

matt313
Membres-
Compteur de contenus
2 -
Inscription
-
Dernière visite
Autres informations
-
Mes langues
français / anglais
matt313's Achievements

Junior Member (3/12)
0
Réputation sur la communauté
-
PC infecté / publicités intempestives ...
matt313 a répondu à un(e) sujet de matt313 dans Analyses et éradication malwares
Merci. Voici le rapport : Rapport de ZHPDiag v1.28.1346 par Nicolas Coolman, Update du 29/08/2011 Run by Matt at 08/09/2011 23:22:14 Web site : ZHPDiag Outil de diagnostic ---\\ Web Browser MSIE: Internet Explorer v7.0.6000.17037 MFIE: Mozilla Firefox 6.0.1 v6.0.1 (Defaut) ---\\ Windows Product Information Windows Vista Home Premium Edition, 32-bit (Build 6000) Windows Server License Manager Script : OK ~ Vista, OEM_SLP channel System Locked Preinstallation (OEM_SLP) : OK Windows ID Activation : OK ~ Windows Partial Key : G6MF9 Windows License : OK Windows Automatic Updates : OK ---\\ System Information ~ Processor: x86 Family 6 Model 15 Stepping 6, GenuineIntel ~ Operating System: 32 Bits Boot mode: Normal (Normal boot) Total RAM: 2045 MB (68% free) System Restore: Activé (Enable) System drive C: has 29 GB (20%) free of 140 GB ---\\ Logged in mode ~ Computer Name: PC-DE-MATT ~ User Name: Matt ~ All Users Names: Matt, Administrateur, ~ Unselected Option: O45,O61,O62,O65,O66,O82 Logged in as Administrator ---\\ Environnement Variables ~ System Unit : C:\ ~ %AppData% : C:\Users\Matt\AppData\Roaming\ ~ %Desktop% : C:\Users\Matt\Desktop\ ~ %Favorites% : C:\Users\Matt\Favorites\ ~ %LocalAppData% : C:\Users\Matt\AppData\Local\ ~ %StartMenu% : C:\Users\Matt\AppData\Roaming\Microsoft\Windows\Start Menu\ ~ %Windir% : C:\Windows\ ~ %System% : C:\Windows\system32\ ---\\ DOS/Devices C:\ Hard drive, Flash drive, Thumb drive (Free 29 Go of 140 Go) D:\ Floppy drive, Flash card reader, USB Key (Free 51 Go of 60 Go) E:\ CD-ROM drive (Not Inserted) F:\ CD-ROM drive (Not Inserted) G:\ Floppy drive, Flash card reader, USB Key (Free 0 Go of 1 Go) ---\\ Security Center & Tools Informations [HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK [HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK [HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoStartMenuSubFolder: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoResolveSearch: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoClose: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableRegistryTools: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoDispScrSavPage: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : OK ~ Scan Security Center in 00mn 00s ---\\ Recherche particulière de fichiers génériques [MD5.37440D09DEAE0B672A04DCCF7ABF06BE] - (.Microsoft Corporation - Explorateur Windows.) (.10/12/2008 - 07:20:29.) -- C:\Windows\Explorer.exe [2923520] [MD5.4B555106290BD117334E9A08761C035A] - (....) (.02/01/2007 - 10:45:37.) -- C:\Windows\system32\rundll32.exe [44544] [MD5.D4385B03E8CCCEE6F0EE249F827C1F3E] - (.Microsoft Corporation - Application de démarrage de Windows.) (.02/01/2007 - 10:45:57.) -- C:\Windows\system32\Wininit.exe [95744] [MD5.0F340B61FA7221DDF8B8375BC0217B71] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.03/04/2010 - 17:54:49.) -- C:\Windows\system32\wininet.dll [832512] [MD5.9F75392B9128A91ABAFB044EA350BAAD] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.02/01/2007 - 10:45:57.) -- C:\Windows\system32\Winlogon.exe [308224] [MD5.B35CFCEF838382AB6490B321C87EDF17] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.13/02/2008 - 23:05:24.) -- C:\Windows\system32\drivers\atapi.sys [21560] [MD5.37430AA7A66D7A63407ADC2C0D05E9F6] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.11/03/2008 - 23:50:41.) -- C:\Windows\system32\drivers\ntfs.sys [1060920] [MD5.FF524497A864EDF9C040E31DB29D6449] - (....) (.02/01/2007 - 16:41:45.) -- C:\Windows\system32\fr-FR\user32.dll.mui [20480] ~ Scan Generic Processes in 00mn 00s ---\\ Etat des fichiers cachés (Caché/Total) ~ Mes images (My Pictures) : 34/7393 ~ Mes musiques (My Musics) : 235/932 ~ Mes Videos (My Videos) : 1/6 ~ Mes Favoris (My Favorites) : 46/456 ~ Mes Documents (My Documents) : 20/313 ~ Mon Bureau (My Desktop) : 42/2569 ~ Menu demarrer (Programs) : 7/24 ~ Scan Hidden Files in 00mn 10s ---\\ Processus lancés [MD5.AFA1F8CC076AB0462512A78473D86D53] - (.BitTorrent, Inc. - DNA.) -- C:\Users\Matt\Program Files\DNA\btdna.exe [323392] [PID.2220] [MD5.6FB6057066E2AC3434AFD6152C471840] - (.Sony Corporation - VAIO Update.) -- C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe [546936] [PID.2352] [MD5.83E9CD075F8D80D19609AB0FF6EAF5D6] - (.Sony Corporation - Wireless Switch Setting Utility.) -- C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe [465016] [PID.2368] [MD5.A3281C695E7280D402A635442D85F88F] - (.TOSHIBA CORPORATION. - TosBtMng.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2134016] [PID.2376] [MD5.9041C38ED44C81016CE03162E9F134CD] - (.TOSHIBA CORPORATION. - TosA2dp.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe [274432] [PID.2644] [MD5.2C92B17E820094F37037B6CE114BEB69] - (.TOSHIBA CORPORATION. - Pas de description.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe [69632] [PID.2796] [MD5.8C35DB52F07A78E8DF230D76F141FD29] - (.TOSHIBA CORPORATION. - TosBtHSP.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe [270336] [PID.3040] [MD5.93FA8AD0F0B1466C80D38DE3361B0EA2] - (.TOSHIBA CORPORATION. - TosAVRC.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe [270336] [PID.3748] [MD5.7914370AAC5CDE8DCAE1C674A6C90229] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [669696] [PID.3264] [MD5.05CB3DA78A4BBD9B799A5957F9D101CC] - (.Microsoft Corporation - Console IME.) -- C:\Windows\system32\conime.exe [68608] [PID.2152] [MD5.A1DCD30534835CB67733AD00175125A6] - (.Microsoft Corporation - Service de gestion des licences Microsoft.) -- C:\Windows\system32\SLsvc.exe [2605568] [PID.] [MD5.00E36BEEA22C92D1030C6D8F80BC0F6A] - (.Microsoft Corporation - SQL Server Windows NT.) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29262680] [PID.] [MD5.D2F4F32B59440011174B4F8137AF4E0C] - (.Microsoft Corporation - SQL Server VSS Writer.) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [87904] [PID.] [MD5.28DC5D626E036A75A572556F0A6EB1F6] - (.Conexant Systems, Inc. - Modem Audio Service.) -- C:\Windows\system32\DRIVERS\xaudio.exe [386560] [PID.] ~ Scan Processes Running in 00mn 01s ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3) C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\tox6nznd.default\prefs.js C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\tox6nznd.default\user.js M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\avg_igeared.xml M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml M2 - MFEP: prefs.js [Matt - tox6nznd.default\{20a82645-c095-46ed-80e3-08825760534b}] [MicrosoftCG] Microsoft .NET Framework Assistant v1.1 (.Microsoft.) P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files\Mozilla Firefox\Plugins\np-mswmp.dll P2 - FPN:Firefox Plugin Navigator . (.BitTorrent, Inc. - BitTorrent Plugin 1.) -- C:\Program Files\Mozilla Firefox\Plugins\npbittorrent.dll P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeployJava1.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin2.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin3.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin4.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin5.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin6.dll P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin7.dll P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32.dll P2 - FPN: [HKLM] [@adobe.com/ShockwavePlayer] - (.Adobe Systems, Inc. - Adobe Shockwave for Director Netscape plug-in, version 11.5.) -- C:\Windows\system32\Adobe\Director\np32dsw.dll P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll P2 - FPN: [HKLM] [@bittorrent.com/BitTorrentDNA] - (.BitTorrent, Inc. - Delivery Network Acceleration by BitTorrent™.) -- C:\Program Files\DNA\plugins\npbtdna.dll P2 - FPN: [HKLM] [@divx.com/DivX Browser Plugin,version=1.0.0] - (...) -- C:\Program Files\DivX\DivX Web Player\npdivx32.dll (.not file.) P2 - FPN: [HKLM] [@divx.com/DivX Content Upload Plugin,version=1.0.0] - (.DivX,Inc. - DivX® Content Upload Plugin.) -- C:\Program Files\DivX\DivX Content Uploader\npUpload.dll P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll P2 - FPN: [HKLM] [@google.com/npPicasa3,version=3.0.0] - (.Google, Inc. - Picasa plugin.) -- C:\Program Files\Google\Picasa3\npPicasa3.dll P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll P2 - FPN: [HKCU] [@bittorrent.com/BitTorrentDNA] - (.BitTorrent, Inc. - Delivery Network Acceleration by BitTorrent™.) -- C:\Users\Matt\Program Files\DNA\plugins\npbtdna.dll P2 - FPN: [HKCU] [@facebook.com/FBPlugin,version=1.0.3] - (.Pas de propriétaire - Provides additional functionality on Facebook. See <a href="http://www.) -- C:\Users\Matt\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll P2 - FPN: [HKCU] [@talk.google.com/GoogleTalkPlugin] - (.Google - Version 2.2.2.0.) -- C:\Users\Matt\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll P2 - FPN: [HKCU] [@talk.google.com/O3DPlugin] - (.Pas de propriétaire - Google Talk Plugin Video Accelerator version:0.1.44.9.) -- C:\Users\Matt\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Users\Matt\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Users\Matt\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll ~ Scan Firefox Browser in 00mn 00s ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Bing, Actualité et Sport R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Bing, Actualité et Sport R0 - HKUS\S-1-5-21-2335098037-1364520116-3212336512-1003\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Bing, Actualité et Sport R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Microsoft Corporation R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Microsoft Corporation R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = Bing R1 - HKUS\S-1-5-21-2335098037-1364520116-3212336512-1003\Software\Microsoft\Internet Explorer\Main,Search Page = Microsoft Corporation R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (7.00.6000.16386 (vista_rtm.061101-2205)) -- C:\Windows\system32\ieframe.dll R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} . (...) (No version) -- (.not file.) R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2 ~ Scan IE Browser in 00mn 00s ---\\ Internet Explorer, Proxy Management (R5) R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ~ Scan Proxy management in 00mn 00s ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2) F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe, F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl" ~ Scan Keys in 00mn 00s ---\\ Redirection du fichier Hosts (O1) ~ Scan Hosts File in 00mn 00s ---\\ Browser Helper Objects de navigateur (O2) O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Mediafour XPlay Explorer notifications - {4907C0AD-874D-44D9-B13E-7B0A4D8B9D3E} . (.Mediafour Corporation - Pas de description.) -- C:\Program Files\Mediafour\XPlay 3\XPBHO.DLL O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} . (.Safer Networking Limited - SBSD IE Protection.) -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} Clé orpheline O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} . (.Your Company Name - BAE.dll.) -- C:\PROGRA~1\GOOGLE~1\BAE.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll ~ Scan BHO in 00mn 00s ---\\ Applications démarrées par registre & par dossier (O4) O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe O4 - HKCU\..\Run: [bitTorrent DNA] . (.BitTorrent, Inc. - DNA.) -- C:\Users\Matt\Program Files\DNA\btdna.exe O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] . (.Microsoft Corporation - Chargeur CTF.) -- C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] . (.Microsoft Corporation - Chargeur CTF.) -- C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-21-2335098037-1364520116-3212336512-1003\..\Run: [bitTorrent DNA] . (.BitTorrent, Inc. - DNA.) -- C:\Users\Matt\Program Files\DNA\btdna.exe ~ Scan Application in 00mn 00s ---\\ Autres liens utilisateurs (O4) O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Mail\WinMail.exe O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe O4 - Global Startup: C:\Users\Matt\Desktop\Ad-Aware.lnk . (...) -- C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe (.not file.) O4 - Global Startup: C:\Users\Matt\Desktop\ColorPic.lnk . (...) -- C:\Program Files\ColorPic 4.1\ColorPic.exe O4 - Global Startup: C:\Users\Matt\Desktop\Grand Dictionnaire Hachette Oxford.lnk . (.Oxford University Press.) -- C:\Program Files\GDHO\gdho.exe O4 - Global Startup: C:\Users\Matt\Desktop\Incoming - Raccourci.lnk . (...) -- C:\Program Files\eMule\Incoming O4 - Global Startup: C:\Users\Matt\Desktop\PhotoFiltre.lnk . (.Antonio Da Cruz.) -- C:\Program Files\PhotoFiltre\photofiltre.exe O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Démarrer Microsoft Office Outlook.lnk . (.Microsoft Corporation.) -- C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk . (...) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe ~ Scan Global Startup in 00mn 00s ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8) O8 - Extra context menu item: Add to Google Photos Screensa&ver . (.Google Inc. - Google Photos Screensaver.) -- C:\Windows\system32\GPhotos.scr O8 - Extra context menu item: Ajouter un site de support RSS à VAIO Information FLOW . (...) -- C:\Program Files\Sony\VAIO Information FLOW\aiesc.html O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.exe ~ Scan IE Menu Contextuel in 00mn 00s ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9) O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\PROGRA~1\MICROS~3\OFFICE11\REFBARH.ICO O9 - Extra button: Recherche - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} -- C:\Program Files\Bodog Poker\BPGame.exe (.not file.) ~ Scan IE Extra Buttons in 00mn 00s ---\\ Winsock hijacker (Layered Service Provider) (O10) O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll O10 - WLSP:\000000000007\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll ~ Scan Winsock in 00mn 00s ---\\ Objets ActiveX (Downloaded Program Files)(O16) O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab ~ Scan Objets ActiveX in 00mn 00s ---\\ Protocole additionnel (O18) O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\system32\mshtml.dll O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\system32\mshtml.dll O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler.) -- C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\system32\mshtml.dll O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\system32\inetcomm.dll O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler.) -- C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Handler: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} . (.Microsoft Corporation - Microsoft Office XP Web Components.) -- C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL O18 - Handler: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} . (.Microsoft Corporation - Microsoft Office Web Components 2003.) -- C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\system32\mshtml.dll O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\system32\mshtml.dll O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL ~ Scan Protocole Additionnel in 00mn 00s ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20) O20 - Winlogon Notify: VESWinlogon . (.Sony Corporation - VAIO Event Service (Winlogon Notification M.) -- C:\Windows\system32\VESWinlogon.dll ~ Scan Winlogon in 00mn 00s ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Contrôleur de site Web.) -- C:\Windows\system32\webcheck.dll ~ Scan SSODL in 00mn 00s ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22) O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\system32\browseui.dll ~ Scan STS/SSO in 00mn 00s ---\\ Liste des services NT non Microsoft et non désactivés (O23) O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) . (...) - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe (.not file.) O23 - Service: Apple Mobile Device (Apple Mobile Device) . (...) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (.not file.) O23 - Service: Service Bonjour (Bonjour Service) . (...) - C:\Program Files\Bonjour\mDNSResponder.exe (.not file.) O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) . (...) - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (.not file.) O23 - Service: Service Google Update (gupdate) (gupdate) . (...) - C:\Program Files\Google\Update\GoogleUpdate.exe (.not file.) O23 - Service: M4iPodWPDService (M4iPodWPDService) . (...) - C:\Program Files\Common Files\Mediafour\iPod\M4iPodWPDService.exe (.not file.) O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) . (...) - C:\Windows\system32\sfrem01.exe (.not file.) O23 - Service: SigmaTel Audio Service (STacSV) . (...) - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe (.not file.) O23 - Service: TOSHIBA Bluetooth Service (TOSHIBA Bluetooth Service) . (...) - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (.not file.) O23 - Service: VAIO Event Service (VAIO Event Service) . (...) - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) . (...) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (.not file.) O23 - Service: VAIO Entertainment File Import Service (VzFw) . (...) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (.not file.) O23 - Service: XAudioService (XAudioService) . (.Conexant Systems, Inc. - Modem Audio Service.) - C:\Windows\system32\DRIVERS\xaudio.exe ~ Scan Services in 00mn 00s ---\\ Enumération Active Desktop & MHTML Editor (O24) O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Office Word.) - C:\Program Files\Microsoft Office\OFFICE11\WINWORD.exe ~ Scan Desktop Component in 00mn 00s ---\\ Tâches planifiées en automatique (O39) O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2335098037-1364520116-3212336512-1003Core.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2335098037-1364520116-3212336512-1003UA.job O39 - APT:Automatic Planified Task - C:\Windows\Tasks\User_Feed_Synchronization-{749F7267-3809-4F65-A674-B375A4B1B6E4}.job ~ Scan Scheduled Task in 00mn 00s ---\\ Pilotes lancés au démarrage (O41) O41 - Driver: (CbFs) . (.EldoS Corporation - Callback File System Driver.) - C:\Windows\system32\drivers\cbfs.sys O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\DRIVERS\cdrom.sys O41 - Driver: (DfsC) . (.Microsoft Corporation - DFS Client MUP Surrogate Driver.) - C:\Windows\system32\Drivers\dfsc.sys O41 - Driver: (DMICall) . (.Sony Corporation - Windows 2000 DMI Call Kernel Driver.) - C:\Windows\system32\DRIVERS\DMICall.sys O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\system32\DRIVERS\i8042prt.sys O41 - Driver: (kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\system32\DRIVERS\kbdclass.sys O41 - Driver: (mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\system32\DRIVERS\mouclass.sys O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\system32\DRIVERS\netbios.sys O41 - Driver: (netbt) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\system32\DRIVERS\netbt.sys O41 - Driver: (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\system32\drivers\nsiproxy.sys O41 - Driver: C:\Windows\system32\drivers\pacer.sys (PSched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\system32\DRIVERS\pacer.sys O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\system32\DRIVERS\rasacd.sys O41 - Driver: (rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\system32\DRIVERS\rdbss.sys O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\DRIVERS\RDPCDD.sys O41 - Driver: (RDPENCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\drivers\rdpencdd.sys O41 - Driver: C:\Windows\system32\tcpipcfg.dll (Smb) . (.Microsoft Corporation - SMB Transport driver.) - C:\Windows\system32\DRIVERS\smb.sys O41 - Driver: C:\Windows\system32\tcpipcfg.dll (Tcpip) . (.Microsoft Corporation - TCP/IP Driver.) - C:\Windows\system32\drivers\tcpip.sys O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\system32\DRIVERS\termdd.sys O41 - Driver: (Tosrfcom) . (.TOSHIBA Corporation - Bluetooth RFCOMM Driver.) - C:\Windows\system32\Drivers\tosrfcom.sys O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys O41 - Driver: (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\system32\DRIVERS\wanarp.sys ~ Scan Drivers in 00mn 00s ---\\ Logiciels installés (O42) O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin O42 - Logiciel: Adobe Photoshop Elements 5.0 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Photoshop Elements 5 O42 - Logiciel: Adobe Shockwave Player 11.5 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Shockwave Player O42 - Logiciel: Alps Pointing-device for VAIO - (.Pas de propriétaire.) [HKLM] -- {9F72EF8B-AEC9-4CA5-B483-143980AFD6FD} O42 - Logiciel: Archiveur WinRAR - (.Pas de propriétaire.) [HKLM] -- WinRAR archiver O42 - Logiciel: AviSynth 2.5 - (.Pas de propriétaire.) [HKLM] -- AviSynth O42 - Logiciel: Azureus Vuze - (.Vuze, Inc..) [HKLM] -- Azureus Vuze O42 - Logiciel: BS Contact VRML/X3D - (.Bitmanagement Software GmbH.) [HKLM] -- {2928EFE3-4841-4571-AD29-9900AB10943E} O42 - Logiciel: BitTorrent - (.BitTorrent, Inc.) [HKCU] -- BitTorrent O42 - Logiciel: Browser Address Error Redirector - (.Pas de propriétaire.) [HKLM] -- {3EE33958-7381-4E7B-A4F3-6E43098E9E9C} O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner O42 - Logiciel: Click to DVD 2.0.05 Menu Data - (.Sony Corporation.) [HKLM] -- {9E407618-D9CD-4F39-9490-9ED45294073D} O42 - Logiciel: Click to DVD 2.6.00 - (.Sony Corporation.) [HKLM] -- {E809063C-51A3-4269-8984-D1EB742F2151} O42 - Logiciel: ColorPic - (.Iconico.) [HKLM] -- ColorPic O42 - Logiciel: CopyTrans Suite Remove Only - (.Pas de propriétaire.) [HKLM] -- CopyTrans Suite O42 - Logiciel: DNA - (.BitTorrent Inc..) [HKCU] -- BitTorrent DNA O42 - Logiciel: DVgate Plus - (.Sony Corporation.) [HKLM] -- {685BCC47-B8EC-45EC-BBCE-77DF2451502C} O42 - Logiciel: DivX Content Uploader - (.DivX, Inc..) [HKLM] -- {D050D7362D214723AD585B541FFB6C11} O42 - Logiciel: DivX Web Player - (.DivX,Inc..) [HKLM] -- {B7050CBDB2504B34BC2A9CA0A692CC29} O42 - Logiciel: EPSON Stylus SX400 Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM] -- EPSON Stylus SX400 Series O42 - Logiciel: Facebook Plug-In - (.Facebook, Inc..) [HKCU] -- Facebook Plug-In O42 - Logiciel: FastStone Capture 5.2 (French) - (.FastStone Soft.) [HKLM] -- FastStone Capture O42 - Logiciel: GDR 4053 for SQL Server Database Services 2005 ENU (KB970892) - (.Microsoft Corporation.) [HKLM] -- KB970892_SQL9 O42 - Logiciel: Grand Dictionnaire Hachette-Oxford - (.Pas de propriétaire.) [HKLM] -- Grand Dictionnaire Hachette-Oxford O42 - Logiciel: HDAUDIO SoftV92 Data Fax Modem with SmartCP - (.Pas de propriétaire.) [HKLM] -- CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200 O42 - Logiciel: HotKey Utility - (.Pas de propriétaire.) [HKLM] -- {B36C3DFD-BAB0-4513-BD27-FA4906A738FD} O42 - Logiciel: HotKey Utility - (.Pas de propriétaire.) [HKLM] -- {BB311F54-39D6-4A03-8E18-053D1B2833D7} O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595 O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484 O42 - Logiciel: Intel® PRO Network Connections Drivers - (.Pas de propriétaire.) [HKLM] -- PROSet O42 - Logiciel: LAN Setting Utility - (.Sony Corporation.) [HKLM] -- {5958CAC6-373E-402F-84FE-0A699AA920B9} O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1 O42 - Logiciel: Microsoft SQL Server 2005 - (.Microsoft Corporation.) [HKLM] -- Microsoft SQL Server 2005 O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 Language Pack SP1 - fra O42 - Logiciel: Mozilla Firefox 6.0.1 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 6.0.1 (x86 fr) O42 - Logiciel: Octoshape add-in for Adobe Flash Player - (.Pas de propriétaire.) [HKCU] -- Octoshape add-in for Adobe Flash Player O42 - Logiciel: OpenMG Secure Module 4.6.01 - (.Sony Corporation.) [HKLM] -- InstallShield_{3D79DB6E-73DA-46C9-B8FA-DAE52108246F} O42 - Logiciel: Outil VAIO Media Registration 6.0 - (.Sony Corporation.) [HKLM] -- {AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6} O42 - Logiciel: PDFCreator - (.Frank Heindörfer, Philip Chinery.) [HKLM] -- {0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D} O42 - Logiciel: PhotoFiltre - (.Pas de propriétaire.) [HKCU] -- PhotoFiltre O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM] -- Picasa 3 O42 - Logiciel: Plugins SonicStage Mastering Studio - (.Sony Corporation.) [HKLM] -- {9C1C8A04-F8CA-4472-A92D-4288CE32DE86} O42 - Logiciel: PokerStars - (.PokerStars.com.) [HKLM] -- PokerStars O42 - Logiciel: SanDisk_Button_Manager.exe - (.DMAILER.) [HKCU] -- {7994634D-6165-49f7-A296-F60D4F87E1EC}SanDisk_Button_Manager.exe O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- KB931906 O42 - Logiciel: Setting Utility Series - (.Sony Corporation.) [HKLM] -- {59452470-A902-477F-9338-9B88101681BD} O42 - Logiciel: SigmaTel Audio - (.SigmaTel.) [HKLM] -- {A462213D-EED4-42C2-9A60-7BDD4D4B0B17} O42 - Logiciel: SonicStage 4.2 - (.Sony Corporation.) [HKLM] -- {A0EB195B-5876-48E6-879D-33D4B2102610} O42 - Logiciel: SonicStage Mastering Studio - (.Sony Corporation.) [HKLM] -- {6332AFF1-9D9A-429C-AA03-F82749FA4F49} O42 - Logiciel: SonicStage Mastering Studio Audio Filter - (.Sony Corporation.) [HKLM] -- {DF7DB916-90E5-40F2-9010-B8125EB5FD6F} O42 - Logiciel: SonicStage Mastering Studio Audio Filter Custom Preset - (.Sony Corporation.) [HKLM] -- {EC37A846-53AC-4DA7-98FA-76A4E74AA900} O42 - Logiciel: Sony Utilities DLL - (.Sony Corporation.) [HKLM] -- {EF3D45BB-2260-4008-88EA-492E7744A9DF} O42 - Logiciel: Sony Video Shared Library - (.Sony Corporation.) [HKLM] -- {01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902} O42 - Logiciel: SoulSeek Client 156c - (.Pas de propriétaire.) [HKLM] -- Soulseek O42 - Logiciel: SpaceMonger 2.1.1 - (.Sixty-Five.) [HKLM] -- SpaceMonger O42 - Logiciel: Spybot - Search & Destroy - (.Safer Networking Limited.) [HKLM] -- {B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 O42 - Logiciel: Spybot - Search & Destroy 1.3 - (.Safer Networking Limited.) [HKLM] -- Spybot - Search & Destroy_is1 O42 - Logiciel: System Requirements Lab - (.Pas de propriétaire.) [HKLM] -- SystemRequirementsLab O42 - Logiciel: Time Adjuster STANDARD 3.1 - (.IrekSoftware.com.) [HKCU] -- TimeAdjuster O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707 O42 - Logiciel: VAIO Aqua Breeze Wallpaper - (.Sony Corporation.) [HKLM] -- {97BCD719-6ECB-458F-97D6-F38D2E07375E} O42 - Logiciel: VAIO Camera Capture Utility - (.Sony Corporation.) [HKLM] -- {6D2576EC-A0E9-418A-A09A-409933A3B6F4} O42 - Logiciel: VAIO Camera Utility - (.Sony Corporation.) [HKLM] -- {1417F599-1DBD-4499-9375-B2813E9F890C} O42 - Logiciel: VAIO Control Center - (.Sony Corporation.) [HKLM] -- {FC37C108-821D-4EDE-8F40-D5B497586805} O42 - Logiciel: VAIO Cozy Orange Wallpaper - (.Sony Corporation.) [HKLM] -- {2A2FF7F5-6F0E-4A5D-A881-39365E718BD6} O42 - Logiciel: VAIO Data Restore Tool - (.Pas de propriétaire.) [HKLM] -- {57B955CE-B5D3-495D-AF1B-FAEE0540BFEF} O42 - Logiciel: VAIO Entertainment Platform - (.Sony Corporation.) [HKLM] -- {6B1F20F2-6321-4669-A58C-33DF8E7517FF} O42 - Logiciel: VAIO Event Service - (.Sony Corporation.) [HKLM] -- {F0D85ADD-DD61-4B43-87A0-6DA52A211A8B} O42 - Logiciel: VAIO Hardware Diagnostics - (.Pas de propriétaire.) [HKLM] -- {A947C2B3-7445-42C4-9063-EE704CACCB22} O42 - Logiciel: VAIO Information FLOW - (.Sony Corporation.) [HKLM] -- {24960AC2-C413-4A86-B1C1-E4CCADCA44D3} O42 - Logiciel: VAIO Media 6.0 - (.Sony Corporation.) [HKLM] -- {560F6B2E-F0DF-44E5-8190-A4A161F0E205} O42 - Logiciel: VAIO Media AC3 Decoder 1.0 - (.Pas de propriétaire.) [HKLM] -- {2063C2E8-3812-4BBD-9998-6610F80C1DD4} O42 - Logiciel: VAIO Media Content Collection 6.0 - (.Sony Corporation.) [HKLM] -- {500162A0-4DD5-460A-BAFD-895AAE48C532} O42 - Logiciel: VAIO Media Integrated Server 6.0 - (.Sony Corporation.) [HKLM] -- {785EB1D4-ECEC-4195-99B4-73C47E187721} O42 - Logiciel: VAIO Media Redistribution 6.0 - (.Sony Corporation.) [HKLM] -- {5855C127-1F20-404D-B7FB-1FD84D7EAB5E} O42 - Logiciel: VAIO Photo 2007 - (.Sony Corporation.) [HKLM] -- {5E343EF6-D27C-4CFC-9FAE-9AAFB541BCEE} O42 - Logiciel: VAIO Power Management - (.Sony Corporation.) [HKLM] -- {9E319E96-ED8E-4B01-9775-C521A1869A25} O42 - Logiciel: VAIO Tender Green Wallpaper - (.Sony Corporation.) [HKLM] -- {934A3213-1CB6-4264-84A2-EE080C017BCA} O42 - Logiciel: VAIO Update 3 - (.Sony Corporation.) [HKLM] -- {48820099-ED7D-424B-890C-9A82EF00656D} O42 - Logiciel: Videora iPod touch Converter 3.07 - (.Red Kawa Inc..) [HKLM] -- Videora iPod touch Converter O42 - Logiciel: Visual C++ 2008 x86 Runtime - v9.0.30729.01 - (.Microsoft Corporation.) [HKLM] -- {F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01 O42 - Logiciel: WinDVD for VAIO - (.InterVideo Inc..) [HKLM] -- InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85} O42 - Logiciel: Wireless Switch Setting Utility - (.Sony Corporation.) [HKLM] -- {2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5} O42 - Logiciel: dBpoweramp Music Converter - (.Illustrate.) [HKLM] -- dBpoweramp Music Converter ---\\ HKCU & HKLM Software Keys [HKCU\Software\65] [HKCU\Software\Ad-Remover] [HKCU\Software\Adobe] [HKCU\Software\Alcohol Soft] [HKCU\Software\Alps] [HKCU\Software\AppDataLow\Aurigma] [HKCU\Software\AppDataLow\Software\AVG] [HKCU\Software\AppDataLow\Software\Adobe] [HKCU\Software\AppDataLow\Software\Macromedia] [HKCU\Software\AppDataLow\Software\Microsoft] [HKCU\Software\AppDataLow\Software] [HKCU\Software\AppDataLow] [HKCU\Software\Apple Computer, Inc.] [HKCU\Software\Apple Inc.] [HKCU\Software\Aurigma] [HKCU\Software\Avg] [HKCU\Software\Azureus] [HKCU\Software\BAE] [HKCU\Software\BST] [HKCU\Software\Bitmanagement Software] [HKCU\Software\Bodog Poker] [HKCU\Software\CDDB] [HKCU\Software\Classes] [HKCU\Software\Clients] [HKCU\Software\DT Soft] [HKCU\Software\DivXNetworks] [HKCU\Software\EPSON] [HKCU\Software\Full Tilt Poker] [HKCU\Software\GNU] [HKCU\Software\Gabest] [HKCU\Software\GameSpy] [HKCU\Software\GibbHill] [HKCU\Software\Google] [HKCU\Software\Gost Publishing] [HKCU\Software\IM Providers] [HKCU\Software\Illustrate] [HKCU\Software\InterVideo] [HKCU\Software\IrekZielinskiSoft] [HKCU\Software\JEDI-VCL] [HKCU\Software\JavaSoft] [HKCU\Software\Lake] [HKCU\Software\Lavasoft] [HKCU\Software\Licenses] [HKCU\Software\Local AppWizard-Generated Applications] [HKCU\Software\Macromedia] [HKCU\Software\Malwarebytes' Anti-Malware] [HKCU\Software\Mediafour] [HKCU\Software\MozillaPlugins] [HKCU\Software\Mozilla] [HKCU\Software\NVIDIA Corporation] [HKCU\Software\NVIDIA nvCpl Container] [HKCU\Software\Nadeo] [HKCU\Software\Netscape] [HKCU\Software\ODBC] [HKCU\Software\PDFCreator] [HKCU\Software\PDFDesk] [HKCU\Software\PepiMK Software] [HKCU\Software\Piriform] [HKCU\Software\Policies] [HKCU\Software\SCC] [HKCU\Software\Safer Networking Limited] [HKCU\Software\SecuROM] [HKCU\Software\Skype] [HKCU\Software\Sony Corporation] [HKCU\Software\SoulSeek] [HKCU\Software\SpoonInstall] [HKCU\Software\Symantec] [HKCU\Software\Sysinternals] [HKCU\Software\Toshiba] [HKCU\Software\Trolltech] [HKCU\Software\VB and VBA Program Settings] [HKCU\Software\VHLD] [HKCU\Software\Wget] [HKCU\Software\WinRAR SFX] [HKCU\Software\WinRAR] [HKCU\Software\Xilisoft] [HKCU\Software\YahooPartnerToolbar] [HKCU\Software\ZjSoft] [HKCU\Software\ej-technologies] [HKCU\Software\encryptX] [HKCU\Software\shockwave.com] [HKLM\Software\ACE Compression Software] [HKLM\Software\AGEIA Technologies] [HKLM\Software\ALA] [HKLM\Software\AVG] [HKLM\Software\Adobe] [HKLM\Software\Alcohol Soft] [HKLM\Software\Alps] [HKLM\Software\AppDataLow] [HKLM\Software\Apple Computer, Inc.] [HKLM\Software\Apple Inc.] [HKLM\Software\Azureus] [HKLM\Software\BitTorrent] [HKLM\Software\Bitmanagement Software] [HKLM\Software\Bodog Poker] [HKLM\Software\C07ft5Y] [HKLM\Software\CDDB] [HKLM\Software\CXT] [HKLM\Software\Classes] [HKLM\Software\Clients] [HKLM\Software\Conexant Systems Inc ] [HKLM\Software\DivXNetworks] [HKLM\Software\EPSON] [HKLM\Software\EnigmaSoftwareGroup] [HKLM\Software\Full Tilt Poker] [HKLM\Software\GEAR Software] [HKLM\Software\Global IP Solutions] [HKLM\Software\Google] [HKLM\Software\Iconico] [HKLM\Software\InstallShield] [HKLM\Software\Intel] [HKLM\Software\InterVideo] [HKLM\Software\JavaSoft] [HKLM\Software\JreMetrics] [HKLM\Software\Lake] [HKLM\Software\Lavasoft] [HKLM\Software\Licenses] [HKLM\Software\Macromedia] [HKLM\Software\Macrovision] [HKLM\Software\Malwarebytes' Anti-Malware (Trial)] [HKLM\Software\Malwarebytes' Anti-Malware] [HKLM\Software\Mediafour] [HKLM\Software\MimarSinan] [HKLM\Software\MozillaPlugins] [HKLM\Software\Mozilla] [HKLM\Software\NVIDIA Corporation] [HKLM\Software\Nadeo] [HKLM\Software\Nullsoft] [HKLM\Software\ODBC] [HKLM\Software\PDFCreator] [HKLM\Software\PTECH] [HKLM\Software\Piriform] [HKLM\Software\Policies] [HKLM\Software\RegisteredApplications] [HKLM\Software\Safer Networking Limited] [HKLM\Software\Services] [HKLM\Software\SigmaTel] [HKLM\Software\Skype] [HKLM\Software\Sonic] [HKLM\Software\Sony Corporation] [HKLM\Software\Sony] [HKLM\Software\Swearware] [HKLM\Software\Symantec] [HKLM\Software\Toshiba] [HKLM\Software\Trad-FR] [HKLM\Software\VideoLAN] [HKLM\Software\Volatile] [HKLM\Software\WholeSecurity] [HKLM\Software\ej-technologies] [HKLM\Software\mozilla.org] ~ Scan Softwares in 00mn 00s ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43) O43 - CFD: 30/08/2011 - 22:53:48 - [101607514] ----D- C:\Program Files\Ad-Remover O43 - CFD: 03/03/2008 - 20:36:20 - [2010920809] ----D- C:\Program Files\Adobe O43 - CFD: 05/08/2007 - 16:53:14 - [3177] ----D- C:\Program Files\ALA O43 - CFD: 25/05/2007 - 14:55:38 - [13] ----D- C:\Program Files\Alice O43 - CFD: 10/10/2010 - 00:44:42 - [2738105] ----D- C:\Program Files\Apoint O43 - CFD: 01/09/2011 - 01:20:22 - [2428606] ----D- C:\Program Files\Apple Software Update O43 - CFD: 10/03/2009 - 00:33:52 - [0] ----D- C:\Program Files\AVG O43 - CFD: 22/12/2007 - 00:11:18 - [2655233] ----D- C:\Program Files\AviSynth 2.5 O43 - CFD: 05/08/2008 - 22:31:20 - [32847214] ----D- C:\Program Files\Azureus O43 - CFD: 23/04/2008 - 21:02:36 - [8409490] R---D- C:\Program Files\Bitmanagement Software O43 - CFD: 20/01/2009 - 01:10:18 - [1041232] ----D- C:\Program Files\BitTorrent O43 - CFD: 05/09/2011 - 22:27:08 - [223449] ----D- C:\Program Files\Bonjour O43 - CFD: 22/08/2011 - 21:56:56 - [4068448] ----D- C:\Program Files\CCleaner O43 - CFD: 02/04/2011 - 13:45:38 - [432522] ----D- C:\Program Files\ColorPic 4.1 O43 - CFD: 05/09/2011 - 22:21:26 - [794519606] ----D- C:\Program Files\Common Files O43 - CFD: 04/12/2006 - 12:01:12 - [1033640] ----D- C:\Program Files\CONEXANT O43 - CFD: 03/08/2007 - 21:43:34 - [1634536] ----D- C:\Program Files\DAEMON Tools O43 - CFD: 27/10/2007 - 00:24:04 - [6144939] ----D- C:\Program Files\DivX O43 - CFD: 28/08/2011 - 21:18:24 - [408704] ----D- C:\Program Files\DNA O43 - CFD: 28/08/2011 - 15:38:10 - [9120287551] ----D- C:\Program Files\eMule O43 - CFD: 14/08/2011 - 00:09:04 - [16894659] ----D- C:\Program Files\Enigma Software Group O43 - CFD: 26/02/2007 - 22:53:02 - [1368984] ----D- C:\Program Files\FastStone Capture O43 - CFD: 04/12/2006 - 12:06:04 - [0] -SH-D- C:\Program Files\Fichiers communs O43 - CFD: 25/01/2009 - 01:45:50 - [145] ----D- C:\Program Files\Full Tilt Poker O43 - CFD: 30/03/2008 - 18:54:16 - [107476875] ----D- C:\Program Files\GDHO O43 - CFD: 20/08/2011 - 15:54:48 - [158019604] ----D- C:\Program Files\Google O43 - CFD: 05/12/2006 - 10:44:42 - [98346] ----D- C:\Program Files\Google BAE O43 - CFD: 30/12/2009 - 20:58:56 - [1273978] ----D- C:\Program Files\HotKey_2.4.00.07090 O43 - CFD: 29/08/2009 - 03:15:54 - [9893135] ----D- C:\Program Files\Illustrate O43 - CFD: 30/12/2009 - 21:39:46 - [84458491] --H-D- C:\Program Files\InstallShield Installation Information O43 - CFD: 04/12/2006 - 12:20:44 - [41895] ----D- C:\Program Files\Intel O43 - CFD: 04/04/2010 - 20:16:22 - [2776365] ----D- C:\Program Files\Internet Explorer O43 - CFD: 21/12/2006 - 16:04:40 - [144706607] ----D- C:\Program Files\InterVideo O43 - CFD: 01/09/2011 - 01:39:40 - [1047787] ----D- C:\Program Files\iPod O43 - CFD: 01/09/2011 - 01:41:34 - [124246827] ----D- C:\Program Files\iTunes O43 - CFD: 29/05/2010 - 12:22:22 - [170275531] ----D- C:\Program Files\Java O43 - CFD: 05/09/2011 - 22:06:38 - [449584] ----D- C:\Program Files\Malwarebytes' Anti-Malware O43 - CFD: 25/01/2009 - 02:27:28 - [10563334] ----D- C:\Program Files\Mediafour O43 - CFD: 09/03/2008 - 12:40:26 - [800662] ----D- C:\Program Files\Microsoft CAPICOM 2.1.0.2 O43 - CFD: 14/04/2007 - 14:20:58 - [92804023] ----D- C:\Program Files\Microsoft Games O43 - CFD: 14/08/2011 - 00:04:28 - [314904501] ----D- C:\Program Files\Microsoft Office O43 - CFD: 15/10/2009 - 03:04:08 - [252565008] ----D- C:\Program Files\Microsoft SQL Server O43 - CFD: 24/07/2011 - 23:15:30 - [6583142] ----D- C:\Program Files\Microsoft Windows 7 Upgrade Advisor O43 - CFD: 07/01/2008 - 14:27:46 - [324960225] ----D- C:\Program Files\Microsoft Works O43 - CFD: 05/02/2007 - 16:56:00 - [1856386] ----D- C:\Program Files\Microsoft.NET O43 - CFD: 13/03/2010 - 04:22:04 - [99153006] ----D- C:\Program Files\Movie Maker O43 - CFD: 05/09/2011 - 18:39:54 - [37617962] ----D- C:\Program Files\Mozilla Firefox O43 - CFD: 02/11/2006 - 14:37:36 - [25757] ----D- C:\Program Files\MSBuild O43 - CFD: 02/01/2010 - 13:40:08 - [29794014] ----D- C:\Program Files\MSECache O43 - CFD: 02/11/2006 - 14:37:36 - [3272760] ----D- C:\Program Files\MSN O43 - CFD: 02/02/2007 - 21:12:02 - [0] ----D- C:\Program Files\MSXML 4.0 O43 - CFD: 21/07/2007 - 19:05:56 - [43189] ----D- C:\Program Files\nutri O43 - CFD: 03/04/2011 - 17:38:56 - [2028] ----D- C:\Program Files\office Convert Pdf to Jpg Jpeg Tiff Free O43 - CFD: 19/02/2011 - 18:58:02 - [103880292] ----D- C:\Program Files\PC Tools Security O43 - CFD: 29/08/2009 - 00:23:36 - [21625423] ----D- C:\Program Files\PDFCreator O43 - CFD: 16/07/2010 - 02:54:34 - [16419068] ----D- C:\Program Files\Photo Story 3 for Windows O43 - CFD: 