cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Rapport de ZHPDiag v2013.6.13.18 par Nicolas Coolman, Update du 13/06/2013
Run by modesta at 14/06/2013 17:39:06
WebSite: http://nicolascoolman.webs.com
State : Version � jour.
WhiteList : Enable
High Elevated Privileges : OK
UAC : Deactivate by program


---\\ Web Browser
MSIE: Internet Explorer v10.0.9200.16618
GCIE: Google Chrome v27.0.1453.110 (Defaut)

---\\ Windows Product Information
~ Langage: Fran�ais
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 3Q6C9
Windows License : OK
~ Windows Remaining Initializations Number : 2
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ System Protection
avast! Free Antivirus v8.0.1489.0
Windows Defender W7

---\\ System Optimizer
CCleaner v4.00 =>Piriform Ltd

---\\ Peer To Peer (P2P)
Pando Media Booster v2.6.0.8

---\\ Software Update
Adobe Flash Player 11 Plugin
Adobe Reader 9.5.5 MUI
Java 7 Update 21

---\\ System Information
~ Processor: AMD64 Family 16 Model 6 Stepping 2, AuthenticAMD
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 2812 MB (56% free)
System Restore: Activ� (Enable)
System drive C: has 76 GB (26%) free of 284 GB

---\\ Logged in mode
~ Computer Name: MODESTA-PC
~ User Name: modesta
~ All Users Names: postgres, modesta, HomeGroupUser$, Administrateur,
~ Unselected Option: None
Logged in as Administrator

---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Users\modesta\AppData\Roaming\
~ %Desktop% : C:\Users\modesta\Desktop\
~ %Favorites% : C:\Users\modesta\Favorites\
~ %LocalAppData% : C:\Users\modesta\AppData\Local\
~ %StartMenu% : C:\Users\modesta\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 76 Go of 284 Go)
D:\ Hard drive, Flash drive, Thumb drive (Free 2 Go of 13 Go)
E:\ Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)
F:\ CD-ROM drive (Not Inserted)
H:\ CD-ROM drive (Not Inserted)
I:\ CD-ROM drive (Not Inserted)
L:\ Floppy drive, Flash card reader, USB Key (Free 2 Go of 4 Go)



---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
~ Security Center: 37 Legitimates Filtered in 00mn 00s



---\\ Recherche particuli�re de fichiers g�n�riques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de d�marrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.12716D987D475B051F35895659159705] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.17/05/2013 - 01:59:03.) -- C:\Windows\System32\wininet.dll [2241024]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d�ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Biblioth�que de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.1C7857B62DE5994A75B054A9FD4C3825] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/12/2011 - 04:59:24.) -- C:\Windows\system32\Drivers\AFD.sys [498688]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du syst�me de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parall�le.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de clich� instantan� du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s



---\\ Etat des fichiers cach�s (Cach�/Total)
~ Mes images (My Pictures) : 2/22
~ Mes musiques (My Musics) : 2/165
~ Mes Videos (My Videos) : 2/43
~ Mes Favoris (My Favorites) : 1/67
~ Mes Documents (My Documents) : 2/1946
~ Mon Bureau (My Desktop) : 2/23209
~ Menu demarrer (Programs) : 1/48
~ Hidden Files: Scanned in 00mn 54s



---\\ Processus lanc�s
[MD5.349AB4F70E2AC44970894E7F03E1576E] - (.Huawei Technologies Co., Ltd. - DataCardMonitor MFC Application.) -- C:\ProgramData\DatacardService\DCSHelper.exe [236384] [PID.1604]
[MD5.D63797E8E7781EE1500A810CB6194FA6] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816] [PID.3156]
[MD5.3F11B20D12D89365D7721BDC860CE5F0] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968] [PID.3180]
[MD5.598396AE125095BBEDFAC532854D7EB7] - (.IObit - Game Booster.) -- C:\Program Files (x86)\IObit\Game Booster 3\gbtray.exe [609624] [PID.3520]
[MD5.2F3390C8E3620B3991D7D82014E26AA7] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [825808] [PID.172]
[MD5.B8DD83B85636F7D6EC0F09B090E49130] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [7494656] [PID.3980]
[MD5.28D6701C710AD7BA3CB95E75F8F1A9AA] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808] [PID.1408]
[MD5.F401929EE0CC92BFE7F15161CA535383] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55184] [PID.1784]
[MD5.ACC93675D78D1C07DAD09D7837F2397A] - (.PostgreSQL Global Development Group - pg_ctl - starts/stops/restarts the PostgreS.) -- C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe [65536] [PID.1516]
[MD5.498EB62A160674E793FA40FD65390625] - (.Pas de propri�taire - RichVideo Module.) -- C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152] [PID.2136]
[MD5.E5C796B621F6FBA8616511063D7F0FFE] - (.StarWind Software - StarWind iSCSI Target (Alcohol Edition).) -- C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [370688] [PID.2204]
[MD5.879F46329B7DC4D109345AA96F1AB47F] - (.TeamViewer GmbH - TeamViewer 8.) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [4150112] [PID.2256]
[MD5.D78830C645884DB617C50B264BFFEBA2] - (.PostgreSQL Global Development Group - PostgreSQL Server.) -- C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe [3690496] [PID.2368]
[MD5.1BBBF640BC0E0B750537BAECE8D66C18] - (.Nero AG - NeroUpdate.) -- C:\Program Files (x86)\Nero\Update\NASvc.exe [641832] [PID.3720]
~ Processes Running: Scanned in 00mn 01s



