Rapport de ZHPDiag v1.34.76 par Nicolas Coolman, Update du 01/02/2013 Run by stéphanie at 02/02/2013 15:51:01 State : Version à jour. UAC : Deactivate by program ---\\ Web Browser MSIE: Internet Explorer v8.0.7601.17514 (Defaut) ---\\ Windows Product Information ~ Langage: Français Windows 7 Starter Edition, 32-bit Service Pack 1 (Build 7601) Windows Server License Manager Script : OK Software Protection Service (Protection logicielle) : KO Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ System Information ~ Processor: x86 Family 6 Model 28 Stepping 10, GenuineIntel ~ Operating System: 32 Bits Boot mode: Sans échec avec prise en charge du réseau (Fail-safe with network boot) Total RAM: 2037 MB (71% free) System Restore: Activé (Enable) System drive C: has 264 GB (92%) free of 285 GB ---\\ Logged in mode ~ Computer Name: STÉPHANIE-PC ~ User Name: stéphanie ~ All Users Names: stéphanie, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Environnement Variables ~ System Unit : C:\ ~ %AppData% : C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\ ~ %Desktop% : C:\Users\stéphanie.stéphanie-PC\Desktop\ ~ %Favorites% : C:\Users\stéphanie.stéphanie-PC\Favorites\ ~ %LocalAppData% : C:\Users\stéphanie.stéphanie-PC\AppData\Local\ ~ %StartMenu% : C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ DOS/Devices C:\ Hard drive, Flash drive, Thumb drive (Free 264 Go of 285 Go) ---\\ Security Center & Tools Informations [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Scan Security Center in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320] [MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256] [MD5.44214C94911C7CFB1D52CB64D5E8368D] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.20/11/2010 - 22:29:12.) -- C:\Windows\System32\wininet.dll [980992] [MD5.6D13E1406F50C66E2A95D97F22C47560] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.20/11/2010 - 22:29:06.) -- C:\Windows\System32\Winlogon.exe [286720] [MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 22:29:24.) -- C:\Windows\System32\sppcomapi.dll [193536] [MD5.9EBBBA55060F786F0FCAA3893BFA2806] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.25/04/2011 - 03:18:03.) -- C:\Windows\system32\Drivers\AFD.sys [338944] [MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584] [MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656] [MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544] [MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 22:29:07.) -- C:\Windows\system32\Drivers\DfsC.sys [78336] [MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544] [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896] [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888] [MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904] [MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 22:29:08.) -- C:\Windows\system32\Drivers\netBT.sys [187904] [MD5.81189C3D7763838E55C397759D49007A] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.11/03/2011 - 06:39:00.) -- C:\Windows\system32\Drivers\ntfs.sys [1211264] [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360] [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848] [MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168] [MD5.B459575348C20E8121D6039DA063C704] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 22:29:07.) -- C:\Windows\system32\Drivers\tdx.sys [74752] [MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\volsnap.sys [245632] ~ Scan Generic Processes in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes Videos (My Videos) : 1/2 ~ Mes Favoris (My Favorites) : 1/50 ~ Mes Documents (My Documents) : 1/4 ~ Mon Bureau (My Desktop) : 1/6 ~ Menu demarrer (Programs) : 1/44 ~ Scan Hidden Files in 00mn 00s ---\\ Processus lancés [MD5.C613E69C3B191BB02C7A191741A1D024] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [673040] [PID.2036] [MD5.72CB29B523061FF64B3F66B8F3A5E034] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [5648896] [PID.1844] ~ Scan Processes Running in 00mn 00s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.50401.0.) -- c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3508.1109] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.107\npGoogleUpdate3.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.107\npGoogleUpdate3.dll P2 - FPN: [HKLM] [@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (...) -- C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ~ Scan Firefox Browser in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (8.00.7600.16385 (win7_rtm.090713-1255)) -- C:\Windows\System32\ieframe.dll R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 ~ Scan IE Browser in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Scan Proxy management in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Scan Keys in 00mn 00s ---\\ Redirection du fichier Hosts (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Scan Hosts File in 00mn 00s ~ Nombre de lignes (Lines number): 21 ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} . (.Symantec Corporation - coIEPlugIn.) -- C:\Program Files\Norton Internet Security\Engine\19.9.0.9\coIEPlg.dll O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} . (.Symantec Corporation - IPS Browser Helper DLL.) -- C:\Program Files\Norton Internet Security\Engine\19.9.0.9\IPS\IPSBHO.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} . (...) -- "C:\Program Files\Microsoft\BingBar\BingExt.dll" (.not file.) ~ Scan BHO in 00mn 00s ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: Norton Toolbar - [HKLM]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} . (.Symantec Corporation - coIEPlugIn.) -- C:\Program Files\Norton Internet Security\Engine\19.9.0.9\coIEPlg.dll O3 - Toolbar: Bing Bar - [HKLM]{8dcb7100-df86-4384-8842-8fa844297b3f} . (.Microsoft Corporation. - Extensions du client Bing.) -- C:\Program Files\Microsoft\BingBar\BingExt.dll O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll ~ Scan Toolbar in 00mn 00s ---\\ Applications démarrées par registre & par dossier (O4) O4 - HKLM\..\Run: [Norton Online Backup] . (.Symantec Corporation - Norton Online Backup Service.) -- C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe O4 - HKLM\..\Run: [OOTag] . (.Microsoft - OOTag.) -- C:\Program Files\eMachines\OOBEOffer\OOTag.exe O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe O4 - HKLM\..\Run: [LManager] . (.Dritek System Inc. - Launch Manager.) -- C:\Program Files\Launch Manager\LManager.exe O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [AutosetFrequency] . (.Pas de propriétaire - AutosetFrequency.) -- C:\Windows\AutosetFrequency.exe O4 - HKLM\..\Run: [Power Management] . (.Acer Incorporated - ePowerTray.) -- C:\Program Files\eMachines\eMachines Power Management\ePowerTray.