Rapport de ZHPDiag v2013.6.13.18 par Nicolas Coolman, Update du 13/06/2013 Run by modesta at 15/06/2013 17:09:23 WebSite: http://nicolascoolman.webs.com State : Version à jour. WhiteList : Enable High Elevated Privileges : OK UAC : Activate by user ---\\ Web Browser MSIE: Internet Explorer v10.0.9200.16618 GCIE: Google Chrome v27.0.1453.110 (Defaut) ---\\ Windows Product Information ~ Langage: Français Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601) Windows Server License Manager Script : OK ~ Windows(R) 7, OEM_SLP channel System Locked Preinstallation (OEM_SLP) : OK Windows ID Activation : OK ~ Windows Partial Key : 3Q6C9 Windows License : OK ~ Windows Remaining Initializations Number : 2 Software Protection Service (Protection logicielle) : OK Windows Automatic Updates : OK Windows Activation Technologies : OK ---\\ System Protection avast! Free Antivirus v8.0.1489.0 Windows Defender W7 ---\\ System Optimizer ---\\ Peer To Peer (P2P) Pando Media Booster v2.6.0.8 ---\\ Software Update Adobe Flash Player 11 Plugin Adobe Reader 9.5.5 MUI Java 7 Update 21 ---\\ System Information ~ Processor: AMD64 Family 16 Model 6 Stepping 2, AuthenticAMD ~ Operating System: 64 Bits Boot mode: Normal (Normal boot) Total RAM: 2812 MB (52% free) System Restore: Activé (Enable) System drive C: has 74 GB (26%) free of 284 GB ---\\ Logged in mode ~ Computer Name: MODESTA-PC ~ User Name: modesta ~ All Users Names: postgres, modesta, HomeGroupUser$, Administrateur, ~ Unselected Option: None Logged in as Administrator ---\\ Environnement Variables ~ System Unit : C:\ ~ %AppData% : C:\Users\modesta\AppData\Roaming\ ~ %Desktop% : C:\Users\modesta\Desktop\ ~ %Favorites% : C:\Users\modesta\Favorites\ ~ %LocalAppData% : C:\Users\modesta\AppData\Local\ ~ %StartMenu% : C:\Users\modesta\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\System32\ ---\\ DOS/Devices C:\ Hard drive, Flash drive, Thumb drive (Free 74 Go of 284 Go) D:\ Hard drive, Flash drive, Thumb drive (Free 2 Go of 13 Go) E:\ Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go) F:\ CD-ROM drive (Not Inserted) H:\ CD-ROM drive (Not Inserted) I:\ CD-ROM drive (Not Inserted) L:\ Floppy drive, Flash card reader, USB Key (Free 2 Go of 4 Go) ---\\ Security Center & Tools Informations [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified ~ Security Center: 37 Legitimates Filtered in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808] [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024] [MD5.12716D987D475B051F35895659159705] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.17/05/2013 - 01:59:03.) -- C:\Windows\System32\wininet.dll [2241024] [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656] [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448] [MD5.1C7857B62DE5994A75B054A9FD4C3825] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/12/2011 - 04:59:24.) -- C:\Windows\system32\Drivers\AFD.sys [498688] [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128] [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160] [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456] [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400] [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368] [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472] [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224] [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208] [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632] [MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680] [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280] [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536] [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184] [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296] [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808] ~ Generic Processes: Scanned in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 2/22 ~ Mes musiques (My Musics) : 2/165 ~ Mes Videos (My Videos) : 2/43 ~ Mes Favoris (My Favorites) : 1/67 ~ Mes Documents (My Documents) : 2/1946 ~ Mon Bureau (My Desktop) : 2/23203 ~ Menu demarrer (Programs) : 1/48 ~ Hidden Files: Scanned in 01mn 04s ---\\ Processus lancés [MD5.349AB4F70E2AC44970894E7F03E1576E] - (.Huawei Technologies Co., Ltd. - DataCardMonitor MFC Application.) -- C:\ProgramData\DatacardService\DCSHelper.exe [236384] [PID.3420] [MD5.D63797E8E7781EE1500A810CB6194FA6] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816] [PID.3940] [MD5.3F11B20D12D89365D7721BDC860CE5F0] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968] [PID.3952] [MD5.2F3390C8E3620B3991D7D82014E26AA7] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [825808] [PID.3404] [MD5.B8DD83B85636F7D6EC0F09B090E49130] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [7494656] [PID.3964] [MD5.28D6701C710AD7BA3CB95E75F8F1A9AA] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808] [PID.1408] [MD5.F401929EE0CC92BFE7F15161CA535383] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55184] [PID.1764] [MD5.ACC93675D78D1C07DAD09D7837F2397A] - (.PostgreSQL Global Development Group - pg_ctl - starts/stops/restarts the PostgreS.) -- C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe [65536] [PID.1080] [MD5.498EB62A160674E793FA40FD65390625] - (.Pas de propriétaire - RichVideo Module.) -- C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152] [PID.1116] [MD5.E5C796B621F6FBA8616511063D7F0FFE] - (.StarWind Software - StarWind iSCSI Target (Alcohol Edition).) -- C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [370688] [PID.1488] [MD5.879F46329B7DC4D109345AA96F1AB47F] - (.TeamViewer GmbH - TeamViewer 8.) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [4150112] [PID.1736] [MD5.D78830C645884DB617C50B264BFFEBA2] - (.PostgreSQL Global Development Group - PostgreSQL Server.) -- C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe [3690496] [PID.1792] [MD5.1BBBF640BC0E0B750537BAECE8D66C18] - (.Nero AG - NeroUpdate.) -- C:\Program Files (x86)\Nero\Update\NASvc.exe [641832] [PID.3508] ~ Processes Running: Scanned in 00mn 01s ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2) C:\Users\modesta\AppData\Local\Google\Chrome\User Data\Default\Preferences ~ Google Browser: 12 Legitimates Filtered in 00mn 16s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\modesta\AppData\Roaming\Mozilla\Firefox\Profiles\et9kzzm3.default\prefs.js C:\Users\modesta\AppData\Roaming\Mozilla\Firefox\Profiles\tkx0l4k9.default\prefs.js (.not file.) C:\Users\modesta\AppData\Roaming\Mozilla\Firefox\Profiles\tkx0l4k9.default\user.js ~ Firefox Browser: 11 Legitimates Filtered in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Proxy management: Scanned in 00mn 00s ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: Shell=C:\Windows\explorer.exe F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe ~ Keys: Scanned in 00mn 00s ---\\ Redirection du fichier Hosts (O1) ~ Le fichier hosts est sain (The hosts file is clean). ~ Hosts File: Scanned in 00mn 00s ~ Nombre de lignes (Lines number): 0 ---\\ Internet Explorer Toolbars (O3) O3 - Toolbar: (no name) [64Bits] - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline ~ Toolbar: Scanned in 00mn 00s ---\\ Applications démarrées par registre & par dossier (O4) O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.) O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray64.exe O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe O4 - HKLM\..\Wow6432Node\Run: [avast] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastUI.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe O4 - HKUS\S-1-5-21-3600749335-942430350-662760979-1003\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe O4 - HKUS\S-1-5-21-3600749335-942430350-662760979-1003\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe ~ Application: Scanned in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - GS\Accessories: Private Character Editor.lnk . (.Microsoft Corporation - Éditeur de caractères privés.) -- C:\Windows\system32\eudcedit.exe O4 - GS\SendTo: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) -- C:\Windows\system32\WFS.exe O4 - GS\Desktop: ASIO4ALL v2 Instruction Manual.lnk . (...) -- C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL v2 Instruction Manual.pdf (.not file.) O4 - GS\Desktop: ASIO4ALL v2 Off-Line Settings.lnk . (...) -- C:\Program Files (x86)\ASIO4ALL v2\a4apanel.exe (.not file.) O4 - GS\Desktop: Audacity.lnk . (...) -- C:\Program Files\MultimediaTools\Audacity\audacity.exe O4 - GS\Desktop: Bandicam.lnk . (.www.Bandisoft.com - Bandisoft - bdcam.exe.) -- C:\Program Files (x86)\Bandicam\bdcam.exe O4 - GS\Desktop: Collab.lnk . (.Image-Line bvba - Collab executable.) -- C:\Program Files (x86)\Image-Line\Collab\Collab.exe O4 - GS\Desktop: Cool Audio Video Converter.lnk . (...) -- C:\Program Files (x86)\Cool Audio Video Converter\Cool Audio Video Converter.exe (.not file.) O4 - GS\Desktop: Crossfire Europe.lnk . (.TODO: - CF_SGI.) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe O4 - GS\Desktop: GameCenter.lnk . (.Cyanide - GameCenter.) -- C:\Program Files (x86)\Cyanide\GameCenter\GameCenter.exe O4 - GS\Desktop: Installation de PMU Poker.lnk . (...) -- C:\Program Files (x86)\Mozilla Firefox\PMUPoker_Installer\SmartInstaller.exe (.not file.) O4 - GS\Desktop: Installeur de World of Warcraft.lnk - Clé orpheline O4 - GS\Desktop: iTuner.lnk . (.Pyxsys - Pas de description.) -- C:\Program Files (x86)\OOBOX\Music\iTuner\XTuner2.exe O4 - GS\Desktop: LimeWire 5.5.10.lnk . (...) -- C:\Program Files (x86)\LimeWire\LimeWire.exe (.not file.) O4 - GS\Desktop: PhotoFiltre.lnk . (.Antonio Da Cruz - PhotoFiltre.) -- C:\Program Files (x86)\PhotoFiltre\photofiltre.exe O4 - GS\Desktop: PMU Poker.lnk . (...) -- C:\Programs\PMU\PMU.exe (.not file.) O4 - GS\Desktop: Super Mp3 Recorder Professional.lnk . (...) -- C:\Program Files (x86)\Admiresoft\Super Mp3 Recorder Professional\smrpro.exe O4 - GS\Desktop: Teamspeak 2 RC2.lnk . (.Dominating Bytes Design - The TeamSpeak 2 client.) -- C:\Program Files (x86)\Teamspeak2_RC2\TeamSpeak.exe O4 - GS\Desktop: TopSpin Demo Launcher.lnk . (...) -- C:\Program Files (x86)\Atari\TopSpin-Demo\Launcher.exe (.not file.) O4 - GS\Desktop: Tunatic.lnk . (.Wildbits - Tunatic 1.0.1b.) -- C:\Program Files (x86)\Tunatic\tunatic.exe O4 - GS\Desktop: Virtual DJ Trial.lnk . (.Atomix Productions - VirtualDJ.) -- C:\Program Files (x86)\VirtualDJ\virtualdj_trial.exe O4 - GS\TaskBar: Explorateur Windows.lnk . (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\explorer.exe O4 - GS\TaskBar: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O4 - GS\TaskBar: Reason.lnk . (.Propellerhead Software AB - Reason program file.) -- C:\Program Files (x86)\Propellerhead\Reason\Reason.exe O4 - GS\Programs: Free mp3 Wma Converter.lnk . (.Koyote Soft - Free Audio Converter.) -- C:\Program Files (x86)\Free mp3 Wma Converter\FreeConverter\FreeConverter.exe O4 - GS\Programs: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\QuickLaunch: Easy Audio Cutter.lnk . (.Koyote Soft - Pas de description.) -- C:\Program Files (x86)\Free mp3 Wma Converter\Easy Audio Cutter\AudioCutter.exe O4 - GS\QuickLaunch: Free CD Ripper.lnk . (.Koyote Soft - FreeCDRipper.) -- C:\Program Files (x86)\Free mp3 Wma Converter\Free CD Ripper\FreeCDRipper.exe O4 - GS\QuickLaunch: Free Mp3 Wma Converter.lnk . (.Koyote Soft - Free Audio Converter.) -- C:\Program Files (x86)\Free mp3 Wma Converter\FreeConverter\FreeConverter.exe O4 - GS\QuickLaunch: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O4 - GS\QuickLaunch: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\QuickLaunch: PokerStars.fr.lnk . (.PokerStars - PokerStars Update.) -- C:\Program Files (x86)\PokerStars.FR\PokerStarsUpdate.exe O4 - GS\QuickLaunch: Xilisoft Video to Audio Converter.lnk . (...) -- C:\Program Files (x86)\Xilisoft\Video to Audio Converter\vcloader.exe O4 - GS\Accessories: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe O4 - GS\SendTo: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe O4 - GS\SendTo: Xfire Ami(e).lnk . (...) -- C:\Program Files (x86)\Xfire\Xfire.exe (.not file.) O4 - GS\Desktop: ALBUMS - Raccourci.lnk . (...) -- C:\Users\modesta\Desktop\HIPHOPISDREAM\ALBUMS O4 - Global Startup: C:\Users\modesta\Desktop\clubic pc.url . (...) -- C:\Users\modesta\Desktop\clubic pc.url O4 - GS\Desktop: CMD.lnk . (...) -- C:\Users\modesta\Desktop\Mes Documents\CMD.txt O4 - Global Startup: C:\Users\modesta\Desktop\FACEBOOK.url . (...) -- C:\Users\modesta\Desktop\FACEBOOK.url O4 - GS\Desktop: Free Mp3 Wma Converter.lnk . (.Koyote Soft - Free Audio Converter.) -- C:\Program Files (x86)\Free mp3 Wma Converter\FreeConverter\FreeConverter.exe O4 - GS\Desktop: Reason.lnk . (.Propellerhead Software AB - Reason program file.) -- C:\Program Files (x86)\Propellerhead\Reason\Reason.exe O4 - GS\Desktop: ReCycle.lnk . (.Propellerhead Software AB - ReCycle Program File.) -- C:\Program Files (x86)\Propellerhead\ReCycle\ReCycle.exe O4 - Global Startup: C:\Users\modesta\Desktop\UC.url . (...) -- C:\Users\modesta\Desktop\UC.url O4 - GS\Desktop: VirtualDJ Home FREE.lnk . (.Atomix Productions - VirtualDJ.) -- C:\Program Files (x86)\VirtualDJ\virtualdj_home.exe ~ Global Startup: Scanned in 00mn 02s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: Free YouTube Download [64Bits] - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} . (...) -- C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\dvdvideosoft.ico ~ IE Extra Buttons: Scanned in 00mn 00s ---\\ Modification Domaine/Adresses DNS (O17) O17 - HKLM\System\CCS\Services\Tcpip\..\{75728A8F-5917-406F-A6DB-FA5BD6410464}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{B86F66EB-44E0-4145-8B54-36BA2F4839B6}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{E582CE4B-ABFA-4A20-8251-A614A5B4AD1C}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{75728A8F-5917-406F-A6DB-FA5BD6410464}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{B86F66EB-44E0-4145-8B54-36BA2F4839B6}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{E582CE4B-ABFA-4A20-8251-A614A5B4AD1C}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{75728A8F-5917-406F-A6DB-FA5BD6410464}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{B86F66EB-44E0-4145-8B54-36BA2F4839B6}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{E582CE4B-ABFA-4A20-8251-A614A5B4AD1C}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 ~ Domain: Scanned in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) -- O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll ~ Protocole Additionnel: Scanned in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) . (.PostgreSQL Global Development Group - pg_ctl - starts/stops/restarts the PostgreS.) - C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe O23 - Service: TeamViewer 8 (TeamViewer8) . (.TeamViewer GmbH - TeamViewer 8.) - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe ~ Services: 15 Legitimates Filtered in 00mn 09s ---\\ Tâches planifiées en automatique (O39) [MD5.00000000000000000000000000000000] [APT] [Programme de mise … jour en ligne de Sun Microsystems] (...) -- C:\Program Files\Java\jre6\bin\jusched.