03/04/2011 - 03:27:18 - [3699431] ----D- C:\Program Files\PhotoFiltre O43 - CFD: 05/11/2010 - 22:21:58 - [73920286] ----D- C:\Program Files\PokerStars O43 - CFD: 01/09/2011 - 01:24:52 - [75697179] ----D- C:\Program Files\QuickTime O43 - CFD: 22/12/2007 - 00:36:54 - [14669943] ----D- C:\Program Files\Red Kawa O43 - CFD: 02/11/2006 - 14:37:36 - [38637313] ----D- C:\Program Files\Reference Assemblies O43 - CFD: 05/12/2006 - 10:59:10 - [295644083] ----D- C:\Program Files\Roxio O43 - CFD: 17/05/2009 - 18:03:48 - [3125920] ----D- C:\Program Files\SDHelper (Spybot - Search & Destroy) O43 - CFD: 04/12/2006 - 12:25:04 - [7656563] ----D- C:\Program Files\SigmaTel O43 - CFD: 31/07/2011 - 18:29:02 - [17357532] R---D- C:\Program Files\Skype O43 - CFD: 30/12/2009 - 21:00:24 - [502724736] ----D- C:\Program Files\Sony O43 - CFD: 08/06/2011 - 22:32:06 - [3218853] ----D- C:\Program Files\Soulseek O43 - CFD: 27/08/2011 - 21:46:18 - [4273752] ----D- C:\Program Files\SpaceMonger O43 - CFD: 14/08/2011 - 10:35:00 - [64231932] ----D- C:\Program Files\Spybot - Search & Destroy O43 - CFD: 13/10/2007 - 13:03:10 - [767494] ----D- C:\Program Files\SystemRequirementsLab O43 - CFD: 17/05/2009 - 18:03:48 - [4520960] ----D- C:\Program Files\TeaTimer (Spybot - Search & Destroy) O43 - CFD: 25/09/2007 - 00:45:54 - [0] ----D- C:\Program Files\THQ O43 - CFD: 12/06/2007 - 00:20:10 - [2045407] ----D- C:\Program Files\TimeAdjuster O43 - CFD: 21/12/2006 - 16:05:32 - [47144382] ----D- C:\Program Files\Toshiba O43 - CFD: 11/01/2008 - 22:25:42 - [0] ----D- C:\Program Files\Ubisoft O43 - CFD: 02/11/2006 - 15:01:56 - [0] --H-D- C:\Program Files\Uninstall Information O43 - CFD: 06/02/2007 - 11:18:36 - [74973069] ----D- C:\Program Files\VideoLAN O43 - CFD: 26/10/2007 - 13:48:50 - [0] ----D- C:\Program Files\Webteh O43 - CFD: 30/08/2007 - 03:10:50 - [1016832] ----D- C:\Program Files\Windows Calendar O43 - CFD: 02/11/2006 - 14:42:34 - [2761216] ----D- C:\Program Files\Windows Collaboration O43 - CFD: 13/04/2007 - 03:02:38 - [4486592] ----D- C:\Program Files\Windows Defender O43 - CFD: 02/11/2006 - 14:42:34 - [7078008] ----D- C:\Program Files\Windows Journal O43 - CFD: 12/04/2008 - 17:50:02 - [32695964] ----D- C:\Program Files\Windows Live O43 - CFD: 17/04/2010 - 04:22:00 - [9071240] ----D- C:\Program Files\Windows Mail O43 - CFD: 30/10/2009 - 23:00:50 - [4496487] ----D- C:\Program Files\Windows Media Player O43 - CFD: 04/12/2006 - 12:06:04 - [7940176] ----D- C:\Program Files\Windows NT O43 - CFD: 02/11/2006 - 14:42:34 - [13463714] ----D- C:\Program Files\Windows Photo Gallery O43 - CFD: 10/01/2008 - 04:03:10 - [6503190] ----D- C:\Program Files\Windows Sidebar O43 - CFD: 05/02/2008 - 00:19:18 - [6036676] ----D- C:\Program Files\WindSolutions O43 - CFD: 04/02/2007 - 13:15:00 - [3718034] ----D- C:\Program Files\WinRAR O43 - CFD: 08/09/2011 - 23:22:46 - [4016808] ----D- C:\Program Files\ZHPDiag O43 - CFD: 03/03/2008 - 20:36:20 - [87326373] ----D- C:\Program Files\Common Files\Adobe O43 - CFD: 01/09/2011 - 01:39:32 - [93153076] ----D- C:\Program Files\Common Files\Apple O43 - CFD: 05/02/2007 - 16:59:16 - [86016] ----D- C:\Program Files\Common Files\DESIGNER O43 - CFD: 21/12/2006 - 16:10:48 - [16253778] ----D- C:\Program Files\Common Files\InstallShield O43 - CFD: 29/05/2010 - 12:47:10 - [32860126] ----D- C:\Program Files\Common Files\Java O43 - CFD: 25/01/2009 - 02:27:28 - [5627234] ----D- C:\Program Files\Common Files\Mediafour O43 - CFD: 15/07/2010 - 22:37:40 - [338718107] ----D- C:\Program Files\Common Files\microsoft shared O43 - CFD: 02/11/2006 - 13:18:34 - [2702] ----D- C:\Program Files\Common Files\Services O43 - CFD: 21/12/2006 - 16:21:58 - [70991261] ----D- C:\Program Files\Common Files\Sony Shared O43 - CFD: 02/11/2006 - 13:18:34 - [41100711] ----D- C:\Program Files\Common Files\SpeechEngines O43 - CFD: 16/08/2009 - 21:35:52 - [5381514] ----D- C:\Program Files\Common Files\Symantec Shared O43 - CFD: 14/06/2007 - 09:14:16 - [22732900] ----D- C:\Program Files\Common Files\System O43 - CFD: 19/12/2009 - 19:41:26 - [0] ----D- C:\Program Files\Common Files\Windows Live O43 - CFD: 07/03/2008 - 11:06:12 - [55124592] -SH-D- C:\Program Files\Common Files\WindowsLiveInstaller O43 - CFD: 14/08/2011 - 00:08:38 - [25161216] ----D- C:\Program Files\Common Files\Wise Installation Wizard O43 - CFD: 03/03/2008 - 20:36:44 - [376291648] ----D- C:\ProgramData\Adobe O43 - CFD: 11/08/2011 - 04:01:12 - [208] ----D- C:\ProgramData\aN01603MdKiF01603 O43 - CFD: 06/02/2010 - 16:34:44 - [145475780] ----D- C:\ProgramData\Apple O43 - CFD: 01/09/2011 - 01:23:58 - [66283534] ----D- C:\ProgramData\Apple Computer O43 - CFD: 02/11/2006 - 15:02:04 - [0] -SH-D- C:\ProgramData\Application Data O43 - CFD: 04/08/2008 - 01:26:26 - [20] ----D- C:\ProgramData\Azureus O43 - CFD: 04/12/2006 - 12:06:04 - [0] -SH-D- C:\ProgramData\Bureau O43 - CFD: 05/02/2008 - 00:19:34 - [3489219] ----D- C:\ProgramData\CopyTransControlCenter O43 - CFD: 02/11/2006 - 15:02:04 - [0] -SH-D- C:\ProgramData\Desktop O43 - CFD: 02/11/2006 - 15:02:04 - [0] -SH-D- C:\ProgramData\Documents O43 - CFD: 28/08/2011 - 15:38:10 - [0] ----D- C:\ProgramData\eMule O43 - CFD: 28/08/2011 - 19:03:42 - [566344] ----D- C:\ProgramData\EPSON O43 - CFD: 04/12/2006 - 12:06:04 - [0] -SH-D- C:\ProgramData\Favoris O43 - CFD: 02/11/2006 - 15:02:04 - [0] -SH-D- C:\ProgramData\Favorites O43 - CFD: 12/12/2007 - 00:56:56 - [19772] ----D- C:\ProgramData\FLEXnet O43 - CFD: 22/06/2007 - 21:16:00 - [4096] ----D- C:\ProgramData\Grisoft O43 - CFD: 28/08/2011 - 22:34:20 - [359] ----D- C:\ProgramData\Lavasoft O43 - CFD: 01/08/2011 - 00:53:42 - [9468189] ----D- C:\ProgramData\Malwarebytes O43 - CFD: 25/01/2009 - 02:27:26 - [10593042] ----D- C:\ProgramData\Mediafour O43 - CFD: 04/12/2006 - 12:06:04 - [0] -SH-D- C:\ProgramData\Menu Démarrer O43 - CFD: 19/12/2009 - 19:41:22 - [304901871] -S--D- C:\ProgramData\Microsoft O43 - CFD: 04/12/2006 - 12:06:04 - [0] -SH-D- C:\ProgramData\Modèles O43 - CFD: 17/04/2010 - 12:59:06 - [155] ----D- C:\ProgramData\Norton O43 - CFD: 17/04/2010 - 12:10:38 - [181474] ----D- C:\ProgramData\NortonInstaller O43 - CFD: 18/12/2006 - 15:14:00 - [8480] ----D- C:\ProgramData\NVIDIA O43 - CFD: 22/08/2011 - 21:53:50 - [208] ----D- C:\ProgramData\oG01300OoIlL01300 O43 - CFD: 31/07/2011 - 18:29:00 - [18861207] ----D- C:\ProgramData\Skype O43 - CFD: 04/12/2006 - 12:09:44 - [18009573] ----D- C:\ProgramData\Sony O43 - CFD: 02/02/2007 - 22:31:18 - [616133926] ----D- C:\ProgramData\Sony Corporation O43 - CFD: 05/09/2011 - 17:35:38 - [208239] ----D- C:\ProgramData\Spybot - Search & Destroy O43 - CFD: 02/11/2006 - 15:02:04 - [0] -SH-D- C:\ProgramData\Start Menu O43 - CFD: 29/05/2010 - 12:47:10 - [119] ----D- C:\ProgramData\Sun O43 - CFD: 17/04/2010 - 12:10:40 - [25524389] ----D- C:\ProgramData\Symantec O43 - CFD: 19/02/2011 - 01:44:38 - [0] ---AD- C:\ProgramData\TEMP O43 - CFD: 02/11/2006 - 15:02:06 - [0] -SH-D- C:\ProgramData\Templates O43 - CFD: 21/12/2006 - 16:17:42 - [0] ----D- C:\ProgramData\VAIO Media Platform O43 - CFD: 12/04/2008 - 17:47:24 - [395900] ----D- C:\ProgramData\WLInstaller O43 - CFD: 01/03/2011 - 23:31:24 - [542643] ----D- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521} O43 - CFD: 06/02/2010 - 16:18:04 - [3350] ----D- C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD} O43 - CFD: 29/08/2009 - 03:16:06 - [0] ----D- C:\Users\Matt\AppData\Roaming\AccurateRip O43 - CFD: 25/09/2007 - 00:52:24 - [66776] ----D- C:\Users\Matt\AppData\Roaming\Ace O43 - CFD: 05/09/2011 - 22:26:02 - [12671993] ----D- C:\Users\Matt\AppData\Roaming\Adobe O43 - CFD: 19/08/2011 - 02:27:18 - [899] ----D- C:\Users\Matt\AppData\Roaming\Afycb O43 - CFD: 06/02/2010 - 16:33:54 - [1021678534] ----D- C:\Users\Matt\AppData\Roaming\Apple Computer O43 - CFD: 03/10/2009 - 15:41:36 - [1582863] ----D- C:\Users\Matt\AppData\Roaming\Azureus O43 - CFD: 06/08/2011 - 23:25:36 - [6241142] ----D- C:\Users\Matt\AppData\Roaming\BitTorrent O43 - CFD: 26/10/2007 - 13:48:50 - [512000] ----D- C:\Users\Matt\AppData\Roaming\BSplayer O43 - CFD: 26/10/2007 - 13:43:56 - [6292] ----D- C:\Users\Matt\AppData\Roaming\BSplayer Pro O43 - CFD: 09/08/2011 - 00:34:24 - [0] ----D- C:\Users\Matt\AppData\Roaming\c42f7236 O43 - CFD: 05/02/2008 - 00:51:22 - [26878] ----D- C:\Users\Matt\AppData\Roaming\CopyTrans O43 - CFD: 05/02/2008 - 00:19:28 - [30740] ----D- C:\Users\Matt\AppData\Roaming\CopyTransControlCenter O43 - CFD: 16/08/2009 - 21:23:16 - [17652] ----D- C:\Users\Matt\AppData\Roaming\CopyTransDoctor O43 - CFD: 16/08/2009 - 19:03:18 - [0] ----D- C:\Users\Matt\AppData\Roaming\DAEMON Tools Lite O43 - CFD: 08/09/2011 - 23:19:14 - [17827] ----D- C:\Users\Matt\AppData\Roaming\DNA O43 - CFD: 16/07/2011 - 21:08:32 - [951] ----D- C:\Users\Matt\AppData\Roaming\dvdcss O43 - CFD: 26/06/2010 - 02:14:14 - [5719763] ----D- C:\Users\Matt\AppData\Roaming\Facebook O43 - CFD: 26/02/2007 - 22:53:06 - [3377] ----D- C:\Users\Matt\AppData\Roaming\FastStone O43 - CFD: 02/12/2007 - 16:48:32 - [0] ----D- C:\Users\Matt\AppData\Roaming\GibbHill Properties Ltd O43 - CFD: 12/02/2007 - 21:49:48 - [34314] ----D- C:\Users\Matt\AppData\Roaming\Google O43 - CFD: 19/08/2011 - 01:47:14 - [0] ----D- C:\Users\Matt\AppData\Roaming\Icytvo O43 - CFD: 04/12/2006 - 12:08:46 - [0] ----D- C:\Users\Matt\AppData\Roaming\Identities O43 - CFD: 02/02/2007 - 23:02:28 - [0] ----D- C:\Users\Matt\AppData\Roaming\InterVideo O43 - CFD: 02/09/2008 - 00:07:10 - [0] ----D- C:\Users\Matt\AppData\Roaming\Lavasoft O43 - CFD: 02/02/2007 - 21:02:00 - [4150742] ----D- C:\Users\Matt\AppData\Roaming\Macromedia O43 - CFD: 01/08/2011 - 00:53:50 - [8615786] ----D- C:\Users\Matt\AppData\Roaming\Malwarebytes O43 - CFD: 02/11/2006 - 14:37:36 - [0] ----D- C:\Users\Matt\AppData\Roaming\Media Center Programs O43 - CFD: 15/08/2011 - 18:37:42 - [7386648] -S--D- C:\Users\Matt\AppData\Roaming\Microsoft O43 - CFD: 22/08/2011 - 21:10:26 - [30661135] ----D- C:\Users\Matt\AppData\Roaming\Mozilla O43 - CFD: 18/12/2007 - 01:04:52 - [0] ----D- C:\Users\Matt\AppData\Roaming\Opera O43 - CFD: 11/04/2011 - 22:16:04 - [269] ----D- C:\Users\Matt\AppData\Roaming\PhotoFiltre O43 - CFD: 20/08/2011 - 11:30:20 - [41160891] ----D- C:\Users\Matt\AppData\Roaming\SanDisk O43 - CFD: 22/02/2007 - 23:12:26 - [8096] R-H-D- C:\Users\Matt\AppData\Roaming\SecuROM O43 - CFD: 12/06/2011 - 18:11:42 - [0] ----D- C:\Users\Matt\AppData\Roaming\SharePod O43 - CFD: 06/08/2011 - 23:25:36 - [2404652] ----D- C:\Users\Matt\AppData\Roaming\Skype O43 - CFD: 02/06/2007 - 13:34:08 - [2294499] ----D- C:\Users\Matt\AppData\Roaming\Sony Corporation O43 - CFD: 27/08/2011 - 21:46:18 - [39713] ----D- C:\Users\Matt\AppData\Roaming\SpaceMonger O43 - CFD: 07/01/2008 - 14:23:22 - [0] ----D- C:\Users\Matt\AppData\Roaming\Template O43 - CFD: 24/06/2007 - 17:37:06 - [0] ----D- C:\Users\Matt\AppData\Roaming\Toshiba O43 - CFD: 09/02/2007 - 19:26:46 - [4] ----D- C:\Users\Matt\AppData\Roaming\Uniblue O43 - CFD: 05/09/2011 - 00:05:54 - [645631] ----D- C:\Users\Matt\AppData\Roaming\vlc O43 - CFD: 23/08/2009 - 16:25:48 - [1458171] ----D- C:\Users\Matt\AppData\Local\Adobe O43 - CFD: 21/12/2007 - 02:40:08 - [69980968] ----D- C:\Users\Matt\AppData\Local\Apple O43 - CFD: 19/12/2010 - 03:11:38 - [54068088] ----D- C:\Users\Matt\AppData\Local\Apple Computer O43 - CFD: 02/02/2007 - 20:33:26 - [0] -SH-D- C:\Users\Matt\AppData\Local\Application Data O43 - CFD: 17/10/2007 - 00:15:08 - [0] ----D- C:\Users\Matt\AppData\Local\Apps O43 - CFD: 21/01/2008 - 23:40:50 - [0] ----D- C:\Users\Matt\AppData\Local\Asobo Studio O43 - CFD: 23/04/2008 - 21:03:04 - [10506238] ----D- C:\Users\Matt\AppData\Local\Bitmanagement Software O43 - CFD: 20/01/2009 - 01:10:04 - [0] ----D- C:\Users\Matt\AppData\Local\DNA O43 - CFD: 24/08/2009 - 20:54:16 - [596883796] ----D- C:\Users\Matt\AppData\Local\Google O43 - CFD: 02/02/2007 - 20:33:26 - [0] -SH-D- C:\Users\Matt\AppData\Local\Historique O43 - CFD: 28/12/2007 - 19:40:38 - [160149571] ----D- C:\Users\Matt\AppData\Local\Microsoft O43 - CFD: 24/07/2011 - 23:17:58 - [13238] ----D- C:\Users\Matt\AppData\Local\Microsoft Corporation O43 - CFD: 03/03/2007 - 20:34:16 - [1456623] ----D- C:\Users\Matt\AppData\Local\Microsoft Games O43 - CFD: 08/12/2007 - 19:48:10 - [65293955] ----D- C:\Users\Matt\AppData\Local\Mozilla O43 - CFD: 06/11/2010 - 11:13:40 - [2149448] ----D- C:\Users\Matt\AppData\Local\PokerStars O43 - CFD: 09/10/2010 - 17:51:22 - [0] ----D- C:\Users\Matt\AppData\Local\Sunbelt Software O43 - CFD: 08/09/2011 - 23:20:20 - [33384] ----D- C:\Users\Matt\AppData\Local\temp O43 - CFD: 02/02/2007 - 20:33:26 - [0] -SH-D- C:\Users\Matt\AppData\Local\Temporary Internet Files O43 - CFD: 21/12/2006 - 16:32:44 - [34693] ----D- C:\Users\Matt\AppData\Local\Toshiba O43 - CFD: 02/02/2007 - 21:53:26 - [6713606] ----D- C:\Users\Matt\AppData\Local\VirtualStore ~ Scan Program Folder in 00mn 13s ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44) O44 - LFC:[MD5.D4F8042CD2B651D15B63D74F840D378E] - 08/09/2011 - 21:21:08 ---A- . (...) -- C:\Windows\WindowsUpdate.log [24815] O44 - LFC:[MD5.271117592DD1E98CC58E490125CA8AF9] - 08/09/2011 - 21:18:42 -S-A- . (...) -- C:\Windows\bootstat.dat [67584] O44 - LFC:[MD5.3A65872381030E52A1D4A7388F5D5ADC] - 05/09/2011 - 21:46:55 ---A- . (...) -- C:\ComboFix.txt [16111] O44 - LFC:[MD5.3CF3D4A45CC2AF973DBC30EC8D33252B] - 05/09/2011 - 21:33:06 ---A- . (...) -- C:\Windows\system.ini [215] O44 - LFC:[MD5.96C0CA43392D7147D1BC1D8C6CA45D68] - 05/09/2011 - 21:31:37 ---A- . (...) -- C:\Windows\PFRO.log [3670] O44 - LFC:[MD5.753BC16326FEE4A421ACB636CCD602F4] - 05/09/2011 - 17:43:52 ---A- . (.NirSoft - NirCmd.) -- C:\Windows\NIRCMD.exe [60416] O44 - LFC:[MD5.A46842C9B0C567A5A9584E83A163560C] - 05/09/2011 - 17:43:52 ---A- . (.SteelWerX - Freeware implementation of REG.EXE.) -- C:\Windows\SWREG.exe [518144] O44 - LFC:[MD5.0297C72529807322B152F517FDB0A9FC] - 05/09/2011 - 17:43:52 ---A- . (.SteelWerX - Freeware implementation of SC.EXE.) -- C:\Windows\SWSC.exe [406528] O44 - LFC:[MD5.B1A9CF0B6F80611D31987C247EC630B4] - 05/09/2011 - 17:43:52 ---A- . (.SteelWerX - Freeware implementation of XCACLS.) -- C:\Windows\SWXCACLS.exe [212480] O44 - LFC:[MD5.8182FF89C65E4D38B2DE4BB0FB18564E] - 01/09/2011 - 00:41:36 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\system32\drivers\GEARAspiWDM.sys [26600] O44 - LFC:[MD5.005EE82BABF1D2D32188A75BEDF500A4] - 01/09/2011 - 00:41:36 ---A- . (.GEAR Software Inc. - GEARAspi (x86).) -- C:\Windows\system32\GEARAspi.dll [107368] O44 - LFC:[MD5.9860E0446EB0490A4C44F647F1B33EC3] - 28/08/2011 - 21:28:10 ---A- . (...) -- C:\aaw7boot.log [25183] O44 - LFC:[MD5.84E2BAF41430A967C0F8EC7E0CD27D94] - 28/08/2011 - 20:20:07 ---A- . (...) -- C:\Ad-Report-SCAN[2].txt [4072] O44 - LFC:[MD5.B279EEB09E6F7CA578DCBE04093A96C7] - 28/08/2011 - 10:31:45 ---A- . (...) -- C:\Ad-Report-CLEAN[1].txt [5104] O44 - LFC:[MD5.307B42DC13AEE90B240B3CBB4D33F9D5] - 28/08/2011 - 09:40:29 ---A- . (...) -- C:\Ad-Report-SCAN[1].txt [4837] O44 - LFC:[MD5.E9344F2ACC7D69841432AC95E2D98FD1] - 27/08/2011 - 20:46:21 ---A- . (...) -- C:\Windows\system32\wnsm2i.rdb [4] O44 - LFC:[MD5.F51C8102BF019AD2C59B9AD397617794] - 27/08/2011 - 20:43:41 ---A- . (...) -- C:\Windows\system32\PerfStringBackup.INI [1697198] O44 - LFC:[MD5.576526BFE96B5C4CED719438B94A6119] - 27/08/2011 - 20:43:41 ---A- . (...) -- C:\Windows\system32\perfc009.dat [127716] O44 - LFC:[MD5.2FC98A840A429B6266F5D9A38A85E766] - 27/08/2011 - 20:43:41 ---A- . (...) -- C:\Windows\system32\perfc00C.dat [147298] O44 - LFC:[MD5.E4F24B46A4738C64980A614339A4D2CE] - 27/08/2011 - 20:43:41 ---A- . (...) -- C:\Windows\system32\perfh009.dat [665312] O44 - LFC:[MD5.6DCEED90430B49825ECE04FE054E83C5] - 27/08/2011 - 20:43:41 ---A- . (...) -- C:\Windows\system32\perfh00C.dat [764018] O44 - LFC:[MD5.CB17A47D090938A02DACB066D6D5A124] - 27/08/2011 - 18:19:23 ---A- . (...) -- C:\Windows\system32\rp_rules.dat [44] O44 - LFC:[MD5.8A3D5B46FF8C9CED46304F1EBB5F9AFE] - 27/08/2011 - 18:19:23 ---A- . (...) -- C:\Windows\system32\rp_stats.dat [64] O44 - LFC:[MD5.73CF233421AFCFF617879C27B8790AD0] - 19/08/2011 - 00:34:46 ---A- . (...) -- C:\scandisk.lnk [479] O44 - LFC:[MD5.E42BC24ED4DBD4C23A59231A3CAA57C9] - 11/08/2011 - 02:06:33 ---A- . (...) -- C:\Windows\system32\MRT.INI [127] O44 - LFC:[MD5.77CFB196DBEE4AB8E5A175326E907CFB] - 11/08/2011 - 02:02:09 ---A- . (...) -- C:\Windows\win.ini [388] O44 - LFC:[MD5.F042EE4C8D66248D9B86DCF52ABAE416] - 26/06/2011 - 07:45:56 ---A- . (...) -- C:\Windows\PEV.exe [256000] O44 - LFC:[MD5.0277C027A26428DB64EF4F64F52BB4FD] - 07/11/2010 - 18:20:24 ---A- . (...) -- C:\Windows\MBR.exe [208896] O44 - LFC:[MD5.9E05A9C264C8A908A8E79450FCBFF047] - 31/08/2000 - 01:00:00 ---A- . (...) -- C:\Windows\grep.exe [80412] O44 - LFC:[MD5.2B657A67AEBB84AEA5632C53E61E23BF] - 31/08/2000 - 01:00:00 ---A- . (...) -- C:\Windows\sed.exe [98816] O44 - LFC:[MD5.5E832F4FAF5F481F2EAF3B3A48F603B8] - 31/08/2000 - 01:00:00 ---A- . (...) -- C:\Windows\zip.exe [68096] ~ Scan Files in 00mn 01s ---\\ Export de clé d'application autorisée (O47) O47 - AAKE:Key Export SP - "C:\Program Files\BitTorrent\bittorrent.exe" [Enabled] .(.BitTorrent, Inc. - BitTorrent.) -- C:\Program Files\BitTorrent\bittorrent.exe ~ Scan Keys in 00mn 00s ---\\ Contrôle du Safe Boot (CSB) (O49) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\system32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\system32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\system32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\system32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Volume Manager Extension Driver.) -- C:\Windows\system32\Drivers\volmgrx.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\system32\Drivers\ipnat.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\system32\Drivers\nsiproxy.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Miniport.) -- C:\Windows\system32\Drivers\rdpencdd.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\system32\Drivers\sermouse.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\system32\Drivers\vga.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\system32\Drivers\vgasave.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\system32\Drivers\volmgr.sys O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Volume Manager Extension Driver.) -- C:\Windows\system32\Drivers\volmgrx.sys ~ Scan CSB in 00mn 00s ---\\ Trojan Driver Search Data (HKLM) (O52) O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\system32\iccvid.dll O52 - TDSD: \Drivers32\"VIDC.dvsd"="C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll" . (...) -- (.not file.) O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm ~ Scan Keys in 00mn 00s ---\\ ShareTools MSconfig StartupReg (O53) O53 - SMSR:HKLM\...\startupreg\Google Update [Key] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Matt\AppData\Local\Google\Update\GoogleUpdate.exe O53 - SMSR:HKLM\...\startupreg\iTunesHelper [Key] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe O53 - SMSR:HKLM\...\startupreg\QuickTime Task [Key] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe O53 - SMSR:HKLM\...\startupreg\SanDisk_Button_Manager.exe [Key] . (.Gemalto N.V. - SanDiskBackup.) -- C:\Users\Matt\AppData\Roaming\SanDisk\SanDisk_Button_Manager.exe ~ Scan SMSR Keys in 00mn 00s ---\\ Microsoft Control Security Providers (O54) O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TS Single Sign On Security Package.) -- C:\Windows\system32\credssp.dll O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TS Single Sign On Security Package.) -- C:\Windows\system32\credssp.dll ~ Scan Keys in 00mn 00s ---\\ Microsoft Windows Policies System (O55) O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=2 O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1 O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1 O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1 O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0 O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0 O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"= O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"= O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0 O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1 O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0 O55 - MWPS:[HKLM\...\Policies\System] - "DisableRegistryTools"=0 ~ Scan Keys in 00mn 00s ---\\ Microsoft Windows Policies Explorer (O56) O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145 O56 - MWPE:[HKCU\...\policies\Explorer] - "NoLogOff"=0 O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDrives"=0 O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDrives"=0 ~ Scan Keys in 00mn 00s ---\\ Liste des Drivers Système (O58) O58 - SDL:[MD5.2EDC5BBAC6C651ECE337BDE8ED97C9FB] - 02/01/2007 - 10:51:38 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\system32\drivers\adp94xx.sys [420968] O58 - SDL:[MD5.B84088CA3CDCA97DA44A984C6CE1CCAD] - 02/01/2007 - 10:51:32 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\system32\drivers\adpahci.sys [297576] O58 - SDL:[MD5.7880C67BCCC27C86FD05AA2AFB5EA469] - 02/01/2007 - 10:50:35 ---A- . (.Adaptec, Inc. - Adaptec LH Ultra160 Driver (x86).) -- C:\Windows\system32\drivers\adpu160m.sys [98408] O58 - SDL:[MD5.9AE713F8E30EFC2ABCCD84904333DF4D] - 02/01/2007 - 10:51:00 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\system32\drivers\adpu320.sys [147048] O58 - SDL:[MD5.90395B64600EBB4552E26E178C94B2E4] - 02/01/2007 - 10:49:20 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\system32\drivers\aliide.sys [14952] O58 - SDL:[MD5.7C2F57BCE81FA74933F0E1C84A97C9DB] - 02/01/2007 - 01:35:58 ---A- . (.Alps Electric Co., Ltd. - Alps Touch Pad Driver.) -- C:\Windows\system32\drivers\Apfiltr.sys [140800] O58 - SDL:[MD5.5F673180268BB1FDB69C99B6619FE379] - 02/01/2007 - 10:50:09 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\system32\drivers\arc.sys [67688] O58 - SDL:[MD5.957F7540B5E7F602E44648C7DE5A1C05] - 02/01/2007 - 10:50:10 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\system32\drivers\arcsas.sys [67688] O58 - SDL:[MD5.9F9ACC7F7CCDE8A15C282D3F88B43309] - 02/01/2007 - 09:24:45 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\system32\drivers\BrFiltLo.sys [13568] O58 - SDL:[MD5.56801AD62213A41F6497F96DEE83755A] - 02/01/2007 - 09:24:46 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\system32\drivers\BrFiltUp.sys [5248] O58 - SDL:[MD5.B304E75CFF293029EDDF094246747113] - 02/01/2007 - 09:25:24 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\system32\drivers\BrSerId.sys [71808] O58 - SDL:[MD5.203F0B1E73ADADBBB7B7B1FABD901F6B] - 02/01/2007 - 09:24:44 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\system32\drivers\BrSerWdm.sys [62336] O58 - SDL:[MD5.BD456606156BA17E60A04E18016AE54B] - 02/01/2007 - 09:24:44 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\system32\drivers\BrUsbMdm.sys [12160] O58 - SDL:[MD5.AF72ED54503F717A43268B3CC5FAEC2E] - 02/01/2007 - 09:24:47 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\system32\drivers\BrUsbSer.sys [11904] O58 - SDL:[MD5.68DFC4BCFA33C91CBCFC86C058267398] - 25/01/2009 - 20:20:16 ---A- . (.EldoS Corporation - Callback File System Driver.) -- C:\Windows\system32\drivers\cbfs.sys [136744] O58 - SDL:[MD5.45201046C776FFDAF3FC8A0029C581C8] - 02/01/2007 - 10:49:28 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\cmdide.sys [16488] O58 - SDL:[MD5.AE1FDF7BF7BB6C6A70F67699D880592A] - 02/01/2007 - 10:50:11 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\system32\drivers\djsvs.sys [71272] O58 - SDL:[MD5.F206E28ED74C491FD5D7C0A1119CE37F] - 02/01/2007 - 11:56:30 ---A- . (.Sony Corporation - Windows 2000 DMI Call Kernel Driver.) -- C:\Windows\system32\drivers\DMICall.sys [10216] O58 - SDL:[MD5.5C940A174DFB2C42B9F6BA6EDC2BAA0B] - 02/01/2007 - 06:15:24 ---A- . (.Intel Corporation - Intel® PRO/100 Adapter NDIS 5.1 driver.) -- C:\Windows\system32\drivers\e100b325.sys [165760] O58 - SDL:[MD5.7505290504C8E2D172FA378CC0497BCC] - 02/01/2007 - 08:30:55 ---A- . (.Intel Corporation - Pilote désérialisé NDIS 6 de la carte Intel® PRO/1000.) -- C:\Windows\system32\drivers\e1e6032.sys [200704] O58 - SDL:[MD5.F88FB26547FD2CE6D0A5AF2985892C48] - 02/01/2007 - 08:30:54 ---A- . (.Intel Corporation - Pilote désérialisé NDIS 6 de la carte Intel® PRO/1000.) -- C:\Windows\system32\drivers\E1G60I32.sys [117760] O58 - SDL:[MD5.E8F3F21A71720C84BCF423B80028359F] - 02/01/2007 - 10:51:34 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\system32\drivers\elxstor.sys [316520] O58 - SDL:[MD5.8182FF89C65E4D38B2DE4BB0FB18564E] - 01/09/2011 - 12:17:00 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\system32\drivers\GEARAspiWDM.sys [26600] O58 - SDL:[MD5.DF353B401001246853763C4B7AAA6F50] - 02/01/2007 - 10:50:10 ---A- . (.Hewlett-Packard Company - Smart Array Storport Driver.) -- C:\Windows\system32\drivers\HpCISSs.sys [37480] O58 - SDL:[MD5.31F949D452201F2F0AF0C88D7DB512CD] - 02/01/2007 - 03:08:14 ---A- . (.Conexant Systems, Inc. - HSF_HWAZL WDM driver.) -- C:\Windows\system32\drivers\HSXHWAZL.sys [206848] O58 - SDL:[MD5.6D2350BB6E77E800FC4BE4E5B7A2E89A] - 02/01/2007 - 03:08:04 ---A- . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- C:\Windows\system32\drivers\HSX_CNXT.sys [659968] O58 - SDL:[MD5.53229DCF431D76434816CD29251168A0] - 02/01/2007 - 03:09:26 ---A- . (.Conexant Systems, Inc. - HSF_DP driver.) -- C:\Windows\system32\drivers\HSX_DPV.sys [986624] O58 - SDL:[MD5.C957BF4B5D80B46C5017BF0101E6C906] - 02/01/2007 - 10:51:25 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver (base).) -- C:\Windows\system32\drivers\iaStorV.sys [232040] O58 - SDL:[MD5.2D077BF86E843F901D8DB709C95B49A5] - 02/01/2007 - 10:50:17 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\system32\drivers\iirsp.sys [41576] O58 - SDL:[MD5.BCED60D16156E428F8DF8CF27B0DF150] - 02/01/2007 - 10:50:07 ---A- . (.Integrated Technology Express, Inc. - ITE IT8211 ATA/ATAPI SCSI miniport.) -- C:\Windows\system32\drivers\iteatapi.sys [35944] O58 - SDL:[MD5.06FA654504A498C30ADCA8BEC4E87E7E] - 02/01/2007 - 10:50:09 ---A- . (.Integrated Technology Express, Inc. - ITE IT8212 ATA RAID SCSI miniport.) -- C:\Windows\system32\drivers\iteraid.sys [35944] O58 - SDL:[MD5.FE8300320281D658A7854D5CFC02A63F] - 11/02/2005 - 11:19:20 ---A- . (.MCCI - Sony Ericsson 750 Driver.) -- C:\Windows\system32\drivers\k750bus.sys [55216] O58 - SDL:[MD5.A03516D5C5FB064835DFF8FD1C251E5D] - 11/02/2005 - 11:19:14 ---A- . (.MCCI - Windows 2000/XP support functions.) -- C:\Windows\system32\drivers\k750wh.sys [5744] O58 - SDL:[MD5.A03516D5C5FB064835DFF8FD1C251E5D] - 11/02/2005 - 11:19:14 ---A- . (.MCCI - Windows 2000/XP support functions.) -- C:\Windows\system32\drivers\k750whnt.sys [5744] O58 - SDL:[MD5.A2262FB9F28935E862B4DB46438C80D2] - 02/01/2007 - 10:50:04 ---A- . (.LSI Logic - LSI Logic Fusion-MPT FC Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_fc.sys [65640] O58 - SDL:[MD5.30D73327D390F72A62F32C103DAF1D6D] - 02/01/2007 - 10:50:05 ---A- . (.LSI Logic - LSI Logic Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas.sys [65640] O58 - SDL:[MD5.E1E36FEFD45849A95F1AB81DE0159FE3] - 02/01/2007 - 10:50:10 ---A- . (.LSI Logic - LSI Logic Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_scsi.sys [65640] O58 - SDL:[MD5.A3442F017D533025F5EFB26DFB5A4CD0] - 25/01/2009 - 07:53:16 ---A- . (.Mediafour Corporation - MacDrive file system driver.) -- C:\Windows\system32\drivers\MDFSYSNT.SYS [293632] O58 - SDL:[MD5.0CEA2D0D3FA284B85ED5B68365114F76] - 02/01/2007 - 06:26:58 ---A- . (.Conexant - Diagnostic Interface x86 Driver.) -- C:\Windows\system32\drivers\mdmxsdk.sys [12672] O58 - SDL:[MD5.D153B14FC6598EAE8422A2037553ADCE] - 02/01/2007 - 10:49:53 ---A- . (.LSI Logic Corporation - MEGASAS RAID Controller Driver for Windows Vista/Longhorn for x.) -- C:\Windows\system32\drivers\megasas.sys [28776] O58 - SDL:[MD5.4FBBB70D30FD20EC51F80061703B001E] - 02/01/2007 - 10:49:59 ---A- . (.LSI Logic Corporation - MegaRAID RAID Controller Driver for Windows Vista/Longhorn for.) -- C:\Windows\system32\drivers\Mraid35x.sys [33384] O58 - SDL:[MD5.ACC6170D80C69E50145B370023B64ED3] - 02/01/2007 - 01:42:28 ---A- . (.Intel® Corporation - Intel® Wireless LAN Driver.) -- C:\Windows\system32\drivers\NETw3v32.sys [1786880] O58 - SDL:[MD5.2E7FB731D4790A1BC6270ACCEFACB36E] - 02/01/2007 - 10:50:19 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\system32\drivers\nfrd960.sys [45160] O58 - SDL:[MD5.E875C093AEC0C978A90F30C9E0DFBB72] - 02/01/2007 - 08:36:50 ---A- . (.N-trig Innovative Technologies - Pilote intégré de digitalisateur de tablette N-trig.) -- C:\Windows\system32\drivers\ntrigdigi.sys [20608] O58 - SDL:[MD5.B4B983D2B0BD436298EA2F8CE63E20CF] - 02/01/2007 - 08:58:00 ---A- . (.NVIDIA Corporation - NVIDIA Compatible Windows 2000 Miniport Driver, Version 97.32.) -- C:\Windows\system32\drivers\nvlddmkm.sys [4451392] O58 - SDL:[MD5.E69E946F80C1C31C53003BFBF50CBB7C] - 02/01/2007 - 10:50:24 ---A- . (.NVIDIA Corporation - NVIDIA® nForce RAID Driver.) -- C:\Windows\system32\drivers\nvraid.sys [88680] O58 - SDL:[MD5.9E0BA19A28C498A6D323D065DB76DFFC] - 02/01/2007 - 10:50:13 ---A- . (.NVIDIA Corporation - NVIDIA® nForce Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor.sys [40040] O58 - SDL:[MD5.49452BFCEC22F36A7A9B9C2181BC3042] - 25/01/2009 - 20:19:06 ---A- . (.Sonic Solutions - Px Engine Device Driver for Windows 2000/XP.) -- C:\Windows\system32\drivers\pxhelp20.sys [43872] O58 - SDL:[MD5.CCDAC889326317792480C0A67156A1EC] - 02/01/2007 - 10:51:45 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\system32\drivers\ql2300.sys [900712] O58 - SDL:[MD5.81A7E5C076E59995D54BC1ED3A16E60B] - 02/01/2007 - 10:50:35 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\system32\drivers\ql40xx.sys [106088] O58 - SDL:[MD5.F2B3E0E54817BECDEDBC095B25DAA248] - 02/01/2007 - 14:08:36 ---A- . (.Ricoh - Description string for UvcFilter driver.) -- C:\Windows\system32\drivers\R5U870FLx86.sys [72704] O58 - SDL:[MD5.5F598E844E7A465932507314444BD97A] - 02/01/2007 - 14:08:32 ---A- . (.Ricoh - Description string for UvcUpperFilter driver.) -- C:\Windows\system32\drivers\R5U870FUx86.sys [43904] O58 - SDL:[MD5.0505DA5D357F18A5D42FC5DEDE6BC9A0] - 30/07/2011 - 20:32:51 ---A- . (.Sunbelt Software - Anti-Rootkit Engine.) -- C:\Windows\system32\drivers\SBREDrv.sys [101720] O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 02/01/2007 - 07:37:21 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\system32\drivers\secdrv.sys [20480] O58 - SDL:[MD5.AAD95FE3E005489C7156FA111F744EAF] - 05/07/2006 - 13:39:29 ---A- . (.Protection Technology (StarForce) - FrontLine Environment Driver.) -- C:\Windows\system32\drivers\sfdrv01.sys [59256] O58 - SDL:[MD5.4D0CE0FADCA29E7DA68CE597AC9010BD] - 05/07/2006 - 13:46:06 ---A- . (.Protection Technology (StarForce) - FrontLine Environment Driver.) -- C:\Windows\system32\drivers\sfdrv01a.sys [63352] O58 - SDL:[MD5.DAAD4C099EBF5094D32C373AC1AC0F3C] - 14/06/2006 - 15:56:56 ---A- . (.Protection Technology (StarForce) - FrontLine Helper Driver.) -- C:\Windows\system32\drivers\sfhlp02.sys [13680] O58 - SDL:[MD5.107B772690050D3B19CBC637AD8FD96E] - 12/01/2007 - 19:09:53 ---A- . (.Protection Technology (StarForce) - FrontLine File System Driver.) -- C:\Windows\system32\drivers\sfvfs02.sys [82296] O58 - SDL:[MD5.4CDAF939DF995B0EEFD91E069BFDA30D] - 02/01/2007 - 05:30:34 ---A- . (.Silicon Image, Inc. - Serial ATA miniport driver.) -- C:\Windows\system32\drivers\SI3132.sys [74672] O58 - SDL:[MD5.85F5613EBFE1C51A72D03BDAA1F7B912] - 02/01/2007 - 05:31:14 ---A- . (.Silicon Image, Inc. - Filter driver for Silicon Image SATALink controllers..) -- C:\Windows\system32\drivers\SiRemFil.sys [12464] O58 - SDL:[MD5.CEDD6F4E7D84E9F98B34B3FE988373AA] - 02/01/2007 - 10:50:10 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\system32\drivers\sisraid2.sys [38504] O58 - SDL:[MD5.DF843C528C4F69D12CE41CE462E973A7] - 02/01/2007 - 10:50:16 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\system32\drivers\sisraid4.sys [71784] O58 - SDL:[MD5.E2BC0802646A08A443EE17A43DCBB68A] - 02/01/2007 - 05:31:46 ---A- . (.Silicon Image, Inc. - Windows Accelerator Driver.) -- C:\Windows\system32\drivers\SiWinAcc.sys [17328] O58 - SDL:[MD5.2F30C6EC1904CDB6F32CA69622726EB4] - 02/01/2007 - 10:44:52 ---A- . (.Sony Corporation - Sony Image Filter Driver.) -- C:\Windows\system32\drivers\SonyImgF.sys [30976] O58 - SDL:[MD5.DB31D8989B3450569C29780E7FA98C48] - 02/01/2007 - 12:34:22 ---A- . (.Sony Corporation - Sony Firmware Extension Parser driver.) -- C:\Windows\system32\drivers\SonyNC.sys [27520] O58 - SDL:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 09/02/2007 - 00:00:00 ---A- . (...) -- C:\Windows\system32\drivers\sptd.sys [721904] O58 - SDL:[MD5.09460DFF222BD1D2CB051C99EE4204E6] - 02/01/2007 - 06:18:44 ---A- . (.SigmaTel, Inc. - NDRC.) -- C:\Windows\system32\drivers\stwrt.sys [645120] O58 - SDL:[MD5.192AA3AC01DF071B541094F251DEED10] - 02/01/2007 - 10:50:05 ---A- . (.LSI Logic - LSI Logic 8XX SCSI Miniport Driver.) -- C:\Windows\system32\drivers\symc8xx.sys [35944] O58 - SDL:[MD5.8C8EB8C76736EBAF3B13B633B2E64125] - 02/01/2007 - 10:49:56 ---A- . (.LSI Logic - LSI Logic Hi-Perf SCSI Miniport Driver.) -- C:\Windows\system32\drivers\sym_hi.sys [31848] O58 - SDL:[MD5.8072AF52B5FD103BBBA387A1E49F62CB] - 02/01/2007 - 10:50:03 ---A- . (.LSI Logic - LSI Logic Ultra160 SCSI Miniport Driver.) -- C:\Windows\system32\drivers\sym_u3.sys [34920] O58 - SDL:[MD5.7C7445B4C2BD46C56ABB3499DA52B75C] - 02/01/2007 - 14:56:03 ---A- . (.Texas Instruments - ti21sony.sys.) -- C:\Windows\system32\drivers\ti21sony.sys [227328] O58 - SDL:[MD5.E362D54FD394999C4178936396664E57] - 02/01/2007 - 18:58:56 ---A- . (.TOSHIBA Corporation. - Toshiba Bluetooth HID mini port driver.) -- C:\Windows\system32\drivers\Toshidpt.sys [3712] O58 - SDL:[MD5.8D624D3BD1F2D78BD1C01A2D4E954B4E] - 02/01/2007 - 19:33:22 ---A- . (.TOSHIBA Corporation - TOSHIBA Bluetooth Port Emulation Driver.) -- C:\Windows\system32\drivers\tosporte.sys [41600] O58 - SDL:[MD5.B758FDA2E4389DC41688E4B8CEE832A0] - 02/01/2007 - 13:57:36 ---A- . (.TOSHIBA CORPORATION - Bluetooth RF Bus Driver.) -- C:\Windows\system32\drivers\tosrfbd.sys [113792] O58 - SDL:[MD5.90C8525BC578AAFFE87C2D0ED4379E9E] - 02/01/2007 - 17:55:16 ---A- . (.TOSHIBA Corporation - Bluetooth RFBNEP Driver.) -- C:\Windows\system32\drivers\tosrfbnp.sys [36480] O58 - SDL:[MD5.5BA1CA3B3CDDB1DDC67DF473F05D1EC2] - 02/01/2007 - 16:45:08 ---A- . (.TOSHIBA Corporation - Bluetooth RFCOMM Driver.) -- C:\Windows\system32\drivers\tosrfcom.sys [64896] O58 - SDL:[MD5.28099A4E52148319AFA685D93A2244D0] - 02/01/2007 - 16:07:46 ---A- . (.TOSHIBA Corporation. - Bluetooth HID Driver from TOSHIBA.) -- C:\Windows\system32\drivers\TosRfhid.sys [73600] O58 - SDL:[MD5.C52FD27B9ADF3A1F22CB90E6BCF9B0CB] - 02/01/2007 - 13:42:42 ---A- . (.TOSHIBA Corporation. - Bluetooth BNEP Driver.) -- C:\Windows\system32\drivers\tosrfnds.sys [18612] O58 - SDL:[MD5.1FF09B64D1E0C82EE81026718D8D47C2] - 02/01/2007 - 16:09:22 ---A- . (.TOSHIBA Corporation - Bluetooth Audio Driver (WDM).) -- C:\Windows\system32\drivers\TosRfSnd.sys [53504] O58 - SDL:[MD5.20CC46C5D3326122E1A0A8C9DAD00E0D] - 02/01/2007 - 00:29:10 ---A- . (.TOSHIBA CORPORATION - Bluetooth USB Miniport Driver.) -- C:\Windows\system32\drivers\tosrfusb.sys [40960] O58 - SDL:[MD5.3CD4EA35A6221B85DCC25DAA46313F8D] - 02/01/2007 - 10:51:25 ---A- . (.ULi Electronics Inc. - ULi SATA Controller Driver.) -- C:\Windows\system32\drivers\uliahci.sys [235112] O58 - SDL:[MD5.8514D0E5CD0534467C5FC61BE94A569F] - 02/01/2007 - 10:50:35 ---A- . (.Promise Technology, Inc. - Promise Ultra/Sata Series Driver for Win2003.) -- C:\Windows\system32\drivers\ulsata.sys [98408] O58 - SDL:[MD5.38C3C6E62B157A6BC46594FADA45C62B] - 02/01/2007 - 10:50:45 ---A- . (.Promise Technology, Inc. - Promise SATAII150 Series Windows Drivers.) -- C:\Windows\system32\drivers\ulsata2.sys [115816] O58 - SDL:[MD5.83CAFCB53201BBAC04D822F32438E244] - 01/09/2011 - 07:06:08 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\system32\drivers\usbaapl.sys [42496] O58 - SDL:[MD5.FD2E3175FCADA350C7AB4521DCA187EC] - 02/01/2007 - 10:49:30 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\viaide.sys [17512] O58 - SDL:[MD5.D984439746D42B30FC65A4C3546C6829] - 02/01/2007 - 10:50:41 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR X86-32.) -- C:\Windows\system32\drivers\vsmraid.sys [112232] O58 - SDL:[MD5.5A7FF9A18FF6D7E0527FE3ABF9204EF8] - 02/01/2007 - 09:39:10 ---A- . (.Conexant Systems, Inc. - Modem Audio Device Driver.) -- C:\Windows\system32\drivers\XAudio.sys [8192] O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 02/01/2007 - 08:09:42 ---A- . (...) -- C:\Windows\system32\ANSI.SYS [9029] O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 02/01/2007 - 08:09:45 ---A- . (...) -- C:\Windows\system32\country.sys [27097] O58 - SDL:[MD5.E6BC0F98FECEF245A0010D350C1A0B9B] - 02/01/2007 - 08:09:41 ---A- . (...) -- C:\Windows\system32\HIMEM.SYS [4768] O58 - SDL:[MD5.492090267B9608C62B956CD29BE3AFB7] - 02/01/2007 - 08:09:44 ---A- . (...) -- C:\Windows\system32\KEY01.SYS [42809] O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 02/01/2007 - 08:09:44 ---A- . (...) -- C:\Windows\system32\KEYBOARD.SYS [42537] O58 - SDL:[MD5.FFFF296A08DBF2AC0126C62E3778AC0D] - 02/01/2007 - 08:09:29 ---A- . (...) -- C:\Windows\system32\NTDOS.SYS [27866] O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 02/01/2007 - 08:09:35 ---A- . (...) -- C:\Windows\system32\NTDOS404.SYS [29146] O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 02/01/2007 - 08:09:38 ---A- . (...) -- C:\Windows\system32\NTDOS411.SYS [29370] O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 02/01/2007 - 08:09:40 ---A- . (...) -- C:\Windows\system32\NTDOS412.SYS [29274] O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 02/01/2007 - 08:09:31 ---A- . (...) -- C:\Windows\system32\NTDOS804.SYS [29146] O58 - SDL:[MD5.2E4112FB7D1B76E11ADFD7487B5D0E95] - 02/01/2007 - 08:09:20 ---A- . (...) -- C:\Windows\system32\NTIO.SYS [33952] O58 - SDL:[MD5.A98EBD4C2DF983665BF2D1AF49949974] - 02/01/2007 - 08:09:23 ---A- . (...) -- C:\Windows\system32\NTIO404.SYS [34672] O58 - SDL:[MD5.3F7E6406EDEF197C5CAAB2240EEF6F48] - 02/01/2007 - 08:09:24 ---A- . (...) -- C:\Windows\system32\NTIO411.SYS [35776] O58 - SDL:[MD5.3E64D681B776CC57BDC38A46D881F85B] - 02/01/2007 - 08:09:26 ---A- . (...) -- C:\Windows\system32\NTIO412.SYS [35536] O58 - SDL:[MD5.D86B6435729231C171432B4E77801BDB] - 02/01/2007 - 08:09:22 ---A- . (...) -- C:\Windows\system32\NTIO804.SYS [34672] ~ Scan Drivers in 00mn 05s ---\\ Liste des outils de nettoyage (O63) O63 - Logiciel: ZHPDiag 1.28 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 ~ Scan ADS in 00mn 00s ---\\ Liste des services Legacy (O64) O64 - Services: CurCS - ??