Rapport de ZHPDiag v1.3.5.35 par Nicolas Coolman, Update du 07/02/2013 Run by mylene at 09/02/2013 17:36:35 State : Version à jour. UAC : Deactivate by program ---\\ Web Browser MSIE: Internet Explorer v9.0.8112.16421 MFIE: Mozilla Firefox 18.0.2 v18.0.2 (Defaut) ---\\ Windows Product Information ~ Langage: Français Windows 7 Starter Edition, 32-bit Service Pack 1 (Build 7601) Windows Server License Manager Script : OK Software Protection Service (Protection logicielle) : KO Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ System Information ~ Processor: x86 Family 6 Model 54 Stepping 1, GenuineIntel ~ Operating System: 32 Bits Boot mode: Sans échec avec prise en charge du réseau (Fail-safe with network boot) Total RAM: 1012 MB (47% free) System Restore: Activé (Enable) System drive C: has 257 GB (90%) free of 285 GB ---\\ Logged in mode ~ Computer Name: MYLENE-PC ~ User Name: mylene ~ All Users Names: mylene, Administrateur, ~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89 Logged in as Administrator ---\\ Environnement Variables ~ System Unit : C:\ ~ %AppData% : C:\Users\mylene\AppData\Roaming\ ~ %Desktop% : C:\Users\mylene\Desktop\ ~ %Favorites% : C:\Users\mylene\Favorites\ ~ %LocalAppData% : C:\Users\mylene\AppData\Local\ ~ %StartMenu% : C:\Users\mylene\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ DOS/Devices C:\ Hard drive, Flash drive, Thumb drive (Free 257 Go of 285 Go) ---\\ Security Center & Tools Informations [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK ~ Scan Security Center in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.14/07/2011 - 02:34:17.) -- C:\Windows\Explorer.exe [2616320] [MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256] [MD5.7FA3A810F383588D46220967DE8B64FF] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.14/11/2012 - 02:57:37.) -- C:\Windows\System32\wininet.dll [1129472] [MD5.6D13E1406F50C66E2A95D97F22C47560] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.20/11/2010 - 22:29:06.) -- C:\Windows\System32\Winlogon.exe [286720] [MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 22:29:24.) -- C:\Windows\System32\sppcomapi.dll [193536] [MD5.9EBBBA55060F786F0FCAA3893BFA2806] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.14/07/2011 - 02:30:42.) -- C:\Windows\system32\Drivers\AFD.sys [338944] [MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584] [MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656] [MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544] [MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 22:29:07.) -- C:\Windows\system32\Drivers\DfsC.sys [78336] [MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544] [MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896] [MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888] [MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.14/07/2011 - 02:36:43.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904] [MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 22:29:08.) -- C:\Windows\system32\Drivers\netBT.sys [187904] [MD5.0D87503986BB3DFED58E343FE39DDE13] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.31/08/2012 - 18:18:09.) -- C:\Windows\system32\Drivers\ntfs.sys [1211760] [MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360] [MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848] [MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168] [MD5.B459575348C20E8121D6039DA063C704] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 22:29:07.) -- C:\Windows\system32\Drivers\tdx.sys [74752] [MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\volsnap.sys [245632] ~ Scan Generic Processes in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 1/36 ~ Mes Favoris (My Favorites) : 1/18 ~ Mon Bureau (My Desktop) : 1/7 ~ Menu demarrer (Programs) : 1/21 ~ Scan Hidden Files in 00mn 00s ---\\ Processus lancés [MD5.58ED0528F2B1BFB3301BC10E0E707C35] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [917400] [PID.2008] [MD5.B45F1D52C0A9519028BD95D34FFAB216] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [17304] [PID.1360] [MD5.4EBF0CF9B48781DA145A147AA7E9E505] - (.Adobe Systems, Inc. - Adobe Flash Player 11.5 r502.) -- C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe [1808392] [PID.1108] [MD5.5AF5988C947F34FC478E0054DFD5D5F9] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [5660160] [PID.1432] ~ Scan Processes Running in 00mn 00s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\mylene\AppData\Roaming\Mozilla\Firefox\Profiles\j3m8pwj1.default\prefs.js M3 - MFPP: Plugins - [mylene] -- C:\Users\mylene\AppData\Roaming\Mozilla\Firefox\Profiles\j3m8pwj1.default\searchplugins\bingp.xml M3 - MFPP: Plugins - [mylene] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml M3 - MFPP: Plugins - [mylene] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml M3 - MFPP: Plugins - [mylene] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml M3 - MFPP: Plugins - [mylene] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml M3 - MFPP: Plugins - [mylene] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml M3 - MFPP: Plugins - [mylene] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml M3 - MFPP: Plugins - [mylene] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.1.10329.0.) -- c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8117.0416] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll P2 - FPN: [HKLM] [@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (...) -- C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.5.) -- C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll ~ Scan Firefox Browser in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://packardbell.msn.com R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)) -- C:\Windows\System32\ieframe.dll R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1 ~ Scan IE Browser in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Scan Proxy management in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Scan Keys in 00mn 00s ---\\ Redirection du fichier Hosts (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Scan Hosts File in 00mn 13s ~ Nombre de lignes (Lines number): 15313 ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} . (.Symantec Corporation - coIEPlugIn.) -- C:\Program Files\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} . (.Symantec Corporation - IPS Browser Helper DLL.) -- C:\Program Files\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} . (...) -- "C:\Program Files\Microsoft\BingBar\BingExt.dll" (.not file.) ~ Scan BHO in 00mn 00s ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: Norton Toolbar - [HKLM]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} . (.Symantec Corporation - coIEPlugIn.) -- C:\Program Files\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll O3 - Toolbar: Bing Bar - [HKLM]{8dcb7100-df86-4384-8842-8fa844297b3f} . (.Microsoft Corporation. - Extensions du client Bing.) -- C:\Program Files\Microsoft\BingBar\BingExt.dll ~ Scan Toolbar in 00mn 00s ---\\ Applications démarrées par registre & par dossier (O4) O4 - HKLM\..\Run: [Norton Online Backup] . (.Symantec Corporation - Norton Online Backup Service.) -- C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [GfxServiceInstall] . (...) -- C:\Windows\system32\GfxCUIServiceInstall.vbs O4 - HKLM\..\Run: [LManager] . (.Dritek System Inc. - Launch Manager.) -- C:\Program Files\Launch Manager\LManager.exe O4 - HKLM\..\Run: [ETDCtrl] . (.ELAN Microelectronics Corp. - ETD Control Center.) -- C:\Program Files\Elantech\ETDCtrl.exe O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe O4 - HKLM\..\Run: [Power Management] . (.Acer Incorporated - ePowerTray.) -- C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe O4 - HKCU\..\Run: [ooVoo.exe] . (.ooVoo LLC - ooVoo.) -- C:\program files\oovoo\oovoo.