 - HKLM\..\Run: [FrameFox Extensions] . (.Duuqu Group - FrameFox Extensions.) -- C:\Program Files\FrameFox\Extensions\InternetExplorer\framefox.exe O4 - HKCU\..\Run: [ABBYY Screenshot Reader Bonus] . (.ABBYY - ABBYY ScreenshotReader.) -- C:\Program Files\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe O4 - HKCU\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe O4 - HKUS\S-1-5-21-3276480709-338746168-2113458505-1000\..\Run: [ABBYY Screenshot Reader Bonus] . (.ABBYY - ABBYY ScreenshotReader.) -- C:\Program Files\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe O4 - HKUS\S-1-5-21-3276480709-338746168-2113458505-1000\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe ~ Application: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\Programs: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O4 - GS\Programs: Windows Mail.lnk . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe O4 - GS\Programs: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe O4 - GS\QuickLaunch: Launch Internet Explorer Browser (2).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O4 - GS\QuickLaunch: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O4 - GS\QuickLaunch: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture.) -- C:\Windows\System32\SnippingTool.exe O4 - GS\QuickLaunch: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe O4 - GS\Accessories: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O4 - GS\SendTo: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe O4 - GS\Desktop: 2013_SENSAS_FR - Raccourci.lnk . (...) -- C:\Users\serge\Desktop\PECHE\Catalogues Pêche\2013_SENSAS_FR.pdf O4 - GS\Desktop: Guides de l'utilisateur VAIO.lnk . (...) -- C:\Documentation\Documentation O4 - GS\Desktop: Microsoft Office Excel 2003.lnk . (...) -- C:\Windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe O4 - GS\Desktop: Microsoft Office Picture Manager.lnk . (...) -- C:\Windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe O4 - GS\Desktop: Microsoft Office Word 2003 (2).lnk . (...) -- C:\Windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe O4 - GS\Desktop: WhoCrashed.lnk . (...) -- C:\Program Files\WhoCrashed\WhoCrashed.exe ~ Global Startup: Scanned in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} . (.Microsoft Corporation - Windows Live Messenger Companion core resources.) -- C:\Program Files\Windows Live\Companion\companionres.dll O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\OFFICE11\REFBARH.ICO ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll ~ Winsock: 6 Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{9017D80C-FB37-4584-98A4-E9B01B4BA34B}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{FAD502BB-E309-409A-8B10-E649FF17D639}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{9017D80C-FB37-4584-98A4-E9B01B4BA34B}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{FAD502BB-E309-409A-8B10-E649FF17D639}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{9017D80C-FB37-4584-98A4-E9B01B4BA34B}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{FAD502BB-E309-409A-8B10-E649FF17D639}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS3\Services\Tcpip\..\{9017D80C-FB37-4584-98A4-E9B01B4BA34B}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.dll ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll O20 - Winlogon Notify: VESWinlogon . (.Sony Corporation - VAIO Event Service (Winlogon Notification M.) -- C:\Windows\System32\VESWinlogon.dll ~ Winlogon: Scanned in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - AppInit_DLLs: . (...) - C:\Program Files\Google\GOOGLE~1\GOEC62~1dll C:\Program Files\Google\GOOGLE~1\GOEC62~1.dll (.not file.) ~ AppInit DLL: Scanned in 00mn 00s ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Contrôleur de site Web.) -- C:\Windows\System32\webcheck.dll ~ SSODL: 1 Scanned in 00mn 00s ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22) O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\System32\browseui.dll ~ STS/SSO: Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: avast! Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: Duuqu Update Service (dqupdate) (dqupdate) . (.Duuqu Group - Duuqu Installer.) - C:\Program Files\Duuqu\Update\DuuquUpdate.exe O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: NSUService (NSUService) . (.Sony Corporation - VAIO Smart Network.) - C:\Program Files\Sony\Network Utility\NSUService.exe O23 - Service: Secunia PSI Agent (Secunia PSI Agent) . (.Secunia - Secunia PSI Agent.) - C:\Program Files\Secunia\PSI\PSIA.exe O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) . (.Sony Corporation - VAIO Entertainment Database Service.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe O23 - Service: VAIO Entertainment File Import Service (VzFw) . (.Sony Corporation - VAIO Entertainment File Import Service.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe O23 - Service: XAudioService (XAudioService) . (.Conexant Systems, Inc. - Modem Audio Service.) - C:\Windows\System32\DRIVERS\xaudio.exe ~ Services: 10 Scanned in 00mn 05s ---\\ Enumération Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - C:\Program Files\Microsoft Office\Office12\WINWORD.exe (.not file.) ~ Desktop Component: 4 Scanned in 00mn 00s ---\\ BootExecute (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found ~ BEX: 1 Scanned in 00mn 00s ---\\ Tâches planifiées en automatique (O39) O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Adobe Flash Player Updater.job [1002] O39 - APT:Automatic Planified Task - C:\Windows\Tasks\AmiUpdXp.job [356] O39 - APT:Automatic Planified Task - C:\Windows\Tasks\DuuquUpdateTaskMachineCore.job [870] O39 - APT:Automatic Planified Task - C:\Windows\Tasks\DuuquUpdateTaskMachineUA.job [874] O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1050] O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1054] [MD5.479901C99FA62D1C3261B7ACB1228DAD] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [256904] [MD5.861DDA2A5B38AC54B2469DD04D35A935] [APT] [AmiUpdXp] (.Amonetize ltd..) -- C:\Users\serge\AppData\Local\SwvUpdater\Updater.exe [301608] [MD5.AB3C4A3667AEAD147F175721D8719B78] [APT] [avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [250248] [MD5.9CE3B11704038F711481ACD6BD9A9A5A] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [3274008] [MD5.136E913B1D3771B3535C3622C36B5E38] [APT] [DuuquUpdateTaskMachineCore] (.Duuqu Group.) -- C:\Program Files\Duuqu\Update\DuuquUpdate.exe [98360] [MD5.136E913B1D3771B3535C3622C36B5E38] [APT] [DuuquUpdateTaskMachineUA] (.Duuqu Group.) -- C:\Program Files\Duuqu\Update\DuuquUpdate.exe [98360] [MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [136176] [MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe [136176] [MD5.15698CEFF3FBFA6DE2D8ADAC952B54EC] [APT] [VAIO Update] (.Sony Corporation.) -- C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe [551032] ~ Scheduled Task: 19 Scanned in 00mn 05s ---\\ Composants installés (ActiveSetup Installed Components) (O40) O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\system32\ie4uinit.exe O40 - ASIC: Browser Customizations - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - Personnalisation d’IEAK.) -- C:\Windows\system32\iedkcs32.dll O40 - ASIC: Microsoft Windows Media Player 11.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Microsoft Windows Mail 7 - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 11.7 r700.) -- C:\Windows\system32\Macromed\Flash\Flash32_11_7_700_169.ocx ~ Active Setup: 12 Scanned in 00mn 00s ---\\ Pilotes lancés au démarrage (O41) O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: (DMICall) . (.Sony Corporation - Windows 2000 DMI Call Kernel Driver.) - C:\Windows\System32\DRIVERS\DMICall.sys O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\System32\DRIVERS\i8042prt.sys O41 - Driver: (kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\System32\DRIVERS\kbdclass.sys O41 - Driver: (mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\System32\DRIVERS\mouclass.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: (netbt) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (PSched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\System32\DRIVERS\rasacd.sys O41 - Driver: (rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys O41 - Driver: (RDPENCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (Smb) . (.Microsoft Corporation - SMB Transport driver.) - C:\Windows\System32\DRIVERS\smb.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys ~ Drivers: 78 Scanned in 00mn 00s ---\\ Logiciels installés (O42) O42 - Logiciel: 7-Zip 9.20 - (...) [HKLM] -- 7-Zip O42 - Logiciel: ABBYY FineReader 9.0 Sprint - (.ABBYY.) [HKLM] -- ABBYY FineReader 9.0 Sprint O42 - Logiciel: ABBYY FineReader 9.0 Sprint - (.ABBYY.) [HKLM] -- {F9000000-0018-0000-0000-074957833700} O42 - Logiciel: Adobe Flash Player 11 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin O42 - Logiciel: Adobe Reader XI (11.0.02) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AB0000000001} O42 - Logiciel: Alps Pointing-device for VAIO - (...) [HKLM] -- {9F72EF8B-AEC9-4CA5-B483-143980AFD6FD} O42 - Logiciel: Atlantis - Sky Patrol - (...) [HKLM] -- Atlantis - Sky Patrol O42 - Logiciel: Big Fish Games Sudoku - (...) [HKLM] -- Big Fish Games Sudoku O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM] -- {1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF} O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner O42 - Logiciel: Centre de Big Fish Games - (...) [HKLM] -- Centre de Big Fish Games O42 - Logiciel: Click to DVD 2.0.05 Menu Data - (.Sony Corporation.) [HKLM] -- {9E407618-D9CD-4F39-9490-9ED45294073D} O42 - Logiciel: Click to DVD 2.6.00 - (.Sony Corporation.) [HKLM] -- {E809063C-51A3-4269-8984-D1EB742F2151} O42 - Logiciel: Complément Messenger - (.Microsoft Corporation.) [HKLM] -- {6E5324C1-84FC-4F76-9A3A-C65E07F80EE6} O42 - Logiciel: ConvertHelper 2.2 - (.DownloadHelper.) [HKLM] -- {27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1 O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} O42 - Logiciel: DivX Codec - (.DivX, Inc..) [HKLM] -- {7B63B2922B174135AFC0E1377DD81EC2} O42 - Logiciel: DivX Converter - (.DivX, Inc..) [HKLM] -- {B13A7C41581B411290FBC0395694E2A9} O42 - Logiciel: DivX Player - (.DivXNetworks, Inc..) [HKLM] -- {8ADFC4160D694100B5B8A22DE9DCABD9} O42 - Logiciel: Download Navigator - (.SEIKO EPSON CORPORATION.) [HKLM] -- {E728441A-7820-4B1C-87C9-DE7BE37B2953} O42 - Logiciel: EMET - (.Microsoft.) [HKLM] -- {DE7A5DDF-47B3-42FF-A082-E158DEA37392} O42 - Logiciel: EPSON SX440 Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM] -- EPSON SX440 Series O42 - Logiciel: EPSON Scan - (.Seiko Epson Corporation.) [HKLM] -- EPSON Scanner O42 - Logiciel: Epson Easy Photo Print 2 - (.SEIKO EPSON CORPORATION.) [HKLM] -- {FFF841F3-9A15-4F61-BD16-C19F132E5A27} O42 - Logiciel: Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) - (.SEIKO EPSON CORPORATION2.) [HKLM] -- {B2D55EB8-32C5-4B43-9006-9E97DECBA178} O42 - Logiciel: Epson Event Manager - (.SEIKO EPSON CORPORATION.) [HKLM] -- {8ED43F7E-A8F6-4898-AF11-B6158F2EDF94} O42 - Logiciel: EpsonNet Print - (.SEIKO EPSON CORPORATION.) [HKLM] -- {3E31400D-274E-4647-916C-2CACC3741799} O42 - Logiciel: FrameFox Extensions 1.0.1.0 - (.QwertyBox Team.) [HKLM] -- {052150E0-CE37-4C12-B9F1-C1F311C8E675} O42 - Logiciel: GearDrvs - (.Symantec Corporation.) [HKLM] -- {206FD69B-F9FE-4164-81BD-D52552BC9C23} O42 - Logiciel: Google Desktop - (.Google.) [HKLM] -- Google Desktop O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} O42 - Logiciel: Guide d'utilisation EPSON SX440 Series - (...) [HKLM] -- EPSON SX440 Series Useg O42 - Logiciel: Guide des opérations de base EPSON SX440 Series - (...) [HKLM] -- EPSON SX440 Series Bog O42 - Logiciel: Guide réseau EPSON SX440 Series - (...) [HKLM] -- EPSON SX440 Series Netg O42 - Logiciel: HDAUDIO SoftV92 Data Fax Modem with SmartCP - (...) [HKLM] -- CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200 O42 - Logiciel: ImageShack Uploader 2.2.0 - (.ImageShack Corp..) [HKLM] -- {8BCD7AE7-F713-4D50-BAB9-7839B9386870} O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (...) [HKLM] -- HDMI O42 - Logiciel: Java 7 Update 21 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83217017FF} O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4} O42 - Logiciel: Lecteur CANALPLAY 2.3 - (.Canal+ Active.) [HKLM] -- {E9E37358-E3E1-47BA-9E21-375EF3616BC9} O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} O42 - Logiciel: MSXML 4.0 SP2 (KB927978) - (.Microsoft Corporation.) [HKLM] -- {37477865-A3F1-4772-AD43-AAFC6BCFF99F} O42 - Logiciel: MSXML 4.0 SP2 (KB936181) - (.Microsoft Corporation.) [HKLM] -- {C04E32E0-0416-434D-AFB9-6969D703A9EF} O42 - Logiciel: MSXML 4.0 SP2 (KB941833) - (.Microsoft Corporation.) [HKLM] -- {C523D256-313D-4866-B36A-F3DE528246EF} O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71} O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC} O42 - Logiciel: MSXML 4.0 SP3 Parser (KB2721691) - (.Microsoft Corporation.) [HKLM] -- {355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36} O42 - Logiciel: MSXML 4.0 SP3 Parser (KB2758694) - (.Microsoft Corporation.) [HKLM] -- {1D95BA90-F4F8-47EC-A882-441C99D30C1E} O42 - Logiciel: MSXML 4.0 SP3 Parser - (.Microsoft Corporation.) [HKLM] -- {196467F1-C11F-4F76-858B-5812ADC83B94} O42 - Logiciel: Mahjong Towers Eternity - (...) [HKLM] -- Mahjong Towers Eternity O42 - Logiciel: Malwarebytes Anti-Malware version 1.75.0.1300 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1 O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E} O42 - Logiciel: Microsoft Camera Codec Pack - (.Microsoft Corporation.) [HKLM] -- {643318F0-6DC8-4DBA-B962-D5B74FE3677D} O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM] -- {6B1CB38D-E2E4-4a30-933D-EFDEBA76AD9C} O42 - Logiciel: Mozilla Firefox 20.0.1 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 20.0.1 (x86 fr) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService O42 - Logiciel: Mystery Case Files - Prime Suspects - (...) [HKLM] -- Mystery Case Files - Prime Suspects O42 - Logiciel: NATURABUY.fr : Logiciel de retouche photo - V2.0 - (.NATURABUY.FR.) [HKLM] -- NATURABUY.fr : Logiciel de retouche photo O42 - Logiciel: OpenMG Limited Patch 4.7-07-15-19-01 - (...) [HKLM] -- OpenMG HotFix4.7-07-13-22-01 O42 - Logiciel: OpenMG Secure Module 4.7.00 - (.Sony Corporation.) [HKLM] -- InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D} O42 - Logiciel: OpenOffice.org Installer 1.0 - (.Sun Microsystems.) [HKLM] -- {3A2AF807-9F9F-43C9-A24A-17B617238B74} O42 - Logiciel: Orange Player Communicator - (.video-a-la-demande.orange.fr.) [HKCU] -- 465758002.video-a-la-demande.orange.fr O42 - Logiciel: Orange Plug-in messagerie vocale 888 - (...) [HKLM] -- {16E79B1D-D1C2-4CA6-8B23-F4D890E0DCB9} O42 - Logiciel: Outil VAIO Media Registration 6.0 - (.Sony Corporation.) [HKLM] -- {AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6} O42 - Logiciel: Outil de restauration de données VAIO - (.Sony Corporation.) [HKLM] -- {57B955CE-B5D3-495D-AF1B-FAEE0540BFEF} O42 - Logiciel: PHOTOfunSTUDIO 5.0 - (.Panasonic Corporation.) [HKLM] -- {959282E3-55A9-49D8-B885-D27CF8A2FD82} O42 - Logiciel: Package de pilotes Windows - MobileTop (sshpmdm) Modem (01/26/2008 2.6.0.0 - (.MobileTop.) [HKLM] -- E24870CB6AA1C3511635FF9020A3E9471287FBE7 O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM] -- Picasa 3 O42 - Logiciel: PriceGong 2.6.11 - (.PriceGong.) [HKLM] -- PriceGong =>Adware.PriceGong O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} O42 - Logiciel: Revo Uninstaller 1.94 - (.VS Revo Group.) [HKLM] -- Revo Uninstaller O42 - Logiciel: Roxio Easy Media Creator Home - (.Roxio.) [HKLM] -- {B7FB0C86-41A4-4402-9A33-912C462042A0} O42 - Logiciel: SAMSUNG Android USB Modem Software - (...) [HKLM] -- SAMSUNG Android USB Modem O42 - Logiciel: SAMSUNG Mobile Composite Device Software - (...) [HKLM] -- SAMSUNG Mobile Composite Device O42 - Logiciel: SAMSUNG Mobile Modem Driver Set - (...) [HKLM] -- SAMSUNG Mobile Modem O42 - Logiciel: SAMSUNG Mobile Modem V2 Software - (...) [HKLM] -- SAMSUNG Mobile Modem V2 O42 - Logiciel: SAMSUNG Mobile USB Download Driver Software - (...) [HKLM] -- SAMSUNG Mobile USB Download Driver O42 - Logiciel: SAMSUNG Mobile USB Driver - (.SAMSUNG.) [HKLM] -- {7184F382-8A6C-4B85-A3AC-B63734B1E241} O42 - Logiciel: SAMSUNG Mobile USB Modem 1.0 Software - (...) [HKLM] -- SAMSUNG Mobile USB Modem 1.0 O42 - Logiciel: SAMSUNG Mobile USB Modem Software - (...) [HKLM] -- SAMSUNG Mobile USB Modem O42 - Logiciel: SAMSUNG USB Mobile Device Software - (...) [HKLM] -- SAMSUNG USB Mobile Device O42 - Logiciel: Samsung Mobile Modem Device Software - (...) [HKLM] -- Samsung Mobile Modem Device O42 - Logiciel: Samsung Mobile USB Modem Device Software - (...) [HKLM] -- Samsung Mobile USB Modem Device O42 - Logiciel: Samsung Mobile phone USB driver Software - (...) [HKLM] -- Samsung Mobile phone USB driver O42 - Logiciel: Samsung New PC Studio - (.Samsung Electronics