cjoint

Publicité

Priorité au Logiciel Libre! Je soutiens l'April.

Publicité

Priorité au Logiciel Libre! Je soutiens l'April.

Format du document : text/plain

Prévisualisation

Rapport de ZHPDiag v1.34.76 par Nicolas Coolman, Update du 01/02/2013
Run by st�phanie at 02/02/2013 15:51:01
State : Version � jour.
UAC : Deactivate by program


---\\ Web Browser
MSIE: Internet Explorer v8.0.7601.17514 (Defaut)

---\\ Windows Product Information
~ Langage: Fran�ais
Windows 7 Starter Edition, 32-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
Software Protection Service (Protection logicielle) : KO
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ System Information
~ Processor: x86 Family 6 Model 28 Stepping 10, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Sans �chec avec prise en charge du r�seau (Fail-safe with network boot)
Total RAM: 2037 MB (71% free)
System Restore: Activ� (Enable)
System drive C: has 264 GB (92%) free of 285 GB

---\\ Logged in mode
~ Computer Name: ST�PHANIE-PC
~ User Name: st�phanie
~ All Users Names: st�phanie, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\
~ %Desktop% : C:\Users\st�phanie.st�phanie-PC\Desktop\
~ %Favorites% : C:\Users\st�phanie.st�phanie-PC\Favorites\
~ %LocalAppData% : C:\Users\st�phanie.st�phanie-PC\AppData\Local\
~ %StartMenu% : C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 264 Go of 285 Go)



---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Scan Security Center in 00mn 00s



---\\ Recherche particuli�re de fichiers g�n�riques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de d�marrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.44214C94911C7CFB1D52CB64D5E8368D] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.20/11/2010 - 22:29:12.) -- C:\Windows\System32\wininet.dll [980992]
[MD5.6D13E1406F50C66E2A95D97F22C47560] - (.Microsoft Corporation - Application d�ouverture de session Windows.) (.20/11/2010 - 22:29:06.) -- C:\Windows\System32\Winlogon.exe [286720]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Biblioth�que de licences.) (.20/11/2010 - 22:29:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.9EBBBA55060F786F0FCAA3893BFA2806] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.25/04/2011 - 03:18:03.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 22:29:07.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 22:29:08.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.81189C3D7763838E55C397759D49007A] - (.Microsoft Corporation - Pilote du syst�me de fichiers NT.) (.11/03/2011 - 06:39:00.) -- C:\Windows\system32\Drivers\ntfs.sys [1211264]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parall�le.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.B459575348C20E8121D6039DA063C704] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 22:29:07.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de clich� instantan� du volume.) (.20/11/2010 - 22:29:03.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Scan Generic Processes in 00mn 00s



---\\ Etat des fichiers cach�s (Cach�/Total)
~ Mes Videos (My Videos) : 1/2
~ Mes Favoris (My Favorites) : 1/50
~ Mes Documents (My Documents) : 1/4
~ Mon Bureau (My Desktop) : 1/6
~ Menu demarrer (Programs) : 1/44
~ Scan Hidden Files in 00mn 00s



---\\ Processus lanc�s
[MD5.C613E69C3B191BB02C7A191741A1D024] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [673040] [PID.2036]
[MD5.72CB29B523061FF64B3F66B8F3A5E034] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [5648896] [PID.1844]
~ Scan Processes Running in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.50401.0.) -- c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3508.1109] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.107\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.107\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@WildTangent.com/GamesAppPresenceDetector,Version=1.0] - (...) -- C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
~ Scan Firefox Browser in 00mn 00s



---\\ Internet Explorer, D�marrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (8.00.7600.16385 (win7_rtm.090713-1255)) -- C:\Windows\System32\ieframe.dll
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ Scan IE Browser in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Scan Keys in 00mn 00s



---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Scan Hosts File in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} . (.Symantec Corporation - coIEPlugIn.) -- C:\Program Files\Norton Internet Security\Engine\19.9.0.9\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} . (.Symantec Corporation - IPS Browser Helper DLL.) -- C:\Program Files\Norton Internet Security\Engine\19.9.0.9\IPS\IPSBHO.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft� Windows Live ID Login Helper.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} . (...) -- "C:\Program Files\Microsoft\BingBar\BingExt.dll" (.not file.)
~ Scan BHO in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Norton Toolbar - [HKLM]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} . (.Symantec Corporation - coIEPlugIn.) -- C:\Program Files\Norton Internet Security\Engine\19.9.0.9\coIEPlg.dll
O3 - Toolbar: Bing Bar - [HKLM]{8dcb7100-df86-4384-8842-8fa844297b3f} . (.Microsoft Corporation. - Extensions du client Bing.) -- C:\Program Files\Microsoft\BingBar\BingExt.dll
O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
~ Scan Toolbar in 00mn 00s



---\\ Applications d�marr�es par registre & par dossier (O4)
O4 - HKLM\..\Run: [Norton Online Backup] . (.Symantec Corporation - Norton Online Backup Service.) -- C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [OOTag] . (.Microsoft - OOTag.) -- C:\Program Files\eMachines\OOBEOffer\OOTag.exe
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [LManager] . (.Dritek System Inc. - Launch Manager.) -- C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AutosetFrequency] . (.Pas de propri�taire - AutosetFrequency.) -- C:\Windows\AutosetFrequency.exe
O4 - HKLM\..\Run: [Power Management] . (.Acer Incorporated - ePowerTray.) -- C:\Program Files\eMachines\eMachines Power Management\ePowerTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
~ Scan Application in 00mn 00s



---\\ Invisibilit� de l'ic�ne d'options IE dans le panneau de Configuration (O5)
O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
~ Scan IE Control Panel in 00mn 00s



---\\ Boutons situ�s sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBro
~ Scan IE Extra Buttons in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d�affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d�espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d�espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft� Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll
O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corp. - Microsoft� Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll
~ Scan Winsock in 00mn 00s



---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://oas.support.microsoft.com/ActiveX/MSDcode.cab
~ Scan Objets ActiveX in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{153ADEBD-6FC8-418F-B07C-AEAB67346F63}: DhcpNameServer = 109.88.203.3 62.197.111.140
O17 - HKLM\System\CCS\Services\Tcpip\..\{28DC8B5E-4A5A-42B8-AABA-1263BA50DD4B}: DhcpNameServer = 192.168.1.250
O17 - HKLM\System\CCS\Services\Tcpip\..\{28DC8B5E-4A5A-42B8-AABA-1263BA50DD4B}: DhcpDomain = PXE.ACER.COM
O17 - HKLM\System\CS1\Services\Tcpip\..\{153ADEBD-6FC8-418F-B07C-AEAB67346F63}: DhcpNameServer = 109.88.203.3 62.197.111.140
O17 - HKLM\System\CS1\Services\Tcpip\..\{28DC8B5E-4A5A-42B8-AABA-1263BA50DD4B}: DhcpNameServer = 192.168.1.250
O17 - HKLM\System\CS1\Services\Tcpip\..\{28DC8B5E-4A5A-42B8-AABA-1263BA50DD4B}: DhcpDomain = PXE.ACER.COM
O17 - HKLM\System\CS2\Services\Tcpip\..\{153ADEBD-6FC8-418F-B07C-AEAB67346F63}: DhcpNameServer = 109.88.203.3 62.197.111.140
O17 - HKLM\System\CS2\Services\Tcpip\..\{28DC8B5E-4A5A-42B8-AABA-1263BA50DD4B}: DhcpNameServer = 192.168.1.250
O17 - HKLM\System\CS2\Services\Tcpip\..\{28DC8B5E-4A5A-42B8-AABA-1263BA50DD4B}: DhcpDomain = PXE.ACER.COM
~ Scan Domain in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contr�le ActiveX pour le flux vid�o.) -- C:\Windows\System32\msvidctl.dll
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft� InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\system32\inetcomm.dll
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft� InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contr�le ActiveX pour le flux vid�o.) -- C:\Windows\System32\msvidctl.dll
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll
~ Scan Protocole Additionnel in 00mn 00s



---\\ Valeur de Registre AppInit_DLLs et sous-cl�s Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Scan Winlogon in 00mn 00s



---\\ Cl� de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
~ Scan SSODL in 00mn 00s