/??/???? - C:\ComboFix\catchme.sys (.not file.) - catchme (catchme) .(...) - LEGACY_CATCHME O64 - Services: CurCS - 22/08/2008 - C:\Windows\system32\drivers\cbfs.sys - CbFs(CbFs) .(.EldoS Corporation - Callback File System Driver.) - LEGACY_CBFS O64 - Services: CurCS - 18/10/2006 - C:\Windows\system32\DRIVERS\DMICall.sys - Sony DMI Call service(DMICall) .(.Sony Corporation - Windows 2000 DMI Call Kernel Driver.) - LEGACY_DMICALL O64 - Services: CurCS - ??/??/???? - C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys (.not file.) - esgiguard (esgiguard) .(...) - LEGACY_ESGIGUARD O64 - Services: CurCS - 05/07/2006 - C:\Windows\system32\drivers\sfdrv01.sys - StarForce Protection Environment Driver (version 1.x)(sfdrv01) .(.Protection Technology (StarForce) - FrontLine Environment Driver.) - LEGACY_SFDRV01 O64 - Services: CurCS - 05/07/2006 - C:\Windows\system32\drivers\sfdrv01a.sys - StarForce Protection Environment Driver (version 1.x.a)(sfdrv01a) .(.Protection Technology (StarForce) - FrontLine Environment Driver.) - LEGACY_SFDRV01A O64 - Services: CurCS - 14/06/2006 - C:\Windows\system32\drivers\sfhlp02.sys - StarForce Protection Helper Driver (version 2.x)(sfhlp02) .(.Protection Technology (StarForce) - FrontLine Helper Driver.) - LEGACY_SFHLP02 O64 - Services: CurCS - 12/01/2007 - C:\Windows\system32\drivers\sfvfs02.sys - StarForce Protection VFS Driver (version 2.x)(sfvfs02) .(.Protection Technology (StarForce) - FrontLine File System Driver.) - LEGACY_SFVFS02 O64 - Services: CurCS - 01/11/2006 - C:\Windows\system32\drivers\siwinacc.sys - SATALink driver accelerator(SiFilter) .(.Silicon Image, Inc. - Windows Accelerator Driver.) - LEGACY_SIFILTER O64 - Services: CurCS - ??/??/???? - C:\Windows\system32\Drivers\sptd.sys - sptd (sptd) .(...) - LEGACY_SPTD O64 - Services: CurCS - 04/08/2006 - C:\Windows\system32\DRIVERS\xaudio.sys - XAudio(XAudio) .(.Conexant Systems, Inc. - Modem Audio Device Driver.) - LEGACY_XAUDIO ~ Scan Services in 00mn 01s ---\\ File Associations Shell Spawning (O67) O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (. - .) -- "%1" %* O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\system32\shell32.dll O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- "%1" %* O67 - Shell Spawning: <.com> <ComFile>[HKLM\..\open\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- "%1" %* O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe O67 - Shell Spawning: <.exe> <exefile>[HKCU\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.exe> <exefile>[HKU\..\open\Command] (...) -- C:\Windows\system32\config\systemprofile\AppData\Local\nfj.exe O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\system32\shell32.dll O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- "%1" %* O67 - Shell Spawning: <.com> <ComFile>[HKCR\..\open\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- "%1" %* O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe ~ Scan Keys in 00mn 00s ---\\ Start Menu Internet (O68) O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe ~ Scan Keys in 00mn 00s ---\\ Search Browser Infection (O69) O69 - SBI: SearchScopes [HKCU] ${searchCLSID} [DefaultScope] - (@ieframe.dll,-12512) - Bing O69 - SBI: SearchScopes [HKCU] {6C247B9D-04A8-4F04-B308-D0582265D29D} - (Google) - Google O69 - SBI: SearchScopes [HKCU] {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (AVG Secure Search) - iGeared – A Community Toolbar for Smart Webmasters ~ Scan Keys in 00mn 00s ---\\ Internet Feature Controls (O81) O81 - IFC: Internet Feature Controls [HKUS\.DEFAULT] [FEATURE_BROWSER_EMULATION] -- svchost.exe O81 - IFC: Internet Feature Controls [HKUS\S-1-5-18] [FEATURE_BROWSER_EMULATION] -- svchost.exe ~ Scan Keys in 00mn 00s ---\\ Recherche particuliere à la racine de certains dossiers (O84) [MD5.B55E9CC49FF03496C478273A0950D7FB] [sPRF][01/09/2008] (...) -- C:\Program Files\Lavasoft_Adaware_multi.exe [19153264] [MD5.8919AF797D9DCF0F224CFE4ED88548C6] [sPRF][21/12/2007] (...) -- C:\Program Files\videoraipodtouchconverter_Installer.exe [7151099] [MD5.0E6B9B7B6EF8ED324535A632AD8C1E04] [sPRF][29/10/2007] (...) -- C:\Program Files\vlc-0.8.6c-win32.exe [9679815] ~ Scan Files in 00mn 01s ---\\ Recherche d'infection Rogue (O86) C:\Users\Matt\AppData\Roaming\c42f7236 ~ Scan Files in 00mn 00s ---\\ Firewall Active Exception List (FirewallRules) (O87) O87 - FAEL: "{84E48B24-F2F7-4219-9A1E-21894EB4909E}" | In - Public - P6 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\Program Files\DNA\btdna.exe O87 - FAEL: "{67EAD51B-3505-4E4B-A1C8-318A94B477FD}" | In - Public - P17 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\Program Files\DNA\btdna.exe O87 - FAEL: "{514CAD07-E706-4688-A641-DD815AEA53EB}" | In - Public - P6 - TRUE | .(.BitTorrent, Inc. - BitTorrent.) -- C:\Program Files\BitTorrent\bittorrent.exe O87 - FAEL: "{9FFF6818-9ADA-49B3-B4BB-7C9FB2B970B0}" | In - Public - P17 - TRUE | .(.BitTorrent, Inc. - BitTorrent.) -- C:\Program Files\BitTorrent\bittorrent.exe O87 - FAEL: "{CC3AE0CD-0C29-44E4-8DBD-4D360EC85660}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files\Bonjour\mDNSResponder.exe (.not file.) O87 - FAEL: "{F3468DBA-CD99-462D-A617-976D47327236}" |In - Public - P17 - TRUE | .(...) -- C:\Program Files\Bonjour\mDNSResponder.exe (.not file.) O87 - FAEL: "{EFA4DA92-F782-495E-BDCF-D452D1612402}" | In - Public - P6 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files\iTunes\iTunes.exe O87 - FAEL: "{5F30FC77-BE86-4FA9-8260-CE0B14232970}" | In - Public - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files\iTunes\iTunes.exe O87 - FAEL: "{A101A122-3CD5-40D6-B028-38132B1B093B}" | In - Public - P6 - FALSE | .(...) -- C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe O87 - FAEL: "{17FE5BEB-EA17-48E2-B9D8-DF9C61B87E5F}" | In - Public - P17 - FALSE | .(...) -- C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe O87 - FAEL: "TCP Query User{1295C9CD-2821-4DA8-91A1-6352F383A415}C:\program files\emule\emule.exe" |In - Public - P6 - TRUE | .(...) -- C:\program files\emule\emule.exe (.not file.) O87 - FAEL: "UDP Query User{B62C87C6-DD3F-4A8D-83FD-EEFBE4B627A5}C:\program files\emule\emule.exe" |In - Public - P17 - TRUE | .(...) -- C:\program files\emule\emule.exe (.not file.) O87 - FAEL: "TCP Query User{9DFCC76F-7DDD-4F45-AE59-89D5D2584227}C:\program files\sopcast\sopcast.exe" |In - Public - P6 - TRUE | .(...) -- C:\program files\sopcast\sopcast.exe (.not file.) O87 - FAEL: "UDP Query User{FB0C63F7-8E8B-4282-B938-3C4B541A2488}C:\program files\sopcast\sopcast.exe" |In - Public - P17 - TRUE | .(...) -- C:\program files\sopcast\sopcast.exe (.not file.) O87 - FAEL: "TCP Query User{FA45268A-7DCF-485A-8FED-7174D3C30962}C:\program files\sopcast\adv\sopadver.exe" |In - Public - P6 - TRUE | .(...) -- C:\program files\sopcast\adv\sopadver.exe (.not file.) O87 - FAEL: "UDP Query User{C28F2345-5B78-4998-98F0-229FF3447D06}C:\program files\sopcast\adv\sopadver.exe" |In - Public - P17 - TRUE | .(...) -- C:\program files\sopcast\adv\sopadver.exe (.not file.) O87 - FAEL: "TCP Query User{1A0B2D8B-EEEF-40F3-8C10-88E1C7F1C1EC}C:\program files\soulseek\slsk.exe" | In - Public - P6 - TRUE | .(.Pas de propriétaire - SoulSeek.) -- C:\program files\soulseek\slsk.exe O87 - FAEL: "UDP Query User{46EF7D67-68E5-4502-91AD-D973CCA13BFE}C:\program files\soulseek\slsk.exe" | In - Public - P17 - TRUE | .(.Pas de propriétaire - SoulSeek.) -- C:\program files\soulseek\slsk.exe O87 - FAEL: "TCP Query User{2FE62528-EE52-4010-99F5-BD2145E1E466}C:\program files\mozilla firefox\firefox.exe" | In - Public - P6 - TRUE | .(.Mozilla Corporation - Firefox.) -- C:\program files\mozilla firefox\firefox.exe O87 - FAEL: "UDP Query User{29CFA443-5D64-4E28-B199-F380A1F6982F}C:\program files\mozilla firefox\firefox.exe" | In - Public - P17 - TRUE | .(.Mozilla Corporation - Firefox.) -- C:\program files\mozilla firefox\firefox.exe O87 - FAEL: "{20112519-126F-48FE-8285-A5C4C9590CCE}" | In - Public - P6 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.dll O87 - FAEL: "{139E471F-CB70-464F-A315-92B750D7A511}" | In - Public - P17 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.dll O87 - FAEL: "{310DFBE7-07E5-41A5-AB0B-460549B0C0AF}" | In - Public - P6 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe O87 - FAEL: "{7D0AFA5D-032E-4F9E-87A8-1C4E8602D4D5}" | In - Public - P17 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe O87 - FAEL: "TCP Query User{45DBB206-C737-4F21-A6CA-AD25F50DD2F5}C:\users\matt\program files\dna\btdna.exe" | In - Public - P6 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\users\matt\program files\dna\btdna.exe O87 - FAEL: "UDP Query User{F22AC7E9-9160-4E7E-8EFF-F96B31BBF848}C:\users\matt\program files\dna\btdna.exe" | In - Public - P17 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\users\matt\program files\dna\btdna.exe O87 - FAEL: "TCP Query User{B347802D-B532-4988-A110-E5D2CA5F78D1}C:\users\matt\program files\dna\btdna.exe" | In - Private - P6 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\users\matt\program files\dna\btdna.exe O87 - FAEL: "UDP Query User{BFD14251-6312-417D-830A-4E4B1B0F5AF1}C:\users\matt\program files\dna\btdna.exe" | In - Private - P17 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\users\matt\program files\dna\btdna.exe O87 - FAEL: "{165B9827-4AF7-4870-AF09-B08075B8C6D7}" | In - Private - P6 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.dll O87 - FAEL: "{4670BEC3-5130-4800-9210-CDD4916CCDF5}" | In - Private - P17 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.dll O87 - FAEL: "{3EB155BB-3734-4CAA-BC49-075353B5F326}" | In - Private - P6 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe O87 - FAEL: "{854D566D-EAA0-495B-9258-6E55D45541C3}" | In - Private - P17 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe O87 - FAEL: "TCP Query User{0666A263-B69E-461A-B48C-E22C7BEC5F23}C:\program files\dna\btdna.exe" | In - Private - P6 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\program files\dna\btdna.exe O87 - FAEL: "UDP Query User{B6DCA486-4509-4C9F-A965-8EFBFD2958FA}C:\program files\dna\btdna.exe" | In - Private - P17 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\program files\dna\btdna.exe O87 - FAEL: "TCP Query User{058D2BD5-7A9D-4A68-804E-36BB5A3962B9}C:\program files\soulseek\slsk.exe" | In - Private - P6 - TRUE | .(.Pas de propriétaire - SoulSeek.) -- C:\program files\soulseek\slsk.exe O87 - FAEL: "UDP Query User{20B98830-1474-4EC8-9602-D51824836C69}C:\program files\soulseek\slsk.exe" | In - Private - P17 - TRUE | .(.Pas de propriétaire - SoulSeek.) -- C:\program files\soulseek\slsk.exe O87 - FAEL: "TCP Query User{159143BA-0A47-4DB7-A52D-CBEA6D2DAAA6}C:\program files\emule\emule.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files\emule\emule.exe (.not file.) O87 - FAEL: "UDP Query User{53DE6241-9E85-46D7-A580-9FF26763A73A}C:\program files\emule\emule.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files\emule\emule.exe (.not file.) O87 - FAEL: "TCP Query User{1F8AFBC9-5455-4695-B5A8-BB5147D3BB93}C:\program files\bittorrent\bittorrent.exe" | In - Private - P6 - TRUE | .(.BitTorrent, Inc. - BitTorrent.) -- C:\program files\bittorrent\bittorrent.exe O87 - FAEL: "UDP Query User{ECB6AF88-1E49-4AA6-B977-C7A6C682DE06}C:\program files\bittorrent\bittorrent.exe" | In - Private - P17 - TRUE | .(.BitTorrent, Inc. - BitTorrent.) -- C:\program files\bittorrent\bittorrent.exe O87 - FAEL: "TCP Query User{59D48740-417C-4236-8490-EBC832FEDBF0}C:\program files\mozilla firefox\firefox.exe" | In - Private - P6 - TRUE | .(.Mozilla Corporation - Firefox.) -- C:\program files\mozilla firefox\firefox.exe O87 - FAEL: "UDP Query User{89CC35D7-FD81-4EBF-9E8D-C6C491CF58B5}C:\program files\mozilla firefox\firefox.exe" | In - Private - P17 - TRUE | .(.Mozilla Corporation - Firefox.) -- C:\program files\mozilla firefox\firefox.exe O87 - FAEL: "{6B858B40-31C8-4FF4-8782-902075EA170F}" | In - Public - P6 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe O87 - FAEL: "{3B6A6340-3E17-40EC-AA46-8DCB8901C469}" | In - Public - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe O87 - FAEL: "{F9030FCE-3E72-42C0-BEB5-C3F16F4AC2C9}" | In - Private - P6 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe O87 - FAEL: "{56D08488-2F00-4C14-A4A3-2C3A12FCBC3D}" | In - Private - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe O87 - FAEL: "TCP Query User{DF698C2F-33FB-4F49-B412-E8D5B5F93887}C:\users\matt\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" | In - Private - P6 - TRUE | .