Aller au contenu
Zebulon

Sandy

Membres
  • Compteur de contenus

    50
  • Inscription

  • Dernière visite

Messages posté(e)s par Sandy

  1. Bonsoir

     

    Voici les log des differentes analyses demandées

     

    MBAM

    --------

    Malwarebytes' Anti-Malware 1.50.1.1100

    www.malwarebytes.org

     

    Version de la base de données: 5979

     

    Windows 5.1.2600 Service Pack 3

    Internet Explorer 7.0.5730.13

     

    07/03/2011 17:29:29

    mbam-log-2011-03-07 (17-29-28).txt

     

    Type d'examen: Examen complet (C:\|E:\|F:\|)

    Elément(s) analysé(s): 804723

    Temps écoulé: 5 heure(s), 36 minute(s), 20 seconde(s)

     

    Processus mémoire infecté(s): 0

    Module(s) mémoire infecté(s): 0

    Clé(s) du Registre infectée(s): 0

    Valeur(s) du Registre infectée(s): 0

    Elément(s) de données du Registre infecté(s): 0

    Dossier(s) infecté(s): 0

    Fichier(s) infecté(s): 8

     

    Processus mémoire infecté(s):

    (Aucun élément nuisible détecté)

     

    Module(s) mémoire infecté(s):

    (Aucun élément nuisible détecté)

     

    Clé(s) du Registre infectée(s):

    (Aucun élément nuisible détecté)

     

    Valeur(s) du Registre infectée(s):

    (Aucun élément nuisible détecté)

     

    Elément(s) de données du Registre infecté(s):

    (Aucun élément nuisible détecté)

     

    Dossier(s) infecté(s):

    (Aucun élément nuisible détecté)

     

    Fichier(s) infecté(s):

    f:\HASSAN\programes files\program files\pdfforge toolbar\searchsettings.dll (PUP.Dealio) -> Quarantined and deleted successfully.

    f:\HASSAN\programes files\program files\pdfforge toolbar\searchsettings.exe (PUP.Dealio) -> Quarantined and deleted successfully.

    f:\HASSAN\programes files\program files\pdfforge toolbar\searchsettingsres409.dll (PUP.Dealio) -> Quarantined and deleted successfully.

    f:\HASSAN\programes files\program files\pdfforge toolbar\widgihelper.exe (PUP.Dealio) -> Quarantined and deleted successfully.

    f:\HASSAN\programes files\program files\pdfforge toolbar\SSFF\components\searchsettingsff.dll (PUP.Dealio) -> Quarantined and deleted successfully.

    f:\HASSAN\programes files\program files\pdfforge toolbar\FF\components\pdfforgetoolbarff.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.

    f:\HASSAN\programes files\program files\pdfforge toolbar\IE\1.1.2\pdfforgetoolbarie.dll (PUP.Dealio) -> Quarantined and deleted successfully.

    f:\HASSAN\programes files\program files\application updater\applicationupdater.exe (PUP.Dealio) -> Quarantined and deleted successfully.

     

     

    AD_REMOVER

    --------------------

    ======= RAPPORT D'AD-REMOVER 2.0.0.2,F | UNIQUEMENT XP/VISTA/7 =======

     

    Mis à jour par TeamXscript le 01/03/11

    Contact: AdRemover[DOT]contact[AT]gmail[DOT]com

    Site web: TeamXscript : AD-Remover - FindyKill - UsbFix - SEAF

     

    C:\Program Files\Ad-Remover\main.exe (SCAN [2]) -> Lancé à 19:15:57 le 07/03/2011, Mode normal

     

    Microsoft Windows XP Professionnel Service Pack 3 (X86)

    Sandy@KILL_BILL ( )

     

    ============== RECHERCHE ==============

     

     

     

    Clé trouvée: HKLM\Software\Classes\TypeLib\{090ACFA1-1580-11D1-8AC0-00C0F00910F9}

    Clé trouvée: HKLM\Software\Classes\TypeLib\{B4E90801-B83C-11D0-8B40-00C0F00AE35A}

    Clé trouvée: HKLM\Software\PopCap

     

     

    ============== SCAN ADDITIONNEL ==============

     

    **** Mozilla Firefox Version [3.6.13 (fr)] ****

     

    Plugins\npdnu.dll (AOL LLC)

    Plugins\npdnupdater2.dll (AOL LLC)

    HKLM_MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5 (x)

     

    -- C:\Documents and Settings\Sandy\Application Data\Mozilla\FireFox\Profiles\rf2clfwr.default --

    Extensions\firebug@software.joehewitt.com (Firebug)

    Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} (Forecastfox Weather)

    Extensions\{4D1E692F-D179-413b-A987-EEEAAD85DDB3} (MapQuest Toolbar)

    Extensions\{a6ca9b3b-5e52-4f47-85d8-cca35bb57596} (Sage)

    Searchplugins\aol-search.xml (?)

    Prefs.js - browser.startup.homepage, hxxp://www.google.fr

    Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.2.13

     

    -- C:\Documents and Settings\Eddy Terra\Application Data\Mozilla\FireFox\Profiles\5rrldg75.default --

    Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.2.13

     

    ========================================

     

    **** Internet Explorer Version [7.0.5730.13] ****

     

    HKCU_Main|Default_Page_URL - hxxp://g.uk.msn.com/USSMB/7

    HKCU_Main|Search bar - hxxp://search.msn.com/sphome.aspx

    HKCU_Main|Search Page - hxxp://www.live.com

    HKCU_Main|Start Page - hxxp://www.google.fr/

    HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=69157

    HKLM_Main|Default_Search_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896

    HKLM_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896

    HKLM_Main|Start Page - hxxp://go.microsoft.com/fwlink/?LinkId=69157

    HKCU_Toolbar|{710EB7A1-45ED-11D0-924A-0020AFC7AC4D} (x)

    HKCU_Toolbar\WebBrowser|{47833539-D0C5-4125-9FA8-0819E2EAAC93} (x)

    HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)

    BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)

    BHO\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - "Search Helper" (C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll)

     

    ========================================

     

    C:\Program Files\Ad-Remover\Quarantine: 0 Fichier(s)

    C:\Program Files\Ad-Remover\Backup: 2 Fichier(s)

     

    C:\Ad-Report-SCAN[1].txt - 07/03/2011 19:07:38 (2827 Octet(s))

    C:\Ad-Report-SCAN[2].txt - 07/03/2011 19:16:02 (2273 Octet(s))

     

    Fin à: 19:16:36, 07/03/2011

     

    ============== E.O.F ==============

     

     

    ======= RAPPORT D'AD-REMOVER 2.0.0.2,F | UNIQUEMENT XP/VISTA/7 =======

     

    Mis à jour par TeamXscript le 01/03/11

    Contact: AdRemover[DOT]contact[AT]gmail[DOT]com

    Site web: TeamXscript : AD-Remover - FindyKill - UsbFix - SEAF

     

    C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 19:19:43 le 07/03/2011, Mode normal

     

    Microsoft Windows XP Professionnel Service Pack 3 (X86)

    Administrateur@KILL_BILL ( )

     

    ============== ACTION(S) ==============

     

     

     

    (!) -- Fichiers temporaires supprimés.

     

     

    Clé supprimée: HKLM\Software\Classes\TypeLib\{090ACFA1-1580-11D1-8AC0-00C0F00910F9}

    Clé supprimée: HKLM\Software\Classes\TypeLib\{B4E90801-B83C-11D0-8B40-00C0F00AE35A}

    Clé supprimée: HKLM\Software\PopCap

     

     

    ============== SCAN ADDITIONNEL ==============

     

    **** Mozilla Firefox Version [3.6.13 (fr)] ****

     

    Plugins\npdnu.dll (AOL LLC)

    Plugins\npdnupdater2.dll (AOL LLC)

    HKLM_MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5 (x)

     

    -- C:\Documents and Settings\Eddy Terra\Application Data\Mozilla\FireFox\Profiles\5rrldg75.default --

    Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.2.13

     

    -- C:\Documents and Settings\Sandy\Application Data\Mozilla\FireFox\Profiles\rf2clfwr.default --

    Extensions\firebug@software.joehewitt.com (Firebug)

    Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} (Forecastfox Weather)

    Extensions\{4D1E692F-D179-413b-A987-EEEAAD85DDB3} (MapQuest Toolbar)

    Extensions\{a6ca9b3b-5e52-4f47-85d8-cca35bb57596} (Sage)

    Searchplugins\aol-search.xml (?)

    Prefs.js - browser.startup.homepage, hxxp://www.google.fr

    Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.2.13

     

    ========================================

     

    **** Internet Explorer Version [7.0.5730.13] ****

     

    HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

    HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

    HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896

    HKCU_Main|Start Page - hxxp://fr.msn.com/

    HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896

    HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

    HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm

    HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

    HKLM_Main|Start Page - hxxp://fr.msn.com/

    HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)

    BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)

    BHO\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - "Search Helper" (C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll)

     

    ========================================

     

    C:\Program Files\Ad-Remover\Quarantine: 0 Fichier(s)

    C:\Program Files\Ad-Remover\Backup: 15 Fichier(s)

     

    \Ad-Report-CLEAN[1].txt - 07/03/2011 19:19:47 (483 Octet(s))

    \Ad-Report-SCAN[1].txt - 07/03/2011 19:07:38 (2870 Octet(s))

    \Ad-Report-SCAN[2].txt - 07/03/2011 19:16:02 (2893 Octet(s))

     

    Fin à: 19:20:19, 07/03/2011

     

    ============== E.O.F ==============

     

     

    J'ai effectué les différentes mises à jour demandées.

     

    Les différentes analyses et suppressions des malwares/Toolbars n'ont pas eu d'effets. Le PC plante irrémédiablement dans Outlook à l'affichage de messages ou suite à des clic droits...:(

     

     

    Voiluche

  2. Bonjour

     

    Merci de ta réponse voici le rapport demandé.

     

    N.B. : Je fais des backup toutes les semaines de mes données.

     

     

    Rapport de ZHPDiag v1.27.1626 par Nicolas Coolman, Update du 01/03/2011

    Run by Sandy at 04/03/2011 12:10:41

    Web site : ZHPDiag Outil de diagnostic

    Contact : nicolascoolman@yahoo.fr

     

    ---\\ Web Browser

    MSIE: Internet Explorer v7.0.5730.13

    MFIE: Mozilla Firefox v3.6.13 (fr) (Defaut)

     

    ---\\ System Information

    Windows XP Professional Service Pack 3 (Build 2600)

    Processor: x86 Family 6 Model 23 Stepping 7, GenuineIntel

    Operating System: 32 Bits

    Boot mode: Normal (Normal boot)

    Total RAM: 2046 MB (58% free)

    System Restore: Activé (Enable)

    System drive C: has 265 GB (56%) free of 466 GB

     

    ---\\ Logged in mode

    Computer Name: KILL_BILL

    User Name: Sandy

    All Users Names: SUPPORT_388945a0, Sandy, HelpAssistant, Eddy Terra, ASPNET, Administrateur,

    Unselected Option: O45,O61,O62,O65,O66,O82

    Logged in as Administrator

     

    ---\\ Environnement Variables

    %AppData%=C:\Documents and Settings\Sandy\Application Data

    %LocalAppData%=C:\Documents and Settings\Sandy\Local Settings\Application Data

    %StartMenu%=C:\Documents and Settings\Sandy\Menu Démarrer

     

    ---\\ DOS/Devices

    C:\ Hard drive, Flash drive, Thumb drive (Free 265 Go of 466 Go)

    D:\ CD-ROM drive (Free 0 Go of 0 Go)

    E:\ Hard drive, Flash drive, Thumb drive (Free 20 Go of 466 Go)

     

     

    ---\\ Security Center & Tools Informations

    [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK

    [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK

    [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK

    [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK

    [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK

     

     

    ---\\ Recherche particulière de fichiers génériques

    [MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) (.14/04/2008 13:00:00.) -- C:\Windows\Explorer.exe [1037824]

    [MD5.FB22AE2861836D16FCBAECB1B715752E] - (.Microsoft Corporation - Internet Extensions for Win32.) (.21/12/2010 00:06:56.) -- C:\Windows\System32\wininet.dll [832512]

    [MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.14/04/2008 13:00:00.) -- C:\Windows\System32\Winlogon.exe [512000]

    [MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.14/04/2008 00:40:32.) -- C:\Windows\System32\drivers\atapi.sys [96512]

    [MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.14/04/2008 13:00:00.) -- C:\Windows\System32\drivers\ntfs.sys [574976]

     

     

    ---\\ Processus lancés

    [MD5.AC78982EAE5CA0F4BBC418E9C5ED3845] - (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) -- C:\WINDOWS\system32\Ati2evxx.exe [638976]

    [MD5.43232A9BA2C65971C0462AFE9B325017] - (.Wacom Technology, Corp. - Touch Service.) -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe [416112]

    [MD5.7207DB389CEAD101251883511A676F91] - (.Avira GmbH - Antivirus Scheduler.) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe [135336]

    [MD5.AC5D343FCF038C851F9DDB893B60FA97] - (.Avira GmbH - Antivirus On-Access Service.) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe [267944]

    [MD5.020EC70045C677B40FEA89C3FE483137] - (.Apache Software Foundation - Apache HTTP Server.) -- C:\Program Files\Apache Group\Apache2\bin\Apache.exe [20550]

    [MD5.70D7BE78061126DD0C3ACCDB7E129017] - (.Apple Inc. - Apple Mobile Device Service.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [144672]

    [MD5.CDE000884FD7BAF0C1FDFE029B0891DE] - (.Avira GmbH - AntiVir shadow copy service.) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe [76968]

    [MD5.5E06A9D23727DAF96FAA796F1135FDCD] - (.Sun Microsystems, Inc. - Java Quick Starter Service.) -- C:\Program Files\Java\jre6\bin\jqs.exe [153376]

    [MD5.EF2C875A4DCED27482A0FA123D3F331E] - (...) -- C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe [6574720]

    [MD5.777115C9CC675BD98127660712D2F784] - (.SupportSoft, Inc. - SupportSoft Agent Service.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968]

    [MD5.A508A09387FBEFDF9E73633CF4080D9B] - (.Wacom Technology, Corp. - Tablet Service for consumer driver.) -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe [4869488]

    [MD5.FAB13554E86325F5CC1041E7537DC8F2] - (.Apache Software Foundation - Commons Daemon Service Runner.) -- C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe [61440]

    [MD5.FFA821F9E2D1FE5FB9B54EA0A01983E1] - (.Wacom Technology, Corp. - Tablet user module for consumer driver.) -- C:\Program Files\Tablet\Pen\Pen_TabletUser.exe [1153392]

    [MD5.3E42C4691AAD4B1E8D0466F9CBF05CBE] - (.Intel Corporation - RAID Monitor.) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [354840]

    [MD5.EA5872F1BC10D8A830BBB41F2EAF34E0] - (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.EXE [16806912]

    [MD5.186C9D39541CC0DFFCC454F79AA0B0BF] - (.CyberLink Corp. - CyberLink PowerDVD Resident Program.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [128296]

    [MD5.D3804513FC9C11A4637392B4F0F43BC5] - (.Intel Corporation - Event Monitor User Notification Tool.) -- C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [182808]

    [MD5.00D1FB0073B4A8BD2989EA8FF4CC792B] - (.SupportSoft, Inc. - Dell Support Center Updates.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe [206064]

    [MD5.98FAFD82E4F0674D2D7BB3C8FD141D32] - (.Adobe Sytems Incorporated - Adobe Version Cue CS2.) -- C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe [856064]

    [MD5.9D5E8B45BD348DF0882C69EED0E83111] - (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [281768]

    [MD5.DDACBCA1D0E66BBA5C984842F372A6D4] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [421160]

    [MD5.3FD46312B435095EC6F001A9B000AC47] - (.Apache Software Foundation - Commons Daemon Service Manager.) -- C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5w.exe [98304]

    [MD5.E7704CBF568815C1CAA6E513387BD3F2] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Monitoring program.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe [65536]

    [MD5.2E5212A0BFB98FE0167C92C76C87AFE3] - (.Sun Microsystems, Inc. - Java Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe [249064]

    [MD5.43D083268A0919F3527A2837390BAF63] - (.Macrovision Corporation - Macrovision Software Manager.) -- C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe [218032]

    [MD5.0E6E43D31AC16BCF682EB5F63178C492] - (.Adobe Systems Inc. - AcroTray.) -- C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [49254]

    [MD5.045552CDB233417A9DC8DA31B6FB2E3C] - (...) -- C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe [36955]

    [MD5.F4D6D11C89616549652067E7C8FA1ADF] - (.Dropbox, Inc. - Dropbox.) -- C:\Documents and Settings\Sandy\Application Data\Dropbox\bin\Dropbox.exe [23343848]

    [MD5.3A19B2D2B5659D375FFFBA9EB71987B8] - (.OpenOffice.org - OpenOffice.org 3.1.) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe [7424000]

    [MD5.EEBD0B763F32A26421A35CC2C735E8E3] - (.OpenOffice.org - OpenOffice.org 3.1.) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin [7418368]

    [MD5.7A9DE9202630CBED9A17525C480FF68B] - (.Fred's Software - Pas de description.) -- C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe [869888]

    [MD5.12C358D7E2B3BFD478FA2833555F5DF7] - (...) -- C:\Program Files\SpamPal\spampal.exe [387616]

    [MD5.CCE5D71F19AB70D969F9819B5C88438D] - (.ATI Technologies Inc. - Catalyst Control Center: Host application.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe [65536]

    [MD5.DCB3796E0169419618C72F0CE34C68ED] - (.Apple Inc. - iPodService Module (32-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [820008]

    [MD5.54F7805158746902D1554F76590866EA] - (.Wacom Technology, Corp. - Touch User Mode Driver.) -- C:\Program Files\Tablet\Pen\Pen_TouchUser.exe [2954608]

    [MD5.2DCC5C800F51D487178814CA9EADA181] - (.Microsoft Corporation - Bloc-notes.) -- C:\WINDOWS\system32\NOTEPAD.EXE [70656]

    [MD5.0E20A3213ED010FC4997D1EF48082ABC] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [912344]

    [MD5.BA9A09CF1B9503C363617F3748F6D791] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [16856]

    [MD5.FE10BD8390A37F3A1F7506244A5C98C1] - (.Pas de propriétaire - ERMLicSrv_ATL Module.) -- C:\WINDOWS\system32\ERM\7.1\ERMLicSrv_ATL71.exe [94208]

    [MD5.D804D54E70E15078DFF46F9543A5E151] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [632320]

     

     

    ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)

    M3 - MFPP: Plugins - [sandy] -- C:\Documents and Settings\Sandy\Application Data\Mozilla\Firefox\Profiles\rf2clfwr.default\searchplugins\aol-search.xml

    M3 - MFPP: Plugins - [sandy] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml

    M3 - MFPP: Plugins - [sandy] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml

    M3 - MFPP: Plugins - [sandy] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml

    M3 - MFPP: Plugins - [sandy] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml

    M3 - MFPP: Plugins - [sandy] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml

    M3 - MFPP: Plugins - [sandy] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml

    P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files\Mozilla Firefox\Plugins\np-mswmp.dll

    P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeployJava1.dll

    P2 - FPN:Firefox Plugin Navigator . (.AOL LLC - npdnu.) -- C:\Program Files\Mozilla Firefox\Plugins\npdnu.dll

    P2 - FPN:Firefox Plugin Navigator . (.AOL LLC - npdnupdater2.) -- C:\Program Files\Mozilla Firefox\Plugins\npdnupdater2.dll

    P2 - FPN:Firefox Plugin Navigator . (.mozilla.org - Default Plug-in.) -- C:\Program Files\Mozilla Firefox\Plugins\npnul32.dll

    P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL

    P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFFICE.DLL

    P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape "9.4.2".) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll

    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin.dll

    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin2.dll

    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin3.dll

    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin4.dll

    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin5.dll

    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin6.dll

    P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin7.dll

    P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

    P2 - FPN: [HKLM] [@adobe.com/ShockwavePlayer] - (.Adobe Systems, Inc. - Adobe Shockwave for Director Netscape plug-in, version 11.5.) -- C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

    P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

    P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

    P2 - FPN: [HKLM] [@google.com/npPicasa3,version=3.0.0] - (.Google, Inc. - Picasa plugin.) -- C:\Program Files\Google\Picasa3\npPicasa3.dll

    P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_24 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

    P2 - FPN: [HKLM] [@ma-config.com/HardwareDetection] - (.Cybelsoft - Plugin NPAPI Ma-Config.com.) -- C:\Program Files\ma-config.com\nphardwaredetection.dll

    P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.60129.0.) -- c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll

    P2 - FPN: [HKLM] [@microsoft.com/OfficeLive,version=1.3] - (.Microsoft Corp. - Office Live Update v1.3.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll

    P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8081.0709] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

    P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

    P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=8] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll

    P2 - FPN: [HKLM] [@wacom.com/wacom-plugin,version=1.1.0.5] - (.Wacom, Inc. - Wacom Dynamic Link Library.) -- C:\Program Files\TabletPlugins\npwacom.dll

    M0 - MFSP: prefs.js [sandy - rf2clfwr.default] Google

    M2 - MFEP: prefs.js [sandy - rf2clfwr.default\firebug@software.joehewitt.com] [] Firebug v1.6.2 (.Joe Hewitt.)

    M2 - MFEP: prefs.js [sandy - rf2clfwr.default\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}] [] Forecastfox Weather v2.0.2 (.Jon Stritar.)

    M2 - MFEP: prefs.js [sandy - rf2clfwr.default\{20a82645-c095-46ed-80e3-08825760534b}] [MicrosoftCG] Microsoft .NET Framework Assistant v1.2.1 (.Microsoft.)

    M2 - MFEP: prefs.js [sandy - rf2clfwr.default\{4D1E692F-D179-413b-A987-EEEAAD85DDB3}] [] MapQuest Toolbar v1.2.1 (.MapQuest, Inc.)

    M2 - MFEP: prefs.js [sandy - rf2clfwr.default\{a6ca9b3b-5e52-4f47-85d8-cca35bb57596}] [] Sage v1.4.9 (.The Sage Team.)

     

     

    ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Search Microsoft.com

    R0 - HKUS\S-1-5-21-4159549855-2446266082-2188733381-1006\Software\Microsoft\Internet Explorer\Main,Start Page = Google

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Search Microsoft.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Search Microsoft.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Search Microsoft.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk

    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = Bing

    R1 - HKUS\S-1-5-21-4159549855-2446266082-2188733381-1006\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In

    R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (7.00.6000.17095 (vista_gdr.101217-1830)) -- C:\WINDOWS\system32\ieframe.dll

    R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 1

     

     

    ---\\ Internet Explorer, Proxy Management (R5)

    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key

    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0

    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1

    R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1

    R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

     

     

    ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,

    F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

     

     

    ---\\ Browser Helper Objects de navigateur (O2)

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline

    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} . (.Microsoft Corporation - Search Helper for Internet Explorer.) -- C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- C:\Program Files\Windows Live\Toolbar\wltcore.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} . (.Sun Microsystems, Inc. - Java Quick Starter binary.) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

     

     

    ---\\ Internet Explorer Toolbars (O3)

    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- C:\Program Files\Windows Live\Toolbar\wltcore.dll

    O3 - Toolbar: (no name) - {710EB7A1-45ED-11D0-924A-0020AFC7AC4D} . (.Pas de propriétaire - Pas de description.) -- (.not file.)

