J'ai windows vista, ca fait 2-3 fois que quand je suis sur le PC je perd la page ou je suis et il y a une page bleu qui apparait avec pleins d'écritures à première vu ca parle de windows et erreur, la page s'éteint et mon écran devient couleur vert sarcelle avec aucune icones et aucune barre du bas avec le démarré.


Je fais Ctrl + Alt + Delite et je demande de fermer la session, après 2-3 fois comme ca mon PC revient à la normal mais hier soir rien à faire, quand je redémarrais mon PC ca demande le mot de passe et par la suite un écran vert.


Je viens d'ouvrir mon PC et cela a fait la même chose, mais après quelques minutes j'ai eu se message:



erreur dans igfxdeu.dll

entrée manquante: unistall TV Wisard


J'ai cliqué sur OK


Mon PC est redevenu normal avec l'écran avec les icones et elle fonctionne bien




Je dois faire quelques choses, ou si en cliquant ok j'ai réglé le problème?


Merci de me répondre :)

Bonjour tournedos,



  • Démarrer > Accessoires > Invite de commandes > Click Droit sur invite de commandes et tu choisis "exécuter en tant qu'administrateur"
  • Lance l'utilitaire chkdsk en tapant la commande suivante : chkdsk c: /f /r, puis valide par Enter
  • La commande /f corrige automatiquement les erreurs rencontrées
  • La commande /r détecte les "bad sectors" (secteurs endommagés) du disque et récupère les informations qui y sont toujours lisibles
  • Un redémarrage est en général nécessaire afin que chkdsk puisse s'exécuter correctement :
    => redémarre le pc et chkdsk s'exécutera automatiquement
  • Ce scan peut prendre un certain temps selon la taille de ton disque et le nombre de réparation à effectuer
  • Lorsque la vérification est terminée, le PC redémarrera normalement sous Windows


  • Télécharge la version Free de Malwarebytes' Anti-Malware (MBAM) :
  • Tu peux garder ce programme
  • Connecte tous tes supports avant d’effectuer un scan (disque dur ou clé USB, par ex.)
  • Double clique sur le fichier téléchargé pour lancer linstallation
  • Clique sur le bouton « Recherche de mise à jour » situé dans l'onglet « Mise à jour » ; au cas où le pare-feu demande l'autorisation à MBAM de se connecter, accepte
  • Lorsque la mise à jour est finie, rends-toi dans l'onglet « Recherche », sélectionne « Exécuter un examen complet » et clique sur « Rechercher »
  • Ceci va déclencher le démarrage de l'analyse (qui peut être longue).
  • A la fin de l'analyse, un message s'affiche :
    L'examen s'est terminé normalement. Cliquer sur « Afficher les résultats » pour afficher tous les objets trouvés.
  • Clique sur « OK » pour continuer. Si MBAM n'a rien trouvé, il te préviendra également
  • Ferme tes navigateurs
  • Si MBAM a trouvé des malwares, clique sur « Afficher les résultats »
  • Coche l’ensemble, ou laisse coché, puis clique sur « Supprimer la sélection » : MBAM va alors détruire les fichiers et clés de registre et en placer une copie dans la quarantaine
  • En parallèle, MBAM ouvre le Bloc-notes et y copie le rapport d'analyse
    --> Copie/colle ce rapport et poste-le dans ta prochaine réponse stp

Bon après-midi,


Bonjour, merci de m'avoir répondu si rapidement


1- j'ai fat ce que tu m'a demandé ca inscrit:


- Le type du système de fichiers est NTFS


- CHKDSK ne peut pas s'executer parce que le volume est utilisé par un autre processus.


- Voulez-vous que le volume soit vérifié au prochain redémarrage du système? (O/N) j'écris O


- Ce volume sera vérifié au prochain redémarrage du système.


- Quans je redémarre le PC, il apparait un messafe de 4 lignes mais j'ai pas le temps de le lire ca va trop vite ca dure 1 seconde, puis le PC s'allume normalement. Y a-t-il un moyen pour que je puisse voir le message ou si c'est correct comme cela.


2- J'avais déjà Malwarebytes' Anti-Malware, je fais le test à toutes les semaines, je l'ai fait aujourd'hui et il y a rien.


Mercdi, j'attend votre réponse :)

Re, ;)


On va regarder plus en détails :


  • Télécharge ZHPDiag de Nicolas Coolman :
  • Enregistre le sur ton bureau
    - Sous XP : double-clique sur l'icône
    - Sous Vista ou Windows 7 : clique droit sur l’icône puis « exécuter en tant quadministrateur »
  • Suis les instructions à l'écran
  • Clique sur l'icône LOUPE pour lancer l'analyse
  • Clique sur l'icône APPAREIL PHOTO pour copier le rapport, puis colle-le dans ta prochaine réponse
  • Tu peux également trouver le rapport sous C:\Program Files\ZebHelpProcess\ZHPDiag.txt



alors voici le résultat du test:



Rapport de ZHPDiag v1.27.18 par Nicolas Coolman, Update du 19/03/2011

Run by mimi at 2011-03-20 15:54:18

Web site : ZHPDiag Outil de diagnostic

Contact :



---\\ Web Browser

MSIE: Internet Explorer v8.0.6001.19019 (Defaut)


---\\ System Information

Windows Vista Home Premium Edition, 32-bit Service Pack 2 (Build 6002)

Processor: x86 Family 6 Model 15 Stepping 13, GenuineIntel

Operating System: 32 Bits

Boot mode: Normal (Normal boot)

Total RAM: 1012 MB (18% free)

System Restore: Activé (Enable)

System drive C: has 217 GB (75%) free of 289 GB


---\\ Logged in mode

Computer Name: PC-DE-MIMI

User Name: mimi

All Users Names: mimi, Administrateur,

Unselected Option: O45,O61,O62,O65,O66,O82

Logged in as Administrator


---\\ Environnement Variables



%StartMenu%=C:\Users\mimi\AppData\Roaming\Microsoft\Windows\Start Menu


---\\ DOS/Devices

C:\ Hard drive, Flash drive, Thumb drive (Free 217 Go of 289 Go)