---\\ Google Chrome, D�marrage,Recherche,Extensions (G0,G1,G2)
C:\Users\modesta\AppData\Local\Google\Chrome\User Data\Default\Preferences
~ Google Browser: 12 Legitimates Filtered in 00mn 14s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\modesta\AppData\Roaming\Mozilla\Firefox\Profiles\et9kzzm3.default\prefs.js
C:\Users\modesta\AppData\Roaming\Mozilla\Firefox\Profiles\tkx0l4k9.default\prefs.js (.not file.)
C:\Users\modesta\AppData\Roaming\Mozilla\Firefox\Profiles\tkx0l4k9.default\user.js
~ Firefox Browser: 11 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 0



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: (no name) [64Bits] - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Cl� orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Applications d�marr�es par registre & par dossier (O4)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
O4 - HKLM\..\Wow6432Node\Run: [avast] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastUI.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-21-3600749335-942430350-662760979-1003\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-21-3600749335-942430350-662760979-1003\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
~ Application: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Accessories: Private Character Editor.lnk . (.Microsoft Corporation - �diteur de caract�res priv�s.) -- C:\Windows\system32\eudcedit.exe
O4 - GS\SendTo: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) -- C:\Windows\system32\WFS.exe
O4 - GS\Desktop: ASIO4ALL v2 Instruction Manual.lnk . (...) -- C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL v2 Instruction Manual.pdf (.not file.)
O4 - GS\Desktop: ASIO4ALL v2 Off-Line Settings.lnk . (...) -- C:\Program Files (x86)\ASIO4ALL v2\a4apanel.exe (.not file.)
O4 - GS\Desktop: Audacity.lnk . (...) -- C:\Program Files\MultimediaTools\Audacity\audacity.exe
O4 - GS\Desktop: Bandicam.lnk . (.www.Bandisoft.com - Bandisoft - bdcam.exe.) -- C:\Program Files (x86)\Bandicam\bdcam.exe
O4 - GS\Desktop: Collab.lnk . (.Image-Line bvba - Collab executable.) -- C:\Program Files (x86)\Image-Line\Collab\Collab.exe
O4 - GS\Desktop: Cool Audio Video Converter.lnk . (...) -- C:\Program Files (x86)\Cool Audio Video Converter\Cool Audio Video Converter.exe (.not file.)
O4 - GS\Desktop: Crossfire Europe.lnk . (.TODO: - CF_SGI.) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe
O4 - GS\Desktop: GameCenter.lnk . (.Cyanide - GameCenter.) -- C:\Program Files (x86)\Cyanide\GameCenter\GameCenter.exe
O4 - GS\Desktop: Installation de PMU Poker.lnk . (...) -- C:\Program Files (x86)\Mozilla Firefox\PMUPoker_Installer\SmartInstaller.exe (.not file.)
O4 - GS\Desktop: Installeur de World of Warcraft.lnk - Cl� orpheline
O4 - GS\Desktop: iTuner.lnk . (.Pyxsys - Pas de description.) -- C:\Program Files (x86)\OOBOX\Music\iTuner\XTuner2.exe
O4 - GS\Desktop: LimeWire 5.5.10.lnk . (...) -- C:\Program Files (x86)\LimeWire\LimeWire.exe (.not file.)
O4 - GS\Desktop: PhotoFiltre.lnk . (.Antonio Da Cruz - PhotoFiltre.) -- C:\Program Files (x86)\PhotoFiltre\photofiltre.exe
O4 - GS\Desktop: PMU Poker.lnk . (...) -- C:\Programs\PMU\PMU.exe (.not file.)
O4 - GS\Desktop: Super Mp3 Recorder Professional.lnk . (...) -- C:\Program Files (x86)\Admiresoft\Super Mp3 Recorder Professional\smrpro.exe