     

     

    ---\\ Applications démarrées par registre & par dossier (O4)

    O4 - HKLM\..\Run: [RTHDCPL] . (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\Windows\RTHDCPL.exe

    O4 - HKLM\..\Run: [PDVDDXSrv] . (.CyberLink Corp. - CyberLink PowerDVD Resident Program.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

    O4 - HKLM\..\Run: [iAAnotif] . (.Intel Corporation - Event Monitor User Notification Tool.) -- C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe

    O4 - HKLM\..\Run: [dscactivate] . (...) -- C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe

    O4 - HKLM\..\Run: [DellSupportCenter] . (.SupportSoft, Inc. - Dell Support Center Updates.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe

    O4 - HKLM\..\Run: [Alcmtr] . (.Realtek Semiconductor Corp. - Realtek Azalia Audio - Event Monitor.) -- C:\Windows\ALCMTR.exe

    O4 - HKLM\..\Run: [Adobe Version Cue CS2] . (.Adobe Sytems Incorporated - Adobe Version Cue CS2.) -- C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe

    O4 - HKLM\..\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    O4 - HKLM\..\Run: [AdobeCS4ServiceManager] . (.Adobe Systems Incorporated - Adobe CS4 Service Manager.) -- C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe

    O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe

    O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe

    O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe

    O4 - HKLM\..\Run: [ApacheTomcatMonitor] . (.Apache Software Foundation - Commons Daemon Service Manager.) -- C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5w.exe

    O4 - HKLM\..\Run: [startCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    O4 - HKLM\..\Run: [ATICustomerCare] . (.Advanced Micro Devices, Inc. - ATI Customer Care.) -- C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe

    O4 - HKCU\..\Run: [iSUSPM] . (.Macrovision Corporation - Macrovision Software Manager.) -- C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe

    O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe

    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe

    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe

    O4 - HKUS\S-1-5-21-4159549855-2446266082-2188733381-1006\..\Run: [iSUSPM] . (.Macrovision Corporation - Macrovision Software Manager.) -- C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe

    O4 - HKUS\S-1-5-21-4159549855-2446266082-2188733381-1006\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Démarrage\Acrobat Assistant.lnk . (.Adobe Systems Inc..) -- C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma.lnk . (.Adobe Systems, Inc..) -- C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Démarrage\Monitor Apache Servers.lnk . (...) -- C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe

    O4 - Global Startup: C:\Documents And Settings\Sandy\Menu Démarrer\Programmes\Démarrage\Dropbox.lnk . (.Dropbox, Inc..) -- C:\Documents and Settings\Sandy\Application Data\Dropbox\bin\Dropbox.exe

    O4 - Global Startup: C:\Documents And Settings\Sandy\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 3.1.lnk . (...) -- C:\Program Files\OpenOffice.org 3\program\quickstart.exe

    O4 - Global Startup: C:\Documents And Settings\Sandy\Menu Démarrer\Programmes\Démarrage\PrintKey 2000 Fr.lnk . (.Fred's Software.) -- C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe

    O4 - Global Startup: C:\Documents And Settings\Sandy\Menu Démarrer\Programmes\Démarrage\SpamPal.lnk . (...) -- C:\Program Files\SpamPal\spampal.exe

     

     

    ---\\ Autres liens utilisateurs (O4)

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Acrobat Distiller 5.0.lnk . (.Adobe Systems Incorporated..) -- C:\Program Files\Adobe\Acrobat 5.0\Distillr\acrodist.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Bridge CS4.lnk . (.Adobe Systems, Inc..) -- C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Bridge.lnk . (.Adobe Systems, Inc..) -- C:\Program Files\Adobe\Adobe Bridge\Bridge.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Device Central CS4.lnk . (.Adobe Systems.) -- C:\Program Files\Adobe\Adobe Device Central CS4\DeviceCentral.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Drive CS4.lnk . (.Adobe Systems Incorporated.) -- C:\Program Files\Fichiers communs\Adobe\Adobe Drive CS4\ConnectUI\Adobe Drive CS4.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe ExtendScript Toolkit CS4.lnk . (.Adobe Systems Incorporated.) -- C:\Program Files\Adobe\Adobe Utilities\ExtendScript Toolkit CS4\ExtendScript Toolkit.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Extension Manager CS4.lnk . (.Adobe Systems Incorporated.) -- C:\Program Files\Adobe\Adobe Extension Manager CS4\Adobe Extension Manager CS4.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Flash CS4 Professional.lnk . (.Adobe Systems Incorporated..) -- C:\Program Files\Adobe\Adobe Flash CS4\Flash.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Help Center.lnk . (.Adobe Systems Incorporated.) -- C:\Program Files\Adobe\Adobe Help Center\ahc.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Illustrator CS2.lnk . (.Adobe Systems, Inc..) -- C:\Program Files\Adobe\Adobe Illustrator CS2\Support Files\Contents\Windows\Illustrator.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe ImageReady CS2.lnk . (.Adobe Systems Incorporated.) -- C:\Program Files\Adobe\Adobe Photoshop CS2\ImageReady.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe InDesign CS2.lnk . (.Adobe Systems Incorporated.) -- C:\Program Files\Adobe\Adobe InDesign CS2\InDesign.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Media Encoder CS4.lnk . (.Adobe Systems, Incorporated.) -- C:\Program Files\Adobe\Adobe Media Encoder CS4\Adobe Media Encoder.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Photoshop CS2.lnk . (.Adobe Systems, Incorporated.) -- C:\Program Files\Adobe\Adobe Photoshop CS2\Photoshop.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Pixel Bender Toolkit.lnk . (...) -- C:\Program Files\Adobe\Adobe Utilities\Pixel Bender Toolkit\pixel_bender_toolkit.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Reader 9.lnk . (...) -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-A94000000001}\SC_Reader.ico

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Apple Software Update.lnk . (...) -- C:\WINDOWS\Installer\{C41300B9-185D-475E-BFEC-39EF732F19B1}\AppleSoftwareUpdateIco.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\GeoConcept 5.0.lnk . (...) -- C:\Program Files\GeoConcept 5.0\Wingeo.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\GeoConcept.lnk . (...) -- C:\Program Files\Geoconcept66GCIS40185\Wingeo.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Lanceur de tâches Microsoft Works.lnk . (.Microsoft® Corporation.) -- C:\Program Files\Microsoft Works\MSWorks.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\MultiViewer.lnk . (.GeoConcept.) -- C:\Program Files\Geoconcept66GCIS40185\Multiviewer.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\PowerDVD DX.lnk . (.CyberLink Corp..) -- C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Safari.lnk . (...) -- C:\WINDOWS\Installer\{AFAC914D-9E83-4A89-8ABE-427521C82CCF}\SafariIco.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\SyncToy 2.0.lnk . (...) -- C:\WINDOWS\Installer\{AFDFC350-C142-4790-BE12-8357AECD028F}\_6FEFF9B68218417F98F549.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Visionneuse Microsoft Office PowerPoint 2007.lnk . (...) -- C:\WINDOWS\Installer\{95120000-00AF-040C-0000-0000000FF1CE}\ppvwicon.exe

    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Movie Maker.LNK . (.Microsoft Corporation.) -- C:\Program Files\Movie Maker\moviemk.exe

    O4 - Global Startup: C:\Documents And Settings\Sandy\Menu Démarrer\Programmes\Assistance à distance.LNK . (.Microsoft Corporation.) -- C:\WINDOWS\system32\rcimlby.exe

    O4 - Global Startup: C:\Documents And Settings\Sandy\Menu Démarrer\Programmes\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe

    O4 - Global Startup: C:\Documents And Settings\Sandy\Menu Démarrer\Programmes\Outlook Express.LNK . (.Microsoft Corporation.) -- C:\Program Files\Outlook Express\msimn.exe

    O4 - Global Startup: C:\Documents And Settings\Sandy\Menu Démarrer\Programmes\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe

     

     

    ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)

    O8 - Extra context menu item: Add to Google Photos Screensa&ver . (.Google Inc. - Google Photos Screensaver.) -- C:\WINDOWS\system32\GPhotos.scr

    O8 - Extra context menu item: Ajouter la cible du lien à un fichier PDF existant - (.not file.) - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

    O8 - Extra context menu item: Ajouter à un fichier PDF existant - (.not file.) - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

    O8 - Extra context menu item: Convertir au format Adobe PDF - (.not file.) - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

    O8 - Extra context menu item: Convertir la cible du lien au format Adobe PDF - (.not file.) - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

    O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.exe

     

     

    ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)

    O9 - Extra button: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: &Ajout Direct dans Windows Live Writer - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~1\MICROS~3\OFFICE11\REFBARH.ICO

    O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~1\MICROS~3\OFFICE11\REFBARH.ICO

    O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe

     

     

    ---\\ Winsock hijacker (Layered Service Provider) (O10)

    O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll

    O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll

    O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll

    O10 - WLSP:\000000000004\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll

     

     

    ---\\ Objets ActiveX (Downloaded Program Files)(O16)

    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - Technical difficulties

     

     

    ---\\ Modification Domaine/Adresses DNS (O17)

    O17 - HKLM\System\CCS\Services\Tcpip\..\{E01A3F13-2F13-4AF7-B8ED-C8BBF01B25B6}: DhcpNameServer = 192.168.1.1

    O17 - HKLM\System\CS1\Services\Tcpip\..\{E01A3F13-2F13-4AF7-B8ED-C8BBF01B25B6}: DhcpNameServer = 192.168.1.1

    O17 - HKLM\System\CS3\Services\Tcpip\..\{E01A3F13-2F13-4AF7-B8ED-C8BBF01B25B6}: DhcpNameServer = 192.168.1.1

    O17 - HKLM\System\CCS\Services\Tcpip\..\{E01A3F13-2F13-4AF7-B8ED-C8BBF01B25B6}: DhcpDomain = lan

    O17 - HKLM\System\CS1\Services\Tcpip\..\{E01A3F13-2F13-4AF7-B8ED-C8BBF01B25B6}: DhcpDomain = lan

    O17 - HKLM\System\CS3\Services\Tcpip\..\{E01A3F13-2F13-4AF7-B8ED-C8BBF01B25B6}: DhcpDomain = lan

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

     

     

    ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)

    O20 - Winlogon Notify: AtiExtEvent . (.ATI Technologies Inc. - ATI External Event Utility DLL Module.) -- C:\Windows\System32\Ati2evxx.dll

    O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\Windows\System32\crypt32.dll

    O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\Windows\System32\cryptnet.dll

    O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\Windows\System32\cscdll.dll

    O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\System32\dimsntfy.dll

    O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll

    O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll

    O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\Windows\System32\sclgntfy.dll

    O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\WlNotify.dll

    O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll

    O20 - Winlogon Notify: WgaLogon . (.Microsoft Corporation - Notifications Windows Genuine Advantage.) -- C:\Windows\System32\WgaLogon.dll

    O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll

     

     

    ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)

    O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll

    O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll

    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll

    O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\system32\stobject.dll

    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll

     

     

    ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)

    O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll

     

     

    ---\\ Liste des services NT non Microsoft et non désactivés (O23)

    O23 - Service: (Adobe LM Service) . (.Adobe Systems - System Level Service Utility.) - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe

    O23 - Service: (Adobe Version Cue CS2) . (.Adobe Systems Incorporated - Adobe Version Cue CS2.) - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe

    O23 - Service: (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: (Apache2) . (.Apache Software Foundation - Apache HTTP Server.) - C:\Program Files\Apache Group\Apache2\bin\Apache.exe

    O23 - Service: (Apple Mobile Device) . (.Apple Inc. - Apple Mobile Device Service.) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: (Ati HotKey Poller) . (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) - C:\WINDOWS\system32\Ati2evxx.exe

    O23 - Service: (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: (BrlAPI) - Clé orpheline

    O23 - Service: (dmadmin) . (.Microsoft Corp., Veritas Software - Processus du service Gestionnaire de disque.) - C:\WINDOWS\System32\dmadmin.exe

    O23 - Service: (ERMLicSrv_ATL71) . (.Pas de propriétaire - ERMLicSrv_ATL Module.) - C:\WINDOWS\system32\ERM\7.1\ERMLicSrv_ATL71.exe

    O23 - Service: (FLEXnet Licensing Service) . (.Acresso Software Inc. - Activation Licensing Service.) - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: (GeoConceptService) . (.GEO CONCEPT - GCIS - Executable - GeoConcept Service.) - C:\Program Files\Geoconcept66GCIS40185\GeoSvc.exe

    O23 - Service: (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: (gusvc) . (.Google - gusvc.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: (IAANTMON) . (.Intel Corporation - RAID Monitor.) - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    O23 - Service: (iPod Service) . (.Apple Inc. - iPodService Module (32-bit).) - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: (JavaQuickStarterService) . (.Sun Microsystems, Inc. - Java Quick Starter Service.) - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: (maconfservice) . (.CybelSoft - Service de détection matériel.) - C:\Program Files\ma-config.com\maconfservice.exe

    O23 - Service: (Macromedia Licensing Service) . (.Pas de propriétaire - System Level Service Utilty.) - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe

    O23 - Service: (MySQL) - Clé orpheline

    O23 - Service: (sprtsvc_dellsupportcenter) . (.SupportSoft, Inc. - SupportSoft Agent Service.) - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

    O23 - Service: (stllssvr) . (.MicroVision Development, Inc. - SureThing Labelflash Disc Printer Service M.) - C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe

    O23 - Service: (TabletServicePen) . (.Wacom Technology, Corp. - Tablet Service for consumer driver.) - C:\Program Files\Tablet\Pen\Pen_Tablet.exe

    O23 - Service: (Tomcat5) . (.Apache Software Foundation - Commons Daemon Service Runner.) - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe

    O23 - Service: (TouchServicePen) . (.Wacom Technology, Corp. - Touch Service.) - C:\Program Files\Tablet\Pen\Pen_TouchService.exe

     

     

    ---\\ Enumération Active Desktop & MHTML Editor (O24)

    O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Office Word.) - C:\Program Files\Microsoft Office\OFFICE11\WINWORD.exe

     

     

    ---\\ Tâches planifiées en automatique (O39)

    O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

    O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job

    O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

    [MD5.187E0D2AB859AD03393DDD731076BE81] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe

    [MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe

    [MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe

     

     

    ---\\ Pilotes lancés au démarrage (O41)

    O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys

    O41 - Driver: (avgio) . (.Avira GmbH - Avira AntiVir Support for Minifilter.) - C:\Program Files\Avira\AntiVir Desktop\avgio.sys

    O41 - Driver: (avipbb) . (.Avira GmbH - Avira Driver for Security Enhancement.) - C:\Windows\System32\DRIVERS\avipbb.sys

    O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys

    O41 - Driver: (DLARTL_M) . (.Roxio - Shared Driver Component.) - C:\Windows\System32\Drivers\DLARTL_M.sys

    O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\System32\DRIVERS\i8042prt.sys

    O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\Windows\System32\DRIVERS\imapi.sys

    O41 - Driver: (intelppm) . (.Microsoft Corporation - Pilote de périphérique processeur.) - C:\Windows\System32\DRIVERS\intelppm.sys

    O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\Windows\System32\DRIVERS\ipsec.sys

    O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\System32\DRIVERS\kbdclass.sys

    O41 - Driver: (kbdhid) . (.Microsoft Corporation - Pilote de filtre souris HID.) - C:\Windows\System32\DRIVERS\kbdhid.sys

    O41 - Driver: (Mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\System32\DRIVERS\mouclass.sys

    O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\Windows\System32\DRIVERS\mrxsmb.sys

    O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys

    O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys

    O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\System32\DRIVERS\rasacd.sys

    O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\System32\DRIVERS\rdbss.sys

    O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys

    O41 - Driver: (redbook) . (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) - C:\Windows\System32\DRIVERS\redbook.sys

    O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\Windows\System32\DRIVERS\serial.sys

    O41 - Driver: (ssmdrv) . (.Avira GmbH - AVIRA SnapShot Driver.) - C:\Windows\System32\DRIVERS\ssmdrv.sys

    O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\Windows\System32\DRIVERS\tcpip.sys

    O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys

    O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys

     

     

    ---\\ Logiciels installés (O42)

    O42 - Logiciel: 7-Zip 4.65 - (.Pas de propriétaire.) [HKLM] -- 7-Zip

    O42 - Logiciel: ATI Catalyst Registration - (.ATI Technologies Inc..) [HKLM] -- {11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}

    O42 - Logiciel: ATI Stream SDK v2 Developer - (.ATI Technologies Inc..) [HKLM] -- {0ED98038-0885-F902-C419-669ADE471A46}

    O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM] -- Adobe AIR

    O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM] -- {197A3012-8C85-4FD3-AB66-9EC7E13DB92E}

    O42 - Logiciel: Adobe Acrobat 5.0 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Acrobat 5.0

    O42 - Logiciel: Adobe Anchor Service CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {1618734A-3957-4ADD-8199-F973763109A8}

    O42 - Logiciel: Adobe Bridge 1.0 - (.Adobe Systems.) [HKLM] -- {B74D4E10-6884-0000-0000-000000000103}

    O42 - Logiciel: Adobe Bridge CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {83877DB1-8B77-45BC-AB43-2BAC22E093E0}

    O42 - Logiciel: Adobe CMaps CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {94D398EB-D2FD-4FD1-B8C4-592635E8A191}

    O42 - Logiciel: Adobe CSI CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0F723FC1-7606-4867-866C-CE80AD292DAF}

    O42 - Logiciel: Adobe Color EU Recommended Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0DC0E85F-36E4-463B-B3EA-4CD8ED2222A1}

    O42 - Logiciel: Adobe Color JA Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {0D6013AB-A0C7-41DC-973C-E93129C9A29F}

    O42 - Logiciel: Adobe Color NA Extra Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {098A2A49-7CF3-4F08-A38D-FB879117152A}

    O42 - Logiciel: Adobe Common File Installer - (.Adobe System Incorporated.) [HKLM] -- {8EDBA74D-0686-4C99-BFDD-F894678E5101}

    O42 - Logiciel: Adobe Creative Suite 2 - (.Pas de propriétaire.) [HKLM] -- {0134A1A1-C283-4A47-91A1-92F19F960372}

    O42 - Logiciel: Adobe Default Language CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {C52E3EC1-048C-45E1-8D53-10B0C6509683}

    O42 - Logiciel: Adobe Device Central CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {67F0E67A-8E93-4C2C-B29D-47C48262738A}

    O42 - Logiciel: Adobe Drive CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {16E16F01-2E2D-4248-A42F-76261C147B6C}

    O42 - Logiciel: Adobe Dynamiclink Support - (.Adobe Systems Incorporated.) [HKLM] -- {60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}

    O42 - Logiciel: Adobe ExtendScript Toolkit CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F8EF2B3F-C345-4F20-8FE4-791A20333CD5}

    O42 - Logiciel: Adobe Extension Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {054EFA56-2AC1-48F4-A883-0AB89874B972}

    O42 - Logiciel: Adobe Flash CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F6E99614-F042-4459-82B7-8B38B2601356}

    O42 - Logiciel: Adobe Flash CS4 Extension - Flash Lite STI fr - (.Adobe Systems Incorporated.) [HKLM] -- {BD423B54-8668-44B6-8610-D24514445E88}

    O42 - Logiciel: Adobe Flash CS4 Professional - (.Adobe Systems Incorporated.) [HKLM] -- Adobe_a68eec966ce913ddaa63251dc82ed31

    O42 - Logiciel: Adobe Flash CS4 STI-fr - (.Adobe Systems Incorporated.) [HKLM] -- {48F9998C-3BA0-42D3-82E6-5882441EB8CE}

    O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX

    O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems, Inc..) [HKLM] -- {3A6829EF-0791-4FDD-9382-C690DD0821B9}

    O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin

    O42 - Logiciel: Adobe Help Center 1.0 - (.Adobe Systems.) [HKLM] -- {E9787678-119F-4D52-B551-6739B2B22101}

    O42 - Logiciel: Adobe Linguistics CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {931AB7EA-3656-4BB7-864D-022B09E3DD67}

    O42 - Logiciel: Adobe Media Encoder CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}

    O42 - Logiciel: Adobe Output Module - (.Adobe Systems Incorporated.) [HKLM] -- {BB4E33EC-8181-4685-96F7-8554293DEC6A}

    O42 - Logiciel: Adobe PDF Library Files CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {F93C84A6-0DC6-42AF-89FA-776F7C377353}

    O42 - Logiciel: Adobe Reader 9.4.2 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A94000000001}

    O42 - Logiciel: Adobe SVG Viewer 3.0 - (.Pas de propriétaire.) [HKLM] -- Adobe SVG Viewer

    O42 - Logiciel: Adobe Search for Help - (.Adobe Systems Incorporated.) [HKLM] -- {F0E64E2E-3A60-40D8-A55D-92F6831875DA}

    O42 - Logiciel: Adobe Service Manager Extension - (.Adobe Systems Incorporated.) [HKLM] -- {4943EFF5-229F-435D-BEA9-BE3CAEA783A7}

    O42 - Logiciel: Adobe Setup - (.Adobe Systems Incorporated.) [HKLM] -- {EED50C97-C79E-4149-BD82-7C5A22437708}

    O42 - Logiciel: Adobe Shockwave Player 11.5 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Shockwave Player

    O42 - Logiciel: Adobe Stock Photos 1.0 - (.Adobe Systems.) [HKLM] -- {786C5747-0C40-4930-9AFE-113BCE553101}

    O42 - Logiciel: Adobe Type Support CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {820D3F45-F6EE-4AAF-81EF-CE21FF21D230}

    O42 - Logiciel: Adobe Update Manager CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {05308C4E-7285-4066-BAE3-6B50DA6ED755}

    O42 - Logiciel: Adobe WinSoft Linguistics Plugin - (.Adobe Systems Incorporated.) [HKLM] -- {3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}

    O42 - Logiciel: Adobe XMP Panels CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {3A4E8896-C2E7-4084-A4A4-B8FD1894E739}

    O42 - Logiciel: AdobeColorCommonSetCMYK - (.Adobe Systems Incorporated.) [HKLM] -- {E5FCED12-3E77-4C0E-A305-5AEB38A52A70}

    O42 - Logiciel: AdobeColorCommonSetRGB - (.Adobe Systems Incorporated.) [HKLM] -- {16E6D2C1-7C90-4309-8EC4-D2212690AAA4}

    O42 - Logiciel: Apache HTTP Server 2.0.64 - (.Apache Software Foundation.) [HKLM] -- {3A862C7D-0504-48BC-AEF8-7F7479C7C158}

    O42 - Logiciel: Apache Tomcat 5.5 (remove only) - (.Pas de propriétaire.) [HKLM] -- Apache Tomcat 5.5

    O42 - Logiciel: Apago PDF Enhancer 3.2 - (.Apago, Inc..) [HKLM] -- Apago PDF Enhancer

    O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {DAEAFD68-BB4A-4507-A241-C8804D2EA66D}

    O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}

    O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {C41300B9-185D-475E-BFEC-39EF732F19B1}

    O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM] -- {DCE8CD14-FBF5-4464-B9A4-E18E473546C7}

    O42 - Logiciel: Avira AntiVir Personal - Free Antivirus - (.Avira GmbH.) [HKLM] -- Avira AntiVir Desktop

    O42 - Logiciel: Bamboo - (.Wacom Technology Corp..) [HKLM] -- Pen Tablet Driver

    O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {FF1C31AE-0CDC-40CE-AB85-406F8B70D643}

    O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner

    O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM] -- {5FD89EA1-99C2-40EE-BBF5-20F8991ED756}

    O42 - Logiciel: Color Network ScanGear Ver.2.42 - (.CANON INC..) [HKLM] -- {D1ADE2BF-32D3-4EC3-9BF4-F5E1A740F92E}

    O42 - Logiciel: Connect - (.Adobe Systems Incorporated.) [HKLM] -- {B29AD377-CC12-490A-A480-1452337C618D}

    O42 - Logiciel: DH Driver Cleaner Professional Edition - (.Ruud Ketelaars.) [HKLM] -- Driver Cleaner Pro

    O42 - Logiciel: Dell Support Center (Support Software) - (.Dell.) [HKLM] -- {E3BFEE55-39E2-4BE0-B966-89FE583822C1}

    O42 - Logiciel: Diagnostics Utility - (.Realtek.) [HKLM] -- {88253B77-33C9-4A9D-9E4C-4579E39D9158}

    O42 - Logiciel: Download Updater (AOL LLC) - (.Pas de propriétaire.) [HKLM] -- SoftwareUpdUtility

    O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKCU] -- Dropbox

    O42 - Logiciel: Désinstallation d'UltraEdit-32 - (.Pas de propriétaire.) [HKLM] -- UltraEdit-32

    O42 - Logiciel: ECW Header Editor 2.52 - (.Pas de propriétaire.) [HKLM] -- ECW Header Editor

    O42 - Logiciel: ECW Imagery Plugin 2.2 for Photoshop® - (.Pas de propriétaire.) [HKLM] -- {418E0169-12D1-4848-BEB6-A3564ABEA0A1}

    O42 - Logiciel: ER Mapper 7.1 - (.Pas de propriétaire.) [HKLM] -- ER Mapper 7.1

    O42 - Logiciel: ER Viewer 7.1 - (.Pas de propriétaire.) [HKLM] -- {671D7AB6-8118-4C41-B602-3001A5A949AA}

    O42 - Logiciel: FME Desktop 2010 SP2 (Build 6225 - win32) - (.Safe Software Inc..) [HKLM] -- {A46E0806-B64D-4FDE-9520-B0A3F61F4BFA}