D:\ Hard drive, Flash drive, Thumb drive (Free 2 Go of 9 Go)

E:\ CD-ROM drive (Not Inserted)




---\\ Security Center & Tools Informations

[HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: Modified

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK




---\\ Recherche particulière de fichiers génériques

[MD5.D07D4C3038F3578FFCE1C0237F2A1253] - (.Microsoft Corporation - Explorateur Windows.) (.2009-04-11 01:27:36.) -- C:\Windows\Explorer.exe [2926592]

[MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de démarrage de Windows.) (.2008-01-20 21:23:42.) -- C:\Windows\System32\Wininit.exe [96768]

[MD5.74BCC23D622F32DA0450D164735ACAB1] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.2010-12-18 01:27:04.) -- C:\Windows\System32\wininet.dll [916480]

[MD5.898E7C06A350D4A1A64A9EA264D55452] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.2009-04-11 01:28:13.) -- C:\Windows\System32\Winlogon.exe [314368]

[MD5.1F05B78AB91C9075565A9D8A4B880BC4] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.2009-04-11 01:32:26.) -- C:\Windows\System32\drivers\atapi.sys [19944]

[MD5.6A4A98CEE84CF9E99564510DDA4BAA47] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.2009-04-11 01:32:49.) -- C:\Windows\System32\drivers\ntfs.sys [1083880]




---\\ Processus lancés

[MD5.0D392EDE3B97E0B3131B2F63EF1DB94E] - (.Microsoft Corporation - Windows Defender User Interface.) -- C:\Program Files\Windows Defender\MSASCui.exe [1008184]

[MD5.D93985F5D87DF1A119E939EADB5C4B9E] - (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Windows\RtHDVCpl.exe [6266880]

[MD5.9A4322EE420D6FACD4D4B1FF6CB856B1] - (.Hewlett-Packard Company - hpsysdrv.) -- C:\hp\support\hpsysdrv.exe [65536]

[MD5.B1361669BDC6ED612C35B7C67ADA2240] - (.OsdMaestro - OsdMaestro main program.) -- C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [118784]

[MD5.C68BD48274B8C6E4401CF9F71A0CA4BD] - (...) -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [565008]

[MD5.3F212472FDBA7ACF3A68C8B05D6B38D2] - (.Vidéotron - Agent de services Vidéotron.) -- C:\Program Files\Videotron\Videotron Service Agent\VideotronSA.exe [3376368]

[MD5.2E9A1A6555C20424FC6DCC3AF21F4D68] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe [3451496]

[MD5.2E5212A0BFB98FE0167C92C76C87AFE3] - (.Sun Microsystems, Inc. - Java Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [249064]

[MD5.409E5B10053382C9D339BAEAA6584999] - (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe [166424]

[MD5.B76195C8E8845FF2A8FA658709345DE2] - (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe [133656]

[MD5.BF08674925F151BD4537B89A493E3E0C] - (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehtray.exe [125952]

[MD5.EF4EE38DEF63166D8C2B369FD03029E3] - (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe [160592]

[MD5.CF03C8F6F6B0D71F6E5BCE167FCF7CA6] - (.Hewlett-Packard Co. - HP Digital Imaging Monitor.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [214360]

[MD5.1CF370D5C495F52DB8B83346BDF3AE7C] - (.Intel Corporation - igfxsrvc Module.) -- C:\Windows\system32\igfxsrvc.exe [256536]

[MD5.38440FE1A65B1FE3D246C5C4CAD22F53] - (.Logitech Inc. - Logitech Video COM Service.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe [186904]

[MD5.8A96CEAF576F92E3D9C47ADDAE85DF78] - ( - Webshots Photo Manager.) -- C:\PROGRA~1\Webshots\Webshots.scr [3446088]

[MD5.0F4195B9B348DE5CF9B822F81704B20E] - (.Microsoft Corporation - Media Center Media Status Aggregator Servic.) -- C:\Windows\ehome\ehmsas.exe [37376]

[MD5.B988D7F127B94BD5BF8356FE81B985C4] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [638232]

[MD5.80B8AE8E18FF57BE13FF4A5959DB0EC1] - (.Hewlett-Packard Co. - HP CUE Status Root.) -- C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe [184320]

[MD5.F0898E9BD7C914FB7389F393D189B32F] - (.Hewlett-Packard Co. - HP CUE Alert Popup Window Objects.) -- C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe [569344]

[MD5.711FD53E441255983C0AB014E2F107F4] - (.Adobe Systems, Inc. - Adobe® Flash® Player Installer/Uninstaller.) -- C:\Windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe [233936]

[MD5.6080A176D09435FC8E6E800996656E18] - (.Microsoft Corporation - Console IME.) -- C:\Windows\system32\conime.exe [69120]

[MD5.745C54B66C61E9B52318D329D62708DD] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [658432]




---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)

P2 - FPN: [HKLM] [] - (.Pas de propriétaire - Pas de description.) -- C:\Windows\system32\Macromed\Flash\NPSWF32.dll

P2 - FPN: [HKLM] [] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_24 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

P2 - FPN: [HKLM] [,version=1.0] - (. Microsoft Corporation - 4.0.60129.0.) -- c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll

P2 - FPN: [HKLM] [,version=1.5] - (.Microsoft Corp. - Office Live Update v1.5.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll

P2 - FPN: [HKLM] [,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

P2 - FPN: [HKLM] [,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

P2 - FPN: [HKLM] [,version=1] - (.Vidéotron - Pas de description.) -- C:\Program Files\Videotron\Videotron Service Agent\nprpspa.dll

P2 - FPN: [HKLM] [ Update;version=8] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\\npGoogleOneClick8.dll




---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Browzad

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKUS\S-1-5-21-2164166307-1310619440-4161934922-1000\Software\Microsoft\Internet Explorer\Main,Start Page = Browzad

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Microsoft Corporation

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Search

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Search

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = Bing

R1 - HKUS\S-1-5-21-2164166307-1310619440-4161934922-1000\Software\Microsoft\Internet Explorer\Main,Search Page = Microsoft Corporation

R3 - URLSearchHook: agihelper.AGUtils - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) (4.0.31106.0 (Main.031106-0000)) -- mscoree.dll

R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 1




---\\ Internet Explorer, Proxy Management (R5)

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1

R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1

R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll




---\\ ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)

F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,

F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"




---\\ Browser Helper Objects de navigateur (O2)

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} Clé orpheline

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: agihelper.AGUtils - {0bc6e3fa-78ef-4886-842c-5a1258c4455a} . (...) -- mscoree.dll (.not file.)