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{0167CEC1-7073-4F51-83C0-F19F6E417C2F}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{07C9D1E0-167A-42BD-8AEE-6C84482DAED8}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{08ACE16C-0362-433E-A0E4-C7837DFB8B2E}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0] [MD5.00000000000000000000000000000000] [APT] [{0A832D6B-998F-4836-B8F3-8C954FF6CB57}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0] [MD5.B186735BDC45649FD172D18E3F6B7DB9] [APT] [{16F4C069-B88C-47F7-BFFC-5ECBFF8D837A}] (...) -- C:\Program Files (x86)\Propellerhead\ReCycle\unins000.exe [691481] [MD5.EB906EDD7889FBE6829EFEDBEC53A3DC] [APT] [{3F59FBF4-5E7E-40FC-9363-090CA4C292F5}] (...) -- C:\Program Files (x86)\PENDULO Studios\RUNAWAY 2 - The dream of the turtle\runaway2.exe [2543616] [MD5.00000000000000000000000000000000] [APT] [{3FBD547C-8DDE-4618-8119-FDBAF2872833}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0] [MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{40578DFC-2D38-40B7-8527-65AEB3C8CF61}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752] [MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{49F28A68-CD56-4F9F-BBE7-D3828E2E0D1D}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752] [MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{53D25BB6-B56B-4D8C-8CBA-2201A82FF13F}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752] [MD5.00000000000000000000000000000000] [APT] [{54BF14C3-36AF-4BEE-90CA-7BA896DE2EA1}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0] [MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{8B2A43B6-9213-4FD0-999A-BED41845A40E}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752] [MD5.00000000000000000000000000000000] [APT] [{AA21DD51-728E-473B-8D80-1990991281F9}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0] [MD5.EB906EDD7889FBE6829EFEDBEC53A3DC] [APT] [{B4E14F8B-ABEC-46AD-8B3F-0C351B0F9965}] (...) -- C:\Program Files (x86)\PENDULO Studios\RUNAWAY 2 - The dream of the turtle\runaway2.exe [2543616] [MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{BA2F7725-49AC-49A7-91F7-EC4DD8978CC3}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752] [MD5.EB906EDD7889FBE6829EFEDBEC53A3DC] [APT] [{BCD169D0-5B76-4238-A278-9D103A124947}] (...) -- C:\Program Files (x86)\PENDULO Studios\RUNAWAY 2 - The dream of the turtle\runaway2.exe [2543616] [MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{BE044ABC-14E7-4E96-ABF4-341E0BECD7BB}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752] [MD5.00000000000000000000000000000000] [APT] [{C1E6C74A-E4A1-4842-9EB2-4B7E15BE9572}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0] [MD5.EB906EDD7889FBE6829EFEDBEC53A3DC] [APT] [{C351A5CC-89AB-433B-8378-0D6C39776CC4}] (...) -- C:\Program Files (x86)\PENDULO Studios\RUNAWAY 2 - The dream of the turtle\runaway2.exe [2543616] [MD5.EB906EDD7889FBE6829EFEDBEC53A3DC] [APT] [{C5F77096-F998-4DE1-9256-615A44D40874}] (...) -- C:\Program Files (x86)\PENDULO Studios\RUNAWAY 2 - The dream of the turtle\runaway2.exe [2543616] [MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{D1853B27-F8B0-4D07-BDBB-2D76A44378EC}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752] [MD5.00000000000000000000000000000000] [APT] [{E19C652B-E3E7-4B1E-A874-D2C7112A4337}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0] [MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{E7B95E11-326D-4119-BDC6-0A234EE2EB24}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752] [MD5.00000000000000000000000000000000] [APT] [{FCFCD9F7-18D0-4D88-B613-DC2635F375C2}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0] [MD5.EB906EDD7889FBE6829EFEDBEC53A3DC] [APT] [{FD3054B5-5079-451D-AECB-2A2478BEE9EE}] (...) -- C:\Program Files (x86)\PENDULO Studios\RUNAWAY 2 - The dream of the turtle\runaway2.exe [2543616] ~ Scheduled Task: 48 Legitimates Filtered in 00mn 05s ---\\ Pilotes lancés au démarrage (O41) O41 - Driver: (appdrv01) . (.Protection Technology - Application Driver (01).) - C:\Windows\System32\Drivers\appdrv01.sys ~ Drivers: 69 Legitimates Filtered in 00mn 00s ---\\ Logiciels installés (O42) O42 - Logiciel: Audiggle version 3.0.0.1 - (.Audiggle LTD.) [HKLM][64Bits] -- {FCAD9ED0-C00F-45FA-91DB-F89140EFAB3A}_is1 O42 - Logiciel: Lexicon Alpha Driver - (.Lexicon.) [HKLM][64Bits] -- Lexicon Alpha Driver O42 - Logiciel: Lexicon Pantheon VST Plug-in (remove only) - (...) [HKLM][64Bits] -- LexiconStudio O42 - Logiciel: PokerStars.fr - (.PokerStars.fr.) [HKLM][64Bits] -- PokerStars.fr ~ Logic: 152 Legitimates Filtered in 00mn 01s ---\\ HKCU & HKLM Software Keys [HKCU\Software\Audiggle