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe ~ Scan Application in 00mn 00s ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5) O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no ~ Scan IE Control Panel in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBro ~ Scan IE Extra Buttons in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll ~ Scan Winsock in 00mn 00s ---\\ Objets ActiveX (Downloaded Program Files)(O16) O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://oas.support.microsoft.com/ActiveX/MSDcode.cab ~ Scan Objets ActiveX in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{153ADEBD-6FC8-418F-B07C-AEAB67346F63}: DhcpNameServer = 109.88.203.3 62.197.111.140 O17 - HKLM\System\CCS\Services\Tcpip\..\{28DC8B5E-4A5A-42B8-AABA-1263BA50DD4B}: DhcpNameServer = 192.168.1.250 O17 - HKLM\System\CCS\Services\Tcpip\..\{28DC8B5E-4A5A-42B8-AABA-1263BA50DD4B}: DhcpDomain = PXE.ACER.COM O17 - HKLM\System\CS1\Services\Tcpip\..\{153ADEBD-6FC8-418F-B07C-AEAB67346F63}: DhcpNameServer = 109.88.203.3 62.197.111.140 O17 - HKLM\System\CS1\Services\Tcpip\..\{28DC8B5E-4A5A-42B8-AABA-1263BA50DD4B}: DhcpNameServer = 192.168.1.250 O17 - HKLM\System\CS1\Services\Tcpip\..\{28DC8B5E-4A5A-42B8-AABA-1263BA50DD4B}: DhcpDomain = PXE.ACER.COM O17 - HKLM\System\CS2\Services\Tcpip\..\{153ADEBD-6FC8-418F-B07C-AEAB67346F63}: DhcpNameServer = 109.88.203.3 62.197.111.140 O17 - HKLM\System\CS2\Services\Tcpip\..\{28DC8B5E-4A5A-42B8-AABA-1263BA50DD4B}: DhcpNameServer = 192.168.1.250 O17 - HKLM\System\CS2\Services\Tcpip\..\{28DC8B5E-4A5A-42B8-AABA-1263BA50DD4B}: DhcpDomain = PXE.ACER.COM ~ Scan Domain in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\system32\inetcomm.dll O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files\Windows Live\Mail\mailcomm.dll O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll ~ Scan Protocole Additionnel in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll ~ Scan Winlogon in 00mn 00s ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. ~ Scan SSODL in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: Dritek WMI Service (DsiWMIService) . (.Dritek System Inc. - Dritek WMI Service.) - C:\Program Files\Launch Manager\dsiwmis.exe O23 - Service: Acer ePower Service (ePowerSvc) . (.Acer Incorporated - ePowerSvc.) - C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe O23 - Service: GREGService (GREGService) . (.Acer Incorporated - Global Registration Service.) - C:\Program Files\eMachines\Registration\GREGsvc.exe O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Live Updater Service (Live Updater Service) . (.Acer Incorporated - Updater Service.) - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe O23 - Service: Norton Internet Security (NIS) . (.Symantec Corporation - Symantec Service Framework.) - C:\Program Files\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe O23 - Service: Norton Online Backup (NOBU) . (.Symantec Corporation - Norton Online Backup Service.) - C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe O23 - Service: Software Updater (SrvUpdater) . (.Pas de propriétaire - Updater.) - C:\Program Files\SoftwareUpdater\UpdaterService.exe ~ Scan Services in 00mn 06s ---\\ Enumération Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Scan Desktop Component in 00mn 00s ---\\ BootExecute (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found ~ Scan Keys in 00mn 00s ---\\ Tâches planifiées en automatique (O39) O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job ~ Scan Scheduled Task in 00mn 00s ---\\ Composants installés (ActiveSetup Installed Components) (O40) O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitaire d’initialisation d’Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: Browser Customizations - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - Personnalisation d’IEAK.) -- C:\Windows\System32\iedkcs32.dll O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Internet Explorer - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\system32\cmd.exe O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d’initialisation d’Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll ~ Scan Active Setup in 00mn 00s ---\\ Pilotes lancés au démarrage (O41) O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (BHDrvx86) . (.Symantec Corporation - BASH Driver.) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20130116.013\BHDrvx86.sys O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\system32\drivers\blbdrive.sys O41 - Driver: (ccSet_NIS) . (.Symantec Corporation - Common Client Settings Driver.) - C:\Windows\system32\drivers\NIS\1309000.009\ccSetx86.sys O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys O41 - Driver: (eeCtrl) . (.Symantec Corporation - Symantec Eraser Control Driver.) - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys O41 - Driver: (IDSVix86) . (.Symantec Corporation - IDS Core Driver.) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20130201.001\IDSvix86.sys O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys O41 - Driver: (SRTSPX) . (.Symantec Corporation - Symantec AutoProtect.) - C:\Windows\system32\drivers\NIS\1309000.009\SRTSPX.sys O41 - Driver: (SymIRON) . (.Symantec Corporation - Iron Driver.) - C:\Windows\system32\drivers\NIS\1309000.009\Ironx86.sys O41 - Driver: (SymNetS) . (.Symantec Corporation - Network Security Driver.) - C:\Windows\system32\Drivers\NIS\1309000.009\SYMNETS.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys ~ Scan Drivers in 00mn 00s ---\\ Logiciels installés (O42) O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Reader X MUI - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-FFFF-7B44-AA0000000001} O42 - Logiciel: Agatha Christie - Death on the Nile - (.WildTangent.) [HKLM] -- WTA-925c7736-1e17-452e-8e6a-68b08c2ab05e O42 - Logiciel: Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver - (.Atheros Communications Inc..) [HKLM] -- {3108C217-BE83-42E4-AE9E-A56A2A92E549} O42 - Logiciel: Bejeweled 2 Deluxe - (.WildTangent.) [HKLM] -- WTA-d9ec04e5-2fff-48ee-be48-f82bfc5d176a O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM] -- {C28D96C0-6A90-459E-A077-A6706F4EC0FC} O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner O42 - Logiciel: Chuzzle Deluxe - (.WildTangent.) [HKLM] -- WTA-03d733e7-32c2-445b-8696-686ca0bb41c0 O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF} O42 - Logiciel: ENE USB Card Reader Driver - (.ENE.) [HKLM] -- 3B29FD3CCF1F5B855DA0C521597413EBABE97DFB O42 - Logiciel: FATE - (.WildTangent.) [HKLM] -- WTA-8d06cc61-a80a-4fce-b85e-aa6651382d99 O42 - Logiciel: Final Drive: Nitro - (.WildTangent.) [HKLM] -- WTA-235b2e77-c9e3-4a19-b9b6-e3474efdbcd9 O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F} O42 - Logiciel: Identity Card - (.Acer Incorporated.) [HKLM] -- Identity Card O42 - Logiciel: Insaniquarium Deluxe - (.WildTangent.) [HKLM] -- WTA-d2c8058e-73f4-48bf-85ff-1ca3c377ce65 O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- HDMI O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM] -- {3E29EE6C-963A-4aae-86C1-DC237C4A49FC} O42 - Logiciel: Jewel Match 3 - (.WildTangent.) [HKLM] -- WTA-52df1be1-22dc-4b38-bb2b-25bdd13259bf O42 - Logiciel: Jewel Quest Solitaire - (.WildTangent.) [HKLM] -- WTA-b55b5f87-9df8-4bc9-8f48-8ed78f3c5933 O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4} O42 - Logiciel: Launch Manager - (.eMachines.) [HKLM] -- LManager