O2 - BHO: IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Clé orpheline

O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} Clé orpheline

O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files\Siber Systems\AI RoboForm\roboform.dll

O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll




---\\ Internet Explorer Toolbars (O3)

O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} . (.Pas de propriétaire - Pas de description.) -- (.not file.)

O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files\Siber Systems\AI RoboForm\roboform.dll




---\\ ---\\ Applications démarrées par registre & par dossier (O4)

O4 - HKLM\..\Run: [Windows Defender] . (.Microsoft Corporation - Windows Defender User Interface.) -- C:\Program Files\Windows Defender\MSASCui.exe

O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Windows\RtHDVCpl.exe

O4 - HKLM\..\Run: [hpsysdrv] . (.Hewlett-Packard Company - hpsysdrv.) -- c:\hp\support\hpsysdrv.exe

O4 - HKLM\..\Run: [OsdMaestro] . (.OsdMaestro - OsdMaestro main program.) -- C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe

O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM\..\Run: [LogitechCommunicationsManager] . (...) -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

O4 - HKLM\..\Run: [VideotronSA.exe] . (.Vidéotron - Agent de services Vidéotron.) -- C:\Program Files\Videotron\Videotron Service Agent\VideotronSA.exe

O4 - HKLM\..\Run: [avast5] . (.AVAST Software - avast! Antivirus.) -- C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe

O4 - HKLM\..\Run: [HP Software Update] . (.Hewlett-Packard Co. - Hewlett-Packard Product Assistant.) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe

O4 - HKLM\..\Run: [EoWeather] Clé orpheline

O4 - HKLM\..\Run: [sunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe

O4 - HKLM\..\Run: [igfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe

O4 - HKCU\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [RoboForm] . (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] oobefldr.dll

O4 - HKUS\S-1-5-20\..\Run: [sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe

O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] oobefldr.dll

O4 - HKUS\S-1-5-21-2164166307-1310619440-4161934922-1000\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe

O4 - HKUS\S-1-5-21-2164166307-1310619440-4161934922-1000\..\Run: [RoboForm] . (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe

O4 - Global Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk . (.Hewlett-Packard Co..) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: C:\Users\mimi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Webshots.lnk . ( -- C:\Program Files\Webshots\Launcher.exe




---\\ ---\\ Autres liens utilisateurs (O4)

O4 - Global Startup: C:\Users\mimi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite Deluxe.lnk . (.CyberLink.) -- C:\Program Files\CyberLink\DVD Suite Deluxe\PowerStarter.exe

O4 - Global Startup: C:\Users\mimi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe

O4 - Global Startup: C:\Users\mimi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Mail\WinMail.exe

O4 - Global Startup: C:\Users\mimi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe

O4 - Global Startup: C:\Users\mimi\Desktop\CCleaner.lnk . (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe

O4 - Global Startup: C:\Users\mimi\Desktop\Courrier.lnk - Clé orpheline

O4 - Global Startup: C:\Users\mimi\Desktop\Documents.lnk . (...) -- C:\Users\mimi\Documents

O4 - Global Startup: C:\Users\mimi\Desktop\Favoris.lnk . (...) -- C:\Users\mimi\Favorites

O4 - Global Startup: C:\Users\mimi\Desktop\Internet.lnk - Clé orpheline

O4 - Global Startup: C:\Users\mimi\Desktop\Messenger.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe

O4 - Global Startup: C:\Users\mimi\Desktop\Microsoft Office Word 2007.lnk . (...) -- C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe

O4 - Global Startup: C:\Users\mimi\Desktop\Webshots Desktop.lnk . ( -- C:\Program Files\Webshots\Launcher.exe

O4 - Global Startup: C:\Users\mimi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Courrier.lnk - Clé orpheline

O4 - Global Startup: C:\Users\mimi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Jouer à Mes jeux.lnk . (...) -- C:\Program Files\bfgclient\bfgclient.exe

O4 - Global Startup: C:\Users\mimi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Run.lnk - Clé orpheline

O4 - Global Startup: C:\Users\mimi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe




---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)

O8 - Extra context menu item: Barre RoboForm - (.not file.) - file:\\C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html

O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~3\Office12\EXCEL.exe

O8 - Extra context menu item: Enregistrer le formulaire - (.not file.) - file:\\C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

O8 - Extra context menu item: Google Sidewiki... - (.not file.) - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll

O8 - Extra context menu item: Personnaliser le menu - (.not file.) - file:\\C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html

O8 - Extra context menu item: Remplir le formulaire - (.not file.) - file:\\C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html




---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)

O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBro

O9 - Extra button: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft Office OneNote Internet Explorer Add-in.) -- C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files\Siber Systems\AI RoboForm\roboform.dll

O9 - Extra button: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files\Siber Systems\AI RoboForm\roboform.dll

O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} . (.Siber Systems Inc. - RoboForm Main Module.) -- C:\Program Files\Siber Systems\AI RoboForm\roboform.dll

O9 - Extra button: Barre RoboForm - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~1\MICROS~3\Office12\REFBARH.ICO




---\\ Winsock hijacker (Layered Service Provider) (O10)

O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll

O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll

O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll

O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll

O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll

O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll

O10 - WLSP:\000000000007\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll




---\\ Objets ActiveX (Downloaded Program Files)(O16)