---\\ Liste des services NT non Microsoft et non d�sactiv�s (O23)
O23 - Service: Dritek WMI Service (DsiWMIService) . (.Dritek System Inc. - Dritek WMI Service.) - C:\Program Files\Launch Manager\dsiwmis.exe
O23 - Service: Acer ePower Service (ePowerSvc) . (.Acer Incorporated - ePowerSvc.) - C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe
O23 - Service: GREGService (GREGService) . (.Acer Incorporated - Global Registration Service.) - C:\Program Files\eMachines\Registration\GREGsvc.exe
O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Live Updater Service (Live Updater Service) . (.Acer Incorporated - Updater Service.) - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
O23 - Service: Norton Internet Security (NIS) . (.Symantec Corporation - Symantec Service Framework.) - C:\Program Files\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe
O23 - Service: Norton Online Backup (NOBU) . (.Symantec Corporation - Norton Online Backup Service.) - C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: Software Updater (SrvUpdater) . (.Pas de propri�taire - Updater.) - C:\Program Files\SoftwareUpdater\UpdaterService.exe
~ Scan Services in 00mn 06s



---\\ Enum�ration Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Scan Desktop Component in 00mn 00s



---\\ BootExecute (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ Scan Keys in 00mn 00s



---\\ T�ches planifi�es en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
~ Scan Scheduled Task in 00mn 00s



---\\ Composants install�s (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll
O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitaire d�initialisation d�Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: Browser Customizations - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - Personnalisation d�IEAK.) -- C:\Windows\System32\iedkcs32.dll
O40 - ASIC: Microsoft Windows Media Player 12.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
O40 - ASIC: Internet Explorer - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - Interpr�teur de commandes Windows.) -- C:\Windows\system32\cmd.exe
O40 - ASIC: Microsoft Windows - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files\Windows Mail\WinMail.exe
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll
O40 - ASIC: Windows Desktop Update - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O40 - ASIC: Web Platform Customizations - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d�initialisation d�Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
~ Scan Active Setup in 00mn 00s



---\\ Pilotes lanc�s au d�marrage (O41)
O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (BHDrvx86) . (.Symantec Corporation - BASH Driver.) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20130116.013\BHDrvx86.sys
O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\system32\drivers\blbdrive.sys
O41 - Driver: (ccSet_NIS) . (.Symantec Corporation - Common Client Settings Driver.) - C:\Windows\system32\drivers\NIS\1309000.009\ccSetx86.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
O41 - Driver: (eeCtrl) . (.Symantec Corporation - Symantec Eraser Control Driver.) - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
O41 - Driver: (IDSVix86) . (.Symantec Corporation - IDS Core Driver.) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20130201.001\IDSvix86.sys
O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-syst�me de mise en m�moire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
O41 - Driver: (SRTSPX) . (.Symantec Corporation - Symantec AutoProtect.) - C:\Windows\system32\drivers\NIS\1309000.009\SRTSPX.sys
O41 - Driver: (SymIRON) . (.Symantec Corporation - Iron Driver.) - C:\Windows\system32\drivers\NIS\1309000.009\Ironx86.sys
O41 - Driver: (SymNetS) . (.Symantec Corporation - Network Security Driver.) - C:\Windows\system32\Drivers\NIS\1309000.009\SYMNETS.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\drivers\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
~ Scan Drivers in 00mn 00s



---\\ Logiciels install�s (O42)
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Reader X MUI - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-FFFF-7B44-AA0000000001}
O42 - Logiciel: Agatha Christie - Death on the Nile - (.WildTangent.) [HKLM] -- WTA-925c7736-1e17-452e-8e6a-68b08c2ab05e
O42 - Logiciel: Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver - (.Atheros Communications Inc..) [HKLM] -- {3108C217-BE83-42E4-AE9E-A56A2A92E549}
O42 - Logiciel: Bejeweled 2 Deluxe - (.WildTangent.) [HKLM] -- WTA-d9ec04e5-2fff-48ee-be48-f82bfc5d176a
O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM] -- {C28D96C0-6A90-459E-A077-A6706F4EC0FC}
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: Chuzzle Deluxe - (.WildTangent.) [HKLM] -- WTA-03d733e7-32c2-445b-8696-686ca0bb41c0
O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
O42 - Logiciel: ENE USB Card Reader Driver - (.ENE.) [HKLM] -- 3B29FD3CCF1F5B855DA0C521597413EBABE97DFB
O42 - Logiciel: FATE - (.WildTangent.) [HKLM] -- WTA-8d06cc61-a80a-4fce-b85e-aa6651382d99
O42 - Logiciel: Final Drive: Nitro - (.WildTangent.) [HKLM] -- WTA-235b2e77-c9e3-4a19-b9b6-e3474efdbcd9
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F}
O42 - Logiciel: Identity Card - (.Acer Incorporated.) [HKLM] -- Identity Card
O42 - Logiciel: Insaniquarium Deluxe - (.WildTangent.) [HKLM] -- WTA-d2c8058e-73f4-48bf-85ff-1ca3c377ce65
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- HDMI
O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM] -- {3E29EE6C-963A-4aae-86C1-DC237C4A49FC}
O42 - Logiciel: Jewel Match 3 - (.WildTangent.) [HKLM] -- WTA-52df1be1-22dc-4b38-bb2b-25bdd13259bf
O42 - Logiciel: Jewel Quest Solitaire - (.WildTangent.) [HKLM] -- WTA-b55b5f87-9df8-4bc9-8f48-8ed78f3c5933
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
O42 - Logiciel: Launch Manager - (.eMachines.) [HKLM] -- LManager
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Norton Internet Security - (.Symantec Corporation.) [HKLM] -- NIS
O42 - Logiciel: Norton Online Backup - (.Symantec Corporation.) [HKLM] -- {40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}
O42 - Logiciel: Penguins! - (.WildTangent.) [HKLM] -- WTA-c35f3a5e-614a-4784-914a-6f4846204ea1
O42 - Logiciel: Plants vs. Zombies - Game of the Year - (.WildTangent.) [HKLM] -- WTA-9adef830-0d82-4638-9eeb-96b6d9bb6782
O42 - Logiciel: Polar Bowler - (.WildTangent.) [HKLM] -- WTA-92bfff70-1faf-42dc-9520-153b584510d3
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: Skip-Bo - Castaway Caper - (.WildTangent.) [HKLM] -- WTA-6b9a8033-86ca-427f-80cc-e4207f85038d
O42 - Logiciel: Skype� 5.3 - (.Skype Technologies S.A..) [HKLM] -- {5335DADB-34BA-4AE8-A519-648D78498846}
O42 - Logiciel: Slingo Deluxe - (.WildTangent.) [HKLM] -- WTA-50d17a46-c6df-4d1f-b2ac-921178c25f7a
O42 - Logiciel: SoftwareUpdater - (.Pas de propri�taire.) [HKLM] -- SoftwareUpdater
O42 - Logiciel: Sweetpacks Bundle Uninstaller - (.SweetPacks LTD.) [HKLM] -- Sweetpacks Bundle Uninstaller
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey
O42 - Logiciel: Torchlight - (.WildTangent.) [HKLM] -- WTA-192b1ee3-4ef3-4ff2-8998-ee9412954832
O42 - Logiciel: Tradewinds Legends - (.WildTangent.) [HKLM] -- WTA-e6b52a4b-6bb6-45be-943b-ffe535563780
O42 - Logiciel: Update Installer for WildTangent Games App - (.WildTangent.) [HKLM] -- {2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App
O42 - Logiciel: Video Web Camera Ver:1.0.55.221 - (.Chicony Electronics Co.,Ltd..) [HKLM] -- {17C50809-F2E0-4DD8-84D7-55FF74615723}
O42 - Logiciel: Virtual Villagers 4 - The Tree of Life - (.WildTangent.) [HKLM] -- WTA-15b567d0-1ca4-4762-a6d0-59b88c6eca33
O42 - Logiciel: Wedding Dash - (.WildTangent.) [HKLM] -- WTA-bfebe051-ced1-48b8-9dce-484109bab0cb
O42 - Logiciel: Welcome Center - (.Acer Incorporated.) [HKLM] -- eMachines Welcome Center
O42 - Logiciel: WildTangent Games App (eMachines Games) - (.WildTangent.) [HKLM] -- {70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-emachines
O42 - Logiciel: Zuma Deluxe - (.WildTangent.) [HKLM] -- WTA-d6f56b12-6f3e-43b3-9c3a-7c3394d27813
O42 - Logiciel: eMachines Games - (.WildTangent.) [HKLM] -- WildTangent emachines Master Uninstall
O42 - Logiciel: eMachines Power Management - (.Acer Incorporated.) [HKLM] -- {3DB0448D-AD82-4923-B305-D001E521A964}
O42 - Logiciel: eMachines Recovery Management - (.Acer Incorporated.) [HKLM] -- {7F811A54-5A09-4579-90E1-C93498E230D9}
O42 - Logiciel: eMachines Registration - (.Acer Incorporated.) [HKLM] -- eMachines Registration
O42 - Logiciel: eMachines ScreenSaver - (.Acer Incorporated.) [HKLM] -- eMachines Screensaver
O42 - Logiciel: eMachines Updater - (.Acer Incorporated.) [HKLM] -- {EE171732-BEB4-4576-887D-CB62727F01CA}

