Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e)

Voici donc le rapport LOG :

 

Logfile of random's system information tool 1.08 (written by random/random)

Run by Mikael at 2010-08-18 20:13:44

Microsoft Windows 7 Édition Familiale Premium Service Pack 2

System drive C: has 65 GB (14%) free of 467 GB

Total RAM: 3067 MB (54% free)

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 20:14:07, on 18/08/2010

Platform: Windows 7 (WinNT 6.00.3504)

MSIE: Internet Explorer v8.00 (8.00.7600.16385)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\VIA\VIAudioi\VDeck\viaaud.exe

C:\Program Files\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files\Launch Manager\LManager.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\Program Files\Wi-Fi Sync\wifisync.exe

C:\Program Files\DivX\DivX Update\DivXUpdate.exe

C:\Program Files\PowerISO\PWRISOVM.EXE

C:\Program Files\SFR\Kit\9props.exe

C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe

C:\Program Files\SuperCopier2\SuperCopier2.exe

C:\Program Files\RocketDock\RocketDock.exe

C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe

C:\Users\Mikael\AppData\Roaming\Dropbox\bin\Dropbox.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Packard Bell\Packard Bell PowerSave Solution\ePowerTray.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe

C:\Program Files\MSN Toolbar\Platform\6.0.2156.0\mswinext.exe

C:\Program Files\Fluendo\Moovida\spointer\moovida_air.exe

C:\Program Files\Mozilla Firefox\plugin-container.exe

C:\Users\Mikael\Desktop\RSIT.exe

C:\Program Files\trend micro\Mikael.exe

C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Bing, Actualité et Sport

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Bing, Actualité et Sport

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: mipony-plugin Toolbar - {90d46c30-9f25-4104-aea9-35c3f84477ff} - C:\Program Files\mipony-plugin\tbmipo.dll

O1 - Hosts: ::1 localhost

O2 - BHO: Aide à la navigation SFR - {0F6E720A-1A6B-40E1-A294-1D4D19F156C8} - C:\Program Files\SFR\Kit\SFRNavErrorHelper.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL

O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: mipony-plugin Toolbar - {90d46c30-9f25-4104-aea9-35c3f84477ff} - C:\Program Files\mipony-plugin\tbmipo.dll

O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL

O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: Interest recogniser for Moovida (powered by Spointer) - {E2A7BD67-0EAF-497f-B05B-748D7BF3C421} - C:\Program Files\Fluendo\Moovida\spointer\extensions\moovida_air_ie.dll

O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll

O3 - Toolbar: mipony-plugin Toolbar - {90d46c30-9f25-4104-aea9-35c3f84477ff} - C:\Program Files\mipony-plugin\tbmipo.dll

O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [VIAAUD] C:\Program Files\VIA\VIAudioi\VDeck\VIAAUD.exe

O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Packard Bell\Packard Bell PowerSave Solution\ePowerTrayLauncher.exe

O4 - HKLM\..\Run: [backupManagerTray] "C:\Program Files\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" -k

O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [Wi-Fi Sync] "C:\Program Files\Wi-Fi Sync\wifisync.exe"

O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume

O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe

O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE

O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO

O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon

O4 - HKCU\..\Run: [smpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe

O4 - HKCU\..\Run: [superCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"

O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"

O4 - HKCU\..\Run: [PasteFireClient] C:\Users\Mikael\AppData\Local\Temp\Rar$EX00.911\PasteFireClient0.5.3a\PasteFireClient.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU')

O4 - Startup: Dock.lnk = ?

O4 - Startup: Dropbox.lnk = Mikael\AppData\Roaming\Dropbox\bin\Dropbox.exe

O8 - Extra context menu item: &Envoyer à OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: Add to &Evernote - res://C:\Program Files\Evernote\Evernote3.5\enbar.dll/2000

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200

O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000

O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html

O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

O8 - Extra context menu item: Télécharger avec Mipony - file://C:\Program Files\MiPony\Browser\IEContext.htm

O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll

O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html

O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html

O9 - Extra button: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra 'Tools' menuitem: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files\Evernote\Evernote3.5\enbar.dll

O9 - Extra 'Tools' menuitem: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files\Evernote\Evernote3.5\enbar.dll

O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1280935001081

O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader2.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe

O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (Audiosrv) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: Service de transfert intelligent en arrière-plan (BITS) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: CanalPlus.VOD - Canal+ Active - C:\Program Files\Canal+\CANAL+ CANALSAT A LA DEMANDE\VOD\CanalPlus.VOD.exe

O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe

O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe

O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Packard Bell\Packard Bell PowerSave Solution\ePowerSvc.exe

O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: Service Google Update (gupdate1ca4125ddefdc00) (gupdate1ca4125ddefdc00) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: HsfXAudioService - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - libusb-Win32 - C:\Windows\system32\libusbd-nt.exe

O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: Lundi Matin Business Apache (LMBApache) - Unknown owner - c:\xampplite\srvany.exe

O23 - Service: Lundi Matin Business MySQL (LMBMySQL) - Unknown owner - c:\xampplite\srvany.exe

O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\ehome\ehres.dll,-15501 (Mcx2Svc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: Mobiola Wave Service - Unknown owner - C:\Program Files\Mobiola Headset for iPhone\MobiolaWaveService.exe

O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe

O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe

O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe

O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe

O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (StiSvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe

O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe

O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe

O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe

O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\wmpnetwk.exe

O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe

O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe

O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe

O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe

 

--

End of file - 29581 bytes

 

======Scheduled tasks folder======

 

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

 

======Registry dump======

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]

Objet d'aide à la navigation SFR - C:\Program Files\SFR\Kit\SFRNavErrorHelper.dll [2009-10-15 165184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]

Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]

Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-02-24 138624]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{724d43a9-0d85-11d4-9908-00400523e39a}]

C:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2010-07-03 6042176]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]

Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2010-03-25 4222864]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-05-26 448384]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90d46c30-9f25-4104-aea9-35c3f84477ff}]

mipony-plugin Toolbar - C:\Program Files\mipony-plugin\tbmipo.dll [2010-06-03 2736736]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]

Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-06-07 380800]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]

Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-14 278192]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]

Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll [2010-06-02 814648]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]

Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2010-02-28 561552]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]

Bing Bar BHO - C:\Program Files\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll [2010-05-07 603920]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-17 41760]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E2A7BD67-0EAF-497f-B05B-748D7BF3C421}]

Interest recogniser for Moovida (powered by Spointer) - C:\Program Files\Fluendo\Moovida\spointer\extensions\moovida_air_ie.dll [2010-06-14 132256]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

{724d43a0-0d85-11d4-9908-00400523e39a} - &RoboForm - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll [2010-07-03 6042176]

{90d46c30-9f25-4104-aea9-35c3f84477ff} - mipony-plugin Toolbar - C:\Program Files\mipony-plugin\tbmipo.dll [2010-06-03 2736736]

{8dcb7100-df86-4384-8842-8fa844297b3f} - @C:\Program Files\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll,-100 - C:\Program Files\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll [2010-05-07 603920]

{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-14 278192]

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-02-06 1430824]

"VIAAUD"=C:\Program Files\VIA\VIAudioi\VDeck\VIAAUD.exe [2009-06-04 413696]

"Acer ePower Management"=C:\Program Files\Packard Bell\Packard Bell PowerSave Solution\ePowerTrayLauncher.exe [2009-08-26 494112]

"BackupManagerTray"=C:\Program Files\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe [2009-03-10 250624]

"LManager"=C:\Program Files\Launch Manager\LManager.exe [2009-04-03 866824]

"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]

"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [2010-07-13 47904]

"Wi-Fi Sync"=C:\Program Files\Wi-Fi Sync\wifisync.exe [2010-05-27 373248]

"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-06-03 1144104]

"Microsoft Default Manager"=C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2010-05-10 439568]

"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]

"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2009-07-27 180224]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"ccleaner"=C:\Program Files\CCleaner\CCleaner.exe [2010-06-23 1699128]

"Connexion SFR 9props.exe"=C:\Program Files\SFR\Kit\9props.exe [2009-10-15 959808]

"SmpcSys"=C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe [2009-03-18 1160736]

"SuperCopier2.exe"=C:\Program Files\SuperCopier2\SuperCopier2.exe [2009-08-16 955392]

"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-09-11 68856]

"RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]

"RoboForm"=C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2010-07-03 160328]

"PasteFireClient"=C:\Users\Mikael\AppData\Local\Temp\Rar$EX00.911\PasteFireClient0.5.3a\PasteFireClient.exe []

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]

C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2009-11-07 611712]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]

C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-06-29 30192]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

C:\Program Files\iTunes\iTunesHelper.exe [2010-07-21 141608]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]

C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2010-06-07 4176760]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess]

C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [2010-03-16 718208]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

C:\Program Files\Steam\Steam.exe [2010-07-14 1238352]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Mikael^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^FreeRapid 0.83u1.lnk]

C:\Users\Mikael\DOWNLO~1\FREERA~1.83U\FREERA~1.83U\frd.exe [2009-10-29 35840]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Mikael^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MySurvey Messenger.lnk]

C:\Users\Mikael\AppData\Roaming\MICROS~1\INSTAL~1\{3CFCD~1\ICON3C~1.ICO [2010-03-20 12288]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Mikael^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^YesMessenger.lnk]

C:\PROGRA~1\YESMES~1\YESMES~1.EXE []

 

C:\Users\Mikael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

Dock.lnk - C:\VistaOSX09\RKLauncher.exe

Dropbox.lnk - C:\Users\Mikael\AppData\Roaming\Dropbox\bin\Dropbox.exe

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - C:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll [2009-11-18 70960]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2010-03-25 4222864]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"ConsentPromptBehaviorAdmin"=5

"ConsentPromptBehaviorUser"=3

"EnableUIADesktopToggle"=0

"dontdisplaylastusername"=0

"legalnoticecaption"=

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

"legalnoticetext"=

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"BindDirectlyToPropertySetStorage"=0

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

 

======File associations======

 

.js - edit - C:\Windows\System32\Notepad.exe %1

.js - open - C:\Windows\System32\WScript.exe "%1" %*

.reg - open - "regedit.exe" "%1"

 

======List of files/folders created in the last 1 months======

 

2010-08-18 20:13:44 ----D---- C:\rsit

2010-08-18 09:10:12 ----A---- C:\Windows\system32\drivers\sffp_sd.sys

2010-08-18 03:22:00 ----D---- C:\Windows\system32\Wat

2010-08-18 03:05:40 ----A---- C:\Windows\system32\PresentationHostProxy.dll

2010-08-18 03:05:40 ----A---- C:\Windows\system32\PresentationHost.exe

2010-08-18 03:05:40 ----A---- C:\Windows\system32\netfxperf.dll

2010-08-18 03:05:40 ----A---- C:\Windows\system32\mscoree.dll

2010-08-18 03:05:40 ----A---- C:\Windows\system32\dfshim.dll

2010-08-17 22:23:26 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys

2010-08-17 22:23:24 ----D---- C:\Program Files\Malwarebytes' Anti-Malware

2010-08-17 22:23:24 ----A---- C:\Windows\system32\drivers\mbam.sys

2010-08-17 20:56:02 ----A---- C:\Windows\system32\drivers\tcpip.sys

2010-08-17 20:54:17 ----A---- C:\Ad-Report-CLEAN[1].txt

2010-08-17 20:52:56 ----A---- C:\Windows\system32\ir32_32.dll

2010-08-17 20:52:56 ----A---- C:\Windows\system32\iccvid.dll

2010-08-17 20:52:54 ----A---- C:\Windows\system32\rtutils.dll

2010-08-17 20:52:52 ----A---- C:\Windows\system32\msxml3.dll

2010-08-17 20:52:49 ----A---- C:\Windows\system32\ntdll.dll

2010-08-17 20:52:43 ----A---- C:\Windows\system32\asycfilt.dll

2010-08-17 20:52:41 ----A---- C:\Windows\system32\drivers\srvnet.sys

2010-08-17 20:52:41 ----A---- C:\Windows\system32\drivers\srv2.sys

2010-08-17 20:52:41 ----A---- C:\Windows\system32\drivers\srv.sys

2010-08-17 20:52:39 ----A---- C:\Windows\system32\CPFilters.dll

2010-08-17 20:52:38 ----A---- C:\Windows\system32\msdri.dll

2010-08-17 20:51:59 ----A---- C:\Windows\system32\ntoskrnl.exe

2010-08-17 20:51:59 ----A---- C:\Windows\system32\ntkrnlpa.exe

2010-08-17 20:51:44 ----A---- C:\Windows\system32\mshtml.dll

2010-08-17 20:51:44 ----A---- C:\Windows\system32\ieframe.dll

2010-08-17 20:51:43 ----A---- C:\Windows\system32\wininet.dll

2010-08-17 20:51:43 ----A---- C:\Windows\system32\urlmon.dll

2010-08-17 20:51:43 ----A---- C:\Windows\system32\mstime.dll

2010-08-17 20:51:43 ----A---- C:\Windows\system32\msfeedssync.exe

2010-08-17 20:51:43 ----A---- C:\Windows\system32\msfeedsbs.dll

2010-08-17 20:51:43 ----A---- C:\Windows\system32\jsproxy.dll

2010-08-17 20:51:43 ----A---- C:\Windows\system32\ieui.dll

2010-08-17 20:51:43 ----A---- C:\Windows\system32\iepeers.dll

2010-08-17 20:51:43 ----A---- C:\Windows\system32\iedkcs32.dll

2010-08-17 20:51:03 ----A---- C:\Windows\system32\shell32.dll

2010-08-17 20:50:51 ----A---- C:\Windows\system32\tzres.dll

2010-08-17 20:50:48 ----A---- C:\Windows\system32\schannel.dll

2010-08-17 20:48:07 ----A---- C:\Windows\system32\win32k.sys

2010-08-17 20:48:00 ----A---- C:\Windows\system32\atmlib.dll

2010-08-17 20:48:00 ----A---- C:\Windows\system32\atmfd.dll

2010-08-17 20:41:11 ----A---- C:\Ad-Report-SCAN[1].txt

2010-08-17 20:40:53 ----D---- C:\Program Files\Ad-Remover

2010-08-16 22:14:22 ----A---- C:\TDSSKiller.2.4.1.2_16.08.2010_22.14.22_log.txt

2010-08-15 16:28:36 ----D---- C:\Program Files\iPhInstaller

2010-08-08 17:09:11 ----A---- C:\Windows\system32\drivers\mobiolawave.sys

2010-08-08 17:09:10 ----D---- C:\Program Files\Mobiola Headset for iPhone

2010-08-08 16:27:59 ----D---- C:\Program Files\ZHPDiag

2010-08-08 16:16:58 ----D---- C:\Windows\CheckSur

2010-08-08 16:14:19 ----D---- C:\ProgramData\Windows Genuine Advantage

2010-08-07 18:13:08 ----A---- C:\Windows\system32\HerculesDJDevices.dll

2010-08-07 18:13:05 ----A---- C:\Windows\system32\HRFDongle.dll

2010-08-07 18:13:05 ----A---- C:\Windows\system32\HDJSAPI.dll

2010-08-07 18:13:03 ----A---- C:\Windows\system32\HDJAPI.dll

2010-08-07 18:12:48 ----D---- C:\Program Files\Hercules

2010-08-05 14:06:46 ----D---- C:\Users\Mikael\AppData\Roaming\com.appsfire.afsync.461FBD7549A7A8E31B5EA80B0C5E6DEE8C543914.1