O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () -

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} () -




---\\ Modification Domaine/Adresses DNS (O17)

O17 - HKLM\System\CCS\Services\Tcpip\..\{335E3D66-E7C5-4D4C-98C6-416C35AE4FA5}: DhcpNameServer =

O17 - HKLM\System\CS1\Services\Tcpip\..\{335E3D66-E7C5-4D4C-98C6-416C35AE4FA5}: DhcpNameServer =

O17 - HKLM\System\CS2\Services\Tcpip\..\{335E3D66-E7C5-4D4C-98C6-416C35AE4FA5}: DhcpNameServer =

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =




---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)

O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll




---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)

O20 - AppInit_DLLs: . (.AVG Technologies CZ, s.r.o. - AVG Resident Shield Starter.) - C:\Windows\System32\avgrsstx.dll




---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Contrôleur de site Web.) -- C:\Windows\System32\webcheck.dll




---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)

O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\system32\browseui.dll




---\\ Liste des services NT non Microsoft et non désactivés (O23)

O23 - Service: (AGCoreService) . (.AG Interactive - AGCoreService.) - C:\Program Files\AGI\core\\AGCoreService.exe

O23 - Service: (AGWinService) - Clé orpheline

O23 - Service: (Apple Mobile Device) . (.Apple, Inc. - Apple Mobile Device Service.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: (avg8emc) - Clé orpheline

O23 - Service: (avg8wd) - Clé orpheline

O23 - Service: (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: (HP Health Check Service) . (.Hewlett-Packard - HP Health Check Service.) - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

O23 - Service: (LightScribeService) . (.Hewlett-Packard Company - LightScribe Service.) - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: (LVCOMSer) . (.Logitech Inc. - Logitech Video COM Service.) - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

O23 - Service: (LVPrcSrv) . (.Logitech Inc. - Logitech LVPrcSrv Module..) - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

O23 - Service: (PCD5SRVC{BD6912E3-AC9D80E8-05040000}) - Clé orpheline

O23 - Service: (ServicepointService) . (.Radialpoint Inc. - Pas de description.) - C:\Program Files\Videotron\Videotron Service Agent\ServicepointService.exe

O23 - Service: (wlidsvc) . (.Microsoft Corp. - Microsoft® Windows Live ID Service.) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.exe

O23 - Service: (XAudioService) . (.Conexant Systems, Inc. - Modem Audio Service.) - C:\Windows\system32\DRIVERS\xaudio.exe




---\\ Enumération Active Desktop & MHTML Editor (O24)

O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Office Word.) - C:\Program Files\Microsoft Office\Office12\WINWORD.exe




---\\ Tâches planifiées en automatique (O39)

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Ad-Aware Update (Weekly).job

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\EasyShare Registration Task.job

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\HPCeeScheduleFormimi.job

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\User_Feed_Synchronization-{48152027-D49C-4742-A93F-27B7EBA78948}.job

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\WebReg Deskjet F4100 series.job

[MD5.00000000000000000000000000000000] [APT] [Ad-Aware Update (Weekly)] (.Pas de propriétaire.) -- (.not file.)

[MD5.00000000000000000000000000000000] [APT] [GoogleUpdateTaskMachineCore] (.Pas de propriétaire.) -- (.not file.)

[MD5.00000000000000000000000000000000] [APT] [GoogleUpdateTaskMachineUA] (.Pas de propriétaire.) -- (.not file.)

[MD5.00000000000000000000000000000000] [APT] [HPCeeScheduleFormimi] (.Pas de propriétaire.) -- (.not file.)

[MD5.00000000000000000000000000000000] [APT] [Run RoboForm TaskBar Icon] (.Pas de propriétaire.) -- (.not file.)

[MD5.00000000000000000000000000000000] [APT] [WebReg Deskjet F4100 series] (.Pas de propriétaire.) -- (.not file.)

[MD5.00000000000000000000000000000000] [APT] [{9C88BA63-6AF0-4B54-93FF-336886DB3D7E}] (.Pas de propriétaire.) -- C:\Users\mimi\AppData\Local\Temp\Temp1_Standard_Monitor_Driver_Signed_Vista_x64_070717[1].zip\Standard_Monitor_Driver_Signed_Vista_x64_070717

[MD5.00000000000000000000000000000000] [APT] [{C0F42BB1-69D5-4B89-8476-D0D804D132CE}] (.Pas de propriétaire.) -- (.not file.)

[MD5.00000000000000000000000000000000] [APT] [AppleSoftwareUpdate] (.Pas de propriétaire.) -- (.not file.)

[MD5.00000000000000000000000000000000] [APT] [Reminders - mimi] (.Pas de propriétaire.) -- (.not file.)

[MD5.00000000000000000000000000000000] [APT] [MP Scheduled Scan] (.Pas de propriétaire.) -- (.not file.)

[MD5.00000000000000000000000000000000] [APT] [scheduled Maintenance] (.Pas de propriétaire.) -- (.not file.)

[MD5.00000000000000000000000000000000] [APT] [scheduled Maintenance Swap] (.Pas de propriétaire.) -- (.not file.)