    O42 - Logiciel: FileZilla Client 3.3.5.1 - (.Pas de propriétaire.) [HKLM] -- FileZilla Client

    O42 - Logiciel: Free DWG Viewer 6.3 - (.IGC.) [HKLM] -- {B8B4D43C-EAA0-4EEC-B93E-D4D012316286}

    O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM] -- {B131E59D-202C-43C6-84C9-68F0C37541F1}

    O42 - Logiciel: GeoConcept 5.0 (5.0.742) - (.GeoConcept SA.) [HKLM] -- {43875067-5C2D-11D5-AAAB-0050BAEB85D3}_000

    O42 - Logiciel: GeoConcept Internet Server cdis/185-1 - (.Pas de propriétaire.) [HKLM] -- {FE85862E-5689-4912-B86C-9F0B737ECAE8}

    O42 - Logiciel: GeoConcept cdgc/1545-5 - (.GeoConcept SA.) [HKLM] -- {25866E76-1146-41BE-8A88-8B400EF7E852}

    O42 - Logiciel: GeoConcept cdgc/1545-6 - (.GeoConcept SA.) [HKLM] -- {E7E3D3F9-C9E1-47D8-B468-81E67407044F}

    O42 - Logiciel: Google Earth Plug-in - (.Google.) [HKLM] -- {75AE638F-750A-11DF-96D5-005056806466}

    O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

    O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595

    O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484

    O42 - Logiciel: Hotfix for Windows Media Format 11 SDK (KB929399) - (.Microsoft Corporation.) [HKLM] -- KB929399

    O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5

    O42 - Logiciel: Hotfix for Windows XP (KB976002-v5) - (.Microsoft Corporation.) [HKLM] -- KB976002-v5

    O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3

    O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- {46ABBC54-1872-4AA3-95E2-F2C063A63F31}

    O42 - Logiciel: Intel® Matrix Storage Manager - (.Intel Corporation.) [HKLM] -- {9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}

    O42 - Logiciel: Java 6 Update 24 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216011FF}

    O42 - Logiciel: Java 6 Update 7 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160070}

    O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {E2DFE069-083E-4631-9B6C-43C48E991DE5}

    O42 - Logiciel: Lecteur Windows Media 11 - (.Pas de propriétaire.) [HKLM] -- Windows Media Player

    O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}

    O42 - Logiciel: MSXML 6.0 Parser (KB927977) - (.Microsoft Corporation.) [HKLM] -- {025B7033-5D4A-4B72-A1C2-84BE4BE2F72F}

    O42 - Logiciel: Ma-Config.com - (.Cybelsoft.) [HKLM] -- {81E95872-8357-4363-A764-8F98B28340C5}

    O42 - Logiciel: Macromedia Dreamweaver MX 2004 - (.Macromedia.) [HKLM] -- {05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}

    O42 - Logiciel: Macromedia Extension Manager - (.Macromedia.) [HKLM] -- {A5BA14E0-7384-11D4-BAE7-00409631A2C8}

    O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1

    O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Microsoft.) [HKLM] -- {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}

    O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Pas de propriétaire.) [HKLM] -- Microsoft .NET Framework 1.1 (1033)

    O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB2416447) - (.Pas de propriétaire.) [HKLM] -- M2416447

    O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB979906) - (.Pas de propriétaire.) [HKLM] -- M979906

    O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}

    O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA - (.Microsoft Corporation.) [HKLM] -- {72AD53CC-CCC0-3757-8480-9EE176866A7C}

    O42 - Logiciel: Microsoft .NET Framework 3.0 French Language Pack - (.Microsoft Corporation.) [HKLM] -- {E3C080B0-23F5-49AF-89F8-8E8DBC89E659}

    O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}

    O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA - (.Microsoft Corporation.) [HKLM] -- {0BD83598-C2EF-3343-847B-7D2E84599128}

    O42 - Logiciel: Microsoft .NET Framework 3.5 Language Pack SP1 - fra - (.Microsoft Corporation.) [HKLM] -- {3E31821C-7917-367E-938E-E65FC413EA31}

    O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1

    O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}

    O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}

    O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM] -- MSCompPackV1

    O42 - Logiciel: Microsoft Internationalized Domain Names Mitigation APIs - (.Microsoft Corporation.) [HKLM] -- IDNMitigationAPIs

    O42 - Logiciel: Microsoft National Language Support Downlevel APIs - (.Microsoft Corporation.) [HKLM] -- NLSDownlevelMapping

    O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}_PRJPROR_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}

    O42 - Logiciel: Microsoft Office Live Add-in 1.3 - (.Microsoft Corporation.) [HKLM] -- {57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}

    O42 - Logiciel: Microsoft Office Outlook Connector - (.Microsoft Corporation.) [HKLM] -- {95120000-0122-040C-0000-0000000FF1CE}

    O42 - Logiciel: Microsoft Office PowerPoint Viewer 2007 (French) - (.Microsoft Corporation.) [HKLM] -- {95120000-00AF-040C-0000-0000000FF1CE}

    O42 - Logiciel: Microsoft Office Professional Edition 2003 - (.Microsoft Corporation.) [HKLM] -- {9111040C-6000-11D3-8CFE-0150048383C9}

    O42 - Logiciel: Microsoft Office Project 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-00B4-040C-0000-0000000FF1CE}_PRJPROR_{427E1F73-275B-4344-BB19-BEFC1DD15AB6}

    O42 - Logiciel: Microsoft Office Project 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{9E73617F-2F38-4864-BD61-BB2DDFE43323}

    O42 - Logiciel: Microsoft Office Project MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-00B4-040C-0000-0000000FF1CE}

    O42 - Logiciel: Microsoft Office Project Professional 2007 - (.Microsoft Corporation.) [HKLM] -- PRJPROR

    O42 - Logiciel: Microsoft Office Project Professional 2007 - (.Microsoft Corporation.) [HKLM] -- {91120000-003B-0000-0000-0000000FF1CE}

    O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}

    O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}

    O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}

    O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}

    O42 - Logiciel: Microsoft Office Proof (German) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}

    O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}

    O42 - Logiciel: Microsoft Office Proofing (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002C-040C-0000-0000000FF1CE}

    O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}_PRJPROR_{14809F99-C601-4D4A-9391-F1E8FAA964C5}

    O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}_PRJPROR_{A0516415-ED61-419A-981D-93596DA74165}

    O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_PRJPROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}

    O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}_PRJPROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}

    O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}_PRJPROR_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}

    O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_PRJPROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}

    O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}

    O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}

    O42 - Logiciel: Microsoft Search Enhancement Pack - (.Microsoft Corporation.) [HKLM] -- {4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}

    O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}

    O42 - Logiciel: Microsoft Sync Framework Runtime Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {8A74E887-8F0F-4017-AF53-CBA42211AAA5}

    O42 - Logiciel: Microsoft Sync Framework Runtime v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {A8BD5A60-E843-46DC-8271-ABF20756BE0F}

    O42 - Logiciel: Microsoft Sync Framework Services Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {BD64AF4A-8C80-4152-AD77-FCDDF05208AB}

    O42 - Logiciel: Microsoft Sync Framework Services v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {03CAB33F-D1C2-48C6-8766-DAE84DFC25FE}

    O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- Wudf01000

    O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118}

    O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {7299052b-02a4-4627-81f2-1818da5d550d}

    O42 - Logiciel: Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}

    O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM] -- {9A25302D-30C0-39D9-BD6F-21E6EC160475}

    O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}

    O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM] -- {3B160861-7250-451E-B5EE-8B92BF30A710}

    O42 - Logiciel: MobileMe Control Panel - (.Apple Inc..) [HKLM] -- {146E206D-7D2C-493A-B431-1F1D16E822AF}

    O42 - Logiciel: Module de compatibilité pour Microsoft Office System 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0020-040C-0000-0000000FF1CE}

    O42 - Logiciel: Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.0 French Language Pack

    O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 Language Pack SP1 - fra

    O42 - Logiciel: Mozilla Firefox (3.6.13) - (.Mozilla.) [HKLM] -- Mozilla Firefox (3.6.13)

    O42 - Logiciel: MySQL Server 5.1 - (.MySQL AB.) [HKLM] -- {6A152894-9026-4DE0-9A1D-72FC215C1BFD}

    O42 - Logiciel: MySQL Tools for 5.0 - (.MySQL AB, Sun Microsystems, Inc..) [HKLM] -- {FCB10DE3-E190-4A7E-B06A-FAC61567ABFC}

    O42 - Logiciel: OGA Notifier 2.0.0048.0 - (.Microsoft Corporation.) [HKLM] -- {B2544A03-10D0-4E5E-BA69-0362FFC20D18}

    O42 - Logiciel: OpenOffice.org 3.1 - (.OpenOffice.org.) [HKLM] -- {0FA44E79-CD7D-4E8D-A2EE-26FE05F509B6}

    O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM] -- {205C6BDD-7B73-42DE-8505-9A093F35A238}

    O42 - Logiciel: PDF Settings CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {35D94F92-1D3A-43C5-8605-EA268B1A7BD9}

    O42 - Logiciel: PDF-XChange 3 - (.Tracker Software.) [HKLM] -- PDF-XChange 3_is1

    O42 - Logiciel: PSPad editor - (.Jan Fiala.) [HKLM] -- PSPad editor_is1

    O42 - Logiciel: Photoshop Camera Raw - (.Adobe Systems Incorporated.) [HKLM] -- {CC75AB5C-2110-4A7F-AF52-708680D22FE8}

    O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM] -- Picasa 3

    O42 - Logiciel: Pixel Bender Toolkit - (.Adobe Systems Incorporated.) [HKLM] -- {43509E18-076E-40FE-AF38-CA5ED400A5A9}

    O42 - Logiciel: PowerDVD - (.Dell.) [HKLM] -- {6811CAA0-BF12-11D4-9EA1-0050BAE317E1}

    O42 - Logiciel: PrintKey 2000 Fr - (.Pas de propriétaire.) [HKLM] -- PrintKey 2000 Fr

    O42 - Logiciel: Publisher for GeoConcept (2.0.34) - (.Pas de propriétaire.) [HKLM] -- {1F8D65FE-A159-4DF3-BA31-01E9F70A4DE0}

    O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {EB900AF8-CC61-4E15-871B-98D1EA3E8025}

    O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}

    O42 - Logiciel: Roxio Activation Module - (.Roxio.) [HKLM] -- {07159635-9DFE-4105-BFC0-2817DB540C68}

    O42 - Logiciel: Roxio Creator Audio - (.Roxio.) [HKLM] -- {83FFCFC7-88C6-41C6-8752-958A45325C82}

    O42 - Logiciel: Roxio Creator BDAV Plugin - (.Roxio.) [HKLM] -- {880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}

    O42 - Logiciel: Roxio Creator Copy - (.Roxio.) [HKLM] -- {619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}

    O42 - Logiciel: Roxio Creator DE - (.Roxio.) [HKLM] -- {C8B0680B-CDAE-4809-9F91-387B6DE00F7C}

    O42 - Logiciel: Roxio Creator Data - (.Roxio.) [HKLM] -- {0D397393-9B50-4C52-84D5-77E344289F87}

    O42 - Logiciel: Roxio Creator Tools - (.Roxio.) [HKLM] -- {0394CDC8-FABD-4ED8-B104-03393876DFDF}

    O42 - Logiciel: Roxio Drag-to-Disc - (.Roxio.) [HKLM] -- {2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}

    O42 - Logiciel: Roxio Express Labeler 3 - (.Roxio.) [HKLM] -- {6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}

    O42 - Logiciel: Roxio Update Manager - (.Roxio.) [HKLM] -- {30465B6C-B53F-49A1-9EBA-A3F187AD502E}

    O42 - Logiciel: Safari - (.Apple Inc..) [HKLM] -- {AFAC914D-9E83-4A89-8ABE-427521C82CCF}

    O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288621) - (.Microsoft.) [HKLM] -- {91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{5C497F0B-2061-4CC9-A61C-6B45B867354D}

    O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288931) - (.Microsoft.) [HKLM] -- {91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{CD769337-C8AC-46DB-A7DC-643E50089263}

    O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2289158) - (.Microsoft.) [HKLM] -- {91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{210B16C0-CEBD-4DE9-B474-04A7E8735E16}

    O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM] -- {91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{69F52148-9BF6-4CDC-BF76-103DEAF3DD08}

    O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) - (.Microsoft.) [HKLM] -- {91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{7F207DCA-3399-40CB-A968-6E5991B1421A}

    O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2416473

    O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM] -- {91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{3D019598-7B59-447A-80AE-815B703B84FF}

    O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM] -- {91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{FCD742B9-7A55-44BC-A776-F795F21FEDDC}

    O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM] -- {A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}

    O42 - Logiciel: SmartLabel Editor for GeoConcept (2.1.173) - (.GeoConcept SA.) [HKLM] -- {248609E4-97A8-4B1C-A8D4-80661EF30788}

    O42 - Logiciel: Sonic CinePlayer Decoder Pack - (.Sonic Solutions.) [HKLM] -- {8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}

    O42 - Logiciel: SpamPal - (.Pas de propriétaire.) [HKLM] -- {DE6CFFA1-4A51-11D6-BD6E-EF01F93E642D}

    O42 - Logiciel: Spelling Dictionaries Support For Adobe Reader 9 - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-5464-3428-900000000004}

    O42 - Logiciel: Stanza - (.Pas de propriétaire.) [HKLM] -- Stanza

    O42 - Logiciel: Suite Shared Configuration CS4 - (.Adobe Systems Incorporated.) [HKLM] -- {842B4B72-9E8F-4962-B3C1-1C422A5C4434}

    O42 - Logiciel: Suite Specific - (.Adobe Systems, Incorporated.) [HKLM] -- {C49DAA9C-5BA8-459A-8244-E57B69DF0F04}

    O42 - Logiciel: SyncToy 2.0 (x86) - (.Microsoft.) [HKLM] -- {AFDFC350-C142-4790-BE12-8357AECD028F}

    O42 - Logiciel: TWAIN FieryScan - (.Pas de propriétaire.) [HKLM] -- {B20B3E91-5E94-11D4-B650-00500488DA92}

    O42 - Logiciel: The Lord of the Rings FREE Trial - (.ATI Technologies Inc..) [HKLM] -- {8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}

    O42 - Logiciel: TopStyle Lite (Version 3) - (.Pas de propriétaire.) [HKLM] -- TSLite3_is1

    O42 - Logiciel: TopStyle Lite (Version 3) - (.Pas de propriétaire.) [HKLM] -- TopStyle Lite (Version 3.0)

    O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM] -- {91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}

    O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707

    O42 - Logiciel: Utilitaire de configuration iPhone - (.Apple Inc..) [HKLM] -- {FA54AFB1-5745-4389-B8C1-9F7509672ED1}

    O42 - Logiciel: WebTablet IE Plugin - (.Wacom Technology Corp..) [HKLM] -- Wacom WebTabletPlugin for IE

    O42 - Logiciel: WebTablet Netscape Plugin - (.Wacom Technology Corp..) [HKLM] -- Wacom WebTabletPlugin for Netscape

    O42 - Logiciel: Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray - (.Microsoft Corporation.) [HKLM] -- KB952011

    O42 - Logiciel: Windows Genuine Advantage Notifications (KB905474) - (.Microsoft Corporation.) [HKLM] -- WgaNotify

    O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM] -- KB892130

    O42 - Logiciel: Windows Internet Explorer 7 - (.Microsoft Corporation.) [HKLM] -- ie7

    O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}

    O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {3B4E636E-9D65-4D67-BA61-189800823F52}

    O42 - Logiciel: Windows Live FolderShare - (.Microsoft Corporation.) [HKLM] -- {2075CB0A-D26F-4DAA-B424-5079296B43BA}

    O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {5DD76286-9BE7-4894-A990-E905E91AC818}

    O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {770F1BEC-2871-4E70-B837-FB8525FFA3B1}

    O42 - Logiciel: Windows Live OneCare safety scanner - (.Pas de propriétaire.) [HKLM] -- Windows Live OneCare safety scanner

    O42 - Logiciel: Windows Live Toolbar - (.Microsoft Corporation.) [HKLM] -- {F7D27C70-90F5-49B9-B188-0A133C0CE353}

    O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM] -- {4634B21A-CC07-4396-890C-2B8168661FEA}

    O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11

    O42 - Logiciel: Windows Media Format 11 runtime - (.Pas de propriétaire.) [HKLM] -- Windows Media Format Runtime

    O42 - Logiciel: Windows Media Player 11 - (.Microsoft Corporation.) [HKLM] -- wmp11

    O42 - Logiciel: Windows Media Player Firefox Plugin - (.Microsoft Corp.) [HKLM] -- {69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

    O42 - Logiciel: Windows Presentation Foundation - (.Microsoft Corporation.) [HKLM] -- {BAF78226-3200-4DB4-BE33-4D922A799840}

    O42 - Logiciel: Windows Presentation Foundation Language Pack (FRA) - (.Microsoft Corporation.) [HKLM] -- {6901DD22-527A-41EF-9059-E81FEDE9E494}

    O42 - Logiciel: Windows Resource Kit Tools - SubInAcl.exe - (.Microsoft Corporation.) [HKLM] -- {D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}

    O42 - Logiciel: XML Paper Specification Shared Components Language Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- XPSEPSCLP

    O42 - Logiciel: XML Paper Specification Shared Components Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- XpsEPSC

    O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {350FB27C-CF62-4EF3-AF9D-70FF313FE221}

    O42 - Logiciel: kuler - (.Adobe Systems Incorporated.) [HKLM] -- {098727E1-775A-4450-B573-3F441F1CA243}

     

    ---\\ HKCU & HKLM Software Keys

    [HKCU\Software\7-Zip]

    [HKCU\Software\ATI Technologies Inc.]

    [HKCU\Software\ATI]

    [HKCU\Software\Adobe]

    [HKCU\Software\Alsoft]

    [HKCU\Software\Apache Software Foundation]

    [HKCU\Software\AppDataLow\Software\Macromedia]

    [HKCU\Software\AppDataLow\Software]

    [HKCU\Software\AppDataLow]

    [HKCU\Software\Apple Computer, Inc.]

    [HKCU\Software\Apple Inc.]

    [HKCU\Software\Avira]

    [HKCU\Software\Borland]

    [HKCU\Software\Bradbury]

    [HKCU\Software\CDDB]

    [HKCU\Software\Canon]

    [HKCU\Software\Classes]

    [HKCU\Software\Clients]

    [HKCU\Software\Cyberlink]

    [HKCU\Software\DELL]

    [HKCU\Software\DSCLauncher]

    [HKCU\Software\Earth Resource Mapping]

    [HKCU\Software\FileMaker]

    [HKCU\Software\Google]

    [HKCU\Software\IDM Computer Solutions]

    [HKCU\Software\IM Providers]

    [HKCU\Software\InstallShield]

    [HKCU\Software\Intel]

    [HKCU\Software\JavaSoft]

    [HKCU\Software\Local AppWizard-Generated Applications]

    [HKCU\Software\Luke Pascoe Software]

    [HKCU\Software\Macromedia]

    [HKCU\Software\Malwarebytes' Anti-Malware]

    [HKCU\Software\Mozilla]

    [HKCU\Software\MySQL AB]

    [HKCU\Software\Netscape]

    [HKCU\Software\ODBC]

    [HKCU\Software\OpenOffice.org]

    [HKCU\Software\PSPad]

    [HKCU\Software\Piriform]

    [HKCU\Software\Policies]

    [HKCU\Software\PrintKey2000]

    [HKCU\Software\Realtek]

    [HKCU\Software\Roxio]

    [HKCU\Software\Safe Software Inc.]

    [HKCU\Software\Software FX, Inc]

    [HKCU\Software\Sonic]

    [HKCU\Software\SpamPal for Windows]

    [HKCU\Software\SupportSoft]

    [HKCU\Software\Tracker Software]

    [HKCU\Software\Trolltech]

    [HKCU\Software\VB and VBA Program Settings]

    [HKCU\Software\Windows Live Writer]

    [HKCU\Software\YahooPartnerToolbar]

    [HKCU\Software\cybelsoft]

    [HKCU\Software\keyhole.com]

    [HKLM\Software\781]

    [HKLM\Software\8169Diag]

    [HKLM\Software\ATI Technologies]

    [HKLM\Software\ATI]

    [HKLM\Software\Adobe Systems Incorporated]

    [HKLM\Software\Adobe Systems]

    [HKLM\Software\Adobe]

    [HKLM\Software\Aladdin Knowledge Systems]

    [HKLM\Software\Alsoft]

    [HKLM\Software\Apache Group]

    [HKLM\Software\Apache Software Foundation]

    [HKLM\Software\AppDataLow]

    [HKLM\Software\Apple Computer, Inc.]

    [HKLM\Software\Apple Inc.]

    [HKLM\Software\Autodesk]

    [HKLM\Software\Avira]

    [HKLM\Software\Borland]

    [HKLM\Software\Bradbury]

    [HKLM\Software\C07ft5Y]

    [HKLM\Software\Canon]

    [HKLM\Software\Classes]

    [HKLM\Software\Clients]

    [HKLM\Software\CyberLink]

    [HKLM\Software\Dell]

    [HKLM\Software\DivXNetworks]

    [HKLM\Software\Earth Resource Mapping]

    [HKLM\Software\Electronics For Imaging]

    [HKLM\Software\FileZilla 3]

    [HKLM\Software\GEAR Software]

    [HKLM\Software\Gemplus]

    [HKLM\Software\GeoConcept SA]

    [HKLM\Software\GeoConcept]

    [HKLM\Software\Google]

    [HKLM\Software\IGC]

    [HKLM\Software\InstallShield]

    [HKLM\Software\Intel]

    [HKLM\Software\JavaSoft]

    [HKLM\Software\JreMetrics]

    [HKLM\Software\Khronos]

    [HKLM\Software\Lexcycle]

    [HKLM\Software\Macromedia]

    [HKLM\Software\Macrovision]

    [HKLM\Software\Malwarebytes' Anti-Malware]

    [HKLM\Software\MicroQuill]

    [HKLM\Software\MicroVision]

    [HKLM\Software\MozillaPlugins]

    [HKLM\Software\Mozilla]

    [HKLM\Software\MySQL AB]

    [HKLM\Software\ODBC]

    [HKLM\Software\OpenOffice.org]

    [HKLM\Software\Policies]

    [HKLM\Software\PopCap]

    [HKLM\Software\Program Groups]

    [HKLM\Software\ReflexiveArcade]

    [HKLM\Software\RegisteredApplications]

    [HKLM\Software\Roxio]

    [HKLM\Software\Safe Software Inc.]