O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F} O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E} O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} O42 - Logiciel: Norton Internet Security - (.Symantec Corporation.) [HKLM] -- NIS O42 - Logiciel: Norton Online Backup - (.Symantec Corporation.) [HKLM] -- {40A66DF6-22D3-44B5-A7D3-83B118A2C0DC} O42 - Logiciel: Penguins! - (.WildTangent.) [HKLM] -- WTA-c35f3a5e-614a-4784-914a-6f4846204ea1 O42 - Logiciel: Plants vs. Zombies - Game of the Year - (.WildTangent.) [HKLM] -- WTA-9adef830-0d82-4638-9eeb-96b6d9bb6782 O42 - Logiciel: Polar Bowler - (.WildTangent.) [HKLM] -- WTA-92bfff70-1faf-42dc-9520-153b584510d3 O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} O42 - Logiciel: Skip-Bo - Castaway Caper - (.WildTangent.) [HKLM] -- WTA-6b9a8033-86ca-427f-80cc-e4207f85038d O42 - Logiciel: Skype™ 5.3 - (.Skype Technologies S.A..) [HKLM] -- {5335DADB-34BA-4AE8-A519-648D78498846} O42 - Logiciel: Slingo Deluxe - (.WildTangent.) [HKLM] -- WTA-50d17a46-c6df-4d1f-b2ac-921178c25f7a O42 - Logiciel: SoftwareUpdater - (.Pas de propriétaire.) [HKLM] -- SoftwareUpdater O42 - Logiciel: Sweetpacks Bundle Uninstaller - (.SweetPacks LTD.) [HKLM] -- Sweetpacks Bundle Uninstaller O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey O42 - Logiciel: Torchlight - (.WildTangent.) [HKLM] -- WTA-192b1ee3-4ef3-4ff2-8998-ee9412954832 O42 - Logiciel: Tradewinds Legends - (.WildTangent.) [HKLM] -- WTA-e6b52a4b-6bb6-45be-943b-ffe535563780 O42 - Logiciel: Update Installer for WildTangent Games App - (.WildTangent.) [HKLM] -- {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App O42 - Logiciel: Video Web Camera Ver:1.0.55.221 - (.Chicony Electronics Co.,Ltd..) [HKLM] -- {17C50809-F2E0-4DD8-84D7-55FF74615723} O42 - Logiciel: Virtual Villagers 4 - The Tree of Life - (.WildTangent.) [HKLM] -- WTA-15b567d0-1ca4-4762-a6d0-59b88c6eca33 O42 - Logiciel: Wedding Dash - (.WildTangent.) [HKLM] -- WTA-bfebe051-ced1-48b8-9dce-484109bab0cb O42 - Logiciel: Welcome Center - (.Acer Incorporated.) [HKLM] -- eMachines Welcome Center O42 - Logiciel: WildTangent Games App (eMachines Games) - (.WildTangent.) [HKLM] -- {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-emachines O42 - Logiciel: Zuma Deluxe - (.WildTangent.) [HKLM] -- WTA-d6f56b12-6f3e-43b3-9c3a-7c3394d27813 O42 - Logiciel: eMachines Games - (.WildTangent.) [HKLM] -- WildTangent emachines Master Uninstall O42 - Logiciel: eMachines Power Management - (.Acer Incorporated.) [HKLM] -- {3DB0448D-AD82-4923-B305-D001E521A964} O42 - Logiciel: eMachines Recovery Management - (.Acer Incorporated.) [HKLM] -- {7F811A54-5A09-4579-90E1-C93498E230D9} O42 - Logiciel: eMachines Registration - (.Acer Incorporated.) [HKLM] -- eMachines Registration O42 - Logiciel: eMachines ScreenSaver - (.Acer Incorporated.) [HKLM] -- eMachines Screensaver O42 - Logiciel: eMachines Updater - (.Acer Incorporated.) [HKLM] -- {EE171732-BEB4-4576-887D-CB62727F01CA} ---\\ HKCU & HKLM Software Keys [HKCU\Software\Acer] [HKCU\Software\AppDataLow\Software\Microsoft] [HKCU\Software\AppDataLow\Software] [HKCU\Software\AppDataLow] [HKCU\Software\Classes] [HKCU\Software\Dritek] [HKCU\Software\Google] [HKCU\Software\Intel] [HKCU\Software\Licenses] [HKCU\Software\Local AppWizard-Generated Applications] [HKCU\Software\Macromedia] [HKCU\Software\OEM] [HKCU\Software\Piriform] [HKCU\Software\Policies] [HKCU\Software\Realtek] [HKCU\Software\Softonic] [HKCU\Software\SweetIM] [HKCU\Software\Symantec] [HKCU\Software\Synaptics] [HKCU\Software\ZebHelpProcess Helper] [HKLM\Software\ATI Technologies] [HKLM\Software\Acer Incorporated] [HKLM\Software\Acer] [HKLM\Software\Adobe] [HKLM\Software\Atheros Communications Inc.] [HKLM\Software\CBSTEST] [HKLM\Software\Chicony Electronics Co.,Ltd.] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\Cyberlink] [HKLM\Software\DTS] [HKLM\Software\Dolby] [HKLM\Software\Dritek] [HKLM\Software\Google] [HKLM\Software\InstalledOptions] [HKLM\Software\Intel] [HKLM\Software\Macromedia] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\Norton] [HKLM\Software\ODBC] [HKLM\Software\OEM] [HKLM\Software\Piriform] [HKLM\Software\Policies] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\SRS Labs] [HKLM\Software\Skype] [HKLM\Software\SonicFocus] [HKLM\Software\Symantec] [HKLM\Software\Synaptics] [HKLM\Software\Systweak] [HKLM\Software\Vittalia] [HKLM\Software\WOW6432Node] [HKLM\Software\Waves Audio] [HKLM\Software\WildTangent] ~ Scan Softwares in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 19/07/2011 - 16:41:36 - [448,464] ----D C:\Program Files\Adobe O43 - CFD: 02/02/2013 - 14:49:01 - [4,750] ----D C:\Program Files\CCleaner O43 - CFD: 19/07/2011 - 16:44:17 - [90,469] ----D C:\Program Files\Common Files O43 - CFD: 19/07/2011 - 16:11:36 - [0,759] ----D C:\Program Files\DIFX O43 - CFD: 30/01/2013 - 01:39:30 - [3,997] ----D C:\Program Files\DVD Maker O43 - CFD: 30/01/2013 - 18:25:47 - [87,250] ----D C:\Program Files\eMachines O43 - CFD: 19/07/2011 - 16:17:51 - [429,271] ----D C:\Program Files\eMachines Games O43 - CFD: 29/01/2013 - 17:48:17 - [0] R---D C:\Program Files\Fichiers communs O43 - CFD: 02/02/2013 - 14:48:58 - [14,979] ----D C:\Program Files\Google O43 - CFD: 30/01/2013 - 10:49:37 - [28,485] --H-D C:\Program Files\InstallShield Installation Information O43 - CFD: 19/07/2011 - 16:03:03 - [3,587] ----D C:\Program Files\Intel O43 - CFD: 30/01/2013 - 20:11:34 - [4,403] ----D C:\Program Files\Internet Explorer O43 - CFD: 29/01/2013 - 17:22:31 - [7,058] ----D C:\Program Files\Launch Manager O43 - CFD: 30/01/2013 - 10:16:21 - [19,951] ----D C:\Program Files\Microsoft O43 - CFD: 14/07/2009 - 05:52:30 - [44,521] ----D C:\Program Files\Microsoft Games O43 - CFD: 30/01/2013 - 10:47:01 - [6,126] ----D C:\Program Files\Microsoft Office O43 - CFD: 30/01/2013 - 16:26:36 - [0,157] ----D C:\Program Files\Microsoft Security Client O43 - CFD: 19/07/2011 - 16:18:25 - [36,499] ----D C:\Program Files\Microsoft Silverlight O43 - CFD: 19/07/2011 - 16:31:14 - [1,745] ----D C:\Program Files\Microsoft SQL Server Compact Edition O43 - CFD: 14/07/2009 - 05:52:30 - [0,025] ----D C:\Program Files\MSBuild O43 - CFD: 19/07/2011 - 16:43:29 - [219,496] ----D C:\Program Files\Norton Internet Security O43 - CFD: 19/07/2011 - 16:43:16 - [42,648] ----D C:\Program Files\NortonInstaller O43 - CFD: 29/01/2013 - 16:48:34 - [24,361] ----D C:\Program Files\Realtek O43 - CFD: 14/07/2009 - 05:52:30 - [37,345] ----D C:\Program Files\Reference Assemblies O43 - CFD: 19/07/2011 - 16:18:13 - [14,446] R---D C:\Program Files\Skype O43 - CFD: 02/02/2013 - 14:47:48 - [0,456] ----D C:\Program Files\SoftwareUpdater O43 - CFD: 02/02/2013 - 14:47:37 - [0,358] ----D C:\Program Files\sweetpacks bundle uninstaller O43 - CFD: 30/01/2013 - 12:08:44 - [4,981] ----D C:\Program Files\Symantec O43 - CFD: 19/07/2011 - 16:44:22 - [0,727] ----D C:\Program Files\SymSilent O43 - CFD: 29/01/2013 - 17:29:38 - [28,545] ----D C:\Program Files\Synaptics O43 - CFD: 29/01/2013 - 16:48:43 - [0] --H-D C:\Program Files\Temp O43 - CFD: 14/07/2009 - 05:53:23 - [0] --H-D C:\Program Files\Uninstall Information O43 - CFD: 29/01/2013 - 17:30:35 - [1,343] ----D C:\Program