---\\ Pilotes lancés au démarrage (O41)

O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys

O41 - Driver: (AvgLdx86) . (.AVG Technologies CZ, s.r.o. - AVG AVI Loader Driver.) - C:\Windows\system32\Drivers\avgldx86.sys

O41 - Driver: (AvgMfx86) . (.AVG Technologies CZ, s.r.o. - AVG Resident Shield Minifilter Driver.) - C:\Windows\system32\Drivers\avgmfx86.sys

O41 - Driver: (AvgTdiX) . (.AVG Technologies CZ, s.r.o. - AVG Network connection watcher.) - C:\Windows\system32\Drivers\avgtdix.sys

O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys

O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys

O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\System32\DRIVERS\i8042prt.sys

O41 - Driver: (kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\System32\DRIVERS\kbdclass.sys

O41 - Driver: (mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\System32\DRIVERS\mouclass.sys

O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys

O41 - Driver: (netbt) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys

O41 - Driver: (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys

O41 - Driver: C:\Windows\system32\drivers\pacer.sys (PSched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys

O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\System32\DRIVERS\rasacd.sys

O41 - Driver: (rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\System32\DRIVERS\rdbss.sys

O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys

O41 - Driver: (RDPENCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys

O41 - Driver: C:\Windows\system32\tcpipcfg.dll (Smb) . (.Microsoft Corporation - SMB Transport driver.) - C:\Windows\System32\DRIVERS\smb.sys

O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys

O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys

O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys

O41 - Driver: (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys




---\\ Logiciels installés (O42)

O42 - Logiciel: 32 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM] -- {2614F54E-A828-49FA-93BA-45A3F756BFAA}

O42 - Logiciel: AI RoboForm (All Users) - (.Pas de propriétaire.) [HKLM] -- AI RoboForm

O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX

O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin

O42 - Logiciel: Adobe Reader 8.1.3 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A81300000003}

O42 - Logiciel: Agent de services Vidéotron 3.0.21 - (.Vidéotron.) [HKLM] -- RadialpointClientGateway_is1

O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {DAEAFD68-BB4A-4507-A241-C8804D2EA66D}

O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {44734179-8A79-4DEE-BB08-73037F065543}

O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {6956856F-B6B3-4BE0-BA0B-8F495BE32033}

O42 - Logiciel: Big Fish Games Client - (.Pas de propriétaire.) [HKLM] -- BFGC

O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {07287123-B8AC-41CE-8346-3D777245C35B}

O42 - Logiciel: CCScore - (.EASTMAN KODAK Company.) [HKLM] -- {B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}

O42 - Logiciel: CCleaner (remove only) - (.Pas de propriétaire.) [HKLM] -- CCleaner

O42 - Logiciel: Coffret de pilotes Labtec Legacy USB Camera - (.Pas de propriétaire.) [HKLM] -- legacyqcam_10.51

O42 - Logiciel: Coffret de pilotes Logitech QuickCam - (.Pas de propriétaire.) [HKLM] -- lvdrivers_11.80

O42 - Logiciel: Compaq Demo - (.Hewlett-Packard.) [HKLM] -- {7F2B6338-4C07-49A0-BDF0-AD92E3124A7E}

O42 - Logiciel: CyberLink DVD Suite Deluxe - (.CyberLink Corp..) [HKLM] -- {1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}

O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}

O42 - Logiciel: ESSBrwr - (.EASTMAN KODAK Company.) [HKLM] -- {643EAE81-920C-4931-9F0B-4B343B225CA6}

O42 - Logiciel: ESSCDBK - (.EASTMAN KODAK Company.) [HKLM] -- {AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}

O42 - Logiciel: ESSPCD - (.EASTMAN KODAK Company.) [HKLM] -- {14D4ED84-6A9A-45A0-96F6-1753768C3CB5}

O42 - Logiciel: ESSPDock - (.Nom de votre société.) [HKLM] -- {FCDB1C92-03C6-4C76-8625-371224256091}

O42 - Logiciel: ESSTOOLS - (.EASTMAN KODAK Company.) [HKLM] -- {8A502E38-29C9-49FA-BCFA-D727CA062589}

O42 - Logiciel: ESScore - (.Nom de votre société.) [HKLM] -- {42938595-0D83-404D-9F73-F8177FDD531A}

O42 - Logiciel: ESSgui - (.EASTMAN KODAK Company.) [HKLM] -- {91517631-A9F3-4B7C-B482-43E0068FD55A}

O42 - Logiciel: ESSini - (.Nom de votre société.) [HKLM] -- {8E92D746-CD9F-4B90-9668-42B74C14F765}

O42 - Logiciel: FTDI USB Serial Converter Drivers - (.FTDI Ltd.) [HKLM] -- FTDICOMM

O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM] -- {488F0347-C4A7-4374-91A7-30818BEDA710}

O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

O42 - Logiciel: HP Advisor - (.Hewlett-Packard.) [HKLM] -- {73A43E42-3658-4DD9-8551-FACDA3632538}

O42 - Logiciel: HP Customer Experience Enhancements - (.Hewlett-Packard.) [HKLM] -- {C8D47273-7A1A-4614-A3D8-263632D8A5ED}

O42 - Logiciel: HP Customer Feedback - (.Hewlett-Packard.) [HKLM] -- {9DBA770F-BF73-4D39-B1DF-6035D95268FC}

O42 - Logiciel: HP Customer Participation Program 9.0 - (.HP.) [HKLM] -- HPExtendedCapabilities

O42 - Logiciel: HP Deskjet All-In-One Software 9.0 - (.HP.) [HKLM] -- {706BB40A-4102-4c89-8107-DC68C4EBD19B}

O42 - Logiciel: HP Easy Setup - Frontend - (.Hewlett-Packard.) [HKLM] -- {1BCE2581-B7CA-4BB4-BDFB-D113506AA38B}

O42 - Logiciel: HP Imaging Device Functions 9.0 - (.HP.) [HKLM] -- HP Imaging Device Functions

O42 - Logiciel: HP On-Screen Cap/Num/Scroll Lock Indicator - (.Hewlett-Packard.) [HKLM] -- OsdMaestro

O42 - Logiciel: HP Photosmart Essential 2.5 - (.HP.) [HKLM] -- HP Photosmart Essential

O42 - Logiciel: HP Product Assistant - (.Hewlett-Packard.) [HKLM] -- {36FDBE6E-6684-462B-AE98-9A39A1B200CC}

O42 - Logiciel: HP Solution Center 9.0 - (.HP.) [HKLM] -- HP Solution Center & Imaging Support Tools

O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM] -- {818ABC3C-635C-4651-8183-D0E9640B7DD1}

O42 - Logiciel: HPSSupply - (.Nom de votre société.) [HKLM] -- {487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}