    [HKLM\Software\Schlumberger]

    [HKLM\Software\Secure]

    [HKLM\Software\Sonic]

    [HKLM\Software\SupportSoft]

    [HKLM\Software\Tracker Software]

    [HKLM\Software\TrendMicro]

    [HKLM\Software\Wacom]

    [HKLM\Software\Windows 3.1 Migration Status]

    [HKLM\Software\Windows]

    [HKLM\Software\X-AVCSD]

    [HKLM\Software\cybelsoft]

    [HKLM\Software\mozilla.org]

     

     

    ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)

    O43 - CFD: 04/05/2009 - 13:55:42 - [3094515] ----D- C:\Program Files\7-Zip

    O43 - CFD: 27/07/2009 - 09:54:54 - [3283675068] ----D- C:\Program Files\Adobe

    O43 - CFD: 31/01/2011 - 18:26:02 - [70832480] ----D- C:\Program Files\Apache Group

    O43 - CFD: 01/02/2011 - 16:13:48 - [14829592] ----D- C:\Program Files\Apache Software Foundation

    O43 - CFD: 22/06/2010 - 17:32:28 - [2306366] ----D- C:\Program Files\Apple Software Update

    O43 - CFD: 23/02/2011 - 17:30:52 - [602552] ----D- C:\Program Files\ATI

    O43 - CFD: 23/02/2011 - 17:30:50 - [21016410] ----D- C:\Program Files\ATI Stream

    O43 - CFD: 23/02/2011 - 17:30:38 - [50395681] ----D- C:\Program Files\ATI Technologies

    O43 - CFD: 04/05/2009 - 11:14:56 - [165655428] ----D- C:\Program Files\Avira

    O43 - CFD: 16/02/2010 - 18:31:40 - [10139352] ----D- C:\Program Files\Bejeweled 2 Deluxe

    O43 - CFD: 02/09/2010 - 16:54:58 - [599838] ----D- C:\Program Files\Bonjour

    O43 - CFD: 17/04/2009 - 08:53:26 - [18297113] ----D- C:\Program Files\Borland

    O43 - CFD: 25/06/2009 - 11:43:10 - [4725420] ----D- C:\Program Files\Bradbury

    O43 - CFD: 29/04/2009 - 17:05:02 - [11126028] ----D- C:\Program Files\Canon

    O43 - CFD: 12/05/2010 - 17:40:58 - [2858200] ----D- C:\Program Files\CCleaner

    O43 - CFD: 25/04/2008 - 18:58:16 - [0] ----D- C:\Program Files\ComPlus Applications

    O43 - CFD: 04/02/2009 - 01:33:30 - [42328948] ----D- C:\Program Files\CyberLink

    O43 - CFD: 04/02/2009 - 01:32:50 - [16738791] ----D- C:\Program Files\Dell Support Center

    O43 - CFD: 11/02/2011 - 15:36:20 - [1841335] ----D- C:\Program Files\Driver Cleaner Pro

    O43 - CFD: 12/05/2010 - 12:23:18 - [15537714] ----D- C:\Program Files\Earth Resource Mapping

    O43 - CFD: 27/10/2010 - 14:28:50 - [1950705650] ----D- C:\Program Files\Fichiers communs

    O43 - CFD: 15/12/2010 - 18:39:46 - [22129882] ----D- C:\Program Files\FileMaker

    O43 - CFD: 24/02/2011 - 16:34:42 - [16451399] ----D- C:\Program Files\FileZilla FTP Client

    O43 - CFD: 07/10/2010 - 10:28:50 - [774209328] ----D- C:\Program Files\FME

    O43 - CFD: 11/02/2010 - 18:33:44 - [49081649] ----D- C:\Program Files\Geoconcept 4.0.516-Cartabossy

    O43 - CFD: 02/03/2011 - 18:46:58 - [31920050] ----D- C:\Program Files\GeoConcept 4.2

    O43 - CFD: 04/03/2011 - 11:11:48 - [115606556] ----D- C:\Program Files\GeoConcept 5.0

    O43 - CFD: 24/02/2011 - 12:24:38 - [118697099] ----D- C:\Program Files\GeoConcept 6.0

    O43 - CFD: 06/10/2010 - 16:27:58 - [367545291] ----D- C:\Program Files\GeoConcept 6.6

    O43 - CFD: 06/10/2010 - 16:28:32 - [1247508] ----D- C:\Program Files\GeoConcept SA

    O43 - CFD: 23/02/2011 - 18:27:32 - [459842745] ----D- C:\Program Files\Geoconcept66GCIS40185

    O43 - CFD: 01/07/2010 - 12:56:28 - [133376971] ----D- C:\Program Files\Google

    O43 - CFD: 04/11/2009 - 15:38:22 - [52909303] ----D- C:\Program Files\IGC

    O43 - CFD: 04/02/2011 - 20:06:04 - [570069055] --H-D- C:\Program Files\InstallShield Installation Information

    O43 - CFD: 04/02/2009 - 01:29:28 - [49874540] ----D- C:\Program Files\Intel

    O43 - CFD: 10/02/2011 - 10:50:38 - [3554795] ----D- C:\Program Files\Internet Explorer

    O43 - CFD: 02/09/2010 - 17:04:56 - [1856115] ----D- C:\Program Files\iPod

    O43 - CFD: 02/09/2010 - 17:05:22 - [121825212] ----D- C:\Program Files\iTunes

    O43 - CFD: 28/02/2011 - 14:41:44 - [166274323] ----D- C:\Program Files\Java

    O43 - CFD: 25/06/2009 - 15:33:38 - [16283032] ----D- C:\Program Files\JRE

    O43 - CFD: 11/02/2011 - 15:17:06 - [5644596] ----D- C:\Program Files\ma-config.com

    O43 - CFD: 22/04/2009 - 13:36:10 - [139878797] ----D- C:\Program Files\Macromedia

    O43 - CFD: 21/02/2011 - 13:59:16 - [4992983] ----D- C:\Program Files\Malwarebytes' Anti-Malware

    O43 - CFD: 04/02/2009 - 01:27:42 - [2152579] ----D- C:\Program Files\Messenger

    O43 - CFD: 16/10/2009 - 10:54:14 - [1544075] ----D- C:\Program Files\Microsoft

    O43 - CFD: 25/04/2008 - 19:01:18 - [0] ----D- C:\Program Files\microsoft frontpage

    O43 - CFD: 02/02/2011 - 12:02:18 - [474219510] ----D- C:\Program Files\Microsoft Office

    O43 - CFD: 16/10/2009 - 10:54:08 - [1559148] ----D- C:\Program Files\Microsoft Office Outlook Connector

    O43 - CFD: 28/02/2011 - 19:22:04 - [38371963] ----D- C:\Program Files\Microsoft Silverlight

    O43 - CFD: 04/02/2009 - 01:41:42 - [1829877] ----D- C:\Program Files\Microsoft SQL Server Compact Edition

    O43 - CFD: 04/02/2009 - 01:42:58 - [2326117] ----D- C:\Program Files\Microsoft Sync Framework

    O43 - CFD: 02/02/2011 - 12:02:22 - [145421942] ----D- C:\Program Files\Microsoft Works

    O43 - CFD: 16/02/2009 - 16:47:26 - [8336384] ----D- C:\Program Files\Microsoft.NET

    O43 - CFD: 11/08/2010 - 02:00:56 - [10374874] ----D- C:\Program Files\Movie Maker

    O43 - CFD: 03/02/2011 - 12:56:30 - [32290314] ----D- C:\Program Files\Mozilla Firefox

    O43 - CFD: 25/04/2008 - 19:15:12 - [25757] ----D- C:\Program Files\MSBuild

    O43 - CFD: 27/11/2009 - 16:07:42 - [29794014] ----D- C:\Program Files\MSECache

    O43 - CFD: 25/04/2008 - 18:57:30 - [19278399] ----D- C:\Program Files\MSN

    O43 - CFD: 25/04/2008 - 18:57:40 - [8745735] ----D- C:\Program Files\MSN Gaming Zone

    O43 - CFD: 01/02/2011 - 18:22:12 - [135105552] ----D- C:\Program Files\MySQL

    O43 - CFD: 25/04/2008 - 18:59:12 - [3285523] ----D- C:\Program Files\NetMeeting

    O43 - CFD: 25/04/2008 - 18:57:54 - [1804] ----D- C:\Program Files\Online Services

    O43 - CFD: 25/06/2009 - 15:33:36 - [375056676] ----D- C:\Program Files\OpenOffice.org 3

    O43 - CFD: 15/12/2010 - 17:59:40 - [4379321] ----D- C:\Program Files\Outlook Express

    O43 - CFD: 09/04/2009 - 20:09:38 - [19461625] ----D- C:\Program Files\PDF Enhancer

    O43 - CFD: 19/10/2009 - 14:16:58 - [912053] ----D- C:\Program Files\PrintKey 2000 Fr

    O43 - CFD: 31/01/2011 - 12:54:10 - [13910332] ----D- C:\Program Files\PSPad editor

    O43 - CFD: 02/09/2010 - 17:03:12 - [76334922] ----D- C:\Program Files\QuickTime

    O43 - CFD: 04/02/2009 - 01:29:12 - [2045651] ----D- C:\Program Files\Realtek

    O43 - CFD: 25/04/2008 - 19:11:22 - [37949185] ----D- C:\Program Files\Reference Assemblies

    O43 - CFD: 16/02/2010 - 18:29:30 - [0] ----D- C:\Program Files\ReflexiveArcade

    O43 - CFD: 10/08/2010 - 14:02:42 - [26424156] ----D- C:\Program Files\Roxio

    O43 - CFD: 17/06/2010 - 10:03:48 - [42155440] ----D- C:\Program Files\Safari

    O43 - CFD: 25/04/2008 - 18:59:26 - [1025] ----D- C:\Program Files\Services en ligne

    O43 - CFD: 04/02/2009 - 01:31:38 - [28666352] ----D- C:\Program Files\Sonic

    O43 - CFD: 09/02/2009 - 12:22:24 - [1485830] ----D- C:\Program Files\SpamPal

    O43 - CFD: 01/09/2009 - 17:24:44 - [44626190] ----D- C:\Program Files\Stanza

    O43 - CFD: 30/03/2009 - 14:17:06 - [1506813] ----D- C:\Program Files\SyncToy 2.0

    O43 - CFD: 29/12/2010 - 16:08:58 - [32537494] ----D- C:\Program Files\Tablet

    O43 - CFD: 29/12/2010 - 16:08:56 - [844079] ----D- C:\Program Files\TabletPlugins

    O43 - CFD: 06/10/2010 - 16:29:30 - [16139096] ----D- C:\Program Files\Tracker Software

    O43 - CFD: 26/02/2009 - 22:31:36 - [1391611] ----D- C:\Program Files\UltraEdit

    O43 - CFD: 25/04/2008 - 19:04:36 - [0] --H-D- C:\Program Files\Uninstall Information

    O43 - CFD: 17/09/2009 - 09:24:52 - [23509198] ----D- C:\Program Files\Utilitaire de configuration iPhone

    O43 - CFD: 10/09/2010 - 15:09:02 - [9403099] ----D- C:\Program Files\wdgps_INSEE

    O43 - CFD: 16/10/2009 - 10:53:42 - [136574239] ----D- C:\Program Files\Windows Live

    O43 - CFD: 06/02/2009 - 15:59:34 - [41500194] ----D- C:\Program Files\Windows Live Safety Center

    O43 - CFD: 04/02/2009 - 01:39:46 - [245112] ----D- C:\Program Files\Windows Live SkyDrive

    O43 - CFD: 26/03/2010 - 19:17:50 - [3581070] ----D- C:\Program Files\Windows Media Connect 2

    O43 - CFD: 26/03/2010 - 19:17:50 - [8278281] ----D- C:\Program Files\Windows Media Player

    O43 - CFD: 25/04/2008 - 18:57:38 - [3942655] ----D- C:\Program Files\Windows NT

    O43 - CFD: 06/02/2009 - 15:26:32 - [389835] ----D- C:\Program Files\Windows Resource Kits

    O43 - CFD: 25/04/2008 - 18:59:32 - [0] --H-D- C:\Program Files\WindowsUpdate

    O43 - CFD: 25/04/2008 - 19:01:18 - [0] ----D- C:\Program Files\xerox

    O43 - CFD: 04/03/2011 - 12:10:58 - [3454830] ----D- C:\Program Files\ZHPDiag

    O43 - CFD: 12/10/2010 - 15:16:34 - [928934847] ----D- C:\Program Files\Fichiers Communs\Adobe

    O43 - CFD: 25/06/2009 - 16:31:38 - [27374423] ----D- C:\Program Files\Fichiers Communs\Adobe AIR

    O43 - CFD: 06/02/2009 - 20:38:16 - [72704] ----D- C:\Program Files\Fichiers Communs\Adobe Systems Shared

    O43 - CFD: 02/09/2010 - 17:04:56 - [86975155] ----D- C:\Program Files\Fichiers Communs\Apple

    O43 - CFD: 12/08/2010 - 15:12:00 - [0] ----D- C:\Program Files\Fichiers Communs\Autodesk Shared

    O43 - CFD: 16/02/2009 - 16:48:20 - [86016] ----D- C:\Program Files\Fichiers Communs\DESIGNER

    O43 - CFD: 10/02/2009 - 12:04:42 - [14167210] ----D- C:\Program Files\Fichiers Communs\InstallShield

    O43 - CFD: 28/02/2011 - 14:41:56 - [39120477] ----D- C:\Program Files\Fichiers Communs\Java

    O43 - CFD: 22/04/2009 - 13:36:10 - [1126524] ----D- C:\Program Files\Fichiers Communs\Macromedia

    O43 - CFD: 22/04/2009 - 13:36:12 - [68096] ----D- C:\Program Files\Fichiers Communs\Macromedia Shared

    O43 - CFD: 25/06/2009 - 16:28:24 - [655885] ----D- C:\Program Files\Fichiers Communs\Macrovision Shared

    O43 - CFD: 03/02/2011 - 03:01:58 - [314055738] ----D- C:\Program Files\Fichiers Communs\Microsoft Shared

    O43 - CFD: 25/04/2008 - 18:59:12 - [284160] ----D- C:\Program Files\Fichiers Communs\MSSoap

    O43 - CFD: 25/04/2008 - 06:53:12 - [0] ----D- C:\Program Files\Fichiers Communs\ODBC

    O43 - CFD: 04/02/2009 - 01:31:14 - [74772917] ----D- C:\Program Files\Fichiers Communs\Roxio Shared

    O43 - CFD: 12/08/2010 - 15:13:46 - [663040] ----D- C:\Program Files\Fichiers Communs\Safe Software Shared

    O43 - CFD: 25/04/2008 - 18:59:12 - [8106] ----D- C:\Program Files\Fichiers Communs\Services

    O43 - CFD: 27/10/2010 - 14:28:50 - [240776] ----D- C:\Program Files\Fichiers Communs\Software Update Utility

    O43 - CFD: 10/08/2010 - 14:14:36 - [5528200] ----D- C:\Program Files\Fichiers Communs\Sonic Shared

    O43 - CFD: 25/04/2008 - 06:53:10 - [3787229] ----D- C:\Program Files\Fichiers Communs\SpeechEngines

    O43 - CFD: 04/02/2009 - 01:32:50 - [7526487] ----D- C:\Program Files\Fichiers Communs\supportsoft

    O43 - CFD: 04/02/2009 - 01:31:34 - [710656] ----D- C:\Program Files\Fichiers Communs\SureThing Shared

    O43 - CFD: 16/10/2009 - 10:54:08 - [25250998] ----D- C:\Program Files\Fichiers Communs\System

    O43 - CFD: 04/02/2009 - 01:34:58 - [419296006] ----D- C:\Program Files\Fichiers Communs\Windows Live

    O43 - CFD: 22/09/2010 - 13:57:20 - [133798890] ----D- C:\Documents and Settings\Sandy\Application Data\Adobe

    O43 - CFD: 20/09/2010 - 13:58:24 - [440867832] ----D- C:\Documents and Settings\Sandy\Application Data\Apple Computer

    O43 - CFD: 23/02/2011 - 17:33:16 - [0] ----D- C:\Documents and Settings\Sandy\Application Data\ATI

    O43 - CFD: 21/02/2011 - 10:39:46 - [0] ----D- C:\Documents and Settings\Sandy\Application Data\Avira

    O43 - CFD: 06/02/2009 - 20:36:20 - [0] ----D- C:\Documents and Settings\Sandy\Application Data\CyberLink

    O43 - CFD: 08/04/2009 - 18:32:18 - [80] ----D- C:\Documents and Settings\Sandy\Application Data\Download Manager

    O43 - CFD: 03/03/2011 - 17:40:46 - [29813817] ----D- C:\Documents and Settings\Sandy\Application Data\Dropbox

    O43 - CFD: 15/12/2010 - 18:41:54 - [107956] ----D- C:\Documents and Settings\Sandy\Application Data\FileMaker

    O43 - CFD: 03/03/2011 - 18:02:44 - [29047] ----D- C:\Documents and Settings\Sandy\Application Data\FileZilla

    O43 - CFD: 25/02/2011 - 11:03:24 - [2472] ----D- C:\Documents and Settings\Sandy\Application Data\GeoConcept

    O43 - CFD: 29/01/2010 - 15:32:20 - [155684] ----D- C:\Documents and Settings\Sandy\Application Data\Google

    O43 - CFD: 03/11/2009 - 15:38:10 - [63] ----D- C:\Documents and Settings\Sandy\Application Data\Help

    O43 - CFD: 25/04/2008 - 19:04:38 - [0] ----D- C:\Documents and Settings\Sandy\Application Data\Identities

    O43 - CFD: 04/02/2009 - 01:29:12 - [544] ----D- C:\Documents and Settings\Sandy\Application Data\InstallShield

    O43 - CFD: 03/06/2009 - 10:44:38 - [0] ----D- C:\Documents and Settings\Sandy\Application Data\InterTrust

    O43 - CFD: 14/06/2010 - 12:16:34 - [8221834] ----D- C:\Documents and Settings\Sandy\Application Data\Macromedia

    O43 - CFD: 10/09/2009 - 17:27:30 - [18351] ----D- C:\Documents and Settings\Sandy\Application Data\Malwarebytes

    O43 - CFD: 02/02/2011 - 12:04:24 - [15840973] -S--D- C:\Documents and Settings\Sandy\Application Data\Microsoft

    O43 - CFD: 06/02/2009 - 14:36:16 - [10977755] ----D- C:\Documents and Settings\Sandy\Application Data\Mozilla

    O43 - CFD: 01/02/2011 - 19:25:48 - [14080] ----D- C:\Documents and Settings\Sandy\Application Data\MySQL

    O43 - CFD: 02/10/2009 - 10:40:36 - [220] ----D- C:\Documents and Settings\Sandy\Application Data\Office Genuine Advantage

    O43 - CFD: 25/06/2009 - 15:35:06 - [9621881] ----D- C:\Documents and Settings\Sandy\Application Data\OpenOffice.org

    O43 - CFD: 10/02/2009 - 13:24:12 - [0] ----D- C:\Documents and Settings\Sandy\Application Data\Opera

    O43 - CFD: 31/01/2011 - 12:53:52 - [5404] ----D- C:\Documents and Settings\Sandy\Application Data\PSpad

    O43 - CFD: 21/04/2009 - 15:21:14 - [640] ----D- C:\Documents and Settings\Sandy\Application Data\Roxio

    O43 - CFD: 12/08/2010 - 15:15:48 - [4389] ----D- C:\Documents and Settings\Sandy\Application Data\Safe Software

    O43 - CFD: 26/11/2009 - 11:16:30 - [168799] ----D- C:\Documents and Settings\Sandy\Application Data\SpamPal

    O43 - CFD: 04/02/2009 - 01:28:18 - [46429836] ----D- C:\Documents and Settings\Sandy\Application Data\Sun

    O43 - CFD: 21/10/2010 - 16:13:20 - [3604480] ----D- C:\Documents and Settings\Sandy\Application Data\U3

    O43 - CFD: 01/04/2009 - 13:46:50 - [0] ----D- C:\Documents and Settings\Sandy\Application Data\Windows Live Writer

    O43 - CFD: 29/12/2010 - 16:09:06 - [65944] ----D- C:\Documents and Settings\Sandy\Application Data\WTablet

    O43 - CFD: 25/06/2009 - 16:43:18 - [36262326] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\Adobe

    O43 - CFD: 17/02/2009 - 12:44:42 - [0] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\Apple

    O43 - CFD: 26/03/2010 - 19:14:08 - [123211051] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\Apple Computer

    O43 - CFD: 03/03/2011 - 17:40:22 - [10914] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\ApplicationHistory

    O43 - CFD: 23/02/2011 - 17:33:16 - [70979] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\ATI

    O43 - CFD: 29/01/2010 - 15:32:20 - [457322292] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\Google

    O43 - CFD: 09/04/2009 - 17:55:00 - [0] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\Help

    O43 - CFD: 06/02/2009 - 19:49:50 - [2536638644] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\Identities

    O43 - CFD: 21/02/2011 - 16:46:14 - [2562084259] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\Microsoft

    O43 - CFD: 02/02/2011 - 12:00:46 - [0] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\Microsoft Help

    O43 - CFD: 06/02/2009 - 14:36:16 - [55999467] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\Mozilla

    O43 - CFD: 04/06/2010 - 17:19:42 - [10330] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\PowerDVD DX

    O43 - CFD: 28/04/2009 - 20:13:06 - [72170] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\SMSI

    O43 - CFD: 06/02/2009 - 14:27:18 - [15289564] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\SupportSoft

    O43 - CFD: 22/10/2010 - 04:05:26 - [0] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\Temp

    O43 - CFD: 01/04/2009 - 13:46:50 - [327638] ----D- C:\Documents and Settings\Sandy\Local Settings\Application Data\Windows Live Writer

     

     

    ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)

    O44 - LFC:[MD5.B0ED1200F915817C00FCFD7F84EE1200] - 04/03/2011 - 12:04:35 ---A- . (...) -- C:\WINDOWS\wiadebug.log [781]

    O44 - LFC:[MD5.B0ED1200F915817C00FCFD7F84EE1200] - 04/03/2011 - 10:35:00 ---A- . (...) -- C:\WINDOWS\WindowsUpdate.log [648621]

    O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 04/03/2011 - 10:27:42 ---A- . (...) -- C:\WINDOWS\System32\null [0]

    O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 03/03/2011 - 17:40:04 ---A- . (...) -- C:\WINDOWS\0.log [0]

    O44 - LFC:[MD5.24B61D73C3098919A4E380A1C464F471] - 03/03/2011 - 17:39:58 ---A- . (...) -- C:\WINDOWS\System32\wpa.dbl [2206]

    O44 - LFC:[MD5.B0ED1200F915817C00FCFD7F84EE1200] - 03/03/2011 - 17:39:57 ---A- . (...) -- C:\WINDOWS\wiaservc.log [50]

    O44 - LFC:[MD5.B0ED1200F915817C00FCFD7F84EE1200] - 03/03/2011 - 17:39:52 ---A- . (...) -- C:\WINDOWS\SchedLgU.Txt [32530]

    O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 03/03/2011 - 17:39:49 -S-A- . (...) -- C:\WINDOWS\bootstat.dat [2048]

    O44 - LFC:[MD5.49C0C8A900865E0BC570FC5AA7C46823] - 02/03/2011 - 15:17:14 ---A- . (...) -- C:\WINDOWS\UEDIT32.INI [11961]

    O44 - LFC:[MD5.C111894B52BB4838DBF3B682ED622678] - 28/02/2011 - 19:19:38 ---A- . (...) -- C:\WINDOWS\KB971029.log [13707]

    O44 - LFC:[MD5.F7F1FFF56829C91AA7FFF0C9F4C715CE] - 28/02/2011 - 19:19:38 ---A- . (...) -- C:\WINDOWS\MedCtrOC.log [425]

    O44 - LFC:[MD5.600C5F22A7CEAB74CAA9BB73D905CDC9] - 28/02/2011 - 19:19:38 ---A- . (...) -- C:\WINDOWS\comsetup.log [2063]

    O44 - LFC:[MD5.F56C02CA579B872B5572B3E794DE1223] - 28/02/2011 - 19:19:38 ---A- . (...) -- C:\WINDOWS\iis6.log [7068]

    O44 - LFC:[MD5.725036532C5686531CF916F2C2DB1ACA] - 28/02/2011 - 19:19:38 ---A- . (...) -- C:\WINDOWS\imsins.log [1374]

    O44 - LFC:[MD5.C538C135E5275BD3784C2D871655790D] - 28/02/2011 - 19:19:38 ---A- . (...) -- C:\WINDOWS\msgsocm.log [309]

    O44 - LFC:[MD5.3930E30BEA0A968F39A46FA994F2A6CC] - 28/02/2011 - 19:19:38 ---A- . (...) -- C:\WINDOWS\netfxocm.log [1083]

    O44 - LFC:[MD5.088930CA1881DB27DD6A5E69D7FB11DD] - 28/02/2011 - 19:19:38 ---A- . (...) -- C:\WINDOWS\ntdtcsetup.log [1247]

    O44 - LFC:[MD5.AE8C843EDAF7B40346DF14E42E778382] - 28/02/2011 - 19:19:38 ---A- . (...) -- C:\WINDOWS\ocgen.log [2956]

    O44 - LFC:[MD5.4A75975A94C47C38406E0B45495B6321] - 28/02/2011 - 19:19:38 ---A- . (...) -- C:\WINDOWS\ocmsn.log [342]

    O44 - LFC:[MD5.9CC3ADC4007C1A19D639DB9510EDC7AC] - 28/02/2011 - 19:19:38 ---A- . (...) -- C:\WINDOWS\tabletoc.log [311]

    O44 - LFC:[MD5.034AD008D432A5EB5719B64D4585E559] - 28/02/2011 - 19:19:38 ---A- . (...) -- C:\WINDOWS\tsoc.log [2821]

    O44 - LFC:[MD5.BB04F4E73960FF5F4D272D7D076C80B4] - 28/02/2011 - 19:19:37 ---A- . (...) -- C:\WINDOWS\FaxSetup.log [6182]

    O44 - LFC:[MD5.A4D32B4C97749E284D0E87DBD9D34852] - 28/02/2011 - 19:19:35 ---A- . (...) -- C:\WINDOWS\msmqinst.log [1926]

    O44 - LFC:[MD5.31BF7CD69A8FE7702FBB36AF5FB95787] - 28/02/2011 - 19:19:30 ---A- . (...) -- C:\WINDOWS\updspapi.log [590]