O4 - GS\Desktop: Teamspeak 2 RC2.lnk . (.Dominating Bytes Design - The TeamSpeak 2 client.) -- C:\Program Files (x86)\Teamspeak2_RC2\TeamSpeak.exe
O4 - GS\Desktop: TopSpin Demo Launcher.lnk . (...) -- C:\Program Files (x86)\Atari\TopSpin-Demo\Launcher.exe (.not file.)
O4 - GS\Desktop: Tunatic.lnk . (.Wildbits - Tunatic 1.0.1b.) -- C:\Program Files (x86)\Tunatic\tunatic.exe
O4 - GS\Desktop: Virtual DJ Trial.lnk . (.Atomix Productions - VirtualDJ.) -- C:\Program Files (x86)\VirtualDJ\virtualdj_trial.exe
O4 - GS\TaskBar: Explorateur Windows.lnk . (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\explorer.exe
O4 - GS\TaskBar: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\TaskBar: Reason.lnk . (.Propellerhead Software AB - Reason program file.) -- C:\Program Files (x86)\Propellerhead\Reason\Reason.exe
O4 - GS\Programs: Free mp3 Wma Converter.lnk . (.Koyote Soft - Free Audio Converter.) -- C:\Program Files (x86)\Free mp3 Wma Converter\FreeConverter\FreeConverter.exe
O4 - GS\Programs: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch: Easy Audio Cutter.lnk . (.Koyote Soft - Pas de description.) -- C:\Program Files (x86)\Free mp3 Wma Converter\Easy Audio Cutter\AudioCutter.exe
O4 - GS\QuickLaunch: Free CD Ripper.lnk . (.Koyote Soft - FreeCDRipper.) -- C:\Program Files (x86)\Free mp3 Wma Converter\Free CD Ripper\FreeCDRipper.exe
O4 - GS\QuickLaunch: Free Mp3 Wma Converter.lnk . (.Koyote Soft - Free Audio Converter.) -- C:\Program Files (x86)\Free mp3 Wma Converter\FreeConverter\FreeConverter.exe
O4 - GS\QuickLaunch: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch: PokerStars.fr.lnk . (.PokerStars - PokerStars Update.) -- C:\Program Files (x86)\PokerStars.FR\PokerStarsUpdate.exe
O4 - GS\QuickLaunch: UltraDefrag.lnk . (.UltraDefrag Development Team - UltraDefrag GUI interface.) -- C:\Program Files\UltraDefrag\ultradefrag.exe
O4 - GS\QuickLaunch: Xilisoft Video to Audio Converter.lnk . (...) -- C:\Program Files (x86)\Xilisoft\Video to Audio Converter\vcloader.exe
O4 - GS\Accessories: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\SendTo: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O4 - GS\SendTo: Xfire Ami(e).lnk . (...) -- C:\Program Files (x86)\Xfire\Xfire.exe (.not file.)
O4 - GS\Desktop: ALBUMS - Raccourci.lnk . (...) -- C:\Users\modesta\Desktop\HIPHOPISDREAM\ALBUMS
O4 - Global Startup: C:\Users\modesta\Desktop\clubic pc.url . (...) -- C:\Users\modesta\Desktop\clubic pc.url
O4 - GS\Desktop: CMD.lnk . (...) -- C:\Users\modesta\Desktop\Mes Documents\CMD.txt
O4 - Global Startup: C:\Users\modesta\Desktop\FACEBOOK.url . (...) -- C:\Users\modesta\Desktop\FACEBOOK.url
O4 - GS\Desktop: Free Mp3 Wma Converter.lnk . (.Koyote Soft - Free Audio Converter.) -- C:\Program Files (x86)\Free mp3 Wma Converter\FreeConverter\FreeConverter.exe
O4 - GS\Desktop: Reason.lnk . (.Propellerhead Software AB - Reason program file.) -- C:\Program Files (x86)\Propellerhead\Reason\Reason.exe
O4 - GS\Desktop: ReCycle.lnk . (.Propellerhead Software AB - ReCycle Program File.) -- C:\Program Files (x86)\Propellerhead\ReCycle\ReCycle.exe
O4 - Global Startup: C:\Users\modesta\Desktop\UC.url . (...) -- C:\Users\modesta\Desktop\UC.url
O4 - GS\Desktop: VirtualDJ Home FREE.lnk . (.Atomix Productions - VirtualDJ.) -- C:\Program Files (x86)\VirtualDJ\virtualdj_home.exe
~ Global Startup: Scanned in 00mn 02s