Co., Ltd..) [HKLM] -- InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A} O42 - Logiciel: Samsung New PC Studio - (.Samsung Electronics Co., Ltd..) [HKLM] -- {F193FC0E-9E18-40FC-A974-509A1BDD240A} O42 - Logiciel: Secunia PSI (3.0.0.3001) - (.Secunia.) [HKLM] -- Secunia PSI O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- KB931906 O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- {0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM] -- {5DD4FCBD-A3C1-4155-9E17-4161C70AAABA} O42 - Logiciel: Setting Utility Series - (.Sony Corporation.) [HKLM] -- {A7DA438C-2E43-4C20-BFDA-C1F4A6208558} O42 - Logiciel: Skype™ 6.3 - (.Skype Technologies S.A..) [HKLM] -- {4E76FF7E-AEBA-4C87-B788-CD47E5425B9D} O42 - Logiciel: Software Version Updater - (...) [HKLM] -- {99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} O42 - Logiciel: SonicStage Mastering Studio - (.Sony Corporation.) [HKLM] -- {6332AFF1-9D9A-429C-AA03-F82749FA4F49} O42 - Logiciel: SonicStage Mastering Studio Audio Filter - (.Sony Corporation.) [HKLM] -- {DF7DB916-90E5-40F2-9010-B8125EB5FD6F} O42 - Logiciel: SonicStage Mastering Studio Audio Filter Custom Preset - (.Sony Corporation.) [HKLM] -- {EC37A846-53AC-4DA7-98FA-76A4E74AA900} O42 - Logiciel: SonicStage Mastering Studio Plugins - (.Sony Corporation.) [HKLM] -- {9C1C8A04-F8CA-4472-A92D-4288CE32DE86} O42 - Logiciel: Sony Video Shared Library - (.Sony Corporation.) [HKLM] -- {01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902} O42 - Logiciel: VAIO Aqua Breeze Wallpaper - (.Sony Corporation.) [HKLM] -- {97BCD719-6ECB-458F-97D6-F38D2E07375E} O42 - Logiciel: VAIO Content Folder Setting - (.Sony Corporation.) [HKLM] -- {23825B69-36DF-4DAD-9CFD-118D11D80F16} O42 - Logiciel: VAIO Content Importer / VAIO Content Exporter - (.Sony Corporation.) [HKLM] -- {68A69CFF-130D-4CDE-AB0E-7374ECB144C8} O42 - Logiciel: VAIO Content Metadata Intelligent Analyzing Manager - (.Sony Corporation.) [HKLM] -- {FAA6B94E-78A7-489C-B2DB-050D9FEBFADA} O42 - Logiciel: VAIO Content Metadata Manager Setting - (.Sony Corporation.) [HKLM] -- {69351E9E-23ED-41D5-B146-EDBF83C63B66} O42 - Logiciel: VAIO Content Metadata XML Interface Library - (.Sony Corporation.) [HKLM] -- {5F5DE5D5-D130-4110-A3A4-69FFB0B14BD9} O42 - Logiciel: VAIO Control Center - (.Sony Corporation.) [HKLM] -- {72042FA6-5609-489F-A8EA-3C2DD650F667} O42 - Logiciel: VAIO Cozy Orange Wallpaper - (.Sony Corporation.) [HKLM] -- {2A2FF7F5-6F0E-4A5D-A881-39365E718BD6} O42 - Logiciel: VAIO Entertainment Platform - (.Sony Corporation.) [HKLM] -- {6B1F20F2-6321-4669-A58C-33DF8E7517FF} O42 - Logiciel: VAIO Event Service - (.Sony Corporation.) [HKLM] -- {F0D85ADD-DD61-4B43-87A0-6DA52A211A8B} O42 - Logiciel: VAIO Launcher - (.Sony Corporation.) [HKLM] -- {15D5C238-4C2E-4AEA-A66D-D6989A4C586B} O42 - Logiciel: VAIO Media 6.0 - (.Sony Corporation.) [HKLM] -- {560F6B2E-F0DF-44E5-8190-A4A161F0E205} O42 - Logiciel: VAIO Media AC3 Decoder 1.0 - (...) [HKLM] -- {2063C2E8-3812-4BBD-9998-6610F80C1DD4} O42 - Logiciel: VAIO Media Content Collection 6.0 - (.Sony Corporation.) [HKLM] -- {500162A0-4DD5-460A-BAFD-895AAE48C532} O42 - Logiciel: VAIO Media Integrated Server 6.1 - (.Sony Corporation.) [HKLM] -- {785EB1D4-ECEC-4195-99B4-73C47E187721} O42 - Logiciel: VAIO Media Redistribution 6.0 - (.Sony Corporation.) [HKLM] -- {5855C127-1F20-404D-B7FB-1FD84D7EAB5E} O42 - Logiciel: VAIO Movie Story - (.Sony Corporation.) [HKLM] -- {B25563A0-41F4-4A81-A6C1-6DBC0911B1F3} O42 - Logiciel: VAIO Movie Story Template Data - (.Sony Corporation.) [HKLM] -- {6FA8BA2C-052B-4072-B8E2-2302C268BE9E} O42 - Logiciel: VAIO MusicBox - (.Sony Corporation.) [HKLM] -- {4EA55D20-27FB-45D7-8726-147E8A5F6C62} O42 - Logiciel: VAIO MusicBox Sample Music - (.Sony Corporation.) [HKLM] -- {98FC7A64-774B-49B5-B046-4B4EBC053FA9} O42 - Logiciel: VAIO Original Function Setting - (.Sony Corporation.) [HKLM] -- {A63E7492-A0BC-4BB9-89A7-352965222380} O42 - Logiciel: VAIO Power Management - (.Sony Corporation.) [HKLM] -- {802889F8-6AF5-45A5-9764-CA5B999E50FC} O42 - Logiciel: VAIO Smart Network - (.Sony Corporation.) [HKLM] -- {3B659FAD-E772-44A3-B7E7-560FF084669F} O42 - Logiciel: VAIO Tender Green Wallpaper - (.Sony Corporation.) [HKLM] -- {934A3213-1CB6-4264-84A2-EE080C017BCA} O42 - Logiciel: VAIO Update 3 - (.Sony Corporation.) [HKLM] -- {48820099-ED7D-424B-890C-9A82EF00656D} O42 - Logiciel: VLC media player 2.0.6 - (.VideoLAN.) [HKLM] -- VLC media player O42 - Logiciel: VSO Image Resizer 3.0.1.72 - (.VSO-Software.) [HKLM] -- {3EE51BAD-9916-49C7-90BA-3D500B031E0C}_is1 O42 - Logiciel: Virtual Villagers - (...) [HKLM] -- Virtual Villagers O42 - Logiciel: VirtualCom driver - (.AIT.) [HKLM] -- {1943A043-5C85-4A16-A0D0-D687B2C1A40F} O42 - Logiciel: WhoCrashed 3.06 - (.Resplendence Software Projects Sp..) [HKLM] -- WhoCrashed_is1 O42 - Logiciel: WinDVD for VAIO - (.InterVideo Inc..) [HKLM] -- InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85} O42 - Logiciel: Windows Media Player Firefox Plugin - (.Microsoft Corp.) [HKLM] -- {69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} O42 - Logiciel: avast! Free Antivirus v8.0.1483.0 - (.AVAST Software.) [HKLM] -- avast ~ Logic: 200 Scanned in 00mn 00s ---\\ HKCU & HKLM Software Keys [HKCU\Software\7-Zip] [HKCU\Software\ABBYY] [HKCU\Software\ALWIL Software] [HKCU\Software\APEXOFT] [HKCU\Software\AVAST Software] [HKCU\Software\Adobe] [HKCU\Software\Alps] [HKCU\Software\AppDataLow\Software\JavaSoft] [HKCU\Software\AppDataLow\Software\PriceGong] =>Adware.PriceGong [HKCU\Software\AppDataLow] [HKCU\Software\Atlantis - Sky Patrol] [HKCU\Software\BAE] [HKCU\Software\Canal+ Active] [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\Digital River] [HKCU\Software\DivXNetworks] [HKCU\Software\Duuqu] [HKCU\Software\EPSON] [HKCU\Software\FRANCE TELECOM] [HKCU\Software\Google] [HKCU\Software\HookNetwork] [HKCU\Software\IM Providers] [HKCU\Software\ImageShack Corp.] [HKCU\Software\ImageShack] [HKCU\Software\Iminent] =>Adware.IMBooster [HKCU\Software\Intel] [HKCU\Software\InterVideo] [HKCU\Software\JEDI-VCL] [HKCU\Software\JavaSoft] [HKCU\Software\Lake] [HKCU\Software\Local AppWizard-Generated Applications] [HKCU\Software\Macromedia] [HKCU\Software\Mahjong Towers Eternity] [HKCU\Software\Malwarebytes' Anti-Malware] [HKCU\Software\MimarSinan] [HKCU\Software\Mobileleader] [HKCU\Software\Mozilla] [HKCU\Software\Mystery Case Files - Prime Suspects] [HKCU\Software\Netscape] [HKCU\Software\ODBC] [HKCU\Software\ObviousIdea] [HKCU\Software\Panasonic] [HKCU\Software\Piriform] [HKCU\Software\Policies] [HKCU\Software\PowerPack] [HKCU\Software\Realtek] [HKCU\Software\Resplendence Sp] [HKCU\Software\Roxio] [HKCU\Software\SEIKO EPSON CORPORATION] [HKCU\Software\SFR] [HKCU\Software\Samsung] [HKCU\Software\Secunia] [HKCU\Software\Skype] [HKCU\Software\SoftVTU] [HKCU\Software\Sonic] [HKCU\Software\Sony Corporation] [HKCU\Software\Sun Microsystems] [HKCU\Software\SysInternals] [HKCU\Software\Trolltech] [HKCU\Software\VB and VBA Program Settings] [HKCU\Software\VSO] [HKCU\Software\VSRevoGroup] [HKCU\Software\Virtual Villagers] [HKCU\Software\YahooPartnerToolbar] [HKCU\Software\ZebHelpProcess Helper] [HKCU\Software\delta LTD] [HKLM\Software\ABBYY] [HKLM\Software\ALWIL Software] [HKLM\Software\AVAST Software] [HKLM\Software\Adobe] [HKLM\Software\Alps] [HKLM\Software\Babylon] =>Toolbar.Babylon [HKLM\Software\CDDB] [HKLM\Software\CXT] [HKLM\Software\Canal+ Active] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\Conexant Systems Inc ] [HKLM\Software\Conexant] [HKLM\Software\Debug] [HKLM\Software\DivXNetworks] [HKLM\Software\DownloadHelper] [HKLM\Software\Duuqu] [HKLM\Software\EPSON] [HKLM\Software\EpsonNet] [HKLM\Software\Google] [HKLM\Software\IM Providers] [HKLM\Software\Iminent] =>Adware.IMBooster [HKLM\Software\InstallShield] [HKLM\Software\Intel] [HKLM\Software\InterVideo] [HKLM\Software\JavaRa] [HKLM\Software\JavaSoft] [HKLM\Software\JreMetrics] [HKLM\Software\MCCI] [HKLM\Software\Macromedia] [HKLM\Software\Malwarebytes' Anti-Malware] [HKLM\Software\MarkAny] [HKLM\Software\MimarSinan] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\Nikon] [HKLM\Software\ODBC] [HKLM\Software\ObviousIdea] [HKLM\Software\Orange] [HKLM\Software\Panasonic] [HKLM\Software\Piriform] [HKLM\Software\Policies] [HKLM\Software\Realtek Semiconductor Corp.] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\Roxio] [HKLM\Software\S3R521] [HKLM\Software\SEIKO EPSON CORPORATION2] [HKLM\Software\SEIKO EPSON CORPORATION] [HKLM\Software\SFR] [HKLM\Software\SRS Labs] [HKLM\Software\Samsung] [HKLM\Software\Secunia] [HKLM\Software\Skype] [HKLM\Software\Sonic] [HKLM\Software\Sony Corporation] [HKLM\Software\Sony] [HKLM\Software\Sun Microsystems] [HKLM\Software\SymNRT] [HKLM\Software\Symantec] [HKLM\Software\TrendMicro] [HKLM\Software\Unisys Corporation] [HKLM\Software\VideoLAN] [HKLM\Software\VirtualVillagers] [HKLM\Software\Volatile] [HKLM\Software\Windows] [HKLM\Software\Xerox] [HKLM\Software\Yahoo] [HKLM\Software\illiminable] [HKLM\Software\mozilla.org] [HKLM\Software\vso] ~ Key Software: 212 Scanned in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 30/12/2011 - 16:47:25 - [172,780] ----D C:\Program Files\ABBYY FineReader 9.0 Sprint O43 - CFD: 21/06/2008 - 00:07:58 - [0,000] ----D C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites O43 - CFD: 19/10/2012 - 10:47:02 - [119,532] ----D C:\Program Files\Adobe O43 - CFD: 03/08/2007 - 10:26:01 - [2,764] ----D C:\Program Files\Apoint O43 - CFD: 10/10/2012 - 22:47:58 - [328,363] ----D C:\Program Files\AVAST Software O43 - CFD: 03/08/2007 - 12:00:58 - [0,316] ----D C:\Program Files\BFG O43 - CFD: 23/02/2013 - 12:38:32 - [5,071] ----D C:\Program Files\CCleaner O43 - CFD: 28/01/2011 - 17:17:54 - [0,413] ----D C:\Program Files\Club-Internet O43 - CFD: 19/04/2013 - 16:22:05 - [664,129] ----D C:\Program Files\Common Files O43 - CFD: 03/08/2007 - 10:11:32 - [1,012] ----D C:\Program Files\CONEXANT O43 - CFD: 08/03/2013 - 18:17:00 - [29,417] ----D C:\Program Files\ConvertHelper O43 - CFD: 13/05/2011 - 20:49:36 - [0,757] ----D C:\Program Files\DIFX O43 - CFD: 03/08/2007 - 12:01:54 - [45,021] ----D C:\Program Files\DivX O43 - CFD: 19/04/2013 - 15:49:29 - [2,121] ----D C:\Program Files\Duuqu O43 - CFD: 23/09/2012 - 11:47:29 - [11,403] ----D C:\Program Files\EMET O43 - CFD: 29/12/2011 - 19:40:23 - [7,907] ----D C:\Program Files\epson O43 - CFD: 29/12/2011 - 19:45:34 - [108,317] ----D C:\Program Files\EPSON Software O43 - CFD: 29/12/2011 - 19:38:40 - [4,367] ----D C:\Program Files\EpsonNet O43 - CFD: 02/08/2007 - 17:16:13 - [0] ----D C:\Program Files\Fichiers communs O43 - CFD: 12/10/2012 - 00:22:48 - [0,000] ----D C:\Program Files\FileHippo.com O43 - CFD: 19/04/2013 - 15:50:04 - [0,227] ----D C:\Program Files\FrameFox O43 - CFD: 03/03/2013 - 16:42:11 - [29,166] ----D C:\Program Files\Google O43 - CFD: 28/07/2008 - 00:29:37 - [0,000] ----D C:\Program Files\Google BAE O43 - CFD: 13/05/2012 - 23:56:12 - [26,352] ----D C:\Program Files\ImageShack Uploader O43 - CFD: 03/08/2007 - 10:04:44 - [0,062] ----D C:\Program Files\Intel O43 - CFD: 10/04/2013 - 10:10:17 - [5,866] ----D C:\Program Files\Internet Explorer O43 - CFD: 20/06/2008 - 22:27:41 - [138,223] ----D C:\Program Files\InterVideo O43 - CFD: 18/04/2013 - 12:22:02 - [122,342] ----D C:\Program Files\Java O43 - CFD: 01/09/2008 - 17:23:13 - [11,993] ----D C:\Program Files\Lecteur CANALPLAY O43 - CFD: 11/04/2013 - 18:50:50 - [13,360] ----D C:\Program Files\Malwarebytes' Anti-Malware O43 - CFD: 16/08/2012 - 18:13:18 - [0,211] ----D C:\Program Files\MarkAny O43 - CFD: 23/03/2011 - 21:19:38 - [41,136] ----D C:\Program Files\Microsoft O43 - CFD: 25/07/2008 - 10:45:31 - [0,764] ----D C:\Program Files\Microsoft CAPICOM 2.1.0.2 O43 - CFD: 02/11/2006 - 14:37:34 - [89,117] ----D C:\Program Files\Microsoft Games O43 - CFD: 30/06/2011 - 15:22:38 - [282,271] ----D C:\Program Files\Microsoft Office O43 - CFD: 14/03/2013 - 01:23:56 - [40,835] ----D C:\Program Files\Microsoft Silverlight O43 - CFD: 21/10/2010 - 16:48:38 - [3,999] ----D C:\Program Files\Microsoft SQL Server Compact Edition O43 - CFD: 23/08/2010 - 17:52:51 - [0,331] ----D C:\Program Files\Microsoft Synchronization Services O43 - CFD: 14/10/2009 - 17:55:18 - [143,671] ----D C:\Program Files\Microsoft Works O43 - CFD: 23/06/2010 - 20:47:05 - [0,316] ----D C:\Program Files\Microsoft.NET O43 - CFD: 12/08/2010 - 20:24:31 - [94,740] ----D C:\Program Files\Movie Maker O43 - CFD: 11/04/2013 - 23:19:47 - [48,036] ----D C:\Program Files\Mozilla Firefox O43 - CFD: 18/04/2013 - 12:09:40 - [0,212] ----D C:\Program Files\Mozilla Maintenance Service O43 - CFD: 02/11/2006 - 14:37:34 - [0,025] ----D C:\Program Files\MSBuild O43 - CFD: 03/09/2012 - 11:20:31 - [55,014] ----D C:\Program Files\MSECache O43 - CFD: 03/09/2012 - 11:10:02 - [0,147] ----D C:\Program Files\MSXML 4.0 O43 - CFD: 19/04/2013 - 15:45:07 - [12,920] ----D C:\Program Files\ObviousIdea O43 - CFD: 01/02/2010 - 14:10:08 - [1,141] ----D C:\Program Files\Orange O43 - CFD: 23/08/2010 - 18:03:54 - [83,292] ----D C:\Program Files\Panasonic O43 - CFD: 19/04/2013 - 14:34:39 - [100,220] ----D C:\Program Files\Picasa2 O43 - CFD: 19/04/2013 - 15:51:00 - [0,691] ----D C:\Program Files\PriceGong =>Adware.PriceGong O43 - CFD: 03/08/2007 - 10:28:35 - [14,790] ----D C:\Program Files\Realtek O43 - CFD: 02/11/2006 - 14:37:34 - [36,910] ----D C:\Program Files\Reference Assemblies O43 - CFD: 20/06/2008 - 22:10:04 - [10,569] ----D C:\Program Files\Roxio O43 - CFD: 13/05/2011 - 21:01:40 - [299,577] ----D C:\Program Files\Samsung O43 - CFD: 03/09/2012 - 00:18:51 - [10,625] ----D C:\Program Files\Secunia O43 - CFD: 18/12/2009 - 10:59:47 - [57,636] ----D C:\Program Files\Securitoo O43 - CFD: 24/03/2013 - 11:28:54 - [18,033] R---D C:\Program Files\Skype O43 - CFD: 20/06/2008 - 22:30:28 - [592,379] ----D C:\Program Files\Sony O43 - CFD: 22/07/2008 - 21:08:19 - [2,430] ----D C:\Program Files\Sun O43 - CFD: 03/03/2011 - 19:10:43 - [0,765] ----D C:\Program Files\trend micro O43 - CFD: 02/11/2006 - 15:01:55 - [0] --H-D C:\Program Files\Uninstall Information O43 - CFD: 03/09/2012 - 15:47:24 - [101,902] ----D C:\Program Files\VideoLAN O43 - CFD: 25/09/2012 - 13:05:32 - [6,499] ----D C:\Program Files\VS Revo Group O43 - CFD: 03/03/2010 - 22:21:50 - [26,849] ----D C:\Program Files\VSO O43 - CFD: 12/10/2012 - 10:34:03 - [6,017] ----D C:\Program Files\WhoCrashed O43 - CFD: 05/06/2009 - 15:46:09 - [0,970] ----D C:\Program Files\Windows Calendar O43 - CFD: 05/06/2009 - 15:46:09 - [2,610] ----D C:\Program Files\Windows Collaboration O43 - CFD: 05/06/2009 - 15:46:06 - [4,283] ----D C:\Program Files\Windows Defender O43 - CFD: 13/05/2012 - 00:24:23 - [6,757] ----D C:\Program Files\Windows Journal O43 - CFD: 19/04/2013 - 16:22:03 - [156,209] ----D C:\Program Files\Windows Live O43 - CFD: 12/04/2012 - 11:00:59 - [8,694] ----D C:\Program Files\Windows Mail O43 - CFD: 13/10/2010 - 20:26:33 - [4,290] ----D C:\Program Files\Windows Media Player O43 - CFD: 02/08/2007 - 17:16:13 - [7,589] ----D C:\Program Files\Windows NT O43 - CFD: 05/06/2009 - 15:46:08 - [12,902] ----D C:\Program Files\Windows Photo Gallery O43 - CFD: 29/10/2009 - 22:03:10 - [0,128] ----D C:\Program Files\Windows Portable Devices O43 - CFD: 11/04/2011 - 23:40:17 - [6,426] ----D C:\Program Files\Windows Sidebar O43 - CFD: 19/04/2013 - 17:05:25 - [16,633] ----D C:\Program Files\ZHPDiag O43 - CFD: 29/12/2011 - 19:49:25 - [7,724] ----D C:\Program Files\Common Files\ABBYY O43 - CFD: 19/10/2012 - 10:47:08 - [6,379] ----D C:\Program Files\Common Files\Adobe O43 - CFD: 21/06/2008 - 01:19:15 - [0,082] ----D C:\Program Files\Common Files\DESIGNER O43 - CFD: 30/12/2011 - 16:49:13 - [1,878] ----D C:\Program Files\Common Files\EPSON O43 - CFD: 20/06/2008 - 22:18:28 - [11,907] ----D C:\Program Files\Common Files\InstallShield O43 - CFD: 18/04/2013 - 12:22:49 - [1,189] ----D C:\Program Files\Common Files\Java O43 - CFD: 22/09/2012 - 17:47:20 - [391,456] ----D C:\Program Files\Common Files\microsoft shared O43 - CFD: 23/08/2010 - 17:53:39 - [0,567] ----D C:\Program Files\Common Files\Panasonic O43 - CFD: 03/08/2007 - 12:01:51 - [3,745] ----D C:\Program Files\Common Files\PX Storage Engine O43 - CFD: 20/06/2008 - 22:10:20 - [33,966] ----D C:\Program Files\Common Files\Roxio Shared O43 - CFD: 02/11/2006 - 13:18:33 - [0,003] ----D C:\Program Files\Common Files\Services O43 - CFD: 24/03/2013 - 11:28:54 - [1,904] ----D C:\Program Files\Common Files\Skype O43 - CFD: 20/06/2008 - 22:10:20 - [6,392] ----D C:\Program Files\Common Files\Sonic Shared O43 - CFD: 20/06/2008 - 22:18:28 - [106,487] ----D C:\Program Files\Common Files\Sony Shared O43 - CFD: 02/11/2006 - 13:18:33 - [39,198] ----D C:\Program Files\Common Files\SpeechEngines O43 - CFD: 07/11/2008 - 16:47:17 - [0,433] ----D C:\Program Files\Common Files\Symantec Shared O43 - CFD: 09/11/2011 - 17:08:50 - [15,329] ----D C:\Program Files\Common Files\System O43 - CFD: 12/11/2009 - 18:20:58 - [0] ----D C:\Program Files\Common Files\Windows Live O43 - CFD: 25/07/2008 - 23:30:47 - [35,491] -SH-D C:\Program Files\Common Files\WindowsLiveInstaller O43 - CFD: 