    O44 - LFC:[MD5.BEC6F062A75925C41FC0B61F69782C0E] - 28/02/2011 - 14:41:43 ---A- . (...) -- C:\WINDOWS\System32\jupdate-1.6.0_24-b07.log [3297]

    O44 - LFC:[MD5.582E0BF48EB5E0CC523DF1E8B4225C6B] - 28/02/2011 - 12:21:30 ---A- . (...) -- C:\WINDOWS\setupapi.log [86325]

    O44 - LFC:[MD5.E1DC3727784464DC30FCF8844FCE4EE4] - 24/02/2011 - 20:24:04 ---A- . (...) -- C:\WINDOWS\win.ini [688]

    O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 23/02/2011 - 17:30:33 ---A- . (...) -- C:\WINDOWS\ativpsrm.bin [0]

    O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 23/02/2011 - 17:30:25 ---A- . (...) -- C:\WINDOWS\setupact.log [0]

    O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 23/02/2011 - 17:30:25 ---A- . (...) -- C:\WINDOWS\setuperr.log [0]

    O44 - LFC:[MD5.AE33E24863EC2F5E4FF8674655CFE609] - 23/02/2011 - 16:06:37 ---A- . (...) -- C:\WINDOWS\System32\d3d9caps.dat [1324]

    O44 - LFC:[MD5.1B2F9D826EE272A18AB03BAB79E8206E] - 21/02/2011 - 17:45:03 ---A- . (...) -- C:\WINDOWS\System32\PerfStringBackup.INI [1127266]

    O44 - LFC:[MD5.BD840F5220F5FE01F4A0E246716683C9] - 21/02/2011 - 17:45:03 ---A- . (...) -- C:\WINDOWS\System32\perfc009.dat [72576]

    O44 - LFC:[MD5.069290F7C55FF441B973F5CE7DC508B5] - 21/02/2011 - 17:45:03 ---A- . (...) -- C:\WINDOWS\System32\perfc00C.dat [86274]

    O44 - LFC:[MD5.6FADCF0C9A83A7F93A651A11C30EE74C] - 21/02/2011 - 17:45:03 ---A- . (...) -- C:\WINDOWS\System32\perfh009.dat [445370]

    O44 - LFC:[MD5.C115C7D68A6F6B46C40D14EBE2955E62] - 21/02/2011 - 17:45:03 ---A- . (...) -- C:\WINDOWS\System32\perfh00C.dat [514630]

    O44 - LFC:[MD5.8BE8D9ED56BDAF8ABD33C958372D0544] - 21/02/2011 - 17:00:15 ---A- . (...) -- C:\WINDOWS\ODBC.INI [484]

    O44 - LFC:[MD5.0E796653B0C8E2EF1F4D1A9C11B0F4DD] - 21/02/2011 - 16:59:42 ---A- . (...) -- C:\WINDOWS\System32\mapisvc.inf [45]

    O44 - LFC:[MD5.C9DD76D0EF94637C77FF8CA5E0FB0684] - 21/02/2011 - 12:20:39 ---A- . (...) -- C:\WINDOWS\system.ini [227]

    O44 - LFC:[MD5.6D3A8799AAF564FBAECEF2D90950FFCE] - 21/02/2011 - 12:20:39 RSHA- . (...) -- C:\boot.ini [212]

    O44 - LFC:[MD5.422A03E319DCAEC7F5E695398E163230] - 21/02/2011 - 12:13:01 ---A- . (.ATI Technologies Inc. - ATI Radeon WindowsNT Display Driver.) -- C:\WINDOWS\System32\ati2dvag.dll [302080]

    O44 - LFC:[MD5.6936F713DC69ADE85C50788990E34C16] - 21/02/2011 - 12:13:01 ---A- . (.ATI Technologies Inc. - ATI Radeon WindowsNT Miniport Driver.) -- C:\WINDOWS\System32\drivers\ati2mtag.sys [5656576]

    O44 - LFC:[MD5.40862C7B551F40CAB1CE35C9DD3A85E6] - 21/02/2011 - 12:13:01 ---A- . (.ATI Technologies Inc. - Central Memory Manager / Queue Server Modul.) -- C:\WINDOWS\System32\ati2cqag.dll [851968]

    O44 - LFC:[MD5.47825B5FF0E5D5AC84DF29665B887ACE] - 21/02/2011 - 12:13:01 ---A- . (.ATI Technologies Inc. - ati3duag.dll.) -- C:\WINDOWS\System32\ati3duag.dll [4021984]

    O44 - LFC:[MD5.B92093532ADB511941EEB1B26830706E] - 21/02/2011 - 12:13:01 ---A- . (.Advanced Micro Devices, Inc. - Radeon Video Acceleration Universal Driver.) -- C:\WINDOWS\System32\ativvaxx.dll [2670464]

    O44 - LFC:[MD5.DA39805E2BAD99D37FCE9477DD94E7F2] - 21/02/2011 - 10:12:48 ---A- . (.Avira GmbH - Avira Driver for Security Enhancement.) -- C:\WINDOWS\System32\drivers\avipbb.sys [135096]

    O44 - LFC:[MD5.F3626682B876196352156D514908A749] - 11/02/2011 - 15:41:13 ---A- . (. ATI Technologies Inc. - atiddc.) -- C:\WINDOWS\System32\ATIDDC.DLL [53248]

    O44 - LFC:[MD5.B2229CDC22C6A6BAC4A66F5A2679D827] - 11/02/2011 - 15:41:13 ---A- . (.ATI Technologies Inc. - .INF file installer.) -- C:\WINDOWS\System32\atiiiexx.dll [311296]

    O44 - LFC:[MD5.AC78982EAE5CA0F4BBC418E9C5ED3845] - 11/02/2011 - 15:41:13 ---A- . (.ATI Technologies Inc. - ATI External Event Utility EXE Module.) -- C:\WINDOWS\System32\ati2evxx.exe [638976]

    O44 - LFC:[MD5.28201D76145311739720ED2502D188E8] - 11/02/2011 - 15:41:13 ---A- . (.ATI Technologies Inc. - ATI RageTheater/ImpacTV2 COM interface.) -- C:\WINDOWS\System32\atitvo32.dll [17408]

    O44 - LFC:[MD5.D19966B6F44EFA839905BFFF70CE45CD] - 11/02/2011 - 15:41:13 ---A- . (.ATI Technologies Inc. - Virtual Command And Memory Manager.) -- C:\WINDOWS\System32\atikvmag.dll [651264]

    O44 - LFC:[MD5.83C65D23BE3C5C414CE1EAE4B68D3078] - 11/02/2011 - 15:41:13 ---A- . (.ATI Technologies Inc. - eRecord Message Resource File.) -- C:\WINDOWS\System32\drivers\ati2erec.dll [53248]

    O44 - LFC:[MD5.9505C5D2F033614EF8725DCF6DE6013A] - 11/02/2011 - 15:41:13 ---A- . (.ATI Technologies, Inc. - 32-bit ATI VCO Driver.) -- C:\WINDOWS\System32\ativcoxx.dll [24064]

    O44 - LFC:[MD5.887DDD888E376D4C129F29F9B8CC53AA] - 11/02/2011 - 15:41:13 ---A- . (.ATI Technologies, Inc. - ATI Desktop CWDDEDI DLL.) -- C:\WINDOWS\System32\atipdlxx.dll [212992]

    O44 - LFC:[MD5.C86AD67CDF2D3579033CFAA12E0EB81C] - 11/02/2011 - 15:41:13 ---A- . (.ATI Technologies, Inc. - ATI Driver Interface DLL.) -- C:\WINDOWS\System32\Oemdspif.dll [155648]

    O44 - LFC:[MD5.42830219EFD7BBF7DCDFDAC1799F2182] - 11/02/2011 - 15:41:13 ---A- . (.ATI Technologies, Inc. - ATI2MDXX.) -- C:\WINDOWS\System32\Ati2mdxx.exe [26112]

    O44 - LFC:[MD5.1351ABBD3ADE031174F5F4294E8BFCA6] - 11/02/2011 - 15:41:13 ---A- . (.ATI Technologies, Inc. - ati2edxx.) -- C:\WINDOWS\System32\ati2edxx.dll [43520]

    O44 - LFC:[MD5.09AA08F393FE0E0485106525AA59250D] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices Inc. - ATI CAL DD.) -- C:\WINDOWS\System32\aticaldd.dll [4489216]

    O44 - LFC:[MD5.CD81F5284E91259F02D83F40217AD3BA] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices Inc. - ATI CAL compiler runtime.) -- C:\WINDOWS\System32\aticalcl.dll [53248]

    O44 - LFC:[MD5.6A401C0F03AA9C80216E82CA849C2229] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices Inc. - ATI CAL runtime.) -- C:\WINDOWS\System32\aticalrt.dll [57344]

    O44 - LFC:[MD5.890B4F50743E589131A5547BD339E2EC] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices, Inc. - ATI OpenGL driver.) -- C:\WINDOWS\System32\atioglxx.dll [17084416]

    O44 - LFC:[MD5.749584902AE80A53EFDA4F8FA03E1713] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices, Inc. - ATIBRTMON.) -- C:\WINDOWS\System32\atibtmon.exe [118784]

    O44 - LFC:[MD5.F1D4AE214C5A7F3B830BBE7C6076F835] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices, Inc. - ATIODCLI Application.) -- C:\WINDOWS\System32\ATIODCLI.exe [45056]

    O44 - LFC:[MD5.337E0565819A1A93D2A8AA37B5816EA2] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices, Inc. - ATIODE Application.) -- C:\WINDOWS\System32\ATIODE.exe [294912]

    O44 - LFC:[MD5.E18A6386D41BE6072B3576388F5C4961] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices, Inc. - Graphics DEM.) -- C:\WINDOWS\System32\ATIDEMGX.dll [462848]

    O44 - LFC:[MD5.FC7DC127F35DD3D8E2A52E9C1CDC0946] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) -- C:\WINDOWS\System32\amdpcom32.dll [64512]

    O44 - LFC:[MD5.FC7DC127F35DD3D8E2A52E9C1CDC0946] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices, Inc. - Radeon PCOM Universal Driver.) -- C:\WINDOWS\System32\atimpc32.dll [64512]

    O44 - LFC:[MD5.FE7A555235E1593E34197CC5E2398AE5] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices, Inc. - Radeon Video Acceleration Universal Driver.) -- C:\WINDOWS\System32\ativvamv.dll [1112576]

    O44 - LFC:[MD5.2C2D7AB1AA85014BF12883DA95F0DC39] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices, Inc. - Ring 0 x2 component.) -- C:\WINDOWS\System32\atiok3x2.dll [471040]

    O44 - LFC:[MD5.4B33DF6F760B3A9EC866BD326ABD6E94] - 11/02/2011 - 15:41:13 ---A- . (.Advanced Micro Devices, Inc. - atiapfxx Application.) -- C:\WINDOWS\System32\atiapfxx.exe [143360]

    O44 - LFC:[MD5.698AA385E87E94F901A3F18FBB09A26E] - 10/02/2011 - 12:02:17 ---A- . (...) -- C:\WINDOWS\System32\FNTCACHE.DAT [1177584]

    O44 - LFC:[MD5.BD796673059AA5D09D2806842897F677] - 05/01/2011 - 03:36:36 ---A- . (...) -- C:\WINDOWS\System32\ativvaxx.cap [538880]

    O44 - LFC:[MD5.DADAFE066983AB646E8550013FB7DA13] - 05/01/2011 - 03:36:24 ---A- . (...) -- C:\WINDOWS\System32\ativva5x.dat [3]

    O44 - LFC:[MD5.CD663D99F1458BAA1840411C01B86EE5] - 05/01/2011 - 03:36:24 ---A- . (...) -- C:\WINDOWS\System32\ativva6x.dat [887724]

    O44 - LFC:[MD5.60E144B677A00DD00D5AA77D9E394AD3] - 05/01/2011 - 03:35:16 ---A- . (...) -- C:\WINDOWS\System32\atiapfxx.blb [138384]

    O44 - LFC:[MD5.ACD2DF3E369E484937822E63AF68C8EA] - 27/10/2010 - 23:13:58 ---A- . (...) -- C:\WINDOWS\System32\atiicdxx.dat [226857]

    O44 - LFC:[MD5.C983F6DED87442AAD6597CAED5C2F043] - 21/10/2010 - 19:57:38 ---A- . (...) -- C:\WINDOWS\atiogl.xml [22280]

     

     

    ---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)

    O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll

     

     

    ---\\ Export de clé d'application autorisée (O47)

    O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O47 - AAKE:Key Export SP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe

    O47 - AAKE:Key Export SP - "C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" [Enabled] .(.Adobe Systems Incorporated - Adobe Version Cue CS2.) -- C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe

    O47 - AAKE:Key Export SP - "C:\Program Files\FileZilla FTP Client\filezilla.exe" [Enabled] .(.FileZilla Project - FileZilla FTP Client.) -- C:\Program Files\FileZilla FTP Client\filezilla.exe

    O47 - AAKE:Key Export SP - "C:\Program Files\Canon\Color Network ScanGear\SgTool.exe" [Enabled] .(.CANON INC. - SGTOOL.) -- C:\Program Files\Canon\Color Network ScanGear\SgTool.exe

    O47 - AAKE:Key Export SP - "C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [Enabled] .(.Adobe Systems Incorporated.) -- C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe

    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.Microsoft Corporation - Windows Live Sync.) -- C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe

    O47 - AAKE:Key Export SP - "C:\cygwin\bin\XWin.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) -- C:\cygwin\bin\XWin.exe (.not file.)

    O47 - AAKE:Key Export SP - "C:\Program Files\Google\Google Earth\plugin\geplugin.exe" [Enabled] .(.Google - Google Earth.) -- C:\Program Files\Google\Google Earth\plugin\geplugin.exe

    O47 - AAKE:Key Export SP - "C:\Program Files\Bonjour\mDNSResponder.exe" [Enabled] .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe

    O47 - AAKE:Key Export SP - "C:\Program Files\iTunes\iTunes.exe" [Enabled] .(.Apple Inc. - iTunes.) -- C:\Program Files\iTunes\iTunes.exe

    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Sandy\Application Data\Dropbox\bin\Dropbox.exe" [Enabled] .(.Dropbox, Inc. - Dropbox.) -- C:\Documents and Settings\Sandy\Application Data\Dropbox\bin\Dropbox.exe

    O47 - AAKE:Key Export SP - "C:\Program Files\ma-config.com\maconfservice.exe" [Enabled] .(.CybelSoft - Service de détection matériel.) -- C:\Program Files\ma-config.com\maconfservice.exe

    O47 - AAKE:Key Export DP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O47 - AAKE:Key Export DP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe

    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.Microsoft Corporation - Windows Live Sync.) -- C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe

     

     

    ---\\ Déni du service (Local Security Authority) (O48)

    O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\System32\msv1_0.dll

    O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l'Éditeur de configuration de sécurité Windows.) -- C:\WINDOWS\System32\scecli.dll

    O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\System32\msv1_0.dll

     

     

    ---\\ Image File Execution Options (IFEO) (O50)

    O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - ntsd -d

     

     

    ---\\ MountPoints2 Shell Key (O51)

    O51 - MPSK:{6a5d7116-c3bd-11de-b56a-00219b17f077}\AutoRun\command. (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\PressKit.htm (.not file.)

     

     

    ---\\ Trojan Driver Search Data (HKLM) (O52)

    O52 - TDSD: \Drivers32\"msacm.trspch"="tssoft32.acm" . (.DSP GROUP, INC. - Codec audio TrueSpeech DSP Group pour MSACM V3.50.) -- C:\WINDOWS\System32\tssoft32.acm

    O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\System32\iccvid.dll

    O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ir32_32.dll

    O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ir32_32.dll

    O52 - TDSD: \Drivers32\"vidc.iv41"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\WINDOWS\System32\ir41_32.ax

    O52 - TDSD: \Drivers32\"msacm.sl_anet"="sl_anet.acm" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\System32\sl_anet.acm

    O52 - TDSD: \Drivers32\"msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax

    O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\WINDOWS\System32\ir50_32.dll

    O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm

    O52 - TDSD: \drivers.desc\"sl_anet.acm"="Sipro Lab Telecom Audio Codec" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\System32\sl_anet.acm

    O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax

    O52 - TDSD: \drivers.desc\"ir50_32.dll"="Indeo® video 5.10" . (.Pas de propriétaire - Pas de description.) -- (.not file.)

    O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm

     

     

    ---\\ ShareTools MSconfig StartupReg (O53)

    O53 - SMSR:HKLM\...\startupreg\8169Diag [Key] . (.Realtek - Diagnostic Utility MFC Application.) -- C:\Program Files\Realtek\Diagnostics Utility\8169Diag.exe

    O53 - SMSR:HKLM\...\startupreg\AppleSyncNotifier [Key] . (.Apple Inc. - AppleSyncNotifier.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleSyncNotifier.exe

    O53 - SMSR:HKLM\...\startupreg\iTunesHelper [Key] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe

     

     

    ---\\ Microsoft Control Security Providers (O54)

    O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- C:\WINDOWS\system32\msapsspc.dll

    O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll

    O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- C:\WINDOWS\system32\digest.dll

    O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- C:\WINDOWS\system32\msapsspc.dll

    O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll

    O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- C:\WINDOWS\system32\digest.dll

     

     

    ---\\ Microsoft Windows Policies System (O55)

    O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0

    O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=

    O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=

    O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1

    O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1

     

     

    ---\\ Microsoft Windows Policies Explorer (O56)

    O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145

    O56 - MWPE:[HKLM\...\policies\Explorer] - "HonorAutoRunSetting"=1

    O56 - MWPE:[HKLM\...\policies\Explorer] - "NoCDBurning"=0

     

     

    ---\\ Liste des Drivers Système (O58)

    O58 - SDL:[MD5.73685E15EF8B0BD9C30F1AF413F13D49] - 27/07/2009 - 09:54:31 ---A- . (.Adobe Systems, Inc. - Adobe Drive File System Driver.) -- C:\WINDOWS\system32\drivers\adfs.sys [73312]

    O58 - SDL:[MD5.1140AB9938809700B46BB88E46D72A96] - 18/08/2001 - 10:51:56 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\WINDOWS\system32\drivers\aliide.sys [5248]

    O58 - SDL:[MD5.95B4FB835E28AA1336CEEB07FD5B9398] - 14/04/2008 - 00:36:40 ---A- . (.Advanced Micro Devices, Inc. - AMD Win2000 AGP Filter.) -- C:\WINDOWS\system32\drivers\AMDAGP.SYS [43008]

    O58 - SDL:[MD5.62D318E9A0C8FC9B780008E724283707] - 18/08/2001 - 10:52:00 ---A- . (.Advanced System Products, Inc. - AdvanSys SCSI Controller Driver.) -- C:\WINDOWS\system32\drivers\asc.sys [26496]

    O58 - SDL:[MD5.5D8DE112AA0254B907861E9E9C31D597] - 18/08/2001 - 10:51:58 ---A- . (.Advanced System Products, Inc. - AdvanSys Ultra-Wide PCI SCSI Driver.) -- C:\WINDOWS\system32\drivers\asc3550.sys [14848]

    O58 - SDL:[MD5.6936F713DC69ADE85C50788990E34C16] - 05/01/2011 - 04:34:28 ---A- . (.ATI Technologies Inc. - ATI Radeon WindowsNT Miniport Driver.) -- C:\WINDOWS\system32\drivers\ati2mtag.sys [5656576]

    O58 - SDL:[MD5.EAECE4A0D90D6E1FBE068CCE9EFD73A0] - 21/07/2008 - 22:09:12 ---A- . (.ATI Research Inc. - Ati High Definition Audio Function Driver.) -- C:\WINDOWS\system32\drivers\AtiHdmi.sys [84992]

    O58 - SDL:[MD5.5B44C214F9CD9F590BE9125347610380] - 13/02/2009 - 11:17:49 ---A- . (.Avira GmbH - Avira AntiVir File Filter Driver.) -- C:\WINDOWS\system32\drivers\avgntdd.sys [45416]

    O58 - SDL:[MD5.47B879406246FFDCED59E18D331A0E7D] - 29/12/2010 - 12:51:37 ---A- . (.Avira GmbH - Avira Minifilter Driver.) -- C:\WINDOWS\system32\drivers\avgntflt.sys [61960]

    O58 - SDL:[MD5.87451AA7CC6B6A590EBCEA05E755075A] - 17/06/2010 - 15:28:03 ---A- . (.Avira GmbH - Avira AntiVir File Filter Driver Manager.) -- C:\WINDOWS\system32\drivers\avgntmgr.sys [22360]

    O58 - SDL:[MD5.DA39805E2BAD99D37FCE9477DD94E7F2] - 21/02/2011 - 10:12:48 ---A- . (.Avira GmbH - Avira Driver for Security Enhancement.) -- C:\WINDOWS\system32\drivers\avipbb.sys [135096]

    O58 - SDL:[MD5.223DEA13C9D064BABC882B4727F6F905] - 20/06/2007 - 04:00:00 ---A- . (.Sonic Solutions - CDR4 CD and DVD Place Holder Driver (see PxHelp).) -- C:\WINDOWS\system32\drivers\cdr4_xp.sys [9072]

    O58 - SDL:[MD5.9E26599599D178E71AFB5599E146031A] - 20/06/2007 - 04:00:00 ---A- . (.Sonic Solutions - CDRAL Place Holder Driver (see PxHelp).) -- C:\WINDOWS\system32\drivers\cdralw2k.sys [9200]

    O58 - SDL:[MD5.C9B25AE9B8ABD983C5AD3F8CBFAB0F9C] - 14/04/2008 - 13:00:00 ---A- . (.RAVISENT Technologies Inc. - Pilote principal CineMaster C 1.2 WDM.) -- C:\WINDOWS\system32\drivers\cinemst2.sys [262528]

    O58 - SDL:[MD5.E3726AD522D0BDAE090671048C991AB3] - 24/08/2001 - 06:04:44 ---A- . (.CMD Technology, Inc. - Pilote de bus PCI IDE CMD.) -- C:\WINDOWS\system32\drivers\cmdide.sys [6656]

    O58 - SDL:[MD5.9624293E55AD405415862B504CA95B73] - 14/04/2008 - 13:00:00 ---A- . (.Compaq Computer Corporation - Compaq PA-1 Player Driver.) -- C:\WINDOWS\system32\drivers\cpqdap01.sys [11776]

    O58 - SDL:[MD5.E550E7418984B65A78299D248F0A7F36] - 18/08/2001 - 10:52:16 ---A- . (.Mylex Corporation - Mylex Disk Array Controller Driver.) -- C:\WINDOWS\system32\drivers\dac2w2k.sys [179584]

    O58 - SDL:[MD5.A22D5A027F397E412CBB2D97E8661BFF] - 03/12/2007 - 12:13:48 ---A- . (.Realtek Semiconductor Corporation - Realtek 10/100/1000 Ethernet Adapter Hardware Diagnostics Drive.) -- C:\WINDOWS\system32\drivers\diag69xp.sys [11264]

    O58 - SDL:[MD5.A0500678A33802D8954153839301D539] - 23/07/2007 - 16:04:58 ---A- . (.Roxio - Drive Letter Access Component.) -- C:\WINDOWS\system32\drivers\DLABMFSM.SYS [37360]

    O58 - SDL:[MD5.B8D2F68CAC54D46281399F9092644794] - 23/07/2007 - 16:04:52 ---A- . (.Roxio - Drive Letter Access Component.) -- C:\WINDOWS\system32\drivers\DLABOIOM.SYS [32848]

    O58 - SDL:[MD5.0EE93AB799D1CB4EC90B36F3612FE907] - 23/07/2007 - 15:49:44 ---A- . (.Roxio - Shared Driver Component.) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS [14576]

    O58 - SDL:[MD5.86DFC5BAE3878CFABDE1430475BD52A7] - 23/07/2007 - 16:05:26 ---A- . (.Roxio - Drive Letter Access Component.) -- C:\WINDOWS\system32\drivers\DLADResM.SYS [9136]

    O58 - SDL:[MD5.766A148235BE1C0039C974446E4C0EDC] - 23/07/2007 - 16:04:50 ---A- . (.Roxio - Drive Letter Access Component.) -- C:\WINDOWS\system32\drivers\DLAIFS_M.SYS [108752]