---\\ Boutons situ�s sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Free YouTube Download [64Bits] - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} . (...) -- C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\dvdvideosoft.ico
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{75728A8F-5917-406F-A6DB-FA5BD6410464}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{B86F66EB-44E0-4145-8B54-36BA2F4839B6}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{E582CE4B-ABFA-4A20-8251-A614A5B4AD1C}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{75728A8F-5917-406F-A6DB-FA5BD6410464}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{B86F66EB-44E0-4145-8B54-36BA2F4839B6}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{E582CE4B-ABFA-4A20-8251-A614A5B4AD1C}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{75728A8F-5917-406F-A6DB-FA5BD6410464}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{B86F66EB-44E0-4145-8B54-36BA2F4839B6}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{E582CE4B-ABFA-4A20-8251-A614A5B4AD1C}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non d�sactiv�s (O23)
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) . (.PostgreSQL Global Development Group - pg_ctl - starts/stops/restarts the PostgreS.) - C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: TeamViewer 8 (TeamViewer8) . (.TeamViewer GmbH - TeamViewer 8.) - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
~ Services: 15 Legitimates Filtered in 00mn 09s



---\\ T�ches planifi�es en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [Programme de mise � jour en ligne de Sun Microsystems] (...) -- C:\Program Files\Java\jre6\bin\jusched.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{0167CEC1-7073-4F51-83C0-F19F6E417C2F}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{07C9D1E0-167A-42BD-8AEE-6C84482DAED8}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{08ACE16C-0362-433E-A0E4-C7837DFB8B2E}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [{0A832D6B-998F-4836-B8F3-8C954FF6CB57}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0]
[MD5.B186735BDC45649FD172D18E3F6B7DB9] [APT] [{16F4C069-B88C-47F7-BFFC-5ECBFF8D837A}] (...) -- C:\Program Files (x86)\Propellerhead\ReCycle\unins000.exe [691481]
[MD5.EB906EDD7889FBE6829EFEDBEC53A3DC] [APT] [{3F59FBF4-5E7E-40FC-9363-090CA4C292F5}] (...) -- C:\Program Files (x86)\PENDULO Studios\RUNAWAY 2 - The dream of the turtle\runaway2.exe [2543616]
[MD5.00000000000000000000000000000000] [APT] [{3FBD547C-8DDE-4618-8119-FDBAF2872833}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0]
[MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{40578DFC-2D38-40B7-8527-65AEB3C8CF61}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752]
[MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{49F28A68-CD56-4F9F-BBE7-D3828E2E0D1D}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752]
[MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{53D25BB6-B56B-4D8C-8CBA-2201A82FF13F}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752]
[MD5.00000000000000000000000000000000] [APT] [{54BF14C3-36AF-4BEE-90CA-7BA896DE2EA1}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0]
[MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{8B2A43B6-9213-4FD0-999A-BED41845A40E}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752]
[MD5.00000000000000000000000000000000] [APT] [{AA21DD51-728E-473B-8D80-1990991281F9}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0]
[MD5.EB906EDD7889FBE6829EFEDBEC53A3DC] [APT] [{B4E14F8B-ABEC-46AD-8B3F-0C351B0F9965}] (...) -- C:\Program Files (x86)\PENDULO Studios\RUNAWAY 2 - The dream of the turtle\runaway2.exe [2543616]
[MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{BA2F7725-49AC-49A7-91F7-EC4DD8978CC3}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752]
[MD5.EB906EDD7889FBE6829EFEDBEC53A3DC] [APT] [{BCD169D0-5B76-4238-A278-9D103A124947}] (...) -- C:\Program Files (x86)\PENDULO Studios\RUNAWAY 2 - The dream of the turtle\runaway2.exe [2543616]
[MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{BE044ABC-14E7-4E96-ABF4-341E0BECD7BB}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752]
[MD5.00000000000000000000000000000000] [APT] [{C1E6C74A-E4A1-4842-9EB2-4B7E15BE9572}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0]
[MD5.EB906EDD7889FBE6829EFEDBEC53A3DC] [APT] [{C351A5CC-89AB-433B-8378-0D6C39776CC4}] (...) -- C:\Program Files (x86)\PENDULO Studios\RUNAWAY 2 - The dream of the turtle\runaway2.exe [2543616]
[MD5.EB906EDD7889FBE6829EFEDBEC53A3DC] [APT] [{C5F77096-F998-4DE1-9256-615A44D40874}] (...) -- C:\Program Files (x86)\PENDULO Studios\RUNAWAY 2 - The dream of the turtle\runaway2.exe [2543616]
[MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{D1853B27-F8B0-4D07-BDBB-2D76A44378EC}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752]
[MD5.00000000000000000000000000000000] [APT] [{E19C652B-E3E7-4B1E-A874-D2C7112A4337}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0]
[MD5.B73A3A0A4983610ABAD6454C09BA6F19] [APT] [{E7B95E11-326D-4119-BDC6-0A234EE2EB24}] (.TODO: .) -- C:\SG Interactive\Crossfire Europe\CF_SGIN.exe [2216752]
[MD5.00000000000000000000000000000000] [APT] [{FCFCD9F7-18D0-4D88-B613-DC2635F375C2}] (...) -- C:\Program Files (x86)\ManyCam 2.4\ManyCam.exe (.not file.) [0]
[MD5.EB906EDD7889FBE6829EFEDBEC53A3DC] [APT] [{FD3054B5-5079-451D-AECB-2A2478BEE9EE}] (...) -- C:\Program Files (x86)\PENDULO Studios\RUNAWAY 2 - The dream of the turtle\runaway2.exe [2543616]
~ Scheduled Task: 49 Legitimates Filtered in 00mn 07s



---\\ Pilotes lanc�s au d�marrage (O41)
O41 - Driver: (appdrv01) . (.Protection Technology - Application Driver (01).) - C:\Windows\System32\Drivers\appdrv01.sys
~ Drivers: 69 Legitimates Filtered in 00mn 00s



---\\ Logiciels install�s (O42)
O42 - Logiciel: Audiggle version 3.0.0.1 - (.Audiggle LTD.) [HKLM][64Bits] -- {FCAD9ED0-C00F-45FA-91DB-F89140EFAB3A}_is1
O42 - Logiciel: Lexicon Alpha Driver - (.Lexicon.) [HKLM][64Bits] -- Lexicon Alpha Driver
O42 - Logiciel: Lexicon Pantheon VST Plug-in (remove only) - (...) [HKLM][64Bits] -- LexiconStudio
O42 - Logiciel: PokerStars.fr - (.PokerStars.fr.) [HKLM][64Bits] -- PokerStars.fr
~ Logic: 152 Legitimates Filtered in 00mn 01s