---\\ HKCU & HKLM Software Keys
[HKCU\Software\Acer]
[HKCU\Software\AppDataLow\Software\Microsoft]
[HKCU\Software\AppDataLow\Software]
[HKCU\Software\AppDataLow]
[HKCU\Software\Classes]
[HKCU\Software\Dritek]
[HKCU\Software\Google]
[HKCU\Software\Intel]
[HKCU\Software\Licenses]
[HKCU\Software\Local AppWizard-Generated Applications]
[HKCU\Software\Macromedia]
[HKCU\Software\OEM]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\Realtek]
[HKCU\Software\Softonic]
[HKCU\Software\SweetIM]
[HKCU\Software\Symantec]
[HKCU\Software\Synaptics]
[HKCU\Software\ZebHelpProcess Helper]
[HKLM\Software\ATI Technologies]
[HKLM\Software\Acer Incorporated]
[HKLM\Software\Acer]
[HKLM\Software\Adobe]
[HKLM\Software\Atheros Communications Inc.]
[HKLM\Software\CBSTEST]
[HKLM\Software\Chicony Electronics Co.,Ltd.]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Cyberlink]
[HKLM\Software\DTS]
[HKLM\Software\Dolby]
[HKLM\Software\Dritek]
[HKLM\Software\Google]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\Macromedia]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Norton]
[HKLM\Software\ODBC]
[HKLM\Software\OEM]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Realtek]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\SRS Labs]
[HKLM\Software\Skype]
[HKLM\Software\SonicFocus]
[HKLM\Software\Symantec]
[HKLM\Software\Synaptics]
[HKLM\Software\Systweak]
[HKLM\Software\Vittalia]
[HKLM\Software\WOW6432Node]
[HKLM\Software\Waves Audio]
[HKLM\Software\WildTangent]
~ Scan Softwares in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 19/07/2011 - 16:41:36 - [448,464] ----D C:\Program Files\Adobe
O43 - CFD: 02/02/2013 - 14:49:01 - [4,750] ----D C:\Program Files\CCleaner
O43 - CFD: 19/07/2011 - 16:44:17 - [90,469] ----D C:\Program Files\Common Files
O43 - CFD: 19/07/2011 - 16:11:36 - [0,759] ----D C:\Program Files\DIFX
O43 - CFD: 30/01/2013 - 01:39:30 - [3,997] ----D C:\Program Files\DVD Maker
O43 - CFD: 30/01/2013 - 18:25:47 - [87,250] ----D C:\Program Files\eMachines
O43 - CFD: 19/07/2011 - 16:17:51 - [429,271] ----D C:\Program Files\eMachines Games
O43 - CFD: 29/01/2013 - 17:48:17 - [0] R---D C:\Program Files\Fichiers communs
O43 - CFD: 02/02/2013 - 14:48:58 - [14,979] ----D C:\Program Files\Google
O43 - CFD: 30/01/2013 - 10:49:37 - [28,485] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 19/07/2011 - 16:03:03 - [3,587] ----D C:\Program Files\Intel
O43 - CFD: 30/01/2013 - 20:11:34 - [4,403] ----D C:\Program Files\Internet Explorer
O43 - CFD: 29/01/2013 - 17:22:31 - [7,058] ----D C:\Program Files\Launch Manager
O43 - CFD: 30/01/2013 - 10:16:21 - [19,951] ----D C:\Program Files\Microsoft
O43 - CFD: 14/07/2009 - 05:52:30 - [44,521] ----D C:\Program Files\Microsoft Games
O43 - CFD: 30/01/2013 - 10:47:01 - [6,126] ----D C:\Program Files\Microsoft Office
O43 - CFD: 30/01/2013 - 16:26:36 - [0,157] ----D C:\Program Files\Microsoft Security Client
O43 - CFD: 19/07/2011 - 16:18:25 - [36,499] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 19/07/2011 - 16:31:14 - [1,745] ----D C:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 14/07/2009 - 05:52:30 - [0,025] ----D C:\Program Files\MSBuild
O43 - CFD: 19/07/2011 - 16:43:29 - [219,496] ----D C:\Program Files\Norton Internet Security
O43 - CFD: 19/07/2011 - 16:43:16 - [42,648] ----D C:\Program Files\NortonInstaller
O43 - CFD: 29/01/2013 - 16:48:34 - [24,361] ----D C:\Program Files\Realtek
O43 - CFD: 14/07/2009 - 05:52:30 - [37,345] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 19/07/2011 - 16:18:13 - [14,446] R---D C:\Program Files\Skype
O43 - CFD: 02/02/2013 - 14:47:48 - [0,456] ----D C:\Program Files\SoftwareUpdater
O43 - CFD: 02/02/2013 - 14:47:37 - [0,358] ----D C:\Program Files\sweetpacks bundle uninstaller
O43 - CFD: 30/01/2013 - 12:08:44 - [4,981] ----D C:\Program Files\Symantec
O43 - CFD: 19/07/2011 - 16:44:22 - [0,727] ----D C:\Program Files\SymSilent
O43 - CFD: 29/01/2013 - 17:29:38 - [28,545] ----D C:\Program Files\Synaptics
O43 - CFD: 29/01/2013 - 16:48:43 - [0] --H-D C:\Program Files\Temp
O43 - CFD: 14/07/2009 - 05:53:23 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 29/01/2013 - 17:30:35 - [1,343] ----D C:\Program Files\Video Web Camera
O43 - CFD: 19/07/2011 - 16:13:40 - [9,211] ----D C:\Program Files\WildTangent Games
O43 - CFD: 30/01/2013 - 01:39:30 - [2,909] ----D C:\Program Files\Windows Defender
O43 - CFD: 19/07/2011 - 16:22:43 - [461,915] ----D C:\Program Files\Windows Live
O43 - CFD: 30/01/2013 - 01:39:31 - [5,895] ----D C:\Program Files\Windows Mail
O43 - CFD: 30/01/2013 - 01:39:30 - [6,298] ----D C:\Program Files\Windows Media Player
O43 - CFD: 29/01/2013 - 17:48:17 - [11,632] ----D C:\Program Files\Windows NT
O43 - CFD: 30/01/2013 - 01:39:30 - [4,213] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 20/11/2010 - 22:33:48 - [0,181] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 30/01/2013 - 01:39:31 - [6,314] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 02/02/2013 - 15:51:03 - [11,883] ----D C:\Program Files\ZHPDiag
O43 - CFD: 19/07/2011 - 16:42:09 - [17,968] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 19/07/2011 - 16:05:41 - [1,943] ----D C:\Program Files\Common Files\InstallShield
O43 - CFD: 19/07/2011 - 16:21:22 - [20,704] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 14/07/2009 - 03:37:05 - [0,003] ----D C:\Program Files\Common Files\Services
O43 - CFD: 14/07/2009 - 03:37:05 - [39,200] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 30/01/2013 - 10:45:24 - [0,880] ----D C:\Program Files\Common Files\Symantec Shared
O43 - CFD: 30/01/2013 - 01:39:30 - [9,771] ----D C:\Program Files\Common Files\System
O43 - CFD: 19/07/2011 - 16:20:48 - [0] ----D C:\Program Files\Common Files\Windows Live
O43 - CFD: 19/07/2011 - 16:41:55 - [0,000] ----D C:\ProgramData\Adobe
O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Application Data
O43 - CFD: 02/02/2013 - 13:37:00 - [0] ----D C:\ProgramData\boost_interprocess
O43 - CFD: 29/01/2013 - 17:48:17 - [0] --H-D C:\ProgramData\Bureau
O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Documents
O43 - CFD: 19/07/2011 - 16:19:58 - [0,050] ----D C:\ProgramData\eMachines
O43 - CFD: 29/01/2013 - 17:48:17 - [0] --H-D C:\ProgramData\Favoris
O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Favorites
O43 - CFD: 02/02/2013 - 14:48:59 - [0,012] ----D C:\ProgramData\Google
O43 - CFD: 29/01/2013 - 17:48:17 - [0] --H-D C:\ProgramData\Menu D�marrer
O43 - CFD: 02/02/2013 - 14:13:40 - [1352,906] -S--D C:\ProgramData\Microsoft
O43 - CFD: 29/01/2013 - 17:48:17 - [0] --H-D C:\ProgramData\Mod�les
O43 - CFD: 29/01/2013 - 18:57:21 - [268,393] ----D C:\ProgramData\Norton
O43 - CFD: 19/07/2011 - 16:43:16 - [113,453] ----D C:\ProgramData\NortonInstaller
O43 - CFD: 30/01/2013 - 10:49:45 - [0,000] ----D C:\ProgramData\oem
O43 - CFD: 19/07/2011 - 16:18:12 - [19,371] ----D C:\ProgramData\Skype
O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Start Menu
O43 - CFD: 19/07/2011 - 16:41:17 - [0,023] ----D C:\ProgramData\Symantec
O43 - CFD: 14/07/2009 - 05:53:55 - [0] --H-D C:\ProgramData\Templates
O43 - CFD: 19/07/2011 - 16:17:51 - [897,083] ----D C:\ProgramData\WildTangent
O43 - CFD: 30/01/2013 - 13:32:56 - [0] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Adobe
O43 - CFD: 30/01/2013 - 10:15:06 - [0] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Identities
O43 - CFD: 30/01/2013 - 13:33:00 - [0,001] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Macromedia
O43 - CFD: 30/01/2013 - 16:12:21 - [1,342] -S--D C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Microsoft
O43 - CFD: 02/02/2013 - 14:52:02 - [0] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Systweak
O43 - CFD: 29/01/2013 - 19:54:46 - [0] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Local\Application Data
O43 - CFD: 02/02/2013 - 14:49:58 - [0] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Local\CrashDumps
O43 - CFD: 02/02/2013 - 15:04:09 - [0,239] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Local\ElevatedDiagnostics
O43 - CFD: 02/02/2013 - 14:48:56 - [0] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Local\Google
O43 - CFD: 29/01/2013 - 19:54:46 - [0] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Local\Historique
O43 - CFD: 30/01/2013 - 16:15:11 - [42,860] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Local\Microsoft
O43 - CFD: 02/02/2013 - 15:45:10 - [78,416] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp
O43 - CFD: 29/01/2013 - 19:54:46 - [0] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temporary Internet Files
O43 - CFD: 29/01/2013 - 19:58:08 - [0] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Local\VirtualStore
O43 - CFD: 30/01/2013 - 12:50:18 - [0] ----D C:\Users\st�phanie.st�phanie-PC\AppData\Local\{CEF42EA3-0557-47E3-97AD-9057132D3B5F}
O43 - CFD: 14/07/2009 - 05:42:04 - [0,014] R---D C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 30/01/2013 - 10:15:19 - [0,000] R---D C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 14/07/2009 - 05:37:42 - [0,001] R---D C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 30/01/2013 - 10:15:19 - [0,000] R---D C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
~ Scan Program Folder in 00mn 02s