O42 - Logiciel: Hewlett-Packard Active Check - (.Hewlett-Packard.) [HKLM] -- {254C37AA-6B72-4300-84F6-98A82419187E}

O42 - Logiciel: Hewlett-Packard Asset Agent for Health Check - (.HP.) [HKLM] -- {669D4A35-146B-4314-89F1-1AC3D7B88367}

O42 - Logiciel: Hidden Expedition: Amazon - (.Pas de propriétaire.) [HKLM] -- BFG-Hidden Expedition - Amazon

O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595

O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484

O42 - Logiciel: Intel® Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM] -- HDMI

O42 - Logiciel: Java 6 Update 24 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216011FF}

O42 - Logiciel: Java 6 Update 4 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160040}

O42 - Logiciel: Java 6 Update 7 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160070}

O42 - Logiciel: Java SE Runtime Environment 6 Update 1 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160010}

O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}

O42 - Logiciel: LabelPrint - (.CyberLink Corp..) [HKLM] -- {C59C179C-668D-49A9-B6EA-0121CCFC1243}

O42 - Logiciel: LightScribe System Software - (.LightScribe.) [HKLM] -- {7F10292C-A190-4176-A665-A1ED3478DF86}

O42 - Logiciel: Logiciel Kodak EasyShare - (.Eastman Kodak Company.) [HKLM] -- {D32470A1-B10C-4059-BA53-CF0486F68EBC}

O42 - Logiciel: Logitech QuickCam - (.Logitech Inc..) [HKLM] -- {3AF8FCCD-F51A-4014-9002-F195E1CBC876}

O42 - Logiciel: Logitech Updater - (.Nom de votre société.) [HKLM] -- {53735ECE-E461-4FD0-B742-23A352436D3A}

O42 - Logiciel: MP3 Player Utilities - (. .) [HKLM] -- {5BBFB0E4-2250-49C3-A8A3-65BE2197D13B}

O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}

O42 - Logiciel: MSXML 4.0 SP2 (KB936181) - (.Microsoft Corporation.) [HKLM] -- {C04E32E0-0416-434D-AFB9-6969D703A9EF}

O42 - Logiciel: MSXML 4.0 SP2 (KB941833) - (.Microsoft Corporation.) [HKLM] -- {C523D256-313D-4866-B36A-F3DE528246EF}

O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}

O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}

O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1

O42 - Logiciel: Microsoft .NET Framework 3.5 Language Pack SP1 - fra - (.Microsoft Corporation.) [HKLM] -- {3E31821C-7917-367E-938E-E65FC413EA31}

O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1

O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}

O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile

O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}

O42 - Logiciel: Microsoft .NET Framework 4 Client Profile FRA Language Pack - (.Microsoft Corporation.) [HKLM] -- {0F5B4A82-9DAF-3D13-8CB8-AEB25E4A614E}

O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}

O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}

O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}

O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}_HOMESTUDENTR_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}

O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-00A1-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}

O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}

O42 - Logiciel: Microsoft Office Excel MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Home and Student 2007 - (.Microsoft Corporation.) [HKLM] -- HOMESTUDENTR

O42 - Logiciel: Microsoft Office Home and Student 2007 - (.Microsoft Corporation.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Live Add-in 1.5 - (.Microsoft Corporation.) [HKLM] -- {F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}

O42 - Logiciel: Microsoft Office OneNote MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-00A1-040C-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Proof (German) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Proofing (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002C-040C-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}_HOMESTUDENTR_{14809F99-C601-4D4A-9391-F1E8FAA964C5}

O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}

O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}

O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}

O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}_HOMESTUDENTR_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}

O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}

O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Word MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}

O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}

O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}

O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118}

O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {837b34e3-7c30-493c-8f6a-2b0f04e2912c}

O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}

O42 - Logiciel: Microsoft Works - (.Microsoft Corporation.) [HKLM] -- {3B160861-7250-451E-B5EE-8B92BF30A710}

O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 Language Pack SP1 - fra

O42 - Logiciel: Module linguistique Microsoft .NET Framework 4 Client Profile FRA - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile FRA Language Pack

O42 - Logiciel: OfotoXMI - (.EASTMAN KODAK Company.) [HKLM] -- {B162D0A6-9A1D-4B7C-91A5-88FB48113C45}

O42 - Logiciel: Paint.NET v3.36 - (.dotPDN LLC.) [HKLM] -- {43602F34-1AA3-44FB-AEB2-D08C2C73743F}

O42 - Logiciel: Power2Go - (.CyberLink Corp..) [HKLM] -- {40BF1E83-20EB-11D8-97C5-0009C5020658}

O42 - Logiciel: PowerDirector - (.CyberLink Corp..) [HKLM] -- InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}

O42 - Logiciel: Python 2.5 - (.Martin v. Löwis.) [HKLM] -- {0A2C5854-557E-48C8-835A-3B9F074BDCAA}

O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {E7004147-2CCA-431C-AA05-2AB166B9785D}

O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}

O42 - Logiciel: SFR - (.Eastman Kodak Company.) [HKLM] -- {DB02F716-6275-42E9-B8D2-83BA2BF5100B}

O42 - Logiciel: SHASTA - (.EASTMAN KODAK Company.) [HKLM] -- {605A4E39-613C-4A12-B56F-DEFBE6757237}

O42 - Logiciel: SKINXSDK - (.EASTMAN KODAK Company.) [HKLM] -- {F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}

O42 - Logiciel: Security Advisor - (.Nom de votre société.) [HKLM] -- {809B9368-87AE-4F56-9743-FB16C99C2038}

O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288621) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{5C497F0B-2061-4CC9-A61C-6B45B867354D}

O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288931) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CD769337-C8AC-46DB-A7DC-643E50089263}

O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2289158) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{210B16C0-CEBD-4DE9-B474-04A7E8735E16}

O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2344875) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6FC5C4C1-D7AE-44C3-94B7-6424FC3E752F}