---\\ HKCU & HKLM Software Keys
[HKCU\Software\Audiggle LTD]
[HKCU\Software\CFLoader]
[HKCU\Software\Guy]
[HKCU\Software\Lexicon]
[HKCU\Software\Nohope92]
[HKCU\Software\PMU]
[HKCU\Software\PartoucheFR]
[HKCU\Software\PatchPoker]
[HKCU\Software\Prodipe]
[HKLM\Software\Wow6432Node\Guy]
[HKLM\Software\Wow6432Node\Prodipe]
~ Key Software: 336 Legitimates Filtered in 00mn 01s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 25/05/2013 - 13:06:06 - [0] ----D C:\Program Files (x86)\Ascentive
O43 - CFD: 01/12/2011 - 08:58:30 - [2,554] ----D C:\Program Files (x86)\Audiggle
O43 - CFD: 06/07/2012 - 17:28:11 - [2,214] ----D C:\Program Files (x86)\Lexicon
O43 - CFD: 06/06/2012 - 17:43:25 - [0,000] ----D C:\Program Files (x86)\LimeWire
O43 - CFD: 02/07/2010 - 13:06:55 - [6,205] ----D C:\Program Files (x86)\OOBOX
O43 - CFD: 25/06/2010 - 02:23:10 - [0] ----D C:\Program Files (x86)\poker
O43 - CFD: 21/12/2012 - 20:51:15 - [144,504] ----D C:\Program Files (x86)\PokerStars.FR
O43 - CFD: 17/11/2010 - 21:05:02 - [2,590] ----D C:\Program Files (x86)\PokerTracker 3
O43 - CFD: 09/07/2010 - 22:29:42 - [1,031] ----D C:\Program Files (x86)\Shareaza
O43 - CFD: 11/05/2013 - 15:27:47 - [1,277] ----D C:\Program Files (x86)\SoulseekQt =>P2P.SoulSeek
O43 - CFD: 23/03/2012 - 22:24:09 - [38,653] ----D C:\ProgramData\Ascentive
O43 - CFD: 03/09/2010 - 12:42:27 - [0,053] ----D C:\ProgramData\WSG32
O43 - CFD: 25/10/2010 - 03:14:24 - [0,001] ----D C:\Users\modesta\AppData\Roaming\fr.barrierepoker.air.D043989C8F5E91300BF71855036B28F854BB8613.1
O43 - CFD: 01/12/2011 - 09:26:18 - [0] ----D C:\Users\modesta\AppData\Roaming\MusicBrainz
O43 - CFD: 12/09/2010 - 14:55:24 - [9,333] ----D C:\Users\modesta\AppData\Roaming\Partouche Poker
O43 - CFD: 12/09/2010 - 14:55:55 - [0] ----D C:\Users\modesta\AppData\Roaming\PokerAcademyPro2
O43 - CFD: 09/07/2010 - 22:28:38 - [0,014] ----D C:\Users\modesta\AppData\Roaming\Shareaza
O43 - CFD: 01/12/2011 - 09:00:28 - [0,001] ----D C:\Users\modesta\AppData\Local\Audiggle_LTD
O43 - CFD: 15/05/2013 - 00:44:44 - [0,001] ----D C:\Users\modesta\AppData\Local\DarkOS
O43 - CFD: 08/04/2013 - 19:53:00 - [0,001] ----D C:\Users\modesta\AppData\Local\GNHacks
O43 - CFD: 16/02/2013 - 18:33:12 - [0,006] ----D C:\Users\modesta\AppData\Local\Injector
O43 - CFD: 30/04/2013 - 03:47:06 - [0,001] ----D C:\Users\modesta\AppData\Local\kokicrossfireinjector
O43 - CFD: 09/03/2013 - 21:29:33 - [0,001] ----D C:\Users\modesta\AppData\Local\MetreInjector
O43 - CFD: 04/06/2013 - 13:09:12 - [3,972] ----D C:\Users\modesta\AppData\Local\PokerStars.FR
O43 - CFD: 08/07/2010 - 23:59:45 - [0,029] ----D C:\Users\modesta\AppData\Local\Shareaza
O43 - CFD: 29/01/2012 - 21:15:36 - [0,001] ----D C:\Users\modesta\AppData\Local\Team_CP9_Injector_V1
O43 - CFD: 06/07/2012 - 17:28:11 - [0,001] ----D C:\Users\modesta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lexicon
~ Program Folder: 325 Legitimates Filtered in 02mn 03s



---\\ Derniers fichiers modifi�s ou cr�es sous Windows et System32 (O44)
O44 - LFC:[MD5.F390146AE3A191CF2C6F7E06F7A79D6A] - 12/06/2013 - 21:48:33 ---A- . (...) -- C:\Windows\DeleteOnReboot.bat [98]
O44 - LFC:[MD5.2BD357F2A8CBB722F19091DA27DB0B34] - 12/06/2013 - 13:59:45 ---A- . (...) -- C:\Windows\RUNAWAY2.INI [59]
~ Files: 139 Legitimates Filtered in 00mn 37s