Files\Video Web Camera O43 - CFD: 19/07/2011 - 16:13:40 - [9,211] ----D C:\Program Files\WildTangent Games O43 - CFD: 30/01/2013 - 01:39:30 - [2,909] ----D C:\Program Files\Windows Defender O43 - CFD: 19/07/2011 - 16:22:43 - [461,915] ----D C:\Program Files\Windows Live O43 - CFD: 30/01/2013 - 01:39:31 - [5,895] ----D C:\Program Files\Windows Mail O43 - CFD: 30/01/2013 - 01:39:30 - [6,298] ----D C:\Program Files\Windows Media Player O43 - CFD: 29/01/2013 - 17:48:17 - [11,632] ----D C:\Program Files\Windows NT O43 - CFD: 30/01/2013 - 01:39:30 - [4,213] ----D C:\Program Files\Windows Photo Viewer O43 - CFD: 20/11/2010 - 22:33:48 - [0,181] ----D C:\Program Files\Windows Portable Devices O43 - CFD: 30/01/2013 - 01:39:31 - [6,314] ----D C:\Program Files\Windows Sidebar O43 - CFD: 02/02/2013 - 15:51:03 - [11,883] ----D C:\Program Files\ZHPDiag O43 - CFD: 19/07/2011 - 16:42:09 - [17,968] ----D C:\Program Files\Common Files\Adobe O43 - CFD: 19/07/2011 - 16:05:41 - [1,943] ----D C:\Program Files\Common Files\InstallShield O43 - CFD: 19/07/2011 - 16:21:22 - [20,704] ----D C:\Program Files\Common Files\microsoft shared O43 - CFD: 14/07/2009 - 03:37:05 - [0,003] ----D C:\Program Files\Common Files\Services O43 - CFD: 14/07/2009 - 03:37:05 - [39,200] ----D C:\Program Files\Common Files\SpeechEngines O43 - CFD: 30/01/2013 - 10:45:24 - [0,880] ----D C:\Program Files\Common Files\Symantec Shared O43 - CFD: 30/01/2013 - 01:39:30 - [9,771] ----D C:\Program Files\Common Files\System O43 - CFD: 19/07/2011 - 16:20:48 - [0] ----D C:\Program Files\Common Files\Windows Live O43 - CFD: 19/07/2011 - 16:41:55 - [0,000] ----D C:\ProgramData\Adobe O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Application Data O43 - CFD: 02/02/2013 - 13:37:00 - [0] ----D C:\ProgramData\boost_interprocess O43 - CFD: 29/01/2013 - 17:48:17 - [0] --H-D C:\ProgramData\Bureau O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Desktop O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Documents O43 - CFD: 19/07/2011 - 16:19:58 - [0,050] ----D C:\ProgramData\eMachines O43 - CFD: 29/01/2013 - 17:48:17 - [0] --H-D C:\ProgramData\Favoris O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Favorites O43 - CFD: 02/02/2013 - 14:48:59 - [0,012] ----D C:\ProgramData\Google O43 - CFD: 29/01/2013 - 17:48:17 - [0] --H-D C:\ProgramData\Menu Démarrer O43 - CFD: 02/02/2013 - 14:13:40 - [1352,906] -S--D C:\ProgramData\Microsoft O43 - CFD: 29/01/2013 - 17:48:17 - [0] --H-D C:\ProgramData\Modèles O43 - CFD: 29/01/2013 - 18:57:21 - [268,393] ----D C:\ProgramData\Norton O43 - CFD: 19/07/2011 - 16:43:16 - [113,453] ----D C:\ProgramData\NortonInstaller O43 - CFD: 30/01/2013 - 10:49:45 - [0,000] ----D C:\ProgramData\oem O43 - CFD: 19/07/2011 - 16:18:12 - [19,371] ----D C:\ProgramData\Skype O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Start Menu O43 - CFD: 19/07/2011 - 16:41:17 - [0,023] ----D C:\ProgramData\Symantec O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Templates O43 - CFD: 19/07/2011 - 16:17:51 - [897,083] ----D C:\ProgramData\WildTangent O43 - CFD: 30/01/2013 - 13:32:56 - [0] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Adobe O43 - CFD: 30/01/2013 - 10:15:06 - [0] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Identities O43 - CFD: 30/01/2013 - 13:33:00 - [0,001] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Macromedia O43 - CFD: 30/01/2013 - 16:12:21 - [1,342] -S--D C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Microsoft O43 - CFD: 02/02/2013 - 14:52:02 - [0] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Systweak O43 - CFD: 29/01/2013 - 19:54:46 - [0] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Local\Application Data O43 - CFD: 02/02/2013 - 14:49:58 - [0] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Local\CrashDumps O43 - CFD: 02/02/2013 - 15:04:09 - [0,239] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Local\ElevatedDiagnostics O43 - CFD: 02/02/2013 - 14:48:56 - [0] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Local\Google O43 - CFD: 29/01/2013 - 19:54:46 - [0] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Local\Historique O43 - CFD: 30/01/2013 - 16:15:11 - [42,860] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Local\Microsoft O43 - CFD: 02/02/2013 - 15:45:10 - [78,416] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp O43 - CFD: 29/01/2013 - 19:54:46 - [0] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temporary Internet Files O43 - CFD: 29/01/2013 - 19:58:08 - [0] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Local\VirtualStore O43 - CFD: 30/01/2013 - 12:50:18 - [0] ----D C:\Users\stéphanie.stéphanie-PC\AppData\Local\{CEF42EA3-0557-47E3-97AD-9057132D3B5F} O43 - CFD: 14/07/2009 - 05:42:04 - [0,014] R---D C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 30/01/2013 - 10:15:19 - [0,000] R---D C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 14/07/2009 - 05:37:42 - [0,001] R---D C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 30/01/2013 - 10:15:19 - [0,000] R---D C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup ~ Scan Program Folder in 00mn 02s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.17BCC903A6ED037F7812B17B6351393A] - 02/02/2013 - 15:06:44 ---A- . (...) -- C:\Windows\ntbtlog.txt [171874] O44 - LFC:[MD5.657BDAAFC7E2311C419F2DA483F07F8F] - 02/02/2013 - 15:06:38 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.AC849B99E032F4017BB1CE37934DD4AF] - 02/02/2013 - 15:05:18 ---A- . (...) -- C:\Windows\setupact.log [112] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 02/02/2013 - 14:53:47 ---A- . (...) -- C:\Windows\setuperr.log [0] O44 - LFC:[MD5.D218281712B82D3A413AC86D5A6F52D6] - 02/02/2013 - 14:53:32 ---A- . (...) -- C:\Windows\PFRO.log [362] O44 - LFC:[MD5.A2E885F1F607921A1C87FB169200CCD4] - 02/02/2013 - 14:27:35 ---A- . (...) -- C:\Windows\System32\ASOROSet.bin [1728] O44 - LFC:[MD5.18B3AFB51D16BD28F6B2C0C920CF1A18] - 02/02/2013 - 14:18:41 ---A- . (.Systweak Inc., (www.systweak.com) - Regclean Pro.) -- C:\Windows\System32\roboot.exe [18360] O44 - LFC:[MD5.6141626E90EB1E7F5B4D0DD17E197AD9] - 02/02/2013 - 13:36:50 ---A- . (...) -- C:\Windows\AutoSetFrequency.ini [743] O44 - LFC:[MD5.7197ED407442592EA2D388BE94A8254D] - 30/01/2013 - 21:37:29 --HA- . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [16160] O44 - LFC:[MD5.7197ED407442592EA2D388BE94A8254D] - 30/01/2013 - 21:37:29 --HA- . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [16160] O44 - LFC:[MD5.3AFB7BAD0967EACE8D3ED16CF2A8FD8A] - 30/01/2013 - 12:31:21 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1524562] O44 - LFC:[MD5.EED51D56C1041D48C08D31CFC0876496] - 30/01/2013 - 12:31:21 ---A- . (...) -- C:\Windows\System32\perfc009.dat [103568] O44 - LFC:[MD5.FF7FA933B2ABBB07373BDCD201A1ABA9] - 30/01/2013 - 12:31:21 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [127684] O44 - LFC:[MD5.EE946017F68304658A20B6732CE5F8B8] - 30/01/2013 - 12:31:21 ---A- . (...) -- C:\Windows\System32\perfh009.dat [607190] O44 - LFC:[MD5.E4468BFBF99A521D733AA7B7BB2359F4] - 30/01/2013 - 12:31:21 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [695004] O44 - LFC:[MD5.B8C266D6FEC5FDDA70443D8B4F8FBCAF] - 30/01/2013 - 12:08:43 ---A- . (...) -- C:\Windows\System32\Drivers\SYMEVENT.CAT [7468] O44 - LFC:[MD5.5F32C104CAB48375171244BCB2A8D7F8] - 30/01/2013 - 12:08:43 ---A- . (...) -- C:\Windows\System32\Drivers\SYMEVENT.INF [806] O44 - LFC:[MD5.74E2521E96176A4449570E50BE91954D] - 30/01/2013 - 12:08:43 ---A- . (.Symantec Corporation - Symantec Event Library.) -- C:\Windows\System32\Drivers\SYMEVENT.SYS [141944] O44 - LFC:[MD5.D84C95CC0E9A06521259FA76DEFB85CA] - 30/01/2013 - 10:10:19 ---A- . (...) -- C:\Windows\System32\GDIPFONTCACHEV1.DAT [57560] O44 - LFC:[MD5.07BA000B2E67565BDF112C35171865A5] - 30/01/2013 - 01:39:09 ---A- . (...) -- C:\Windows\System32\perfd00C.dat [38160] O44 - LFC:[MD5.04F6C9757DB75FF27C427E5B31DDB289] - 30/01/2013 - 01:39:09 ---A- . (...) -- C:\Windows\System32\perfi00C.dat [344522] O44 - LFC:[MD5.6FBB766EB79F9EED3684194EEAF838DF] - 30/01/2013 - 01:31:04 ---A- . (...) -- C:\Windows\ChangeLang_Done.tag [11453] O44 - LFC:[MD5.46C61F995D7A38A7E26D339233914214] - 29/01/2013 - 17:45:16 ---A- . (...) -- C:\Windows\System32\license.rtf [190563] O44 - LFC:[MD5.D8EDD9F9DD740235FF779AE2850CD749] - 29/01/2013 - 17:33:37 ---A- . (...) -- C:\Windows\devices.txt [13925] O44 - LFC:[MD5.9E4F1363B3F083027FB013F93AE022F6] - 29/01/2013 - 17:30:27 ---A- . (.Pas de propriétaire - AutosetFrequency.) -- C:\Windows\AutosetFrequency.exe [51712] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 29/01/2013 - 17:29:47 --HA- . (...) -- C:\Windows\System32\Drivers\Msft_Kernel_SynTP_01009.Wdf [0] O44 - LFC:[MD5.EF3024328398C07DE0BDF35B67ABEC68] - 29/01/2013 - 17:22:31 ---A- . (...) -- C:\Windows\LMv4.UNI [172] O44 - LFC:[MD5.729C9C2DEC166E44842D0CEA78F7FC49] - 29/01/2013 - 17:21:07 ---A- . (...) -- C:\Windows\System32\results.xml [15122] O44 - LFC:[MD5.757349DFD98BFECA9FE4D287E64A5594] - 29/01/2013 - 17:12:11 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [257848] O44 - LFC:[MD5.63D2B014282D833076FF39F8BCB2CDCB] - 29/01/2013 - 17:09:10 ---A- . (.Intel Corporation - Intel® Graphics Media Accelerator Driver in.) -- C:\Windows\System32\igxpun.exe [1006104] O44 - LFC:[MD5.F38B53088F3200BC9B8037DBA400F0AA] - 16/12/2009 - 15:13:36 ---A- . (...) -- C:\Windows\FixUVC.exe [113264] ~ Scan Files in 00mn 04s ---\\ Derniers fichiers créés dans Windows Prefetcher (O45) O45 - LFCP:[MD5.FCC99232E3E7BA902013BE75B479647F] - 02/02/2013 - 12:04:27 ---A- - C:\Windows\Prefetch\AgAppLaunch.db O45 - LFCP:[MD5.0D7DD2F613D0789ECC0D3CE48E4D1CF3] - 02/02/2013 - 12:53:56 ---A- - C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-1442334213-2374068315-3074064575-1000.db O45 - LFCP:[MD5.045972645C8D6AC656C60614D0DDF133] - 02/02/2013 - 12:53:56 ---A- - C:\Windows\Prefetch\AgGlUAD_S-1-5-21-1442334213-2374068315-3074064575-1000.db O45 - LFCP:[MD5.765A4DCB6FB06A8362EF8E32E48AA57D] - 02/02/2013 - 12:55:08 ---A- - C:\Windows\Prefetch\AgGlFaultHistory.db O45 - LFCP:[MD5.E0EF382C9D5777E4EBBE935AE521C8CA] - 02/02/2013 - 12:55:08 ---A- - C:\Windows\Prefetch\AgGlFgAppHistory.db O45 - LFCP:[MD5.935A070BD93FF18EC949F1A462AC2015] - 02/02/2013 - 12:55:08 ---A- - C:\Windows\Prefetch\AgGlGlobalHistory.db O45 - LFCP:[MD5.9C34C048B3A520F40A589CB65B70560A] - 02/02/2013 - 12:55:08 ---A- - C:\Windows\Prefetch\AgRobust.db O45 - LFCP:[MD5.3BD5B7984EB60D7B607441F20EA421E1] - 02/02/2013 - 12:55:08 ---A- - C:\Windows\Prefetch\PfSvPerfStats.bin O45 - LFCP:[MD5.02B768DC5B81EF557B1B86F8203B783B] - 02/02/2013 - 13:05:01 ---A- - C:\Windows\Prefetch\NTOSBOOT-B00DFAAD.pf O45 - LFCP:[MD5.CB71C2016ABC4D01A0B8B7C38434BA20] - 02/02/2013 - 13:05:11 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-27D91624.pf O45 - LFCP:[MD5.E31EBFEF9595F0372767E4EB668CBA4E] - 02/02/2013 - 13:05:12 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-A0F5E092.pf O45 - LFCP:[MD5.499DD0E64E11C0858214C1395CFA8B9D] - 02/02/2013 - 13:15:02 ---A- - C:\Windows\Prefetch\CLTLMH.EXE-D052B5C8.pf O45 - LFCP:[MD5.1AAA87C8D8A38512058CF1F716BFC283] - 02/02/2013 - 13:15:20 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-6389524F.pf O45 - LFCP:[MD5.B39FB55AE2F4EB26693005A26CBFEF2D] - 02/02/2013 - 13:15:20 ---A- - C:\Windows\Prefetch\WMIADAP.EXE-BB21CD77.pf O45 - LFCP:[MD5.37976BB52150A7F8CB7182E2D36E11AC] - 02/02/2013 - 13:32:13 ---A- - C:\Windows\Prefetch\SEARCHINDEXER.EXE-1CF42BC6.pf O45 - LFCP:[MD5.0899772165A0FFFD01364962CA90428B] - 02/02/2013 - 13:32:13 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-B6CF74F4.pf O45 - LFCP:[MD5.FCFB3E47693FE35782B150C45FDA57D6] - 02/02/2013 - 13:32:14 ---A- - C:\Windows\Prefetch\COFIRE.EXE-C2A69CED.pf O45 - LFCP:[MD5.869D93B8393EE774C616B56ADE440261] - 02/02/2013 - 13:32:16 ---A- - C:\Windows\Prefetch\CCSVCHST.EXE-2F293289.pf O45 - LFCP:[MD5.1930C31233F7C2103CA585EE402B1D26] - 02/02/2013 - 13:32:17 ---A- - C:\Windows\Prefetch\USERINIT.EXE-5114915C.pf O45 - LFCP:[MD5.45CCB4FC799ABDDB555A6B0A3BC132A2] - 02/02/2013 - 13:32:20 ---A- - C:\Windows\Prefetch\AgCx_SC1.db.trx O45 - LFCP:[MD5.55D701EECE0B8293FC08C7B302E38A29] - 02/02/2013 - 13:32:32 ---A- - C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-69C456C3.pf O45 - LFCP:[MD5.4CAF3267526EF6881AAFAB4E65DF0F8D] - 02/02/2013 - 13:32:39 ---A- - C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-44162447.pf O45 - LFCP:[MD5.BB822478B2CE1FA1A2C3321CB3BC8C05] - 02/02/2013 - 13:32:39 ---A- - C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-766EFF52.pf O45 - LFCP:[MD5.B4F379520B43AE5AFEF3A936DBB0FAAF] - 02/02/2013 - 13:33:20 ---A- - C:\Windows\Prefetch\AgCx_SC1.db O45 - LFCP:[MD5.E0027DA70898A646F6ED71F1F37620D8] - 02/02/2013 - 13:34:36 ---A- - C:\Windows\Prefetch\NOBUCLIENT.EXE-C25AA4A1.pf O45 - LFCP:[MD5.FFE4122D83083BEF0194535DF83194EF] - 02/02/2013 - 13:34:57 ---A- - C:\Windows\Prefetch\OOTAG.EXE-34708895.pf O45 - LFCP:[MD5.D32C38719B9D46E0DB25C353841714A3] - 02/02/2013 - 13:35:20 ---A- - C:\Windows\Prefetch\IGFXTRAY.EXE-F30110F3.pf O45 - LFCP:[MD5.4992E6FE4E23CABE9E232E6AE17B4B6C] - 02/02/2013 - 13:35:46 ---A- - C:\Windows\Prefetch\HKCMD.EXE-61FD4888.pf O45 - LFCP:[MD5.35D54E6391E932C811C690264E8B867E] - 02/02/2013 - 13:36:11 ---A- - C:\Windows\Prefetch\IGFXSRVC.EXE-C5618119.pf O45 - LFCP:[MD5.83CF7BA97C6E866BDB1CA384D1F1B789] - 02/02/2013 - 13:36:21 ---A- - C:\Windows\Prefetch\IGFXPERS.EXE-540AA77D.pf O45 - LFCP:[MD5.FB624F7463B38621A376E22C3A8C42BC] - 02/02/2013 - 13:36:52 ---A- - C:\Windows\Prefetch\RTHDVCPL.EXE-BDBA07C9.pf O45 - LFCP:[MD5.4F39500C9568826CD0AFE7874731D064] - 02/02/2013 - 13:36:53 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-4B6CB38A.pf O45 - LFCP:[MD5.0A09B750944E677FB06B3C26404E9F8C] - 02/02/2013 - 13:36:57 ---A- - C:\Windows\Prefetch\AUTOSETFREQUENCY.EXE-5D8B13A2.pf O45 - LFCP:[MD5.259929CBDB602D3105D642BC7810F4BC] - 02/02/2013 - 13:36:57 ---A- - C:\Windows\Prefetch\LMANAGER.EXE-5CFD020C.pf O45 - LFCP:[MD5.B051712E35F8D2DD119E71111885F4AF] - 02/02/2013 - 13:36:57 ---A- - C:\Windows\Prefetch\SYNTPENH.EXE-8A564A20.pf O45 - LFCP:[MD5.C4A360F3A9E2CF54615469F9D29F9C9B] - 02/02/2013 - 13:37:05 ---A- - C:\Windows\Prefetch\AUDIODG.EXE-AB22E9A6.pf O45 - LFCP:[MD5.BBB0EF988ED1B63CE7C8F987991E1417] - 