---\\ Derniers fichiers modifi�s ou cr�es sous Windows et System32 (O44)
O44 - LFC:[MD5.17BCC903A6ED037F7812B17B6351393A] - 02/02/2013 - 15:06:44 ---A- . (...) -- C:\Windows\ntbtlog.txt [171874]
O44 - LFC:[MD5.657BDAAFC7E2311C419F2DA483F07F8F] - 02/02/2013 - 15:06:38 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.AC849B99E032F4017BB1CE37934DD4AF] - 02/02/2013 - 15:05:18 ---A- . (...) -- C:\Windows\setupact.log [112]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 02/02/2013 - 14:53:47 ---A- . (...) -- C:\Windows\setuperr.log [0]
O44 - LFC:[MD5.D218281712B82D3A413AC86D5A6F52D6] - 02/02/2013 - 14:53:32 ---A- . (...) -- C:\Windows\PFRO.log [362]
O44 - LFC:[MD5.A2E885F1F607921A1C87FB169200CCD4] - 02/02/2013 - 14:27:35 ---A- . (...) -- C:\Windows\System32\ASOROSet.bin [1728]
O44 - LFC:[MD5.18B3AFB51D16BD28F6B2C0C920CF1A18] - 02/02/2013 - 14:18:41 ---A- . (.Systweak Inc., (www.systweak.com) - Regclean Pro.) -- C:\Windows\System32\roboot.exe [18360]
O44 - LFC:[MD5.6141626E90EB1E7F5B4D0DD17E197AD9] - 02/02/2013 - 13:36:50 ---A- . (...) -- C:\Windows\AutoSetFrequency.ini [743]
O44 - LFC:[MD5.7197ED407442592EA2D388BE94A8254D] - 30/01/2013 - 21:37:29 --HA- . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [16160]
O44 - LFC:[MD5.7197ED407442592EA2D388BE94A8254D] - 30/01/2013 - 21:37:29 --HA- . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [16160]
O44 - LFC:[MD5.3AFB7BAD0967EACE8D3ED16CF2A8FD8A] - 30/01/2013 - 12:31:21 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1524562]
O44 - LFC:[MD5.EED51D56C1041D48C08D31CFC0876496] - 30/01/2013 - 12:31:21 ---A- . (...) -- C:\Windows\System32\perfc009.dat [103568]
O44 - LFC:[MD5.FF7FA933B2ABBB07373BDCD201A1ABA9] - 30/01/2013 - 12:31:21 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [127684]
O44 - LFC:[MD5.EE946017F68304658A20B6732CE5F8B8] - 30/01/2013 - 12:31:21 ---A- . (...) -- C:\Windows\System32\perfh009.dat [607190]
O44 - LFC:[MD5.E4468BFBF99A521D733AA7B7BB2359F4] - 30/01/2013 - 12:31:21 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [695004]
O44 - LFC:[MD5.B8C266D6FEC5FDDA70443D8B4F8FBCAF] - 30/01/2013 - 12:08:43 ---A- . (...) -- C:\Windows\System32\Drivers\SYMEVENT.CAT [7468]
O44 - LFC:[MD5.5F32C104CAB48375171244BCB2A8D7F8] - 30/01/2013 - 12:08:43 ---A- . (...) -- C:\Windows\System32\Drivers\SYMEVENT.INF [806]
O44 - LFC:[MD5.74E2521E96176A4449570E50BE91954D] - 30/01/2013 - 12:08:43 ---A- . (.Symantec Corporation - Symantec Event Library.) -- C:\Windows\System32\Drivers\SYMEVENT.SYS [141944]
O44 - LFC:[MD5.D84C95CC0E9A06521259FA76DEFB85CA] - 30/01/2013 - 10:10:19 ---A- . (...) -- C:\Windows\System32\GDIPFONTCACHEV1.DAT [57560]
O44 - LFC:[MD5.07BA000B2E67565BDF112C35171865A5] - 30/01/2013 - 01:39:09 ---A- . (...) -- C:\Windows\System32\perfd00C.dat [38160]
O44 - LFC:[MD5.04F6C9757DB75FF27C427E5B31DDB289] - 30/01/2013 - 01:39:09 ---A- . (...) -- C:\Windows\System32\perfi00C.dat [344522]
O44 - LFC:[MD5.6FBB766EB79F9EED3684194EEAF838DF] - 30/01/2013 - 01:31:04 ---A- . (...) -- C:\Windows\ChangeLang_Done.tag [11453]
O44 - LFC:[MD5.46C61F995D7A38A7E26D339233914214] - 29/01/2013 - 17:45:16 ---A- . (...) -- C:\Windows\System32\license.rtf [190563]
O44 - LFC:[MD5.D8EDD9F9DD740235FF779AE2850CD749] - 29/01/2013 - 17:33:37 ---A- . (...) -- C:\Windows\devices.txt [13925]
O44 - LFC:[MD5.9E4F1363B3F083027FB013F93AE022F6] - 29/01/2013 - 17:30:27 ---A- . (.Pas de propri�taire - AutosetFrequency.) -- C:\Windows\AutosetFrequency.exe [51712]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 29/01/2013 - 17:29:47 --HA- . (...) -- C:\Windows\System32\Drivers\Msft_Kernel_SynTP_01009.Wdf [0]
O44 - LFC:[MD5.EF3024328398C07DE0BDF35B67ABEC68] - 29/01/2013 - 17:22:31 ---A- . (...) -- C:\Windows\LMv4.UNI [172]
O44 - LFC:[MD5.729C9C2DEC166E44842D0CEA78F7FC49] - 29/01/2013 - 17:21:07 ---A- . (...) -- C:\Windows\System32\results.xml [15122]
O44 - LFC:[MD5.757349DFD98BFECA9FE4D287E64A5594] - 29/01/2013 - 17:12:11 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [257848]
O44 - LFC:[MD5.63D2B014282D833076FF39F8BCB2CDCB] - 29/01/2013 - 17:09:10 ---A- . (.Intel Corporation - Intel� Graphics Media Accelerator Driver in.) -- C:\Windows\System32\igxpun.exe [1006104]
O44 - LFC:[MD5.F38B53088F3200BC9B8037DBA400F0AA] - 16/12/2009 - 15:13:36 ---A- . (...) -- C:\Windows\FixUVC.exe [113264]
~ Scan Files in 00mn 04s