O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2345043) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{536FB502-775F-4494-BACE-C02CC90B7A5B}

O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{69F52148-9BF6-4CDC-BF76-103DEAF3DD08}

O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{7F207DCA-3399-40CB-A968-6E5991B1421A}

O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2416473

O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB2345035) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{B23002DD-34EC-4988-B810-A5E2A0BF04F1}

O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}

O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB982158) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{F5B70033-E79C-4569-90BF-BC9B4E4F3F46}

O42 - Logiciel: Security Update for Microsoft Office PowerPoint Viewer (KB2413381) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3DED0A62-44C8-4E00-A785-5212F297A9D9}

O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{71127777-8B2C-4F97-AF7A-6CF8CAC8224D}

O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB2344993) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}

O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}

O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{FCD742B9-7A55-44BC-A776-F795F21FEDDC}

O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM] -- {5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}

O42 - Logiciel: Soft Data Fax Modem with SmartCP - (.Conexant Systems.) [HKLM] -- CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1

O42 - Logiciel: SoftwareUpdate 1.5 - (.EoRezo.) [HKLM] -- SoftwareUpdate_is1

O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}

O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707

O42 - Logiciel: Update for Microsoft Office OneNote 2007 (KB980729) - (.Microsoft.) [HKLM] -- {91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{329050A9-EF80-40F9-B633-74508F54C1FF}

O42 - Logiciel: VPRINTOL - (.EASTMAN KODAK Company.) [HKLM] -- {999D43F4-9709-4887-9B1A-83EBB15A8370}

O42 - Logiciel: ViewSonic Windows Vista x64 Signed Files - (.Pas de propriétaire.) [HKLM] -- {FC47C7A5-BE63-11D5-B7C9-005004566E4D}

O42 - Logiciel: Visual C++ 2008 x86 Runtime - (v9.0.30729) - (.Microsoft Corporation.) [HKLM] -- {F333A33D-125C-32A2-8DCE-5C5D14231E27}

O42 - Logiciel: Visual C++ 2008 x86 Runtime - v9.0.30729.01 - (.Microsoft Corporation.) [HKLM] -- {F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01

O42 - Logiciel: WIRELESS - (.EASTMAN KODAK Company.) [HKLM] -- {F9593CFB-D836-49BC-BFF1-0E669A411D9F}

O42 - Logiciel: WeatherBug Gadget - (.AWS Convergence Technologies.) [HKLM] -- {209CDA54-D390-46A2-A97C-7BF61734418D}

O42 - Logiciel: Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite

O42 - Logiciel: Windows Live - (.Microsoft Corporation.) [HKLM] -- {34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}

O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {D45240D3-B6B3-4FF9-B243-54ECE3E10066}

O42 - Logiciel: Windows Live FolderShare - (.Microsoft Corporation.) [HKLM] -- {2075CB0A-D26F-4DAA-B424-5079296B43BA}

O42 - Logiciel: Windows Live ID Sign-in Assistant - (.Microsoft Corporation.) [HKLM] -- {61AD15B2-50DB-4686-A739-14FE180D4429}

O42 - Logiciel: Windows Live Installer - (.Microsoft Corporation.) [HKLM] -- {0B0F231F-CE6A-483D-AA23-77B364F75917}

O42 - Logiciel: Windows Live MIME IFilter - (.Microsoft Corporation.) [HKLM] -- {AF844339-2F8A-4593-81B3-9F4C54038C4E}

O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {9D56775A-93F3-44A3-8092-840E3826DE30}

O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {9FAE6E8D-E686-49F5-A574-0A58DFD9580C}

O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {6057E21C-ABE9-4059-AE3E-3BEB9925E660}

O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {EB4DF488-AAEF-406F-A341-CB2AAA315B90}

O42 - Logiciel: Windows Live Movie Maker - (.Microsoft Corporation.) [HKLM] -- {6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}

O42 - Logiciel: Windows Live Movie Maker - (.Microsoft Corporation.) [HKLM] -- {92EA4134-10D1-418A-91E1-5A0453131A38}

O42 - Logiciel: Windows Live PIMT Platform - (.Microsoft Corporation.) [HKLM] -- {4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}

O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM] -- {A9BDCA6B-3653-467B-AC83-94367DA3BFE3}

O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM] -- {C893D8C0-1BA0-4517-B11C-E89B65E72F70}

O42 - Logiciel: Windows Live Photo Gallery - (.Microsoft Corporation.) [HKLM] -- {3336F667-9049-4D46-98B6-4C743EEBC5B1}

O42 - Logiciel: Windows Live SOXE - (.Microsoft Corporation.) [HKLM] -- {682B3E4F-696A-42DE-A41C-4C07EA1678B4}

O42 - Logiciel: Windows Live SOXE Definitions - (.Microsoft Corporation.) [HKLM] -- {200FEC62-3C34-4D60-9CE8-EC372E01C08F}

O42 - Logiciel: Windows Live UX Platform - (.Microsoft Corporation.) [HKLM] -- {CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}

O42 - Logiciel: Windows Live UX Platform Language Pack - (.Microsoft Corporation.) [HKLM] -- {09F56A49-A7B1-4AAB-95B9-D13094254AD1}

O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM] -- {3B9A92DA-6374-4872-B646-253F18624D5F}

O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM] -- {A726AE06-AAA3-43D1-87E3-70F510314F04}

O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM] -- {AAAFC670-569B-4A2F-82B4-42945E0DE3EF}

O42 - Logiciel: Windows Live Writer Resources - (.Microsoft Corporation.) [HKLM] -- {62687B11-58B5-4A18-9BC3-9DF4CE03F194}

O42 - Logiciel: avast! Free Antivirus - (.AVAST Software.) [HKLM] -- avast

O42 - Logiciel: essvatgt - (.EASTMAN KODAK Company.) [HKLM] -- {2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}

O42 - Logiciel: kgcbaby - (.EASTMAN KODAK Company.) [HKLM] -- {E18B549C-5D15-45DA-8D8F-8FD2BD946344}