2010-08-05 14:06:42 ----D---- C:\Program Files\Appsfire Sync

2010-08-03 15:58:04 ----D---- C:\Program Files\Common Files\Java

2010-08-03 15:57:46 ----A---- C:\Windows\system32\javaws.exe

2010-08-03 15:57:46 ----A---- C:\Windows\system32\javaw.exe

2010-08-03 15:57:46 ----A---- C:\Windows\system32\java.exe

2010-07-31 15:36:29 ----D---- C:\Program Files\THQ

2010-07-31 14:35:01 ----D---- C:\ProgramData\SEGA Corporation

2010-07-29 13:10:51 ----D---- C:\Program Files\iPod

2010-07-29 13:10:50 ----D---- C:\Program Files\iTunes

2010-07-29 00:50:41 ----D---- C:\Program Files\4Game

2010-07-29 00:44:51 ----D---- C:\Program Files\GStudio7

2010-07-29 00:43:07 ----A---- C:\psapi.dll

2010-07-20 15:22:09 ----D---- C:\Program Files\Planetarium0261

2010-07-20 15:12:48 ----D---- C:\Program Files\WinStars2

2010-07-20 15:06:27 ----D---- C:\Program Files\Solstice

2010-07-19 19:04:00 ----D---- C:\Program Files\planetes3D

2010-07-19 14:11:52 ----D---- C:\Program Files\Magrathea

2010-07-19 14:10:51 ----D---- C:\Program Files\Solar System

2010-07-19 01:42:09 ----D---- C:\Users\Mikael\AppData\Roaming\NASA

2010-07-19 01:41:26 ----D---- C:\Program Files\NASA

 

======List of files/folders modified in the last 1 months======

 

2010-08-18 20:14:03 ----D---- C:\Windows\Temp

2010-08-18 20:13:50 ----D---- C:\Program Files\trend micro

2010-08-18 20:05:19 ----D---- C:\Windows\system32\config

2010-08-18 20:04:13 ----D---- C:\Windows

2010-08-18 20:02:50 ----D---- C:\Users\Mikael\AppData\Roaming\Dropbox

2010-08-18 13:44:52 ----D---- C:\Users\Mikael\AppData\Roaming\FileZilla

2010-08-18 12:54:26 ----HD---- C:\ProgramData

2010-08-18 09:14:32 ----D---- C:\Windows\debug

2010-08-18 09:13:37 ----D---- C:\Windows\winsxs

2010-08-18 09:12:41 ----D---- C:\Program Files\Microsoft Silverlight

2010-08-18 09:11:47 ----D---- C:\Windows\system32\DriverStore

2010-08-18 09:11:46 ----D---- C:\Windows\system32\drivers

2010-08-18 09:11:14 ----SHD---- C:\Windows\Installer

2010-08-18 09:10:17 ----D---- C:\Windows\system32\catroot

2010-08-18 09:10:08 ----SHD---- C:\System Volume Information

2010-08-18 03:35:16 ----D---- C:\Windows\Microsoft.NET

2010-08-18 03:34:49 ----RSD---- C:\Windows\assembly

2010-08-18 03:22:03 ----D---- C:\Windows\System32

2010-08-18 03:22:02 ----D---- C:\Windows\ehome

2010-08-18 03:22:01 ----D---- C:\Windows\system32\migration

2010-08-18 03:22:01 ----D---- C:\Program Files\Internet Explorer

2010-08-18 03:22:00 ----D---- C:\Windows\system32\fr-FR

2010-08-18 03:22:00 ----D---- C:\Windows\AppPatch

2010-08-18 03:06:49 ----D---- C:\ProgramData\Microsoft Help

2010-08-18 03:05:15 ----D---- C:\Program Files\Microsoft Works

2010-08-18 03:01:28 ----D---- C:\Windows\system32\catroot2

2010-08-17 22:23:24 ----RD---- C:\Program Files

2010-08-17 20:56:55 ----D---- C:\Windows\system32\Tasks

2010-08-17 20:56:55 ----D---- C:\Windows\Downloaded Program Files

2010-08-17 20:48:51 ----D---- C:\Users\Mikael\AppData\Roaming\GoodSync

2010-08-16 21:14:24 ----D---- C:\Users\Mikael\AppData\Roaming\moovida-1

2010-08-16 21:08:20 ----D---- C:\Windows\inf

2010-08-16 21:08:20 ----A---- C:\Windows\system32\PerfStringBackup.INI

2010-08-15 20:42:50 ----D---- C:\Users\Mikael\AppData\Roaming\uTorrent

2010-08-15 16:05:30 ----D---- C:\Program Files\FileZilla FTP Client

2010-08-07 18:12:48 ----HD---- C:\Program Files\InstallShield Installation Information

2010-08-07 17:49:37 ----D---- C:\Users\Mikael\AppData\Roaming\InstallShield

2010-08-07 02:09:02 ----D---- C:\Windows\Prefetch

2010-08-07 01:28:45 ----D---- C:\Windows\Minidump

2010-08-05 17:15:19 ----D---- C:\Windows\system32\drivers\etc

2010-08-05 14:06:39 ----D---- C:\Program Files\Adobe

2010-08-05 14:06:37 ----D---- C:\Program Files\Common Files\Adobe AIR

2010-08-05 13:21:14 ----D---- C:\Windows\Tasks

2010-08-04 22:19:06 ----D---- C:\Program Files\Common Files\Services

2010-08-04 17:20:32 ----D---- C:\Windows\SoftwareDistribution

2010-08-03 15:58:04 ----D---- C:\Program Files\Common Files

2010-08-03 15:57:30 ----D---- C:\Program Files\Java

2010-08-03 12:33:59 ----D---- C:\Program Files\Electronic Arts

2010-08-03 12:31:57 ----D---- C:\Program Files\Common Files\InstallShield

2010-08-03 12:31:34 ----D---- C:\Program Files\Google

2010-08-03 12:22:03 ----D---- C:\Program Files\Steam

2010-08-03 11:09:32 ----A---- C:\Windows\system32\MRT.exe

2010-07-31 19:46:28 ----D---- C:\Users\Mikael\AppData\Roaming\DiskAid

2010-07-31 18:13:34 ----D---- C:\bwinPoker

2010-07-31 15:48:27 ----D---- C:\Windows\pss

2010-07-31 15:40:58 ----D---- C:\Windows\system32\en-US

2010-07-31 15:40:57 ----D---- C:\Program Files\Microsoft.NET

2010-07-31 13:39:52 ----D---- C:\Program Files\Common Files\Wise Installation Wizard

2010-07-31 13:39:27 ----D---- C:\Program Files\AGEIA Technologies

2010-07-29 14:47:28 ----D---- C:\Users\Mikael\AppData\Roaming\Mipony

2010-07-29 13:10:50 ----D---- C:\Program Files\Common Files\Apple

2010-07-29 13:04:31 ----D---- C:\Program Files\Safari

2010-07-25 13:16:48 ----D---- C:\ProgramData\DivX

2010-07-25 13:14:30 ----D---- C:\Program Files\DivX

2010-07-25 07:59:20 ----D---- C:\Program Files\Mozilla Firefox

2010-07-22 07:45:36 ----D---- C:\Program Files\Common Files\Steam

2010-07-20 15:13:05 ----RSD---- C:\Windows\Fonts

 

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

 

R0 amdxata;amdxata; C:\Windows\system32\DRIVERS\amdxata.sys [2009-07-14 23616]

R0 CNG;CNG; C:\Windows\System32\Drivers\cng.sys [2009-07-14 369568]

R0 fvevol;@%SystemRoot%\system32\drivers\fvevol.sys,-100; C:\Windows\System32\DRIVERS\fvevol.sys [2009-09-26 194488]

R0 hwpolicy;@%systemroot%\system32\drivers\hwpolicy.sys,-101; C:\Windows\System32\drivers\hwpolicy.sys [2009-07-14 13904]

R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-05 330264]

R0 KSecPkg;KSecPkg; C:\Windows\System32\Drivers\ksecpkg.sys [2009-12-11 133720]

R0 pcw;Performance Counters for Windows Driver; C:\Windows\System32\drivers\pcw.sys [2009-07-14 43088]

R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2010-03-31 44944]

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]

R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-31 13824]

R0 vdrvroot;Pilote d’énumérateur de lecteur virtuel Microsoft; C:\Windows\system32\DRIVERS\vdrvroot.sys [2009-07-14 32832]

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [2009-02-13 11608]

R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]

R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2009-07-14 32256]

R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys [2009-07-14 7168]

R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2009-07-27 58908]

R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]

R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys [2009-07-14 9728]

R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2009-11-07 73312]

R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2009-11-25 56816]

R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]

R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\XAudio32.sys [2008-11-04 8704]

R3 AmdLLD;AMD Low Level Device Driver; C:\Windows\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]

R3 CompositeBus;Pilote de l’énumérateur de bus composite; C:\Windows\system32\DRIVERS\CompositeBus.sys [2009-07-14 31232]

R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-03 21264]

R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]

R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2009-02-13 980992]

R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2009-02-13 207360]

R3 k57nd60x;Broadcom NetLink Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60x.sys [2009-07-14 229888]

R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1; C:\Windows\system32\drivers\libusb0.sys [2005-03-09 33792]

R3 MOBIOLA_Wave;Mobiola Wave Audio Device (WDM); C:\Windows\system32\drivers\mobiolawave.sys [2010-05-14 25024]

R3 netw5v32;Pilote de carte de liaison WiFi sans fil Intel® 5000 Series pour Windows Vista 32 bits; C:\Windows\system32\DRIVERS\netw5v32.sys [2009-07-14 4231168]

R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\Drivers\NTIDrvr.sys [2008-01-31 14848]

R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2009-01-23 52768]

R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-06-04 9752448]

R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2009-07-14 49152]

R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-02-06 205232]

R3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2009-07-14 146176]

R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2009-06-22 1056768]

R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2009-02-13 661504]

R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]

S3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys [2009-07-14 163328]

S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys [2009-07-14 9728]

S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys [2009-07-14 52736]

S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [2009-07-14 79952]

S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312]

S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2009-07-14 50176]

S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbdx.sys [2009-07-14 430080]

S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]

S3 drmkaud;Pilotes audio approuvés par Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2009-07-14 5120]

S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbdx.sys [2009-07-14 3100160]

S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys [2009-07-14 7168]

S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2009-07-14 46160]

S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-06-07 39272]

S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys [2009-07-14 26624]

S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys [2009-07-14 21504]

S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys [2009-07-14 67152]

S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864]

S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584]

S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2009-07-14 4096]

S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2009-07-14 8320]

S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2009-07-14 5888]

S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2009-07-14 5504]

S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2009-07-14 6144]

S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys [2009-07-14 12288]

S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys [2009-07-14 27136]

S3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944]

S3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2009-02-23 62976]

S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2009-07-14 26624]

S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072]

S3 UmPass;Pilote Microsoft UMPass; C:\Windows\system32\DRIVERS\umpass.sys [2009-07-14 8192]

S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2010-04-19 41984]

S3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-07-14 80640]

S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys [2009-07-14 159824]

S3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2009-07-14 19968]

S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]

S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]

S3 xnacc;Contrôleur XBOX 360 pour le service de pilote Windows; C:\Windows\system32\DRIVERS\xnacc.sys [2009-07-14 465408]

 

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

 

R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6; C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]

R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-21 144176]

R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]

R2 CanalPlus.VOD;CanalPlus.VOD; C:\Program Files\Canal+\CANAL+ CANALSAT A LA DEMANDE\VOD\CanalPlus.VOD.exe [2010-07-06 188416]

R2 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2009-07-14 22528]

R2 ePowerSvc;Acer ePower Service; C:\Program Files\Packard Bell\Packard Bell PowerSave Solution\ePowerSvc.exe [2009-08-26 690720]

R2 HsfXAudioService;HsfXAudioService; C:\Windows\system32\svchost.exe [2009-07-14 20992]

R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1; C:\Windows\system32\libusbd-nt.exe [2005-03-09 18944]

R2 LMBApache;Lundi Matin Business Apache; c:\xampplite\srvany.exe [1997-05-14 13312]