02/02/2013 - 13:37:05 ---A- - C:\Windows\Prefetch\EPOWERTRAY.EXE-9A6C7E85.pf O45 - LFCP:[MD5.C162836892449EE3602A7061D69DF4F9] - 02/02/2013 - 13:37:05 ---A- - C:\Windows\Prefetch\SPPSVC.EXE-96070FE0.pf O45 - LFCP:[MD5.F989F163D0F0D39BEE5499F9289FCAD3] - 02/02/2013 - 13:37:05 ---A- - C:\Windows\Prefetch\WERMGR.EXE-F439C551.pf O45 - LFCP:[MD5.9C54A457DF8C860225DF871C079E2AB1] - 02/02/2013 - 13:37:05 ---A- - C:\Windows\Prefetch\WMIPRVSE.EXE-E8B8DD29.pf O45 - LFCP:[MD5.550DAE05CB04DB18C4E6BCA7577A251A] - 02/02/2013 - 13:39:33 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-F31BDE28.pf O45 - LFCP:[MD5.46993449B332D52CB6EA900CC62ED0A1] - 02/02/2013 - 13:40:17 ---A- - C:\Windows\Prefetch\SETAPM.EXE-B95DC105.pf O45 - LFCP:[MD5.7CFDAC0BAD1DF7A749396DB4F615F835] - 02/02/2013 - 13:40:32 ---A- - C:\Windows\Prefetch\CONHOST.EXE-0C6456FB.pf O45 - LFCP:[MD5.8087A33E4E3FADF46D78767DCEB59172] - 02/02/2013 - 13:40:36 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-6E1A6101.pf O45 - LFCP:[MD5.0C793E7166A16057CBE85B12D31D55C4] - 02/02/2013 - 13:42:38 ---A- - C:\Windows\Prefetch\IEXPLORE.EXE-058FE8F5.pf O45 - LFCP:[MD5.35822ECC7FB977CC75B79A7E0A7FB78C] - 02/02/2013 - 13:42:43 ---A- - C:\Windows\Prefetch\SYMERR.EXE-382F472E.pf O45 - LFCP:[MD5.A730062ED575CEE2F0A68C5BEA7CE2F4] - 02/02/2013 - 13:45:12 ---A- - C:\Windows\Prefetch\WERFAULT.EXE-155C56CF.pf ~ Scan Prefetcher in 00mn 00s ---\\ Déni du service (Local Security Authority) (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll ~ Scan Keys in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ Scan CSB in 00mn 00s ---\\ MountPoints2 Shell Key (O51) (None) ---\\ Trojan Driver Search Data (HKLM) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm ~ Scan Keys in 00mn 00s ---\\ ShareTools MSconfig StartupReg (O53) (None) ---\\ Microsoft Control Security Providers (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll ~ Scan Keys in 00mn 00s ---\\ Microsoft Windows Policies System (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ Scan Keys in 00mn 00s ---\\ Liste des Drivers Système (O58) O58 - SDL:[MD5.21E785EBD7DC90A06391141AAC7892FB] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976] O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029] ~ Scan Drivers in 00mn 00s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC:Last File Created 01/02/2013 - 19:25:36 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\~DF560F53E8F32F77F7.TMP [0] O61 - LFC:Last File Created 01/02/2013 - 19:25:36 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\~DF8A524B70CC6161B9.TMP [0] O61 - LFC:Last File Created 01/02/2013 - 19:25:37 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\~DF27618593F3E16CAB.TMP [0] O61 - LFC:Last File Created 01/02/2013 - 19:25:37 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\~DFA366D2EE1575BDA8.TMP [0] O61 - LFC:Last File Created 01/02/2013 - 19:26:46 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\instloffer.exe [168728] O61 - LFC:Last File Created 02/02/2013 - 14:03:10 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\d14412c4-2d38-4a20-abf0-11ad01a1b080 [64] O61 - LFC:Last File Created 02/02/2013 - 14:03:35 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\c9bb8f6f-3456-4518-934d-b61fa8b691d4 [66] O61 - LFC:Last File Created 02/02/2013 - 14:05:24 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\890a6401-9fb2-48aa-ad4b-ae9c10bf6bb9 [66] O61 - LFC:Last File Created 02/02/2013 - 14:46:53 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\276.txt [0] O61 - LFC:Last File Created 02/02/2013 - 14:47:31 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\Shortcut_Shortcut_toolbar_vit_sweetim.exe [7216040] O61 - LFC:Last File Created 02/02/2013 - 14:47:31 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\Shortcut_toolbar_vit_sweetim.exe [7216040] O61 - LFC:Last File Created 02/02/2013 - 14:48:07 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\25623-667949-ccleaner.exe [3907920] O61 - LFC:Last File Created 02/02/2013 - 14:50:50 ---A- C:\Users\stéphanie.stéphanie-PC\Documents\cc_20130202_145040.reg [25914] O61 - LFC:Last File Created 02/02/2013 - 15:04:09 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\ElevatedDiagnostics\460911090\2013020214.000\NetworkDiagnostics.0.debugreport.xml [71904] O61 - LFC:Last File Created 02/02/2013 - 15:04:09 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\ElevatedDiagnostics\460911090\2013020214.000\results.xsl [49097] O61 - LFC:Last File Created 02/02/2013 - 15:04:17 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\ElevatedDiagnostics\460911090\2013020214.000\NetworkDiagnostics.1.debugreport.xml [69784] O61 - LFC:Last File Created 02/02/2013 - 15:04:17 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\ElevatedDiagnostics\460911090\2013020214.000\ResultReport.xml [38055] O61 - LFC:Last File Created 02/02/2013 - 15:04:17 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\ElevatedDiagnostics\460911090\2013020214.000\results.xml [256] O61 - LFC:Last File Created 02/02/2013 - 15:04:17 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\ElevatedDiagnostics\460911090\latest.cab [21957] O61 - LFC:Last File Created 02/02/2013 - 15:19:14 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\GenericUninstall.exe [127320] O61 - LFC:Last File Created 02/02/2013 - 15:19:14 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\SIMEEIInstaller.exe [3380216] O61 - LFC:Last File Created 02/02/2013 - 15:19:14 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\SimboApp.exe [1285976] O61 - LFC:Last File Created 02/02/2013 - 15:19:14 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\mgsqlite3.dll [393016] O61 - LFC:Last File Created 02/02/2013 - 15:19:14 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\uninstaller.exe [375128] O61 - LFC:Last File Created 30/01/2013 - 10:15:19 ---A- C:\Users\stéphanie.stéphanie-PC\Links\Desktop.lnk [495] O61 - LFC:Last File Created 30/01/2013 - 10:15:19 ---A- C:\Users\stéphanie.stéphanie-PC\Links\Downloads.lnk [970] O61 - LFC:Last File Created 30/01/2013 - 10:15:19 ---A- C:\Users\stéphanie.stéphanie-PC\Links\RecentPlaces.lnk [383] O61 - LFC:Last File Created 30/01/2013 - 10:15:46 ----- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\FXSAPIDebugLogFile.txt [0] O61 - LFC:Last File Created 30/01/2013 - 10:15:48 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\rasphone.pbk [0] O61 - LFC:Last File Created 30/01/2013 - 16:14:56 ---A- C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Microsoft\MMC\eventvwr [145892] O61 - LFC:Last File Created 30/12/1899 - 01:58:14 -SHA- C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Microsoft\Protect\CREDHIST [24] O61 - LFC:Last File Created 30/12/1899 - 01:58:27 -SHA- C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Microsoft\Protect\S-1-5-21-1442334213-2374068315-3074064575-1000\1419c45f-9986-4d98-8ac1-8f5f90267ddd [468] O61 - LFC:Last File Created 30/12/1899 - 01:58:28 -SHA- C:\Users\stéphanie.stéphanie-PC\AppData\Roaming\Microsoft\Protect\S-1-5-21-1442334213-2374068315-3074064575-1000\Preferred [24] O61 - LFC:Last File Created 30/12/1899 - 10:15:19 R-HA- C:\Users\stéphanie.stéphanie-PC\Searches\Everywhere.search-ms [248] O61 - LFC:Last File Created 30/12/1899 - 10:15:19 R-HA- C:\Users\stéphanie.stéphanie-PC\Searches\Indexed Locations.search-ms [248] ~ Scan Files in 00mn 03s ---\\ Liste des outils de nettoyage (O63) O63 - Logiciel: ZHPDiag 1.34 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 ~ Scan ADS in 00mn 00s ---\\ Liste des services Legacy (O64) O64 - Services: CurCS - 25/04/2011 - C:\Windows\system32\drivers\afd.sys (AFD) .