29/12/2011 - 19:49:26 - [1,827] ----D C:\ProgramData\ABBYY O43 - CFD: 10/04/2013 - 09:45:01 - [129,044] ----D C:\ProgramData\Adobe O43 - CFD: 02/11/2006 - 15:02:03 - [0] --H-D C:\ProgramData\Application Data O43 - CFD: 10/10/2012 - 22:47:58 - [22,278] ----D C:\ProgramData\AVAST Software O43 - CFD: 19/04/2013 - 15:50:56 - [0] ----D C:\ProgramData\Babylon =>Toolbar.Babylon O43 - CFD: 02/08/2007 - 17:16:13 - [0] --H-D C:\ProgramData\Bureau O43 - CFD: 02/11/2006 - 15:02:03 - [0] --H-D C:\ProgramData\Desktop O43 - CFD: 02/11/2006 - 15:02:03 - [0] --H-D C:\ProgramData\Documents O43 - CFD: 30/12/2011 - 17:49:23 - [8,331] ----D C:\ProgramData\EPSON O43 - CFD: 02/08/2007 - 17:16:13 - [0] --H-D C:\ProgramData\Favoris O43 - CFD: 02/11/2006 - 15:02:03 - [0] --H-D C:\ProgramData\Favorites O43 - CFD: 07/11/2008 - 19:35:59 - [0,014] ----D C:\ProgramData\Google O43 - CFD: 30/01/2010 - 22:06:00 - [15,904] ----D C:\ProgramData\Malwarebytes O43 - CFD: 02/08/2007 - 17:16:13 - [0] --H-D C:\ProgramData\Menu Démarrer O43 - CFD: 23/03/2011 - 21:20:09 - [176,991] -S--D C:\ProgramData\Microsoft O43 - CFD: 20/06/2008 - 23:45:28 - [0,054] ----D C:\ProgramData\Microsoft Help O43 - CFD: 02/08/2007 - 17:16:13 - [0] --H-D C:\ProgramData\Modèles O43 - CFD: 25/04/2012 - 17:00:36 - [0,034] ----D C:\ProgramData\Mozilla O43 - CFD: 23/08/2010 - 18:46:46 - [3,662] ----D C:\ProgramData\Panasonic O43 - CFD: 12/07/2012 - 18:41:59 - [0] ----D C:\ProgramData\Roxio O43 - CFD: 13/05/2011 - 21:01:20 - [0,177] ----D C:\ProgramData\Samsung O43 - CFD: 24/03/2013 - 11:29:11 - [52,992] ----D C:\ProgramData\Skype O43 - CFD: 20/06/2008 - 22:10:28 - [0,001] ----D C:\ProgramData\Sonic O43 - CFD: 03/08/2007 - 12:01:32 - [13,791] ----D C:\ProgramData\Sony O43 - CFD: 31/10/2009 - 23:29:17 - [927,412] ----D C:\ProgramData\Sony Corporation O43 - CFD: 02/11/2006 - 15:02:03 - [0] --H-D C:\ProgramData\Start Menu O43 - CFD: 11/02/2010 - 22:13:49 - [0,000] ----D C:\ProgramData\Sun O43 - CFD: 02/11/2006 - 15:02:04 - [0] --H-D C:\ProgramData\Templates O43 - CFD: 29/12/2011 - 19:45:58 - [0,004] ----D C:\ProgramData\UDL O43 - CFD: 20/06/2008 - 22:18:32 - [0] ----D C:\ProgramData\VAIO Media Platform O43 - CFD: 07/11/2008 - 19:08:11 - [4,729] ----D C:\ProgramData\WLInstaller O43 - CFD: 30/07/2012 - 00:17:58 - [0,002] ----D C:\ProgramData\Xerox O43 - CFD: 28/01/2011 - 19:06:39 - [12,158] ----D C:\Users\serge\AppData\Roaming\Adobe O43 - CFD: 19/04/2013 - 15:50:55 - [0,005] ----D C:\Users\serge\AppData\Roaming\Babylon =>Toolbar.Babylon O43 - CFD: 04/02/2013 - 18:19:18 - [0,000] ----D C:\Users\serge\AppData\Roaming\dvdcss O43 - CFD: 31/12/2011 - 20:04:34 - [1,336] ----D C:\Users\serge\AppData\Roaming\EPSON O43 - CFD: 21/06/2008 - 01:03:15 - [0] ----D C:\Users\serge\AppData\Roaming\Google O43 - CFD: 02/08/2007 - 17:18:30 - [0] ----D C:\Users\serge\AppData\Roaming\Identities O43 - CFD: 23/08/2010 - 17:55:44 - [0] ----D C:\Users\serge\AppData\Roaming\InstallShield O43 - CFD: 29/09/2008 - 11:37:07 - [0] ----D C:\Users\serge\AppData\Roaming\InterVideo O43 - CFD: 21/06/2008 - 01:03:03 - [0,000] ----D C:\Users\serge\AppData\Roaming\Macromedia O43 - CFD: 30/01/2010 - 22:06:07 - [0,066] ----D C:\Users\serge\AppData\Roaming\Malwarebytes O43 - CFD: 02/11/2006 - 14:37:34 - [0] ----D C:\Users\serge\AppData\Roaming\Media Center Programs O43 - CFD: 14/07/2012 - 16:03:39 - [4,260] -S--D C:\Users\serge\AppData\Roaming\Microsoft O43 - CFD: 23/01/2009 - 16:32:32 - [57,751] ----D C:\Users\serge\AppData\Roaming\Mozilla O43 - CFD: 16/11/2008 - 01:06:12 - [0] ----D C:\Users\serge\AppData\Roaming\PeerNetworking O43 - CFD: 21/06/2008 - 00:21:17 - [0] ----D C:\Users\serge\AppData\Roaming\Roxio O43 - CFD: 13/05/2011 - 20:47:45 - [3,214] ----D C:\Users\serge\AppData\Roaming\Samsung O43 - CFD: 18/10/2009 - 18:16:15 - [0,175] ----D C:\Users\serge\AppData\Roaming\SFR O43 - CFD: 17/04/2013 - 21:01:28 - [8,793] ----D C:\Users\serge\AppData\Roaming\Skype O43 - CFD: 08/07/2012 - 21:24:04 - [0,000] ----D C:\Users\serge\AppData\Roaming\Sony Corporation O43 - CFD: 22/07/2008 - 21:16:47 - [0,008] ----D C:\Users\serge\AppData\Roaming\Template O43 - CFD: 19/04/2013 - 14:53:06 - [0,463] ----D C:\Users\serge\AppData\Roaming\vlc O43 - CFD: 18/04/2013 - 15:35:04 - [0,071] ----D C:\Users\serge\AppData\Roaming\VSO O43 - CFD: 14/10/2012 - 17:27:31 - [0] ----D C:\Users\serge\AppData\Roaming\Windows Live Writer O43 - CFD: 29/12/2011 - 20:00:53 - [1,834] ----D C:\Users\serge\AppData\Local\ABBYY O43 - CFD: 28/01/2011 - 19:04:46 - [33,418] ----D C:\Users\serge\AppData\Local\Adobe O43 - CFD: 20/06/2008 - 23:04:51 - [0] ----D C:\Users\serge\AppData\Local\Application Data O43 - CFD: 19/04/2013 - 15:51:10 - [2,306] ----D C:\Users\serge\AppData\Local\Babylon =>Toolbar.Babylon O43 - CFD: 13/05/2011 - 20:43:16 - [122,223] ----D C:\Users\serge\AppData\Local\Downloaded Installations O43 - CFD: 19/04/2013 - 15:49:28 - [0] ----D C:\Users\serge\AppData\Local\Duuqu O43 - CFD: 12/10/2012 - 00:09:01 - [885,163] ----D C:\Users\serge\AppData\Local\Google O43 - CFD: 20/06/2008 - 23:04:51 - [0] ----D C:\Users\serge\AppData\Local\Historique O43 - CFD: 23/06/2012 - 15:37:34 - [0] ----D C:\Users\serge\AppData\Local\Macromedia O43 - CFD: 14/10/2012 - 17:27:01 - [632,382] ----D C:\Users\serge\AppData\Local\Microsoft O43 - CFD: 03/08/2007 - 11:55:00 - [0] ----D C:\Users\serge\AppData\Local\Microsoft Help O43 - CFD: 21/06/2008 - 01:29:50 - [50,320] ----D C:\Users\serge\AppData\Local\Mozilla O43 - CFD: 23/08/2010 - 17:56:17 - [1,265] ----D C:\Users\serge\AppData\Local\Panasonic O43 - CFD: 03/09/2012 - 11:01:52 - [0] ----D C:\Users\serge\AppData\Local\Secunia PSI O43 - CFD: 03/08/2007 - 11:59:09 - [0,272] ----D C:\Users\serge\AppData\Local\Seven Zip O43 - CFD: 19/04/2013 - 15:50:12 - [0,289] ----D C:\Users\serge\AppData\Local\SwvUpdater O43 - CFD: 20/06/2008 - 23:39:09 - [0,001] ----D C:\Users\serge\AppData\Local\Symantec_Corporation O43 - CFD: 19/04/2013 - 17:04:19 - [74,620] ----D C:\Users\serge\AppData\Local\Temp O43 - CFD: 20/06/2008 - 23:04:51 - [0] ----D C:\Users\serge\AppData\Local\Temporary Internet Files O43 - CFD: 11/08/2008 - 18:25:39 - [0,362] ----D C:\Users\serge\AppData\Local\VirtualStore O43 - CFD: 03/03/2010 - 22:22:45 - [0,000] ----D C:\Users\serge\AppData\Local\VSO O43 - CFD: 14/10/2012 - 17:27:02 - [0,219] ----D C:\Users\serge\AppData\Local\Windows Live O43 - CFD: 14/10/2012 - 17:27:39 - [0,618] ----D C:\Users\serge\AppData\Local\Windows Live Writer O43 - CFD: 02/11/2006 - 14:54:36 - [0,014] R---D C:\Users\serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 02/08/2007 - 17:18:39 - [0,000] R---D C:\Users\serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 23/09/2012 - 11:47:29 - [0,004] ----D C:\Users\serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Enhanced Mitigation Experience Toolkit O43 - CFD: 29/12/2011 - 19:37:38 - [0,001] ----D C:\Users\serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EPSON Software O43 - CFD: 02/11/2006 - 14:50:41 - [0,001] R---D C:\Users\serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 07/07/2012 - 17:15:26 - [0] ----D C:\Users\serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NATURABUY - Photos O43 - CFD: 25/09/2012 - 13:05:34 - [0,004] ----D C:\Users\serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller O43 - CFD: 02/08/2007 - 17:18:39 - [0,000] R---D C:\Users\serge\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup ~ 83 Dossiers CLSID vides (CLSID Empty Folders) ~ Program Folder: 266 Scanned in 00mn 25s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.12B88221EE4245393B99BA9D880F26A0] - 19/04/2013 - 15:35:43 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1274477] O44 - LFC:[MD5.02CFC3AD44FA2D9CCCB73FF13696FE7E] - 19/04/2013 - 15:35:35 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1495948] O44 - LFC:[MD5.10B4ACCA7ABEECC63AEA3DC8C4A4A839] - 19/04/2013 - 15:35:35 ---A- . (...) -- C:\Windows\System32\perfc009.dat [104070] O44 - LFC:[MD5.955079A6E15DF7585A3A02C8FADD65AA] - 19/04/2013 - 15:35:35 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [126626] O44 - LFC:[MD5.4EC62F3FFD0E69710E1F8CF8368A01ED] - 19/04/2013 - 15:35:35 ---A- . (...) -- C:\Windows\System32\perfh009.dat [595996] O44 - LFC:[MD5.E2B1AB3234F8A993A7D894110CBAF903] - 19/04/2013 - 15:35:35 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [679042] O44 - LFC:[MD5.DF1349E79AEC42FA57C57F7C5A64DB09] - 19/04/2013 - 15:26:38 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.9FB79CE3EFBEABC2CEB06C00E63595E0] - 19/04/2013 - 15:26:16 ---A- . (...) -- C:\Windows\PFRO.log [3048] O44 - LFC:[MD5.444C17D4E51CAA49D47F5DF6FD8D2472] - 19/04/2013 - 15:22:02 ---A- . (...) -- C:\Windows\System32\InstallUtil.InstallLog [1833] O44 - LFC:[MD5.01C47C2ECED034EF6F8C1552A97CFF00] - 19/04/2013 - 14:13:45 ---A- . (...) -- C:\Windows\System32\config.nt [2577] O44 - LFC:[MD5.CA9D5826A58411E0095BA6D41E31FF9B] - 18/04/2013 - 11:22:02 ---A- . (...) -- C:\Windows\System32\jupdate-1.7.0_21-b11.log [4003] O44 - LFC:[MD5.091C84FE9C2A2C4AE1F30AC7C6A4BDD1] - 18/04/2013 - 11:22:02 ---A- . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Windows\System32\java.exe [174496] O44 - LFC:[MD5.AE5F5021FC66A380FD46B17A3E30E8E8] - 18/04/2013 - 11:22:02 ---A- . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Windows\System32\javaw.exe [174496] O44 - LFC:[MD5.D0F47BFDDE810912F65E079B5956D6C7] - 18/04/2013 - 11:22:02 ---A- . (.Oracle Corporation - Pas de description.) -- C:\Windows\System32\WindowsAccessBridge.dll [94112] O44 - LFC:[MD5.D42274E3477D623931F663D818812461] - 10/04/2013 - 09:15:28 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [375136] O44 - LFC:[MD5.2E56BA5BC215B2AED2B790D42D8C1739] - 10/04/2013 - 09:06:25 ---A- . (.Microsoft Corporation - Microsoft® MSHTML Typelib.) -- C:\Windows\System32\mshtml.tlb [2382848] O44 - LFC:[MD5.507183B4FCB535A7A973427D1F367CA8] - 10/04/2013 - 09:06:24 ---A- . (.Microsoft Corporation - Microsoft ® VBScript.) -- C:\Windows\System32\vbscript.dll [420864] O44 - LFC:[MD5.40169F9AE27BB73F2CB8C7D11A7A2AC2] - 10/04/2013 - 09:06:24 ---A- . (.Microsoft Corporation - Microsoft® HTML Editing Component.) -- C:\Windows\System32\mshtmled.dll [73216] O44 - LFC:[MD5.4BE468D2EE9CC59CB8F666949CD37CD5] - 10/04/2013 - 09:06:21 ---A- . (.Microsoft Corporation - JScript Proxy Auto-Configuration.) -- C:\Windows\System32\jsproxy.dll [65024] O44 - LFC:[MD5.C720BD3BDE2C9A1BFC4476F6D3A4B64D] - 10/04/2013 - 09:06:21 ---A- . (.Microsoft Corporation - Moteur de l’interface utilisateur d’Interne.) -- C:\Windows\System32\ieui.dll [176640] O44 - LFC:[MD5.FC5BBA40E667D20126D91BD6A790705B] - 10/04/2013 - 09:06:21 ---A- . (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) -- C:\Windows\System32\ieUnatt.exe [142848] O44 - LFC:[MD5.9DE04A790F697432871E88BB77EEBCF5] - 10/04/2013 - 09:06:20 ---A- . (.Microsoft Corporation - Microsoft Feeds Manager.) -- C:\Windows\System32\msfeeds.dll [607744] O44 - LFC:[MD5.C5B6468422DB1C8AA36C32CBB0197E5E] - 10/04/2013 - 09:06:19 ---A- . (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [1129472] O44 - LFC:[MD5.26DB6CB9BC434ABA1169B3051E6AB4F2] - 10/04/2013 - 09:06:18 ---A- . (.Microsoft Corporation - Microsoft (R) JScript.) -- C:\Windows\System32\jscript.dll [717824] O44 - LFC:[MD5.7E6052699CAF18ADEDD846D44ECCE81F] - 10/04/2013 - 09:06:17 ---A- . (.Microsoft Corporation - Microsoft (R) JScript.) -- C:\Windows\System32\jscript9.dll [1800704] O44 - LFC:[MD5.69EDE878C3891E7796D46B7E552330B1] - 10/04/2013 - 09:06:16 ---A- . (.Microsoft Corporation - Internet Shortcut Shell Extension DLL.) -- C:\Windows\System32\url.dll [231936] O44 - LFC:[MD5.9BDDA34DC4890169DE5BA21134B33EFB] - 10/04/2013 - 09:06:15 ---A- . (.Microsoft Corporation - Run time utility for Internet Explorer.) -- C:\Windows\System32\iertutil.dll [1796096] O44 - LFC:[MD5.4E7F83E1F6AEFA38E270EA7353D6911E] - 10/04/2013 - 09:06:13 ---A- . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [1104384] O44 - LFC:[MD5.CA78BA218B423C7F22B14906308B8B02] - 10/04/2013 - 09:06:12 ---A- . (.Microsoft Corporation - Panneau de configuration Internet.) -- C:\Windows\System32\inetcpl.cpl [1427968] O44 - LFC:[MD5.DFE118C95C6571B87D1923DAB3FA0A77] - 10/04/2013 - 09:06:09 ---A- . (.Microsoft Corporation - Navigateur Internet.) -- C:\Windows\System32\ieframe.dll [9738752] O44 - LFC:[MD5.658EBC74BD38D16805648C4775F7FA82] - 10/04/2013 - 09:06:09 ---A- . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [12324352] O44 - LFC:[MD5.6E4916DC5BA0697C28915DA5261FF250] - 10/04/2013 - 09:02:52 ---A- . (.Microsoft Corporation - Outil de suppression de logiciels malveilla.) -- C:\Windows\System32\mrt.exe [70490256] O44 - LFC:[MD5.6A166182E32844369FD072057782A22B] - 10/04/2013 - 08:57:14 ---A- . (.Microsoft Corporation - Client ActiveX des services Terminal Server.) -- C:\Windows\System32\mstscax.dll [2067968] O44 - LFC:[MD5.2C1121F2B87E9A6B12485DF53CD848C7] - 10/04/2013 - 08:57:12 ---A- . (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\Windows\System32\Drivers\ntfs.sys [1082232] O44 - LFC:[MD5.21870BAB9C9B802AC641DD644708BDE4] - 10/04/2013 - 08:57:08 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntkrnlpa.exe [3603816] O44 - LFC:[MD5.E31AE50AFB2A4AE804D016E02EE6BE10] - 10/04/2013 - 08:57:06 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntoskrnl.exe [3551080] O44 - LFC:[MD5.BE7480C91E89EB82FC080F772C220AE4] - 10/04/2013 - 08:57:05 ---A- . (.Microsoft Corporation - Windows Session Manager.) -- C:\Windows\System32\smss.exe [64000] O44 - LFC:[MD5.33F84B64D4765BCDFA0AB8464122DA14] - 10/04/2013 - 08:57:04 ---A- . (.Microsoft Corporation - Client Server Runtime Process.) -- C:\Windows\System32\csrsrv.dll [49152] O44 - LFC:[MD5.A508314231C49AEE86987CEA3EAECAD1] - 10/04/2013 - 08:57:01 ---A- . (.Microsoft Corporation - DLL serveur de Windows multi-utilisateurs.) -- C:\Windows\System32\winsrv.dll [376320] O44 - LFC:[MD5.88FB35233A80BB42FF5B4E722705FEF4] - 10/04/2013 - 08:56:14 ---A- . (.Microsoft Corporation - Pilote Win32 multi-utilisateurs.) -- C:\Windows\System32\win32k.sys [2049024] O44 - LFC:[MD5.229770FF9B87160AC3C22517BBFE6BF4] - 10/04/2013 - 08:44:43 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerApp.exe [691592] O44 - LFC:[MD5.33AABF5D0F7C87E1F7C58FCD1966B542] - 10/04/2013 - 08:44:43 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [71048] ~ Files: 42 Scanned in 00mn 08s ---\\ Derniers fichiers créés dans Windows Prefetcher (O45) O45 - LFCP:[MD5.BBB4D3948B0F10FF3376FF0E170F8138] - 10/04/2013 - 08:38:08 ---A- - C:\Windows\Prefetch\FLASHPLAYERPLUGIN_11_6_602_18-133A7329.pf O45 - LFCP:[MD5.FF831FB0A542B82494566749E4F7DDE4] - 18/04/2013 - 19:21:20 ---A- - C:\Windows\Prefetch\Layout.ini O45 - LFCP:[MD5.954050CF2D51050A8E8DD0220405E931] - 18/04/2013 - 19:31:25 ---A- - C:\Windows\Prefetch\VSSVC.EXE-B8AFC319.pf O45 - LFCP:[MD5.98529B51B86F3C1FC5AC6498465B4A08] - 18/04/2013 - 19:31:26 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-7CFEDEA3.pf O45 - LFCP:[MD5.EE415A6A0F09ECB9930C4FB764BD6FCA] - 18/04/2013 - 19:37:22 ---A- - C:\Windows\Prefetch\DEFRAG.EXE-588F90AD.pf O45 - LFCP:[MD5.EC1A7FA2899EA49000AA0C1377DC0A63] - 18/04/2013 - 19:37:22 ---A- - C:\Windows\Prefetch\DFRGNTFS.EXE-7E4077FE.pf O45 - LFCP:[MD5.1ACA17DB38B1CABBD2517982931608E5] - 19/04/2013 - 08:36:50 ---A- - C:\Windows\Prefetch\AgCx_SC2.db O45 - LFCP:[MD5.408BB7569C1EB4B5C8081E448F00D030] - 19/04/2013 - 09:21:43 ---A- - C:\Windows\Prefetch\BUBBLES.SCR-7B603539.pf O45 - LFCP:[MD5.6073107262BEE67D3981368CB07B92D2] - 19/04/2013 - 09:41:17 ---A- - C:\Windows\Prefetch\SNDVOL.EXE-5D4CC7D6.pf O45 - LFCP:[MD5.1B184CB2719AD75DE209F531AC98ED7C] - 19/04/2013 - 12:31:07 ---A- - C:\Windows\Prefetch\AgCx_SC1.db.trx O45 - LFCP:[MD5.5E91377901B5179E2672D201913A72AE] - 19/04/2013 - 12:32:07 ---A- - C:\Windows\Prefetch\AgCx_SC1.db O45 - LFCP:[MD5.DC1A6BAA109D52B24138F68E58317778] - 19/04/2013 - 12:36:30 ---A- - C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-3276480709-338746168-2113458505-1000.db O45 - LFCP:[MD5.664D30B0F123A43D5EC727BFE9D23915] - 19/04/2013 - 12:36:30 ---A- - C:\Windows\Prefetch\AgGlUAD_S-1-5-21-3276480709-338746168-2113458505-1000.db O45 - LFCP:[MD5.FC1C2E684054E301B297B8C4F9F7DF54] - 19/04/2013 - 12:42:38 ---A- - C:\Windows\Prefetch\ACRORD32.EXE-CAD3D38B.pf O45 - LFCP:[MD5.1BE6450DD57BC0FE659129BA9CCF3568] - 19/04/2013 - 12:50:54 ---A- - C:\Windows\Prefetch\CALC.EXE-77FDF17F.pf O45 - LFCP:[MD5.07BDF8D9A7E6C9841D4431A5518D07FE] - 19/04/2013 - 13:31:30 ---A- - C:\Windows\Prefetch\PSI_TRAY.EXE-EC0C06BD.pf O45 - LFCP:[MD5.DE9FA75970C000A7A345DD51EDB3691D] - 19/04/2013 - 13:34:04 ---A- - C:\Windows\Prefetch\PICASAUPDATER_6C54.EXE-1877699F.pf O45 - LFCP:[MD5.C09B60D182CE3FCBAB77E5BAAF9A7955] - 19/04/2013 - 13:34:05 ---A- - C:\Windows\Prefetch\SETUP.EXE-56599686.pf O45 - LFCP:[MD5.54B3C76614B20EE773D36B073E75D110] - 19/04/2013 - 13:34:07 ---A- - C:\Windows\Prefetch\GOOGLEUPDATERSERVICE.EXE-09540BCD.pf O45 - LFCP:[MD5.6A3408590A99BDCB7672A2F3D6ADEDB2] - 19/04/2013 - 13:34:08 ---A- - C:\Windows\Prefetch\PICASAUPDATER_7F2.EXE-C3C33F03.pf O45 - LFCP:[MD5.AC851E2DBAF2083F8991A934C7949838] - 