    O58 - SDL:[MD5.38267CCA177354F1C64450A43A4F7627] - 23/07/2007 - 16:04:54 ---A- . (.Roxio - Drive Letter Access Component.) -- C:\WINDOWS\system32\drivers\DLAOPIOM.SYS [27216]

    O58 - SDL:[MD5.FD363369FD313B46B5AEAB1A688B52E9] - 23/07/2007 - 16:04:52 ---A- . (.Roxio - Drive Letter Access Component.) -- C:\WINDOWS\system32\drivers\DLAPoolM.SYS [16304]

    O58 - SDL:[MD5.336AE18F0912EF4FBE5518849E004D74] - 23/07/2007 - 15:49:44 ---A- . (.Roxio - Shared Driver Component.) -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS [30064]

    O58 - SDL:[MD5.FD85F682C1CC2A7CA878C7A448E6D87E] - 23/07/2007 - 16:04:56 ---A- . (.Roxio - Drive Letter Access Component.) -- C:\WINDOWS\system32\drivers\DLAUDFAM.SYS [93552]

    O58 - SDL:[MD5.AF389CE587B6BF5BBDCD6F6ABE5EABC0] - 23/07/2007 - 16:04:56 ---A- . (.Roxio - Drive Letter Access Component.) -- C:\WINDOWS\system32\drivers\DLAUDF_M.SYS [98448]

    O58 - SDL:[MD5.5D3B71BB2BB0009D65D290E2EF374BD3] - 23/07/2007 - 15:55:44 ---A- . (.Sonic Solutions - Device Driver.) -- C:\WINDOWS\system32\drivers\DRVMCDB.SYS [99808]

    O58 - SDL:[MD5.C591BA9F96F40A1FD6494DAFDCD17185] - 23/07/2007 - 15:43:42 ---A- . (.Roxio - Device Driver Manager.) -- C:\WINDOWS\system32\drivers\DRVNDDM.SYS [52000]

    O58 - SDL:[MD5.8182FF89C65E4D38B2DE4BB0FB18564E] - 18/05/2009 - 12:17:00 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys [26600]

    O58 - SDL:[MD5.C1CC0C9742B881C42F1CC628E6F9EBD1] - 28/07/2005 - 07:18:40 ---A- . (.Aladdin Knowledge Systems Ltd. - Hardlock Device Driver for Windows NT.) -- C:\WINDOWS\system32\drivers\hardlock.sys [685056]

    O58 - SDL:[MD5.573C7D0A32852B48F3058CFD8026F511] - 14/04/2008 - 13:00:00 ---A- . (.Windows ® Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) -- C:\WINDOWS\system32\drivers\hdaudbus.sys [144384]

    O58 - SDL:[MD5.707C1692214B1C290271067197F075F6] - 19/08/2008 - 00:14:46 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\WINDOWS\system32\drivers\iaStor.sys [324120]

    O58 - SDL:[MD5.B07084095F8C03AADB9811C9DF14B5E4] - 19/08/2008 - 00:03:28 ---A- . (.JMicron Technology Corp. - JMicron JMB36X RAID Driver.) -- C:\WINDOWS\system32\drivers\jraid.sys [79960]

    O58 - SDL:[MD5.8F5795B166CBB50966E29982F8CDB310] - 20/11/2007 - 02:04:50 ---A- . (.Realtek Semiconductor Corporation - Realtek LAN Protocol Driver.) -- C:\WINDOWS\system32\drivers\LANPkt.sys [8960]

    O58 - SDL:[MD5.836E0E09CA9869BE7EB39EF2CF3602C7] - 20/12/2010 - 18:08:40 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\system32\drivers\mbam.sys [20952]

    O58 - SDL:[MD5.D68E165C3123ABA3B1282EDDB4213BD8] - 20/12/2010 - 18:09:00 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys [38224]

    O58 - SDL:[MD5.3F4BB95E5A44F3BE34824E8E7CAF0737] - 18/08/2001 - 10:52:12 ---A- . (.American Megatrends Inc. - MegaRAID RAID Controller Driver for Windows Whistler 32.) -- C:\WINDOWS\system32\drivers\mraid35x.sys [17280]

    O58 - SDL:[MD5.BE984D604D91C217355CDD3737AAD25D] - 14/04/2008 - 13:00:00 ---A- . (.S3/Diamond Multimedia Systems - NikeDrv Usb Driver.) -- C:\WINDOWS\system32\drivers\nikedrv.sys [12032]

    O58 - SDL:[MD5.80D317BD1C3DBC5D4FE7B1678C60CADD] - 14/04/2008 - 13:00:00 ---A- . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Library.) -- C:\WINDOWS\system32\drivers\ptilink.sys [17792]

    O58 - SDL:[MD5.0A63FB54039EB5662433CABA3B26DBA7] - 18/08/2001 - 10:52:20 ---A- . (.QLogic Corporation - Miniport Driver for QLogic ISP PCI Adapters.) -- C:\WINDOWS\system32\drivers\ql1080.sys [40320]

    O58 - SDL:[MD5.156ED0EF20C15114CA097A34A30D8A01] - 18/08/2001 - 10:52:20 ---A- . (.QLogic Corporation - Miniport Driver for QLogic ISP PCI Adapters.) -- C:\WINDOWS\system32\drivers\ql12160.sys [45312]

    O58 - SDL:[MD5.907F0AEEA6BC451011611E732BD31FCF] - 18/08/2001 - 10:52:18 ---A- . (.QLogic Corporation - Miniport Driver for QLogic ISP PCI Adapters.) -- C:\WINDOWS\system32\drivers\ql1280.sys [49024]

    O58 - SDL:[MD5.A56FE08EC7473E8580A390BB1081CDD7] - 14/04/2008 - 13:00:00 ---A- . (.S3/Diamond Multimedia Systems - Rio8Drv.sys Usb Driver.) -- C:\WINDOWS\system32\drivers\rio8drv.sys [12032]

    O58 - SDL:[MD5.0A854DF84C77A0BE205BFEAB2AE4F0EC] - 14/04/2008 - 13:00:00 ---A- . (.S3/Diamond Multimedia Systems - RioDrv Usb Driver.) -- C:\WINDOWS\system32\drivers\riodrv.sys [12032]

    O58 - SDL:[MD5.7174F20AD9B7B7878A51ECCA03C499C2] - 19/08/2008 - 00:03:12 ---A- . (.Realtek Semiconductor Corporation - Realtek 10/100/1000 NDIS 5.1 Driver.) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys [106368]

    O58 - SDL:[MD5.5C8F36CDCB489111B24003AF4DFE1FDC] - 18/08/2008 - 23:20:06 ---A- . (.Realtek Semiconductor Corp. - Realtek® High Definition Audio Function Driver.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys [4752896]

    O58 - SDL:[MD5.B9CA69921379EA2931C4450FE975BCE7] - 20/11/2007 - 02:14:08 ---A- . (.Realtek Semiconductor Corporation - RTLVLAN Intermediate Miniport Driver.) -- C:\WINDOWS\system32\drivers\RTLVLAN.SYS [16640]

    O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 14/04/2008 - 13:00:00 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\WINDOWS\system32\drivers\secdrv.sys [20480]

    O58 - SDL:[MD5.6B33D0EBD30DB32E27D1D78FE946A754] - 14/04/2008 - 00:36:40 ---A- . (.Silicon Integrated Systems Corporation - SiS NT AGP Filter.) -- C:\WINDOWS\system32\drivers\SISAGP.SYS [40960]

    O58 - SDL:[MD5.83C0F71F86D3BDAF915685F3D568B20E] - 18/08/2001 - 11:07:44 ---A- . (.Adaptec, Inc. - Adaptec AIC-6x60 series SCSI miniport.) -- C:\WINDOWS\system32\drivers\sparrow.sys [19072]

    O58 - SDL:[MD5.A36EE93698802CD899F98BFD553D8185] - 17/06/2010 - 15:28:02 ---A- . (.Avira GmbH - AVIRA SnapShot Driver.) -- C:\WINDOWS\system32\drivers\ssmdrv.sys [28520]

    O58 - SDL:[MD5.1FF3217614018630D0A6758630FC698C] - 18/08/2001 - 11:07:34 ---A- . (.Symbios Logic Inc. - Symbios Logic Inc. SCSI Miniport Driver.) -- C:\WINDOWS\system32\drivers\symc810.sys [16256]

    O58 - SDL:[MD5.070E001D95CF725186EF8B20335F933C] - 18/08/2001 - 11:07:36 ---A- . (.LSI Logic - Symbios 8XX SCSI Miniport Driver.) -- C:\WINDOWS\system32\drivers\symc8xx.sys [32640]

    O58 - SDL:[MD5.80AC1C4ABBE2DF3B738BF15517A51F2C] - 18/08/2001 - 11:07:40 ---A- . (.LSI Logic - Symbios Hi-Perf SCSI Miniport Driver.) -- C:\WINDOWS\system32\drivers\sym_hi.sys [28384]

    O58 - SDL:[MD5.BF4FAB949A382A8E105F46EBB4937058] - 18/08/2001 - 11:07:42 ---A- . (.LSI Logic - Symbios Ultra3 SCSI Miniport Driver.) -- C:\WINDOWS\system32\drivers\sym_u3.sys [30688]

    O58 - SDL:[MD5.D74A8EC75305F1D3CFDE7C7FC1BD62A9] - 14/04/2008 - 13:00:00 ---A- . (.Toshiba Corporation - WDM Toshiba Tecra Video Capture Driver.) -- C:\WINDOWS\system32\drivers\tsbvcap.sys [21376]

    O58 - SDL:[MD5.1B698A51CD528D8DA4FFAED66DFC51B9] - 18/08/2001 - 10:52:22 ---A- . (.Promise Technology, Inc. - Gestionnaire de miniport ULTRA66 de Promise.) -- C:\WINDOWS\system32\drivers\ultra.sys [36736]

    O58 - SDL:[MD5.4B8A9C16B6D9258ED99C512AECB8C555] - 19/04/2010 - 19:47:42 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\WINDOWS\system32\drivers\usbaapl.sys [41984]

    O58 - SDL:[MD5.55E01061C74A8CEFFF58DC36114A8D3F] - 14/04/2008 - 13:00:00 ---A- . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINDOWS\system32\drivers\vdmindvd.sys [58112]

    O58 - SDL:[MD5.F24EE97511FB901189E11CBBD51605BA] - 05/10/2010 - 13:26:10 ---A- . (.Wacom Technology - Wacom HID Mouse Monitor Filter Driver.) -- C:\WINDOWS\system32\drivers\wacmoumonitor.sys [16240]

    O58 - SDL:[MD5.427A8BC96F16C40DF81C2D2F4EDD32DD] - 05/10/2010 - 13:26:02 ---A- . (.Wacom Technology - Wacom Mouse Filter Driver.) -- C:\WINDOWS\system32\drivers\wacommousefilter.sys [11312]

    O58 - SDL:[MD5.846B58EA44BF8C92E4B59F4E2252C4C0] - 05/10/2010 - 13:26:00 ---A- . (.Wacom Technology - Virtual Hid Device.) -- C:\WINDOWS\system32\drivers\wacomvhid.sys [14120]

    O58 - SDL:[MD5.6D3ADA4CE95CECA7BCE527A08C4C474E] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ansi.sys [9037]

    O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\country.sys [27097]

    O58 - SDL:[MD5.C6D29F29DE7427B1B0775E53E577B623] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\himem.sys [4912]

    O58 - SDL:[MD5.582BCDD47CF4B68B5CB528F18E3CB808] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\key01.sys [42809]

    O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\keyboard.sys [42537]

    O58 - SDL:[MD5.7D30A74B5FB9FE3B245A6CE5FBCD71D5] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos.sys [27916]

    O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos404.sys [29146]

    O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos411.sys [29370]

    O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos412.sys [29274]

    O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntdos804.sys [29146]

    O58 - SDL:[MD5.CAAA108FD7BF71989946B39704323455] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntio.sys [34000]

    O58 - SDL:[MD5.6F73F50162DEF60C84B725C18CD9140F] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntio404.sys [34560]

    O58 - SDL:[MD5.0FDD5E69C1FF3B58043D44F2CC743D45] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntio411.sys [35648]

    O58 - SDL:[MD5.8842837C4D8311BF8E72BEE8CCC42217] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntio412.sys [35424]

    O58 - SDL:[MD5.6B56CEB3C6F9D5CD7293DBD9FE23B311] - 14/04/2008 - 13:00:00 ---A- . (...) -- C:\WINDOWS\system32\ntio804.sys [34560]

     

     

    ---\\ Liste des outils de nettoyage (O63)

    O63 - Logiciel: ZHPDiag 1.27 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1

     

     

    ---\\ Liste des services Legacy (O64)

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\ADFS.sys - adfs (adfs) .(...) - LEGACY_ADFS

    O64 - Services: CurCS - (.not file.) - (.not file.) - Adobe Drive CS4 NP (AdobeDriveCS4_NP) .(...) - LEGACY_ADOBEDRIVECS4_NP

    O64 - Services: CurCS - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe - Adobe LM Service (Adobe LM Service) .(.Adobe Systems - System Level Service Utility.) - LEGACY_ADOBE_LM_SERVICE

    O64 - Services: CurCS - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe - Adobe Version Cue CS2 (Adobe Version Cue CS2) .(.Adobe Systems Incorporated - Adobe Version Cue CS2.) - LEGACY_ADOBE_VERSION_CUE_CS2

    O64 - Services: CurCS - C:\WINDOWS\system32\drivers\afd.sys - AFD (AFD) .(.Microsoft Corporation - Ancillary Function Driver for WinSock.) - LEGACY_AFD

    O64 - Services: CurCS - C:\WINDOWS\System32\alg.exe - Service de la passerelle de la couche Application (ALG) .(.Microsoft Corporation - Application Layer Gateway Service.) - LEGACY_ALG

    O64 - Services: CurCS - C:\Program Files\Avira\AntiVir Desktop\sched.exe - Avira AntiVir Planificateur (AntiVirSchedulerService) .(.Avira GmbH - Antivirus Scheduler.) - LEGACY_ANTIVIRSCHEDULERSERVICE

    O64 - Services: CurCS - C:\Program Files\Avira\AntiVir Desktop\avguard.exe - Avira AntiVir Guard (AntiVirService) .(.Avira GmbH - Antivirus On-Access Service.) - LEGACY_ANTIVIRSERVICE

    O64 - Services: CurCS - C:\Program Files\Apache Group\Apache2\bin\Apache.exe - Apache2 (Apache2) .(.Apache Software Foundation - Apache HTTP Server.) - LEGACY_APACHE2

    O64 - Services: CurCS - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe - Apple Mobile Device (Apple Mobile Device) .(.Apple Inc. - Apple Mobile Device Service.) - LEGACY_APPLE_MOBILE_DEVICE

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Gestion d'applications (AppMgmt) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_APPMGMT

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\atapi.sys - Contrôleur de disque dur IDE/ESDI standard (atapi) .(.Microsoft Corporation - IDE/ATAPI Port Driver.) - LEGACY_ATAPI

    O64 - Services: CurCS - C:\WINDOWS\system32\Ati2evxx.exe - Ati HotKey Poller (Ati HotKey Poller) .(.ATI Technologies Inc. - ATI External Event Utility EXE Module.) - LEGACY_ATI_HOTKEY_POLLER

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Audio Windows (AudioSrv) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_AUDIOSRV

    O64 - Services: CurCS - C:\Program Files\Avira\AntiVir Desktop\avgio.sys - avgio (avgio) .(.Avira GmbH - Avira AntiVir Support for Minifilter.) - LEGACY_AVGIO

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\avgntflt.sys - avgntflt (avgntflt) .(.Avira GmbH - Avira Minifilter Driver.) - LEGACY_AVGNTFLT

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\avipbb.sys - avipbb (avipbb) .(.Avira GmbH - Avira Driver for Security Enhancement.) - LEGACY_AVIPBB

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\BEEP.sys - Beep (Beep) .(...) - LEGACY_BEEP

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Service de transfert intelligent en arrière-plan (BITS) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_BITS

    O64 - Services: CurCS - C:\Program Files\Bonjour\mDNSResponder.exe - Service Bonjour (Bonjour Service) .(.Apple Inc. - Bonjour Service.) - LEGACY_BONJOUR_SERVICE

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Explorateur d'ordinateur (Browser) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_BROWSER

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\CDFS.sys - cdfs (cdfs) .(...) - LEGACY_CDFS

    O64 - Services: CurCS - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe - .NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) .(.Microsoft Corporation - .NET Runtime Optimization Service.) - LEGACY_CLR_OPTIMIZATION_V2.0.50727_32

    O64 - Services: CurCS - (.not file.) - (.not file.) - Application système COM+ (COMSysApp) .(...) - LEGACY_COMSYSAPP

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Services de cryptographie (CryptSvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_CRYPTSVC

    O64 - Services: CurCS - (.not file.) - (.not file.) - Lanceur de processus serveur DCOM (DcomLaunch) .(...) - LEGACY_DCOMLAUNCH

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Client DHCP (Dhcp) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_DHCP

    O64 - Services: CurCS - C:\Windows\System32\Drivers\Diag69xp.sys - Diag69xp (Diag69xp) .(.Realtek Semiconductor Corporation - Realtek 10/100/1000 Ethernet Adapter Hardwa.) - LEGACY_DIAG69XP

    O64 - Services: CurCS - C:\Windows\System32\Drivers\DLABMFSM.sys - DLABMFSM (DLABMFSM) .(.Roxio - Drive Letter Access Component.) - LEGACY_DLABMFSM

    O64 - Services: CurCS - C:\Windows\System32\Drivers\DLABOIOM.sys - DLABOIOM (DLABOIOM) .(.Roxio - Drive Letter Access Component.) - LEGACY_DLABOIOM

    O64 - Services: CurCS - C:\Windows\System32\Drivers\DLADResM.sys - DLADResM (DLADResM) .(.Roxio - Drive Letter Access Component.) - LEGACY_DLADRESM

    O64 - Services: CurCS - C:\Windows\System32\Drivers\DLAIFS_M.sys - DLAIFS_M (DLAIFS_M) .(.Roxio - Drive Letter Access Component.) - LEGACY_DLAIFS_M

    O64 - Services: CurCS - C:\Windows\System32\Drivers\DLAOPIOM.sys - DLAOPIOM (DLAOPIOM) .(.Roxio - Drive Letter Access Component.) - LEGACY_DLAOPIOM

    O64 - Services: CurCS - C:\Windows\System32\Drivers\DLAPoolM.sys - DLAPoolM (DLAPoolM) .(.Roxio - Drive Letter Access Component.) - LEGACY_DLAPOOLM

    O64 - Services: CurCS - C:\Windows\System32\Drivers\DLARTL_M.sys - DLARTL_M (DLARTL_M) .(.Roxio - Shared Driver Component.) - LEGACY_DLARTL_M

    O64 - Services: CurCS - C:\Windows\System32\Drivers\DLAUDFAM.sys - DLAUDFAM (DLAUDFAM) .(.Roxio - Drive Letter Access Component.) - LEGACY_DLAUDFAM

    O64 - Services: CurCS - C:\Windows\System32\Drivers\DLAUDF_M.sys - DLAUDF_M (DLAUDF_M) .(.Roxio - Drive Letter Access Component.) - LEGACY_DLAUDF_M

    O64 - Services: CurCS - C:\WINDOWS\System32\dmadmin.exe - Service d'administration du Gestionnaire de disque logique (dmadmin) .(.Microsoft Corp., Veritas Software - Processus du service Gestionnaire de disque.) - LEGACY_DMADMIN

    O64 - Services: CurCS - C:\Windows\System32\drivers\dmboot.sys - dmboot (dmboot) .(.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disq.) - LEGACY_DMBOOT

    O64 - Services: CurCS - C:\Windows\System32\drivers\dmload.sys - dmload (dmload) .(.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) - LEGACY_DMLOAD

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Gestionnaire de disque logique (dmserver) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_DMSERVER

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Client DNS (Dnscache) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_DNSCACHE

    O64 - Services: CurCS - C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys - driverhardwarev2 (driverhardwarev2) .(.CybelSoft - Driver NT Ma-Config.com.) - LEGACY_DRIVERHARDWAREV2

    O64 - Services: CurCS - C:\Windows\System32\Drivers\DRVNDDM.sys - DRVNDDM (DRVNDDM) .(.Roxio - Device Driver Manager.) - LEGACY_DRVNDDM

    O64 - Services: CurCS - C:\WINDOWS\system32\ERM\7.1\ERMLicSrv_ATL71.exe - ERMLicSrv_ATL71 (ERMLicSrv_ATL71) .(.Pas de propriétaire - ERMLicSrv_ATL Module.) - LEGACY_ERMLICSRV_ATL71

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Service de rapport d'erreurs (ERSvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_ERSVC

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Système d'événements de COM+ (EventSystem) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_EVENTSYSTEM

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\FASTFAT.sys - fastfat (fastfat) .(...) - LEGACY_FASTFAT

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Compatibilité avec le Changement rapide d'utilisateur (FastUserSwitchingCompatibility) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_FASTUSERSWITCHINGCOMPATIBILITY

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\FIPS.sys - Fips (Fips) .(...) - LEGACY_FIPS

    O64 - Services: CurCS - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe - FLEXnet Licensing Service (FLEXnet Licensing Service) .(.Acresso Software Inc. - Activation Licensing Service.) - LEGACY_FLEXNET_LICENSING_SERVICE

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\fltMgr.sys - FltMgr (FltMgr) .(.Microsoft Corporation - Microsoft Filesystem Filter Manager.) - LEGACY_FLTMGR

    O64 - Services: CurCS - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe - Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) .(.Microsoft Corporation - PresentationFontCache.exe.) - LEGACY_FONTCACHE3.0.0.0

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\FS_REC.sys - Fs_Rec (Fs_Rec) .(...) - LEGACY_FS_REC

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\msgpc.sys - Classificateur de paquets générique (Gpc) .(.Microsoft Corporation - MS General Packet Classifier.) - LEGACY_GPC

    O64 - Services: CurCS - C:\Program Files\Google\Update\GoogleUpdate.exe - Service Google Update (gupdate) (gupdate) .(.Google Inc. - Programme d'installation de Google.) - LEGACY_GUPDATE

    O64 - Services: CurCS - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe - Google Updater Service (gusvc) .(.Google - gusvc.) - LEGACY_GUSVC

    O64 - Services: CurCS - C:\WINDOWS\system32\drivers\hardlock.sys - Hardlock (Hardlock) .(.Aladdin Knowledge Systems Ltd. - Hardlock Device Driver for Windows NT.) - LEGACY_HARDLOCK

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Aide et support (helpsvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_HELPSVC

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - HID Input Service (HidServ) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_HIDSERV

    O64 - Services: CurCS - C:\Windows\System32\Drivers\HTTP.sys - HTTP (HTTP) .(.Microsoft Corporation - HTTP Protocol Stack.) - LEGACY_HTTP

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - HTTP SSL (HTTPFilter) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_HTTPFILTER

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\I2OMGMT.sys - i2omgmt (i2omgmt) .(...) - LEGACY_I2OMGMT

    O64 - Services: CurCS - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe - Intel® Matrix Storage Event Monitor (IAANTMON) .(.Intel Corporation - RAID Monitor.) - LEGACY_IAANTMON

    O64 - Services: CurCS - C:\WINDOWS\system32\imapi.exe - Service COM de gravage de CD IMAPI (ImapiService) .(.Microsoft Corporation - API Image Mastering.) - LEGACY_IMAPISERVICE

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\ipnat.sys - Traducteur d'adresses réseau IP (IpNat) .(.Microsoft Corporation - IP Network Address Translator.) - LEGACY_IPNAT

    O64 - Services: CurCS - C:\Program Files\iPod\bin\iPodService.exe - Service de l'iPod (iPod Service) .(.Apple Inc. - iPodService Module (32-bit).) - LEGACY_IPOD_SERVICE

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\ipsec.sys - Pilote IPSEC (IPSec) .(.Microsoft Corporation - IPSec Driver.) - LEGACY_IPSEC

    O64 - Services: CurCS - C:\Program Files\Java\jre6\bin\jqs.exe - Java Quick Starter (JavaQuickStarterService) .(.Sun Microsystems, Inc. - Java Quick Starter Service.) - LEGACY_JAVAQUICKSTARTERSERVICE

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\KSECDD.sys - ksecdd (ksecdd) .(...) - LEGACY_KSECDD

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Serveur (LanmanServer) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_LANMANSERVER

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Station de travail (LanmanWorkstation) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_LANMANWORKSTATION