R2 LMBMySQL;Lundi Matin Business MySQL; c:\xampplite\srvany.exe [1997-05-14 13312]

R2 Mobiola Wave Service;Mobiola Wave Service; C:\Program Files\Mobiola Headset for iPhone\MobiolaWaveService.exe [2010-07-13 123840]

R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [2009-03-10 44800]

R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-02-10 203296]

R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]

R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]

R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-02-24 242560]

R2 TeamViewer5;TeamViewer 5; C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-04-16 173352]

R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-05-26 1730944]

R3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]

R3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]

R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2010-07-21 540968]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

S2 gupdate1ca4125ddefdc00;Service Google Update (gupdate1ca4125ddefdc00); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-09-29 133104]

S2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2009-07-14 3179520]

S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2010-04-08 72704]

S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]

S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-11-02 655624]

S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-06-07 1424232]

S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-06-29 30192]

S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-12 182768]

S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]

S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]

S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]

S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]

S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]

S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-07-21 407336]

S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2009-07-14 22528]

S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-08-18 1343400]

S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]

S4 wlcrasvc;Windows Live Devices remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-06-04 49504]

 

-----------------EOF-----------------

 

Et le rapport INFO :

 

 

info.txt logfile of random's system information tool 1.08 2010-08-18 20:14:15

 

======Uninstall list======

 

-->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL

-->C:\ProgramData\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe /CONVERTER

-->C:\Windows\UNNeroBackItUp.exe /UNINSTALL

-->C:\Windows\UNNeroMediaHome.exe /UNINSTALL

-->C:\Windows\UNNeroShowTime.exe /UNINSTALL

-->C:\Windows\UNNeroVision.exe /UNINSTALL

-->C:\Windows\UNRecode.exe /UNINSTALL

-->MsiExec /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}

µTorrent-->"C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL

1.1-->"C:\Program Files\iPhInstaller\unins000.exe"

Ace Utilities-->"C:\Program Files\Ace Utilities\uninstall.exe"

ACID Pro 7.0-->MsiExec.exe /X{10B39DCD-0325-49FE-BFBC-8EC011CB7CA8}

Acoustica MP3 Audio Mixer-->C:\PROGRA~1\ACOUST~1\UNWISE.EXE C:\PROGRA~1\ACOUST~1\INSTALL.LOG

Adobe After Effects CS4 Presets-->MsiExec.exe /I{44E240EC-2224-4078-A88B-2CEE0D3016EF}

Adobe After Effects CS4-->C:\Program Files\Common Files\Adobe\Installers\3dcb365ab9e01871fb8c6f27b0ea079\Setup.exe --uninstall=1

Adobe After Effects CS4-->MsiExec.exe /I{45EC816C-0771-4C14-AE6D-72D1B578F4C8}

Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall

Adobe AIR-->MsiExec.exe /I{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}

Adobe Anchor Service CS4-->MsiExec.exe /I{1618734A-3957-4ADD-8199-F973763109A8}

Adobe Bridge 1.0-->MsiExec.exe /I{B74D4E10-6884-0000-0000-000000000101}

Adobe Bridge CS4-->MsiExec.exe /I{83877DB1-8B77-45BC-AB43-2BAC22E093E0}

Adobe CMaps CS4-->MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191}

Adobe Color - Photoshop Specific CS4-->MsiExec.exe /I{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}

Adobe Color EU Extra Settings CS4-->MsiExec.exe /I{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}

Adobe Color JA Extra Settings CS4-->MsiExec.exe /I{0D6013AB-A0C7-41DC-973C-E93129C9A29F}

Adobe Color NA Recommended Settings CS4-->MsiExec.exe /I{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}

Adobe Color Video Profiles AE CS4-->MsiExec.exe /I{B15381DD-FF97-4FCD-A881-ED4DB0975500}

Adobe Color Video Profiles CS CS4-->MsiExec.exe /I{63C24A08-70F3-4C8E-B9FB-9F21A903801D}

Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5102}

Adobe CSI CS4-->MsiExec.exe /I{0F723FC1-7606-4867-866C-CE80AD292DAF}

Adobe Default Language CS4-->MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683}

Adobe Device Central CS4-->MsiExec.exe /I{67F0E67A-8E93-4C2C-B29D-47C48262738A}

Adobe Drive CS4-->MsiExec.exe /I{16E16F01-2E2D-4248-A42F-76261C147B6C}

Adobe Dynamiclink Support-->MsiExec.exe /I{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}

Adobe ExtendScript Toolkit CS4-->MsiExec.exe /I{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}

Adobe Extension Manager CS4-->MsiExec.exe /I{054EFA56-2AC1-48F4-A883-0AB89874B972}

Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe

Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10i_Plugin.exe -maintain plugin

Adobe Fonts All-->MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}

Adobe Help Center 1.0-->MsiExec.exe /I{E9787678-119F-4D52-B551-6739B2B22101}

Adobe Linguistics CS4-->MsiExec.exe /I{931AB7EA-3656-4BB7-864D-022B09E3DD67}

Adobe Media Encoder CS4 Additional Exporter-->MsiExec.exe /I{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}

Adobe Media Encoder CS4-->MsiExec.exe /I{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}

Adobe Media Player-->msiexec /qb /x {39F6E2B4-CFE8-C30A-66E8-489651F0F34C}

Adobe Media Player-->MsiExec.exe /I{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}

Adobe MotionPicture Color Files CS4-->MsiExec.exe /I{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}

Adobe Output Module-->MsiExec.exe /I{BB4E33EC-8181-4685-96F7-8554293DEC6A}

Adobe PDF Library Files CS4-->MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353}

Adobe Photoshop CS2-->msiexec /I {236BB7C4-4419-42FD-040C-1E257A25E34D}

Adobe Photoshop CS4 Support-->MsiExec.exe /I{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}

Adobe Photoshop CS4-->C:\Program Files\Common Files\Adobe\Installers\faf656ef605427ee2f42989c3ad31b8\Setup.exe --uninstall=1

Adobe Photoshop CS4-->MsiExec.exe /I{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}

Adobe Photoshop CS4-->MsiExec.exe /I{E4848436-0345-47E2-B648-8B522FCDA623}

Adobe Photoshop Elements 6.0-->msiexec /I {F54AC413-D2C6-4A24-B324-370C223C6250}

Adobe Premiere Elements 4.0 Templates-->msiexec /I {F85C7118-F3DC-4ED9-AB27-3E7931EA3D88}

Adobe Premiere Elements 4.0 Templates-->MsiExec.exe /I{F85C7118-F3DC-4ED9-AB27-3E7931EA3D88}

Adobe Premiere Elements 4.0-->msiexec /I {3E2C691B-B7E6-4053-B5C3-94B8BC407E7A}

Adobe Premiere Elements 4.0-->MsiExec.exe /I{3E2C691B-B7E6-4053-B5C3-94B8BC407E7A}

Adobe Reader 9.3.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A93000000001}

Adobe Search for Help-->MsiExec.exe /I{F0E64E2E-3A60-40D8-A55D-92F6831875DA}

Adobe Service Manager Extension-->MsiExec.exe /I{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}

Adobe Setup-->MsiExec.exe /I{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}

Adobe Setup-->MsiExec.exe /I{411F3ABA-2AB5-4799-AA19-6ADF0A8F7424}

Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-0C40-4930-9AFE-113BCE553101}

Adobe Type Support CS4-->MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}

Adobe Update Manager CS4-->MsiExec.exe /I{05308C4E-7285-4066-BAE3-6B50DA6ED755}

Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}

Adobe XMP Panels CS4-->MsiExec.exe /I{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}

AdobeColorCommonSetCMYK-->MsiExec.exe /I{68243FF8-83CA-466B-B2B8-9F99DA5479C4}

AdobeColorCommonSetRGB-->MsiExec.exe /I{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}

Ad-Remover By C_XX-->C:\Program Files\Ad-Remover\Uninstall.exe

AI RoboForm (All Users)-->"C:\Program Files\Siber Systems\AI RoboForm\rfwipeout.exe"

Apple Application Support-->MsiExec.exe /I{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}

Apple Mobile Device Support-->MsiExec.exe /I{85991ED2-010C-4930-96FA-52F43C2CE98A}

Apple Software Update-->MsiExec.exe /I{C41300B9-185D-475E-BFEC-39EF732F19B1}

appsFire-->msiexec /qb /x {72E7F17C-0B99-4847-285D-440B96DFC3C5}

appsFire-->MsiExec.exe /I{72E7F17C-0B99-4847-285D-440B96DFC3C5}

ASIO4ALL-->C:\Program Files\ASIO4ALL v2\uninstall.exe

Asynx Planetarium Version 2.61-->"C:\Program Files\Planetarium0261\unins000.exe"

Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"

Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE

Barre d'outils Bing-->C:\Program Files\Bing Bar Installer\InstallManager.exe /UNINSTALL

BetClick Poker-->C:\PROGRA~1\BETCLI~1\UNWISE.EXE C:\PROGRA~1\BETCLI~1\INSTALL.LOG

Bing Bar Platform-->MsiExec.exe /I{07766F89-EFAA-4635-86B7-636B89EA2C0D}

Bonjour-->MsiExec.exe /X{0CB9668D-F979-4F31-B8B8-67FE90F929F8}

Broadcom Gigabit NetLink Controller-->MsiExec.exe /X{9AF0B106-56F1-461B-A270-95BC1682E282}

bwin Poker-->"C:\bwinPoker\unins000.exe"

CANAL+ CANALSAT A LA DEMANDE-->MsiExec.exe /X{04DA096D-6236-4A5D-8FB6-3081E67009BA}

CANAL+ pour Windows Media Center-->MsiExec.exe /X{E2A6B1A0-C1E3-4311-BF86-EAF18841FD67}

CCleaner-->"C:\Program Files\CCleaner\uninst.exe"

Cities XL-->C:\Program Files\Monte Cristo\Cities XL\uninst.exe

Company of Heroes Online (THQ)-->MsiExec.exe /X{0B0CE907-3A71-4CF9-BD13-DA74E63278B2}

Configuration DivX-->C:\ProgramData\DivX\Setup\DivXSetup.exe /uninstall /bundleGroupId divx.com

Connect-->MsiExec.exe /I{B29AD377-CC12-490A-A480-1452337C618D}

CopyTrans Suite désinstallation uniquement-->C:\Program Files\WindSolutions\CopyTrans Suite\CopyTransControlCenter.exe uninstall

CréaStart Auto-entrepreneur 10.0-->"C:\Program Files\CréaStart Auto-entrepreneur 2010\unins000.exe"

CyberLink PowerDVD 8-->"C:\Program Files\InstallShield Installation Information\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\Setup.exe" /z-uninstall

CyberLink PowerDVD 8-->"C:\Program Files\InstallShield Installation Information\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\Setup.exe" /z-uninstall

D3DX10-->MsiExec.exe /X{52CDDA92-56B6-4BA5-BD8D-E13B186008CB}

Definition update for Microsoft Office 2010 (KB982726)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{691FAD36-EC97-46FA-9F96-4CA91C126ECA}" "1036" "0"

DiskAid 4.05-->"C:\Program Files\DigiDNA\DiskAid\unins000.exe"

DivX Converter-->C:\ProgramData\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe /CONVERTER

DivX Plus DirectShow Filters-->C:\ProgramData\DivX\DivX7\DivX Plus DirectShow Filters\DivXDSFiltersUninstall.exe /DSFILTERS

Dual-Core Optimizer-->MsiExec.exe /X{9FD6F1A8-5550-46AF-8509-271DF0E768B5}

EA Download Manager-->C:\Program Files\Electronic Arts\EADM\Uninstall.exe

e-anim701-->C:\Program Files\e-anim701\uninstall.exe

Earth 3D Space Survey Screensaver 1.0-->"C:\Program Files\Earth 3D Space Survey Screensaver\unins000.exe"

eToro-->C:\PROGRA~1\eToro\UNWISE.EXE C:\PROGRA~1\eToro\INSTALL.LOG

Evernote-->MsiExec.exe /X{F761359C-9CED-45AE-9A51-9D6605CD55C4}

Fast Browser Search (My Tattoons)-->regsvr32 /u /s "C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll"

FileZilla Client 3.3.4-->C:\Program Files\FileZilla FTP Client\uninstall.exe

FL Studio 9-->C:\Program Files\Image-Line\FL Studio 9\uninstall.exe

FreeCompressor-->MsiExec.exe /X{8CA0170E-6E9E-43A5-AE1F-85A82820B847}

Galerie de photos Windows Live (bêta)-->MsiExec.exe /X{E672FA05-696F-4B98-ABC3-7A26B024496E}

GoodSync-->"C:\Program Files\Siber Systems\GoodSync\uninstall.exe"

Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall

Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_223E2B8E7BAD9544.exe" /uninstall

Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}

Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

Google Earth-->MsiExec.exe /X{C2D129C0-7508-11DF-9F1B-005056806466}

Hardcore-->C:\Program Files\Image-Line\Hardcore\uninstall.exe

HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDA_HSF\UIU32m.exe -U -IAcrZUn32z.INF

Hercules DJ Products Series drivers-->C:\Program Files\InstallShield Installation Information\{33999F1F-EA46-4E55-A239-1BA803235396}\setup.exe -runfromtemp -l0x040c -removeonly

HiJackThis-->MsiExec.exe /X{45A66726-69BC-466B-A7A4-12FCBA4883D7}

IconPackager-->"C:\ProgramData\{1C533CDB-BAC7-4600-B3DE-0B628D9AC643}\IconPackager.exe" REMOVE=TRUE MODIFY=FALSE

IconPackager-->C:\ProgramData\{1C533CDB-BAC7-4600-B3DE-0B628D9AC643}\IconPackager.exe