19/04/2013 - 13:34:32 ---A- - C:\Windows\Prefetch\GOOGLEUPDATERSERVICE.EXE-977F693C.pf O45 - LFCP:[MD5.FB7D6EC521A5F9C1C89DB47F08DC374C] - 19/04/2013 - 13:34:41 ---A- - C:\Windows\Prefetch\GPHOTOS.SCR-12C16302.pf O45 - LFCP:[MD5.166CA03B0D6BAF8B802E9AB7F2CC2D1C] - 19/04/2013 - 13:34:53 ---A- - C:\Windows\Prefetch\PICASA3.EXE-A45A4BC9.pf O45 - LFCP:[MD5.A40B0F04BF5E12E77199153736EF84AD] - 19/04/2013 - 13:35:05 ---A- - C:\Windows\Prefetch\PICASAUPDATER.EXE-D9A0F3E3.pf O45 - LFCP:[MD5.93853D6A22E2911EEAFB8EF29E701BF2] - 19/04/2013 - 13:38:52 ---A- - C:\Windows\Prefetch\VLC-2.0.6-WIN32.EXE-5356371D.pf O45 - LFCP:[MD5.E3CFEACB4A9CC876344DADD795299EF5] - 19/04/2013 - 13:39:04 ---A- - C:\Windows\Prefetch\UNINSTALL.EXE-AEDCFE07.pf O45 - LFCP:[MD5.12D2F950DFB5AD52E439D7472C3BAD95] - 19/04/2013 - 13:42:27 ---A- - C:\Windows\Prefetch\VLC-CACHE-GEN.EXE-4CD0B4D6.pf O45 - LFCP:[MD5.C0EE81E906A27BA43E9EE7B6FAB60F03] - 19/04/2013 - 13:44:35 ---A- - C:\Windows\Prefetch\VLC.EXE-A11F73EE.pf O45 - LFCP:[MD5.D8DA47B79953832CBB8945A836E205BB] - 19/04/2013 - 13:48:29 ---A- - C:\Windows\Prefetch\SNIPPINGTOOL.EXE-EFFDAFDE.pf O45 - LFCP:[MD5.8532EB1344D1B5CD673E4D812B350F54] - 19/04/2013 - 13:48:31 ---A- - C:\Windows\Prefetch\WISPTIS.EXE-595A3677.pf O45 - LFCP:[MD5.BBE536C250ACABFAAFF93684EB8B0367] - 19/04/2013 - 13:50:27 ---A- - C:\Windows\Prefetch\PSI.EXE-B0E5451A.pf O45 - LFCP:[MD5.84760BE23A9AB651BDAA5DFEA949B3D7] - 19/04/2013 - 13:53:06 ---A- - C:\Windows\Prefetch\VLC.EXE-9ED8B77B.pf O45 - LFCP:[MD5.C16B9A2DBDB836E0A18CD6ED43035A14] - 19/04/2013 - 13:54:05 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-94019DEA.pf O45 - LFCP:[MD5.90EBFCF6D2D2CD1AF51915693D93F445] - 19/04/2013 - 13:57:11 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-6A473D35.pf O45 - LFCP:[MD5.9F4D684FC8038E18FFB8BB6FD17DBF41] - 19/04/2013 - 14:00:49 ---A- - C:\Windows\Prefetch\VERCLSID.EXE-7C52E31C.pf O45 - LFCP:[MD5.A7E451DBF3B35D8B36BB5F519EF7E61C] - 19/04/2013 - 14:03:17 ---A- - C:\Windows\Prefetch\JP2LAUNCHER.EXE-DFC71DBB.pf O45 - LFCP:[MD5.191F9D771342F62D307184F072591AAB] - 19/04/2013 - 14:03:19 ---A- - C:\Windows\Prefetch\JAVA.EXE-633ED9BF.pf O45 - LFCP:[MD5.4CF828202F7158051A863C3471EB1F7A] - 19/04/2013 - 14:12:00 ---A- - C:\Windows\Prefetch\FLASHPLAYERUPDATESERVICE.EXE-ECAD9571.pf O45 - LFCP:[MD5.E485E21BECA2EDC12AE7743BB47A1AED] - 19/04/2013 - 14:13:01 ---A- - C:\Windows\Prefetch\AVAST.SETUP-B1D66586.pf O45 - LFCP:[MD5.24FB7BA9DC25A930F148443909020FF8] - 19/04/2013 - 14:13:48 ---A- - C:\Windows\Prefetch\ASWREGSVR.EXE-AD27A91B.pf O45 - LFCP:[MD5.D874E100E484023EA51C10DFC5708BD1] - 19/04/2013 - 14:30:56 ---A- - C:\Windows\Prefetch\AGCP.EXE-34006E12.pf O45 - LFCP:[MD5.B55D3DA16981F07ACC34F6CCA0235597] - 19/04/2013 - 14:37:15 ---A- - C:\Windows\Prefetch\UNINS000.EXE-511E835E.pf O45 - LFCP:[MD5.C76B889E92F236836356FBF7B274124D] - 19/04/2013 - 14:39:31 ---A- - C:\Windows\Prefetch\MSPAINT.EXE-76E10B24.pf O45 - LFCP:[MD5.76FDB9692911C73BEC79E43F757F535D] - 19/04/2013 - 14:40:58 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-4A091A3F.pf O45 - LFCP:[MD5.B76EB8A3DD5F5F60688CF8A0F5BB4C52] - 19/04/2013 - 14:41:08 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-4F28A26F.pf O45 - LFCP:[MD5.5894065FEB33D4FAC5F3A10969B5532D] - 19/04/2013 - 14:41:35 ---A- - C:\Windows\Prefetch\WLXPHOTOGALLERY.EXE-0AE806EC.pf O45 - LFCP:[MD5.FF7BE5BC20524613FB48E4EBDAB36291] - 19/04/2013 - 14:42:07 ---A- - C:\Windows\Prefetch\WLXPHOTOGALLERYREPAIR.EXE-030BB333.pf O45 - LFCP:[MD5.26E9DEA035AC9F379053B1407ED84B99] - 19/04/2013 - 14:44:30 ---A- - C:\Windows\Prefetch\LIGHT_IMAGE_RESIZER4_SETUP.EX-29DE4A32.pf O45 - LFCP:[MD5.CC4B7A215D7B19AF5925F3E811830990] - 19/04/2013 - 14:44:31 ---A- - C:\Windows\Prefetch\LIGHT_IMAGE_RESIZER4_SETUP.TM-E205F071.pf O45 - LFCP:[MD5.4A330408A509EF87D4848EAB718E063F] - 19/04/2013 - 14:45:16 ---A- - C:\Windows\Prefetch\MF.EXE-63D3E06D.pf O45 - LFCP:[MD5.AF638D3419429F74D506B1BD1BA0571F] - 19/04/2013 - 14:45:16 ---A- - C:\Windows\Prefetch\NS255D.TMP-B0BA63D6.pf O45 - LFCP:[MD5.11B5F7ED1C26F69E9E077D6072330F0F] - 19/04/2013 - 14:45:17 ---A- - C:\Windows\Prefetch\EF.EXE-38405685.pf O45 - LFCP:[MD5.8DA1E3E2D5CEC0968FDAA07DA70A0CDA] - 19/04/2013 - 14:45:17 ---A- - C:\Windows\Prefetch\NS2B66.TMP-9476E77E.pf O45 - LFCP:[MD5.F1BF5F16178613FE0BF954DE9D61E81D] - 19/04/2013 - 14:45:24 ---A- - C:\Windows\Prefetch\MF.EXE-E7DD23F5.pf O45 - LFCP:[MD5.64D7FD375C4EA9795DCF7F22255E862B] - 19/04/2013 - 14:45:24 ---A- - C:\Windows\Prefetch\NS4902.TMP-4EDADC81.pf O45 - LFCP:[MD5.87828E6CEF5CD21756CEA1BBE1C960BD] - 19/04/2013 - 14:45:24 ---A- - C:\Windows\Prefetch\POWERPACK.EXE-2171E8DE.pf O45 - LFCP:[MD5.4A66FAA65A9B2043F5B1D7A308BF416D] - 19/04/2013 - 14:45:25 ---A- - C:\Windows\Prefetch\EF.EXE-BC499A0D.pf O45 - LFCP:[MD5.1D58315BBAC1B6066CD0E8C7BE41EA9B] - 19/04/2013 - 14:45:25 ---A- - C:\Windows\Prefetch\NS4AF6.TMP-5C03FB7B.pf O45 - LFCP:[MD5.7E2C94F999694CC64D70C6284B5BFE93] - 19/04/2013 - 14:45:34 ---A- - C:\Windows\Prefetch\PP.EXE-55847D56.pf O45 - LFCP:[MD5.00643F96E37359F7B5FC9ACEA12EC602] - 19/04/2013 - 14:46:46 ---A- - C:\Windows\Prefetch\26.EXE-FF6F8A36.pf O45 - LFCP:[MD5.C953BC60F09A1EDABA590932E593D220] - 19/04/2013 - 14:47:57 ---A- - C:\Windows\Prefetch\MINIBARFIREFOX.EXE-83780ED8.pf O45 - LFCP:[MD5.7E135DE499348AC43BB85929CE01CA89] - 19/04/2013 - 14:48:04 ---A- - C:\Windows\Prefetch\FIREFOXINSTALLER.EXE-71B401D3.pf O45 - LFCP:[MD5.CBDD78FDB2262B4DFE1CABD735024BE5] - 19/04/2013 - 14:48:04 ---A- - C:\Windows\Prefetch\IMINENT.MESSENGERS.EXE-0CD6D400.pf =>Adware.IMBooster O45 - LFCP:[MD5.D4F9473A05A656A4A7AF9D8C03D8F148] - 19/04/2013 - 14:48:35 ---A- - C:\Windows\Prefetch\MINIBARCHROME.EXE-2FE87B6F.pf O45 - LFCP:[MD5.1529DD6E87411F0827B31B20CB888C10] - 19/04/2013 - 14:48:37 ---A- - C:\Windows\Prefetch\CHROMEINSTALLER.EXE-3BDE1ADA.pf O45 - LFCP:[MD5.7F602201E72E6C96736B956250260FC4] - 19/04/2013 - 14:48:42 ---A- - C:\Windows\Prefetch\IEXPLOREINSTALLER.EXE-BFFA57B4.pf O45 - LFCP:[MD5.7A0625A94596530C654337F4487B759E] - 19/04/2013 - 14:48:42 ---A- - C:\Windows\Prefetch\IMINENTMINIBARIE.EXE-C17B344B.pf =>Adware.IMBooster O45 - LFCP:[MD5.E140F1DF6A1EB570D8B527B31CE89B14] - 19/04/2013 - 14:49:20 ---A- - C:\Windows\Prefetch\SETUP__737.EXE-B3CA7FB6.pf O45 - LFCP:[MD5.B3513A15056709E03CE59E791827C858] - 19/04/2013 - 14:49:37 ---A- - C:\Windows\Prefetch\FRAMEFOXSETUP.EXE-45B86BC4.pf O45 - LFCP:[MD5.E4F665623D059A55C38FB3C9D3262860] - 19/04/2013 - 14:49:38 ---A- - C:\Windows\Prefetch\DUUQUUPDATE.EXE-DA57B974.pf O45 - LFCP:[MD5.8AC3FF58E275822E9475122263633453] - 19/04/2013 - 14:50:15 ---A- - C:\Windows\Prefetch\FRAMEFOX.EXE-63AA1ED8.pf O45 - LFCP:[MD5.D5AF487952A4618A4F6EC6786F987D0C] - 19/04/2013 - 14:50:15 ---A- - C:\Windows\Prefetch\UPDATER.EXE-23C246C8.pf O45 - LFCP:[MD5.6FC7466795C981EDCC95522AA2DE41D3] - 19/04/2013 - 14:50:17 ---A- - C:\Windows\Prefetch\UPDATER.EXE-36E3A673.pf O45 - LFCP:[MD5.FB8F01E5B94B98081EA3973A0056A1CA] - 19/04/2013 - 14:51:01 ---A- - C:\Windows\Prefetch\13.EXE-5FFBE96A.pf O45 - LFCP:[MD5.C81946169E3115AF295D008F3BB89DA3] - 19/04/2013 - 14:51:04 ---A- - C:\Windows\Prefetch\27.EXE-12C544BB.pf O45 - LFCP:[MD5.AED6624E319F92EB203F91F866EBE1BA] - 19/04/2013 - 14:51:06 ---A- - C:\Windows\Prefetch\SETUP.EXE-9D689A26.pf O45 - LFCP:[MD5.BFEBEFDCE46FA64C4771AA11FBB9A6FB] - 19/04/2013 - 14:51:10 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-1FDECB71.pf O45 - LFCP:[MD5.58B85DF3818DE582FDFD26D9A1A3D3F5] - 19/04/2013 - 14:51:11 ---A- - C:\Windows\Prefetch\IELOWUTIL.EXE-3885C25E.pf O45 - LFCP:[MD5.684A78DD33E4C793F17C1C9DDC2A01B0] - 19/04/2013 - 14:51:15 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-F82AA420.pf O45 - LFCP:[MD5.ED559C70ADB8C0654FF9999BBA6F8481] - 19/04/2013 - 14:51:28 ---A- - C:\Windows\Prefetch\RUNDLL32.EXE-E1ABEC92.pf O45 - LFCP:[MD5.97DBBE5817E5753D3E199EA01C514379] - 19/04/2013 - 14:51:55 ---A- - C:\Windows\Prefetch\DELTA4IE.EXE-903E6D30.pf O45 - LFCP:[MD5.F6DCD85B193324A6FFF9BAE0EB9EE1CD] - 19/04/2013 - 14:51:59 ---A- - C:\Windows\Prefetch\DELTA4FFX.EXE-BF1EC286.pf O45 - LFCP:[MD5.0281FF1615CCAADF8F1CFAF8D89F9734] - 19/04/2013 - 14:51:59 ---A- - C:\Windows\Prefetch\MYBABYLONTB.EXE-C23969B0.pf =>Toolbar.Babylon O45 - LFCP:[MD5.B691D41F7465663F1B46B4370FE9C3E6] - 19/04/2013 - 14:56:04 ---A- - C:\Windows\Prefetch\WUDFHOST.EXE-AFFEF87C.pf O45 - LFCP:[MD5.3263A06553D3B27C010D6E1524B2DD99] - 19/04/2013 - 14:56:25 ---A- - C:\Windows\Prefetch\MOBSYNC.EXE-C5E2284F.pf O45 - LFCP:[MD5.23963CB7687FE61129464C10D759689A] - 19/04/2013 - 14:57:49 ---A- - C:\Windows\Prefetch\JUSCHED.EXE-D10FBD13.pf O45 - LFCP:[MD5.6BE936F4D6990AD8AEA6592A5AF0D645] - 19/04/2013 - 15:00:06 ---A- - C:\Windows\Prefetch\AVASTEMUPDATE.EXE-6EF4B603.pf O45 - LFCP:[MD5.8EC08257991D6A9DE4F152E4F509E85D] - 19/04/2013 - 15:06:25 ---A- - C:\Windows\Prefetch\SSVAGENT.EXE-4520197F.pf O45 - LFCP:[MD5.534979CA17444AC28CA4CFFC2BE3BD27] - 19/04/2013 - 15:08:37 ---A- - C:\Windows\Prefetch\_IU14D2N.TMP-F6BF9FB8.pf O45 - LFCP:[MD5.9F6353736568C2A65E332DF1A204C1FC] - 19/04/2013 - 15:16:34 ---A- - C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf O45 - LFCP:[MD5.B52BFAA8C34CB2E70AC712DE79774C5D] - 19/04/2013 - 15:20:14 ---A- - C:\Windows\Prefetch\DELTASRV.EXE-F8C5D428.pf O45 - LFCP:[MD5.C87E002BD3C1DE895A5083FE3DD85AF0] - 19/04/2013 - 15:20:53 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-7FAA2E4C.pf O45 - LFCP:[MD5.94A6A45301F0C3A4ECC4BEFA01EBF235] - 19/04/2013 - 15:21:11 ---A- - C:\Windows\Prefetch\MSIEXEC.EXE-A2D55CB6.pf O45 - LFCP:[MD5.8826A4800FD774A15CD0B0AB08CF908C] - 19/04/2013 - 15:21:11 ---A- - C:\Windows\Prefetch\UMBRELLA.EXE-626E77FE.pf O45 - LFCP:[MD5.2CE9E6FF70D0CCACDF4FF736195D456E] - 19/04/2013 - 15:21:35 ---A- - C:\Windows\Prefetch\CSC.EXE-4C85A8F6.pf O45 - LFCP:[MD5.E9D2D0605C1D84D9829A3E72A3DFDBEF] - 19/04/2013 - 15:21:35 ---A- - C:\Windows\Prefetch\CVTRES.EXE-CDAB491C.pf O45 - LFCP:[MD5.7107C03A7ACB20BA1EEC47FA7AE7A4C1] - 19/04/2013 - 15:21:43 ---A- - C:\Windows\Prefetch\TASKKILL.EXE-8F5B2253.pf O45 - LFCP:[MD5.298C794284025B6C5D6EE17C260294A0] - 19/04/2013 - 15:21:46 ---A- - C:\Windows\Prefetch\REGSVR32.EXE-8461DBEE.pf O45 - LFCP:[MD5.CD31AA8770592844C4CD0F6C9D2FF43D] - 19/04/2013 - 15:21:56 ---A- - C:\Windows\Prefetch\REGASM.EXE-4EFC4B44.pf O45 - LFCP:[MD5.0BDA798F0F50A5D3664B85E512518587] - 19/04/2013 - 15:22:02 ---A- - C:\Windows\Prefetch\INSTALLUTIL.EXE-D7AF7FBA.pf O45 - LFCP:[MD5.9740B5AEB78ED80A4A373B489E2C1096] - 19/04/2013 - 15:23:58 ---A- - C:\Windows\Prefetch\CONTROL.EXE-817F8F1D.pf O45 - LFCP:[MD5.2E31DCAD0FEBF87BA8C724597FB06E25] - 19/04/2013 - 15:24:05 ---A- - C:\Windows\Prefetch\IGFXSRVC.EXE-96A493A4.pf O45 - LFCP:[MD5.9A7B6EE96B97627E44F9D4C73C2BDB92] - 19/04/2013 - 15:25:22 ---A- - C:\Windows\Prefetch\WERFAULT.EXE-E69F695A.pf O45 - LFCP:[MD5.ABD451C3561C79D8DA130D59D1179D2F] - 19/04/2013 - 15:25:26 ---A- - C:\Windows\Prefetch\LOGONUI.EXE-09140401.pf O45 - LFCP:[MD5.131FC5015BBB0FD5E760FEB3A92402F5] - 19/04/2013 - 15:25:27 ---A- - C:\Windows\Prefetch\PfSvPerfStats.bin O45 - LFCP:[MD5.0B1E4061C33112881565E48FF73AA55D] - 19/04/2013 - 15:25:29 ---A- - C:\Windows\Prefetch\AgRobust.db O45 - LFCP:[MD5.7E4D08D38478BB73CCEF05947BD3F288] - 19/04/2013 - 15:25:32 ---A- - C:\Windows\Prefetch\AgGlFaultHistory.db O45 - LFCP:[MD5.658CBBD123B4C826DC1C1734050DE993] - 19/04/2013 - 15:25:32 ---A- - C:\Windows\Prefetch\AgGlFgAppHistory.db O45 - LFCP:[MD5.CCD0209FAF03BD73DE6925C9A35CEEAE] - 19/04/2013 - 15:25:32 ---A- - C:\Windows\Prefetch\AgGlGlobalHistory.db O45 - LFCP:[MD5.0AAB315313E00FBC3B12CDC17E6E9ABE] - 19/04/2013 - 15:28:24 ---A- - C:\Windows\Prefetch\NTOSBOOT-B00DFAAD.pf O45 - LFCP:[MD5.4729D2840E33BC30FB8EBADA5DD4DA05] - 19/04/2013 - 15:28:24 ---A- - C:\Windows\Prefetch\VZCDBSVC.EXE-28885566.pf O45 - LFCP:[MD5.531D4E422DDB1CF3C77666500D1950B8] - 19/04/2013 - 15:28:24 ---A- - C:\Windows\Prefetch\WLIDSVCM.EXE-A6EF5B2F.pf O45 - LFCP:[MD5.67A799DAF88421D03A5808AD8E2069E5] - 19/04/2013 - 15:28:24 ---A- - C:\Windows\Prefetch\XAUDIO.EXE-D92946E9.pf O45 - LFCP:[MD5.BCB7D5308C7DC173A6A814E7A21F0DE1] - 19/04/2013 - 15:28:32 ---A- - C:\Windows\Prefetch\VZFW.EXE-0C825B66.pf O45 - LFCP:[MD5.E40999EDF5121E23159D2746439E470A] - 19/04/2013 - 15:28:42 ---A- - C:\Windows\Prefetch\WMPLAYER.EXE-BAD6BD53.pf O45 - LFCP:[MD5.26F3996E3242709D874137EEB21F7FB5] - 19/04/2013 - 15:28:45 ---A- - C:\Windows\Prefetch\AVBUGREPORT.EXE-3B5B9E84.pf O45 - LFCP:[MD5.636923207192A6E10EE5E382C5D511A0] - 19/04/2013 - 15:30:01 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-007FEA55.pf O45 - LFCP:[MD5.2A5312A9A3E811230CAFC7C9CE392875] - 19/04/2013 - 15:30:23 ---A- - C:\Windows\Prefetch\MSCORSVW.EXE-C3C515BD.pf O45 - LFCP:[MD5.0AA8E73205AB0770F85A63173FFF4E6A] - 19/04/2013 - 15:30:25 ---A- - C:\Windows\Prefetch\DUUQUCRASHHANDLER.EXE-2C9640E0.pf O45 - LFCP:[MD5.B1C717F6C25A746E3623F0EEE7F37175] - 19/04/2013 - 15:30:51 ---A- - C:\Windows\Prefetch\UNSECAPP.EXE-A02905A6.pf O45 - LFCP:[MD5.4527EBA1059B792CADE317AD5B574498] - 19/04/2013 - 15:32:07 ---A- - C:\Windows\Prefetch\WMIADAP.EXE-F8DFDFA2.pf O45 - LFCP:[MD5.454DC2C8342EDEA10CA4862279140819] - 19/04/2013 - 15:33:13 ---A- - C:\Windows\Prefetch\WMIPRVSE.EXE-1628051C.pf O45 - LFCP:[MD5.93E6A7B0C3BD90EDD534A1674CDF5A44] - 19/04/2013 - 15:34:14 ---A- - C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-3CC531E5.pf O45 - LFCP:[MD5.AF0F5122BBDC07DA2547ED40149A16CB] - 19/04/2013 - 15:38:29 ---A- - C:\Windows\Prefetch\SEAPORT.EXE-E221DC8E.pf O45 - LFCP:[MD5.A0FB498F7A9D2A10F5991F402F7ABD4C] - 19/04/2013 - 15:39:59 ---A- - C:\Windows\Prefetch\WERMGR.EXE-0F2AC88C.pf O45 - LFCP:[MD5.E7EBEABCFF2621773E71BF553A3EF1F9] - 19/04/2013 - 15:40:02 ---A- - C:\Windows\Prefetch\WERCON.EXE-E36BD04E.pf O45 - LFCP:[MD5.636C6C8E627B2B408F6138B0E3E8496F] - 19/04/2013 - 15:41:54 ---A- - C:\Windows\Prefetch\TASKENG.EXE-48D4E289.pf O45 - LFCP:[MD5.3F1EF91586884013C317B2D3AA18C4DB] - 19/04/2013 - 15:44:35 ---A- - C:\Windows\Prefetch\FLASHUTIL32_11_7_700_169_ACTI-47BA841E.pf O45 - LFCP:[MD5.3BDCFC67FE4A355121D35BC6CF3BAFAA] - 19/04/2013 - 15:49:35 ---A- - C:\Windows\Prefetch\FIREFOX.EXE-A606B53C.pf O45 - LFCP:[MD5.B8FE4CB222BBF86723080668D0300A42] - 19/04/2013 - 15:49:52 ---A- - C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf O45 - LFCP:[MD5.4AEE1E535818F2D04911C9B2E681C131] - 19/04/2013 - 15:54:01 ---A- - C:\Windows\Prefetch\DUUQUUPDATE.EXE-8F6A5D28.pf O45 - LFCP:[MD5.BA50EC2977B742C090D241920743FABF] - 19/04/2013 - 15:57:00 ---A- - C:\Windows\Prefetch\GOOGLEUPDATE.EXE-FE771DDA.pf O45 - LFCP:[MD5.F52B6DEC0A9EB59AC3E64AD35A1461E6] - 19/04/2013 - 16:03:02 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-5E46FA0D.pf O45 - LFCP:[MD5.0B6BD282D3933AA500E481B148A73C80] - 19/04/2013 - 16:03:10 ---A- - C:\Windows\Prefetch\FLASHPLAYERPLUGIN_11_7_700_16-E534506C.pf O45 - LFCP:[MD5.06B138931D662158C67A4ED0530A9E1F] - 19/04/2013 - 16:03:10 ---A- - C:\Windows\Prefetch\PLUGIN-CONTAINER.EXE-7226D1F8.pf O45 - LFCP:[MD5.518E0A003937E794CAB97B8CD33D348A] - 19/04/2013 - 16:03:13 ---A- - C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-77482212.pf O45 - LFCP:[MD5.7AA927306E80D365B1C6758A39C7C6A5] - 19/04/2013 - 16:03:13 ---A- - C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-0CB8CADE.pf O45 - LFCP:[MD5.376BB203D673FBBABEE2053545484F81] - 19/04/2013 - 16:03:24 ---A- - C:\Windows\Prefetch\CONSENT.EXE-531BD9EA.pf O45 - LFCP:[MD5.ECF16C572A117817C9D123391DC5ADC3] - 19/04/2013 - 16:03:29 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-766398D2.pf O45 - LFCP:[MD5.F8158B7AA67A49F6343E12DB8025BEA2] - 19/04/2013 - 16:05:20 ---A- - C:\Windows\Prefetch\CMD.EXE-4A81B364.pf ~ Prefetcher: 140 Scanned in 00mn 02s ---\\ Déni du service (Local Security Authority) (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll ~ LSA: 7 Scanned in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Volume Manager Extension Driver.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Volume Manager Extension Driver.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ CSB: 13 Scanned in 00mn 00s ---\\ Trojan Driver Search Data (HKLM) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll O52 - TDSD: \Drivers32\"vidc.DIVX"="DivX.dll" . (.DivX, Inc. - DivX.) -- C:\Windows\System32\DivX.dll O52 - TDSD: \Drivers32\"vidc.yv12"="DivX.dll" . (.DivX, Inc. - DivX.) -- C:\Windows\System32\DivX.dll O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm ~ TDSD: 5 Scanned in 00mn 00s ---\\ Microsoft Control Security Providers (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TS Single Sign On Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TS Single Sign On Security Package.) -- C:\Windows\System32\credssp.dll ~ MSCP: 2 Scanned in 00mn 00s ---\\ Microsoft Windows Policies System (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=2 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 ~ MWPS: 16 Scanned in 00mn 00s ---\\ Microsoft Windows Policies Explorer (O56) O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=0 O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveAutoRun"=3 O56 - MWPE:[HKLM\...