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-21-2555609281-1652748078-2745268579-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe O4 - HKUS\S-1-5-21-2555609281-1652748078-2745268579-1000\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe O4 - HKUS\S-1-5-21-2555609281-1652748078-2745268579-1000\..\Run: [ooVoo.exe] . (.ooVoo LLC - ooVoo.) -- C:\program files\oovoo\oovoo.exe O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe ~ Scan Application in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - Global Startup: C:\Users\mylene\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Scan Global Startup in 00mn 00s ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5) O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no ~ Scan IE Control Panel in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} . (.Evernote Corp., 333 W Evelyn Ave. Mountain - Evernote Clipper for Microsoft Internet Explorer.) -- C:\Program Files\Evernote\Evernote\Ev ~ Scan IE Extra Buttons in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll ~ Scan Winsock in 00mn 00s ---\\ Objets ActiveX (Downloaded Program Files)(O16) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} ((no name)) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab ~ Scan Objets ActiveX in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{0E7EAF66-0202-4CD2-92C1-2B96E5FFFDC2}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{0E7EAF66-0202-4CD2-92C1-2B96E5FFFDC2}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{0E7EAF66-0202-4CD2-92C1-2B96E5FFFDC2}: DhcpNameServer = 192.168.1.1 ~ Scan Domain in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll ~ Scan Protocole Additionnel in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll ~ Scan Winlogon in 00mn 00s ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. ~ Scan SSODL in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Dritek WMI Service (DsiWMIService) . (.Dritek System Inc. - Dritek WMI Service.) - C:\Program Files\Launch Manager\dsiwmis.exe O23 - Service: ePower Service (ePowerSvc) . (.Acer Incorporated - ePowerSvc.) - C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe O23 - Service: GREGService (GREGService) . (.Acer Incorporated - Global Registration Service.) - C:\Program Files\Packard Bell\Registration\GREGsvc.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation - IAStorDataSvc.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: IconMan_R (IconMan_R) . (.Realsil Microelectronics Inc. - Realtek Card Reader Icon Tool..) - C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe O23 - Service: Live Updater Service (Live Updater Service) . (.Acer Incorporated - Updater Service.) - C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe O23 - Service: Norton Internet Security (NIS) . (.Symantec Corporation - Symantec Service Framework.) - C:\Program Files\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe O23 - Service: Norton Online Backup (NOBU) . (.Symantec Corporation - Norton Online Backup Service.) - C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files\Skype\Updater\Updater.exe ~ Scan Services in 00mn 05s ---\\ Enumération Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(...) - (.not file.) ~ Scan Desktop Component in 00mn 00s ---\\ BootExecute (O34) O34 - HKLM BootExecute: (autocheck autochk *) - File not found ~ Scan Keys in 00mn 00s ---\\ Tâches planifiées en automatique (O39) O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Adobe Flash Player Updater.job ~ Scan Scheduled Task in 00mn 00s ---\\ Composants installés (ActiveSetup Installed Components) (O40) O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: Browser Customizations - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - Personnalisation d’IEAK.) -- C:\Windows\System32\iedkcs32.dll O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll ~ Scan Active Setup in 00mn 00s ---\\ Pilotes lancés au démarrage (O41) O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys O41 - Driver: (BHDrvx86) . (.Symantec Corporation - BASH Driver.) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\BASHDefs\20130116.013\BHDrvx86.sys O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\system32\drivers\blbdrive.sys O41 - Driver: (ccSet_NIS) . (.Symantec Corporation - Common Client Settings Driver.) - C:\Windows\system32\drivers\NIS\1309010.00E\ccSetx86.sys O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys O41 - Driver: (eeCtrl) . (.Symantec Corporation - Symantec Eraser Control Driver.) - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys O41 - Driver: (IDSVix86) . (.Symantec Corporation - IDS Core Driver.) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\IPSDefs\20130208.004\IDSvix86.sys O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys O41 - Driver: (SRTSPX) . (.Symantec Corporation - Symantec AutoProtect.) - C:\Windows\system32\drivers\NIS\1309010.00E\SRTSPX.sys O41 - Driver: (SymIRON) . (.Symantec Corporation - Iron Driver.) - C:\Windows\system32\drivers\NIS\1309010.00E\Ironx86.sys O41 - Driver: (SymNetS) . (.Symantec Corporation - Network Security Driver.) - C:\Windows\system32\Drivers\NIS\1309010.00E\SYMNETS.sys O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys ~ Scan Drivers in 00mn 20s ---\\ Logiciels installés (O42) O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- Adobe AIR O42 - Logiciel: Adobe AIR - (.Adobe Systems Incorporated.) [HKLM] -- {AFF7E080-1974-45BF-9310-10DE1A1F5ED0} O42 - Logiciel: Adobe Flash Player 11 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin O42 - Logiciel: Adobe Reader X (10.1.5) MUI - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-FFFF-7B44-AA0000000001} O42 - Logiciel: Akhra: The Treasures - (.WildTangent.) [HKLM] -- WTA-7582d8ed-4530-4289-853f-fa55a8ce2123 O42 - Logiciel: Alice's Magical Mahjong - (.WildTangent.) [HKLM] -- WTA-0e2431d0-0c13-4bb9-be55-998346fe02e7 O42 - Logiciel: Bejeweled 3 - (.WildTangent.) [HKLM] -- WTA-2e057cab-f511-481a-bb79-5aca019bc99d O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM] -- {C28D96C0-6A90-459E-A077-A6706F4EC0FC} O42 - Logiciel: Chuzzle Deluxe - (.WildTangent.) [HKLM] -- WTA-36c5b6ae-fe06-4937-b8e8-596a9fd12da5 O42 - Logiciel: Deals Plugin Extension - (.215 Apps.) [HKLM] -- Deals Plugin Extension O42 - Logiciel: Diego's Ultimate Rescue - (.WildTangent.) [HKLM] -- WTA-10bad245-0a3a-4afa-b677-25da4d140921 O42 - Logiciel: ETDWare PS/2-X86 8.0.6.0_WHQL - (.ELAN Microelectronic Corp..) [HKLM] -- Elantech O42 - Logiciel: Evernote v. 4.5.2 - (.Evernote Corp..) [HKLM] -- {F77EF646-19EB-11E1-9A9E-984BE15F174E} O42 - Logiciel: Final Drive: Nitro - (.WildTangent.) [HKLM] -- WTA-3449b694-e47f-4c61-adbb-bac3dab462fc O42 - Logiciel: Fooz Kids - (.FUHU, Inc..) [HKLM] -- FoozKids O42 - Logiciel: Fooz Kids - (.FUHU, Inc..) [HKLM] -- {52A066FB-6188-DE44-5170-A9F8003BBF5A} O42 - Logiciel: Fooz Kids Platform - (.FUHU, Inc..) [HKLM] -- {8D68CE08-9A14-4B7B-9857-3C646A2F34C7} O42 - Logiciel: Identity Card - (.Packard Bell.) [HKLM] -- Identity Card O42 - Logiciel: Insaniquarium Deluxe - (.WildTangent.) [HKLM] -- WTA-5b87ba9a-7c2f-43f2-b2b4-1019857efd16 O42 - Logiciel: Intel(R) Control Center - (.Intel Corporation.) [HKLM] -- {F8A9085D-4C7A-41a9-8A77-C8998A96C421} O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM] -- {3E29EE6C-963A-4aae-86C1-DC237C4A49FC} O42 - Logiciel: Launch Manager - (.Packard Bell.) [HKLM] -- LManager O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94} O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570} O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} O42 - Logiciel: Mozilla Firefox 18.