(.Octoshape ApS.) -- C:\users\matt\appdata\roaming\macrom O87 - FAEL: "UDP Query User{06F540C6-95C4-445E-8FCE-A304FF03B389}C:\users\matt\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" | In - Private - P17 - TRUE | .(.Octoshape ApS.) -- C:\users\matt\appdata\roaming\macro O87 - FAEL: "TCP Query User{0A826A8D-0F78-4E65-BF8D-401FBD5CC111}C:\program files\google\google earth\plugin\geplugin.exe" | In - Private - P6 - TRUE | .(.Google - Google Earth.) -- C:\program files\google\google earth\plugin\geplugin.exe O87 - FAEL: "UDP Query User{820FF97A-1BFA-46B9-8604-638A996F993D}C:\program files\google\google earth\plugin\geplugin.exe" | In - Private - P17 - TRUE | .(.Google - Google Earth.) -- C:\program files\google\google earth\plugin\geplugin.exe O87 - FAEL: "{49A864EB-99ED-43E4-8CF5-FCA569A46F9F}" |In - Private - P6 - TRUE | .(...) -- C:\Users\Matt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DH8190VO\241fdfd[1].exe (.not file.) O87 - FAEL: "{6BD9A413-5288-4E06-AB58-B305F2F1CF12}" |In - Private - P17 - TRUE | .(...) -- C:\Users\Matt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DH8190VO\241fdfd[1].exe (.not file.) O87 - FAEL: "{F3F6C444-9E28-40FD-8A0C-FE97219A6097}" |In - Private - P6 - TRUE | .(...) -- C:\Windows\AppPatch\qslkpf.exe (.not file.) O87 - FAEL: "{CA85E7CE-2E48-49C6-B7B0-10A903856D92}" |In - Private - P17 - TRUE | .(...) -- C:\Windows\AppPatch\qslkpf.exe (.not file.) O87 - FAEL: "{716EEB25-F222-4069-8D60-DA484AB29787}" |In - Public - P6 - TRUE | .(...) -- C:\Windows\AppPatch\qslkpf.exe (.not file.) O87 - FAEL: "{1895CCA3-D660-4F5B-B629-3FA4A53E06BF}" |In - Public - P17 - TRUE | .(...) -- C:\Windows\AppPatch\qslkpf.exe (.not file.) O87 - FAEL: "TCP Query User{6C0F3AB7-932A-43EF-93AD-D709DDB32706}C:\program files\mozilla firefox\plugin-container.exe" | In - Private - P6 - TRUE | .(.Mozilla Corporation.) -- C:\program files\mozilla firefox\plugin-container.exe O87 - FAEL: "UDP Query User{6F123AA8-6CA6-4781-853F-74FBFBDBD851}C:\program files\mozilla firefox\plugin-container.exe" | In - Private - P17 - TRUE | .(.Mozilla Corporation.) -- C:\program files\mozilla firefox\plugin-container.exe O87 - FAEL: "TCP Query User{9BE1ABBF-E830-4A50-9BD9-3FFC3B44FED7}C:\users\matt\appdata\local\google\update\googleupdate.exe" | In - Private - P6 - TRUE | .(.Google Inc..) -- C:\users\matt\appdata\local\google\update\googleupdate.exe O87 - FAEL: "UDP Query User{70F2EC4C-9A5B-4F8A-B95E-209BF3CA43EB}C:\users\matt\appdata\local\google\update\googleupdate.exe" | In - Private - P17 - TRUE | .(.Google Inc..) -- C:\users\matt\appdata\local\google\update\googleupdate.exe O87 - FAEL: "TCP Query User{72799B76-90C0-47AD-950D-7F52815DA057}C:\program files\spybot - search & destroy\sdupdate.exe" | In - Private - P6 - TRUE | .(.Safer Networking Limited.) -- C:\program files\spybot - search & destroy\sdupdate.exe O87 - FAEL: "UDP Query User{96F3CEC5-A8D6-497E-9E9E-906842165304}C:\program files\spybot - search & destroy\sdupdate.exe" | In - Private - P17 - TRUE | .(.Safer Networking Limited.) -- C:\program files\spybot - search & destroy\sdupdate.exe O87 - FAEL: "TCP Query User{A5C1965C-090D-4D9B-A60F-83F56A7742B3}C:\program files\sony\vaio update 3\vaioupdt.exe" | In - Private - P6 - TRUE | .(.Sony Corporation - VAIO Update.) -- C:\program files\sony\vaio update 3\vaioupdt.exe O87 - FAEL: "UDP Query User{B984729F-FE08-413B-9CBF-C6498CDBB2F7}C:\program files\sony\vaio update 3\vaioupdt.exe" | In - Private - P17 - TRUE | .(.Sony Corporation - VAIO Update.) -- C:\program files\sony\vaio update 3\vaioupdt.exe O87 - FAEL: "TCP Query User{330D969F-54CA-48AD-A749-41B59A792C07}C:\program files\malwarebytes' anti-malware\mbam.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files\malwarebytes' anti-malware\mbam.exe (.not file.) O87 - FAEL: "UDP Query User{6B48977D-A8E3-43B1-89C4-40DCF3F8C8A2}C:\program files\malwarebytes' anti-malware\mbam.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files\malwarebytes' anti-malware\mbam.exe (.not file.) O87 - FAEL: "TCP Query User{7818D38B-B451-44E7-9241-7A9282940BDF}C:\program files\avira\antivir desktop\avnotify.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files\avira\antivir desktop\avnotify.exe (.not file.) O87 - FAEL: "UDP Query User{B582C45C-B127-4A78-9D87-CA2A9CFFF94E}C:\program files\avira\antivir desktop\avnotify.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files\avira\antivir desktop\avnotify.exe (.not file.) O87 - FAEL: "TCP Query User{C9166196-12E0-49C4-B3C4-4E0A73AA0A76}C:\program files\red kawa\video converter 3\rkvideoconverter.exe" | In - Private - P6 - TRUE | .(.Red Kawa Inc..) -- C:\program files\red kawa\video converter 3\rkvideoconverter.exe O87 - FAEL: "UDP Query User{80203B07-6174-4040-9D69-AA58FDAAF24C}C:\program files\red kawa\video converter 3\rkvideoconverter.exe" | In - Private - P17 - TRUE | .(.Red Kawa Inc..) -- C:\program files\red kawa\video converter 3\rkvideoconverter.exe O87 - FAEL: "{B1C1B2DF-A2BD-420B-910F-766DE2AEB792}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files\Bonjour\mDNSResponder.exe (.not file.) O87 - FAEL: "{7D203B48-2729-489B-B847-6C761D31BE56}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files\Bonjour\mDNSResponder.exe (.not file.) O87 - FAEL: "TCP Query User{4F59AD46-5B7E-426B-A35A-4D3F4ABD3866}C:\program files\itunes\itunes.exe" | In - Private - P6 - TRUE | .(.Apple Inc. - iTunes.) -- C:\program files\itunes\itunes.exe O87 - FAEL: "UDP Query User{52A49439-18A0-4D03-952A-2A3D8767282A}C:\program files\itunes\itunes.exe" | In - Private - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\program files\itunes\itunes.exe O87 - FAEL: "TCP Query User{37CAE5D6-E2AC-4171-AB65-54264D843542}C:\program files\common files\apple\mobile device support\com.google.contactsync.client.exe" | In - Private - P6 - TRUE | .(.Apple Inc..) -- C:\program files\common files\apple\mobile devic O87 - FAEL: "UDP Query User{76E7A423-C596-4840-898D-A3BA869385BA}C:\program files\common files\apple\mobile device support\com.google.contactsync.client.exe" | In - Private - P17 - TRUE | .(.Apple Inc..) -- C:\program files\common files\apple\mobile devi O87 - FAEL: "TCP Query User{7D911D1C-B0C6-4F94-AC8B-E9CEFCE38EF1}C:\program files\avira\antivir desktop\apnstub.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files\avira\antivir desktop\apnstub.exe (.not file.) O87 - FAEL: "UDP Query User{91CC2ADD-A219-4C70-9230-371780577E79}C:\program files\avira\antivir desktop\apnstub.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files\avira\antivir desktop\apnstub.exe (.not file.) O87 - FAEL: "TCP Query User{C7E85CA7-9CF9-4E21-861C-683A01B1C8DD}C:\program files\videolan\vlc\vlc.exe" | In - Private - P6 - TRUE | .(...) -- C:\program files\videolan\vlc\vlc.exe O87 - FAEL: "UDP Query User{7297F383-256E-401C-BA1E-6D80FA80F0D0}C:\program files\videolan\vlc\vlc.exe" | In - Private - P17 - TRUE | .(...) -- C:\program files\videolan\vlc\vlc.exe O87 - FAEL: "TCP Query User{0F7D565D-CD43-4A65-8072-6110237D50E7}C:\combofix\combofix-download.3xe" |In - Private - P6 - TRUE | .(...) -- C:\combofix\combofix-download.3xe (.not file.) O87 - FAEL: "UDP Query User{38EC8024-667E-4349-85A9-F33C8AB787EB}C:\combofix\combofix-download.3xe" |In - Private - P17 - TRUE | .(...) -- C:\combofix\combofix-download.3xe (.not file.) ~ Scan Firewall in 00mn 01s ---\\ Scan Additionnel (O88) Database Version : 8617 - (29/08/2011) Clés trouvées (Keys found) : 0 Valeurs trouvées (Values found) : 0 Dossiers trouvés (Folders found) : 1 Fichiers trouvés (Files found) : 0 C:\Program Files\Enigma Software Group\SpyHunter =>Crapware.SpyHunter ~ Scan Additionnel in 00mn 10s ---\\ Recherche détournement de DNS routeur (O89) Serveur : UnKnown Address: 127.0.0.1:53 ~ Scan DNS in 00mn 00s ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped) SS - | Auto 0 | (AdobeActiveFileMonitor5.0) . (...) - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe SS - | Auto 0 | (Apple Mobile Device) . (...) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe SS - | Auto 0 | (Bonjour Service) . (...) - C:\Program Files\Bonjour\mDNSResponder.exe SS - | Auto 0 | (CLTNetCnService) . (...) - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe SS - | Auto 0 | (gupdate) . (...) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 0 | (gupdatem) . (...) - C:\Program Files\Google\Update\GoogleUpdate.exe SS - | Demand 06/09/2007 136120 | (gusvc) . (.Google.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe SS - | Demand 02/02/2007 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe SS - | Demand 0 | (iPod Service) . (...) - C:\Program Files\iPod\bin\iPodService.exe SS - | Auto 0 | (M4iPodWPDService) . (...) - C:\Program Files\Common Files\Mediafour\iPod\M4iPodWPDService.exe SS - | Demand 02/01/2007 57344 | (MSCSPTISRV) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AvLib\MSCSPTISRV.exe SS - | Demand 02/01/2007 57344 | (PACSPTISVR) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AvLib\PACSPTISVR.exe SS - | Auto 0 | (sfrem01) . (...) - C:\Windows\system32\sfrem01.exe SS - | Demand 02/01/2007 69632 | (SPTISRV) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AvLib\SPTISRV.exe SS - | Demand 02/01/2007 69632 | (SSScsiSV) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AvLib\SSScsiSV.exe SS - | Auto 0 | (STacSV) . (...) - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe SS - | Auto 0 | (TOSHIBA Bluetooth Service) . (...) - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe SS - | Demand 02/01/2007 73728 | (VAIO Entertainment TV Device Arbitration Service) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe SS - | Auto 182392 | (VAIO Event Service) . (...) - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe SS - | Demand 02/01/2007 2523136 | (VAIOMediaPlatform-IntegratedServer-AppServer) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe SS - | Demand 02/01/2007 1089536 | (VAIOMediaPlatform-IntegratedServer-UPnP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe SS - | Demand 02/01/2007 741376 | (VAIOMediaPlatform-UCLS-AppServer) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe SS - | Demand 02/01/2007 1089536 | (VAIOMediaPlatform-UCLS-UPnP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe SS - | Demand 0 | (Vcsw) . (...) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe SS - | Auto 0 | (VzCdbSvc) . (...) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe SS - | Auto 0 | (VzFw) . (...) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe SS - | Auto 02/01/2007 22016 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\system32\svchost.exe SR - | Auto 05/09/2011 386560 | (XAudioService) . (.Conexant Systems, Inc..) - C:\Windows\system32\DRIVERS\xaudio.exe ~ Scan Services in 00mn 01s ---\\ Recherche Master Boot Record Infection (MBR)(O80) Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, GMER - Rootkit Detector and Remover Run by Matt at 08/09/2011 23:23:29 device: opened successfully user: MBR read successfully Disk trace: called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x85DE64D0]<< 1 ntkrnlpa!IofCallDriver[0x82427F3B] -> \Device\Harddisk0\DR0[0x859625E0] 3 nt[0x824B07E2] -> ntkrnlpa!IofCallDriver[0x82427F3B] -> [0x85306858] 5 acpi[0x8044332A] -> ntkrnlpa!IofCallDriver[0x82427F3B] -> [0x852E9BB0] \Driver\atapi[0x8530F5C8] -> IRP_MJ_CREATE -> 0x85DE64D0 error: Read Un périphérique attaché au système ne fonctionne pas correctement. kernel: MBR read successfully detected disk devices: detected hooks: \Driver\atapi -> 0x8521d1f8 user & kernel MBR OK Warning: possible MBR rootkit infection ! ~ Scan MBR in 00mn 03s ---\\ Recherche Master Boot Record Infection (MBRCheck)(O80) Written by ad13, http://ad13.geekstog Run by Matt at 08/09/2011 23:23:31 ********* Dump file Name ********* C:\PhysicalDisk0_MBR.bin ~ Scan MBR in 00mn 05s End of the scan (1331 lines in 01mn 16s)(0) -
PC infecté / publicités intempestives ...
matt313 a posté un sujet dans Analyses et éradication malwares
Bonjour, Mon laptop S/s Windows Vista est fortement ralenti et ne réagit plus normalement. Certaines applications ne se lance plus (pas même en administrateur) c'est le cas pour Malwarebytes et au lancement de certaines applications le centre de sécurité me demande l'autorisation pour lancer celles-ci ! exemple pour Google Chrome, Firefox Enfin les pages de recherche ne sont pas affichés et je tombe sur des pages diverses de publicité Merci par avance pour votre aide