LTD] [HKCU\Software\CFLoader] [HKCU\Software\Guy] [HKCU\Software\Lexicon] [HKCU\Software\Nohope92] [HKCU\Software\PMU] [HKCU\Software\PartoucheFR] [HKCU\Software\PatchPoker] [HKCU\Software\Prodipe] [HKLM\Software\Wow6432Node\Guy] [HKLM\Software\Wow6432Node\Prodipe] ~ Key Software: 335 Legitimates Filtered in 00mn 01s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 25/05/2013 - 13:06:06 - [0] ----D C:\Program Files (x86)\Ascentive O43 - CFD: 01/12/2011 - 08:58:30 - [2,554] ----D C:\Program Files (x86)\Audiggle O43 - CFD: 06/07/2012 - 17:28:11 - [2,214] ----D C:\Program Files (x86)\Lexicon O43 - CFD: 06/06/2012 - 17:43:25 - [0,000] ----D C:\Program Files (x86)\LimeWire O43 - CFD: 02/07/2010 - 13:06:55 - [6,205] ----D C:\Program Files (x86)\OOBOX O43 - CFD: 25/06/2010 - 02:23:10 - [0] ----D C:\Program Files (x86)\poker O43 - CFD: 21/12/2012 - 20:51:15 - [144,504] ----D C:\Program Files (x86)\PokerStars.FR O43 - CFD: 17/11/2010 - 21:05:02 - [2,590] ----D C:\Program Files (x86)\PokerTracker 3 O43 - CFD: 09/07/2010 - 22:29:42 - [1,031] ----D C:\Program Files (x86)\Shareaza O43 - CFD: 11/05/2013 - 15:27:47 - [1,277] ----D C:\Program Files (x86)\SoulseekQt =>P2P.SoulSeek O43 - CFD: 23/03/2012 - 22:24:09 - [38,653] ----D C:\ProgramData\Ascentive O43 - CFD: 03/09/2010 - 12:42:27 - [0,053] ----D C:\ProgramData\WSG32 O43 - CFD: 25/10/2010 - 03:14:24 - [0,001] ----D C:\Users\modesta\AppData\Roaming\fr.barrierepoker.air.D043989C8F5E91300BF71855036B28F854BB8613.1 O43 - CFD: 01/12/2011 - 09:26:18 - [0] ----D C:\Users\modesta\AppData\Roaming\MusicBrainz O43 - CFD: 12/09/2010 - 14:55:24 - [9,333] ----D C:\Users\modesta\AppData\Roaming\Partouche Poker O43 - CFD: 12/09/2010 - 14:55:55 - [0] ----D C:\Users\modesta\AppData\Roaming\PokerAcademyPro2 O43 - CFD: 09/07/2010 - 22:28:38 - [0,014] ----D C:\Users\modesta\AppData\Roaming\Shareaza O43 - CFD: 01/12/2011 - 09:00:28 - [0,001] ----D C:\Users\modesta\AppData\Local\Audiggle_LTD O43 - CFD: 15/05/2013 - 00:44:44 - [0,001] ----D C:\Users\modesta\AppData\Local\DarkOS O43 - CFD: 08/04/2013 - 19:53:00 - [0,001] ----D C:\Users\modesta\AppData\Local\GNHacks O43 - CFD: 16/02/2013 - 18:33:12 - [0,006] ----D C:\Users\modesta\AppData\Local\Injector O43 - CFD: 30/04/2013 - 03:47:06 - [0,001] ----D C:\Users\modesta\AppData\Local\kokicrossfireinjector O43 - CFD: 09/03/2013 - 21:29:33 - [0,001] ----D C:\Users\modesta\AppData\Local\MetreInjector O43 - CFD: 04/06/2013 - 13:09:12 - [3,972] ----D C:\Users\modesta\AppData\Local\PokerStars.FR O43 - CFD: 08/07/2010 - 23:59:45 - [0,029] ----D C:\Users\modesta\AppData\Local\Shareaza O43 - CFD: 29/01/2012 - 21:15:36 - [0,001] ----D C:\Users\modesta\AppData\Local\Team_CP9_Injector_V1 O43 - CFD: 06/07/2012 - 17:28:11 - [0,001] ----D C:\Users\modesta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lexicon ~ Program Folder: 326 Legitimates Filtered in 02mn 12s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.F390146AE3A191CF2C6F7E06F7A79D6A] - 12/06/2013 - 21:48:33 ---A- . (...) -- C:\Windows\DeleteOnReboot.bat [98] O44 - LFC:[MD5.2BD357F2A8CBB722F19091DA27DB0B34] - 12/06/2013 - 13:59:45 ---A- . (...) -- C:\Windows\RUNAWAY2.INI [59] ~ Files: 141 Legitimates Filtered in 00mn 53s ---\\ Derniers fichiers créés dans Windows Prefetcher (O45) O45 - LFCP:[MD5.E00A6CB3BFDB47BB4F8C078722CC8A59] - 14/06/2013 - 14:41:04 ---A- - C:\Windows\Prefetch\REASON.EXE-66F26968.pf O45 - LFCP:[MD5.6B8636818A9C7E0FF07A284719098723] - 14/06/2013 - 14:41:11 ---A- - C:\Windows\Prefetch\QREGDEFRAG_SETUP-2.9.TMP-2472B975.pf O45 - LFCP:[MD5.3C8D00317FA689B2DEB9440F02357116] - 14/06/2013 - 14:41:16 ---A- - C:\Windows\Prefetch\QREGDEFRAG_SETUP-2.9.EXE-169A3ADB.pf O45 - LFCP:[MD5.393A6DF13AA8B70BFB11768831B0282A] - 14/06/2013 - 14:41:17 ---A- - C:\Windows\Prefetch\QREGDEFRAG_SETUP-2.9.TMP-824471D4.pf O45 - LFCP:[MD5.BA1748758C75393D0F077C16712A3793] - 14/06/2013 - 14:53:40 ---A- - C:\Windows\Prefetch\LUA5.1A_GUI.EXE-E6CC1E22.pf O45 - LFCP:[MD5.983D430C3FC29B0D5E2C8A851EED8388] - 14/06/2013 - 15:01:36 ---A- - C:\Windows\Prefetch\ULTRADEFRAG-6.0.2.BIN.AMD64.E-3352AEF7.pf O45 - LFCP:[MD5.6DD367F5DAEA557C483E4FA17DBB8344] - 14/06/2013 - 17:40:12 ---A- - C:\Windows\Prefetch\LAUNCH.EXE-53D1A784.pf O45 - LFCP:[MD5.BEFAE4C8AD9B88C989BE2AB62D92D647] - 14/06/2013 - 17:40:41 ---A- - C:\Windows\Prefetch\NZUFB8OF.EXE-F22C2CA3.pf O45 - LFCP:[MD5.7E6F3974C3E66A59C7D2FB7F26945FAD] - 14/06/2013 - 17:40:42 ---A- - C:\Windows\Prefetch\6BTJ385C.EXE-A504AA46.pf O45 - LFCP:[MD5.0E39B3F65C4D0F4B5DA7FA80598A63A8] - 14/06/2013 - 17:40:43 ---A- - C:\Windows\Prefetch\7L8SA9VX.EXE-1CA8E7B7.pf O45 - LFCP:[MD5.4DD31C7C6394B21035C0E0B3D15C9587] - 14/06/2013 - 20:04:21 ---A- - C:\Windows\Prefetch\WAMOBCTR64.EXE-3B37523A.pf O45 - LFCP:[MD5.6857E489CBF8F1DB2993AF05021262B3] - 14/06/2013 - 20:28:23 ---A- - C:\Windows\Prefetch\_IU14D2N.TMP-AFA910DB.pf O45 - LFCP:[MD5.966A91346285063B01BC839279494426] - 14/06/2013 - 21:23:18 ---A- - C:\Windows\Prefetch\AMD_CATALYST_13.6_BETA2.EXE-FBAD70DF.pf O45 - LFCP:[MD5.39390FD90BF107C8EC489B2C7F2614D8] - 14/06/2013 - 23:26:07 ---A- - C:\Windows\Prefetch\GBTRAY.EXE-9E7D26AC.pf O45 - LFCP:[MD5.4CEDAC632A00143F521673A304AAE4AF] - 14/06/2013 - 23:42:39 ---A- - C:\Windows\Prefetch\BOOST.EXE-927029AA.pf O45 - LFCP:[MD5.037AEABF16FAF1928953C1A638B1568C] - 15/06/2013 - 01:09:18 ---A- - C:\Windows\Prefetch\CF_SGIN.EXE-A6C9DC7C.pf O45 - LFCP:[MD5.6854B38BF1A221380EFD997E4C7428AB] - 15/06/2013 - 01:09:25 ---A- - C:\Windows\Prefetch\PATCHER_CF.EXE-2E8B1AFA.pf O45 - LFCP:[MD5.8007F1918A04380D8A1D9D5616446CC4] - 15/06/2013 - 01:09:29 ---A- - C:\Windows\Prefetch\CF_SGI.EXE-413EE366.pf O45 - LFCP:[MD5.CBCC4A29529454D7DCDC8E0B1DC51426] - 15/06/2013 - 01:09:58 ---A- - C:\Windows\Prefetch\HGWC.EXE-E846B28C.pf O45 - LFCP:[MD5.5D6625C1B44932244021D724C50EBCB5] - 15/06/2013 - 01:10:11 ---A- - C:\Windows\Prefetch\CROSSFIRE.EXE-1734A2D7.pf O45 - LFCP:[MD5.1557725CECB29693875CAD2DEF90CA9E] - 15/06/2013 - 01:10:14 ---A- - C:\Windows\Prefetch\XTRAP.XT-D0CB15BB.pf ~ Prefetcher: 142 Legitimates Filtered in 00mn 01s ---\\ MountPoints2 Shell Key (O51) O51 - MPSK:{6f727110-a885-11e0-bed1-c80aa92458ab}\AutoRun\command. (...) -- G:\setup.exe (.not file.) ~ Keys: Scanned in 00mn 00s ---\\ ShareTools MSconfig StartupReg (O53) O53 - SMSR:HKLM\...\startupreg\Pando Media Booster [Key] . (.Pas de propriétaire - Pando Media Booster.) -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ~ SMSR Keys: 23 Legitimates Filtered in 00mn 00s ---\\ Microsoft Windows Policies System (O55) O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 ~ MWPS: 19 Legitimates Filtered in 00mn 00s ---\\ Microsoft Windows Policies Explorer (O56) O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1 ~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s ---\\ Liste des Drivers Système (O58) O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088] O58 - SDL:[MD5.ACEA6D0C2BFC5DA45FA570668E904C29] - 07/05/2004 - 14:31:46 ---A- . (.Service & Quality Technology. - Universal Serial Bus Camera Driver.) -- C:\Windows\SysWOW64\drivers\Camd905c.sys [24382] O58 - SDL:[MD5.67F389181B6B5B3910381657754124B4] - 06/07/2012 - 16:18:18 ---A- . (...) -- C:\Windows\SysWOW64\audcon.sys [2892] ~ Drivers: Scanned in 00mn 00s ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61) O61 - LFC: 12/06/2013 - 11:52:03 ---A- C:\Users\modesta\Downloads\13-1-legacy_vista_win7_win8_64_dd_ccc.exe [154092488] O61 - LFC: 12/06/2013 - 12:42:49 ---A- C:\Users\modesta\AppData\Local\Resmon.ResmonCfg [7630] O61 - LFC: 12/06/2013 - 13:19:44 ---A- C:\Users\modesta\Downloads\installer_directx_French.exe [2458560] O61 - LFC: 12/06/2013 - 14:48:36 ---A- C:\Users\modesta\Downloads\adwcleaner.exe [648201] O61 - LFC: 12/06/2013 - 21:44:50 ---A- C:\Users\modesta\Downloads\AdwCleaner (1).exe [648201] O61 - LFC: 12/06/2013 - 22:19:56 ---A- C:\Users\modesta\Documents\Cross Fire\Replay\CFReplay20130612_0000kid.cfr [4664166] O61 - LFC: 13/06/2013 - 00:40:18 ---A- C:\Users\modesta\Downloads\bdcamsetup.exe [7062616] O61 - LFC: 13/06/2013 - 11:45:17 -SHA- C:\Users\modesta\Documents\Bandicam\Thumbs.db [10752] O61 - LFC: 13/06/2013 - 12:28:24 ---A- C:\Users\modesta\Downloads\avast_free_antivirus_setup.exe [117478104] O61 - LFC: 13/06/2013 - 12:47:21 ---A- C:\Users\modesta\Downloads\jre-6u45-windows-x64.exe [17355184] O61 - LFC: 13/06/2013 - 12:56:06 ---A- C:\Users\modesta\Downloads\vlc-2.0.7-win32.exe [22937227] O61 - LFC: 13/06/2013 - 15:51:51 ---A- C:\Users\modesta\AppData\Roaming\wklnhst.dat [1080] O61 - LFC: 13/06/2013 - 20:03:43 ---A- C:\Users\modesta\Downloads\WindowsUpdateDiagnostic.diagcab [173620] O61 - LFC: 13/06/2013 - 21:48:37 ---A- C:\Users\modesta\AppData\Local\GDIPFONTCACHEV1.DAT [99400] O61 - LFC: 13/06/2013 - 21:53:33 ---A- C:\Users\modesta\Downloads\Crossfire_downloader.exe [2999088] O61 - LFC: 13/06/2013 - 21:53:46 ---A- C:\Users\modesta\AppData\Local\PMB Files\cert\secmod.db [16384] =>P2P.Pando O61 - LFC: 13/06/2013 - 22:07:05 ---A- C:\Users\modesta\Downloads\RogueKiller.exe [907776] O61 - LFC: 13/06/2013 - 22:12:26 ---A- C:\Users\modesta\AppData\Local\PMB Files\pando.save [918] =>P2P.Pando O61 - LFC: 13/06/2013 - 22:12:41 ---A- C:\Users\modesta\AppData\Local\PMB Files\cert\cert8.db [65536] =>P2P.Pando O61 - LFC: 13/06/2013 - 22:12:41 ---A- C:\Users\modesta\AppData\Local\PMB Files\cert\key3.db [16384] =>P2P.Pando O61 - LFC: 14/06/2013 - 14:36:04 ---A- C:\Users\modesta\Downloads\RegSeeker-2.5.zip [9714] O61 - LFC: 14/06/2013 - 14:40:08 ---A- C:\Users\modesta\Downloads\qregdefrag_setup-2.9.exe [1837290] O61 - LFC: 14/06/2013 - 14:50:01 ---A- C:\Users\modesta\Downloads\ultradefrag-6.0.2.bin.amd64.exe [692869] O61 - LFC: 14/06/2013 - 15:01:18 ---A- C:\Users\modesta\AppData\Roaming\Propellerhead Software\Reason\Reason Preferences.prf [8888] O61 - LFC: 14/06/2013 - 17:39:40 ---A- C:\Users\modesta\Downloads\launch.exe [121999832] O61 - LFC: 14/06/2013 - 20:36:36 ---A- C:\Users\modesta\Downloads\AMD_Catalyst_13.5_CAP1.05212013.exe [1684592] O61 - LFC: 14/06/2013 - 21:12:46 ---A- C:\Users\modesta\Downloads\AMD_Catalyst_13.6_Beta2.exe [187682976] O61 - LFC: 