(.Microsoft Corporation - Ancillary Function Driver for WinSock.) - LEGACY_AFD O64 - Services: CurCS - 16/01/2013 - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20130116.013\BHDrvx86.sys (BHDrvx86) .(.Symantec Corporation - BASH Driver.) - LEGACY_BHDRVX86 O64 - Services: CurCS - 07/06/2012 - C:\Windows\system32\drivers\NIS\1309000.009\ccSetx86.sys (ccSet_NIS) .(.Symantec Corporation - Common Client Settings Driver.) - LEGACY_CCSET_NIS O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\clfs.sys (CLFS) .(.Microsoft Corporation - Common Log File System Driver.) - LEGACY_CLFS O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\Drivers\cng.sys (CNG) .(.Microsoft Corporation - Kernel Cryptography, Next Generation.) - LEGACY_CNG O64 - Services: CurCS - 30/01/2013 - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (eeCtrl) .(.Symantec Corporation - Symantec Eraser Control Driver.) - LEGACY_EECTRL O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\fvevol.sys (fvevol) .(.Microsoft Corporation - BitLocker Drive Encryption Driver.) - LEGACY_FVEVOL O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\hwpolicy.sys (hwpolicy) .(.Microsoft Corporation - Hardware Policy Driver.) - LEGACY_HWPOLICY O64 - Services: CurCS - 29/01/2013 - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20130201.001\IDSvix86.sys (IDSVix86) .(.Symantec Corporation - IDS Core Driver.) - LEGACY_IDSVIX86 O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\lltdio.sys (lltdio) .(.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) - LEGACY_LLTDIO O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\luafv.sys (luafv) .(.Microsoft Corporation - Pilote de filtre de virtualisation de fichi.) - LEGACY_LUAFV O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\wkssvc.dll (mrxsmb20) .(.Microsoft Corporation - DLL du service Station de travail.) - LEGACY_MRXSMB20 O64 - Services: CurCS - 30/01/2013 - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20130201.033\NAVENG.sys (NAVENG) .(.Symantec Corporation - AV Engine.) - LEGACY_NAVENG O64 - Services: CurCS - 30/01/2013 - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20130201.033\NAVEX15.sys (NAVEX15) .(.Symantec Corporation - AV Engine.) - LEGACY_NAVEX15 O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\ndis.sys (NDIS) .(.Microsoft Corporation - Pilote NDIS 6.20.) - LEGACY_NDIS O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\netbt.sys (NetBT) .(.Microsoft Corporation - MBT Transport driver.) - LEGACY_NETBT O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\drivers\pacer.sys (Psched) .(.Microsoft Corporation - Planificateur de paquets QoS.) - LEGACY_PSCHED O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\rspndr.sys (rspndr) .(.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) - LEGACY_RSPNDR O64 - Services: CurCS - ??\??\???? - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV O64 - Services: CurCS - 06/07/2012 - C:\Windows\system32\Drivers\NIS\1309000.009\SRTSP.sys (SRTSP) .(.Symantec Corporation - Symantec AutoProtect.) - LEGACY_SRTSP O64 - Services: CurCS - 06/07/2012 - C:\Windows\system32\drivers\NIS\1309000.009\SRTSPX.sys (SRTSPX) .(.Symantec Corporation - Symantec AutoProtect.) - LEGACY_SRTSPX O64 - Services: CurCS - 29/04/2011 - C:\Windows\System32\DRIVERS\srvnet.sys (srvnet) .(.Microsoft Corporation - Server Network driver.) - LEGACY_SRVNET O64 - Services: CurCS - 16/05/2011 - C:\Windows\System32\drivers\NIS\1309000.009\SYMDS.sys (SymDS) .(.Symantec Corporation - Symantec Data Store.) - LEGACY_SYMDS O64 - Services: CurCS - 22/05/2012 - C:\Windows\System32\drivers\NIS\1309000.009\SYMEFA.sys (SymEFA) .(.Symantec Corporation - Symantec Extended File Attributes.) - LEGACY_SYMEFA O64 - Services: CurCS - 30/01/2013 - C:\Windows\system32\Drivers\SYMEVENT.sys (SymEvent) .(.Symantec Corporation - Symantec Event Library.) - LEGACY_SYMEVENT O64 - Services: CurCS - 18/04/2012 - C:\Windows\system32\drivers\NIS\1309000.009\Ironx86.sys (SymIRON) .(.Symantec Corporation - Iron Driver.) - LEGACY_SYMIRON O64 - Services: CurCS - 18/04/2012 - C:\Windows\system32\Drivers\NIS\1309000.009\SYMNETS.sys (SymNetS) .(.Symantec Corporation - Network Security Driver.) - LEGACY_SYMNETS O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\vga.sys (VgaSave) .(.Microsoft Corporation - VGA/Super VGA Video Driver.) - LEGACY_VGASAVE O64 - Services: CurCS - 20/11/2010 - C:\Windows\System32\drivers\volsnap.sys (volsnap) .(.Microsoft Corporation - Pilote de cliché instantané du volume.) - LEGACY_VOLSNAP O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\rascfg.dll (Wanarpv6) .(.Microsoft Corporation - Objets de configuration RAS.) - LEGACY_WANARPV6 ~ Scan Services in 00mn 00s ---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.bat> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKCR\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O67 - Shell Spawning: <.js> [HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe ~ Scan Keys in 00mn 00s ---\\ Start Menu Internet (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.) O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.) O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.) ~ Scan Keys in 00mn 00s ---\\ Search Browser Infection (O69) O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com ~ Scan Keys in 00mn 00s ---\\ Recherche des services démarrés par Svchost (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [62464] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [674304] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [473600] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [90624] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [286208] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [49664] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [521216] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [1933848] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [47104] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164352] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [102400] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800] ~ Scan Services in 00mn 00s ---\\ Recherche particuliere à la racine de certains dossiers (O84) [MD5.E17022079D0FDAC6EA094B1E29D22B61] [SPRF][02/02/2013] (.Piriform Ltd - CCleaner Installer.) -- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\25623-667949-ccleaner.exe [3907920] [MD5.E340610FFB87526CEA07D93102814D18] [SPRF][02/02/2013] (...) -- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\GenericUninstall.exe [127320] [MD5.39D998E29DC9277C8762070901E69A32] [SPRF][24/06/2011] (.Google Inc. - Google