\policies\Explorer] - "BindDirectlyToPropertySetStorage"=0 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDriveAutoRun"=3 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDriveTypeAutoRun"=0 ~ MWPE Keys: 5 Scanned in 00mn 00s ---\\ Liste des Drivers Système (O58) O58 - SDL:[MD5.2EDC5BBAC6C651ECE337BDE8ED97C9FB] - 02/11/2006 - 10:51:38 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [420968] O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 02/11/2006 - 08:09:42 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029] ~ Drivers: Scanned in 00mn 00s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 16/04/2013 - 16:18:31 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\eas.db [61440] O61 - LFC: 16/04/2013 - 16:18:31 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\eas.db-journal [41552] O61 - LFC: 16/04/2013 - 16:18:35 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\keyval.db [40960] O61 - LFC: 16/04/2013 - 16:18:35 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\keyval.db-journal [33344] O61 - LFC: 16/04/2013 - 16:19:06 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\msn.db [131072] O61 - LFC: 16/04/2013 - 16:19:06 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\msn.db-journal [107216] O61 - LFC: 16/04/2013 - 16:30:18 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\chatsync\50\50ca3f73fdc23f0a.dat [1855] O61 - LFC: 16/04/2013 - 17:44:02 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\bistats.db [73728] O61 - LFC: 16/04/2013 - 17:44:02 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\httpfe\cookies.dat [2] O61 - LFC: 16/04/2013 - 17:44:03 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\bistats.db-journal [37448] O61 - LFC: 16/04/2013 - 17:44:03 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\config.xml [8092] O61 - LFC: 16/04/2013 - 17:44:03 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\main.db [1736704] O61 - LFC: 16/04/2013 - 17:44:03 ---A- C:\Users\serge\AppData\Roaming\Skype\live#3ahomoncapitaine\main.db-journal [866456] O61 - LFC: 16/04/2013 - 23:38:03 ---A- C:\Users\serge\AppData\Roaming\Adobe\Flash Player\AssetCache\BRGQ8B58\381814F6F5270FFBB27E244D6138BC023AF911D5.heu [149] O61 - LFC: 16/04/2013 - 23:38:04 ---A- C:\Users\serge\AppData\Roaming\Adobe\Flash Player\AssetCache\BRGQ8B58\C3306B26751D6A80EB1FCB651912469AE18819AB.heu [149] O61 - LFC: 16/04/2013 - 23:38:05 ---A- C:\Users\serge\AppData\Roaming\Adobe\Flash Player\AssetCache\BRGQ8B58\440AE73B017A477382DEFF7C0DBE4896FED21079.heu [149] O61 - LFC: 16/04/2013 - 23:38:05 ---A- C:\Users\serge\AppData\Roaming\Adobe\Flash Player\AssetCache\BRGQ8B58\6344DCC80A9A6A3676DCEA0C92C8C45EFD2F3220.heu [149] O61 - LFC: 16/04/2013 - 23:38:05 ---A- C:\Users\serge\AppData\Roaming\Adobe\Flash Player\AssetCache\BRGQ8B58\871F12AF0853C06E4EB80A1CCAB295CEADBB817A.heu [149] O61 - LFC: 16/04/2013 - 23:38:06 ---A- C:\Users\serge\AppData\Roaming\Adobe\Flash Player\AssetCache\BRGQ8B58\6DDB94AE3365798230849FA0F931AC132FE417D1.heu [149] O61 - LFC: 17/04/2013 - 14:15:34 ---A- C:\Users\serge\AppData\Local\Temp\AzdhkJfG.part [115283] O61 - LFC: 17/04/2013 - 15:21:53 -SHA- C:\Users\serge\AppData\Local\Temp\acro_rd_dir\Cookies\index.dat [16384] O61 - LFC: 17/04/2013 - 15:21:53 -SHA- C:\Users\serge\AppData\Local\Temp\acro_rd_dir\Fichiers Internet temporaires\Content.IE5\index.dat [32768] O61 - LFC: 17/04/2013 - 15:21:53 -SHA- C:\Users\serge\AppData\Local\Temp\acro_rd_dir\History\History.IE5\index.dat [16384] O61 - LFC: 17/04/2013 - 19:38:01 ---A- C:\Users\serge\AppData\Local\Temp\R5iK719S.zip.part [2780745] O61 - LFC: 17/04/2013 - 20:01:28 ---A- C:\Users\serge\AppData\Roaming\Skype\shared.xml [64421] O61 - LFC: 17/04/2013 - 22:05:25 ---A- C:\Users\serge\AppData\Local\Windows Live\uxcore_MovieMaker_00.etl [8192] O61 - LFC: 17/04/2013 - 22:30:43 ---A- C:\Users\serge\AppData\Roaming\Adobe\Flash Player\AssetCache\BRGQ8B58\8F903698240FE799F61EEDA8595181137B996156.heu [149] O61 - LFC: 18/04/2013 - 10:30:00 ---A- C:\Users\serge\AppData\Local\Temp\MSIb78ff.LOG [173436] O61 - LFC: 18/04/2013 - 11:18:07 ---A- C:\Users\serge\AppData\Local\Temp\jinstall.cfg [1154] O61 - LFC: 18/04/2013 - 11:22:14 ---A- C:\Users\serge\AppData\Local\Temp\MSI92664.LOG [486746] O61 - LFC: 18/04/2013 - 11:22:45 ---A- C:\Users\serge\AppData\Local\Temp\MSIc53d9.LOG [112338] O61 - LFC: 18/04/2013 - 11:22:51 ---A- C:\Users\serge\AppData\Local\Temp\AUCHECK_PARSER.txt [915] O61 - LFC: 18/04/2013 - 11:22:51 ---A- C:\Users\serge\AppData\Local\Temp\MSIc62b8.LOG [183018] O61 - LFC: 18/04/2013 - 12:00:49 ---A- C:\Users\serge\AppData\Local\Temp\99D42CBE-BAB0-7891-83D0-7BB7DE446A58\bab138.deltatb_dmn.dat [223] O61 - LFC: 18/04/2013 - 14:17:30 ---A- C:\Users\serge\AppData\Local\Temp\MSIc4933.LOG [42430] O61 - LFC: 18/04/2013 - 14:33:55 ---A- C:\Users\serge\Documents\Mes fichiers reçus\34_Agathe_062011.JPG [2567379] O61 - LFC: 18/04/2013 - 14:34:23 ---A- C:\Users\serge\Documents\Mes fichiers reçus\DSC00294.JPG [3100674] O61 - LFC: 18/04/2013 - 14:34:52 ---A- C:\Users\serge\AppData\Local\VSO\Images.fl [62] O61 - LFC: 18/04/2013 - 14:35:25 ---A- C:\Users\serge\Documents\Mes fichiers reçus\23_Agathe_042010.JPG [2780607] O61 - LFC: 19/04/2013 - 09:01:49 -SHA- C:\Users\serge\AppData\Local\Temp\acrord32_sbx\Cookies\index.dat [16384] O61 - LFC: 19/04/2013 - 09:01:49 -SHA- C:\Users\serge\AppData\Local\Temp\acrord32_sbx\Fichiers Internet temporaires\Content.IE5\index.dat [32768] O61 - LFC: 19/04/2013 - 09:01:49 -SHA- C:\Users\serge\AppData\Local\Temp\acrord32_sbx\History\History.IE5\index.dat [16384] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_crop64.pmp [4996] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_edit_height.pmp [2472] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_edit_width.pmp [2472] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_edited.pmp [614] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_facequality.pmp [2508] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_facerect.pmp [4996] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_facerectdata.pmp [17017] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_height.pmp [2508] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_originfast.pmp [4924] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_originslow.pmp [4876] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_rotate.pmp [660] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_tags.pmp [1301] O61 - LFC: 19/04/2013 - 13:33:47 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_width.pmp [2508] O61 - LFC: 19/04/2013 - 13:33:48 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\albumdata_location.pmp [70] O61 - LFC: 19/04/2013 - 13:33:48 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\albumdata_name.pmp [506] O61 - LFC: 19/04/2013 - 13:33:48 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\albumdata_token.pmp [1716] O61 - LFC: 19/04/2013 - 13:33:48 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\albumdata_uid.pmp [1606] O61 - LFC: 19/04/2013 - 13:33:48 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\albumdata_unread.pmp [67] O61 - LFC: 19/04/2013 - 13:33:48 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_avgcolor.pmp [2472] O61 - LFC: 19/04/2013 - 13:33:48 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_caption.pmp [986] O61 - LFC: 19/04/2013 - 13:33:49 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\albumdata_description.pmp [110] O61 - LFC: 19/04/2013 - 13:33:49 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\albumdata_filename.pmp [1658] O61 - LFC: 19/04/2013 - 13:33:49 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\albumdata_hascollage.pmp [70] O61 - LFC: 19/04/2013 - 13:33:49 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\albums_0.db [318132] O61 - LFC: 19/04/2013 - 13:33:50 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\facetemplatesV2_0.db [214024] O61 - LFC: 19/04/2013 - 13:34:46 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\ioqueue\slingshot.ioq [0] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\albumdata_category.pmp [220] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\albumdata_date.pmp [420] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\albums_index.db [524] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\bigthumbs_0.db [6954366] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\bigthumbs_index.db [7484] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\catdata_catpri.pmp [29] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\facetemplatesV2_index.db [7484] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\imagedata_filetype.pmp [2508] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\previews_0.db [19739345] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\previews_index.db [7376] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\scanlist.txt [18] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\thumbindex.db [25013] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\thumbs_0.db [4752172] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\thumbs_index.db [7484] O61 - LFC: 19/04/2013 - 13:35:08 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\wordhash.dat [110852] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2Albums\frexcludefolders.txt [33] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2Albums\watchedfolders.txt [78] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\cache\cacheindex_lastfetch.pmp [28] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\contacts\contacts.xml [133] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\facetags.txt [0] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\repository.dat [178] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\saverlist.txt [0] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\starlist.txt [0] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\tags.txt [0] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\thumbs2_0.db [1617526] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\thumbs2_index.db [7484] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\db3\usernames.dat [8] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\ioqueue\albumsafe.ioq [0] O61 - LFC: 19/04/2013 - 13:35:09 ---A- C:\Users\serge\AppData\Local\Google\Picasa2\ioqueue\filesafe.ioq [0] O61 - LFC: 19/04/2013 - 13:38:03 ---A- C:\Users\serge\AppData\Local\Temp\vlc-2.0.6-win32.exe [22948790] O61 - LFC: 19/04/2013 - 14:41:49 ---A- C:\Users\serge\AppData\Local\Windows Live\uxcore_WLXPhotoGallery_00.etl [8192] O61 - LFC: 19/04/2013 - 14:42:09 ---A- C:\Users\serge\AppData\Local\Windows Live\uxcore_WLXPhotoGalleryRepair_00.etl [8192] O61 - LFC: 19/04/2013 - 14:42:41 ---A- C:\Users\serge\AppData\Local\Windows Live\uxcore_WLXPhotoGallery_01.etl [12288] O61 - LFC: 19/04/2013 - 14:47:46 ---A- C:\Users\serge\AppData\Local\Temp\MSIe0d48.LOG [577032] O61 - LFC: 19/04/2013 - 14:49:19 ---A- C:\Users\serge\AppData\Local\Temp\amipixel.cfg [99] O61 - LFC: 19/04/2013 - 14:49:27 ---A- C:\Users\serge\AppData\Local\SwvUpdater\Updater.exe [301608] O61 - LFC: 19/04/2013 - 14:49:37 ---A- C:\Users\serge\AppData\Local\Temp\MSI2402.LOG [75440] O61 - LFC: 19/04/2013 - 14:49:39 ---A- C:\Users\serge\AppData\Local\Temp\MSI2403.LOG [129250] O61 - LFC: 19/04/2013 - 14:50:12 ---A- C:\Users\serge\AppData\Local\SwvUpdater\status.cfg [1] O61 - LFC: 19/04/2013 - 14:51:11 ---A- C:\Users\serge\AppData\Local\Babylon\Setup\bab098.claroico.zpb [953] =>Toolbar.Babylon O61 - LFC: 19/04/2013 - 14:51:11 ---A- C:\Users\serge\AppData\Local\Babylon\Setup\bab138.deltatb_dmn.zpb [254] =>Toolbar.Babylon O61 - LFC: 19/04/2013 - 14:51:11 ---A- C:\Users\serge\AppData\Local\Temp\99D42CBE-BAB0-7891-83D0-7BB7DE446A58\bab098.claroico.zpb [953] O61 - LFC: 19/04/2013 - 14:51:11 ---A- C:\Users\serge\AppData\Local\Temp\99D42CBE-BAB0-7891-83D0-7BB7DE446A58\bab138.deltatb_dmn.zpb [254] O61 - LFC: 19/04/2013 - 14:51:12 ---A- C:\Users\serge\AppData\Local\Babylon\Setup\bab149.spreg.zpb [299] =>Toolbar.Babylon O61 - LFC: 19/04/2013 - 14:51:12 ---A- C:\Users\serge\AppData\Local\Temp\99D42CBE-BAB0-7891-83D0-7BB7DE446A58\bab149.spreg.zpb [299] O61 - LFC: 19/04/2013 - 14:51:48 ---A- C:\Users\serge\AppData\Local\Babylon\Setup\Setup-deltatb.zpb [1755878] =>Toolbar.Babylon O61 - LFC: 19/04/2013 - 14:51:48 ---A- C:\Users\serge\AppData\Local\Temp\99D42CBE-BAB0-7891-83D0-7BB7DE446A58\Setup-deltatb.zpb [1755878] O61 - LFC: 19/04/2013 - 14:51:51 ---A- C:\Users\serge\AppData\Local\Babylon\Setup\GUninstaller_cat.zpb [138930] =>Toolbar.Babylon O61 - LFC: 19/04/2013 - 14:51:51 ---A- C:\Users\serge\AppData\Local\Temp\99D42CBE-BAB0-7891-83D0-7BB7DE446A58\GUninstaller_cat.zpb [138930] O61 - LFC: 19/04/2013 - 14:51:58 ---A- C:\Users\serge\AppData\Local\Babylon\Setup\ccp.zpb [227051] =>Toolbar.Babylon O61 - LFC: 19/04/2013 - 14:51:58 ---A- C:\Users\serge\AppData\Local\Temp\99D42CBE-BAB0-7891-83D0-7BB7DE446A58\ccp.zpb [227051] O61 - LFC: 19/04/2013 - 14:52:00 ---A- C:\Users\serge\AppData\Roaming\Babylon\log_file.txt [5008] =>Toolbar.Babylon O61 - LFC: 19/04/2013 - 14:52:10 ---A- C:\Users\serge\AppData\Local\Babylon\Setup\DeltaChromeTB_1001.zpb [294912] =>Toolbar.Babylon O61 - LFC: 19/04/2013 - 15:22:16 ---A- C:\Users\serge\AppData\Local\Temp\MSIa55cd.LOG [423204] O61 - LFC: 19/04/2013 - 15:25:15 --HA- C:\Users\serge\AppData\Local\IconCache.db [4193683] O61 - LFC: 19/04/2013 - 15:28:16 ---A- C:\Users\serge\AppData\Local\SwvUpdater\Updater.xml [1104] O61 - LFC: 19/04/2013 - 15:33:59 ---A- C:\Users\serge\AppData\Local\Temp\serge.bmp [31832] ~ 29 Fichiers temporaires (Temporary files) ~ 2 Fichiers cookies (Cookies files) ~ Files: 125 Scanned in 00mn 04s ---\\ Liste des outils de nettoyage (O63) O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 ~ ADS: Scanned in 00mn 00s ---\\ Liste des services Legacy (O64) O64 - Services: CurCS - 21/04/2011 - C:\Windows\system32\drivers\afd.sys (AFD) .(.Microsoft Corporation - Ancillary Function Driver for WinSock.) - LEGACY_AFD O64 - Services: CurCS - 07/03/2013 - C:\Windows\System32\Drivers\aswFsBlk.sys (aswFsBlk) .(.AVAST Software - avast! File System Access Blocking Driver.) - LEGACY_ASWFSBLK O64 - Services: CurCS - 07/03/2013 - C:\Windows\system32\drivers\aswMonFlt.sys (aswMonFlt) .(.AVAST Software - avast! File System Minifilter for Windows 2.) - LEGACY_ASWMONFLT O64 - Services: CurCS - 07/03/2013 - C:\Windows\System32\Drivers\aswRdr.sys (aswRdr) .(.AVAST Software - avast! TDI Redirect Driver.) - LEGACY_ASWRDR O64 - Services: CurCS - 07/03/2013 - Pas de propriétaire (aswRvrt) .(...) - LEGACY_ASWRVRT O64 - Services: CurCS - 07/03/2013 - C:\Windows\System32\Drivers\aswSnx.sys (aswSnx) .(.AVAST Software - avast! Virtualization Driver.) - LEGACY_ASWSNX O64 - Services: CurCS - 07/03/2013 - C:\Windows\System32\Drivers\aswSP.sys (aswSP) .(.AVAST Software - avast! self protection module.) - LEGACY_ASWSP O64 - Services: CurCS - 07/03/2013 - C:\Windows\System32\Drivers\aswTdi.sys (aswTdi) .(.AVAST Software - avast! TDI Filter Driver.) - LEGACY_ASWTDI O64 - Services: CurCS - 07/03/2013 - Pas de propriétaire (aswVmm) .(...) - LEGACY_ASWVMM O64 - Services: CurCS - 11/06/2012 - C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe (BBSvc) .(.Microsoft Corporation. - BingBar Service.) - LEGACY_BBSVC O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\Drivers\Beep.sys (Beep) .(.Microsoft Corporation - BEEP Driver.) - LEGACY_BEEP O64 - Services: CurCS - 22/02/2011 - C:\Windows\System32\DRIVERS\bowser.sys (bowser) .(.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) - LEGACY_BOWSER O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\DRIVERS\cdfs.sys (cdfs) .(.Microsoft Corporation - CD-ROM File System Driver.) - LEGACY_CDFS O64 - Services: CurCS - 11/04/2009 - C:\Windows\System32\CLFS.sys (CLFS) .(.Microsoft Corporation - Common Log File System Driver.) - LEGACY_CLFS O64 - Services: CurCS - 02/11/2006 - C:\Windows\System32\drivers\crcdisk.sys (crcdisk) .(.Microsoft Corporation - Disk Block Verification Filter Driver.) - LEGACY_CRCDISK O64 - Services: CurCS - 14/04/2011 - C:\Windows\System32\Drivers\dfsc.sys (DfsC) .(.Microsoft Corporation - DFS Namespace Client Driver.) - LEGACY_DFSC O64 - Services: CurCS - 27/06/2007 - C:\Windows\System32\DRIVERS\DMICall.sys (DMICall) .(.Sony Corporation - Windows 2000 DMI Call Kernel Driver.) - LEGACY_DMICALL O64 - Services: CurCS - 20/01/2011 - C:\Windows\system32\drivers\dxgkrnl.sys (DXGKrnl) .(.Microsoft Corporation - DirectX Graphics Kernel.) - LEGACY_DXGKRNL O64 - Services: CurCS - 11/04/2009 - C:\Windows\System32\Drivers\fastfat.sys (fastfat) .(.Microsoft Corporation - Fast FAT File System Driver.) - LEGACY_FASTFAT O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\drivers\fileinfo.sys (FileInfo) .(.Microsoft Corporation - FileInfo Filter Driver.) - LEGACY_FILEINFO O64 - Services: CurCS - 11/04/2009 - C:\Windows\System32\drivers\fltmgr.sys (FltMgr) .(.Microsoft Corporation - Gestionnaire de filtres de système de fichi.) - LEGACY_FLTMGR O64 - Services: CurCS - 14/06/2010 - Pas de propriétaire (FsUsbExDisk) .(...) - LEGACY_FSUSBEXDISK O64 - Services: CurCS - 20/02/2010 - C:\Windows\System32\drivers\HTTP.sys (HTTP) .