Identity Card-->C:\Program Files\Packard Bell\Identity Card\Uninstall.exe

iKlax Creator Pro-->C:\Program Files\iKlax Media\iKlax Creator Pro\iKlaxCreator-uninstaller.exe

IL Download Manager-->C:\Program Files\Image-Line\Downloader\uninstall.exe

Infocenter-->C:\Program Files\Packard Bell\Infocenter\Uninstall.exe

iTunes-->MsiExec.exe /I{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}

Java DB 10.5.3.0-->MsiExec.exe /X{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}

Java 6 Update 21-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216020FF}

Java SE Development Kit 6 Update 20-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160200}

Junk Mail filter update-->MsiExec.exe /I{11EFF057-8ED2-4321-A19D-D673DECB36CC}

kuler-->MsiExec.exe /I{098727E1-775A-4450-B573-3F441F1CA243}

Launch Manager-->C:\Windows\UNINST32.EXE LManager.UNI

LetsTunes-->MsiExec.exe /X{0F4CA3FF-B735-4933-9295-5B5052F63BD2}

LibUSB-Win32-0.1.10.1-->"C:\Program Files\LibUSB-Win32-0.1.10.1\unins000.exe"

LimeWire 5.5.8-->"C:\Program Files\LimeWire\uninstall.exe"

Live 8.0.5-->C:\PROGRA~1\Ableton\LIVE80~1.5\Install\UNWISE.EXE C:\PROGRA~1\Ableton\LIVE80~1.5\Install\INSTALL.LOG

Logiciel d'archivage WinRAR-->C:\Program Files\WinRAR\uninstall.exe

Lundi Matin Business-->"C:\XAMPPLite\uninstall.exe"

Magrathea Online-->MsiExec.exe /I{B5961753-A506-4D40-8574-D38C1E1DD4C4}

Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"

Martin LightJockey version 2.8 build 1-->"C:\Program Files\Martin Professional\Martin LightJockey\unins000.exe"

Mesh Runtime-->MsiExec.exe /I{2C4F4D53-78D6-41FB-A4D7-105C537464EB}

Messenger Companion-->MsiExec.exe /I{314E3413-E1B7-4148-BE2E-F68FE449F033}

MetaBoli-->"C:\Program Files\InstallShield Installation Information\{709817E4-5439-4206-8738-796B34B623BD}\setup.exe" -runfromtemp -l0x040c -removeonly

Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client

Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}

Microsoft Default Manager-->MsiExec.exe /X{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}

Microsoft Office Access MUI (French) 2010-->MsiExec.exe /X{90140000-0015-040C-0000-0000000FF1CE}

Microsoft Office Excel MUI (French) 2010-->MsiExec.exe /X{90140000-0016-040C-0000-0000000FF1CE}

Microsoft Office Groove MUI (French) 2010-->MsiExec.exe /X{90140000-00BA-040C-0000-0000000FF1CE}

Microsoft Office InfoPath MUI (French) 2010-->MsiExec.exe /X{90140000-0044-040C-0000-0000000FF1CE}

Microsoft Office Live Add-in 1.4-->MsiExec.exe /I{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}

Microsoft Office Live Add-in Patches-->MsiExec.exe /I{8DCD7A9A-8B0B-4184-A5D7-C4BDAA31C750}

Microsoft Office OneNote MUI (French) 2010-->MsiExec.exe /X{90140000-00A1-040C-0000-0000000FF1CE}

Microsoft Office Outlook MUI (French) 2010-->MsiExec.exe /X{90140000-001A-040C-0000-0000000FF1CE}

Microsoft Office PowerPoint MUI (French) 2010-->MsiExec.exe /X{90140000-0018-040C-0000-0000000FF1CE}

Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}

Microsoft Office Professional Plus 2010-->MsiExec.exe /X{90140000-0011-0000-0000-0000000FF1CE}

Microsoft Office Professionnel Plus 2010-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL

Microsoft Office Proof (Arabic) 2010-->MsiExec.exe /X{90140000-001F-0401-0000-0000000FF1CE}

Microsoft Office Proof (Dutch) 2010-->MsiExec.exe /X{90140000-001F-0413-0000-0000000FF1CE}

Microsoft Office Proof (English) 2010-->MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}

Microsoft Office Proof (French) 2010-->MsiExec.exe /X{90140000-001F-040C-0000-0000000FF1CE}

Microsoft Office Proof (German) 2010-->MsiExec.exe /X{90140000-001F-0407-0000-0000000FF1CE}

Microsoft Office Proof (Spanish) 2010-->MsiExec.exe /X{90140000-001F-0C0A-0000-0000000FF1CE}

Microsoft Office Proofing (French) 2010-->MsiExec.exe /X{90140000-002C-040C-0000-0000000FF1CE}

Microsoft Office Publisher MUI (French) 2010-->MsiExec.exe /X{90140000-0019-040C-0000-0000000FF1CE}

Microsoft Office Shared MUI (French) 2010-->MsiExec.exe /X{90140000-006E-040C-0000-0000000FF1CE}

Microsoft Office Suite Activation Assistant-->MsiExec.exe /X{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}

Microsoft Office Word MUI (French) 2010-->MsiExec.exe /X{90140000-001B-040C-0000-0000000FF1CE}

Microsoft Outlook Hotmail Connector 32 bits-->MsiExec.exe /X{95140000-0048-040C-0000-0000000FF1CE}

Microsoft Search Enhancement Pack-->MsiExec.exe /X{3F62782D-2798-4540-B493-F6472197900E}

Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}

Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}

Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}

Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319-->MsiExec.exe /X{196BB40D-1578-3D01-B289-BEFC77A11A1E}

Microsoft Works-->MsiExec.exe /I{0214A441-A4AB-43A8-8DEF-2F73C5364673}

Microsoft WorldWide Telescope-->MsiExec.exe /I{227D7616-EDD3-493B-88EF-C84A76A87F43}

Microsoft WorldWide Telescope-->MsiExec.exe /I{E7A9DCC5-8D19-4B95-BED8-2DB41F920F11}

MiPony 1.0.12-->C:\Program Files\MiPony\uninst.exe

mipony-plugin Toolbar-->C:\PROGRA~1\MIPONY~1\UNWISE.EXE /U C:\PROGRA~1\MIPONY~1\INSTALL.LOG

Mise à jour pour Microsoft Outlook Social Connector (KB983403)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001A-040C-0000-0000000FF1CE}" "{FB10D4D0-9CEE-4248-BE08-50B2ECF10497}" "1036" "0"

Mixed In Key 2.5-->C:\Program Files\Mixed In Key\Uninstall.exe

Mobiola Headset for iPhone 1.1.10-->"C:\Program Files\Mobiola Headset for iPhone\unins000.exe"

Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}

Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe

Montpellier Business Plan Classic-->MsiExec.exe /I{EDA1C1F7-F27E-4B20-B9BC-39964452DBB1}

Moonbase Alpha-->"C:\Program Files\Steam\steam.exe" steam://uninstall/39000

Moovida-->C:\Program Files\Fluendo\Moovida\uninstall.exe

Moovida-->MsiExec.exe /X{6084C211-01A1-464E-97A0-09772E122B50}

Mozilla Firefox (3.6.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe

Mp3Doctor PRO-->"C:\Program Files\Mp3DoctorPRO\unins000.exe"

MSVCRT-->MsiExec.exe /I{035C76D2-7D8E-484D-8CA3-686C0B474A2B}

MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}

MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}

MySurvey Messenger International-->MsiExec.exe /X{3CFCDC11-4584-464B-9194-594D6E1CB246}

NASA World Wind 1.4-->"C:\Program Files\NASA\World Wind 1.4\Uninstall_World_Wind_1.4.exe"

Need For Speed World-->"C:\Program Files\Electronic Arts\Need For Speed World\unins000.exe"

Nero 7 Ultra Edition-->MsiExec.exe /X{C944A844-C830-4DB4-803A-496F91A81036}

neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}

NFS World-->"C:\Program Files\Electronic Arts\NFS World\unins000.exe"

Norton Internet Security-->MsiExec.exe /I{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}

NVIDIA Drivers-->C:\Windows\system32\nvuninst.exe UninstallGUI

NVIDIA PhysX-->MsiExec.exe /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}

Nvu 1.0-->"C:\Program Files\Nvu\unins000.exe"

Packard Bell Customer Registration-->C:\Program Files\Packard Bell\Packard Bell Customer Registration\Uninstall.exe

Packard Bell MyBackup-->C:\Program Files\InstallShield Installation Information\{72B776E5-4530-4C4B-9453-751DF87D9D93}\setup.exe -runfromtemp -l0x040c

Packard Bell PowerSave Solution-->"C:\Program Files\InstallShield Installation Information\{3DB0448D-AD82-4923-B305-D001E521A964}\setup.exe" -runfromtemp -l0x040c -removeonly

Packard Bell Recovery Management-->"C:\Program Files\InstallShield Installation Information\{7F811A54-5A09-4579-90E1-C93498E230D9}\setup.exe" -runfromtemp -l0x040c -removeonly

PackardBell ScreenSaver-->C:\Windows\Screensavers\PackardBell\Uninstall.exe

PDF Settings CS4-->MsiExec.exe /I{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}

Photoshop Camera Raw-->MsiExec.exe /I{CC75AB5C-2110-4A7F-AF52-708680D22FE8}

Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"

PicsAid 1.14-->"C:\Program Files\DigiDNA\PicsAid\unins000.exe"

Pioneer CDJ Driver-->C:\Program Files\Pioneer\Pioneer_CDJ\Uninstall_Pioneer_CDJ.exe

Pixel Bender Toolkit-->MsiExec.exe /I{43509E18-076E-40FE-AF38-CA5ED400A5A9}

Planètes 3D version 1.02-->"C:\Program Files\planetes3D\unins000.exe"

PoiZone-->C:\Program Files\Image-Line\PoiZone\uninstall.exe

PowerISO-->"C:\Program Files\PowerISO\uninstall.exe"

Pro Evolution Soccer 2010-->MsiExec.exe /X{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}

QuickTime-->MsiExec.exe /I{3D9892BB-A751-4E48-ADC8-E4289956CE1D}

Realtek USB 2.0 Card Reader-->C:\Program Files\InstallShield Installation Information\{DC24971E-1946-445D-8A82-CE685433FA7D}\Setup.exe -runfromtemp -l0x0009 -removeonly

Reason 4.0-->"C:\Program Files\Propellerhead\Reason\Uninstall Reason\unins000.exe"

rekordbox 1.0.1-->C:\Program Files\Pioneer\rekordbox 1.0.1\Uninstall rekordbox 1.0.1.exe

RocketDock 1.3.5-->"C:\Program Files\RocketDock\unins000.exe"

Safari-->MsiExec.exe /I{EAFEF30E-3789-49C7-A6D9-77C12E005BAC}

Sawer-->C:\Program Files\Image-Line\Sawer\uninstall.exe

SetUpMyPC-->C:\Program Files\Packard Bell\SetUpMyPC\Uninstall.exe

SFR - Kit de connexion-->C:\Program Files\SFR\Kit\uninstall.exe

SFR - Media Center-->C:\Program Files\SFR\Media Center\uninstall.exe

Skype Toolbars-->MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A}

Skype 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}

Solar System 3D Simulator-->"C:\Program Files\Solar System\unins000.exe"

Solstice-->C:\Program Files\Solstice\Uninstall.exe "C:\Program Files\Solstice\install.log"

Sony Noise Reduction Plug-In 2.0e-->MsiExec.exe /X{D533C9D4-ED96-4191-B9C3-279C0DD6BABA}

Sony Sound Forge 9.0-->MsiExec.exe /X{6842DCCB-2840-4E46-8AF3-BEA9CFF3455B}

Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}

Spotify-->"C:\Program Files\Spotify\uninstall.exe"

Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}

Stellarium 0.10.5-->"C:\Program Files\Stellarium\unins000.exe"

StreamTorrent 1.0-->"C:\Program Files\StreamTorrent 1.0\uninstall.exe"

Suite Shared Configuration CS4-->MsiExec.exe /I{842B4B72-9E8F-4962-B3C1-1C422A5C4434}

SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"

Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall

TeamViewer 5-->C:\Program Files\TeamViewer\Version5\uninstall.exe

Toxic Biohazard-->C:\Program Files\Image-Line\Toxic Biohazard\uninstall.exe

Tucan Manager 0.3.6-->"c:\Tucan\unins000.exe"

Uniblue RegistryBooster 2010-->"C:\Program Files\Uniblue\RegistryBooster\unins000.exe"

Unity Web Player-->C:\Program Files\Unity\WebPlayer\Uninstall.exe

Update for Microsoft Office 2010 (KB2202188)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{86B7A074-265D-420C-9E1E-7A920EF0ECA7}" "1036" "0"

Update for Microsoft Outlook Social Connector (KB983403)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{3D462F23-F81B-4740-B4B4-ED2A07E9AC23}" "1036" "0"

Updator-->C:\Program Files\Packard Bell\Updator\Uninstall.exe

Upgrade Kit-->"C:\Program Files\InstallShield Installation Information\{1D0FDD6D-3C5E-4588-8ED0-02DC88014BF2}\setup.exe" -runfromtemp -l0x040c -removeonly

Utilitaire de configuration iPhone-->MsiExec.exe /I{FA54AFB1-5745-4389-B8C1-9F7509672ED1}

VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}

Veetle TV 0.9.17-->C:\Program Files\Veetle\UninstallVeetleTV.exe

Vegas Movie Studio HD 9.0-->MsiExec.exe /X{655CD886-3B90-4E4D-B314-92BDA9B08C86}

VIA Gestionnaire de périphériques de plate-forme-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}

Video Web Camera-->C:\Program Files\InstallShield Installation Information\{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}\setup.exe -runfromtemp -l0x040c -removeonly