---\\ Derniers fichiers cr��s dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.E00A6CB3BFDB47BB4F8C078722CC8A59] - 14/06/2013 - 14:41:04 ---A- - C:\Windows\Prefetch\REASON.EXE-66F26968.pf
O45 - LFCP:[MD5.6B8636818A9C7E0FF07A284719098723] - 14/06/2013 - 14:41:11 ---A- - C:\Windows\Prefetch\QREGDEFRAG_SETUP-2.9.TMP-2472B975.pf
O45 - LFCP:[MD5.3C8D00317FA689B2DEB9440F02357116] - 14/06/2013 - 14:41:16 ---A- - C:\Windows\Prefetch\QREGDEFRAG_SETUP-2.9.EXE-169A3ADB.pf
O45 - LFCP:[MD5.393A6DF13AA8B70BFB11768831B0282A] - 14/06/2013 - 14:41:17 ---A- - C:\Windows\Prefetch\QREGDEFRAG_SETUP-2.9.TMP-824471D4.pf
O45 - LFCP:[MD5.3F1417D21493DD2AC3D312479F7847BF] - 14/06/2013 - 14:47:11 ---A- - C:\Windows\Prefetch\_IU14D2N.TMP-AFA910DB.pf
O45 - LFCP:[MD5.BA1748758C75393D0F077C16712A3793] - 14/06/2013 - 14:53:40 ---A- - C:\Windows\Prefetch\LUA5.1A_GUI.EXE-E6CC1E22.pf
O45 - LFCP:[MD5.983D430C3FC29B0D5E2C8A851EED8388] - 14/06/2013 - 15:01:36 ---A- - C:\Windows\Prefetch\ULTRADEFRAG-6.0.2.BIN.AMD64.E-3352AEF7.pf
O45 - LFCP:[MD5.86075700A208FC9E8971255CE6B14D68] - 14/06/2013 - 15:09:13 ---A- - C:\Windows\Prefetch\GBTRAY.EXE-9E7D26AC.pf
O45 - LFCP:[MD5.EAC14DF077D0C46FF922C4BEA7BC7D33] - 14/06/2013 - 15:09:31 ---A- - C:\Windows\Prefetch\CF_SGIN.EXE-A6C9DC7C.pf
O45 - LFCP:[MD5.68815DB10BC6E307D9AF2BDE5987DB3B] - 14/06/2013 - 15:09:41 ---A- - C:\Windows\Prefetch\PATCHER_CF.EXE-2E8B1AFA.pf
O45 - LFCP:[MD5.44F0BA2B164748296E212AD73FBC8B39] - 14/06/2013 - 15:09:43 ---A- - C:\Windows\Prefetch\CF_SGI.EXE-413EE366.pf
O45 - LFCP:[MD5.E7763C7D34EA64FF335D2706FE725A9E] - 14/06/2013 - 15:09:59 ---A- - C:\Windows\Prefetch\HGWC.EXE-E846B28C.pf
O45 - LFCP:[MD5.1AA7D1F7A67F2C95F4BE7118D27906FE] - 14/06/2013 - 15:10:21 ---A- - C:\Windows\Prefetch\CROSSFIRE.EXE-1734A2D7.pf
O45 - LFCP:[MD5.FB6880AA20046B1D86249A719F28CA4A] - 14/06/2013 - 15:10:29 ---A- - C:\Windows\Prefetch\XTRAP.XT-D0CB15BB.pf
O45 - LFCP:[MD5.1DF51CE1B91E895F6882DF230E467CF6] - 14/06/2013 - 15:14:59 ---A- - C:\Windows\Prefetch\BOOST.EXE-927029AA.pf
~ Prefetcher: 111 Legitimates Filtered in 00mn 01s



---\\ MountPoints2 Shell Key (O51)
O51 - MPSK:{6f727110-a885-11e0-bed1-c80aa92458ab}\AutoRun\command. (...) -- G:\setup.exe (.not file.)
~ Keys: Scanned in 00mn 00s



---\\ ShareTools MSconfig StartupReg (O53)
O53 - SMSR:HKLM\...\startupreg\Pando Media Booster [Key] . (.Pas de propri�taire - Pando Media Booster.) -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
~ SMSR Keys: 24 Legitimates Filtered in 00mn 00s



---\\ Microsoft Windows Policies System (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 19 Legitimates Filtered in 00mn 00s



---\\ Microsoft Windows Policies Explorer (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s



---\\ Liste des Drivers Syst�me (O58)
O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088]
O58 - SDL:[MD5.ACEA6D0C2BFC5DA45FA570668E904C29] - 07/05/2004 - 14:31:46 ---A- . (.Service & Quality Technology. - Universal Serial Bus Camera Driver.) -- C:\Windows\SysWOW64\drivers\Camd905c.sys [24382]
O58 - SDL:[MD5.67F389181B6B5B3910381657754124B4] - 06/07/2012 - 16:18:18 ---A- . (...) -- C:\Windows\SysWOW64\audcon.sys [2892]
~ Drivers: Scanned in 00mn 00s