14/06/2013 - 22:28:07 R--A- C:\Users\modesta\AppData\Roaming\Microsoft\Installer\{63059735-CA97-FDFB-0E7A-3B8D81572EFD}\ARPPRODUCTICON.exe [88102] O61 - LFC: 15/06/2013 - 01:11:07 ---A- C:\Users\modesta\Documents\Cross Fire\SaveIdData.dat [27] O61 - LFC: 15/06/2013 - 01:35:16 ---A- C:\Users\modesta\Documents\Cross Fire\System.dat [94] O61 - LFC: 15/06/2013 - 10:24:11 ---A- C:\Users\modesta\AppData\Local\Google\Chrome\User Data\Certificate Revocation Lists [270879] O61 - LFC: 15/06/2013 - 16:14:41 ---A- C:\Users\modesta\AppData\Local\Google\Chrome\User Data\Local State [35152] ~ 36 Fichiers temporaires (Temporary files) ~ Files: 324 Legitimates Filtered in 01mn 39s ---\\ Liste des outils de nettoyage (O63) O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 ~ ADS: Scanned in 00mn 00s ---\\ Liste des services Legacy (O64) O64 - Services: CurCS - 01/11/2010 - C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys (WinRing0_1_2_0) .(.OpenLibSys.org - WinRing0.) - LEGACY_WINRING0_1_2_0 O64 - Services: CurCS - ??\??\???? - Pas de propriétaire (XFDriver64) .(...) - LEGACY_XFDRIVER64 ~ Legacy: 142 Legitimates Filtered in 00mn 01s ---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.) ~ FASS Keys: 18 Legitimates Filtered in 00mn 00s ---\\ Start Menu Internet (O68) O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Keys: Scanned in 00mn 00s ---\\ Search Browser Infection (O69) O69 - SBI: SearchScopes [HKCU] {3CAFC3C0-DFF5-4E7D-92EC-7CAF0A57EBA6} - (Yahoo! Search) - http://fr.search.yahoo.com O69 - SBI: SearchScopes [HKCU] {D6311C12-96AD-4063-B4B1-6C5C53A19E3B} - (Bing) - http://www.bing.com ~ Keys: Scanned in 00mn 00s ---\\ Crack & Keygen Files (O82) C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\IMG1_WaveLab.jpg C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\IMG2_WaveLab.jpg C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\Readme!.txt C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Extra\Wavpack Plugin\ReadMe.txt C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Extra\Wavpack Plugin\Wavpack4Wlab6 Setup.msi C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Deutsch\WaveLab.chm C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Deutsch\WaveLab.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Deutsch\WaveLab_61_Addendum.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\English\WaveLab.chm C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\English\WaveLab.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\English\WaveLab_61_Addendum.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\French\WaveLab.chm C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\French\WaveLab.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\French\WaveLab_61_Addendum.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\HelpMap.txt C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Japanese\WaveLab.chm C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Japanese\WaveLab.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Japanese\WaveLab_61_Addendum_JP.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\ReadMe.htm C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Setup.exe C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\wl6emu.exe C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install notes!.txt C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Setup.exe C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH].rar C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\IMG1_WaveLab.jpg C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\IMG2_WaveLab.jpg C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\Readme!.txt C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Extra\Wavpack Plugin\ReadMe.txt C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Extra\Wavpack Plugin\Wavpack4Wlab6 Setup.msi C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Deutsch\WaveLab.chm C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Deutsch\WaveLab.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Deutsch\WaveLab_61_Addendum.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\English\WaveLab.chm C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\English\WaveLab.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\English\WaveLab_61_Addendum.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\French\WaveLab.chm C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\French\WaveLab.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\French\WaveLab_61_Addendum.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\HelpMap.txt C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Japanese\WaveLab.chm C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Japanese\WaveLab.