Virtual DJ - Atomix Productions-->C:\PROGRA~1\VIRTUA~1\UNWISE.EXE C:\PROGRA~1\VIRTUA~1\INSTALL.LOG

VLC media player 1.0.1-->C:\Program Files\VideoLAN\VLC\uninstall.exe

WahOO-->"C:\Users\Mikael\AppData\Local\WahOO\unins000.exe"

WBFS Manager 3.0-->C:\Program Files\WBFS\WBFS Manager 3.0\uninstall.exe

Widestream6-->MsiExec.exe /X{835525BE-63BD-4EC4-9425-00CEAD4849C2}

Wi-Fi Sync-->"C:\Program Files\Wi-Fi Sync\uninstall.exe"

Windows Installer 3.2 (KB893803)-->MsiExec.exe /I{B86EB5B5-03A2-49D0-B38B-EE847A4C7ECD}

Windows Live Bêta-->C:\Program Files\Windows Live\Installer\wlarp.exe

Windows Live Bêta-->MsiExec.exe /I{231E4621-2428-405D-A7A4-8EB93486BAC7}

Windows Live Communications Platform-->MsiExec.exe /I{FA5D1C9E-154D-49B1-8CF0-DF5FAB6171EA}

Windows Live Family Safety-->MsiExec.exe /I{293493A8-6EF6-4335-8C96-08D2A8E87C73}

Windows Live Family Safety-->MsiExec.exe /X{A5DA9FAD-C016-4B49-8A04-4F2B2BF04A7B}

Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}

Windows Live ID Sign-in Assistant-->MsiExec.exe /I{CCF6B621-7C92-4A45-9A87-F7968D87925A}

Windows Live Installer-->MsiExec.exe /I{46BAF2A0-3789-4E49-B000-4BB64426D1BF}

Windows Live Mail-->MsiExec.exe /I{2607FE6B-1D61-46E5-A544-54666B0EF908}

Windows Live Mail-->MsiExec.exe /I{795851D4-BA00-4965-B2A8-94AA9C7C2789}

Windows Live Messenger Companion Core-->MsiExec.exe /I{9D0467C4-F69C-4E9D-8765-7774D8971F5C}

Windows Live Messenger-->MsiExec.exe /X{2578D94A-A88A-4643-9DAA-F0A5E981EB04}

Windows Live Messenger-->MsiExec.exe /X{8D73EFE7-ED6F-49C6-9685-C712A00F8DDD}

Windows Live MIME IFilter-->MsiExec.exe /I{488A6828-2E74-4517-9E9E-CD50664B0EBE}

Windows Live Movie Maker-->MsiExec.exe /X{46C106C9-3856-4A6A-AAC8-7070FBA02D2F}

Windows Live Movie Maker-->MsiExec.exe /X{B6E6635A-4147-4101-BDF7-FDD7F38281FB}

Windows Live Photo Common Beta-->MsiExec.exe /X{15643FB9-1509-44B2-A8CD-9868CB804A5B}

Windows Live Photo Common-->MsiExec.exe /X{61E7F654-7D99-4C69-94D8-DF53E297AF9B}

Windows Live Photo Gallery-->MsiExec.exe /X{91803386-4FBD-4C38-9644-26B0F9464031}

Windows Live PIMT Platform-->MsiExec.exe /I{B5BD2B33-FDB8-4DE5-87B3-2810CAF4A6E4}

Windows Live Provider for Microsoft Outlook Social Connector 32-bit-->MsiExec.exe /X{95140000-0079-0409-0000-0000000FF1CE}

Windows Live Remote Client Resources-->MsiExec.exe /I{E68CB7D2-E092-4898-94A5-19CF4FEC4E32}

Windows Live Remote Client-->MsiExec.exe /I{98C73E3D-0486-4DD8-938B-EC9B1AF35B9C}

Windows Live Remote Service Resources-->MsiExec.exe /I{91F60D84-7781-4298-9FA4-529C5A5D4371}

Windows Live Remote Service-->MsiExec.exe /I{321AC187-D400-41B4-BDEB-F3E80FFCE20F}

Windows Live SOXE Definitions-->MsiExec.exe /I{74B0BEB0-2EB3-448F-B8E9-40983BC902E1}

Windows Live SOXE-->MsiExec.exe /I{EFBE9DAB-9C80-4911-847B-2A2C25E8F9CB}

Windows Live Sync ActiveX Control for Remote Connections-->MsiExec.exe /I{D65F8E34-C050-4E6C-86DB-D2B9075749A0}

Windows Live Sync Beta-->MsiExec.exe /I{15AFFFD3-0E7E-4F56-B393-F22A2FE1A63D}

Windows Live Sync Beta-->MsiExec.exe /I{7A8E7F22-3628-4846-A578-516BDCB2CEAA}

Windows Live UX Platform Language Pack-->MsiExec.exe /I{59AFDB2C-9A14-404E-8574-B4BDAEFD13CF}

Windows Live UX Platform-->MsiExec.exe /I{6592C2B8-949A-4C88-BCB9-0990A218B215}

Windows Live Writer Resources-->MsiExec.exe /X{62D14F31-92AF-4854-B9C9-C08F7F557F84}

Windows Live Writer-->MsiExec.exe /X{224935E4-2014-4B22-95DC-2CCF5428B4BF}

Windows Live Writer-->MsiExec.exe /X{66AF75C3-39FC-4B6F-A05D-C02E9088194C}

Windows Live Writer-->MsiExec.exe /X{EE338AB8-4E85-4C04-AC07-1357A266DD35}

Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

WinSCP 4.2.4 beta-->"C:\Program Files\WinSCP\unins000.exe"

WinStars 2.0-->"C:\Program Files\WinStars2\unins000.exe"

Xilisoft Créateur Sonnerie iPhone-->C:\Program Files\Xilisoft\iPhone Ringtone Maker\Uninstall.exe

Xvid 1.2.1 final uninstall-->"C:\Program Files\Xvid\unins000.exe"

ZHPDiag 1.26-->"C:\Program Files\ZHPDiag\unins000.exe"

 

======System event log======

 

Computer Name: PC-de-Mikael

Event Code: 1014

Message: La résolution du nom teredo.ipv6.microsoft.com a expiré lorsqu’aucun des serveurs DNS configurés n’a répondu.

Record Number: 109850

Source Name: Microsoft-Windows-DNS-Client

Time Written: 20100504113430.655553-000

Event Type: Avertissement

User: AUTORITE NT\SERVICE RÉSEAU

 

Computer Name: PC-de-Mikael

Event Code: 1014

Message: La résolution du nom img.cdn.betclick.com a expiré lorsqu’aucun des serveurs DNS configurés n’a répondu.

Record Number: 109848

Source Name: Microsoft-Windows-DNS-Client

Time Written: 20100504113429.270474-000

Event Type: Avertissement

User: AUTORITE NT\SERVICE RÉSEAU

 

Computer Name: PC-de-Mikael

Event Code: 11

Message: Les bibliothèques de liens dynamiques sont chargées pour chaque application. L’administrateur système doit vérifier la liste des bibliothèques pour s’assurer qu’elles sont associées à des applications approuvées.

Record Number: 109744

Source Name: Microsoft-Windows-Wininit

Time Written: 20100504101024.294454-000

Event Type: Avertissement

User: AUTORITE NT\Système

 

Computer Name: PC-de-Mikael

Event Code: 4

Message: Broadcom NetLink Gigabit Ethernet : le lien réseau est hors service. Vérifiez que le câble réseau est connecté correctement.

Record Number: 109695

Source Name: k57nd60x

Time Written: 20100504101009.989228-000

Event Type: Avertissement

User:

 

Computer Name: PC-de-Mikael

Event Code: 4001

Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

 

Record Number: 109678

Source Name: Microsoft-Windows-WLAN-AutoConfig

Time Written: 20100504021610.320121-000

Event Type: Avertissement

User: AUTORITE NT\Système

 

=====Application event log=====

 

Computer Name: PC-de-Mikael

Event Code: 3013

Message: Impossible de mettre à jour l’entrée <C:\USERS\MIKAEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\CYBERLINK POWERDVD 8\CYBERLINK POWERDVD 8.LNK> dans la configuration de hachage.

 

Contexte : Application , Catalogue SystemIndex

 

Détails :

Un périphérique attaché au système ne fonctionne pas correctement. (0x8007001f)

 

Record Number: 2666

Source Name: Microsoft-Windows-Search

Time Written: 20091002172527.000000-000

Event Type: Erreur

User:

 

Computer Name: PC-de-Mikael

Event Code: 10

Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.

Record Number: 2632

Source Name: Microsoft-Windows-WMI

Time Written: 20091002172054.000000-000

Event Type: Erreur

User:

 

Computer Name: PC-de-Mikael

Event Code: 3013

Message: Impossible de mettre à jour l’entrée <IEHISTORY://{S-1-5-21-2497042213-80627628-3900218270-1000}/HTTP://FR-FR.FACEBOOK.COM> dans la configuration de hachage.

 

Contexte : Application , Catalogue SystemIndex

 

Détails :

Un périphérique attaché au système ne fonctionne pas correctement. (0x8007001f)

 

Record Number: 2602

Source Name: Microsoft-Windows-Search

Time Written: 20091001190124.000000-000

Event Type: Erreur

User:

 

Computer Name: PC-de-Mikael

Event Code: 3013

Message: Impossible de mettre à jour l’entrée <IEHISTORY://{S-1-5-21-2497042213-80627628-3900218270-1000}/HTTP://FR-FR.FACEBOOK.COM> dans la configuration de hachage.

 

Contexte : Application , Catalogue SystemIndex

 

Détails :

Un périphérique attaché au système ne fonctionne pas correctement. (0x8007001f)

 

Record Number: 2601

Source Name: Microsoft-Windows-Search

Time Written: 20091001190124.000000-000

Event Type: Erreur

User:

 

Computer Name: PC-de-Mikael

Event Code: 10

Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.

Record Number: 2594

Source Name: Microsoft-Windows-WMI

Time Written: 20091001185943.000000-000

Event Type: Erreur

User:

 

=====Security event log=====

 

Computer Name: PC-de-Mikael

Event Code: 4634

Message: Fermeture de session d’un compte.

 

Sujet :

ID de sécurité : S-1-5-7

Nom du compte : ANONYMOUS LOGON

Domaine du compte : AUTORITE NT

ID du compte : 0x2c2496f

 

Type d’ouverture de session : 3

 

Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.

Record Number: 34631

Source Name: Microsoft-Windows-Security-Auditing

Time Written: 20100420064555.406095-000

Event Type: Succès de l’audit

User:

 

Computer Name: PC-de-Mikael

Event Code: 4634

Message: Fermeture de session d’un compte.

 

Sujet :

ID de sécurité : S-1-5-7

Nom du compte : ANONYMOUS LOGON

Domaine du compte : AUTORITE NT

ID du compte : 0x2c248fd

 

Type d’ouverture de session : 3

 

Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.

Record Number: 34630

Source Name: Microsoft-Windows-Security-Auditing

Time Written: 20100420064555.404095-000

Event Type: Succès de l’audit

User:

 

Computer Name: PC-de-Mikael

Event Code: 4624

Message: L’ouverture de session d’un compte s’est correctement déroulée.

 

Sujet :

ID de sécurité : S-1-0-0

Nom du compte : -

Domaine du compte : -

ID d’ouverture de session : 0x0

 

Type d’ouverture de session : 3

 

Nouvelle ouverture de session :

ID de sécurité : S-1-5-7

Nom du compte : ANONYMOUS LOGON

Domaine du compte : AUTORITE NT

ID d’ouverture de session : 0x2c2496f

GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

 

Informations sur le processus :

ID du processus : 0x0

Nom du processus : -

 

Informations sur le réseau :

Nom de la station de travail : PC-DE-AURÉLYMYK

Adresse du réseau source : 192.168.1.63

Port source : 62381

 

Informations détaillées sur l’authentification :

Processus d’ouverture de session : NtLmSsp

Package d’authentification : NTLM

Services en transit : -

Nom du package (NTLM uniquement) : NTLM V1

Longueur de la clé : 128

 

Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

 

Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

 

Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

 

Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

 

Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

 

Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.

- Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .

- Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.

- Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.

- La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.

Record Number: 34629

Source Name: Microsoft-Windows-Security-Auditing

Time Written: 20100420064540.176224-000

Event Type: Succès de l’audit

User:

 

Computer Name: PC-de-Mikael

Event Code: 4624

Message: L’ouverture de session d’un compte s’est correctement déroulée.

 

Sujet :

ID de sécurité : S-1-0-0

Nom du compte : -

Domaine du compte : -

ID d’ouverture de session : 0x0

 

Type d’ouverture de session : 3

 

Nouvelle ouverture de session :

ID de sécurité : S-1-5-7

Nom du compte : ANONYMOUS LOGON

Domaine du compte : AUTORITE NT

ID d’ouverture de session : 0x2c248fd

GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

 

Informations sur le processus :

ID du processus : 0x0

Nom du processus : -

 

Informations sur le réseau :

Nom de la station de travail : PC-DE-AURÉLYMYK

Adresse du réseau source : 192.168.1.63

Port source : 62380

 

Informations détaillées sur l’authentification :

Processus d’ouverture de session : NtLmSsp

Package d’authentification : NTLM

Services en transit : -

Nom du package (NTLM uniquement) : NTLM V1

Longueur de la clé : 128

 

Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

 

Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

 

Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

 

Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

 

Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

 

Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.

- Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .

- Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.

- Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.

- La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.

Record Number: 34628

Source Name: Microsoft-Windows-Security-Auditing

Time Written: 20100420064539.795202-000

Event Type: Succès de l’audit

User:

 

Computer Name: PC-de-Mikael

Event Code: 4634

Message: Fermeture de session d’un compte.

 

Sujet :

ID de sécurité : S-1-5-7

Nom du compte : ANONYMOUS LOGON

Domaine du compte : AUTORITE NT

ID du compte : 0x2bc4d27

 

Type d’ouverture de session : 3

 

Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.