---\\ Derniers fichiers modifi�s ou cr�es (Utilisateur) (O61)
O61 - LFC: 12/06/2013 - 11:52:03 ---A- C:\Users\modesta\Downloads\13-1-legacy_vista_win7_win8_64_dd_ccc.exe [154092488]
O61 - LFC: 12/06/2013 - 12:42:49 ---A- C:\Users\modesta\AppData\Local\Resmon.ResmonCfg [7630]
O61 - LFC: 12/06/2013 - 13:19:44 ---A- C:\Users\modesta\Downloads\installer_directx_French.exe [2458560]
O61 - LFC: 12/06/2013 - 14:48:36 ---A- C:\Users\modesta\Downloads\adwcleaner.exe [648201]
O61 - LFC: 12/06/2013 - 21:44:50 ---A- C:\Users\modesta\Downloads\AdwCleaner (1).exe [648201]
O61 - LFC: 12/06/2013 - 22:19:56 ---A- C:\Users\modesta\Documents\Cross Fire\Replay\CFReplay20130612_0000kid.cfr [4664166]
O61 - LFC: 13/06/2013 - 00:40:18 ---A- C:\Users\modesta\Downloads\bdcamsetup.exe [7062616]
O61 - LFC: 13/06/2013 - 11:45:17 -SHA- C:\Users\modesta\Documents\Bandicam\Thumbs.db [10752]
O61 - LFC: 13/06/2013 - 12:28:24 ---A- C:\Users\modesta\Downloads\avast_free_antivirus_setup.exe [117478104]
O61 - LFC: 13/06/2013 - 12:47:21 ---A- C:\Users\modesta\Downloads\jre-6u45-windows-x64.exe [17355184]
O61 - LFC: 13/06/2013 - 12:56:06 ---A- C:\Users\modesta\Downloads\vlc-2.0.7-win32.exe [22937227]
O61 - LFC: 13/06/2013 - 15:51:51 ---A- C:\Users\modesta\AppData\Roaming\wklnhst.dat [1080]
O61 - LFC: 13/06/2013 - 20:03:43 ---A- C:\Users\modesta\Downloads\WindowsUpdateDiagnostic.diagcab [173620]
O61 - LFC: 13/06/2013 - 21:48:37 ---A- C:\Users\modesta\AppData\Local\GDIPFONTCACHEV1.DAT [99400]
O61 - LFC: 13/06/2013 - 21:53:33 ---A- C:\Users\modesta\Downloads\Crossfire_downloader.exe [2999088]
O61 - LFC: 13/06/2013 - 21:53:46 ---A- C:\Users\modesta\AppData\Local\PMB Files\cert\secmod.db [16384] =>P2P.Pando
O61 - LFC: 13/06/2013 - 22:07:05 ---A- C:\Users\modesta\Downloads\RogueKiller.exe [907776]
O61 - LFC: 13/06/2013 - 22:12:26 ---A- C:\Users\modesta\AppData\Local\PMB Files\pando.save [918] =>P2P.Pando
O61 - LFC: 13/06/2013 - 22:12:41 ---A- C:\Users\modesta\AppData\Local\PMB Files\cert\cert8.db [65536] =>P2P.Pando
O61 - LFC: 13/06/2013 - 22:12:41 ---A- C:\Users\modesta\AppData\Local\PMB Files\cert\key3.db [16384] =>P2P.Pando
O61 - LFC: 14/06/2013 - 12:27:19 ---A- C:\Users\modesta\AppData\Local\Google\Chrome\User Data\Certificate Revocation Lists [270908]
O61 - LFC: 14/06/2013 - 14:36:04 ---A- C:\Users\modesta\Downloads\RegSeeker-2.5.zip [9714]
O61 - LFC: 14/06/2013 - 14:40:08 ---A- C:\Users\modesta\Downloads\qregdefrag_setup-2.9.exe [1837290]
O61 - LFC: 14/06/2013 - 14:50:01 ---A- C:\Users\modesta\Downloads\ultradefrag-6.0.2.bin.amd64.exe [692869]
O61 - LFC: 14/06/2013 - 15:01:18 ---A- C:\Users\modesta\AppData\Roaming\Propellerhead Software\Reason\Reason Preferences.prf [8888]
O61 - LFC: 14/06/2013 - 15:11:11 ---A- C:\Users\modesta\Documents\Cross Fire\SaveIdData.dat [27]
O61 - LFC: 14/06/2013 - 15:11:44 ---A- C:\Users\modesta\Documents\Cross Fire\System.dat [94]
O61 - LFC: 14/06/2013 - 16:43:39 ---A- C:\Users\modesta\AppData\Local\Google\Chrome\User Data\Local State [35152]
~ 26 Fichiers temporaires (Temporary files)
~ Files: 230 Legitimates Filtered in 01mn 48s



---\\ Liste des outils de nettoyage (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
~ ADS: Scanned in 00mn 00s



---\\ Liste des services Legacy (O64)
O64 - Services: CurCS - 01/11/2010 - C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys (WinRing0_1_2_0) .(.OpenLibSys.org - WinRing0.) - LEGACY_WINRING0_1_2_0
O64 - Services: CurCS - ??\??\???? - Pas de propri�taire (XFDriver64) .(...) - LEGACY_XFDRIVER64
~ Legacy: 140 Legitimates Filtered in 00mn 02s



---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 18 Legitimates Filtered in 00mn 00s



---\\ Start Menu Internet (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Search Browser Infection (O69)
O69 - SBI: SearchScopes [HKCU] {3CAFC3C0-DFF5-4E7D-92EC-7CAF0A57EBA6} - (Yahoo! Search) - http://fr.search.yahoo.com
O69 - SBI: SearchScopes [HKCU] {D6311C12-96AD-4063-B4B1-6C5C53A19E3B} - (Bing) - http://www.bing.com
~ Keys: Scanned in 00mn 00s



---\\ Crack & Keygen Files (O82)
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\IMG1_WaveLab.jpg
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\IMG2_WaveLab.jpg
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\Readme!.txt
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Extra\Wavpack Plugin\ReadMe.txt
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Extra\Wavpack Plugin\Wavpack4Wlab6 Setup.msi
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Deutsch\WaveLab.chm
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Deutsch\WaveLab.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Deutsch\WaveLab_61_Addendum.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\English\WaveLab.chm
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\English\WaveLab.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\English\WaveLab_61_Addendum.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\French\WaveLab.chm
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\French\WaveLab.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\French\WaveLab_61_Addendum.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\HelpMap.txt
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Japanese\WaveLab.chm
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Japanese\WaveLab.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Japanese\WaveLab_61_Addendum_JP.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\ReadMe.htm
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Setup.exe
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\wl6emu.exe
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install notes!.txt
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Setup.exe
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH].rar
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\IMG1_WaveLab.jpg
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\IMG2_WaveLab.jpg
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\Readme!.txt
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Extra\Wavpack Plugin\ReadMe.txt
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Extra\Wavpack Plugin\Wavpack4Wlab6 Setup.msi
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Deutsch\WaveLab.chm
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Deutsch\WaveLab.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Deutsch\WaveLab_61_Addendum.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\English\WaveLab.chm
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\English\WaveLab.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\English\WaveLab_61_Addendum.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\French\WaveLab.chm
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\French\WaveLab.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\French\WaveLab_61_Addendum.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\HelpMap.txt
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Japanese\WaveLab.chm
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Japanese\WaveLab.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Data\Help\Japanese\WaveLab_61_Addendum_JP.pdf
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\ReadMe.htm
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\Setup.exe
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install\wl6emu.exe
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Install notes!.txt
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH]\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR)\WaveLab 6.1.1_Setup\Setup.exe
C:\Users\modesta\Desktop\HIPHOPISDREAM\00000.nico.com c le taf tupepatest\UTILITAIRE\Steinberg WaveLab 6.1.1.353 (Cracked by TEAM AiR) [RH]\SWL.6.1.1.353_[RH].rar
~ Files: Scanned in 03mn 07s