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\LANPkt.sys - Realtek LANPkt Protocol Driver (LANPkt) .(.Realtek Semiconductor Corporation - Realtek LAN Protocol Driver.) - LEGACY_LANPKT

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Assistance TCP/IP NetBIOS (LmHosts) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_LMHOSTS

    O64 - Services: CurCS - C:\Program Files\ma-config.com\maconfservice.exe - Ma-Config Service (maconfservice) .(.CybelSoft - Service de détection matériel.) - LEGACY_MACONFSERVICE

    O64 - Services: CurCS - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe - Macromedia Licensing Service (Macromedia Licensing Service) .(.Pas de propriétaire - System Level Service Utilty.) - LEGACY_MACROMEDIA_LICENSING_SERVICE

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\MNMDD.sys - mnmdd (mnmdd) .(...) - LEGACY_MNMDD

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\MOUNTMGR.sys - mountmgr (mountmgr) .(...) - LEGACY_MOUNTMGR

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\mrxdav.sys - Redirecteur client WebDav (MRxDAV) .(.Microsoft Corporation - Windows NT WebDav Minirdr.) - LEGACY_MRXDAV

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\mrxsmb.sys - MRXSMB (MRxSmb) .(.Microsoft Corporation - Windows NT SMB Minirdr.) - LEGACY_MRXSMB

    O64 - Services: CurCS - C:\WINDOWS\system32\msdtc.exe - Distributed Transaction Coordinator (MSDTC) .(.Microsoft Corporation - MS DTC console program.) - LEGACY_MSDTC

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\MSFS.sys - Msfs (Msfs) .(...) - LEGACY_MSFS

    O64 - Services: CurCS - C:\WINDOWS\system32\msiexec.exe - Windows Installer (MSIServer) .(.Microsoft Corporation - Windows® installer.) - LEGACY_MSISERVER

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\MUP.sys - (.not file.) - Mup (Mup) .(...) - LEGACY_MUP

    O64 - Services: CurCS - C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld" --defaults-file="C:\Program Files\MySQL\MySQL Server 5.1\my.ini" MySQL (.not file.) - MySQL (MySQL) .(...) - LEGACY_MYSQL

    O64 - Services: CurCS - (.not file.) - NAVENG (NAVENG) .(...) - LEGACY_NAVENG

    O64 - Services: CurCS - (.not file.) - NAVEX15 (NAVEX15) .(...) - LEGACY_NAVEX15

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\NDIS.sys - (.not file.) - Pilote système NDIS (NDIS) .(...) - LEGACY_NDIS

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\ndistapi.sys - Pilote TAPI NDIS d'accès distant (NdisTapi) .(.Microsoft Corporation - NDIS 3.0 connection wrapper driver.) - LEGACY_NDISTAPI

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\ndisuio.sys - NDIS mode utilisateur E/S Protocole (Ndisuio) .(.Microsoft Corporation - NDIS User mode I/O Driver.) - LEGACY_NDISUIO

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\NDPROXY.sys - NDProxy (NDProxy) .(...) - LEGACY_NDPROXY

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\netbios.sys - Interface NetBIOS (NetBIOS) .(.Microsoft Corporation - NetBIOS interface driver.) - LEGACY_NETBIOS

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\netbt.sys - NetBIOS sur TCP/IP (NetBT) .(.Microsoft Corporation - MBT Transport driver.) - LEGACY_NETBT

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Connexions réseau (Netman) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_NETMAN

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - NLA (Network Location Awareness) (Nla) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_NLA

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\NPFS.sys - Npfs (Npfs) .(...) - LEGACY_NPFS

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\NTFS.sys - ntfs (ntfs) .(...) - LEGACY_NTFS

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Stockage amovible (NtmsSvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_NTMSSVC

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\NULL.sys - Null (Null) .(...) - LEGACY_NULL

    O64 - Services: CurCS - C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.exe - Office Source Engine (ose) .(.Microsoft Corporation - Office Source Engine.) - LEGACY_OSE

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\PARTMGR.sys - PartMgr (PartMgr) .(...) - LEGACY_PARTMGR

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\PARVDM.sys - ParVdm (ParVdm) .(...) - LEGACY_PARVDM

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\pciide.sys - PCIIde (PCIIde) .(.Microsoft Corporation - Pilote de bus générique PCI IDE.) - LEGACY_PCIIDE

    O64 - Services: CurCS - C:\WINDOWS\system32\lsass.exe - Services IPSEC (PolicyAgent) .(.Microsoft Corporation - LSA Shell (Export Version).) - LEGACY_POLICYAGENT

    O64 - Services: CurCS - C:\WINDOWS\system32\lsass.exe - Emplacement protégé (ProtectedStorage) .(.Microsoft Corporation - LSA Shell (Export Version).) - LEGACY_PROTECTEDSTORAGE

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\rasacd.sys - Pilote de connexion automatique d'accès distant (RasAcd) .(.Microsoft Corporation - RAS Automatic Connection Driver.) - LEGACY_RASACD

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Gestionnaire de connexions d'accès distant (RasMan) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_RASMAN

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\rdbss.sys - Rdbss (Rdbss) .(.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - LEGACY_RDBSS

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\RDPCDD.sys - RDPCDD (RDPCDD) .(.Microsoft Corporation - RDP Miniport.) - LEGACY_RDPCDD

    O64 - Services: CurCS - (.not file.) - RDPNP (RDPNP) .(...) - LEGACY_RDPNP

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Accès à distance au Registre (RemoteRegistry) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_REMOTEREGISTRY

    O64 - Services: CurCS - (.not file.) - (.not file.) - Appel de procédure distante (RPC) (RpcSs) .(...) - LEGACY_RPCSS

    O64 - Services: CurCS - C:\WINDOWS\system32\lsass.exe - Gestionnaire de comptes de sécurité (SamSs) .(.Microsoft Corporation - LSA Shell (Export Version).) - LEGACY_SAMSS

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Planificateur de tâches (Schedule) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SCHEDULE

    O64 - Services: CurCS - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe - SeaPort (SeaPort) .(.Microsoft Corporation - Microsoft SeaPort Search Enhancement Broker.) - LEGACY_SEAPORT

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Connexion secondaire (seclogon) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SECLOGON

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Notification d'événement système (SENS) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SENS

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Pare-feu Windows / Partage de connexion Internet (SharedAccess) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SHAREDACCESS

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Détection matériel noyau (ShellHWDetection) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SHELLHWDETECTION

    O64 - Services: CurCS - C:\WINDOWS\system32\spoolsv.exe - Spouleur d'impression (Spooler) .(.Microsoft Corporation - Spooler SubSystem App.) - LEGACY_SPOOLER

    O64 - Services: CurCS - C:\Program Files\Dell Support Center\bin\sprtsvc.exe - SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) .(.SupportSoft, Inc. - SupportSoft Agent Service.) - LEGACY_SPRTSVC_DELLSUPPORTCENTER

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\sr.sys - Pilote de filtre de restauration système (sr) .(.Microsoft Corporation - Pilote de filtre de système de fichiers pou.) - LEGACY_SR

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Service de restauration système (srservice) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SRSERVICE

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\srv.sys - Srv (Srv) .(.Microsoft Corporation - Server driver.) - LEGACY_SRV

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Service de découvertes SSDP (SSDPSRV) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_SSDPSRV

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\ssmdrv.sys - ssmdrv (ssmdrv) .(.Avira GmbH - AVIRA SnapShot Driver.) - LEGACY_SSMDRV

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Acquisition d'image Windows (WIA) (stisvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_STISVC

    O64 - Services: CurCS - (.not file.) - (.not file.) - MS Software Shadow Copy Provider (SwPrv) .(...) - LEGACY_SWPRV

    O64 - Services: CurCS - C:\Program Files\Tablet\Pen\Pen_Tablet.exe - TabletServicePen (TabletServicePen) .(.Wacom Technology, Corp. - Tablet Service for consumer driver.) - LEGACY_TABLETSERVICEPEN

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Téléphonie (TapiSrv) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_TAPISRV

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\tcpip.sys - Pilote du protocole TCP/IP (Tcpip) .(.Microsoft Corporation - TCP/IP Protocol Driver.) - LEGACY_TCPIP

    O64 - Services: CurCS - (.not file.) - (.not file.) - Services Terminal Server (TermService) .(...) - LEGACY_TERMSERVICE

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Thèmes (Themes) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_THEMES

    O64 - Services: CurCS - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe - Apache Tomcat (Tomcat5) .(.Apache Software Foundation - Commons Daemon Service Runner.) - LEGACY_TOMCAT5

    O64 - Services: CurCS - C:\Program Files\Tablet\Pen\Pen_TouchService.exe - Wacom Consumer Touch Service (TouchServicePen) .(.Wacom Technology, Corp. - Touch Service.) - LEGACY_TOUCHSERVICEPEN

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Client de suivi de lien distribué (TrkWks) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_TRKWKS

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\UDFS.sys - Udfs (Udfs) .(...) - LEGACY_UDFS

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Hôte de périphérique universel Plug-and-Play (upnphost) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_UPNPHOST

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\VGA.sys - vga (vga) .(...) - LEGACY_VGA

    O64 - Services: CurCS - C:\WINDOWS\system32\drivers\vga.sys - VgaSave (VgaSave) .(.Microsoft Corporation - VGA/Super VGA Video Driver.) - LEGACY_VGASAVE

    O64 - Services: CurCS - C:\WINDOWS\system32\Drivers\VOLSNAP.sys - VolSnap (VolSnap) .(...) - LEGACY_VOLSNAP

    O64 - Services: CurCS - C:\WINDOWS\System32\vssvc.exe - Cliché instantané de volume (VSS) .(.Microsoft Corporation - Service de cliché instantané de volumes Mic.) - LEGACY_VSS

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Windows Time (w32time) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_W32TIME

    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\wanarp.sys - Pilote ARP IP d'accès distant (Wanarp) .(.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - LEGACY_WANARP

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - WebClient (WebClient) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WEBCLIENT

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Infrastructure de gestion Windows (winmgmt) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WINMGMT

    O64 - Services: CurCS - C:\WINDOWS\system32\wbem\wmiapsrv.exe - Carte de performance WMI (WmiApSrv) .(.Microsoft Corporation - Service de la carte de performance WMI.) - LEGACY_WMIAPSRV

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Centre de sécurité (wscsvc) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WSCSVC

    O64 - Services: CurCS - C:\WINDOWS\system32\svchost.exe - Mises à jour automatiques (wuauserv) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WUAUSERV

    O64 - Services: CurCS - C:\WINDOWS\System32\svchost.exe - Configuration automatique sans fil (WZCSVC) .(.Microsoft Corporation - Generic Host Process for Win32 Services.) - LEGACY_WZCSVC

     

     

    ---\\ File Associations Shell Spawning (O67)

    O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] "%1" %* (.not file.)

    O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll

    O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] "%1" %* (.not file.)

    O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] "%1" %* (.not file.)

    O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] "%1" %* (.not file.)

    O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe

    O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Macromedia, Inc. - Dreamweaver MX 2004.) -- C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe

    O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe

    O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe

    O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] "%1" %* (.not file.)

    O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll

    O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] "%1" %* (.not file.)

    O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] "%1" %* (.not file.)

    O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] "%1" %* (.not file.)

    O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe

    O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Macromedia, Inc. - Dreamweaver MX 2004.) -- C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe

    O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe

     

     

    ---\\ Start Menu Internet (O68)

    O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe

    O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe

    O68 - StartMenuInternet: <Safari.exe> <Safari>[HKLM\..\Shell\open\Command] (.Apple Inc. - Safari.) -- C:\Program Files\Safari\Safari.exe

     

     

    ---\\ Search Browser Infection (O69)

    O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (@ieframe.dll,-12512) - Bing

     

     

    ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)

    SS - | Demand 06/02/2009 72704 | (Adobe LM Service) . (.Adobe Systems.) - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe

    SS - | Demand 06/04/2005 163840 | (Adobe Version Cue CS2) . (.Adobe Systems Incorporated.) - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe

    SR - | Auto 17/08/2010 135336 | (AntiVirSchedulerService) . (.Avira GmbH.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    SR - | Auto 29/12/2010 267944 | (AntiVirService) . (.Avira GmbH.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    SR - | Auto 18/10/2010 20550 | (Apache2) . (.Apache Software Foundation.) - C:\Program Files\Apache Group\Apache2\bin\Apache.exe

    SR - | Auto 13/08/2010 144672 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    SR - | Auto 05/01/2011 638976 | (Ati HotKey Poller) . (.ATI Technologies Inc..) - C:\WINDOWS\system32\Ati2evxx.exe

    SS - | Disabled 27/07/2010 345376 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe

    SS - | Demand 27/07/2010 0 | (BrlAPI) . (.Pas de propriétaire.) - C:\cygwin\bin\cygrunsrv.exe

    SS - | Demand 14/04/2008 225280 | (dmadmin) . (.Microsoft Corp., Veritas Software.) - C:\WINDOWS\System32\dmadmin.exe

    SR - | Demand 16/05/2006 94208 | (ERMLicSrv_ATL71) . (.Pas de propriétaire.) - C:\WINDOWS\system32\ERM\7.1\ERMLicSrv_ATL71.exe

    SS - | Demand 25/06/2009 655624 | (FLEXnet Licensing Service) . (.Acresso Software Inc..) - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    SS - | Demand 07/01/2010 24576 | (GeoConceptService) . (.GEO CONCEPT.) - C:\Program Files\Geoconcept66GCIS40185\GeoSvc.exe

    SS - | Auto 01/07/2010 136176 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe

    SS - | Demand 31/07/2008 136120 | (gusvc) . (.Google.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    SR - | Auto 20/07/2008 354840 | (IAANTMON) . (.Intel Corporation.) - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    SR - | Demand 01/09/2010 820008 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe

    SR - | Auto 02/02/2011 153376 | (JavaQuickStarterService) . (.Sun Microsystems, Inc..) - C:\Program Files\Java\jre6\bin\jqs.exe

    SS - | Demand 24/01/2011 310640 | (maconfservice) . (.CybelSoft.) - C:\Program Files\ma-config.com\maconfservice.exe

    SS - | Demand 22/04/2009 68096 | (Macromedia Licensing Service) . (.Pas de propriétaire.) - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe

    SR - | Auto 22/04/2009 0 | (MySQL) . (.Pas de propriétaire.) - C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld" --defaults-file="C:\Program Files\MySQL\MySQL Server 5.1\my.ini" MySQL

    SR - | Auto 14/08/2008 201968 | (sprtsvc_dellsupportcenter) . (.SupportSoft, Inc..) - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

    SS - | Demand 11/07/2007 69632 | (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe

    SR - | Auto 13/10/2010 4869488 | (TabletServicePen) . (.Wacom Technology, Corp..) - C:\Program Files\Tablet\Pen\Pen_Tablet.exe

    SR - | Auto 04/09/2010 61440 | (Tomcat5) . (.Apache Software Foundation.) - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe

    SR - | Auto 13/10/2010 416112 | (TouchServicePen) . (.Wacom Technology, Corp..) - C:\Program Files\Tablet\Pen\Pen_TouchService.exe

     

     

    ---\\ Recherche Master Boot Record Infection (MBR)(O80)

    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.1 by Gmer, GMER - Rootkit Detector and Remover

    Run by Sandy at 04/03/2011 12:14:30

     

    device: opened successfully

    user: MBR read successfully

     

    Disk trace:

    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll

    C:\WINDOWS\system32\drivers\iaStor.sys Intel Corporation Intel Matrix Storage Manager driver

    1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x89DE27C8]

    3 CLASSPNP[0xBA0E8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Ide\IAAStorageDevice-1[0x89842028]

    kernel: MBR read successfully

    user & kernel MBR OK

     

     

    ---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)

    Written by ad13, http://ad13.geekstog

    Run by Sandy at 04/03/2011 12:14:30

    Use the desktop link 'MBRCheck' to have full report

    Dump file Name : C:\PhysicalDisk0_MBR.bin

     

     

     

    End of the scan (1407 lines in 03mn 48s)(0)

  3. Bonjour

     

    Désolée pour le délai de réponse

    J'ai remarqué qu'une grande partie des plantages intervenait lorsque j'étais en train de lire mes mails dans Microsoft Office et dans une moindre mesure sur firefox...Aujourd'hui pour éviter de planter étant donné que je devais pas mal bossé j'ai limité l'accès à Office...Ensuite depuis hier soir j'ai effectué une mise à jour de windows (update automatique) je n'ai pas eu de plantage...Donc suspense je ne sais pas si tout cela est lié...

    Dans tous les cas et étant donné que je dois faire une sauvegarde de l'intégralité de mes données si cela recommençait dans les jours suivants, je vais opter pour un reformatage du PC.

    On peut donc considérer ce problème comme résolu

    Merci à tous les 2 de m'avoir aidée.

    Bonne soirée

  4. Ok voici donc mon message modifié. Désolé pour la prose inutile du message précédent.

    Voici un lien avec un fichier zip contenant des copies d'écran des différents rapports des outils proposés

    http://cjoint.com/data/0cysQx5kfAc.htm

     

    Par rapport à l'observateur d'événements dans la ligne systeme il y a un certains nombre d'erreurs dont les sources sont les suivantes :

    - Browser

    - System Error (102)

    - ati2mtag

    Dois-je t'envoyer le fichier journal ?

     

    La carte graphique a déjà fonctionné sur cet OS (Windows XP Service Pack 3) et ce sans problème.

     

    Concernant le DirectX dois je installer la version DX10 (faut-il au préalable que je backup toutes mes données ?)

     

    Merci de tes réponses

     

     

     

  5. re-Bonjour

     

    J'ai téléchargé le dernier driver et effectuer le test sur la RAM qui n'a rien révélé (0 erreur).

    Malgré tout le problème persiste.

     

    Merci bonne journée également

     

     

    Après un énième plantage le Windows Error reporting m'indique ceci :

    "Mise à niveau de Display Adapter

     

    Ce problème est survenu parce que votre carte vidéo ne prend pas en charge la version requise de DirectX. Cette version de Windows nécessite une carte vidéo prenant en charge DirectX 9.0 ou une version ultérieure.

     

    Quelle est la configuration système requise pour cette version de Windows ?

     

    Pour rechercher des périphériques similaires compatibles avec cette version de Windows, accédez à la page Web Windows Logo''d Products List (en anglais) :

     

    Windows Logo''d Products List (en anglais)Windows Logo''d Products List (en anglais)

     

    Qu''est-ce que DirectX ?"

  6. Bonjour,

     

    Suite à un changement d'écran et la mise à jour du pilote de ma carte graphique mon PC plante. Régulièrement l'écran se fige et j'ai au choix un écran noir ou un écran bleu avec le message indiqué ci-après.

    J'ai effectué plusieurs essais avec différents pilotes (anciens / derniers pilotes) et le problème reste le même. Pourriez vous m'indiquez d'où vient le problème et ce que je dois faire pour y remédier.

     

    Merci d'avance !

     

    Contenu du Msg sur l'écran bleu :

     

    Un problème a été détecté et Windows a été arrêté afin de prévenir tout dommage sur votre ordinateur.

     

    Le problème semble être causé par le fichier suivant : ati2dvag

     

    Si vous voyez cet écran...Blabla.. si cet écran apparait encore, suivez ces étapes :

     

    Le pilote de votre carte graphique est bloqué dans une boucle infinie. Ceci indique généralement un problème provenant de la carte graphique ou d'une programmation incorrecte du matériel par le pilote.

     

    Contactez votre vendeur blabla... pour une mise à jour du pilote.

     

    Informations techniques :

    *** STOP: 0x000000EA (0x87D3F020,0x8913B5A8,0xBA4EFCBC,0x00000001)

     

    ati2dvag

    Début du vidage de la mémoire physique.

    vidage de la mémoire physique terminée.

    Contactez votre administrateur système ...Blabla...

  7. Bonjour,

     

    Je réponds avec un peu de retard mais le problème est résolu grâce à Dr Web!!!

    Un grand merci car le logiciel à trouver 3 chevaux de troie!!!

    Ci joint le rapport et encore merci beaucoup. :P

     

    Processus en mémoire: C:\WINDOWS\Explorer.EXE:788;;BackDoor.Tdss.565;Eradiqué.;

    sdra64.exe;C:\WINDOWS\system32;Trojan.Packed.687;Supprimé.;

    UACcqwgoeuntx.dll;C:\WINDOWS\system32;BackDoor.Tdss.433;Supprimé.;

    UAColqbwulvhk.dll;C:\WINDOWS\system32;Trojan.Packed.2936;Supprimé.;

    UACutfgllofil.dll;C:\WINDOWS\system32;BackDoor.Tdss.598;Supprimé.;

    UAC683d.tmp;C:\DOCUME~1\SEBAST~1\LOCALS~1\Temp;Trojan.Packed.2936;Supprimé.;

    uaccqwgoeuntx.dll;\\?\globalroot\systemroot\system32;BackDoor.Tdss.433;Supprimé.;

    4a7dfcc7.qua\data001;C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\INFECTED\4a7dfcc7.qua;Trojan.Packed.2936;;

    4a7dfcc7.qua;C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\INFECTED;Conteneur comporte des objets infectés;Quarantaine.;

    4b97c295.qua/data001\Starware354.dll;C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\INFECTED\4b97c295.qua/data001;Adware.Comet.71;;

    data001;C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\INFECTED;L'archive contient des éléments infectés;;

    4b97c295.qua;C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\INFECTED;Conteneur comporte des objets infectés;Quarantaine.;

    4b99c25e.qua\data001;C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\INFECTED\4b99c25e.qua;Trojan.Packed.687;;

    4b99c25e.qua;C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\INFECTED;Conteneur comporte des objets infectés;Quarantaine.;

    iTunes.msi/stream004\unvised_2.bin;C:\WINDOWS\Downloaded Installations\{EA1534E6-3516-4C20-B2AA-55277079C80A}\iTunes.msi/stream004;Tool.Reboot;;

    stream004;C:\WINDOWS\Downloaded Installations\{EA1534E6-3516-4C20-B2AA-55277079C80A};L'archive contient des éléments infectés;;

    iTunes.msi;C:\WINDOWS\Downloaded Installations\{EA1534E6-3516-4C20-B2AA-55277079C80A};L'archive contient des éléments infectés;Quarantaine.;

    UACcqwgoeuntx.dll;C:\WINDOWS\system32;BackDoor.Tdss.433;Supprimé.;

    UACutfgllofil.dll;C:\WINDOWS\system32;BackDoor.Tdss.598;Supprimé.;

  8. Ca y est j'ai refait un scannage, voila le rapport!

     

    Avira AntiVir Personal

    Date de création du fichier de rapport : vendredi 25 décembre 2009 13:30

     

    La recherche porte sur 1473402 souches de virus.