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Japanese\WaveLab_61_Addendum_JP.pdf C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\ReadMe.htm C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Setup.exe C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\wl6emu.exe C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install notes!.txt C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Setup.exe C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH].rar ~ Files: Scanned in 03mn 16s ---\\ Recherche particuliere à la racine de certains dossiers (O84) [MD5.B9270BA1B0D210F786D2E001A7BB902B] [SPRF][13/06/2013] (.Eclipse Foundation - SWT for Windows native library.) -- C:\Users\modesta\AppData\Local\Temp\swt-win32-3740.dll [430080] [MD5.A1D10793082FF32A7A9C99CA6572B05A] [SPRF][13/06/2013] (...) -- C:\Users\modesta\AppData\Roaming\wklnhst.dat [1080] [MD5.0FB88FDF9E624A35B3DF191FC1DD38AC] [SPRF][14/06/2013] (...) -- C:\Users\modesta\Desktop\drweb.exe [121999832] [MD5.49CA27A490977A69E1D562AF4E7FDE95] [SPRF][13/06/2013] (...) -- C:\Users\modesta\Desktop\RogueKiller.exe [907776] [MD5.19EF6FE92855D6CC84CDD628D44B2EC5] [SPRF][14/06/2013] (.Nicolas Coolman - ZHPDiag.) -- C:\Users\modesta\Desktop\ZHPDiag2.exe [5678428] ~ Files: Scanned in 00mn 02s ---\\ Firewall Active Exception List (FirewallRules) (O87) O87 - FAEL: "{6CAE1305-C374-4091-91EA-987ADDC7C70A}" | In - Public - P6 - TRUE | .(.Neowiz Games - Crossfire Patcher.) -- C:\SG Interactive\Crossfire Europe\patcher_cf.exe O87 - FAEL: "{BFB9AFC2-738D-4FE7-AF24-032B79C18FB6}" | In - Public - P17 - TRUE | .(.Neowiz Games - Crossfire Patcher.) -- C:\SG Interactive\Crossfire Europe\patcher_cf.exe O87 - FAEL: "{8457D48B-4061-4D04-8E8A-3345098AAD17}" | In - Domain - P6 - FALSE | .(.Neowiz Games - Crossfire Patcher.) -- C:\SG Interactive\Crossfire Europe\patcher_cf.exe O87 - FAEL: "{1FD19848-CE04-44DA-B2DC-AB67A6425847}" | In - Domain - P17 - FALSE | .(.Neowiz Games - Crossfire Patcher.) -- C:\SG Interactive\Crossfire Europe\patcher_cf.exe ~ Firewall: 224 Legitimates Filtered in 00mn 01s ---\\ Scan Additionnel (O88) Database Version : v2.12472 - (13/06/2013) Clés trouvées (Keys found) : 0 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 0 Fichiers trouvés (Files found) : 0 ~ Additionnel Scan: 432540 Items scanned in 01mn 03s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SR - | Auto 02/03/2009 89600 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe SR - | Auto 05/08/2009 203264 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe SS - | Auto 29/06/2010 551896 | (appdrvrem01) . (.Protection Technology.) - C:\Windows\System32\appdrvrem01.exe SR - | Auto 24/05/2012 55184 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe SR - | Auto 09/05/2013 46808 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe SS - | Demand 05/05/2009 228408 | (Com4QLBEx) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe SR - | Auto 14/07/2009 27136 | C:\Windows\System32\ezsvc7.dll (ezSharedSvc) . (.EasyBits Sofware AS.) - C:\Windows\System32\svchost.exe SS - | Auto 04/06/2013 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SS - | Demand 04/06/2013 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe SR - | Auto 27/09/2012 86528 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe SS - | Demand 10/08/2012 1001376 | (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe SR - | Auto 346976 | (HWDeviceService64.exe) . (...) - C:\ProgramData\DatacardService\HWDeviceService64.exe SS - | Demand 04/04/2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe SR - | Auto 23/09/2011 641832 | (NAUpdate) . (.Nero AG.) - C:\Program Files (x86)\Nero\Update\NASvc.exe SS - | Demand ??\??\???? 0 | (npggsvc) . (.INCA Internet Co., Ltd..) - C:\Windows\system32\GameMon.des SR - | Auto 10/12/2009 65536 | (pgsql-8.3) . (.PostgreSQL Global Development Group.) - C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe SR - | Auto 247152 | (RichVideo) . (...) - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe SS - | Auto 08/01/2013 161536 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe SR - | Auto 22/07/2009 240128 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe SR - | Auto 23/12/2009 370688 | (StarWindServiceAE) . (.StarWind Software.) - C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe SR - | Auto 07/06/2013 4150112 | (TeamViewer8) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe SR - | Auto 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe SR - | Auto 14/07/2009 27136 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe ~ Services: Scanned in 00mn 02s ---\\ Recherche Master Boot Record Infection (MBR)(O80) Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net Run by modesta at 15/06/2013 17:20:59 device: opened successfully user: error reading MBR Disk trace: error: Read Descripteur non valide kernel: error reading MBR ~ MBR: 9 Legitimates Filtered in 00mn 02s ---\\ Recherche Master Boot Record Infection (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by modesta at 15/06/2013 17:21:01 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ MBR: Scanned in 00mn 04s ~ 2124 Legitimates filtered by white list End of the scan (653 lines in 11mn 37s)(48)