Toolbar Installer.) -- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\GoogleToolbarInstaller_stub_signed.exe [235184] [MD5.91FAF88F3A51941716E21C1805A8E4FA] [SPRF][01/02/2013] (...) -- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\instloffer.exe [168728] [MD5.8A4AF3B0695F29186AD02E2FD766FA3B] [SPRF][02/02/2013] (.SweetIM Technologies Ltd. - SQLite DLL.) -- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\mgsqlite3.dll [393016] [MD5.3CD1A63A0A2A70DF8A41119EF7B75E57] [SPRF][02/02/2013] (.SweetIM Technologies Ltd. - SweetIM Installer by SweetPacks.) -- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\Shortcut_Shortcut_toolbar_vit_sweetim.exe [7216040] [MD5.3CD1A63A0A2A70DF8A41119EF7B75E57] [SPRF][02/02/2013] (.SweetIM Technologies Ltd. - SweetIM Installer by SweetPacks.) -- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\Shortcut_toolbar_vit_sweetim.exe [7216040] [MD5.3D163F2ED6D30593F69A0CE1E3FBFD02] [SPRF][02/02/2013] (.SweetIM Technologies Ltd. - SweetPacks Browser Updater.) -- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\SimboApp.exe [1285976] [MD5.7704B843006444B69486FD27D4660845] [SPRF][02/02/2013] (.SweetIM Technologies Lt - This installer.) -- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\SIMEEIInstaller.exe [3380216] [MD5.BFA04EC64BE6B677C56B66B09811B7D4] [SPRF][02/02/2013] (.TODO: - TODO: .) -- C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\uninstaller.exe [375128] [MD5.7B0C2FBC82CFD78C90B7279F623F0495] [SPRF][14/12/2010] (.Microsoft Corp - Microsoft Support Diagnostic Tool Control.) -- C:\Windows\Downloaded Program Files\MSDcode.dll [562512] ~ Scan Files in 00mn 00s ---\\ Firewall Active Exception List (FirewallRules) (O87) O87 - FAEL: "{B7A0BF54-BABE-49B0-826D-266110CA6A3C}" | In - None - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe ~ Scan Firewall in 00mn 01s ---\\ Scan Additionnel (O88) Database Version : v2.10502 - (01/02/2013) Clés trouvées (Keys found) : 4 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 0 Fichiers trouvés (Files found) : 13 [HKLM\Software\Microsoft\Tracing\BingBar_RASMANCS] =>Toolbar.Agent [HKCU\Software\Softonic] =>Toolbar.Conduit [HKCU\Software\SweetIM] =>PUP.SweetIM [HKLM\Software\Microsoft\Tracing\BingBar_RASAPI32] =>Toolbar.Agent C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\Shortcut_Shortcut_toolbar_vit_sweetim.exe =>PUP.SweetIM C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\Shortcut_toolbar_vit_sweetim.exe =>PUP.SweetIM C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\SIMEEIInstaller.exe =>PUP.SweetIM C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\mgsqlite3.dll => Infection PUP (PUP.SweetIM) C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\Shortcut_Shortcut_toolbar_vit_sweetim.exe => Infection PUP (PUP.SweetIM) C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\Shortcut_toolbar_vit_sweetim.exe => Infection PUP (PUP.SweetIM) C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\SimboApp.exe => Infection PUP (PUP.SweetIM) C:\Users\stéphanie.stéphanie-PC\AppData\Local\Temp\SIMEEIInstaller.exe => Infection PUP (PUP.SweetIM) ~ Scan Additionnel in 00mn 19s ---\\ Recherche détournement de DNS routeur (O89) (None) ---\\ Product Upgrade Codes (O90) O90 - PUC: "00004159070000000000000000F01FEC" . (.Microsoft Office 2010.) -- C:\Windows\Installer\{95140000-0070-0000-0000-0000000FF1CE}\oobeicon.exe O90 - PUC: "076CFAAAB965F2A4284B2449E5D03EFE" . (.Windows Live Writer.) -- C:\Windows\Installer\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}\ApplicationIcon.ico O90 - PUC: "0C69D82C09A6E9540A776A07F6E40CCF" . (.Bing Bar.) -- C:\Windows\Installer\{C28D96C0-6A90-459E-A077-A6706F4EC0FC}\icon_installer_ico O90 - PUC: "1D034B0FAA6BD374B960AAD30DF10D8B" . (.Microsoft SQL Server 2005 Compact Edition [ENU].) -- C:\Windows\Installer\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}\ProductIcon O90 - PUC: "68AB67CA7DA7FFFFB744AA0000000010" . (.Adobe Reader X MUI.) -- C:\Windows\Installer\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}\SC_Reader.ico O90 - PUC: "6FD66A043D225B447A3D381B812A0CCD" . (.Norton Online Backup.) -- C:\Windows\Installer\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}\MainIcon.ico O90 - PUC: "BDAD5335AB438EA45A9146D887948864" . (.Skype™ 5.3.) -- C:\Windows\Installer\{5335DADB-34BA-4AE8-A519-648D78498846}\SkypeIcon.exe O90 - PUC: "D7314F9862C648A4DB8BE2A5B47BE100" . (.Microsoft Silverlight.) -- c:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ARPIcon ~ Scan Files in 00mn 00s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Demand 07/06/2011 191752 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files\Microsoft\BingBar\BBSvc.exe SS - | Auto 12/05/2011 249648 | (BBUpdate) . (.Microsoft Corporation.) - C:\Program Files\Microsoft\BingBar\SeaPort.exe SS - | Auto 01/12/2010 305744 | (DsiWMIService) . (.Dritek System Inc..) - C:\Program Files\Launch Manager\dsiwmis.exe SS - | Auto 10/05/2011 739944 | (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe SS - | Demand 12/10/2010 206072 | (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files\WildTangent Games\App\GamesAppService.exe SS - | Auto 18/01/2011 39528 | (GREGService) . (.Acer Incorporated.) - C:\Program Files\eMachines\Registration\GREGsvc.exe SS - | Auto 02/02/2013 116648 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 02/02/2013 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 02/02/2013 194032 | (gusvc) . (.Google.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe SS - | Auto 22/04/2011 244624 | (Live Updater Service) . (.Acer Incorporated.) - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe SR - | Auto 16/06/2012 138272 | (NIS) . (.Symantec Corporation.) - C:\Program Files\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe SS - | Auto 01/06/2010 2057560 | (NOBU) . (.Symantec Corporation.) - C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe SS - | Auto 31744 | (SrvUpdater) . (...) - C:\Program Files\SoftwareUpdater\UpdaterService.exe SR - | Auto 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SS - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Scan Services in 00mn 00s ---\\ Recherche Master Boot Record Infection (MBR)(O80) Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net Run by stéphanie at 02/02/2013 15:53:17 device: opened successfully user: MBR read successfully Disk trace: called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys C:\Windows\system32\drivers\iaStor.sys Intel Corporation Intel Rapid Storage Technology driver 1 ntkrnlpa!IofCallDriver[0x8183A52F] -> \Device\Harddisk0\DR0[0x85469AA0] 3 CLASSPNP[0x8890F59E] -> ntkrnlpa!IofCallDriver[0x8183A52F] -> [0x84941370] 5 ACPI[0x87EB13D4] -> ntkrnlpa!IofCallDriver[0x8183A52F] -> \Device\Ide\IAAStorageDevice-0[0x8493E028] kernel: MBR read successfully user & kernel MBR OK ~ Scan MBR in 00mn 02s ---\\ Recherche Master Boot Record Infection (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by stéphanie at 02/02/2013 15:53:19 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ Scan MBR in 00mn 04s End of the scan (1001 lines in 02mn 17s)(0)