(.Microsoft Corporation - HTTP Pile du protocole.) - LEGACY_HTTP O64 - Services: CurCS - 04/06/2012 - C:\Windows\System32\Drivers\ksecdd.sys (KSecDD) .(.Microsoft Corporation - Kernel Security Support Provider Interface.) - LEGACY_KSECDD O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\DRIVERS\lltdio.sys (lltdio) .(.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) - LEGACY_LLTDIO O64 - Services: CurCS - 19/01/2008 - C:\Windows\system32\drivers\luafv.sys (luafv) .(.Microsoft Corporation - Pilote de filtre de virtualisation de fichi.) - LEGACY_LUAFV O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\drivers\mountmgr.sys (MountMgr) .(.Microsoft Corporation - Mount Point Manager.) - LEGACY_MOUNTMGR O64 - Services: CurCS - 19/01/2008 - C:\Windows\system32\FirewallAPI.dll (mpsdrv) .(.Microsoft Corporation - API du Pare-feu Windows.) - LEGACY_MPSDRV O64 - Services: CurCS - 19/01/2008 - C:\Windows\system32\FirewallAPI.dll (MpsSvc) .(.Microsoft Corporation - API du Pare-feu Windows.) - LEGACY_MPSSVC O64 - Services: CurCS - 11/04/2009 - C:\Windows\system32\drivers\mrxdav.sys (MRxDAV) .(.Microsoft Corporation - Windows NT WebDav Minirdr.) - LEGACY_MRXDAV O64 - Services: CurCS - 29/04/2011 - C:\Windows\System32\DRIVERS\mrxsmb.sys (mrxsmb) .(.Microsoft Corporation - Windows NT SMB Minirdr.) - LEGACY_MRXSMB O64 - Services: CurCS - 06/07/2011 - C:\Windows\System32\DRIVERS\mrxsmb10.sys (mrxsmb10) .(.Microsoft Corporation - Longhorn SMB Downlevel SubRdr.) - LEGACY_MRXSMB10 O64 - Services: CurCS - 29/04/2011 - C:\Windows\System32\DRIVERS\mrxsmb20.sys (mrxsmb20) .(.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) - LEGACY_MRXSMB20 O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\drivers\msisadrv.sys (msisadrv) .(.Microsoft Corporation - ISA Driver.) - LEGACY_MSISADRV O64 - Services: CurCS - 11/04/2009 - C:\Windows\System32\Drivers\mup.sys (Mup) .(.Microsoft Corporation - Multiple UNC Provider driver.) - LEGACY_MUP O64 - Services: CurCS - 11/04/2009 - C:\Windows\System32\DRIVERS\nwifi.sys (NativeWifiP) .(.Microsoft Corporation - NativeWiFi Miniport Driver.) - LEGACY_NATIVEWIFIP O64 - Services: CurCS - 11/04/2009 - C:\Windows\System32\drivers\ndis.sys (NDIS) .(.Microsoft Corporation - NDIS 6.0 wrapper driver.) - LEGACY_NDIS O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\DRIVERS\ndisuio.sys (Ndisuio) .(.Microsoft Corporation - NDIS User mode I/O driver.) - LEGACY_NDISUIO O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\DRIVERS\netbios.sys (NetBIOS) .(.Microsoft Corporation - NetBIOS interface driver.) - LEGACY_NETBIOS O64 - Services: CurCS - 11/04/2009 - C:\Windows\System32\DRIVERS\netbt.sys (netbt) .(.Microsoft Corporation - MBT Transport driver.) - LEGACY_NETBT O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) .(.Microsoft Corporation - NSI Proxy.) - LEGACY_NSIPROXY O64 - Services: CurCS - 03/02/2009 - C:\Windows\System32\Drivers\PCAMp50.sys (PCAMp50) .(.Printing Communications Assoc., Inc. (PCAUS - PCAUSA NDIS 5.0 MPR Protocol Driver.) - LEGACY_PCAMP50 O64 - Services: CurCS - 03/02/2009 - C:\Windows\System32\Drivers\PCASp50.sys (PCASp50) .(.Printing Communications Assoc., Inc. (PCAUS - PCAUSA NDIS 5.0 SPR Protocol Driver.) - LEGACY_PCASP50 O64 - Services: CurCS - 02/11/2006 - C:\Windows\System32\drivers\peauth.sys (PEAUTH) .(.Microsoft Corporation - Protected Environment Authentication and Au.) - LEGACY_PEAUTH O64 - Services: CurCS - 11/04/2009 - C:\Windows\System32\drivers\pacer.sys (PSched) .(.Microsoft Corporation - Planificateur de paquets QoS.) - LEGACY_PSCHED O64 - Services: CurCS - 01/09/2010 - C:\Windows\System32\DRIVERS\psi_mf.sys (PSI) .(.Secunia - Secunia PSI Driver.) - LEGACY_PSI O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\DRIVERS\rasacd.sys (RasAcd) .(.Microsoft Corporation - RAS Automatic Connection Driver.) - LEGACY_RASACD O64 - Services: CurCS - 11/04/2009 - C:\Windows\System32\DRIVERS\rdbss.sys (rdbss) .(.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - LEGACY_RDBSS O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) .(.Microsoft Corporation - RDP Miniport.) - LEGACY_RDPCDD O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\drivers\rdpencdd.sys (RDPENCDD) .(.Microsoft Corporation - RDP Miniport.) - LEGACY_RDPENCDD O64 - Services: CurCS - 01/05/2012 - C:\Windows\System32\Drivers\RDPWD.sys (RDPWD) .(.Microsoft Corporation - RDP Terminal Stack Driver.) - LEGACY_RDPWD O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\DRIVERS\rspndr.sys (rspndr) .(.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) - LEGACY_RSPNDR O64 - Services: CurCS - 02/11/2006 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV O64 - Services: CurCS - 11/04/2009 - C:\Windows\system32\tcpipcfg.dll (Smb) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_SMB O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\Drivers\spldr.sys (spldr) .(.Microsoft Corporation - loader for security processor.) - LEGACY_SPLDR O64 - Services: CurCS - 18/02/2011 - C:\Windows\System32\DRIVERS\srv.sys (srv) .(.Microsoft Corporation - Server driver.) - LEGACY_SRV O64 - Services: CurCS - 29/04/2011 - C:\Windows\System32\DRIVERS\srv2.sys (srv2) .(.Microsoft Corporation - Smb 2.0 Server driver.) - LEGACY_SRV2 O64 - Services: CurCS - 29/04/2011 - C:\Windows\System32\DRIVERS\srvnet.sys (srvnet) .(.Microsoft Corporation - Server Network driver.) - LEGACY_SRVNET O64 - Services: CurCS - 11/04/2009 - C:\Windows\system32\tcpipcfg.dll (Tcpip) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_TCPIP O64 - Services: CurCS - 08/12/2009 - C:\Windows\System32\drivers\tcpipreg.sys (tcpipreg) .(.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) - LEGACY_TCPIPREG O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\drivers\tdtcp.sys (TDTCP) .(.Microsoft Corporation - TCP Transport Driver.) - LEGACY_TDTCP O64 - Services: CurCS - 11/04/2009 - C:\Windows\system32\tcpipcfg.dll (tdx) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_TDX O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\DRIVERS\tssecsrv.sys (tssecsrv) .(.Microsoft Corporation - TS Security Filter Driver.) - LEGACY_TSSECSRV O64 - Services: CurCS - 11/04/2009 - C:\Windows\System32\DRIVERS\udfs.sys (udfs) .(.Microsoft Corporation - UDF File System Driver.) - LEGACY_UDFS O64 - Services: CurCS - 24/07/2007 - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (VAIO Event Service) .(.Sony Corporation - VAIO Event Service (Service Module).) - LEGACY_VAIO_EVENT_SERVICE O64 - Services: CurCS - 19/01/2008 - C:\Windows\system32\drivers\vga.sys (VgaSave) .(.Microsoft Corporation - VGA/Super VGA Video Driver.) - LEGACY_VGASAVE O64 - Services: CurCS - 11/04/2009 - C:\Windows\System32\drivers\volmgrx.sys (volmgrx) .(.Microsoft Corporation - Volume Manager Extension Driver.) - LEGACY_VOLMGRX O64 - Services: CurCS - 21/08/2012 - C:\Windows\System32\drivers\volsnap.sys (volsnap) .(.Microsoft Corporation - Pilote de cliché instantané du volume.) - LEGACY_VOLSNAP O64 - Services: CurCS - 19/01/2008 - C:\Windows\System32\DRIVERS\wanarp.sys (Wanarpv6) .(.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - LEGACY_WANARPV6 O64 - Services: CurCS - 26/07/2012 - C:\Windows\System32\drivers\Wdf01000.sys (Wdf01000) .(.Microsoft Corporation - Runtime de l’infrastructure de pilotes en m.) - LEGACY_WDF01000 O64 - Services: CurCS - 13/02/2007 - C:\Windows\System32\DRIVERS\wimfltr.sys (WimFltr) .(.Microsoft Corporation - Windows Image File Mini-Filter Driver.) - LEGACY_WIMFLTR O64 - Services: CurCS - ??\??\???? - Pas de propriétaire (wmiApSrv) .(...) - LEGACY_WMIAPSRV O64 - Services: CurCS - 11/04/2009 - C:\Windows\System32\wscsvc.dll (wscsvc) .(.Microsoft Corporation - Service Centre de sécurité de Windows.) - LEGACY_WSCSVC O64 - Services: CurCS - 26/07/2012 - C:\Windows\system32\drivers\Wudfpf.sys (WudfPf) .(.Microsoft Corporation - Windows Driver Foundation - User-mode Drive.) - LEGACY_WUDFPF O64 - Services: CurCS - 08/05/2007 - C:\Windows\System32\DRIVERS\xaudio.sys (XAudio) .(.Conexant Systems, Inc. - Modem Audio Device Driver.) - LEGACY_XAUDIO ~ Legacy: 89 Scanned in 00mn 01s ---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d'événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.bat> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d'événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.js> [HKCR\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe ~ FASS Keys: 19 Scanned in 00mn 00s ---\\ Start Menu Internet (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Search Browser Infection (O69) O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.admin", false); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.aflt", "babsst"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.autoRvrt", "false"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.bbDpng", "19"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.cntry", "FR"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.dfltLng", "en"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.excTlbr", false); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.ffxUnstlRst", true); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.hdrMd5", "0ADFA6E24F4FBD84BC6EA09132472238"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.id", "e0200379000000000000001b77cae7a0"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.instlDay", "15814"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.instlRef", "sst"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.lastVrsnTs", "1.8.16.1615:51:57"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.newTab", false); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.prdct", "delta"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.prtnrId", "delta"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.rvrt", "false"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.sg", "azb"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.smplGrp", "none"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.tlbrId", "base"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.tlbrSrchUrl", ""); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.vrsn", "1.8.16.16"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.vrsnTs", "1.8.16.1615:51:57"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("extensions.delta.vrsni", "1.8.16.16"); O69 - SBI: prefs.js [serge - gr9voc6h.default] user_pref("weboftrust.search.ask.display", "Ask.com Web Search"); O69 - SBI: SearchScopes [HKCU] ${searchCLSID} - (@ieframe.dll,-12512) - http://search.live.com O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Delta Search) - http://www1.delta-search.com =>Toolbar.DeltaSearch O69 - SBI: SearchScopes [HKCU] {449BD4FF-2F02-4C5B-A230-86D4B76972F9} - (Bing) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {5F698DFF-E87F-406E-A4BD-DBABBE5018BD} [DefaultScope] - (Google) - http://www.google.com O69 - SBI: SearchScopes [HKCU] {70D46D94-BF1E-45ED-B567-48701376298E} - (Google Desktop) - http://127.0.0.1:4664/search&s=fozVJBaxV8odixnJYluZYQ-LXGA?q={searchTerms} ~ Keys: Scanned in 00mn 00s ---\\ Recherche des services démarrés par Svchost (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [24576] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [62976] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [247808] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [40448] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [40448] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [125952] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [576512] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [438784] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [315392] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [90624] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d'accès distant.) -- C:\Windows\System32\rasmans.dll [262144] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [68608] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [47104] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l'application d'assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [288256] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242688] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes Terminal Server.) -- C:\Windows\System32\termsrv.dll [449024] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [1933848] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [758784] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [247808] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [200704] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d'ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [19968] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [33280] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [111616] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [45056] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [153088] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [57344] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [162304] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [601600] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service de configuration des services Terminal Server.) -- C:\Windows\System32\sessenv.dll [84992] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [81920] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [68096] ~ Services: 31 Scanned in 00mn 00s ---\\ Recherche particuliere à la racine de certains dossiers (O84) [MD5.AF463117009758EA90864D3C915657DC] [SPRF][03/08/2007] (...) -- C:\Users\serge\AppData\Local\d3d9caps.dat [680] [MD5.94D8F6C110B4E98B2F30F7F7A0C0F53A] [SPRF][07/03/2013] (...) -- C:\Users\serge\AppData\Local\Temp\chart_data.dat [21054] [MD5.3F4BAF379E2202D3644605F3C2F9A191] [SPRF][20/12/2006] (. InterVideo Inc. - IVIVIDEO LOGID.44657.) -- C:\Users\serge\AppData\Local\Temp\F{0246CA20-776D-11D2-8010-00104B9B8592}0.xxx [5308440] [MD5.43C35081CE0AC367267C5916AB25A817] [SPRF][19/04/2013] (...) -- C:\Users\serge\AppData\Local\Temp\vlc-2.0.6-win32.exe [22948790] [MD5.AD3C3DBDC4F933D8EC8F18111A4C6DEF] [SPRF][28/01/2011] (...) -- C:\Users\serge\AppData\Roaming\wklnhst.dat [340] [MD5.1D18D923EA0390BB2B453FF833C8B1B4] [SPRF][01/02/2010] (.Unisys Corporation - Pas de description.) -- C:\Users\serge\Desktop\Plug-in_messagerie_vocale_888.exe [1517136] [MD5.AF59DE458776D6F5570047749588E460] [SPRF][19/04/2013] (.Nicolas Coolman - ZHPDiag.) -- C:\Users\serge\Desktop\ZHPDiag2.exe [5583119] ~ Files: Scanned in 00mn 05s ---\\ Firewall Active Exception List (FirewallRules) (O87) O87 - FAEL: "PerfLogsAlerts-PLASrv-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Serveur DCOM des journaux et alertes de performance.) -- C:\Windows\system32\plasrv.exe O87 - FAEL: "PerfLogsAlerts-DCOM-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PerfLogsAlerts-PLASrv-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Serveur DCOM des journaux et alertes de performance.) -- C:\Windows\system32\plasrv.exe O87 - FAEL: "PerfLogsAlerts-DCOM-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "SNMPTRAP-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Interruption SNMP.) -- C:\Windows\system32\snmptrap.exe O87 - FAEL: "WMP-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe O87 - FAEL: "WMP-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe O87 - FAEL: "WMP-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-QWave-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-Out-UDP-NoScope" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-WMP-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-WMP-Out-UDP-NoScope" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-WMP-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe O87 - FAEL: "WMPNSS-Out-UDP-NoScope" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe O87 - FAEL: "WMPNSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe O87 - FAEL: "WMPNSS-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe O87 - FAEL: "WMPNSS-QWave-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-Out-UDP" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-QWave-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-SSDPSrv-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-SSDPSrv-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMPNSS-WMP-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-WMP-Out-UDP" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-WMP-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Windows Media Player.) -- C:\Program Files\Windows Media Player\wmplayer.exe O87 - FAEL: "WMPNSS-In-UDP" | In - Public - P17 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe O87 - FAEL: "WMPNSS-Out-UDP" | Out - Public - P17 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe O87 - FAEL: "WMPNSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe O87 - FAEL: "WMPNSS-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmpnetwk.exe O87 - FAEL: "WMPNSS-UPnP-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-SSDPSrv-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-SSDPSrv-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-In-TCP" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Media