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 18.0.2 (x86 fr) O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService O42 - Logiciel: My Farm Life - (.WildTangent.) [HKLM] -- WTA-0aa6b6ca-d63d-4bcf-98ed-327d9519909a O42 - Logiciel: My Kingdom for the Princess 3 - (.WildTangent.) [HKLM] -- WTA-71df113d-e742-476f-8a57-f8d6e3819ef5 O42 - Logiciel: Norton Internet Security - (.Symantec Corporation.) [HKLM] -- NIS O42 - Logiciel: Norton Online Backup - (.Symantec Corporation.) [HKLM] -- {40A66DF6-22D3-44B5-A7D3-83B118A2C0DC} O42 - Logiciel: Packard Bell Games - (.WildTangent.) [HKLM] -- WildTangent packardbell Master Uninstall O42 - Logiciel: Packard Bell Power Management - (.Packard Bell.) [HKLM] -- {3DB0448D-AD82-4923-B305-D001E521A964} O42 - Logiciel: Packard Bell Recovery Management - (.Packard Bell.) [HKLM] -- {7F811A54-5A09-4579-90E1-C93498E230D9} O42 - Logiciel: Packard Bell Registration - (.Packard Bell.) [HKLM] -- Packard Bell Registration O42 - Logiciel: Packard Bell ScreenSaver - (.Packard Bell .) [HKLM] -- Packard Bell Screensaver O42 - Logiciel: Packard Bell Social Networks - (.CyberLink Corp..) [HKLM] -- InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9} O42 - Logiciel: Packard Bell Social Networks - (.CyberLink Corp..) [HKLM] -- {64EF903E-D00A-414C-94A4-FBA368FFCDC9} O42 - Logiciel: Packard Bell Updater - (.Packard Bell.) [HKLM] -- {EE171732-BEB4-4576-887D-CB62727F01CA} O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} O42 - Logiciel: Realtek PCIE Card Reader - (.Realtek Semiconductor Corp..) [HKLM] -- {C1594429-8296-4652-BF54-9DBE4932A44C} O42 - Logiciel: Running Sheep - (.WildTangent.) [HKLM] -- WTA-5f411bdd-11ae-4f89-8184-aec34391a3b8 O42 - Logiciel: Skip-Bo - Castaway Caper - (.WildTangent.) [HKLM] -- WTA-b8d25645-2d04-400d-ba3e-91bd3e330c26 O42 - Logiciel: Skype™ 6.1 - (.Skype Technologies S.A..) [HKLM] -- {4E76FF7E-AEBA-4C87-B788-CD47E5425B9D} O42 - Logiciel: Slingo Deluxe - (.WildTangent.) [HKLM] -- WTA-9220b556-6360-422e-95f3-131be5fd4592 O42 - Logiciel: Super Granny 6 - (.WildTangent.) [HKLM] -- WTA-e9ba15e8-7d04-49e5-b713-507d3660e58c O42 - Logiciel: Update Installer for WildTangent Games App - (.WildTangent.) [HKLM] -- {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App O42 - Logiciel: Wedding Dash - (.WildTangent.) [HKLM] -- WTA-fe65866d-b8a0-4cc2-b0d7-2257a8b60b4e O42 - Logiciel: Welcome Center - (.Packard Bell.) [HKLM] -- Packard Bell Welcome Center O42 - Logiciel: WildTangent Games App (Packard Bell Games) - (.WildTangent.) [HKLM] -- {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-packardbell O42 - Logiciel: eBay Worldwide - (.OEM.) [HKLM] -- {D3E5A972-9A15-427D-AE78-8181A5FD943C} O42 - Logiciel: ooVoo - (.ooVoo LLC..) [HKLM] -- {FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623} ---\\ HKCU & HKLM Software Keys [HKCU\Software\Acer] [HKCU\Software\Adobe] [HKCU\Software\AppDataLow\Software\Deals Plugin Extension] [HKCU\Software\AppDataLow\Software\Microsoft] [HKCU\Software\AppDataLow\Software] [HKCU\Software\AppDataLow] [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\Cyberlink] [HKCU\Software\Dritek] [HKCU\Software\Elantech] [HKCU\Software\IM Providers] [HKCU\Software\Intel] [HKCU\Software\Local AppWizard-Generated Applications] [HKCU\Software\Macromedia] [HKCU\Software\Mozilla] [HKCU\Software\Netscape] [HKCU\Software\OEM] [HKCU\Software\Policies] [HKCU\Software\Realtek] [HKCU\Software\Skype-BackupBySkypePortable] [HKCU\Software\Skype] [HKCU\Software\Symantec] [HKCU\Software\TeleCharger] [HKCU\Software\ZebHelpProcess Helper] [HKCU\Software\ooVoo] [HKLM\Software\ATI Technologies] [HKLM\Software\Acer] [HKLM\Software\Adobe] [HKLM\Software\AdwCleaner] [HKLM\Software\CBSTEST] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\Cyberlink] [HKLM\Software\DTS] [HKLM\Software\Dolby] [HKLM\Software\Dritek] [HKLM\Software\Evernote] [HKLM\Software\FUHU, Inc.] [HKLM\Software\Google] [HKLM\Software\IM Providers] [HKLM\Software\Intel] [HKLM\Software\Knowles] [HKLM\Software\Macromedia] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\Norton] [HKLM\Software\ODBC] [HKLM\Software\OEM] [HKLM\Software\OOBEOffer] [HKLM\Software\OemSetup] [HKLM\Software\Packard Bell] [HKLM\Software\Policies] [HKLM\Software\RTLSetup] [HKLM\Software\Realtek Semiconductor Corp.] [HKLM\Software\Realtek] [HKLM\Software\RegisteredApplications] [HKLM\Software\SRS Labs] [HKLM\Software\Skype] [HKLM\Software\SonicFocus] [HKLM\Software\Symantec] [HKLM\Software\WOW6432Node] [HKLM\Software\Waves Audio] [HKLM\Software\WildTangent] [HKLM\Software\mozilla.org] ~ Scan Softwares in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 30/01/2013 - 19:30:29 - [0,661] ----D C:\Program Files\Accessory Store O43 - CFD: 13/04/2012 - 12:13:03 - [455,751] ----D C:\Program Files\Adobe O43 - CFD: 30/01/2013 - 20:40:43 - [119,696] ----D C:\Program Files\Common Files O43 - CFD: 06/02/2013 - 22:31:37 - [5,131] ----D C:\Program Files\Deals Plugin Extension O43 - CFD: 31/01/2013 - 03:27:25 - [3,997] ----D C:\Program Files\DVD Maker O43 - CFD: 30/01/2013 - 18:53:02 - [12,574] ----D C:\Program Files\Elantech O43 - CFD: 13/04/2012 - 11:43:29 - [170,242] ----D C:\Program Files\Evernote O43 - CFD: 30/01/2013 - 19:29:30 - [0] R---D C:\Program Files\Fichiers communs O43 - CFD: 13/04/2012 - 12:13:04 - [21,344] ----D C:\Program Files\Fooz Kids O43 - CFD: 30/01/2013 - 19:12:31 - [63,913] --H-D C:\Program Files\InstallShield Installation Information O43 - CFD: 30/01/2013 - 18:43:37 - [26,095] ----D C:\Program Files\Intel O43 - CFD: 03/02/2013 - 02:31:17 - [4,954] ----D C:\Program Files\Internet Explorer O43 - CFD: 30/01/2013 - 18:50:10 - [8,668] ----D C:\Program Files\Launch Manager O43 - CFD: 30/01/2013 - 21:33:28 - [20,149] ----D C:\Program Files\Microsoft O43 - CFD: 14/07/2009 - 05:52:30 - [44,521] ----D C:\Program Files\Microsoft Games O43 - CFD: 30/01/2013 - 19:09:27 - [6,126] ----D C:\Program Files\Microsoft Office O43 - CFD: 02/02/2013 - 15:07:51 - [36,641] ----D C:\Program Files\Microsoft Silverlight O43 - CFD: 30/01/2013 - 21:34:28 - [1,745] ----D C:\Program Files\Microsoft SQL Server Compact Edition O43 - CFD: 03/02/2013 - 03:02:21 - [0,015] ----D C:\Program Files\Microsoft.NET O43 - CFD: 06/02/2013 - 18:45:40 - [44,644] ----D C:\Program Files\Mozilla Firefox O43 - CFD: 06/02/2013 - 23:38:55 - [0,212] ----D C:\Program Files\Mozilla Maintenance Service O43 - CFD: 14/07/2009 - 05:52:30 - [0,025] ----D C:\Program Files\MSBuild O43 - CFD: 13/04/2012 - 12:10:14 - [222,227] ----D C:\Program Files\Norton Internet Security O43 - CFD: 13/04/2012 - 12:09:49 - [52,194] ----D C:\Program Files\NortonInstaller O43 - CFD: 30/01/2013 - 19:30:58 - [0,105] ----D C:\Program Files\OEM O43 - CFD: 07/02/2013 - 15:23:05 - [29,038] ----D C:\Program Files\oovoo O43 - CFD: 30/01/2013 - 19:12:31 - [101,371] ----D C:\Program Files\Packard Bell O43 - CFD: 13/04/2012 - 12:05:57 - [260,272] ----D C:\Program Files\Packard Bell Games O43 - CFD: 30/01/2013 - 19:30:18 - [0,127] ----D C:\Program Files\Preload O43 - CFD: 30/01/2013 - 18:56:14 - [46,671] ----D C:\Program Files\Realtek O43 - CFD: 14/07/2009 - 05:52:30 - [37,357] ----D C:\Program Files\Reference Assemblies O43 - CFD: 30/01/2013 - 20:40:43 - [18,091] R---D C:\Program Files\Skype O43 - CFD: 30/01/2013 - 19:06:01 - [33,217] ----D C:\Program Files\Social Networks O43 - CFD: 13/04/2012 - 12:11:05 - [4,982] ----D C:\Program Files\Symantec O43 - CFD: 13/04/2012 - 12:11:09 - [0,727] ----D C:\Program Files\SymSilent O43 - CFD: 30/01/2013 - 18:57:40 - [0] --H-D C:\Program Files\Temp O43 - CFD: 14/07/2009 - 05:53:23 - [0] --H-D C:\Program Files\Uninstall Information O43 - CFD: 13/04/2012 - 11:39:27 - [9,782] ----D C:\Program Files\WildTangent Games O43 - CFD: 31/01/2013 - 03:27:24 - [2,909] ----D C:\Program Files\Windows Defender O43 - CFD: 30/01/2013 - 21:36:16 - [134,104] ----D C:\Program Files\Windows Live O43 - CFD: 30/01/2013 - 21:32:53 - [0,234] ----D C:\Program Files\Windows Live SkyDrive O43 - CFD: 31/01/2013 - 03:27:25 - [5,895] ----D C:\Program Files\Windows Mail O43 - CFD: 31/01/2013 - 03:27:25 - [6,298] ----D C:\Program Files\Windows Media Player O43 - CFD: 30/01/2013 - 19:29:30 - [11,632] ----D C:\Program Files\Windows NT O43 - CFD: 31/01/2013 - 03:27:25 - [4,213] ----D C:\Program Files\Windows Photo Viewer O43 - CFD: 20/11/2010 - 22:33:48 - [0,181] ----D C:\Program Files\Windows Portable Devices O43 - CFD: 31/01/2013 - 03:27:25 - [6,314] ----D C:\Program Files\Windows Sidebar O43 - CFD: 09/02/2013 - 17:36:38 - [15,430] ----D C:\Program Files\ZHPDiag O43 - CFD: 13/04/2012 - 12:07:26 - [18,411] ----D C:\Program Files\Common Files\Adobe O43 - CFD: 13/04/2012 - 12:13:02 - [29,675] ----D C:\Program Files\Common Files\Adobe AIR O43 - CFD: 30/01/2013 - 18:56:06 - [1,943] ----D C:\Program Files\Common Files\InstallShield O43 - CFD: 30/01/2013 - 21:33:02 - [17,761] ----D C:\Program Files\Common Files\microsoft shared O43 - CFD: 14/07/2009 - 03:37:05 - [0,003] ----D C:\Program Files\Common Files\Services O43 - CFD: 30/01/2013 - 20:40:43 - [2,056] ----D C:\Program Files\Common Files\Skype O43 - CFD: 14/07/2009 - 03:37:05 - [39,200] ----D C:\Program Files\Common Files\SpeechEngines O43 - CFD: 31/01/2013 - 00:38:30 - [0,880] ----D C:\Program Files\Common Files\Symantec Shared O43 - CFD: 31/01/2013 - 03:27:25 - [9,767] ----D C:\Program Files\Common Files\System O43 - CFD: 13/04/2012 - 11:46:11 - [0] ----D C:\Program Files\Common Files\Windows Live O43 - CFD: 02/02/2013 - 21:38:01 - [11,474] ----D C:\ProgramData\Adobe O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Application Data O43 - CFD: 30/01/2013 - 19:29:30 - [0] --H-D C:\ProgramData\Bureau O43 - CFD: 30/01/2013 - 19:06:01 - [0,000] ----D C:\ProgramData\CLSK O43 - CFD: 31/01/2013 - 19:23:27 - [0,010] ----D C:\ProgramData\CyberLink O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Desktop O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Documents O43 - CFD: 13/04/2012 - 11:43:16 - [0] ----D C:\ProgramData\Evernote O43 - CFD: 30/01/2013 - 19:29:30 - [0] --H-D C:\ProgramData\Favoris O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Favorites O43 - CFD: 13/04/2012 - 12:13:05 - [0] ----D C:\ProgramData\Fooz Kids O43 - CFD: 30/01/2013 - 19:06:01 - [0,011] ----D C:\ProgramData\install_clap O43 - CFD: 30/01/2013 - 19:29:30 - [0] --H-D C:\ProgramData\Menu Démarrer O43 - CFD: 03/02/2013 - 01:54:26 - [2036,178] -S--D C:\ProgramData\Microsoft O43 - CFD: 30/01/2013 - 19:29:30 - [0] --H-D C:\ProgramData\Modèles O43 - CFD: 30/01/2013 - 20:15:19 - [0,007] ----D C:\ProgramData\Mozilla O43 - CFD: 30/01/2013 - 19:33:09 - [275,124] ----D C:\ProgramData\Norton O43 - CFD: 13/04/2012 - 12:09:49 - [97,983] ----D C:\ProgramData\NortonInstaller O43 - CFD: 30/01/2013 - 19:34:36 - [0,001] ----D C:\ProgramData\oem O43 - CFD: 13/04/2012 - 11:44:23 - [0,260] ----D C:\ProgramData\Packard Bell O43 - CFD: 01/02/2013 - 12:53:01 - [38,210] ----D C:\ProgramData\Skype O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Start Menu O43 - CFD: 13/04/2012 - 12:06:18 - [0,004] ----D C:\ProgramData\Symantec O43 - CFD: 30/01/2013 - 19:10:08 - [0,378] ----D C:\ProgramData\Temp O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Templates O43 - CFD: 13/04/2012 - 11:42:44 - [853,715] ----D C:\ProgramData\WildTangent O43 - CFD: 01/02/2013 - 00:45:53 - [0,671] ----D C:\Users\mylene\AppData\Roaming\Adobe O43 - CFD: 31/01/2013 - 19:20:00 - [0,028] ----D C:\Users\mylene\AppData\Roaming\CyberLink O43 - CFD: 30/01/2013 - 19:32:33 - [0] ----D C:\Users\mylene\AppData\Roaming\Identities O43 - CFD: 13/04/2012 - 12:13:03 - [0,057] ----D C:\Users\mylene\AppData\Roaming\Macromedia O43 - CFD: 01/02/2013 - 00:45:53 - [2,422] -S--D C:\Users\mylene\AppData\Roaming\Microsoft O43 - CFD: 30/01/2013 - 20:18:24 - [16,245] ----D C:\Users\mylene\AppData\Roaming\Mozilla O43 - CFD: 06/02/2013 - 22:32:15 - [2,843] ----D C:\Users\mylene\AppData\Roaming\ooVoo Details O43 - CFD: 09/02/2013 - 17:29:59 - [4,526] ----D C:\Users\mylene\AppData\Roaming\Skype O43 - CFD: 01/02/2013 - 13:06:06 - [0] ----D C:\Users\mylene\AppData\Roaming\SkypePM O43 - CFD: 31/01/2013 - 17:03:15 - [0,001] ----D C:\Users\mylene\AppData\Roaming\SNS O43 - CFD: 01/02/2013 - 00:45:53 - [9,256] ----D C:\Users\mylene\AppData\Local\Adobe O43 - CFD: 30/01/2013 - 19:30:03 - [0] ----D C:\Users\mylene\AppData\Local\Application Data O43 - CFD: 31/01/2013 - 19:19:34 - [0] ----D C:\Users\mylene\AppData\Local\CyberLink O43 - CFD: 06/02/2013 - 22:30:52 - [0,061] ----D C:\Users\mylene\AppData\Local\Deals Plugin Extension O43 - CFD: 06/02/2013 - 22:30:50 - [0,132] ----D C:\Users\mylene\AppData\Local\Google O43 - CFD: 30/01/2013 - 19:30:03 - [0] ----D C:\Users\mylene\AppData\Local\Historique O43 - CFD: 01/02/2013 - 21:58:40 - [0] ----D C:\Users\mylene\AppData\Local\Macromedia O43 - CFD: 01/02/2013 - 00:45:53 - [212,252] ----D C:\Users\mylene\AppData\Local\Microsoft O43 - CFD: 30/01/2013 - 20:15:46 - [8,949] ----D C:\Users\mylene\AppData\Local\Mozilla O43 - CFD: 09/02/2013 - 17:35:58 - [100,924] ----D C:\Users\mylene\AppData\Local\Temp O43 - CFD: 30/01/2013 - 19:30:03 - [0] ----D C:\Users\mylene\AppData\Local\Temporary Internet Files O43 - CFD: 07/02/2013 - 15:24:17 - [0] ----D C:\Users\mylene\AppData\Local\Updater21806 O43 - CFD: 30/01/2013 - 19:30:05 - [0] ----D C:\Users\mylene\AppData\Local\VirtualStore O43 - CFD: 14/07/2009 - 05:42:04 - [0,014] R---D C:\Users\mylene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 03/02/2013 - 12:42:18 - [0,000] R---D C:\Users\mylene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 14/07/2009 - 05:37:42 - [0,001] R---D C:\Users\mylene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 03/02/2013 - 12:42:18 - [0,000] R---D C:\Users\mylene\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup ~ Scan Program Folder in 00mn 22s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.D1C4CF8093701402AB31E7E8F1B65631] - 09/02/2013 - 17:35:25 ---A- . (...) -- C:\Windows\ntbtlog.txt [778744] O44 - LFC:[MD5.331F24509FA723B19666722F2557C194] - 09/02/2013 - 17:35:20 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.C6DB3C5C568FAABA271C052DFC25CAE3] - 09/02/2013 - 17:34:15 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1614095] O44 - LFC:[MD5.A96882467FC5B622E60368D6BBAA6572] - 09/02/2013 - 17:19:53 --HA- . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [16480] O44 - LFC:[MD5.A96882467FC5B622E60368D6BBAA6572] - 09/02/2013 - 17:19:52 --HA- . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [16480] O44 - LFC:[MD5.BE4C51746CF1060063009B94A5D1E815] - 09/02/2013 - 17:12:21 ---A- . (...) -- C:\Windows\setupact.log [36397] O44 - LFC:[MD5.3ABD772582B5A9E193DF5BDA85012278] - 09/02/2013 - 16:52:21 ---A- . (...) -- C:\AdwCleaner[S1].txt [17968] O44 - LFC:[MD5.83A15B297DA6129954C340B424CB565D] - 09/02/2013 - 15:18:19 ---A- . (...) -- C:\Windows\MEMORY.DMP [173364011] O44 - LFC:[MD5.6280A479148CAEAD59E17A0CC3789161] - 08/02/2013 - 18:28:34 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerApp.exe [697712] O44 - LFC:[MD5.3E5633C0E3B4FE04E6EBFFA597227617] - 08/02/2013 - 18:28:34 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [74096] O44 - LFC:[MD5.A6A813E4B9D909810BD9A7CB4FB3993E] - 06/02/2013 - 23:38:05 ----- . (...) -- C:\bootsqm.dat [3288] O44 - LFC:[MD5.18B529E3340ABE1138221F572B4369DD] - 06/02/2013 - 23:29:00 ---A- . (...) -- C:\log.txt [40] O44 - LFC:[MD5.27776727F27184822CDB27595C9A4AA6] - 06/02/2013 - 19:34:17 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1549700] O44 - LFC:[MD5.35B4A2A70613BF32DE9012B0B882F001] - 06/02/2013 - 19:34:17 ---A- . (...) -- C:\Windows\System32\perfc009.dat [106388] O44 - LFC:[MD5.189D330C7BD61C5AF5B16BA94C84981B] - 06/02/2013 - 19:34:17 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [130754] O44 - LFC:[MD5.0035E95346CC0C43175EBB1AC406061D] - 06/02/2013 - 19:34:17 ---A- . (...) -- C:\Windows\System32\perfh009.dat [616008] O44 - LFC:[MD5.E844595E137F81E3BC7125A8E0D11500] - 06/02/2013 - 19:34:17 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [704480] O44 - LFC:[MD5.00AF42EEE139B700E656289435AE6C1C] - 03/02/2013 - 02:33:24 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [259232] O44 - LFC:[MD5.E32230F4135D507E79509C998F4D8C92] - 03/02/2013 - 02:20:12 ---A- . (.Adobe Systems - Windows NT OpenType/Type 1 API Library..) -- C:\Windows\System32\atmlib.dll [34304] O44 - LFC:[MD5.5DAF8A6B7F127C4E70A5C1F707347859] - 03/02/2013 - 02:20:12 ---A- . (.Adobe Systems Incorporated - Windows NT OpenType/Type 1 Font Driver.) -- C:\Windows\System32\atmfd.dll [295424] O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 03/02/2013 - 01:54:24 --HA- . (...) -- C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf [0] O44 - LFC:[MD5.ED59143843560B5EDB543C2A48CB9E4B] - 31/01/2013 - 14:08:10 ---A- . (.Microsoft - Système de classification OFLC-NZ.) -- C:\Windows\System32\oflc-nz.rs [45568] O44 - LFC:[MD5.6EC618588447B82EA8D88719EE46F725] - 31/01/2013 - 14:08:10 ---A- . (.Microsoft - Système de notation CSRR.) -- C:\Windows\System32\csrr.rs [43520] O44 - LFC:[MD5.A067A19A91C2AA0198F9BD01A5CEF5C6] - 31/01/2013 - 14:08:09 ---A- . (.Microsoft - Système de classement GRB.) -- C:\Windows\System32\grb.rs [21504] O44 - LFC:[MD5.4F5C56DBF076D5BBB1D22B37BF281396] - 31/01/2013 - 14:08:09 ---A- . (.Microsoft - Système de classement PEGI au Portugal.) -- C:\Windows\System32\pegi-pt.rs [20480] O44 - LFC:[MD5.5109C45498BC709C8A7E016D5FFCCAC2] - 31/01/2013 - 14:08:09 ---A- . (.Microsoft - Système de classement PEGI.) -- C:\Windows\System32\pegi.rs [20480] O44 - LFC:[MD5.9B7D7F4D1F79E8B7D727BE94B1630D59] - 31/01/2013 - 14:08:09 ---A- . (.Microsoft - Système de classement PEGI/BBFC.) -- C:\Windows\System32\pegibbfc.rs [44544] O44 - LFC:[MD5.9EDCFA23CC081E38C86CA309D0F7E3DC] - 31/01/2013 - 14:08:09 ---A- . (.Microsoft - Système de classement USK.) -- C:\Windows\System32\usk.rs [30720] O44 - LFC:[MD5.41CE7975CAD7BCF92538D2C452239523] - 31/01/2013 - 14:08:09 ---A- . (.Microsoft - Système de classification COB-AU.) -- C:\Windows\System32\cob-au.rs [40960] O44 - LFC:[MD5.27828AAA24AA46F11036954ADE355C1C] - 31/01/2013 - 14:08:09 ---A- . (.Microsoft - Système de classification DJCTQ.) -- C:\Windows\System32\djctq.rs [15360] O44 - LFC:[MD5.A704E750245D5D4EE4A23E99A00F27D5] - 31/01/2013 - 14:08:09 ---A- . (.Microsoft - Système de classification FPB.) -- C:\Windows\System32\fpb.rs [46592] O44 - LFC:[MD5.7752619457598CF057C4CC02A0867029] - 31/01/2013 - 14:08:08 ---A- . (.Microsoft - Système de classement CERO.) -- C:\Windows\System32\cero.rs [55296] O44 - LFC:[MD5.DDD1C4AB9A9DAE6D4092C4C95E714650] - 31/01/2013 - 14:08:08 ---A- . (.Microsoft - Système de classement ESRB.) -- C:\Windows\System32\esrb.rs [51712] O44 - LFC:[MD5.CBC69A055EF410CBD65593E4808B6DB4] - 31/01/2013 - 14:08:08 ---A- . (.Microsoft - Système de classement OFLC.) -- C:\Windows\System32\oflc.rs [23552] O44 - LFC:[MD5.72035C97983745E742D71E9A8EF70BBB] - 31/01/2013 - 14:08:08 ---A- . (.Microsoft - Système de classement PEGI en Finlande.) -- C:\Windows\System32\pegi-fi.rs [20480] O44 - LFC:[MD5.07BA000B2E67565BDF112C35171865A5] - 31/01/2013 - 03:26:53 ---A- . (...) -- C:\Windows\System32\perfd00C.dat [38160] O44 - LFC:[MD5.04F6C9757DB75FF27C427E5B31DDB289] - 31/01/2013 - 03:26:53 ---A- . (...) -- C:\Windows\System32\perfi00C.dat [344522] O44 - LFC:[MD5.6FBB766EB79F9EED3684194EEAF838DF] - 31/01/2013 - 03:19:06 ---A- . (...) -- C:\Windows\ChangeLang_Done.tag [11453] O44 - LFC:[MD5.7EDE42530E8D00A69CAD2BC757D6A1D1] - 30/01/2013 - 21:35:39 ---A- . (...) -- C:\Windows\DirectX.log [29586] O44 - LFC:[MD5.2087D5BDCFBED52E55CD6072356E8824] - 30/01/2013 - 19:39:19 ---A- . (...) -- C:\Windows\Patch.log [19267] O44 - LFC:[MD5.46C61F995D7A38A7E26D339233914214] - 30/01/2013 - 19:27:51 ---A- . (...) -- C:\Windows\System32\license.rtf [190563] O44 - LFC:[MD5.6D8DA2930D7AB1C75C233792D5E712E6] - 30/01/2013 - 19:25:19 ---A- . (...) -- C:\Windows\DtcInstall.log [4059] O44 - LFC:[MD5.B88D2B6867AE03882DE5C0AEC5B34442] - 30/01/2013 - 19:04:21 ---A- . (...) -- C:\Windows\System32\results.xml [15056] O44 - LFC:[MD5.0098E1536DB7F4C691623C08D28D80A8] - 30/01/2013 - 19:02:11 ---A- . (...) -- C:\Windows\Driver_install.log [434] O44 - LFC:[MD5.C9135DA1C45AD58808A11B9F0749D6A5] - 30/01/2013 - 18:56:25 ---A- . (.Waves Audio Ltd. - General Library for Plug-Ins.) -- C:\Windows\System32\WavesGUILib.dll [1725784] O44 - LFC:[MD5.CE1E84AA03EE50362D3C69382DCFA294] - 30/01/2013 - 18:56:25 ---A- . (.Waves Audio Ltd. - General Library for Plug-Ins.) -- C:\Windows\System32\WavesLib.dll [1783056] O44 - LFC:[MD5.272BF8E5DBDAF0614CC367A25EA3B256] - 30/01/2013 - 18:56:24 ---A- . (.SRS Labs, Inc. - COM object implementing SRS Headphone 360.) -- C:\Windows\System32\SRSHP360.dll [173296] O44 - LFC:[MD5.029F36DE21AFBDD2865CC657E252EBA7] - 30/01/2013 - 18:56:24 ---A- . (.SRS Labs, Inc. - TruSurround HD and HD4 COM object for Windo.) -- C:\Windows\System32\SRSTSHD.dll [185584] O44 - LFC:[MD5.8C83CED38F8CAC3E8D5A953C03BCF4B4] - 30/01/2013 - 18:56:24 ---A- . (.SRS Labs, Inc. - TruSurroundXT Module.) -- C:\Windows\System32\SRSTSXT.dll [345328] O44 - LFC:[MD5.A258F7B2B84E88118369B0B2196CC257] - 30/01/2013 - 18:56:24 ---A- . (.SRS Labs, Inc. - WOW HD COM object for Windows.) -- C:\Windows\System32\SRSWOW.dll [140528] O44 - LFC:[MD5.732C6ACAC96D60DF38F5B54989E53EBB] - 30/01/2013 - 18:56:24 ---A- . (.Sony Corporation - Sony SFSS APO(32bit).) -- C:\Windows\System32\SFSS_APO.dll [192104] O44 - LFC:[MD5.D9397A5E3929F61FFA83F07285C414C5] - 30/01/2013 - 18:56:24 ---A- . (.Synopsys, Inc. - SFAPO.DLL.) -- C:\Windows\System32\SFAPO.dll [68960] O44 - LFC:[MD5.736B9CBB1AF8324171CFA3787A024588] - 30/01/2013 - 18:56:24 ---A- . (.Synopsys, Inc. - SFCOM.DLL.) -- C:\Windows\System32\SFCOM.dll [74080] O44 - LFC:[MD5.4D7D49A61594B8A643EA8EAF74F2150C] - 30/01/2013 - 18:56:24 ---A- . (.Synopsys, Inc. - SFNHK.DLL.) -- C:\Windows\System32\SFNHK.dll [214368] O44 - LFC:[MD5.8F3710245B1B923D6C0A2C15BB49C84A] - 30/01/2013 - 18:56:24 ---A- . (.TOSHIBA CORPORATION. - Tepeq APO.) -- C:\Windows\System32\TepeqAPO.dll [58264] O44 - LFC:[MD5.47AC41518B5DCD65FCED33A129CDB1C1] - 30/01/2013 - 18:56:24 ---A- . (.TOSHIBA Corporation - TOSHIBA Audio Enhancement APO.) -- C:\Windows\System32\tadefxapo.dll [134584] O44 - LFC:[MD5.A3637A3C6B21D10525EFC9630E4A1F9E] - 30/01/2013 - 18:56:24 ---A- . (.TOSHIBA Corporation - TOSHIBA Audio Enhancement APO.) -- C:\Windows\System32\tadefxapo2.dll [817600] O44 - LFC:[MD5.38136C24E80EA6C7C0A227A2AD433FA7] - 30/01/2013 - 18:56:24 ---A- . (.TOSHIBA Corporation - TOSHIBA Audio Enhancement.) -- C:\Windows\System32\tosade.dll [1379760] O44 - LFC:[MD5.FDD0B0C903B34CD57A36327C0E7C879C] - 30/01/2013 - 18:56:23 ---A- . (.Realtek Semiconductor Corp. - Realtek APO API.) -- C:\Windows\System32\RtkApoApi.dll [617064] O44 - LFC:[MD5.0CF1A36569C7D095F83FCFB79F813CEA] - 30/01/2013 - 18:56:23 ---A- . (.Realtek Semiconductor Corp. - Realtek HD Audio Coinstaller.) -- C:\Windows\System32\RtkCoInstII.dll [83560] O44 - LFC:[MD5.4B540CD34B883C174008F33F249D6773] - 30/01/2013 - 18:56:23 ---A- . (.Realtek Semiconductor Corp. - Realtek HD Audio Coinstaller.) -- C:\Windows\System32\RtkCoLDR.dll [13416] O44 - LFC:[MD5.A32BFF5625B0BD00553917828AB24CF9] - 30/01/2013 - 18:56:23 ---A- . (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\Windows\System32\RTSndMgr.cpl [1497704] O44 - LFC:[MD5.A3DCFBFF3929313CE16C3ECE822267D4] - 30/01/2013 - 18:56:23 ---A- . (.Realtek Semiconductor Corp. - Realtek LFX/GFX DSP UI component for Window.) -- C:\Windows\System32\RtkPgExt.dll [2378856] O44 - LFC:[MD5.303129C4432D58DE0A56CF6F25512956] - 30/01/2013 - 18:56:23 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\Windows\System32\Drivers\RTKVHDA.sys [3932584] O44 - LFC:[MD5.542393A7C1672C6F49F3520A6E4FF00A] - 30/01/2013 - 18:56:23 ---A- . (.Realtek Semiconductor Corp. - Realtek(r) LFX/GFX DSP component.) -- C:\Windows\System32\RtkAPO.dll [3321960] O44 - LFC:[MD5.C45E7C12A5C6CA76AD577A1D8E982283] - 30/01/2013 - 18:56:19 ---A- . (.Dolby Laboratories - Dolby PCEE4 ASL Analog x86.) -- C:\Windows\System32\R4EEA32A.dll [88408] O44 - LFC:[MD5.AD49F27A24E90E1549FA7089F8D4B0E7] - 30/01/2013 - 18:56:19 ---A- . (.Dolby Laboratories - Dolby PCEE4 COM DLL x86.) -- C:\Windows\System32\R4EED32A.dll [345944] O44 - LFC:[MD5.DA070B7D24C1C437487B7EA5977B4C83] - 30/01/2013 - 18:56:19 ---A- . (.Dolby Laboratories - Dolby PCEE4 Control Panel x86.) -- C:\Windows\System32\R4EEP32A.dll [3296600] O44 - LFC:[MD5.01B187108DDCB9A977D9142684FF7551] - 30/01/2013 - 18:56:19 ---A- . (.Dolby Laboratories - Dolby PCEE4 GFX APO x86.) -- C:\Windows\System32\R4EEG32A.dll [61272] O44 - LFC:[MD5.E16A9D9FEF615233F7B5C5274556C05B] - 30/01/2013 - 18:56:19 ---A- . (.Dolby Laboratories - Dolby PCEE4 LFX APO x86.) -- C:\Windows\System32\R4EEL32A.dll [103256] O44 - LFC:[MD5.E232507C219A1957880D4EB6D022FAC7] - 30/01/2013 - 18:56:19 ---A- . (.Dolby Laboratories, Inc. - Dolby PCEE3 COM DLL x86.) -- C:\Windows\System32\RTEED32A.dll [170840] O44 - LFC:[MD5.A6686775084244141483AEA0391508D2] - 30/01/2013 - 18:56:19 ---A- . (.Dolby Laboratories, Inc. - Dolby PCEE3 Control Panel x86.) -- C:\Windows\System32\RTEEP32A.dll [359768] O44 - LFC:[MD5.3DE99987154319C901A6537BA8777CB9] - 30/01/2013 - 18:56:19 ---A- . (.Dolby Laboratories, Inc. - Dolby PCEE3 GFX APO x86.) -- C:\Windows\System32\RTEEG32A.dll [64856] O44 - LFC:[MD5.5B18398DEDE4A4A78651CD34F0A217A5] - 30/01/2013 - 18:56:19 ---A- . (.Dolby Laboratories, Inc. - Dolby PCEE3 LFX APO x86.) -- C:\Windows\System32\RTEEL32A.dll [78680] O44 - LFC:[MD5.C619CDFA5CDC5A346C89870010A2391C] - 30/01/2013 - 18:56:19 ---A- . (.Dolby Laboratories, Inc. - PCEE3 DAA Control Panel x86.) -- C:\Windows\System32\RP3DAA32.dll [295768] O44 - LFC:[MD5.4F92047498EFEA076E3745C291481975] - 30/01/2013 - 18:56:19 ---A- . (.Dolby Laboratories, Inc. - PCEE3 DHT Control Panel x86.) -- C:\Windows\System32\RP3DHT32.dll [295768] O44 - LFC:[MD5.266420D6F41A88A251CFF883E7063BAC] - 30/01/2013 - 18:56:19 ---A- . (.Realtek Semiconductor Corp. - Realtek HD Audio Coinstaller Resource.) -- C:\Windows\System32\RCoRes.dat [2765312] O44 - LFC:[MD5.6C75723CB2309D23A3A16EF9F45B2F49] - 30/01/2013 - 18:56:19 ---A- . (.Waves Audio Ltd. - MaxxVolumeSD APO.) -- C:\Windows\System32\MaxxVolumeSDAPO.dll [252760] O44 - LFC:[MD5.4C8DBAECEFE8238FCD06D704F3F12300] - 30/01/2013 - 18:56:19 ---A- . (.Waves Audio Ltd. - Pas de description.) -- C:\Windows\System32\MaxxAudioEQ.dll [1836376] O44 - LFC:[MD5.6BEA5DF1D50E2B2B9621D90FC063559C] - 30/01/2013 - 18:56:19 ---A- . (.Waves Audio Ltd. - Pas de description.) -- C:\Windows\System32\MaxxAudioRealtek.dll [5522776] O44 - LFC:[MD5.534D8DC4D6068EB27E3B6E2B69250D92] - 30/01/2013 - 18:56:19 ---A- . (.Waves Audio Ltd. - Waves Realtek App.) -- C:\Windows\System32\MaxxAudioRealtek2.dll [1099096] O44 - LFC:[MD5.56056DF5DC4CFCCA657E57E8FF3714B0] - 30/01/2013 - 18:56:18 ---A- . (.Knowles Acoustics - Knowles HD Audio APO.) -- C:\Windows\System32\KAAPORT.dll [357712] O44 - LFC:[MD5.E5F92DD9448FA937E331C4576F048DBD] - 30/01/2013 - 18:56:18 ---A- . (.Waves Audio Ltd. - MaxxAudio APO Shell.) -- C:\Windows\System32\MaxxAudioAPOShell.dll [685400] O44 - LFC:[MD5.84AB243EBB8839C268BA45975BD6558C] - 30/01/2013 - 18:56:18 ---A- . (.Waves Audio Ltd. - MaxxAudio APO.) -- C:\Windows\System32\MaxxAudioAPO.dll [132368] O44 - LFC:[MD5.57C588F098C811E9459AC7034349AF6F] - 30/01/2013 - 18:56:18 ---A- . (.Waves Audio Ltd. - MaxxAudio APO.) -- C:\Windows\System32\MaxxAudioAPO20.dll [232792] O44 - LFC:[MD5.EE03F5DEF3A7EFC3B798122DEBDD1017] - 30/01/2013 - 18:56:18 ---A- . (.Waves Audio Ltd. - MaxxAudio APO.) -- C:\Windows\System32\MaxxAudioAPO30.dll [259928] O44 - LFC:[MD5.6353994C972CB58EB01854C6FDFAC80D] - 30/01/2013 - 18:56:15 ---A- . (.Andrea Electronics Corporation - Render Noise Filters (32-bit).) -- C:\Windows\System32\AERTARen.dll [96160] O44 - LFC:[MD5.4A635AE3CC50F6BF1317957D1FEE975A] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS Bass Enhancement COM DLL.) -- C:\Windows\System32\DTSBassEnhancementDLL.dll [654952] O44 - LFC:[MD5.B447DFE249DAD3577A9CCCC6960A57D2] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS Boost COM DLL.) -- C:\Windows\System32\DTSBoostDLL.dll [1220200] O44 - LFC:[MD5.C77A4CA13CF78E242C5844D045EDFDA0] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS GFX APO.) -- C:\Windows\System32\DTSGFXAPO.dll [218728] O44 - LFC:[MD5.3B7950071A28E861C877BA77742D9577] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS GFX APO.) -- C:\Windows\System32\DTSGFXAPONS.dll [218728] O44 - LFC:[MD5.3781415D2B09DB870C0B9DFEB29A88D9] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS GFX APO.) -- C:\Windows\System32\DTSU2PGFX32.dll [390656] O44 - LFC:[MD5.5A65D120056B4B814E703E100FDE14C6] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS Gain Compensator COM DLL.) -- C:\Windows\System32\DTSGainCompensatorDLL.dll [389736] O44 - LFC:[MD5.5328523AC3FE93F61054823D90DA73A5] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS LFX APO.) -- C:\Windows\System32\DTSLFXAPO.dll [218216] O44 - LFC:[MD5.040BE746CB773CBBDE5A5EF313C1C5EA] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS LFX APO.) -- C:\Windows\System32\DTSU2PLFX32.dll [413696] O44 - LFC:[MD5.2014F956A83FD7CB04CBDDC6BB82D706] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS LFX APO.) -- C:\Windows\System32\DTSU2PREC32.dll [327168] O44 - LFC:[MD5.255A4B9B8008773D0B143E22A21AB4FA] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS Limiter COM DLL.) -- C:\Windows\System32\DTSLimiterDLL.dll [375400] O44 - LFC:[MD5.4CB970E9423433CC834BF54588E0AA5A] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS NEO:PC COM DLL.) -- C:\Windows\System32\DTSNeoPCDLL.dll [458344] O44 - LFC:[MD5.5ADA836A4F9E4C0CF9CC1BFDBAA9D37F] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS Surround Sensation Headphone COM DLL.) -- C:\Windows\System32\DTSS2HeadphoneDLL.dll [1292904] O44 - LFC:[MD5.C1D3FC8F45C3AA7F0F03DA2A0D384524] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS Surround Sensation Speaker COM DLL.) -- C:\Windows\System32\DTSS2SpeakerDLL.dll [1509480] O44 - LFC:[MD5.426246A4B6A7D1A1D12AAB6BB2E483C5] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS Symmetry COM DLL.) -- C:\Windows\System32\DTSSymmetryDLL.dll [631400] O44 - LFC:[MD5.BAF09FCD09873CF0A3ADF4752F6B144B] - 30/01/2013 - 18:56:15 ---A- . (.DTS - DTS Voice Clarity COM DLL.) -- C:\Windows\System32\DTSVoiceClarityDLL.dll [601704] O44 - LFC:[MD5.C4CF3E9D0B4225B1ED2C9E605BBFD432] - 30/01/2013 - 18:56:15 ---A- . (.Fortemedia Corporation - Fortemedia SAMSoft sAPO.) -- C:\Windows\System32\FMAPO.dll [2189888] O44 - LFC:[MD5.2CCEAF03E8AF4543171D236DF21DC29A] - 30/01/2013 - 18:56:14 ---A- . (.Andrea Electronics Corporation - Capture Noise Filters (32-bit).) -- C:\Windows\System32\AERTACap.dll [175200] O44 - LFC:[MD5.2FA617D1B062B8D9F08036E90003B3E2] - 30/01/2013 - 18:56:13 ---A- . (.Realtek Semiconductor Corp. - RtlExUpd DLL for setup utility function.) -- C:\Windows\RtlExUpd.dll [1698408] O44 - LFC:[MD5.7FD1956E221C3750E0532A48E8EDD305] - 30/01/2013 - 18:53:23 ---A- . (.Pas de propriétaire - About Page.) -- C:\Windows\System32\RtNicProp32.dll [80416] O44 - LFC:[MD5.6A2586DCB5B04A52404699EB325DF1DB] - 30/01/2013 - 18:53:23 ---A- . (.Realtek - Realtek 8101E/8168/8169 NDIS 6.20 32-bit Dr.) -- C:\Windows\System32\Drivers\Rt86win7.sys [490088] O44 - LFC:[MD5.65A5BD4A43ED3C029A514E7502CD804F] - 30/01/2013 - 18:53:23 ---A- . (.Realtek Semiconductor Corporation - RTNUninst.) -- C:\Windows\System32\RTNUninst32.dll [100896] O44 - LFC:[MD5.FE842C465E0412D51915FD9414571A10] - 30/01/2013 - 18:53:04 ---A- . (...) -- C:\Windows\DPINST.LOG [4762] O44 - LFC:[MD5.EF3024328398C07DE0BDF35B67ABEC68] - 30/01/2013 - 18:50:10 ---A- . (...) -- C:\Windows\LMv4.UNI [172] O44 - LFC:[MD5.E39DCDE0722F11BA367F75576D5545E0] - 30/01/2013 - 18:49:07 ---A- . (.Realtek Semiconductor Corp. - Realtek Card Reader Icon Dll.) -- C:\Windows\System32\RtsPStorIcon.dll [9888360] O44 - LFC:[MD5.683B328B077D21F06E18C426DBAC0616] - 30/01/2013 - 18:49:07 ---A- . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vi.) -- C:\Windows\System32\Drivers\RtsPStor.sys [254056] O44 - LFC:[MD5.AC7860C1DEB853D6AE7B25D490CCED06] - 30/01/2013 - 18:37:49 ---A- . (...) -- C:\Windows\mSataSettings.log [25] O44 - LFC:[MD5.9E8B0405F4DC32D58279A714FB1E6B3C] - 30/01/2013 - 18:37:09 ---A- . (...) -- C:\Windows\TSSysprep.log [3652] O44 - LFC:[MD5.1153AC6E133AA849853DFD407B086B80] - 30/11/2012 - 00:17:39 ---A- . (...) -- C:\Windows\System32\locale.nls [420064] O44 - LFC:[MD5.933222B19FF3E7EA5F65517EA1F7D57E] - 02/06/2012 - 15:57:50 ---A- . (...) -- C:\Windows\System32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [3] O44 - LFC:[MD5.933222B19FF3E7EA5F65517EA1F7D57E] - 02/06/2012 - 15:34:21 ---A- . (...) -- C:\Windows\System32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf [3] O44 - LFC:[MD5.1C89E483758777425866218A65FE5890] - 10/01/2012 - 14:03:40 ---A- . (...) -- C:\Windows\System32\Drivers\RTAIODAT.DAT [216472] O44 - LFC:[MD5.7FB4981A4B217EEB5D9C4DE291125485] - 09/01/2012 - 07:48:36 ---A- . (...) -- C:\Windows\System32\Drivers\RtPCEE4.DAT [107248] O44 - LFC:[MD5.99E26EFF2A113E052CB973E989835DC3] - 26/09/2011 - 15:41:10 ---A- . (...) -- C:\Windows\System32\Drivers\rtkhdaud.dat [24] O44 - LFC:[MD5.E67AAB6205BD45C9A9644CDAC9CE9664] - 23/09/2010 - 10:21:40 ---A- . (...) -- C:\Windows\System32\Drivers\RtPCEE3.DAT [39672] O44 - LFC:[MD5.DAE054749540938A0889AA40E0D5594A] - 22/03/2010 - 06:21:38 ---A- . (...) -- C:\Windows\System32\Drivers\RtHdatEx.dat [1448] O44 - LFC:[MD5.4E84A165644886CC5333335C289B33D0] - 22/03/2010 - 06:21:36 ---A- . (...) -- C:\Windows\System32\Drivers\RTConvEQ.dat [247560] O44 - LFC:[MD5.C104D162A7AC593908FCE05456300619] - 11/02/2010 - 08:45:00 ---A- . (...) -- C:\Windows\System32\Drivers\RTHDAEQ1.dat [176] O44 - LFC:[MD5.530A9FEB236FF8DD1BC941A7F08E6561] - 26/01/2010 - 14:52:20 ---A- . (...) -- C:\Windows\System32\Drivers\RTEQEX3.dat [520] O44 - LFC:[MD5.2EAE98B466CFE4C9362D004ED469422A] - 10/07/2009 - 02:32:32 ---A- . (...) -- C:\Windows\InfoCtrPackard Bell.ico [411494] O44 - LFC:[MD5.57B8D47F171677E88563A42924D64D3D] - 21/08/2008 - 06:43:36 ---A- . (...) -- C:\Windows\System32\Drivers\RTEQEX2.dat [520] O44 - LFC:[MD5.EBCA7473A23120CAE4066BEB3835D48F] - 26/06/2005 - 22:29:50 ---A- . (...) -- C:\Windows\System32\Drivers\RTEQEX0.dat [520] O44 - LFC:[MD5.FCA6883B690E3722B6A60ADA972A831A] - 26/06/2005 - 22:29:28 ---A- . (...) -- C:\Windows\System32\Drivers\RTEQEX1.dat [520] ~ Scan Files in 00mn 27s ---\\ Déni du service (Local Security Authority) (O48) O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll ~ Scan Keys in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys ~ Scan CSB in 00mn 00s ---\\ MountPoints2 Shell Key (O51) (None) ---\\ Trojan Driver Search Data (HKLM) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm ~ Scan Keys in 00mn 00s ---\\ ShareTools MSconfig StartupReg (O53) (None) ---\\ Microsoft Control Security Providers (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll ~ Scan Keys in 00mn 00s ---\\ Microsoft Windows Policies System (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0 O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ Scan Keys in 00mn 00s ---\\ Liste des Drivers Système (O58) O58 - SDL:[MD5.21E785EBD7DC90A06391141AAC7892FB] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976] O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029] ~ Scan Drivers in 00mn 00s ---\\ Liste des outils de nettoyage (O63) O63 - Logiciel: ZHPDiag 1.3.5 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 ~ Scan ADS in 00mn 00s ---\\ Liste des services Legacy (O64) O64 - Services: CurCS - 16/01/2013 - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\BASHDefs\20130116.013\BHDrvx86.sys (BHDrvx86) .(.Symantec Corporation - BASH Driver.) - LEGACY_BHDRVX86 O64 - Services: CurCS - 07/06/2012 - C:\Windows\system32\drivers\NIS\1309010.00E\ccSetx86.sys (ccSet_NIS) .(.Symantec Corporation - Common Client Settings Driver.) - LEGACY_CCSET_NIS O64 - Services: CurCS - 30/01/2013 - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (eeCtrl) .(.Symantec Corporation - Symantec Eraser Control Driver.) - LEGACY_EECTRL O64 - Services: CurCS - 30/01/2013 - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\IPSDefs\20130208.004\IDSvix86.sys (IDSVix86) .(.Symantec Corporation - IDS Core Driver.) - LEGACY_IDSVIX86 O64 - Services: CurCS - 26/02/2012 - C:\Windows\System32\DRIVERS\igddim32.sys (igddim32) .(.Intel Corporation - Intel (R) WDDM Kernel Mode Driver.) - LEGACY_IGDDIM32 O64 - Services: CurCS - 30/01/2013 - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\VirusDefs\20130208.032\NAVENG.sys (NAVENG) .(.Symantec Corporation - AV Engine.) - LEGACY_NAVENG O64 - Services: CurCS - 30/01/2013 - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\VirusDefs\20130208.032\NAVEX15.sys (NAVEX15) .(.Symantec Corporation - AV Engine.) - LEGACY_NAVEX15 O64 - Services: CurCS - ??\??\???? - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV O64 - Services: CurCS - 06/07/2012 - C:\Windows\system32\Drivers\NIS\1309010.00E\SRTSP.sys (SRTSP) .(.Symantec Corporation - Symantec AutoProtect.) - LEGACY_SRTSP O64 - Services: CurCS - 06/07/2012 - C:\Windows\system32\drivers\NIS\1309010.00E\SRTSPX.sys (SRTSPX) .(.Symantec Corporation - Symantec AutoProtect.) - LEGACY_SRTSPX O64 - Services: CurCS - 15/08/2011 - C:\Windows\System32\drivers\NIS\1309010.00E\SYMDS.sys (SymDS) .(.Symantec Corporation - Symantec Data Store.) - LEGACY_SYMDS O64 - Services: CurCS - 22/05/2012 - C:\Windows\System32\drivers\NIS\1309010.00E\SYMEFA.sys (SymEFA) .(.Symantec Corporation - Symantec Extended File Attributes.) - LEGACY_SYMEFA O64 - Services: CurCS - 13/04/2012 - C:\Windows\system32\Drivers\SYMEVENT.sys (SymEvent) .(.Symantec Corporation - Symantec Event Library.) - LEGACY_SYMEVENT O64 - Services: CurCS - 18/04/2012 - C:\Windows\system32\drivers\NIS\1309010.00E\Ironx86.sys (SymIRON) .(.Symantec Corporation - Iron Driver.) - LEGACY_SYMIRON O64 - Services: CurCS - 18/04/2012 - C:\Windows\system32\Drivers\NIS\1309010.00E\SYMNETS.sys (SymNetS) .(.Symantec Corporation - Network Security Driver.) - LEGACY_SYMNETS ~ Scan Services in 00mn 00s ---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.bat> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe O67 - Shell Spawning: <.cmd> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe O67 - Shell Spawning: <.exe> [HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> [HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.js> [HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> [HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe ~ Scan Keys in 00mn 00s ---\\ Start Menu Internet (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Scan Keys in 00mn 00s ---\\ Search Browser Infection (O69) O69 - SBI: prefs.js [mylene - j3m8pwj1.default] user_pref("extensions.crossrider.bic", "13cbf68994407651e8eb58369605b201"); O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) - http://www.bing.com O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (@ieframe.dll,-12512) - http://www.bing.com ~ Scan Keys in 00mn 00s ---\\ Recherche des services démarrés par Svchost (O83) O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [62464] O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584] O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960] O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408] O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [674304] O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [473600] O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [90624] O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [286208] O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264] O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [49664] O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544] O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176] O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [521216] O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [1933848] O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728] O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192] O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712] O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504] O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [47104] O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688] O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664] O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440] O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304] O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164352] O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592] O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168] O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664] O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960] O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [102912] O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376] O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800] ~ Scan Services in 00mn 00s ---\\ Recherche particuliere à la racine de certains dossiers (O84) [MD5.D41D8CD98F00B204E9800998ECF8427E] [SPRF][07/02/2013] (...) -- C:\Users\mylene\AppData\Local\Temp\.exe [0] [MD5.C36923084822C017F69396418A999D39] [SPRF][07/02/2013] (.Ask.com - AskStub Application.) -- C:\Users\mylene\AppData\Local\Temp\ApnStub.exe [143240] [MD5.B28C334C03CEE7C5E829C43AE75DAE5A] [SPRF][28/01/2013] (.Ask.com - AskIC Dynamic Link Library.) -- C:\Users\mylene\AppData\Local\Temp\AskSLib.dll [248008] [MD5.943716A509A9E7EBB770268B340F23C1] [SPRF][07/02/2013] (.215 Apps - Deals Plugin Extension Installer.) -- C:\Users\mylene\AppData\Local\Temp\DealsPluginROW.exe [3696601] [MD5.07356626437A164BB31285D2303DFEFB] [SPRF][30/01/2013] (.Skype Technologies S.A. - Skype.) -- C:\Users\mylene\AppData\Local\Temp\SkypeSetup.exe [20903528] [MD5.43130128BCB9DF456C398CAFBF4DA613] [SPRF][10/01/2013] (.Skype Technologies S.A. - Skype.) -- C:\Users\mylene\AppData\Local\Temp\SkypeSetupFull(6.1.73.129)(Trackable457)trackable.exe [20541392] [MD5.E76C43097F7AC4ECD4D9D2D50ABA3341] [SPRF][06/02/2013] (.ooVoo LLC - ooVoo Setup.) -- C:\Users\mylene\Desktop\ooVooSetup.exe [1454656] ~ Scan Files in 00mn 02s ---\\ Firewall Active Exception List (FirewallRules) (O87) O87 - FAEL: "{1F977B11-D3BD-4C6D-B8C6-BBE9FBAA2572}" | In - None - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe O87 - FAEL: "TCP Query User{264ABA28-67D0-4C4E-830E-03800F734FEE}C:\program files\oovoo\oovoo.exe" | In - Private - P6 - TRUE | .(.ooVoo LLC - ooVoo.) -- C:\program files\oovoo\oovoo.exe O87 - FAEL: "UDP Query User{DC89C744-5371-4244-A67C-B2A861EB2D2B}C:\program files\oovoo\oovoo.exe" | In - Private - P17 - TRUE | .(.ooVoo LLC - ooVoo.) -- C:\program files\oovoo\oovoo.exe ~ Scan Firewall in 00mn 01s ---\\ Scan Additionnel (O88) Database Version : v2.10565 - (07/02/2013) Clés trouvées (Keys found) : 0 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 0 Fichiers trouvés (Files found) : 0 ~ Scan Additionnel in 00mn 19s ---\\ Product Upgrade Codes (O90) O90 - PUC: "00004159070000000000000000F01FEC" . (.Microsoft Office 2010.) -- C:\Windows\Installer\{95140000-0070-0000-0000-0000000FF1CE}\oobeicon.exe O90 - PUC: "0C69D82C09A6E9540A776A07F6E40CCF" . (.Bing Bar.) -- C:\Windows\Installer\{C28D96C0-6A90-459E-A077-A6706F4EC0FC}\icon_installer_ico O90 - PUC: "1D034B0FAA6BD374B960AAD30DF10D8B" . (.Microsoft SQL Server 2005 Compact Edition [ENU].) -- C:\Windows\Installer\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}\ProductIcon O90 - PUC: "279A5E3D51A9D724EA8718185ADF49C3" . (.eBay Worldwide.) -- c:\Windows\Installer\{D3E5A972-9A15-427D-AE78-8181A5FD943C}\_6FEFF9B68218417F98F549.exe O90 - PUC: "41DC8ECD5FBF46449B4A1EE87453647C" . (.Assistant de connexion Windows Live.) -- C:\Windows\Installer\{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}\prodicon.ico O90 - PUC: "646FE77FBE911E11A9E989B41EF571E4" . (.Evernote v. 4.5.2.) -- C:\Windows\Installer\{F77EF646-19EB-11E1-9A9E-984BE15F174E}\Evernote.ico O90 - PUC: "68AB67CA7DA7FFFFB744AA0000000010" . (.Adobe Reader X (10.1.5) MUI.) -- C:\Windows\Installer\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}\SC_Reader.ico O90 - PUC: "6FD66A043D225B447A3D381B812A0CCD" . (.Norton Online Backup.) -- C:\Windows\Installer\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}\MainIcon.ico O90 - PUC: "907018673D7AD86419761A87C0E167C6" . (.Windows Live FolderShare.) -- C:\Windows\Installer\{76810709-A7D3-468D-9167-A1780C1E766C}\FolderShare48x48.ico O90 - PUC: "96740EE14C1960A4297BCFFA6EABDB9D" . (.Galerie de photos Windows Live.) -- C:\Windows\Installer\{1EE04769-91C4-4A06-92B7-FCAFE6BABDD9}\WLXPhotoGalleryIcon.exe O90 - PUC: "D381B5441F4F8C549BBD1F3155AC56B7" . (.Windows Live Messenger.) -- C:\Windows\Installer\{445B183D-F4F1-45C8-B9DB-F11355CA657B}\MsblIco.Exe O90 - PUC: "D7314F9862C648A4DB8BE2A5B47BE100" . (.Microsoft Silverlight.) -- c:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ARPIcon O90 - PUC: "DDB6C50237B7ED245850A990F3532A83" . (.Outil de téléchargement Windows Live.) -- C:\Windows\Installer\{205C6BDD-7B73-42DE-8505-9A093F35A238}\RichUpload.ico O90 - PUC: "E309FE46A00DC414494ABF3A86FFDC9C" . (.Social Networks.) -- C:\Windows\Installer\{64EF903E-D00A-414C-94A4-FBA368FFCDC9}\ARPPRODUCTICON.exe O90 - PUC: "E7FF67E4ABEA78C47B88DC745E24B5D9" . (.Skype™ 6.1.) -- C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe O90 - PUC: "FF8F7AAF50C316A4F8418D6A9EDE6632" . (.ooVoo.) -- C:\Windows\Installer\{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}\_6FEFF9B68218417F98F549.exe ~ Scan Files in 00mn 00s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Auto 18/12/2012 65192 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe SS - | Demand 08/02/2013 251248 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe SS - | Demand 07/06/2011 191752 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files\Microsoft\BingBar\BBSvc.exe SS - | Auto 12/05/2011 249648 | (BBUpdate) . (.Microsoft Corporation.) - C:\Program Files\Microsoft\BingBar\SeaPort.exe SS - | Auto 01/07/2011 353360 | (DsiWMIService) . (.Dritek System Inc..) - C:\Program Files\Launch Manager\dsiwmis.exe SS - | Auto 07/02/2012 738688 | (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe SS - | Demand 12/10/2010 206072 | (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files\WildTangent Games\App\GamesAppService.exe SS - | Auto 29/02/2012 28264 | (GREGService) . (.Acer Incorporated.) - C:\Program Files\Packard Bell\Registration\GREGsvc.exe SS - | Auto 06/11/2010 13336 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe SS - | Auto 07/03/2011 1755136 | (IconMan_R) . (.Realsil Microelectronics Inc..) - C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe SS - | Auto 07/02/2012 255376 | (Live Updater Service) . (.Acer Incorporated.) - C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe SS - | Demand 06/02/2013 115608 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe SR - | Auto 16/06/2012 138272 | (NIS) . (.Symantec Corporation.) - C:\Program Files\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe SS - | Auto 01/06/2010 2057560 | (NOBU) . (.Symantec Corporation.) - C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe SS - | Auto 08/01/2013 161536 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SS - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Scan Services in 00mn 02s End of the scan (982 lines in 02mn 15s)(0)