---\\ Derniers fichiers cr��s dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.FCC99232E3E7BA902013BE75B479647F] - 02/02/2013 - 12:04:27 ---A- - C:\Windows\Prefetch\AgAppLaunch.db
O45 - LFCP:[MD5.0D7DD2F613D0789ECC0D3CE48E4D1CF3] - 02/02/2013 - 12:53:56 ---A- - C:\Windows\Prefetch\AgGlUAD_P_S-1-5-21-1442334213-2374068315-3074064575-1000.db
O45 - LFCP:[MD5.045972645C8D6AC656C60614D0DDF133] - 02/02/2013 - 12:53:56 ---A- - C:\Windows\Prefetch\AgGlUAD_S-1-5-21-1442334213-2374068315-3074064575-1000.db
O45 - LFCP:[MD5.765A4DCB6FB06A8362EF8E32E48AA57D] - 02/02/2013 - 12:55:08 ---A- - C:\Windows\Prefetch\AgGlFaultHistory.db
O45 - LFCP:[MD5.E0EF382C9D5777E4EBBE935AE521C8CA] - 02/02/2013 - 12:55:08 ---A- - C:\Windows\Prefetch\AgGlFgAppHistory.db
O45 - LFCP:[MD5.935A070BD93FF18EC949F1A462AC2015] - 02/02/2013 - 12:55:08 ---A- - C:\Windows\Prefetch\AgGlGlobalHistory.db
O45 - LFCP:[MD5.9C34C048B3A520F40A589CB65B70560A] - 02/02/2013 - 12:55:08 ---A- - C:\Windows\Prefetch\AgRobust.db
O45 - LFCP:[MD5.3BD5B7984EB60D7B607441F20EA421E1] - 02/02/2013 - 12:55:08 ---A- - C:\Windows\Prefetch\PfSvPerfStats.bin
O45 - LFCP:[MD5.02B768DC5B81EF557B1B86F8203B783B] - 02/02/2013 - 13:05:01 ---A- - C:\Windows\Prefetch\NTOSBOOT-B00DFAAD.pf
O45 - LFCP:[MD5.CB71C2016ABC4D01A0B8B7C38434BA20] - 02/02/2013 - 13:05:11 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-27D91624.pf
O45 - LFCP:[MD5.E31EBFEF9595F0372767E4EB668CBA4E] - 02/02/2013 - 13:05:12 ---A- - C:\Windows\Prefetch\TASKHOST.EXE-A0F5E092.pf
O45 - LFCP:[MD5.499DD0E64E11C0858214C1395CFA8B9D] - 02/02/2013 - 13:15:02 ---A- - C:\Windows\Prefetch\CLTLMH.EXE-D052B5C8.pf
O45 - LFCP:[MD5.1AAA87C8D8A38512058CF1F716BFC283] - 02/02/2013 - 13:15:20 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-6389524F.pf
O45 - LFCP:[MD5.B39FB55AE2F4EB26693005A26CBFEF2D] - 02/02/2013 - 13:15:20 ---A- - C:\Windows\Prefetch\WMIADAP.EXE-BB21CD77.pf
O45 - LFCP:[MD5.37976BB52150A7F8CB7182E2D36E11AC] - 02/02/2013 - 13:32:13 ---A- - C:\Windows\Prefetch\SEARCHINDEXER.EXE-1CF42BC6.pf
O45 - LFCP:[MD5.0899772165A0FFFD01364962CA90428B] - 02/02/2013 - 13:32:13 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-B6CF74F4.pf
O45 - LFCP:[MD5.FCFB3E47693FE35782B150C45FDA57D6] - 02/02/2013 - 13:32:14 ---A- - C:\Windows\Prefetch\COFIRE.EXE-C2A69CED.pf
O45 - LFCP:[MD5.869D93B8393EE774C616B56ADE440261] - 02/02/2013 - 13:32:16 ---A- - C:\Windows\Prefetch\CCSVCHST.EXE-2F293289.pf
O45 - LFCP:[MD5.1930C31233F7C2103CA585EE402B1D26] - 02/02/2013 - 13:32:17 ---A- - C:\Windows\Prefetch\USERINIT.EXE-5114915C.pf
O45 - LFCP:[MD5.45CCB4FC799ABDDB555A6B0A3BC132A2] - 02/02/2013 - 13:32:20 ---A- - C:\Windows\Prefetch\AgCx_SC1.db.trx
O45 - LFCP:[MD5.55D701EECE0B8293FC08C7B302E38A29] - 02/02/2013 - 13:32:32 ---A- - C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-69C456C3.pf
O45 - LFCP:[MD5.4CAF3267526EF6881AAFAB4E65DF0F8D] - 02/02/2013 - 13:32:39 ---A- - C:\Windows\Prefetch\SEARCHFILTERHOST.EXE-44162447.pf
O45 - LFCP:[MD5.BB822478B2CE1FA1A2C3321CB3BC8C05] - 02/02/2013 - 13:32:39 ---A- - C:\Windows\Prefetch\TRUSTEDINSTALLER.EXE-766EFF52.pf
O45 - LFCP:[MD5.B4F379520B43AE5AFEF3A936DBB0FAAF] - 02/02/2013 - 13:33:20 ---A- - C:\Windows\Prefetch\AgCx_SC1.db
O45 - LFCP:[MD5.E0027DA70898A646F6ED71F1F37620D8] - 02/02/2013 - 13:34:36 ---A- - C:\Windows\Prefetch\NOBUCLIENT.EXE-C25AA4A1.pf
O45 - LFCP:[MD5.FFE4122D83083BEF0194535DF83194EF] - 02/02/2013 - 13:34:57 ---A- - C:\Windows\Prefetch\OOTAG.EXE-34708895.pf
O45 - LFCP:[MD5.D32C38719B9D46E0DB25C353841714A3] - 02/02/2013 - 13:35:20 ---A- - C:\Windows\Prefetch\IGFXTRAY.EXE-F30110F3.pf
O45 - LFCP:[MD5.4992E6FE4E23CABE9E232E6AE17B4B6C] - 02/02/2013 - 13:35:46 ---A- - C:\Windows\Prefetch\HKCMD.EXE-61FD4888.pf
O45 - LFCP:[MD5.35D54E6391E932C811C690264E8B867E] - 02/02/2013 - 13:36:11 ---A- - C:\Windows\Prefetch\IGFXSRVC.EXE-C5618119.pf
O45 - LFCP:[MD5.83CF7BA97C6E866BDB1CA384D1F1B789] - 02/02/2013 - 13:36:21 ---A- - C:\Windows\Prefetch\IGFXPERS.EXE-540AA77D.pf
O45 - LFCP:[MD5.FB624F7463B38621A376E22C3A8C42BC] - 02/02/2013 - 13:36:52 ---A- - C:\Windows\Prefetch\RTHDVCPL.EXE-BDBA07C9.pf
O45 - LFCP:[MD5.4F39500C9568826CD0AFE7874731D064] - 02/02/2013 - 13:36:53 ---A- - C:\Windows\Prefetch\DLLHOST.EXE-4B6CB38A.pf
O45 - LFCP:[MD5.0A09B750944E677FB06B3C26404E9F8C] - 02/02/2013 - 13:36:57 ---A- - C:\Windows\Prefetch\AUTOSETFREQUENCY.EXE-5D8B13A2.pf
O45 - LFCP:[MD5.259929CBDB602D3105D642BC7810F4BC] - 02/02/2013 - 13:36:57 ---A- - C:\Windows\Prefetch\LMANAGER.EXE-5CFD020C.pf
O45 - LFCP:[MD5.B051712E35F8D2DD119E71111885F4AF] - 02/02/2013 - 13:36:57 ---A- - C:\Windows\Prefetch\SYNTPENH.EXE-8A564A20.pf
O45 - LFCP:[MD5.C4A360F3A9E2CF54615469F9D29F9C9B] - 02/02/2013 - 13:37:05 ---A- - C:\Windows\Prefetch\AUDIODG.EXE-AB22E9A6.pf
O45 - LFCP:[MD5.BBB0EF988ED1B63CE7C8F987991E1417] - 02/02/2013 - 13:37:05 ---A- - C:\Windows\Prefetch\EPOWERTRAY.EXE-9A6C7E85.pf
O45 - LFCP:[MD5.C162836892449EE3602A7061D69DF4F9] - 02/02/2013 - 13:37:05 ---A- - C:\Windows\Prefetch\SPPSVC.EXE-96070FE0.pf
O45 - LFCP:[MD5.F989F163D0F0D39BEE5499F9289FCAD3] - 02/02/2013 - 13:37:05 ---A- - C:\Windows\Prefetch\WERMGR.EXE-F439C551.pf
O45 - LFCP:[MD5.9C54A457DF8C860225DF871C079E2AB1] - 02/02/2013 - 13:37:05 ---A- - C:\Windows\Prefetch\WMIPRVSE.EXE-E8B8DD29.pf
O45 - LFCP:[MD5.550DAE05CB04DB18C4E6BCA7577A251A] - 02/02/2013 - 13:39:33 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-F31BDE28.pf
O45 - LFCP:[MD5.46993449B332D52CB6EA900CC62ED0A1] - 02/02/2013 - 13:40:17 ---A- - C:\Windows\Prefetch\SETAPM.EXE-B95DC105.pf
O45 - LFCP:[MD5.7CFDAC0BAD1DF7A749396DB4F615F835] - 02/02/2013 - 13:40:32 ---A- - C:\Windows\Prefetch\CONHOST.EXE-0C6456FB.pf
O45 - LFCP:[MD5.8087A33E4E3FADF46D78767DCEB59172] - 02/02/2013 - 13:40:36 ---A- - C:\Windows\Prefetch\SVCHOST.EXE-6E1A6101.pf
O45 - LFCP:[MD5.0C793E7166A16057CBE85B12D31D55C4] - 02/02/2013 - 13:42:38 ---A- - C:\Windows\Prefetch\IEXPLORE.EXE-058FE8F5.pf
O45 - LFCP:[MD5.35822ECC7FB977CC75B79A7E0A7FB78C] - 02/02/2013 - 13:42:43 ---A- - C:\Windows\Prefetch\SYMERR.EXE-382F472E.pf
O45 - LFCP:[MD5.A730062ED575CEE2F0A68C5BEA7CE2F4] - 02/02/2013 - 13:45:12 ---A- - C:\Windows\Prefetch\WERFAULT.EXE-155C56CF.pf
~ Scan Prefetcher in 00mn 00s