Center.) -- C:\Windows\ehome\ehshell.exe O87 - FAEL: "MCX-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Media Center.) -- C:\Windows\ehome\ehshell.exe O87 - FAEL: "MCX-QWave-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-QWave-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-QWave-In-TCP" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-QWave-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Media Center.) -- C:\Windows\ehome\ehshell.exe O87 - FAEL: "MCX-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Media Center.) -- C:\Windows\ehome\ehshell.exe O87 - FAEL: "MCX-MCX2SVC-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MCX-Prov-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - MCX2 Provisioning library.) -- C:\Windows\ehome\mcx2prov.exe O87 - FAEL: "WinCollab-DFSR-In-TCP" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Réplication DFS.) -- C:\Windows\system32\dfsr.exe O87 - FAEL: "WinCollab-DFSR-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Réplication DFS.) -- C:\Windows\system32\dfsr.exe O87 - FAEL: "WinCollab-In-TCP" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Windows Meeting Space.) -- C:\Program Files\Windows Collaboration\WinCollab.exe O87 - FAEL: "WinCollab-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Windows Meeting Space.) -- C:\Program Files\Windows Collaboration\WinCollab.exe O87 - FAEL: "WinCollab-In-UDP" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Windows Meeting Space.) -- C:\Program Files\Windows Collaboration\WinCollab.exe O87 - FAEL: "WinCollab-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Windows Meeting Space.) -- C:\Program Files\Windows Collaboration\WinCollab.exe O87 - FAEL: "WinCollab-P2P-In-TCP" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WinCollab-P2P-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAdmin-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAdmin-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAdmin-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAdmin-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MsiScsi-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MsiScsi-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MsiScsi-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MsiScsi-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "Collab-P2PHost-In-TCP" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Voisinage immédiat.) -- C:\Windows\system32\p2phost.exe O87 - FAEL: "Collab-P2PHost-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Voisinage immédiat.) -- C:\Windows\system32\p2phost.exe O87 - FAEL: "Collab-P2PHost-WSD-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Voisinage immédiat.) -- C:\Windows\system32\p2phost.exe O87 - FAEL: "Collab-P2PHost-WSD-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Voisinage immédiat.) -- C:\Windows\system32\p2phost.exe O87 - FAEL: "Collab-PNRP-In-UDP" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "Collab-PNRP-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "Collab-PNRP-SSDPSrv-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "Collab-PNRP-SSDPSrv-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RVM-VDS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Service de disque virtuel.) -- C:\Windows\system32\vds.exe O87 - FAEL: "RVM-VDSLDR-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Virtual Disk Service Loader.) -- C:\Windows\system32\vdsldr.exe O87 - FAEL: "RVM-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RVM-VDS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Service de disque virtuel.) -- C:\Windows\system32\vds.exe O87 - FAEL: "RVM-VDSLDR-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Virtual Disk Service Loader.) -- C:\Windows\system32\vdsldr.exe O87 - FAEL: "RVM-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-WINMGMT-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-WINMGMT-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-ASYNC-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) -- C:\Windows\system32\wbem\unsecapp.exe O87 - FAEL: "WMI-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-WINMGMT-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-WINMGMT-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WMI-ASYNC-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Sink to receive asynchronous callbacks for WMI client application.) -- C:\Windows\system32\wbem\unsecapp.exe O87 - FAEL: "PNRPMNRS-PNRP-In-UDP" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PNRPMNRS-PNRP-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PNRPMNRS-SSDPSrv-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "PNRPMNRS-SSDPSrv-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteEventLogSvc-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteEventLogSvc-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteEventLogSvc-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteEventLogSvc-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteSvcAdmin-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\Windows\system32\services.exe O87 - FAEL: "RemoteSvcAdmin-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteSvcAdmin-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\Windows\system32\services.exe O87 - FAEL: "RemoteSvcAdmin-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteFwAdmin-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteFwAdmin-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteFwAdmin-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteFwAdmin-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "BITSSVC-WSD-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "BITSSVC-WSD-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "BITSSVC-RPC-In-TCP" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "BITSSVC-RPCSS-In-TCP" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteTask-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteTask-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteTask-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteTask-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MSDTC-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Programme DTCconsole MS.) -- C:\Windows\system32\msdtc.exe O87 - FAEL: "MSDTC-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Programme DTCconsole MS.) -- C:\Windows\system32\msdtc.exe O87 - FAEL: "MSDTC-KTMRM-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MSDTC-RPCSS-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MSDTC-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Programme DTCconsole MS.) -- C:\Windows\system32\msdtc.exe O87 - FAEL: "MSDTC-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Programme DTCconsole MS.) -- C:\Windows\system32\msdtc.exe O87 - FAEL: "MSDTC-KTMRM-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "MSDTC-RPCSS-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-RAServer-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Serveur COM d’assistance à distance Windows.) -- C:\Windows\system32\raserver.exe O87 - FAEL: "RemoteAssistance-RAServer-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Serveur COM d’assistance à distance Windows.) -- C:\Windows\system32\raserver.exe O87 - FAEL: "RemoteAssistance-DCOM-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-In-TCP-EdgeScope" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe O87 - FAEL: "RemoteAssistance-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe O87 - FAEL: "RemoteAssistance-SSDPSrv-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-SSDPSrv-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-UPnP-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-In-TCP-EdgeScope-Active" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe O87 - FAEL: "RemoteAssistance-Out-TCP-Active" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Assistance à distance Windows.) -- C:\Windows\system32\msra.exe O87 - FAEL: "RemoteAssistance-SSDPSrv-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-SSDPSrv-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "RemoteAssistance-UPnP-Out-TCP-Active" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WPDMTP-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\wudfhost.exe O87 - FAEL: "WPDMTP-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Windows Driver Foundation - Processus hôte de l’infrastructure de pilotes.) -- C:\Windows\system32\wudfhost.exe O87 - FAEL: "WPDMTP-SSDPSrv-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WPDMTP-SSDPSrv-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "WPDMTP-UPnP-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NetPres-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Connect to a Network Projector.) -- C:\Windows\system32\netproj.exe O87 - FAEL: "NetPres-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Connect to a Network Projector.) -- C:\Windows\system32\netproj.exe O87 - FAEL: "NetPres-WSD-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Connect to a Network Projector.) -- C:\Windows\system32\netproj.exe O87 - FAEL: "NetPres-WSD-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Connect to a Network Projector.) -- C:\Windows\system32\netproj.exe O87 - FAEL: "NetPres-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Connect to a Network Projector.) -- C:\Windows\system32\netproj.exe O87 - FAEL: "NetPres-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Connect to a Network Projector.) -- C:\Windows\system32\netproj.exe O87 - FAEL: "CoreNet-DHCP-In" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-DHCP-Out" | Out - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-Teredo-In" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-Teredo-Out" | Out - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-GP-Out-TCP" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-DNS-Out-UDP" | Out - Domain - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "CoreNet-GP-LSASS-Out-TCP" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Processus de l’autorité de sécurité locale.) -- C:\Windows\system32\lsass.exe O87 - FAEL: "{B01DB2A6-B311-49ED-B4A9-91D7E8573516}" | In - Public - P6 - FALSE | .(.Sony Corporation - VAIO Media.) -- C:\Program Files\Sony\VAIO Media 6.0\Vc.exe O87 - FAEL: "{13904DB8-1595-46F3-99F1-EFC4EE68B87B}" | In - Public - P17 - FALSE | .(.Sony Corporation - VAIO Media.) -- C:\Program Files\Sony\VAIO Media 6.0\Vc.exe O87 - FAEL: "TCP Query User{27BFD4A0-1B59-4220-A8D0-453DC8B50F29}C:\program files\skype\phone\skype.exe" | In - Public - P6 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\program files\skype\phone\skype.exe O87 - FAEL: "UDP Query User{76F92962-91C8-43FD-AB91-6AC151606943}C:\program files\skype\phone\skype.exe" | In - Public - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\program files\skype\phone\skype.exe O87 - FAEL: "TCP Query User{FF0A2A70-EFE1-40ED-86F5-1ED4E009B5C7}C:\program files\mozilla firefox\firefox.exe" | In - Public - P6 - TRUE | .(.Mozilla Corporation - Firefox.) -- C:\program files\mozilla firefox\firefox.exe O87 - FAEL: "UDP Query User{4FA491EC-E155-4192-B9CB-2D7D16D3E177}C:\program files\mozilla firefox\firefox.exe" | In - Public - P17 - TRUE | .(.Mozilla Corporation - Firefox.) -- C:\program files\mozilla firefox\firefox.exe O87 - FAEL: "{656C10AA-9363-4661-B8FB-99B15AF784BD}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{DB9A1A34-13EB-466F-927D-43678C7B7BE5}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{ED0FF48C-73E7-4103-9D6A-822AE7E6A3CC}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{F3C72F42-3FB0-4A95-BD18-9518642BFFA6}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "TCP Query User{87184A6E-B3C8-459C-B2DC-FAB92AD5A3C6}C:\windows\system32\ftp.exe" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Logiciel de transfert de fichiers.) -- C:\windows\system32\ftp.exe O87 - FAEL: "UDP Query User{F9A4F129-326E-4038-BE83-3977E9E4A0D1}C:\windows\system32\ftp.exe" | In - Public - P17 - TRUE | .(.Microsoft Corporation - Logiciel de transfert de fichiers.) -- C:\windows\system32\ftp.exe O87 - FAEL: "{B66732D9-5635-4C05-A83F-A98ECEADB18F}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{24014CCB-EB79-4E47-9E88-8BE483A1BE27}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{A21C0690-9DCC-494B-9D18-C6821550E769}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{7D8A7C74-64F6-45A8-AF79-8378FE1BA735}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{62815D31-6CBC-496D-91F4-454D7760E46D}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{6E1E5845-CA57-4E8A-A237-941C42AE890E}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{D81810E8-8844-4F6D-B8DC-0748417A6989}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{08802B96-0D76-4F1E-B2F9-CBA0464B667E}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{209A7EB5-C274-49D8-8ADB-DB3C85795BDA}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{70CCA9BF-0F64-4513-BD92-D6703383663D}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{D554FD73-A694-46EF-BBA1-6524302B357F}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{70347FD3-A63B-428D-BAEA-2B6F4E6A5482}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{34BF2B3B-0280-4A66-BFCA-8D59CF31BA4D}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{C94D6C6F-EA8D-4605-B0ED-88540575939F}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{0980686F-6CBC-443E-9F47-29E3A43CBB3C}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{6EA56A3F-68F3-458C-8672-5D50F7FFF73D}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{D137B6DC-EBAE-4895-9E09-A1BC9854E770}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{22117102-54C8-4C53-B709-B0B2A7E913F5}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{6C448D52-69C4-43D6-8979-63C1C370E320}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{6CFFE782-186B-42BC-A2FD-A21E2A3E9703}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{20A63F1F-A42A-4B83-A2C1-3E5D0E3E21F2}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{AA6EF84C-7463-4FC4-8D38-DA00E7933C5B}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{1F3C7AE6-83A8-44B4-A28E-671A314B6B1B}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{E4291F3F-A475-4FDB-B77B-DE6A1CF561F5}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{C9F67B3A-D654-4971-9677-DF47D8C4F819}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{4F9D340C-55E8-4CF4-9BF6-07260DADA5D3}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{79CBE1CC-5400-4F16-AEF6-1AFE1BC92101}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{682D7A5B-18F6-4C63-A5E7-DBAB5737DEE5}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{33A3DC0A-9ED2-423A-AB32-2DB40B5D3255}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{046B8D7E-2E37-41CE-AF77-253A613DB05A}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{5B8135B7-2C2F-4A07-BA53-44A8DAFC0DE5}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{62F73661-B74F-4088-B30F-49AAFBED0735}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{97B79E66-0536-499A-8619-7B4B50E5FA65}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{2E858CF4-CCCB-4577-A97A-43FDA8623014}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "SNMPTRAP-In-UDP-NoScope" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Interruption SNMP.) -- C:\Windows\system32\snmptrap.exe O87 - FAEL: "FPS-SpoolSvc-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe O87 - FAEL: "FPS-SpoolSvc-In-TCP" | In - Private - P6 - FALSE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe O87 - FAEL: "NETDIS-SSDPSrv-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-SSDPSrv-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-UPnP-Out-TCP-Active" | Out - Private - P6 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDPHOST-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDPHOST-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-LLMNR-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-LLMNR-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDRESPUB-WSD-In-UDP-Active" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDRESPUB-WSD-Out-UDP-Active" | Out - Private - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-SSDPSrv-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-SSDPSrv-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-UPnP-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDPHOST-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDPHOST-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-LLMNR-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-LLMNR-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDRESPUB-WSD-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "NETDIS-FDRESPUB-WSD-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\system32\svchost.exe O87 - FAEL: "{B379D4D7-46B1-4A7A-B6B5-FAF7FF349755}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe (.not file.) O87 - FAEL: "{D9524625-E992-4FAD-B43E-F77686402ED6}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Processus hôte pour les services Windows.) -- C:\Windows\System32\svchost.exe O87 - FAEL: "{F2735C48-F563-47B5-94CD-B62BA575FB9C}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Windows Live Communications Platform.) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe O87 - FAEL: "{13336E8E-9B2B-4FCB-B429-9ACB22C749EF}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Mesh Operating Environment.) -- C:\Program Files\Windows Live\Mesh\MOE.exe O87 - FAEL: "TCP Query User{A1FCAC2D-89A2-402A-8F48-7E133BB322BB}C:\program files\google\google earth\plugin\geplugin.exe" |In - Public - P6 - TRUE | .(...) -- C:\program files\google\google earth\plugin\geplugin.exe (.not file.) O87 - FAEL: "UDP Query User{73505147-3E7D-4EAB-8CDD-8606D9686AAE}C:\program files\google\google earth\plugin\geplugin.exe" |In - Public - P17 - TRUE | .(...) -- C:\program files\google\google earth\plugin\geplugin.exe (.not file.) O87 - FAEL: "{56E82896-A6AF-4615-8447-EC77F5DBFBE3}" | In - Public - P6 - TRUE | .(.PeeringPortal - KTF MUSIC AoD Server.) -- C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe O87 - FAEL: "{C456042E-9A08-406A-8B2E-88706AB9F79D}" | In - Public - P17 - TRUE | .(.PeeringPortal - KTF MUSIC AoD Server.) -- C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe O87 - FAEL: "{3AAE4278-D6A3-485C-B957-E3578E5D5CCF}" | In - Public - P6 - TRUE | .(.PeeringPortal - KTF MUSIC VoD Server.) -- C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe O87 - FAEL: "{AE86ADD9-9229-4FEA-82BC-17B74F344678}" | In - Public - P17 - TRUE | .(.PeeringPortal - KTF MUSIC VoD Server.) -- C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe O87 - FAEL: "TCP Query User{4844B614-C2BF-48E2-88D0-EACD7586D7ED}C:\program files\epson software\event manager\eeventmanager.exe" | In - Public - P6 - TRUE | .(.SEIKO EPSON CORPORATION.) -- C:\program files\epson software\event manager\eeventmanager.exe O87 - FAEL: "UDP Query User{4AFE199D-EFB3-443A-BBBB-2B1AA5802038}C:\program files\epson software\event manager\eeventmanager.exe" | In - Public - P17 - TRUE | .(.SEIKO EPSON CORPORATION.) -- C:\program files\epson software\event manager\eeventmanager.exe O87 - FAEL: "{E52EA634-FE51-4B2B-8AC0-62F94073EBD6}" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe O87 - FAEL: "{432F9295-6443-419E-AA3C-EF3FCAC0C075}" | In - None - P6 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe ~ Firewall: 227 Scanned in 00mn 02s ---\\ Scan Additionnel (O88) Database Version : v2.11580 - (18/04/2013) Clés trouvées (Keys found) : 82 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 11 Fichiers trouvés (Files found) : 0 [HKLM\Software\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}] =>Adware.Agent [HKLM\Software\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}] =>Adware.IMBooster [HKLM\Software\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}] =>Adware.IMBooster [HKLM\Software\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}] =>Adware.IMBooster [HKLM\Software\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}] =>Adware.IMBooster [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] =>Toolbar.Babylon [HKLM\Software\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}] =>PUP.RewardsArcade [HKCU\Software\delta LTD] =>Toolbar.DeltaSearch [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1631550F-191D-4826-B069-D9439253D926}] =>Adware.PriceGong [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1631550F-191D-4826-B069-D9439253D926}] =>Adware.PriceGong [HKLM\Software\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}] =>Adware.PriceGong [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}] =>Adware.PriceGong [HKLM\Software\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}] =>PUP.RewardsArcade [HKLM\Software\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}] =>PUP.RewardsArcade [HKLM\Software\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}] =>PUP.Software.Updater [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}] =>Adware.IMBooster [HKLM\Software\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}] =>PUP.RewardsArcade [HKLM\Software\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}] =>Adware.PriceGong [HKLM\Software\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}] =>PUP.RewardsArcade [HKLM\Software\Classes\TypeLib\{8B3372D0-09F0-41A5-8D9B-134E148672FB}] =>Adware.PriceGong [HKLM\Software\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}] =>PUP.Software.Updater [HKLM\Software\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}] =>PUP.Software.Updater [HKLM\Software\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}] =>PUP.RewardsArcade [HKLM\Software\Classes\CLSID\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}] =>Adware.PriceGong [HKLM\Software\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}] =>PUP.RewardsArcade [HKLM\Software\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}] =>PUP.RewardsArcade [HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}] =>Adware.IMBooster [HKLM\Software\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}] =>PUP.RewardsArcade [HKLM\Software\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}] =>PUP.RewardsArcade [HKLM\Software\Classes\AppID\PriceGongIE.DLL] =>Adware.PriceGong [HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\pricegong] =>Adware.PriceGong [HKLM\Software\Classes\PriceFactorIE.PriceGongBHO] =>Adware.PriceGong [HKLM\Software\Classes\PriceFactorIE.PriceGongBHO.1] =>Adware.PriceGong [HKLM\Software\Classes\PriceGongIE.PriceGongCtrl] =>Adware.PriceGong [HKLM\Software\Classes\PriceGongIE.PriceGongCtrl.1] =>Adware.PriceGong [HKLM\Software\Classes\Updater.AmiUpd] =>PUP.Software.Updater [HKLM\Software\Classes\Updater.AmiUpd.1] =>PUP.Software.Updater [HKLM\Software\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok] =>Adware.PriceGong [HKLM\Software\Classes\Installer\Features\90C64EA18BA25EE488BF80DCF07F2FFD] =>Toolbar.Agent [HKLM\Software\Classes\Installer\Products\90C64EA18BA25EE488BF80DCF07F2FFD] =>Toolbar.Agent [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\90C64EA18BA25EE488BF80DCF07F2FFD] =>Toolbar.Agent [HKCU\Software\Iminent] =>Adware.IMBooster [HKLM\Software\Iminent] =>Adware.IMBooster [HKCU\Software\AppDataLow\Software\PriceGong] =>Adware.PriceGong [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}] =>Toolbar.Agent [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}] =>PUP.Software.Updater [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP] =>Adware.IMBooster [HKLM\Software\Classes\Prod.cap] =>Toolbar.Babylon [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375] =>Toolbar.Agent [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5] =>Toolbar.Agent [HKLM\Software\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}] =>Toolbar.DeltaSearch C:\Program Files\Duuqu =>Toolbar.Agent C:\Program Files\FrameFox =>Toolbar.Agent C:\Program Files\PriceGong =>Adware.PriceGong C:\ProgramData\Babylon =>Toolbar.Babylon C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong =>Adware.PriceGong C:\Users\serge\AppData\Roaming\Babylon =>Toolbar.Babylon C:\Users\serge\AppData\Local\Babylon =>Toolbar.Babylon C:\Users\serge\AppData\Local\Duuqu =>Toolbar.Agent C:\Users\serge\AppData\Local\SwvUpdater =>PUP.Software.Updater C:\Users\serge\AppData\LocalLow\PriceGong =>Adware.PriceGong C:\Users\serge\AppData\Roaming\Mozilla\Firefox\Profiles\gr9voc6h.default\Extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829} =>Adware.PriceGong ~ Additionnel: Scanned in 00mn 30s ---\\ Product Upgrade Codes (O90) O90 - PUC: "0000009F810000000000709475387300" . (.ABBYY FineReader 9.0 Sprint.) -- C:\Windows\Installer\{F9000000-0018-0000-0000-074957833700}\ARPPRODUCTICON.exe O90 - PUC: "000021090200C0400000000000F01FEC" . (.Module de compatibilité pour Microsoft Office System 2007.) -- C:\Windows\Installer\{90120000-0020-040C-0000-0000000FF1CE}\O12ConvIcon.exe O90 - PUC: "00002159FA00C0400000000000F01FEC" . (.Microsoft Office PowerPoint Viewer 2007 (French).) -- C:\Windows\Installer\{95120000-00AF-040C-0000-0000000FF1CE}\ppvwicon.exe,0 O90 - PUC: "076CFAAAB965F2A4284B2449E5D03EFE" . (.Windows Live Writer.) -- C:\Windows\Installer\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}\ApplicationIcon.ico O90 - PUC: "0E05125073EC21C49B1F1C3F118C6E57" . (.FrameFox Extensions 1.0.1.0.) -- C:\Windows\Installer\{052150E0-CE37-4C12-B9F1-C1F311C8E675}\FrameFox.ico O90 - PUC: "0F8133468CD6ABD49B265D7BF43E76D7" . (.Microsoft Camera Codec Pack.) -- C:\Windows\Installer\{643318F0-6DC8-4DBA-B962-D5B74FE3677D}\icon.ico O90 - PUC: "11F12B5E3396B0E42AC597363E0CD711" . (.Windows Live Messenger.) -- C:\Windows\Installer\{E5B21F11-6933-4E0B-A25C-7963E3C07D11}\MsblIco.Exe O90 - PUC: "1C4235E6CF4867F4A9A36CE5708FE06E" . (.Complément Messenger.) -- C:\Windows\Installer\{6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}\CompanionIcon O90 - PUC: "1D034B0FAA6BD374B960AAD30DF10D8B" . (.Microsoft SQL Server 2005 Compact Edition [ENU].) -- C:\Windows\Installer\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}\ProductIcon O90 - PUC: "283F4817C6A858B43ACA6B73431B2E14" . (.SAMSUNG Mobile USB Driver.) -- C:\Windows\Installer\{7184F382-8A6C-4B85-A3AC-B63734B1E241}\ARPPRODUCTICON.exe O90 - PUC: "393793D005B925c4485D773E4482F978" . (.Roxio RecordNow Data.) -- C:\Windows\Installer\{0D397393-9B50-4c52-84D5-77E344289F87}\RoxioCentral.exe O90 - PUC: "68AB67CA7DA76301B744BA0000000010" . (.Adobe Reader XI (11.0.02) - Français.) -- C:\Windows\Installer\{AC76BA86-7AD7-1036-7B44-AB0000000001}\SC_Reader.ico O90 - PUC: "68C0BF7B4A142044A93319C26402240A" . (.Roxio Easy Media Creator Home.) -- C:\Windows\Installer\{B7FB0C86-41A4-4402-9A33-912C462042A0}\ARPPRODUCTICON.exe O90 - PUC: "72B17402207D8EF4D8CE7020CCC8A058" . (.WinDVD.) -- C:\Windows\Installer\{20471B27-D702-4FE8-8DEC-0702CC8C0A85}\ARPPRODUCTICON.exe O90 - PUC: "79D3E6D2FDF13994CA57275FE94C545C" . (.Windows Live Family Safety.) -- C:\Windows\Installer\{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}\fssicon.ico O90 - PUC: "7CFCFF386C886c14782559A85423C528" . (.Roxio RecordNow Audio.) -- C:\Windows\Installer\{83FFCFC7-88C6-41c6-8752-958A45325C82}\RoxioCentral.exe O90 - PUC: "8CDC4930DBAF8de41B4030938367FDFD" . (.Roxio Tools Module.) -- C:\Windows\Installer\{0394CDC8-FABD-4ed8-B104-03393876DFDF}\RoxioCentral.exe O90 - PUC: "90C64EA18BA25EE488BF80DCF07F2FFD" . (.Bing Bar.) -- C:\Windows\Installer\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}\icon_installer_ico O90 - PUC: "9F2FDFE0D6387BE43AD230B83D1FBFA2" . (.Security Update for CAPICOM (KB931906).) -- C:\Windows\Installer\{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}\folder.ico O90 - PUC: "A8DDC9166B411a34BAC6F0E44EC80E84" . (.Roxio RecordNow Copy.) -- C:\Windows\Installer\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}\RoxioCentral.exe O90 - PUC: "B0860B8CEADC9084F91983B7D60EF0C7" . (.Roxio Easy Media Creator Home.) -- C:\Windows\Installer\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}\RoxioCentral.exe O90 - PUC: "B4B39F110F84E4A4EA77FD9AA69966B4" . (.Roxio EasyArchive.) -- C:\Windows\Installer\{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}\RoxioCentral.exe O90 - PUC: "BE31195E5820DFB43AA77BE9CAB6F8B4" . (.Microsoft SQL Server Compact 3.5 SP1 English.) -- C:\Windows\Installer\{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}\ProductIcon O90 - PUC: "C040110900063D11C8EF10054038389C" . (.Microsoft Office Professional Edition 2003.) -- C:\Windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe,6 O90 - PUC: "D7314F9862C648A4DB8BE2A5B47BE100" . (.Microsoft Silverlight.) -- c:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ARPIcon O90 - PUC: "D83BC1B64E2E03a439D3FEEDAB67DAC9" . (.Microsoft Works.) -- C:\Windows\Installer\{6B1CB38D-E2E4-4a30-933D-EFDEBA76AD9C}\Win2Kico.exe O90 - PUC: "E0CF391F81E9CF049A4705A9B1DD42A0" . (.Samsung New PC Studio.) -- C:\Windows\Installer\{F193FC0E-9E18-40FC-A974-509A1BDD240A}\ARPPRODUCTICON.exe O90 - PUC: "E7F34DE86F8A8984FA116B51F8E2FD49" . (.Epson Event Manager.) -- C:\Windows\Installer\{8ED43F7E-A8F6-4898-AF11-B6158F2EDF94}\icon.exe O90 - PUC: "E7FF67E4ABEA78C47B88DC745E24B5D9" . (.Skype™ 6.3.) -- C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe ~ Update Products: 103 Scanned in 00mn 00s ---\\ MyComputer Name Space (O92) O92 - MNS: Dossiers Web - {BDEADF00-C265-11D0-BCED-00A0C90AB50F} ~ MNS: 1 Scanned in 00mn 00s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 14/05/2009 759048 | (ABBYY.Licensing.FineReader.Sprint.9.0) . (.ABBYY.) - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe SR - | Auto 18/12/2012 65192 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe SS - | Demand 10/04/2013 256904 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe SR - | Auto 07/03/2013 45248 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe SS - | Auto 11/06/2012 193616 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe SR - | Demand 11/06/2012 240208 | (BBUpdate) . (.Microsoft Corporation..) - C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe SS - | Auto 19/04/2013 98360 | (dqupdate) . (.Duuqu Group.) - C:\Program Files\Duuqu\Update\DuuquUpdate.exe SS - | Demand 19/04/2013 98360 | (dqupdatem) . (.Duuqu Group.) - C:\Program Files\Duuqu\Update\DuuquUpdate.exe SS - | Demand 29/07/2010 238952 | (FsUsbExService) . (.Teruten.) - C:\Windows\system32\FsUsbExService.exe SS - | Demand 25/06/2010 30192 | (GoogleDesktopManager-051210-111108) . (.Google.) - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe SS - | Auto 19/03/2011 136176 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 19/03/2011 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 03/08/2007 138168 | (gusvc) . (.Google.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe SS - | Demand 14/11/2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe SS - | Demand 11/04/2013 115608 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe SS - | Demand 14/12/2006 45056 | (MSCSPTISRV) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe SS - | Auto 29/06/2007 200704 | (NSUService) . (.Sony Corporation.) - C:\Program Files\Sony\Network Utility\NSUService.exe SS - | Demand 57344 | (PACSPTISVR) . (...) - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe SR - | Auto 25/07/2012 1326176 | (Secunia PSI Agent) . (.Secunia.) - C:\Program Files\Secunia\PSI\PSIA.exe SS - | Demand 25/07/2012 681056 | (Secunia Update Agent) . (.Secunia.) - C:\Program Files\Secunia\PSI\sua.exe SS - | Demand 09/07/2007 415392 | (Service CANALPLAY) . (.Canal+ Active.) - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe SS - | Auto 01/03/2013 161384 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe SS - | Demand 14/12/2006 69632 | (SPTISRV) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe SS - | Demand 28/06/2007 73728 | (VAIO Entertainment TV Device Arbitration Service) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe SS - | Demand 24/07/2007 182392 | (VAIO Event Service) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe SS - | Demand 20/06/2007 2523136 | (VAIOMediaPlatform-IntegratedServer-AppServer) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe SS - | Demand 20/06/2007 397312 | (VAIOMediaPlatform-IntegratedServer-HTTP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe SS - | Demand 20/06/2007 1089536 | (VAIOMediaPlatform-IntegratedServer-UPnP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe SS - | Demand 20/06/2007 499712 | (VAIOMediaPlatform-Mobile-Gateway) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe SS - | Demand 10/01/2007 745472 | (VAIOMediaPlatform-UCLS-AppServer) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe SS - | Demand 20/06/2007 397312 | (VAIOMediaPlatform-UCLS-HTTP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe SS - | Demand 20/06/2007 1089536 | (VAIOMediaPlatform-UCLS-UPnP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe SS - | Demand 05/07/2007 292152 | (VcmIAlzMgr) . (.Sony Corporation.) - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe SS - | Demand 05/07/2007 79736 | (VcmXmlIfHelper) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe SR - | Demand 28/06/2007 274432 | (Vcsw) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe SR - | Auto 28/06/2007 188416 | (VzCdbSvc) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe SR - | Auto 28/06/2007 184320 | (VzFw) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe SS - | Auto 19/01/2008 21504 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 19/01/2008 21504 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 08/05/2007 386560 | (XAudioService) . (.Conexant Systems, Inc..) - C:\Windows\System32\DRIVERS\xaudio.exe ~ Services: Scanned in 00mn 02s ---\\ Recherche Master Boot Record Infection (MBR)(O80) Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net ~ MBR: 1 Scanned in 00mn 02s ---\\ Recherche Master Boot Record Infection (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by serge at 19/04/2013 17:08:04 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 04s End of the scan (1945 lines in 02mn 44s)(0)