Record Number: 34627

Source Name: Microsoft-Windows-Security-Auditing

Time Written: 20100420063350.119611-000

Event Type: Succès de l’audit

User:

 

======Environment variables======

 

"ComSpec"=%SystemRoot%\system32\cmd.exe

"FP_NO_HOST_CHECK"=NO

"OS"=Windows_NT

"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC

"PROCESSOR_ARCHITECTURE"=x86

"TEMP"=%SystemRoot%\TEMP

"TMP"=%SystemRoot%\TEMP

"USERNAME"=SYSTEM

"windir"=%SystemRoot%

"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\

"NUMBER_OF_PROCESSORS"=2

"PROCESSOR_LEVEL"=6

"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel

"PROCESSOR_REVISION"=170a

"DFSTRACINGON"=FALSE

"Path"=C:\Program Files\Common Files\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Adobe\AGL;C:\Program Files\Common Files\DivX Shared\;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Windows Live\Shared

"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat

"asl.log"=Destination=file;OnFirstLog=command,environment

"CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip

"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

 

-----------------EOF-----------------

Posté(e)

Bonsoir,

 

Je ne crois pas aux miracles informatiques et MBAM dans sa version free ne corrigera rien sans ton intervention.

 

Si tu as obtenu une aide extérieure ou par message privé, je préfère que tu me le dises franchement; cela ne serait pas la première fois que ça arrive.

 

Oui, il serait intéressant de relancer une analyse complète avec MalwareBytes AM et de faire les actions préconisées.

 

Avant de faire cette nouvelle analyse, on va utiliser OTM pour liquider une toolbar qui n'a pas été prise en compte par l'outil spécifique.

 

Télécharge systemsr4.pngOTM de OldTimer sur ton Bureau en cliquant sur ce lien:

 

http://oldtimer.geekstogo.com/OTM.exe

 

 

  • Double-clique sur OTM.exe pour le lancer (l'extension .exe peut ne pas apparaître)
     
    ---> sous VISTA/7: clic droit: exécuter en temps qu'administrateur.
     
  • Copie l'entièreté du code ci-dessous.
    Go
    
    :Files
    
    c:\program files\mipony-plugin
    :Services
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks]
    "{90d46c30-9f25-4104-aea9-35c3f84477ff}"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
    [-HKEY_CLASSES_ROOT\CLSID\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{90d46c30-9f25-4104-aea9-35c3f84477ff}"=-
    
    :Commands
    
    [purity]
    [emptytemp]
    [start explorer]
    
    


     

  • Colle ce code dans la partie jaune de OtMoveIt3 intitulée:
    "Paste Instructions for Items to be Moved"
     
  • Clique sur le bouton Moveit! pour lancer le nettoyage:
     
  • Copie-colle dans ta prochaine réponse tout ce qui se trouve dans la fenêtre Results
    --> Un rapport sera généré dans le dossier C:\ _OTMoveIt\MovedFiles avec la date et l'heure du passage de l'outil (mmddyyyy_hhmmss.log)
  • Ferme OTM en cliquant sur Exit:

Note : Si un fichier ou un dossier ne peut être supprimé directement, l'outil peut demander un redémarrage pour terminer le processus. Clique alors sur "Yes" pour accepter.

 

*** L'outil va terminer son travail après le redémarrage du pc puis fournira son rapport; copie/colle le dans ta réponse stp.

 

OTM.jpg

 

 

Après avoir posté le rapport d'après redémarrage du pc, tu devras faire la mise à jour de MBAM avant de lancer son analyse.

 

@++

Posté(e)

Bonjour,

 

Et bien non depuis que je suis sur ce sujet, je n'ai pas d'aide de qui que ce soit !!!

Je ne voit pas ce qui vous fait penser ca ? lol :)

 

 

Voici donc le rapport :

 

Pour MBAM je le ferai peut être demain soir, car je veut être devant l'ordi pour pouvoir effectuer les manipulations !!!

 

 

All processes killed

Error: Unable to interpret <Go> in the current context!

========== FILES ==========

c:\program files\mipony-plugin folder moved successfully.

========== SERVICES/DRIVERS ==========

========== REGISTRY ==========

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{90d46c30-9f25-4104-aea9-35c3f84477ff} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90d46c30-9f25-4104-aea9-35c3f84477ff}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90d46c30-9f25-4104-aea9-35c3f84477ff}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90d46c30-9f25-4104-aea9-35c3f84477ff}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90d46c30-9f25-4104-aea9-35c3f84477ff}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90d46c30-9f25-4104-aea9-35c3f84477ff}\ not found.

Registry key HKEY_CLASSES_ROOT\CLSID\{90d46c30-9f25-4104-aea9-35c3f84477ff}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90d46c30-9f25-4104-aea9-35c3f84477ff}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90d46c30-9f25-4104-aea9-35c3f84477ff}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90d46c30-9f25-4104-aea9-35c3f84477ff}\ not found.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{90d46c30-9f25-4104-aea9-35c3f84477ff} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90d46c30-9f25-4104-aea9-35c3f84477ff}\ not found.

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: All Users

 

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

->Flash cache emptied: 0 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

 

User: Mcx1-PC-DE-MIKAEL

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

User: Mikael

->Temp folder emptied: 393256 bytes

->Temporary Internet Files folder emptied: 1362431 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 75581505 bytes

->Google Chrome cache emptied: 0 bytes

->Apple Safari cache emptied: 0 bytes

->Flash cache emptied: 635 bytes

 

User: Public

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 2116546 bytes

RecycleBin emptied: 128463069 bytes

 

Total Files Cleaned = 198,00 mb

 

 

OTM by OldTimer - Version 3.1.15.0 log created on 08182010_211121

 

Files moved on Reboot...

C:\Windows\temp\ibB25D.tmp moved successfully.

C:\Windows\temp\ibB25E.tmp moved successfully.

C:\Windows\temp\ibB2AD.tmp moved successfully.

C:\Windows\temp\ibB2FC.tmp moved successfully.

C:\Windows\temp\ibDEBE.tmp moved successfully.

 

Registry entries deleted on Reboot...

Posté(e)

Et bien voila on y est arrivé ... mdr :

 

Voici le rapport MBAM :

 

 

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

 

Version de la base de données: 4440

 

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

 

20/08/2010 01:28:22

mbam-log-2010-08-20 (01-28-22).txt

 

Type d'examen: Examen complet (C:\|)

Elément(s) analysé(s): 523320

Temps écoulé: 5 heure(s), 35 minute(s), 27 seconde(s)

 

Processus mémoire infecté(s): 0

Module(s) mémoire infecté(s): 0

Clé(s) du Registre infectée(s): 0

Valeur(s) du Registre infectée(s): 0

Elément(s) de données du Registre infecté(s): 1

Dossier(s) infecté(s): 0

Fichier(s) infecté(s): 0

 

Processus mémoire infecté(s):

(Aucun élément nuisible détecté)

 

Module(s) mémoire infecté(s):

(Aucun élément nuisible détecté)

 

Clé(s) du Registre infectée(s):

(Aucun élément nuisible détecté)

 

Valeur(s) du Registre infectée(s):

(Aucun élément nuisible détecté)

 

Elément(s) de données du Registre infecté(s):

HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

 

Dossier(s) infecté(s):

(Aucun élément nuisible détecté)

 

Fichier(s) infecté(s):

(Aucun élément nuisible détecté)

Posté(e)

Bonjour,

 

Il faudra vérifier les mises à jour de Windows via Microsoft Update.

 

Fais un nouveau rapport de ZHPDiag.

Héberge-le ici: Cijoint.fr - Service gratuit de dépôt de fichiers

 

Poste le lien obtenu stp.

 

@++

Posté(e) (modifié)

Bonsoir,

 

Je pensais que tu l'avais déjà cet outil.

Il ne faut pas d'identifiants, c'est le serveur de Zébulon qui est indisponible depuis deux jours.

 

Voici un lien direct pour le télécharger: http://www.moncompteur.com/compteurclick.php?idLink=18026

Enregistre-le sur le bureau puis fais la manipulation suivante:

 

ZHPDiag :

  • Double-clique sur ZHPDiag.exe pour lancer l'installation
    • Important:
      Sous Vista et Windows 7 : il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur

N'oublie pas de cocher la case qui permet de mettre un raccourci sur le Bureau.

 

 

[*]L'outil a créé 2 icônes ZHPDiag et ZHPFix sur le Bureau.

 

 

[*]Double-clique sur ZHPDiag pour lancer l'exécution

  • Important:
    Sous Vista et Windows 7 : il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur

 

[*]Clique sur la loupe loupe_10.jpg pour lancer l'analyse. Tu patientes jusqu'à ce que le scan affiche 100%

Tu refermes ZHPDiag

 

 

[*]Le rapport ZHPDiag.txt se trouve sur le Bureau.

Ce rapport étant trop long pour le forum, héberge le :

 

++

Modifié par Apollo
Posté(e)

Il reste de vilaines traces d'infection.

On va utiliser la sulfateuse.

 

ComboFix ne doit pas être utilisé comme un outil de diagnostic, il ne doit être employé que sur demande expresse d'un conseiller formé à cet outil et sous son contrôle. Cet outil peut être dangereux!

 

Désactiver les protections (antivirus, firewall, antispyware).

 

Connecter les supports amovibles (clé usb et autres) avant de procéder.

 

TUTO Officiel

 

Fais un clic droit ICI

  • Dans le menu qui se déroule, choisis "Enregistrer la cible du lien sous" (si tu utilises Firefox) et "Enregistrer la cible sous" (si tu utilises Internet Explorer)
  • Une fenêtre va s'ouvrir: dans le champs Nom du fichier (en bas ), tape ceci plop
     
    exemple: comborenomm2.jpg
     
  • On va enregistrer ce fichier sur le Bureau: pour cela, sur le panneau de gauche, clique sur le Bureau.
     
  • Clique enfin sur le bouton Enregistrer en bas de page à droite.
  • Assure toi que tous les programmes sont fermés avant de lancer le fix!
  • Fait un double clique sur plop.
  • Si la console de récupération n'est pas installée sur un XP, ComboFix va proposer de l'installer: Accepte!
  • Clique sur Oui au message de Limitation de Garantie qui s'affiche.
  • Il est possible que ton parefeu te demande si tu acceptes ou non l'accès de nircmd.cfexe à la zone sure: accepte!
  • Note: Ne ferme pas la fenêtre qui vient de s'ouvrir , tu te retrouverais avec un bureau vide !
  • Lorsque le scan est terminé, un rapport sera généré : poste en le contenu dans ton prochain message.

 

Si tu perds la connexion après le passage de ComboFix, voici comment la réparer ICI.

 

NB: Si malgré tout, tu ne parviens pas à réparer la connexion, lis ce sujet stp.

 

Si le message: "Tentative d'opération non autorisée sur une clé du Registre marquée pour suppression".

apparaissait, redémarrer le pc.

 

sshot-1-9.jpg

 

@++

Posté(e)

ComboFix 10-08-21.06 - Mikael 22/08/2010 13:30:03.1.2 - x86

Microsoft Windows 7 Édition Familiale Premium 6.1.7600.0.1252.33.1036.18.3067.2141 [GMT 2:00]

Lancé depuis: c:\users\Mikael\Desktop\plop.exe

* Un nouveau point de restauration a été créé

.

 

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\users\Mikael\AppData\Roaming\MSA

c:\users\Mikael\AppData\Roaming\SQLite3.dll

c:\users\Mikael\videos\vlc-1.0.5-win32.exe

c:\users\Public\RemoveSGP.exe

 

.

((((((((((((((((((((((((((((( Fichiers créés du 2010-07-22 au 2010-08-22 ))))))))))))))))))))))))))))))))))))

.