---\\ Recherche particuliere � la racine de certains dossiers (O84)
[MD5.B9270BA1B0D210F786D2E001A7BB902B] [SPRF][13/06/2013] (.Eclipse Foundation - SWT for Windows native library.) -- C:\Users\modesta\AppData\Local\Temp\swt-win32-3740.dll [430080]
[MD5.A1D10793082FF32A7A9C99CA6572B05A] [SPRF][13/06/2013] (...) -- C:\Users\modesta\AppData\Roaming\wklnhst.dat [1080]
[MD5.49CA27A490977A69E1D562AF4E7FDE95] [SPRF][13/06/2013] (...) -- C:\Users\modesta\Desktop\RogueKiller.exe [907776]
[MD5.19EF6FE92855D6CC84CDD628D44B2EC5] [SPRF][14/06/2013] (.Nicolas Coolman - ZHPDiag.) -- C:\Users\modesta\Desktop\ZHPDiag2.exe [5678428]
~ Files: Scanned in 00mn 00s



---\\ Firewall Active Exception List (FirewallRules) (O87)
O87 - FAEL: "{6CAE1305-C374-4091-91EA-987ADDC7C70A}" | In - Public - P6 - TRUE | .(.Neowiz Games - Crossfire Patcher.) -- C:\SG Interactive\Crossfire Europe\patcher_cf.exe
O87 - FAEL: "{BFB9AFC2-738D-4FE7-AF24-032B79C18FB6}" | In - Public - P17 - TRUE | .(.Neowiz Games - Crossfire Patcher.) -- C:\SG Interactive\Crossfire Europe\patcher_cf.exe
O87 - FAEL: "{8457D48B-4061-4D04-8E8A-3345098AAD17}" | In - Domain - P6 - FALSE | .(.Neowiz Games - Crossfire Patcher.) -- C:\SG Interactive\Crossfire Europe\patcher_cf.exe
O87 - FAEL: "{1FD19848-CE04-44DA-B2DC-AB67A6425847}" | In - Domain - P17 - FALSE | .(.Neowiz Games - Crossfire Patcher.) -- C:\SG Interactive\Crossfire Europe\patcher_cf.exe
~ Firewall: 224 Legitimates Filtered in 00mn 01s



---\\ Scan Additionnel (O88)
Database Version : v2.12472 - (13/06/2013)
Cl�s trouv�es (Keys found) : 0
Valeurs trouv�es (Values found) : 0
Dossiers trouv�s (Folders found) : 0
Fichiers trouv�s (Files found) : 0

~ Additionnel Scan: 431578 Items scanned in 00mn 43s



---\\ Etat g�n�ral des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SR - | Auto 02/03/2009 89600 | (AESTFilters) . (.Andrea Electronics Corporation.) - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\AESTSr64.exe
SR - | Auto 05/08/2009 203264 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SS - | Auto 29/06/2010 551896 | (appdrvrem01) . (.Protection Technology.) - C:\Windows\System32\appdrvrem01.exe
SR - | Auto 24/05/2012 55184 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 09/05/2013 46808 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
SS - | Demand 05/05/2009 228408 | (Com4QLBEx) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\ezsvc7.dll (ezSharedSvc) . (.EasyBits Sofware AS.) - C:\Windows\System32\svchost.exe
SS - | Auto 04/06/2013 116648 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 04/06/2013 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SR - | Auto 27/09/2012 86528 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
SS - | Demand 10/08/2012 1001376 | (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
SR - | Auto 346976 | (HWDeviceService64.exe) . (...) - C:\ProgramData\DatacardService\HWDeviceService64.exe
SS - | Demand 04/04/2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
SR - | Auto 23/09/2011 641832 | (NAUpdate) . (.Nero AG.) - C:\Program Files (x86)\Nero\Update\NASvc.exe
SS - | Demand ??\??\???? 0 | (npggsvc) . (.INCA Internet Co., Ltd..) - C:\Windows\system32\GameMon.des
SR - | Auto 10/12/2009 65536 | (pgsql-8.3) . (.PostgreSQL Global Development Group.) - C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe
SR - | Auto 247152 | (RichVideo) . (...) - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
SS - | Auto 08/01/2013 161536 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SR - | Auto 22/07/2009 240128 | (STacSV) . (.IDT, Inc..) - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_ccf0dd3cb081af84\STacSV64.exe
SR - | Auto 23/12/2009 370688 | (StarWindServiceAE) . (.StarWind Software.) - C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
SR - | Auto 07/06/2013 4150112 | (TeamViewer8) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
SR - | Auto 14/07/2009 27136 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 01s



---\\ Recherche Master Boot Record Infection (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Run by modesta at 14/06/2013 17:49:42

device: opened successfully
user: error reading MBR

Disk trace:
error: Read Descripteur non valide
kernel: error reading MBR
~ MBR: 9 Legitimates Filtered in 00mn 02s



---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by modesta at 14/06/2013 17:49:44

********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s



~ 1991 Legitimates filtered by white list
End of the scan (644 lines in 10mn 38s)(48)








Publicité


Signaler le contenu de ce document

Publicité