---\\ D�ni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package�v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l��diteur de configuration de s�curit� Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de s�curit� Kerberos.) -- C:\Windows\System32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package�v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll
~ Scan Keys in 00mn 00s



---\\ Contr�le du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris s�rie.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d�extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris s�rie.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d�extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
~ Scan CSB in 00mn 00s



---\\ MountPoints2 Shell Key (O51) (None)

---\\ Trojan Driver Search Data (HKLM) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak�.) -- C:\Windows\System32\iccvid.dll
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
~ Scan Keys in 00mn 00s



---\\ ShareTools MSconfig StartupReg (O53) (None)

---\\ Microsoft Control Security Providers (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ Scan Keys in 00mn 00s



---\\ Microsoft Windows Policies System (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ Scan Keys in 00mn 00s



---\\ Liste des Drivers Syst�me (O58)
O58 - SDL:[MD5.21E785EBD7DC90A06391141AAC7892FB] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976]
O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
~ Scan Drivers in 00mn 00s



---\\ Derniers fichiers modifi�s ou cr�es (Utilisateur) (O61)
O61 - LFC:Last File Created 01/02/2013 - 19:25:36 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\~DF560F53E8F32F77F7.TMP [0]
O61 - LFC:Last File Created 01/02/2013 - 19:25:36 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\~DF8A524B70CC6161B9.TMP [0]
O61 - LFC:Last File Created 01/02/2013 - 19:25:37 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\~DF27618593F3E16CAB.TMP [0]
O61 - LFC:Last File Created 01/02/2013 - 19:25:37 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\~DFA366D2EE1575BDA8.TMP [0]
O61 - LFC:Last File Created 01/02/2013 - 19:26:46 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\instloffer.exe [168728]
O61 - LFC:Last File Created 02/02/2013 - 14:03:10 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\d14412c4-2d38-4a20-abf0-11ad01a1b080 [64]
O61 - LFC:Last File Created 02/02/2013 - 14:03:35 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\c9bb8f6f-3456-4518-934d-b61fa8b691d4 [66]
O61 - LFC:Last File Created 02/02/2013 - 14:05:24 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\890a6401-9fb2-48aa-ad4b-ae9c10bf6bb9 [66]
O61 - LFC:Last File Created 02/02/2013 - 14:46:53 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\276.txt [0]
O61 - LFC:Last File Created 02/02/2013 - 14:47:31 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\Shortcut_Shortcut_toolbar_vit_sweetim.exe [7216040]
O61 - LFC:Last File Created 02/02/2013 - 14:47:31 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\Shortcut_toolbar_vit_sweetim.exe [7216040]
O61 - LFC:Last File Created 02/02/2013 - 14:48:07 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\25623-667949-ccleaner.exe [3907920]
O61 - LFC:Last File Created 02/02/2013 - 14:50:50 ---A- C:\Users\st�phanie.st�phanie-PC\Documents\cc_20130202_145040.reg [25914]
O61 - LFC:Last File Created 02/02/2013 - 15:04:09 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\ElevatedDiagnostics\460911090\2013020214.000\NetworkDiagnostics.0.debugreport.xml [71904]
O61 - LFC:Last File Created 02/02/2013 - 15:04:09 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\ElevatedDiagnostics\460911090\2013020214.000\results.xsl [49097]
O61 - LFC:Last File Created 02/02/2013 - 15:04:17 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\ElevatedDiagnostics\460911090\2013020214.000\NetworkDiagnostics.1.debugreport.xml [69784]
O61 - LFC:Last File Created 02/02/2013 - 15:04:17 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\ElevatedDiagnostics\460911090\2013020214.000\ResultReport.xml [38055]
O61 - LFC:Last File Created 02/02/2013 - 15:04:17 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\ElevatedDiagnostics\460911090\2013020214.000\results.xml [256]
O61 - LFC:Last File Created 02/02/2013 - 15:04:17 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\ElevatedDiagnostics\460911090\latest.cab [21957]
O61 - LFC:Last File Created 02/02/2013 - 15:19:14 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\GenericUninstall.exe [127320]
O61 - LFC:Last File Created 02/02/2013 - 15:19:14 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\SIMEEIInstaller.exe [3380216]
O61 - LFC:Last File Created 02/02/2013 - 15:19:14 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\SimboApp.exe [1285976]
O61 - LFC:Last File Created 02/02/2013 - 15:19:14 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\mgsqlite3.dll [393016]
O61 - LFC:Last File Created 02/02/2013 - 15:19:14 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\uninstaller.exe [375128]
O61 - LFC:Last File Created 30/01/2013 - 10:15:19 ---A- C:\Users\st�phanie.st�phanie-PC\Links\Desktop.lnk [495]
O61 - LFC:Last File Created 30/01/2013 - 10:15:19 ---A- C:\Users\st�phanie.st�phanie-PC\Links\Downloads.lnk [970]
O61 - LFC:Last File Created 30/01/2013 - 10:15:19 ---A- C:\Users\st�phanie.st�phanie-PC\Links\RecentPlaces.lnk [383]
O61 - LFC:Last File Created 30/01/2013 - 10:15:46 ----- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\FXSAPIDebugLogFile.txt [0]
O61 - LFC:Last File Created 30/01/2013 - 10:15:48 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\rasphone.pbk [0]
O61 - LFC:Last File Created 30/01/2013 - 16:14:56 ---A- C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Microsoft\MMC\eventvwr [145892]
O61 - LFC:Last File Created 30/12/1899 - 01:58:14 -SHA- C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Microsoft\Protect\CREDHIST [24]
O61 - LFC:Last File Created 30/12/1899 - 01:58:27 -SHA- C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Microsoft\Protect\S-1-5-21-1442334213-2374068315-3074064575-1000\1419c45f-9986-4d98-8ac1-8f5f90267ddd [468]
O61 - LFC:Last File Created 30/12/1899 - 01:58:28 -SHA- C:\Users\st�phanie.st�phanie-PC\AppData\Roaming\Microsoft\Protect\S-1-5-21-1442334213-2374068315-3074064575-1000\Preferred [24]
O61 - LFC:Last File Created 30/12/1899 - 10:15:19 R-HA- C:\Users\st�phanie.st�phanie-PC\Searches\Everywhere.search-ms [248]
O61 - LFC:Last File Created 30/12/1899 - 10:15:19 R-HA- C:\Users\st�phanie.st�phanie-PC\Searches\Indexed Locations.search-ms [248]
~ Scan Files in 00mn 03s