     

    Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus

    Numéro de série : 0000149996-ADJIE-0000001

    Plateforme : Windows XP

    Version de Windows : (Service Pack 2) [5.1.2600]

    Mode Boot : Démarré normalement

    Identifiant : SYSTEM

    Nom de l'ordinateur : BERGOT-8I1SZHR2

     

    Informations de version :

    BUILD.DAT : 9.0.0.74 21698 Bytes 04/12/2009 13:56:00

    AVSCAN.EXE : 9.0.3.10 466689 Bytes 24/12/2009 14:15:00

    AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 10:21:02

    LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 11:35:11

    LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 10:21:31

    VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 14:14:51

    VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 14:14:53

    VBASE002.VDF : 7.10.1.1 2048 Bytes 19/11/2009 14:14:53

    VBASE003.VDF : 7.10.1.2 2048 Bytes 19/11/2009 14:14:53

    VBASE004.VDF : 7.10.1.3 2048 Bytes 19/11/2009 14:14:53

    VBASE005.VDF : 7.10.1.4 2048 Bytes 19/11/2009 14:14:53

    VBASE006.VDF : 7.10.1.5 2048 Bytes 19/11/2009 14:14:53

    VBASE007.VDF : 7.10.1.6 2048 Bytes 19/11/2009 14:14:53

    VBASE008.VDF : 7.10.1.7 2048 Bytes 19/11/2009 14:14:53

    VBASE009.VDF : 7.10.1.8 2048 Bytes 19/11/2009 14:14:53

    VBASE010.VDF : 7.10.1.9 2048 Bytes 19/11/2009 14:14:53

    VBASE011.VDF : 7.10.1.10 2048 Bytes 19/11/2009 14:14:53

    VBASE012.VDF : 7.10.1.11 2048 Bytes 19/11/2009 14:14:53

    VBASE013.VDF : 7.10.1.79 209920 Bytes 25/11/2009 14:14:54

    VBASE014.VDF : 7.10.1.128 197632 Bytes 30/11/2009 14:14:54

    VBASE015.VDF : 7.10.1.178 195584 Bytes 07/12/2009 14:14:54

    VBASE016.VDF : 7.10.1.224 183296 Bytes 14/12/2009 14:14:54

    VBASE017.VDF : 7.10.1.247 182272 Bytes 15/12/2009 14:14:55

    VBASE018.VDF : 7.10.2.30 198144 Bytes 21/12/2009 14:14:55

    VBASE019.VDF : 7.10.2.31 2048 Bytes 21/12/2009 14:14:55

    VBASE020.VDF : 7.10.2.32 2048 Bytes 21/12/2009 14:14:55

    VBASE021.VDF : 7.10.2.33 2048 Bytes 21/12/2009 14:14:55

    VBASE022.VDF : 7.10.2.34 2048 Bytes 21/12/2009 14:14:55

    VBASE023.VDF : 7.10.2.35 2048 Bytes 21/12/2009 14:14:55

    VBASE024.VDF : 7.10.2.36 2048 Bytes 21/12/2009 14:14:55

    VBASE025.VDF : 7.10.2.37 2048 Bytes 21/12/2009 14:14:55

    VBASE026.VDF : 7.10.2.38 2048 Bytes 21/12/2009 14:14:55

    VBASE027.VDF : 7.10.2.39 2048 Bytes 21/12/2009 14:14:55

    VBASE028.VDF : 7.10.2.40 2048 Bytes 21/12/2009 14:14:55

    VBASE029.VDF : 7.10.2.41 2048 Bytes 21/12/2009 14:14:55

    VBASE030.VDF : 7.10.2.42 2048 Bytes 21/12/2009 14:14:55

    VBASE031.VDF : 7.10.2.60 187392 Bytes 24/12/2009 14:14:56

    Version du moteur : 8.2.1.122

    AEVDF.DLL : 8.1.1.2 106867 Bytes 24/12/2009 14:14:58

    AESCRIPT.DLL : 8.1.3.4 586105 Bytes 24/12/2009 14:14:58

    AESCN.DLL : 8.1.3.0 127348 Bytes 24/12/2009 14:14:57

    AESBX.DLL : 8.1.1.1 246132 Bytes 24/12/2009 14:14:58

    AERDL.DLL : 8.1.3.4 479605 Bytes 24/12/2009 14:14:57

    AEPACK.DLL : 8.2.0.3 422261 Bytes 24/12/2009 14:14:57

    AEOFFICE.DLL : 8.1.0.38 196987 Bytes 24/12/2009 14:14:57

    AEHEUR.DLL : 8.1.0.189 2195833 Bytes 24/12/2009 14:14:57

    AEHELP.DLL : 8.1.9.0 237943 Bytes 24/12/2009 14:14:56

    AEGEN.DLL : 8.1.1.82 369014 Bytes 24/12/2009 14:14:56

    AEEMU.DLL : 8.1.1.0 393587 Bytes 24/12/2009 14:14:56

    AECORE.DLL : 8.1.9.1 180598 Bytes 24/12/2009 14:14:56

    AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 14:32:40

    AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 08:47:30

    AVPREF.DLL : 9.0.3.0 44289 Bytes 24/12/2009 14:15:00

    AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 14:34:28

    AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 15:24:42

    AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 15:05:22

    AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 10:36:37

    SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 15:03:49

    SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 08:20:57

    NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 15:40:59

    RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 24/12/2009 14:14:45

    RCTEXT.DLL : 9.0.73.0 88321 Bytes 24/12/2009 14:14:45

     

    Configuration pour la recherche actuelle :

    Nom de la tâche...............................: Contrôle intégral du système

    Fichier de configuration......................: c:\program files\avira\antivir desktop\sysscan.avp

    Documentation.................................: bas

    Action principale.............................: interactif

    Action secondaire.............................: ignorer

    Recherche sur les secteurs d'amorçage maître..: marche

    Recherche sur les secteurs d'amorçage.........: marche

    Secteurs d'amorçage...........................: C:,

    Recherche dans les programmes actifs..........: marche

    Recherche en cours sur l'enregistrement.......: marche

    Recherche de Rootkits.........................: marche

    Contrôle d'intégrité de fichiers système......: arrêt

    Fichier mode de recherche.....................: Tous les fichiers

    Recherche sur les archives....................: marche

    Limiter la profondeur de récursivité..........: 20

    Archive Smart Extensions......................: marche

    Heuristique de macrovirus.....................: marche

    Heuristique fichier...........................: moyen

    Catégories de dangers divergentes.............: +APPL,+GAME,+JOKE,+PCK,+SPR,

     

    Début de la recherche : vendredi 25 décembre 2009 13:30

     

    La recherche d'objets cachés commence.

    Une instance de la bibliothèque ARK fonctionne déjà.

     

    La recherche sur les processus démarrés commence :

    Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'wuauclt.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'Watch.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'wmiprvse.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'alg.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'unsecapp.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'sfus.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'ALERTM~1.EXE' - '1' module(s) sont contrôlés

    Processus de recherche 'PollingModule.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'Inactivity.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'Toaster.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'ComComp.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'FTRTSVC.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'GestionnaireInternet.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'WkCalRem.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'TaskBarIcon.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'msnmsgr.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'ctfmon.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'jusched.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'SFAgent.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'AAWService.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'services.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés

    Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés

    '42' processus ont été contrôlés avec '42' modules

     

    La recherche sur les secteurs d'amorçage maître commence :

    Secteur d'amorçage maître HD0

    [iNFO] Aucun virus trouvé !

     

    La recherche sur les secteurs d'amorçage commence :

    Secteur d'amorçage 'C:\'

    [iNFO] Aucun virus trouvé !

     

    La recherche sur les renvois aux fichiers exécutables (registre) commence :

    Le registre a été contrôlé ( '60' fichiers).

     

     

    La recherche sur les fichiers sélectionnés commence :

     

    Recherche débutant dans 'C:\'

    C:\pagefile.sys

    [AVERTISSEMENT] Impossible d'ouvrir le fichier !

    [REMARQUE] Ce fichier est un fichier système Windows.

    [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.

    C:\Documents and Settings\Sebastien\Local Settings\Temp\c.exe

    [RESULTAT] Contient le cheval de Troie TR/Dropper.Gen

    C:\Documents and Settings\Sebastien\Local Settings\Temp\d.exe

    [RESULTAT] Contient le cheval de Troie TR/Crypt.ZPACK.Gen

    C:\Documents and Settings\Sebastien\Mes documents\Louis NOAL\install.exe

    [RESULTAT] Contient le cheval de Troie TR/Crypt.FKM.Gen

    C:\Documents and Settings\Sebastien\Mes documents\Louis NOAL\recipes_fr.exe

    [RESULTAT] Contient le modèle de détection du dropper DR/Comet.BB.19

    C:\Documents and Settings\Sebastien\Mes documents\Louis NOAL\web-mediaplayer_setup.exe

    [RESULTAT] Contient le modèle de détection du logiciel publicitaire ADWARE/Adware.Gen

    C:\WINDOWS\system32\sdra64.exe

    [AVERTISSEMENT] Impossible d'ouvrir le fichier !

     

    Début de la désinfection :

    C:\Documents and Settings\Sebastien\Local Settings\Temp\c.exe

    [RESULTAT] Contient le cheval de Troie TR/Dropper.Gen

    [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b99c25e.qua' !

    C:\Documents and Settings\Sebastien\Local Settings\Temp\d.exe

    [RESULTAT] Contient le cheval de Troie TR/Crypt.ZPACK.Gen

    [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4a7dfcc7.qua' !

    C:\Documents and Settings\Sebastien\Mes documents\Louis NOAL\install.exe

    [RESULTAT] Contient le cheval de Troie TR/Crypt.FKM.Gen

    [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4ba7c29e.qua' !

    C:\Documents and Settings\Sebastien\Mes documents\Louis NOAL\recipes_fr.exe

    [RESULTAT] Contient le modèle de détection du dropper DR/Comet.BB.19

    [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b97c295.qua' !

    C:\Documents and Settings\Sebastien\Mes documents\Louis NOAL\web-mediaplayer_setup.exe

    [RESULTAT] Contient le modèle de détection du logiciel publicitaire ADWARE/Adware.Gen

    [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b96c296.qua' !

     

     

    Fin de la recherche : vendredi 25 décembre 2009 14:46

    Temps nécessaire: 1:14:56 Heure(s)

     

    La recherche a été effectuée intégralement

     

    4260 Les répertoires ont été contrôlés

    208930 Des fichiers ont été contrôlés

    5 Des virus ou programmes indésirables ont été trouvés

    0 Des fichiers ont été classés comme suspects

    0 Des fichiers ont été supprimés

    0 Des virus ou programmes indésirables ont été réparés

    5 Les fichiers ont été déplacés dans la quarantaine

    0 Les fichiers ont été renommés

    2 Impossible de contrôler des fichiers

    208923 Fichiers non infectés

    2199 Les archives ont été contrôlées

    2 Avertissements

    6 Consignes

  9. Bonjour

     

    Depuis quelques temps un message apparait a chaque lancement d'application, une demande de clé crypto ???

    Voici ci-apres un log d'Hijackthis pouvez vous me l'interpréter

    Merci beaucoup

     

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 11:57:20, on 25/12/2009

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Boot mode: Normal

     

    Running processes:

    C:\WINDOWS\system32\csrss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Internet Explorer\Iexplore.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Avira\AntiVir Desktop\sched.exe

    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    C:\Program Files\SPAMfighter\SFAgent.exe

    C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe

    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe

    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe

    C:\Program Files\Alwil Software\Avast4\ashServ.exe

    C:\WINDOWS\System32\FTRTSVC.exe

    C:\Program Files\SPAMfighter\sfus.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\WINDOWS\system32\msiexec.exe

    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

    C:\WINDOWS\System32\wbem\unsecapp.exe

    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

    C:\WINDOWS\System32\alg.exe

    C:\WINDOWS\system32\wbem\wmiprvse.exe

    C:\Program Files\Internet Explorer\Iexplore.exe

    C:\WINDOWS\system32\wbem\wmiprvse.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

     

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILE...+Xl1zKkH2CBDAuY=

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O4 - HKLM\..\Run: [PMXInit] C:\WINDOWS\system32\pmxinit.exe

    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

    O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe

    O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers

    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe

    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe

    O4 - HKLM\..\Run: [sPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"

    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

    O4 - HKCU\..\Run: [EPSON Stylus S20 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEAE.EXE /FU "C:\WINDOWS\TEMP\E_S49.tmp" /EF "HKCU"

    O4 - HKCU\..\Run: [MsgCenterExe] "C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe" -osboot

    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')

    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe

    O4 - Global Startup: Rappels du Calendrier Microsoft Works.lnk = ?

    O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?

    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe

    O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe

    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)

    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://webcam.asf.fr/AxisCamControl.ocx

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe

    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe

    O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe

    O23 - Service: Service Google Update (gupdate1c9b6e3b7e0cd65) (gupdate1c9b6e3b7e0cd65) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe

     

    --

    End of file - 8628 bytes

  10. Ok merci pour tes remarques

     

    Concernant Bitdefender il a l'avantage d'intégrer un filtre anti-spam un firewall et un antivirus et d'être relativement simple à paramétrer (bon exepté pour le firewall peut-être). Bon d'accord il est périmé mais je comptais le renouveler sur la machine en question... N'y a t'il pas d'outil qui combine tout cela et qui soit simple d'utilisation à qui est refractaire à l'anglais (antivir est en anglais et comodo... ) s'il est payant et efficace ça peut être une option :P

     

    J'ai très peu de compétences en matière de sécurité je sais qu'il faut un antivirus un firewall je navigue avec Firefox et je pense naviguer sur des sites "à priori sûrs". J'ai demandé qu'au sein de la micro-société dans laquelle je travaille personne ne télécharge sur le P2P mais je ne suis pas sure d'avoir été bien entendue... Mes compétences sont limitées et celle de mes collègues sont à l'identique sinon pire. Il m'est difficile d'imposer des outils que je ne maitrise pas et qui peuvent rebuter

     

    En tout cas encore merci de tes conseils et je vais tester ces outils sur ma machine et proposer à mes collègues d'en faire de même mais je ne suis pas sûre du resultat...

  11. Petite question est ce que le fichier catchme.log (situé sur le bureau) est celui qui a causé l'infection de la machine ?

    Voici le log de HijackThis

     

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 17:32:10, on 06/08/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16674)

    Boot mode: Normal

     

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe

    C:\WINDOWS\system32\nvsvc32.exe

    C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe

    C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe

    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe

    C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

    C:\WINDOWS\stsystra.exe

    C:\WINDOWS\System32\DLA\DLACTRLW.EXE

    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe

    C:\Program Files\Unlocker\UnlockerAssistant.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe

    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Documents and Settings\recovery\Bureau\HijackThis.exe

     

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=2070618

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=2070618

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.fr/ig/dell?hl=fr&cli...amp;ibd=2070618

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

    O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE

    O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

    O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start

    O4 - HKLM\..\Run: [unlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"

    O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"

    O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"

    O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"

    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

    O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe

    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll

    O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O17 - HKLM\System\CCS\Services\Tcpip\..\{7414A25E-5D64-4FE0-85F0-D7C68C806CFC}: NameServer = 194.2.0.20,194.2.0.50

    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe

    O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe

    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe

    O24 - Desktop Component 0: Privacy Protection - (no file)

     

    --

    End of file - 8178 bytes

  12. Bonjour

     

    J'ai effectué le scan avec MBAM. Simplement je n'ai pas réussi a fermer quelques fenêtres de l'explorateur IE. Dois-je recommencer ?

    Sinon voici le log. Encore merci

     

    Malwarebytes' Anti-Malware 1.24

    Version de la base de données: 1028

    Windows 5.1.2600 Service Pack 2

     

    15:16:49 06/08/2008

    mbam-log-8-6-2008 (15-16-49).txt

     

    Type de recherche: Examen rapide

    Eléments examinés: 42971

    Temps écoulé: 3 minute(s), 11 second(s)

     

    Processus mémoire infecté(s): 0

    Module(s) mémoire infecté(s): 2

    Clé(s) du Registre infectée(s): 14

    Valeur(s) du Registre infectée(s): 4

    Elément(s) de données du Registre infecté(s): 16

    Dossier(s) infecté(s): 8

    Fichier(s) infecté(s): 23

     

    Processus mémoire infecté(s):

    (Aucun élément nuisible détecté)

     

    Module(s) mémoire infecté(s):

    C:\WINDOWS\xokvrpwg.dll (Trojan.Zlob) -> Delete on reboot.

    C:\WINDOWS\tfnslopk.dll (Trojan.FakeAlert) -> Delete on reboot.

     

    Clé(s) du Registre infectée(s):

    HKEY_CLASSES_ROOT\CLSID\{5d6475d7-b1cc-43a1-b8f4-c4e475626950} (Trojan.Zlob) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\CLSID\{f7a8deb8-d848-47ca-9f08-406b55711883} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\TypeLib\{81bd5880-399d-4e7b-9857-ea80881796fd} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{8b128fcd-b170-4458-aea0-f38050ecfbba} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\CLSID\{905562ef-6f86-4ff3-9963-5ab66372d3a8} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\TypeLib\{e170464b-6850-4d51-912c-b3a508923658} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{06338a1e-d2e0-4a1b-b5b4-8e82772edf42} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{20c41a33-2dde-4e42-b055-039fcfa487b3} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\CLSID\{17c24e63-9a2c-4c50-bf01-86212b497bc7} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{17c24e63-9a2c-4c50-bf01-86212b497bc7} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\bgrqfetx.bapg (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\bgrqfetx.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\SecuriSoft SARL (Trojan.FakeAlert) -> Quarantined and deleted successfully.

     

    Valeur(s) du Registre infectée(s):

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\xokvrpwg (Trojan.Zlob) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0\source (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\tfnslopk (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{905562ef-6f86-4ff3-9963-5ab66372d3a8} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

     

    Elément(s) de données du Registre infecté(s):

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.Homepage) -> Bad: (http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId (Trojan.FakeAlert) -> Bad: (VIRUS ALERT!) Good: (76413-OEM-0011903-00102) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\Control Panel\International\sTimeFormat (Trojan.FakeAlert) -> Bad: (HH:mm: VIRUS ALERT!) Good: (HH:mm:ss) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowControlPanel (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowRun (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoStartMenuMorePrograms (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives (Hijack.Drives) -> Bad: (12) Good: (0) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoToolbarCustomize (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispCPL (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

     

    Dossier(s) infecté(s):

    C:\WINDOWS\privacy_danger (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\WINDOWS\privacy_danger\images (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\BASE (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\DELETED (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\SAVED (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

     

    Fichier(s) infecté(s):

    C:\WINDOWS\xokvrpwg.dll (Trojan.Zlob) -> Quarantined and deleted successfully.

    C:\WINDOWS\eovn.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\WINDOWS\privacy_danger\index.htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\WINDOWS\privacy_danger\images\capt.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\WINDOWS\privacy_danger\images\danger.jpg (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\WINDOWS\privacy_danger\images\down.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\WINDOWS\privacy_danger\images\spacer.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\wspwprtct.exe (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080805103935484.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080805104752078.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080805105518671.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080805113256765.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080805121609515.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.

    C:\WINDOWS\tfnslopk.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\WINDOWS\lnvegaow.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\WINDOWS\bgrqfetx.dll (Trojan.FakeAlert) -> Delete on reboot.

    C:\WINDOWS\wnlmdakqfne.dll (Trojan.FakeAlert) -> Delete on reboot.

    C:\Documents and Settings\recovery\Bureau\Spyware&Malware Protection.url (Rogue.Link) -> Quarantined and deleted successfully.

    C:\Documents and Settings\recovery\Bureau\Privacy Protector.url (Rogue.Link) -> Quarantined and deleted successfully.

    C:\Documents and Settings\recovery\Bureau\Error Cleaner.url (Rogue.Link) -> Quarantined and deleted successfully.

    C:\Documents and Settings\recovery\Favoris\Error Cleaner.url (Rogue.Link) -> Quarantined and deleted successfully.

    C:\Documents and Settings\recovery\Favoris\Privacy Protector.url (Rogue.Link) -> Quarantined and deleted successfully.

    C:\Documents and Settings\recovery\Favoris\Spyware&Malware Protection.url (Rogue.Link) -> Quarantined and deleted successfully.

  13. Merci de ta réponse aussi rapide

    Le fond d'écran est toujours présent et un certain nombre de fonction difficilement accessible ...

    ---

    Voici le rapport SDFix

    ---

    SDFix: Version 1.212

    Run by recovery on 05/08/2008 at 12:21

     

    Microsoft Windows XP [version 5.1.2600]

    Running From: C:\SDFix

     

    Checking Services :

     

     

    Restoring Default Security Values

    Restoring Default Hosts File

    Restoring Windows ProductId To Remove Fake Virus Alert

    Restoring Time Format To Remove Fake Virus Alert

     

    Rebooting

     

     

    Checking Files :

     

    Trojan Files Found:

     

    C:\Documents and Settings\Adm\Bureau\Error Cleaner.url - Deleted

    C:\Documents and Settings\Adm\Favoris\Error Cleaner.url - Deleted

    C:\Documents and Settings\recovery\Bureau\Error Cleaner.url - Deleted

    C:\Documents and Settings\recovery\Favoris\Error Cleaner.url - Deleted

    C:\Documents and Settings\Adm\Bureau\Privacy Protector.url - Deleted

    C:\Documents and Settings\Adm\Favoris\Privacy Protector.url - Deleted

    C:\Documents and Settings\recovery\Bureau\Privacy Protector.url - Deleted

    C:\Documents and Settings\recovery\Favoris\Privacy Protector.url - Deleted

    C:\Documents and Settings\Adm\Bureau\Spyware&Malware Protection.url - Deleted

    C:\Documents and Settings\Adm\Favoris\Spyware&Malware Protection.url - Deleted

    C:\Documents and Settings\recovery\Bureau\Spyware&Malware Protection.url - Deleted

    C:\Documents and Settings\recovery\Favoris\Spyware&Malware Protection.url - Deleted

    C:\WINDOWS\privacy_danger\index.htm - Deleted

    C:\WINDOWS\privacy_danger\images\capt.gif - Deleted

    C:\WINDOWS\privacy_danger\images\danger.jpg - Deleted

    C:\WINDOWS\privacy_danger\images\down.gif - Deleted

    C:\WINDOWS\privacy_danger\images\spacer.gif - Deleted

    C:\DOCUME~1\recovery\LOCALS~1\Temp\lwpwer.exe.bat - Deleted

    C:\DOCUME~1\recovery\LOCALS~1\Temp\lwpwer.exe - Deleted

    C:\DOCUME~1\recovery\LOCALS~1\Temp\lwpwer.exe.bat - Deleted

    C:\DOCUME~1\recovery\LOCALS~1\Temp\s1265.php.bat - Deleted

    C:\WINDOWS\system32\nvrsul32.dll - Deleted

     

     

     

    Folder C:\WINDOWS\privacy_danger - Removed

     

     

    Removing Temp Files

     

    ADS Check :

     

     

     

    Final Check :

     

    catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2008-08-05 12:39:20

    Windows 5.1.2600 Service Pack 2 NTFS

     

    scanning hidden processes ...

     

    scanning hidden services & system hive ...

     

    scanning hidden registry entries ...

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]

    "TracesProcessed"=dword:000000d6

    "TracesSuccessful"=dword:00000009

     

    scanning hidden files ...

     

    scan completed successfully

    hidden processes: 0

    hidden services: 0

    hidden files: 0

     

     

    Remaining Services :

     

     

     

     

    Authorized Application Key Export:

     

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"

    "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:*:Enabled:ActiveSync Connection Manager"

    "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:*:Enabled:ActiveSync Application"

    "C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"="C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe:*:Enabled:Adobe Version Cue CS2"

    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

    "C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client\\SmartFTP.exe:*:Enabled:SmartFTP Client 2.5"

    "C:\\WINDOWS\\explorer.exe"="C:\\WINDOWS\\explorer.exe:*:Enabled:Explorateur Windows"

    "C:\\Program Files\\Canon\\Color Network ScanGear\\SgTool.exe"="C:\\Program Files\\Canon\\Color Network ScanGear\\SgTool.exe:*:Disabled:SGTOOL"

     

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

     

    Remaining Files :

     

     

    File Backups: - C:\SDFix\backups\backups.zip

     

    Files with Hidden Attributes :

     

    Wed 13 Oct 2004 1,694,208 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"

    Wed 16 Jul 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT14.tmp"

    Tue 22 Aug 2006 19,456 A..H. --- "C:\Lignes supprimées avec ma mimine........

     

    Finished!

    ----------------------------------------------------------

    Puis le report HijackThis

     

    ---

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 12:54: VIRUS ALERT!, on 05/08/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16674)

    Boot mode: Normal

     

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe

    C:\WINDOWS\system32\nvsvc32.exe

    C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe

    C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe

    C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe

    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

    C:\WINDOWS\stsystra.exe

    C:\WINDOWS\System32\DLA\DLACTRLW.EXE

    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe

    C:\Program Files\Unlocker\UnlockerAssistant.exe

    C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe

    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    C:\Documents and Settings\recovery\Bureau\HijackThis.exe

     

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=2070618

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=2070618

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.fr/ig/dell?hl=fr&cli...amp;ibd=2070618

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: QXK Olive - {17C24E63-9A2C-4C50-BF01-86212B497BC7} - C:\WINDOWS\wnlmdakqfne.dll

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll

    O3 - Toolbar: bgrqfetx - {905562EF-6F86-4FF3-9963-5AB66372D3A8} - C:\WINDOWS\bgrqfetx.dll

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

    O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE

    O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

    O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start

    O4 - HKLM\..\Run: [unlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"

    O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"

    O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"

    O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"

    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

    O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe

    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll

    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll

    O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O17 - HKLM\System\CCS\Services\Tcpip\..\{7414A25E-5D64-4FE0-85F0-D7C68C806CFC}: NameServer = 194.2.0.20,194.2.0.50

    O21 - SSODL: xokvrpwg - {5D6475D7-B1CC-43A1-B8F4-C4E475626950} - C:\WINDOWS\xokvrpwg.dll

    O21 - SSODL: tfnslopk - {F7A8DEB8-D848-47CA-9F08-406B55711883} - C:\WINDOWS\tfnslopk.dll

    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe

    O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe

    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe

    O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

     

    --

    End of file - 8771 bytes

×
×
  • Créer...