 

2010-08-18 19:11 . 2010-08-18 19:11 -------- d-----w- C:\_OTM

2010-08-18 18:13 . 2010-08-18 18:14 -------- d-----w- C:\rsit

2010-08-18 07:10 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys

2010-08-18 01:22 . 2010-08-18 01:22 -------- d-----w- c:\windows\system32\Wat

2010-08-18 01:05 . 2009-11-25 10:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll

2010-08-18 01:05 . 2009-11-25 10:47 49472 ----a-w- c:\windows\system32\netfxperf.dll

2010-08-18 01:05 . 2009-11-25 10:47 297808 ----a-w- c:\windows\system32\mscoree.dll

2010-08-18 01:05 . 2009-11-25 10:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe

2010-08-18 01:05 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\system32\dfshim.dll

2010-08-17 20:23 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-08-17 20:23 . 2010-08-17 20:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-08-17 20:23 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-08-17 18:56 . 2010-06-14 06:12 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys

2010-08-17 18:52 . 2010-07-29 06:30 197632 ----a-w- c:\windows\system32\ir32_32.dll

2010-08-17 18:52 . 2010-07-29 06:30 82944 ----a-w- c:\windows\system32\iccvid.dll

2010-08-17 18:52 . 2010-06-19 06:23 37376 ----a-w- c:\windows\system32\rtutils.dll

2010-08-17 18:52 . 2010-06-08 06:02 1233920 ----a-w- c:\windows\system32\msxml3.dll

2010-08-17 18:52 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll

2010-08-17 18:52 . 2010-03-05 07:42 67584 ----a-w- c:\windows\system32\asycfilt.dll

2010-08-17 18:52 . 2010-06-22 02:47 310784 ----a-w- c:\windows\system32\drivers\srv.sys

2010-08-17 18:52 . 2010-06-22 02:47 307200 ----a-w- c:\windows\system32\drivers\srv2.sys

2010-08-17 18:52 . 2010-06-22 02:47 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys

2010-08-17 18:52 . 2010-05-09 09:14 641536 ----a-w- c:\windows\system32\CPFilters.dll

2010-08-17 18:52 . 2010-05-09 09:14 417792 ----a-w- c:\windows\system32\msdri.dll

2010-08-17 18:50 . 2010-04-23 07:13 2048 ----a-w- c:\windows\system32\tzres.dll

2010-08-17 18:50 . 2010-06-16 05:48 224256 ----a-w- c:\windows\system32\schannel.dll

2010-08-17 18:48 . 2010-06-19 04:07 2326016 ----a-w- c:\windows\system32\win32k.sys

2010-08-17 18:48 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll

2010-08-17 18:48 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll

2010-08-17 18:40 . 2010-08-17 18:56 -------- d-----w- c:\program files\Ad-Remover

2010-08-15 19:09 . 2010-08-11 23:52 85464 ----a-w- c:\users\Mikael\AppData\Roaming\Mozilla\Firefox\Profiles\r89a7u6p.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll

2010-08-15 19:09 . 2010-08-11 23:52 38872 ----a-w- c:\users\Mikael\AppData\Roaming\Mozilla\Firefox\Profiles\r89a7u6p.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINCE\components\WeaveCrypto.dll

2010-08-15 14:28 . 2010-08-15 14:28 -------- d-----w- c:\program files\iPhInstaller

2010-08-08 15:09 . 2010-05-14 13:13 25024 ----a-w- c:\windows\system32\drivers\mobiolawave.sys

2010-08-08 15:09 . 2010-08-08 15:11 -------- d-----w- c:\program files\Mobiola Headset for iPhone

2010-08-08 14:27 . 2010-08-20 19:14 -------- d-----w- c:\program files\ZHPDiag

2010-08-08 14:16 . 2010-08-08 14:16 -------- d-----w- c:\windows\CheckSur

2010-08-07 16:13 . 2010-01-22 12:53 77312 ----a-w- c:\windows\system32\HerculesDJDevices.dll

2010-08-07 16:13 . 2010-01-25 10:36 110592 ----a-w- c:\windows\system32\HRFDongle.dll

2010-08-07 16:13 . 2009-12-04 15:26 73728 ----a-w- c:\windows\system32\HDJSAPI.dll

2010-08-07 16:13 . 2010-01-25 10:36 380928 ----a-w- c:\windows\system32\HDJAPI.dll

2010-08-07 16:12 . 2010-08-07 16:12 -------- d-----w- c:\program files\Hercules

2010-08-05 12:06 . 2010-08-05 12:06 -------- d-----w- c:\users\Mikael\AppData\Roaming\com.appsfire.afsync.461FBD7549A7A8E31B5EA80B0C5E6DEE8C543914.1

2010-08-05 12:06 . 2010-08-05 12:06 -------- d-----w- c:\program files\Appsfire Sync

2010-08-03 16:14 . 2010-08-03 16:28 -------- d-----w- c:\users\Mikael\AppData\Local\ElevatedDiagnostics

2010-08-03 13:58 . 2010-08-03 13:58 -------- d-----w- c:\program files\Common Files\Java

2010-07-31 13:36 . 2010-07-31 13:36 -------- d-----w- c:\program files\THQ

2010-07-31 12:35 . 2010-07-31 12:35 -------- d-----w- c:\programdata\SEGA Corporation

2010-07-29 11:12 . 2010-07-23 15:22 43008 ----a-w- c:\users\Mikael\AppData\Roaming\Mozilla\Firefox\Profiles\r89a7u6p.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll

2010-07-29 11:12 . 2010-07-23 15:22 1496064 ----a-w- c:\users\Mikael\AppData\Roaming\Mozilla\Firefox\Profiles\r89a7u6p.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll

2010-07-29 11:12 . 2010-07-23 15:22 338944 ----a-w- c:\users\Mikael\AppData\Roaming\Mozilla\Firefox\Profiles\r89a7u6p.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll

2010-07-29 11:12 . 2010-07-23 15:22 346112 ----a-w- c:\users\Mikael\AppData\Roaming\Mozilla\Firefox\Profiles\r89a7u6p.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll

2010-07-29 11:10 . 2010-07-29 11:10 -------- d-----w- c:\program files\iPod

2010-07-29 11:10 . 2010-07-29 11:11 -------- d-----w- c:\program files\iTunes

2010-07-29 11:06 . 2010-07-29 11:06 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe

2010-07-29 11:02 . 2010-07-29 11:02 72488 ----a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.17.8\SetupAdmin.exe

2010-07-28 22:50 . 2010-07-28 22:50 -------- d-----w- c:\program files\4Game

2010-07-28 22:44 . 2010-07-28 22:48 -------- d-----w- c:\program files\GStudio7

2010-07-28 22:43 . 2010-07-28 22:44 17408 ----a-w- C:\psapi.dll

2010-07-27 11:30 . 2010-07-27 11:30 -------- d-----w- c:\users\Mikael\AppData\Local\Seesmic

2010-07-25 11:14 . 2010-07-25 11:14 56765 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe

2010-07-25 11:14 . 2010-07-25 11:14 57715 ----a-w- c:\programdata\DivX\Player\Uninstaller.exe

2010-07-25 11:13 . 2010-07-25 11:13 54153 ----a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe

 

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-08-22 11:07 . 2010-07-02 16:13 -------- d-----w- c:\users\Mikael\AppData\Roaming\Dropbox

2010-08-22 03:42 . 2010-01-26 16:45 -------- d-----w- c:\users\Mikael\AppData\Roaming\FileZilla

2010-08-22 00:50 . 2010-07-03 19:36 -------- d-----w- c:\users\Mikael\AppData\Roaming\GoodSync

2010-08-18 18:13 . 2010-06-27 16:31 -------- d-----w- c:\program files\trend micro

2010-08-18 07:12 . 2010-02-23 19:55 -------- d-----w- c:\program files\Microsoft Silverlight

2010-08-18 01:06 . 2009-03-24 17:57 -------- d-----w- c:\programdata\Microsoft Help

2010-08-18 01:05 . 2009-03-24 17:59 -------- d-----w- c:\program files\Microsoft Works

2010-08-16 20:47 . 2009-07-13 23:19 19024 ----a-w- c:\windows\system32\drivers\compbatt.sys

2010-08-16 19:14 . 2010-07-08 14:02 -------- d-----w- c:\users\Mikael\AppData\Roaming\moovida-1

2010-08-16 19:08 . 2009-07-14 08:39 707236 ----a-w- c:\windows\system32\perfh00C.dat

2010-08-16 19:08 . 2009-07-14 08:39 131632 ----a-w- c:\windows\system32\perfc00C.dat

2010-08-15 18:42 . 2009-12-26 03:04 -------- d-----w- c:\users\Mikael\AppData\Roaming\uTorrent

2010-08-15 14:05 . 2010-04-04 02:12 -------- d-----w- c:\program files\FileZilla FTP Client

2010-08-11 18:56 . 2010-03-22 18:52 2724120 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll

2010-08-11 18:56 . 2010-05-19 14:42 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll

2010-08-11 18:56 . 2010-04-01 09:23 639296 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll

2010-08-07 16:12 . 2009-03-04 19:46 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-08-07 15:49 . 2009-09-18 13:52 -------- d-----w- c:\users\Mikael\AppData\Roaming\InstallShield

2010-08-05 12:06 . 2009-11-01 22:08 -------- d-----w- c:\program files\Common Files\Adobe AIR

2010-08-03 13:57 . 2010-02-05 16:30 -------- d-----w- c:\program files\Java

2010-08-03 10:33 . 2009-11-29 15:36 -------- d-----w- c:\program files\Electronic Arts

2010-08-03 10:31 . 2009-08-08 18:26 -------- d-----w- c:\program files\Common Files\InstallShield

2010-08-03 10:31 . 2009-09-11 20:25 -------- d-----w- c:\program files\Google

2010-08-03 10:22 . 2010-07-14 10:59 -------- d-----w- c:\program files\Steam

2010-07-31 17:46 . 2010-04-18 18:00 -------- d-----w- c:\users\Mikael\AppData\Roaming\DiskAid

2010-07-31 13:40 . 2010-06-24 11:49 -------- d-----w- c:\program files\Microsoft.NET

2010-07-31 11:39 . 2010-07-14 12:56 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard

2010-07-31 11:39 . 2010-07-14 12:56 -------- d-----w- c:\program files\AGEIA Technologies

2010-07-29 12:47 . 2010-06-30 08:05 -------- d-----w- c:\users\Mikael\AppData\Roaming\Mipony

2010-07-29 11:10 . 2009-09-12 11:52 -------- d-----w- c:\program files\Common Files\Apple

2010-07-29 11:04 . 2009-09-18 00:00 -------- d-----w- c:\program files\Safari

2010-07-25 11:16 . 2010-05-10 18:47 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll

2010-07-25 11:16 . 2010-05-10 18:27 -------- d-----w- c:\programdata\DivX

2010-07-25 11:14 . 2009-09-29 16:56 -------- d-----w- c:\program files\DivX

2010-07-25 11:13 . 2010-05-10 18:46 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll

2010-07-25 11:13 . 2010-05-10 18:46 895256 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe

2010-07-22 05:45 . 2010-07-14 10:59 -------- d-----w- c:\program files\Common Files\Steam

2010-07-21 05:21 . 2009-12-08 17:28 140784 ----a-w- c:\users\Mikael\AppData\Local\GDIPFONTCACHEV1.DAT

2010-07-20 13:22 . 2010-07-20 13:22 -------- d-----w- c:\program files\Planetarium0261

2010-07-20 13:17 . 2010-07-20 13:12 -------- d-----w- c:\program files\WinStars2

2010-07-20 13:06 . 2010-07-20 13:06 -------- d-----w- c:\program files\Solstice

2010-07-19 17:04 . 2010-07-19 17:04 -------- d-----w- c:\program files\planetes3D

2010-07-19 12:11 . 2010-07-19 12:11 -------- d-----w- c:\program files\Magrathea

2010-07-19 12:10 . 2010-07-19 12:10 -------- d-----w- c:\program files\Solar System

2010-07-18 23:42 . 2010-07-18 23:42 -------- d-----w- c:\users\Mikael\AppData\Roaming\NASA

2010-07-18 23:41 . 2010-07-18 23:41 -------- d-----w- c:\program files\NASA

2010-07-18 19:05 . 2010-07-18 10:18 -------- d-----w- c:\users\Mikael\AppData\Roaming\Stellarium

2010-07-18 10:17 . 2010-07-18 10:17 -------- d-----w- c:\program files\Stellarium

2010-07-17 03:00 . 2010-05-18 13:18 423656 ----a-w- c:\windows\system32\deployJava1.dll

2010-07-16 05:10 . 2010-07-15 14:55 -------- d-----w- c:\users\Mikael\AppData\Roaming\OpenCandy

2010-07-15 14:57 . 2010-07-15 14:57 -------- d-----w- c:\users\Mikael\AppData\Roaming\Uniblue

2010-07-15 14:55 . 2010-07-15 14:55 -------- d-----w- c:\program files\Uniblue

2010-07-15 14:55 . 2010-07-15 14:55 257257 ----a-w- c:\users\Mikael\AppData\Roaming\OpenCandy\DLMgr3WrapperUniBlue.exe

2010-07-14 13:19 . 2010-07-14 13:19 93754 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{227D7616-EDD3-493B-88EF-C84A76A87F43}\_5C5853195D6159163AA431.exe

2010-07-14 13:19 . 2010-07-14 13:19 93754 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{227D7616-EDD3-493B-88EF-C84A76A87F43}\_02B72D2DBA48D018DAC5DA.exe

2010-07-14 13:19 . 2010-07-14 13:19 174298 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{227D7616-EDD3-493B-88EF-C84A76A87F43}\_D707CE1C009F1381803C2C.exe

2010-07-14 13:19 . 2010-07-14 13:19 174298 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{227D7616-EDD3-493B-88EF-C84A76A87F43}\_A0A3DE56B061199EC4C25F.exe

2010-07-14 13:19 . 2010-07-14 13:19 174298 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{227D7616-EDD3-493B-88EF-C84A76A87F43}\_934312A2105DE40686D86A.exe

2010-07-14 13:19 . 2010-07-14 13:19 174298 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{227D7616-EDD3-493B-88EF-C84A76A87F43}\_6FEFF9B68218417F98F549.exe

2010-07-14 13:19 . 2010-07-14 13:19 174298 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{227D7616-EDD3-493B-88EF-C84A76A87F43}\_6A57ABB05E96FB9513040C.exe

2010-07-14 13:19 . 2010-07-14 13:19 174298 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{227D7616-EDD3-493B-88EF-C84A76A87F43}\_21F3885A18D238E15AAE81.exe

2010-07-14 13:10 . 2010-07-14 13:10 174298 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{E7A9DCC5-8D19-4B95-BED8-2DB41F920F11}\_D707CE1C009F1381803C2C.exe

2010-07-14 13:10 . 2010-07-14 13:10 174298 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{E7A9DCC5-8D19-4B95-BED8-2DB41F920F11}\_6FEFF9B68218417F98F549.exe

2010-07-14 13:10 . 2010-07-14 13:10 174298 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{E7A9DCC5-8D19-4B95-BED8-2DB41F920F11}\_21F3885A18D238E15AAE81.exe

2010-07-14 13:10 . 2010-07-14 13:10 -------- d-----w- c:\program files\Microsoft Research

2010-07-14 12:57 . 2010-07-14 12:57 10134 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}\ARPPRODUCTICON.exe

2010-07-14 12:56 . 2010-07-14 12:56 -------- d-----w- c:\program files\AMD

2010-07-13 11:45 . 2010-04-01 09:23 2724120 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll

2010-07-13 11:34 . 2010-05-23 06:10 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll

2010-07-13 11:19 . 2010-07-13 11:19 -------- d-----w- c:\users\Mikael\AppData\Roaming\Windows Live Writer

2010-07-13 10:59 . 2009-03-24 18:24 -------- d-----w- c:\program files\Windows Live

2010-07-13 10:55 . 2010-07-13 10:54 -------- d-----w- c:\program files\Bing Bar Installer

2010-07-13 10:54 . 2010-07-13 10:54 -------- d-----w- c:\program files\MSN Toolbar

2010-07-08 14:01 . 2010-07-08 14:01 110592 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{6084C211-01A1-464E-97A0-09772E122B50}\ARPPRODUCTICON.exe

2010-07-08 14:01 . 2010-07-08 14:01 102400 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{6084C211-01A1-464E-97A0-09772E122B50}\NewShortcut6_206049A8CD534D8B87D5F66190F05AB3.exe

2010-07-08 14:01 . 2010-07-08 14:01 102400 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{6084C211-01A1-464E-97A0-09772E122B50}\NewShortcut5_F4EE65F1A6CD4124B059E9FA9A98EBF7.exe

2010-07-08 14:01 . 2010-07-08 14:01 102400 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{6084C211-01A1-464E-97A0-09772E122B50}\NewShortcut4_A414E067513C43BA8786F3DC788BC961.exe

2010-07-08 14:01 . 2010-07-08 14:01 102400 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{6084C211-01A1-464E-97A0-09772E122B50}\NewShortcut3_BCB4A930B9F04A2480525A437423D92B.exe

2010-07-08 14:01 . 2010-07-08 14:01 102400 ----a-r- c:\users\Mikael\AppData\Roaming\Microsoft\Installer\{6084C211-01A1-464E-97A0-09772E122B50}\NewShortcut2_B4703F8364D440ADB60E472AD5422128.exe

2010-07-08 14:01 . 2010-07-08 14:01 -------- d-----w- c:\program files\Fluendo

2010-07-05 11:54 . 2009-09-11 23:44 -------- d-----w- c:\program files\CCleaner

2010-07-04 13:05 . 2010-05-10 17:33 -------- d-----w- c:\users\Mikael\AppData\Roaming\vlc

2010-07-03 19:36 . 2010-07-03 19:36 -------- d-----w- c:\programdata\GoodSync

2010-07-03 19:36 . 2009-09-12 00:23 -------- d-----w- c:\program files\Siber Systems

2010-07-02 21:45 . 2010-03-22 18:52 639296 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll

2010-07-02 21:27 . 2010-07-02 21:27 -------- d-----w- c:\users\Mikael\AppData\Roaming\Need for Speed World

2010-07-02 21:17 . 2010-07-02 21:17 10691856 ----a-w- c:\programdata\Electronic Arts\Need For Speed World\Data\nfsw.exe

2010-07-02 21:17 . 2010-07-02 21:17 4078864 ----a-w- c:\programdata\Electronic Arts\Need For Speed World\Data\eawebkit.dll

2010-07-02 21:17 . 2010-07-02 21:17 267536 ----a-w- c:\programdata\Electronic Arts\Need For Speed World\Data\gameplay.dll

2010-07-02 21:17 . 2010-07-02 21:17 1791248 ----a-w- c:\programdata\Electronic Arts\Need For Speed World\Data\gameplay.native.dll

2010-07-02 21:17 . 2010-07-02 21:17 3786760 ----a-w- c:\programdata\Electronic Arts\Need For Speed World\Data\d3dx9_37.dll

2010-07-02 21:17 . 2010-07-02 21:17 462864 ----a-w- c:\programdata\Electronic Arts\Need For Speed World\Data\d3dx10_37.dll

2010-07-02 20:44 . 2010-07-02 20:44 883670 ----a-w- c:\programdata\Electronic Arts\Need For Speed World\Data\pb\pbcl.dll

2010-07-02 20:44 . 2010-07-02 20:44 57344 ----a-w- c:\programdata\Electronic Arts\Need For Speed World\Data\pb\pbag.dll

2010-07-02 20:26 . 2009-11-29 16:00 -------- d-----w- c:\programdata\Electronic Arts

2010-07-02 16:13 . 2010-07-02 16:13 89831 ----a-w- c:\users\Mikael\AppData\Roaming\Dropbox\bin\Uninstall.exe

2010-07-02 15:16 . 2010-07-02 15:16 -------- d-----w- c:\users\Mikael\AppData\Roaming\Xilisoft

2010-07-02 15:15 . 2010-07-02 15:15 -------- d-----w- c:\program files\Xilisoft

2010-07-02 15:11 . 2010-07-02 15:11 -------- d-----w- c:\program files\Techlogg.com ToneShop

2010-07-02 14:56 . 2010-07-02 14:46 -------- d-----w- c:\users\Mikael\AppData\Roaming\Spotify

2010-06-29 04:59 . 2010-06-29 04:59 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll

2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat

2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

.

 

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

REGEDIT4

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]

2009-10-15 08:53 165184 ----a-w- c:\program files\SFR\Kit\SFRNavErrorHelper.dll

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]

2010-02-28 00:20 561552 ----a-w- c:\progra~1\MICROS~3\Office14\URLREDIR.DLL

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E2A7BD67-0EAF-497f-B05B-748D7BF3C421}]

2010-06-14 16:56 132256 ----a-w- c:\program files\Fluendo\Moovida\spointer\extensions\moovida_air_ie.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19 94208 ----a-w- c:\users\Mikael\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19 94208 ----a-w- c:\users\Mikael\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2009-12-09 01:19 94208 ----a-w- c:\users\Mikael\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2010-06-23 1699128]

"Connexion SFR 9props.exe"="c:\program files\SFR\Kit\9props.exe" [2009-10-15 959808]

"SmpcSys"="c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe" [2009-03-18 1160736]

"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2009-08-16 955392]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-11 68856]

"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]

"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2010-07-03 160328]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-06 1430824]

"VIAAUD"="c:\program files\VIA\VIAudioi\VDeck\VIAAUD.exe" [2009-06-04 413696]

"Acer ePower Management"="c:\program files\Packard Bell\Packard Bell PowerSave Solution\ePowerTrayLauncher.exe" [2009-08-26 494112]

"BackupManagerTray"="c:\program files\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" [2009-03-09 250624]

"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-04-02 866824]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]

"Wi-Fi Sync"="c:\program files\Wi-Fi Sync\wifisync.exe" [2010-05-27 373248]

"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]

"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]

"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]

"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-07-27 180224]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

 

[HKLM\~\startupfolder\C:^Users^Mikael^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^FreeRapid 0.83u1.lnk]

path=c:\users\Mikael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FreeRapid 0.83u1.lnk

backup=c:\windows\pss\FreeRapid 0.83u1.lnk.Startup

backupExtension=.Startup

 

[HKLM\~\startupfolder\C:^Users^Mikael^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MySurvey Messenger.lnk]

path=c:\users\Mikael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MySurvey Messenger.lnk

backup=c:\windows\pss\MySurvey Messenger.lnk.Startup

backupExtension=.Startup

 

[HKLM\~\startupfolder\C:^Users^Mikael^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^YesMessenger.lnk]

path=c:\users\Mikael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\YesMessenger.lnk

backup=c:\windows\pss\YesMessenger.lnk.Startup

backupExtension=.Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]

2009-11-07 12:24 611712 ----a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]

2010-03-13 12:54 91520 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]

2010-06-29 04:59 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

2010-07-21 13:53 141608 ----a-w- c:\program files\iTunes\iTunesHelper.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]

2010-06-07 15:33 4176760 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2007-03-01 14:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess]

2010-03-16 00:58 718208 ----a-w- c:\program files\Microsoft Office\Office14\MSOSYNC.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

2010-07-14 10:59 1238352 ----a-w- c:\program files\Steam\Steam.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

 

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 gupdate1ca4125ddefdc00;Service Google Update (gupdate1ca4125ddefdc00);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-29 133104]

R2 LMBApache;Lundi Matin Business Apache;c:\xampplite\srvany.exe [1997-05-14 13312]

R2 LMBMySQL;Lundi Matin Business MySQL;c:\xampplite\srvany.exe [1997-05-14 13312]

R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-06-29 30192]

R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]

R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-18 1343400]

R4 wlcrasvc;Windows Live Devices remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-06-04 49504]

S2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]

S2 CanalPlus.VOD;CanalPlus.VOD;c:\program files\Canal+\CANAL+ CANALSAT A LA DEMANDE\VOD\CanalPlus.VOD.exe [2010-07-06 188416]

S2 ePowerSvc;Acer ePower Service;c:\program files\Packard Bell\Packard Bell PowerSave Solution\ePowerSvc.exe [2009-08-26 690720]

S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 20992]

S2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;c:\windows\system32\libusbd-nt.exe [2005-03-09 18944]

S2 Mobiola Wave Service;Mobiola Wave Service;c:\program files\Mobiola Headset for iPhone\MobiolaWaveService.exe [2010-07-13 123840]

S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [2009-03-09 44800]

S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-04-16 173352]

S3 k57nd60x;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]

S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2005-03-09 33792]

S3 MOBIOLA_Wave;Mobiola Wave Audio Device (WDM);c:\windows\system32\drivers\mobiolawave.sys [2010-05-14 25024]

S3 netw5v32;Pilote de carte de liaison WiFi sans fil Intel® 5000 Series pour Windows Vista 32 bits;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]

S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-01-22 52768]

S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-06-22 1056768]

 

 

--- Autres Services/Pilotes en mémoire ---

 

*Deregistered* - aswFsBlk

*Deregistered* - aswMonFlt

*Deregistered* - aswRdr

*Deregistered* - aswSP

*Deregistered* - aswTdi

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HsfXAudioService REG_MULTI_SZ HsfXAudioService

.

Contenu du dossier 'Tâches planifiées'

 

2010-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-29 16:56]

 

2010-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-29 16:56]

.

.

------- Examen supplémentaire -------

.

uInternet Settings,ProxyOverride = *.local

IE: &Envoyer à OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105

IE: Add to &Evernote - c:\program files\Evernote\Evernote3.5\enbar.dll/2000

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: Barre RoboForm - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html

IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000

IE: Enregistrer le formulaire - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

IE: Personnaliser le menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html

IE: Remplir le formulaire - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

IE: Télécharger avec Mipony - file://c:\program files\MiPony\Browser\IEContext.htm

IE: {{0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\Windows Live\Companion\companioncore.dll

IE: {{E0B8C461-F8FB-49b4-8373-FE32E92528A6} - {BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEEE} - c:\program files\Evernote\Evernote3.5\enbar.dll

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab

FF - ProfilePath - c:\users\Mikael\AppData\Roaming\Mozilla\Firefox\Profiles\r89a7u6p.default\

FF - prefs.js: browser.search.defaulturl - hxxp://gb.iamwired.net/websearch.php?src=tops&search=

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://ecosia.org/

FF - prefs.js: keyword.URL - hxxp://gb.iamwired.net/websearch.php?src=tops&search=

FF - component: c:\program files\Fluendo\Moovida\spointer\extensions\moovida@spointer.com\components\moovida_air_ff.dll

FF - component: c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\components\FFGlobalExtension.dll

FF - component: c:\program files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\components\SEPsearchhelperff.dll

FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll

FF - component: c:\program files\MSN Toolbar\Platform\6.0.2156.0\Firefox\components\DomBridge.dll

FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll

FF - component: c:\users\Mikael\AppData\Roaming\Mozilla\Firefox\Profiles\r89a7u6p.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll

FF - component: c:\users\Mikael\AppData\Roaming\Mozilla\Firefox\Profiles\r89a7u6p.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll

FF - component: c:\users\Mikael\AppData\Roaming\Mozilla\Firefox\Profiles\r89a7u6p.default\extensions\{90d46c30-9f25-4104-aea9-35c3f84477ff}\components\FFExternalAlert.dll

FF - component: c:\users\Mikael\AppData\Roaming\Mozilla\Firefox\Profiles\r89a7u6p.default\extensions\{90d46c30-9f25-4104-aea9-35c3f84477ff}\components\RadioWMPCore.dll

FF - plugin: c:\progra~1\MICROS~3\Office14\NPAUTHZ.DLL

FF - plugin: c:\progra~1\MICROS~3\Office14\NPSPWRAP.DLL

FF - plugin: c:\program files\Canal+\CANAL+ CANALSAT A LA DEMANDE\VOD\npCpVod.dll

FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll

FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll

FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

FF - plugin: c:\program files\MSN Toolbar\Platform\6.0.2156.0\npwinext.dll

FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll

FF - plugin: c:\program files\Veetle\Player\npvlc.dll

FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll

FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll

FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: c:\users\Mikael\AppData\Roaming\Mozilla\Firefox\Profiles\r89a7u6p.default\extensions\npfax@microgaming.co.uk\platform\WINNT_x86-msvc\plugins\npfax.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- PARAMETRES FIREFOX ----

FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

- - - - ORPHELINS SUPPRIMES - - - -

 

URLSearchHooks-{90d46c30-9f25-4104-aea9-35c3f84477ff} - (no file)

WebBrowser-{90D46C30-9F25-4104-AEA9-35C3F84477FF} - (no file)

SafeBoot-klmdb.sys

AddRemove-FileZilla Client - c:\program files\FileZilla FTP Client\uninstall.exe

AddRemove-mipony-plugin Toolbar - c:\progra~1\MIPONY~1\UNWISE.EXE

 

 

.

--------------------- CLES DE REGISTRE BLOQUEES ---------------------

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Heure de fin: 2010-08-22 13:45:10

ComboFix-quarantined-files.txt 2010-08-22 11:45

 

Avant-CF: 71 608 250 368 octets libres

Après-CF: 71 380 336 640 octets libres

 

- - End Of File - - 1A6F98F4558892203CF9F98D20903332

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...