---\\ Liste des outils de nettoyage (O63)
O63 - Logiciel: ZHPDiag 1.34 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
~ Scan ADS in 00mn 00s



---\\ Liste des services Legacy (O64)
O64 - Services: CurCS - 25/04/2011 - C:\Windows\system32\drivers\afd.sys (AFD) .(.Microsoft Corporation - Ancillary Function Driver for WinSock.) - LEGACY_AFD
O64 - Services: CurCS - 16/01/2013 - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20130116.013\BHDrvx86.sys (BHDrvx86) .(.Symantec Corporation - BASH Driver.) - LEGACY_BHDRVX86
O64 - Services: CurCS - 07/06/2012 - C:\Windows\system32\drivers\NIS\1309000.009\ccSetx86.sys (ccSet_NIS) .(.Symantec Corporation - Common Client Settings Driver.) - LEGACY_CCSET_NIS
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\clfs.sys (CLFS) .(.Microsoft Corporation - Common Log File System Driver.) - LEGACY_CLFS
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\Drivers\cng.sys (CNG) .(.Microsoft Corporation - Kernel Cryptography, Next Generation.) - LEGACY_CNG
O64 - Services: CurCS - 30/01/2013 - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (eeCtrl) .(.Symantec Corporation - Symantec Eraser Control Driver.) - LEGACY_EECTRL
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\fvevol.sys (fvevol) .(.Microsoft Corporation - BitLocker Drive Encryption Driver.) - LEGACY_FVEVOL
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\hwpolicy.sys (hwpolicy) .(.Microsoft Corporation - Hardware Policy Driver.) - LEGACY_HWPOLICY
O64 - Services: CurCS - 29/01/2013 - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20130201.001\IDSvix86.sys (IDSVix86) .(.Symantec Corporation - IDS Core Driver.) - LEGACY_IDSVIX86
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\lltdio.sys (lltdio) .(.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) - LEGACY_LLTDIO
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\luafv.sys (luafv) .(.Microsoft Corporation - Pilote de filtre de virtualisation de fichi.) - LEGACY_LUAFV
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\wkssvc.dll (mrxsmb20) .(.Microsoft Corporation - DLL du service Station de travail.) - LEGACY_MRXSMB20
O64 - Services: CurCS - 30/01/2013 - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20130201.033\NAVENG.sys (NAVENG) .(.Symantec Corporation - AV Engine.) - LEGACY_NAVENG
O64 - Services: CurCS - 30/01/2013 - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20130201.033\NAVEX15.sys (NAVEX15) .(.Symantec Corporation - AV Engine.) - LEGACY_NAVEX15
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\ndis.sys (NDIS) .(.Microsoft Corporation - Pilote NDIS 6.20.) - LEGACY_NDIS
O64 - Services: CurCS - 20/11/2010 - C:\Windows\system32\drivers\netbt.sys (NetBT) .(.Microsoft Corporation - MBT Transport driver.) - LEGACY_NETBT
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\drivers\pacer.sys (Psched) .(.Microsoft Corporation - Planificateur de paquets QoS.) - LEGACY_PSCHED
O64 - Services: CurCS - 14/07/2009 - C:\Windows\System32\DRIVERS\rspndr.sys (rspndr) .(.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) - LEGACY_RSPNDR
O64 - Services: CurCS - ??\??\???? - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
O64 - Services: CurCS - 06/07/2012 - C:\Windows\system32\Drivers\NIS\1309000.009\SRTSP.sys (SRTSP) .(.Symantec Corporation - Symantec AutoProtect.) - LEGACY_SRTSP
O64 - Services: CurCS - 06/07/2012 - C:\Windows\system32\drivers\NIS\1309000.009\SRTSPX.sys (SRTSPX) .(.Symantec Corporation - Symantec AutoProtect.) - LEGACY_SRTSPX
O64 - Services: CurCS - 29/04/2011 - C:\Windows\System32\DRIVERS\srvnet.sys (srvnet) .(.Microsoft Corporation - Server Network driver.) - LEGACY_SRVNET
O64 - Services: CurCS - 16/05/2011 - C:\Windows\System32\drivers\NIS\1309000.009\SYMDS.sys (SymDS) .(.Symantec Corporation - Symantec Data Store.) - LEGACY_SYMDS
O64 - Services: CurCS - 22/05/2012 - C:\Windows\System32\drivers\NIS\1309000.009\SYMEFA.sys (SymEFA) .(.Symantec Corporation - Symantec Extended File Attributes.) - LEGACY_SYMEFA
O64 - Services: CurCS - 30/01/2013 - C:\Windows\system32\Drivers\SYMEVENT.sys (SymEvent) .(.Symantec Corporation - Symantec Event Library.) - LEGACY_SYMEVENT
O64 - Services: CurCS - 18/04/2012 - C:\Windows\system32\drivers\NIS\1309000.009\Ironx86.sys (SymIRON) .(.Symantec Corporation - Iron Driver.) - LEGACY_SYMIRON
O64 - Services: CurCS - 18/04/2012 - C:\Windows\system32\Drivers\NIS\1309000.009\SYMNETS.sys (SymNetS) .(.Symantec Corporation - Network Security Driver.) - LEGACY_SYMNETS
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\vga.sys (VgaSave) .(.Microsoft Corporation - VGA/Super VGA Video Driver.) - LEGACY_VGASAVE
O64 - Services: CurCS - 20/11/2010 - C:\Windows\System32\drivers\volsnap.sys (volsnap) .(.Microsoft Corporation - Pilote de clich� instantan� du volume.) - LEGACY_VOLSNAP
O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\rascfg.dll (Wanarpv6) .(.Microsoft Corporation - Objets de configuration RAS.) - LEGACY_WANARPV6
~ Scan Services in 00mn 00s



---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d��v�nements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft � Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - �diteur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.bat> [HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> [HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: <.cmd> [HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> [HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> [HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d��v�nements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> [HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> [HKCR\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> [HKCR\..\open\Command] (.Microsoft Corporation - Microsoft � Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> [HKCR\..\open\Command] (.Microsoft Corporation - �diteur du Registre.) -- C:\Windows\regedit.exe
~ Scan Keys in 00mn 00s



---\\ Start Menu Internet (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.)
O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.)
~ Scan Keys in 00mn 00s



---\\ Search Browser Infection (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
~ Scan Keys in 00mn 00s



---\\ Recherche des services d�marr�s par Svchost (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Exp�rience d�application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes � puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes � puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de strat�gie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [674304]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [473600]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de num�rotation automatique d�acc�s distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d�acc�s distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d�interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d��v�nements syst�me (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l�application d�assistance � Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de t�l�phonie Microsoft� Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur h�te de session Burea.) -- C:\Windows\System32\termsrv.dll [521216]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise � jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [1933848]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arri�re-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivit� IPv6 sur un r�seau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d�ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d�application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de d�couverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multim�dias.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux probl�mes.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164352]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de t�ches.) -- C:\Windows\System32\schedsvc.dll [750592]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des cl�s.) -- C:\Windows\System32\kmsvc.dll [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau � distance.) -- C:\Windows\System32\sessenv.dll [113664]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d�ordinateurs.) -- C:\Windows\System32\browser.dll [102400]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des th�mes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800]
~ Scan Services in 00mn 00s



---\\ Recherche particuliere � la racine de certains dossiers (O84)
[MD5.E17022079D0FDAC6EA094B1E29D22B61] [SPRF][02/02/2013] (.Piriform Ltd - CCleaner Installer.) -- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\25623-667949-ccleaner.exe [3907920]
[MD5.E340610FFB87526CEA07D93102814D18] [SPRF][02/02/2013] (...) -- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\GenericUninstall.exe [127320]
[MD5.39D998E29DC9277C8762070901E69A32] [SPRF][24/06/2011] (.Google Inc. - Google Toolbar Installer.) -- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\GoogleToolbarInstaller_stub_signed.exe [235184]
[MD5.91FAF88F3A51941716E21C1805A8E4FA] [SPRF][01/02/2013] (...) -- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\instloffer.exe [168728]
[MD5.8A4AF3B0695F29186AD02E2FD766FA3B] [SPRF][02/02/2013] (.SweetIM Technologies Ltd. - SQLite DLL.) -- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\mgsqlite3.dll [393016]
[MD5.3CD1A63A0A2A70DF8A41119EF7B75E57] [SPRF][02/02/2013] (.SweetIM Technologies Ltd. - SweetIM Installer by SweetPacks.) -- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\Shortcut_Shortcut_toolbar_vit_sweetim.exe [7216040]
[MD5.3CD1A63A0A2A70DF8A41119EF7B75E57] [SPRF][02/02/2013] (.SweetIM Technologies Ltd. - SweetIM Installer by SweetPacks.) -- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\Shortcut_toolbar_vit_sweetim.exe [7216040]
[MD5.3D163F2ED6D30593F69A0CE1E3FBFD02] [SPRF][02/02/2013] (.SweetIM Technologies Ltd. - SweetPacks Browser Updater.) -- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\SimboApp.exe [1285976]
[MD5.7704B843006444B69486FD27D4660845] [SPRF][02/02/2013] (.SweetIM Technologies Lt - This installer.) -- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\SIMEEIInstaller.exe [3380216]
[MD5.BFA04EC64BE6B677C56B66B09811B7D4] [SPRF][02/02/2013] (.TODO: - TODO: .) -- C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\uninstaller.exe [375128]
[MD5.7B0C2FBC82CFD78C90B7279F623F0495] [SPRF][14/12/2010] (.Microsoft Corp - Microsoft Support Diagnostic Tool Control.) -- C:\Windows\Downloaded Program Files\MSDcode.dll [562512]
~ Scan Files in 00mn 00s



---\\ Firewall Active Exception List (FirewallRules) (O87)
O87 - FAEL: "{B7A0BF54-BABE-49B0-826D-266110CA6A3C}" | In - None - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe
~ Scan Firewall in 00mn 01s



---\\ Scan Additionnel (O88)
Database Version : v2.10502 - (01/02/2013)
Cl�s trouv�es (Keys found) : 4
Valeurs trouv�es (Values found) : 0
Dossiers trouv�s (Folders found) : 0
Fichiers trouv�s (Files found) : 13

[HKLM\Software\Microsoft\Tracing\BingBar_RASMANCS] =>Toolbar.Agent
[HKCU\Software\Softonic] =>Toolbar.Conduit
[HKCU\Software\SweetIM] =>PUP.SweetIM
[HKLM\Software\Microsoft\Tracing\BingBar_RASAPI32] =>Toolbar.Agent
C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\Shortcut_Shortcut_toolbar_vit_sweetim.exe =>PUP.SweetIM
C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\Shortcut_toolbar_vit_sweetim.exe =>PUP.SweetIM
C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\SIMEEIInstaller.exe =>PUP.SweetIM
C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\mgsqlite3.dll => Infection PUP (PUP.SweetIM)
C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\Shortcut_Shortcut_toolbar_vit_sweetim.exe => Infection PUP (PUP.SweetIM)
C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\Shortcut_toolbar_vit_sweetim.exe => Infection PUP (PUP.SweetIM)
C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\SimboApp.exe => Infection PUP (PUP.SweetIM)
C:\Users\st�phanie.st�phanie-PC\AppData\Local\Temp\SIMEEIInstaller.exe => Infection PUP (PUP.SweetIM)
~ Scan Additionnel in 00mn 19s



---\\ Recherche d�tournement de DNS routeur (O89) (None)

---\\ Product Upgrade Codes (O90)
O90 - PUC: "00004159070000000000000000F01FEC" . (.Microsoft Office 2010.) -- C:\Windows\Installer\{95140000-0070-0000-0000-0000000FF1CE}\oobeicon.exe
O90 - PUC: "076CFAAAB965F2A4284B2449E5D03EFE" . (.Windows Live Writer.) -- C:\Windows\Installer\{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}\ApplicationIcon.ico
O90 - PUC: "0C69D82C09A6E9540A776A07F6E40CCF" . (.Bing Bar.) -- C:\Windows\Installer\{C28D96C0-6A90-459E-A077-A6706F4EC0FC}\icon_installer_ico
O90 - PUC: "1D034B0FAA6BD374B960AAD30DF10D8B" . (.Microsoft SQL Server 2005 Compact Edition [ENU].) -- C:\Windows\Installer\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}\ProductIcon
O90 - PUC: "68AB67CA7DA7FFFFB744AA0000000010" . (.Adobe Reader X MUI.) -- C:\Windows\Installer\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}\SC_Reader.ico
O90 - PUC: "6FD66A043D225B447A3D381B812A0CCD" . (.Norton Online Backup.) -- C:\Windows\Installer\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}\MainIcon.ico
O90 - PUC: "BDAD5335AB438EA45A9146D887948864" . (.Skype� 5.3.) -- C:\Windows\Installer\{5335DADB-34BA-4AE8-A519-648D78498846}\SkypeIcon.exe
O90 - PUC: "D7314F9862C648A4DB8BE2A5B47BE100" . (.Microsoft Silverlight.) -- c:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ARPIcon
~ Scan Files in 00mn 00s



---\\ Etat g�n�ral des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 07/06/2011 191752 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files\Microsoft\BingBar\BBSvc.exe
SS - | Auto 12/05/2011 249648 | (BBUpdate) . (.Microsoft Corporation.) - C:\Program Files\Microsoft\BingBar\SeaPort.exe
SS - | Auto 01/12/2010 305744 | (DsiWMIService) . (.Dritek System Inc..) - C:\Program Files\Launch Manager\dsiwmis.exe
SS - | Auto 10/05/2011 739944 | (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe
SS - | Demand 12/10/2010 206072 | (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files\WildTangent Games\App\GamesAppService.exe
SS - | Auto 18/01/2011 39528 | (GREGService) . (.Acer Incorporated.) - C:\Program Files\eMachines\Registration\GREGsvc.exe
SS - | Auto 02/02/2013 116648 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 02/02/2013 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 02/02/2013 194032 | (gusvc) . (.Google.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Auto 22/04/2011 244624 | (Live Updater Service) . (.Acer Incorporated.) - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
SR - | Auto 16/06/2012 138272 | (NIS) . (.Symantec Corporation.) - C:\Program Files\Norton Internet Security\Engine\19.9.0.9\ccSvcHst.exe
SS - | Auto 01/06/2010 2057560 | (NOBU) . (.Symantec Corporation.) - C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe
SS - | Auto 31744 | (SrvUpdater) . (...) - C:\Program Files\SoftwareUpdater\UpdaterService.exe
SR - | Auto 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SS - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Scan Services in 00mn 00s



---\\ Recherche Master Boot Record Infection (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Run by st�phanie at 02/02/2013 15:53:17

device: opened successfully
user: MBR read successfully

Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll iaStor.sys
C:\Windows\system32\drivers\iaStor.sys Intel Corporation Intel Rapid Storage Technology driver
1 ntkrnlpa!IofCallDriver[0x8183A52F] -> \Device\Harddisk0\DR0[0x85469AA0]
3 CLASSPNP[0x8890F59E] -> ntkrnlpa!IofCallDriver[0x8183A52F] -> [0x84941370]
5 ACPI[0x87EB13D4] -> ntkrnlpa!IofCallDriver[0x8183A52F] -> \Device\Ide\IAAStorageDevice-0[0x8493E028]
kernel: MBR read successfully
user & kernel MBR OK
~ Scan MBR in 00mn 02s



---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by st�phanie at 02/02/2013 15:53:19

********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ Scan MBR in 00mn 04s



End of the scan (1001 lines in 02mn 17s)(0)

Publicité

Soutenons La Quadrature du Net ! Soutenons La Quadrature du Net !

Signaler le contenu de ce document

Publicité

Soutenons La Quadrature du Net !