O42 - Logiciel: kgchday - (.EASTMAN KODAK Company.) [HKLM] -- {11F3F858-4131-4FFA-A560-3FE282933B6E}

O42 - Logiciel: kgchlwn - (.EASTMAN KODAK Company.) [HKLM] -- {03EDED24-8375-407D-A721-4643D9768BE1}

O42 - Logiciel: kgcinvt - (.EASTMAN KODAK Company.) [HKLM] -- {9BD54685-1496-46A5-AB62-357CD140ED8B}

O42 - Logiciel: kgckids - (.EASTMAN KODAK Company.) [HKLM] -- {693C08A7-9E76-43FF-B11E-9A58175474C4}

O42 - Logiciel: kgcmove - (.EASTMAN KODAK Company.) [HKLM] -- {A1588373-1D86-4D44-86C9-78ABD190F9CC}

O42 - Logiciel: kgcvday - (.EASTMAN KODAK Company.) [HKLM] -- {8A8664E1-84C8-4936-891C-BC1F07797549}

O42 - Logiciel: muvee autoProducer 6.1 - (.muvee Technologies.) [HKLM] -- {5115C036-C0D5-4E1B-81C9-542CA967478A}

O42 - Logiciel: netbrdg - (.EASTMAN KODAK Company.) [HKLM] -- {4537EA4B-F603-4181-89FB-2953FC695AB1}

O42 - Logiciel: skin0001 - (.EASTMAN KODAK Company.) [HKLM] -- {5316DFC9-CE99-4458-9AB3-E8726EDE0210}

O42 - Logiciel: staticcr - (.EASTMAN KODAK Company.) [HKLM] -- {8943CE61-53BD-475E-90E1-A580869E98A2}

O42 - Logiciel: tooltips - (.EASTMAN KODAK Company.) [HKLM] -- {E79987F0-0E34-42CC-B8FF-6C860AEEB26A}


---\\ HKCU & HKLM Software Keys

[HKCU\Software\ALWIL Software]

[HKCU\Software\AVAST Software]










[HKCU\Software\Apple Computer, Inc.]


[HKCU\Software\Big Fish Games]

[HKCU\Software\Binary Noise]






[HKCU\Software\IM Providers]







[HKCU\Software\Local AppWizard-Generated Applications]







[HKCU\Software\Malwarebytes' Anti-Malware]












[HKCU\Software\Screensaver Factory]

[HKCU\Software\Siber Systems]

[HKCU\Software\Softdisk LLC]


[HKCU\Software\TERMINAL Studio]



[HKCU\Software\Windows Live]





[HKLM\Software\ALWIL Software]

[HKLM\Software\AVAST Software]


[HKLM\Software\America Online]

[HKLM\Software\Apple Computer, Inc.]

[HKLM\Software\Apple Inc.]


[HKLM\Software\Big Fish Games]





[HKLM\Software\Conexant Systems]


















[HKLM\Software\Malwarebytes' Anti-Malware]










[HKLM\Software\Realtek Semiconductor Corp.]




[HKLM\Software\SRS Labs]

[HKLM\Software\Safer Networking Limited]

[HKLM\Software\Siber Systems]






[HKLM\Software\The Learning Company]

[HKLM\Software\ViewSonic Corporation]








[HKLM\Software\muvee Technologies]




---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)

O43 - CFD: 2010-07-25 - 17:23:38 - [11748894] ----D- C:\Program Files\a-squared Free

O43 - CFD: 2009-08-27 - 01:41:36 - [128729474] ----D- C:\Program Files\Adobe

O43 - CFD: 2010-03-12 - 23:37:48 - [581632] ----D- C:\Program Files\AGI

O43 - CFD: 2010-03-12 - 20:50:06 - [151730888] ----D- C:\Program Files\Alwil Software

O43 - CFD: 2010-10-12 - 10:38:54 - [2221118] ----D- C:\Program Files\Apple Software Update

O43 - CFD: 2008-12-14 - 22:27:34 - [0] ----D- C:\Program Files\ArcSoft

O43 - CFD: 2010-12-10 - 03:14:46 - [1618] ----D- C:\Program Files\

O43 - CFD: 2010-03-13 - 23:01:00 - [0] ----D- C:\Program Files\AWS

O43 - CFD: 2011-03-03 - 23:19:34 - [6988263] ----D- C:\Program Files\bfgclient

O43 - CFD: 2010-10-12 - 13:11:14 - [392881] ----D- C:\Program Files\Bonjour

O43 - CFD: 2010-03-08 - 15:00:56 - [1327120] ----D- C:\Program Files\CCleaner

O43 - CFD: 2010-05-09 - 02:25:26 - [1096325485] ----D- C:\Program Files\Common Files

O43 - CFD: 2008-02-19 - 00:46:10 - [1024000] ----D- C:\Program Files\CONEXANT

O43 - CFD: 2008-02-19 - 01:08:04 - [735040696] ----D- C:\Program Files\CyberLink

O43 - CFD: 2010-07-24 - 02:52:38 - [26552477] ----D- C:\Program Files\Emsisoft Anti-Malware

O43 - CFD: 2008-05-03 - 23:12:08 - [0] -SH-D- C:\Program Files\Fichiers communs

O43 - CFD: 2011-02-16 - 18:53:12 - [2908240] ----D- C:\Program Files\Google

O43 - CFD: 2009-10-10 - 22:03:22 - [115240047] ----D- C:\Program Files\Hewlett-Packard

O43 - CFD: 2011-03-04 - 02:58:58 - [167587410] ----D- C:\Program Files\Hidden Expedition - Amazon

O43 - CFD: 2008-07-08 - 15:42:10 - [133852165] ----D- C:\Program Files\HP

O43 - CFD: 2010-04-10 - 00:17:04 - [61467250] --H-D- C:\Program Files\InstallShield Installation Information

O43 - CFD: 2011-02-09 - 07:45:38 - [5699790] ----D- C:\Program Files\Internet Explorer

O43 - CFD: 2011-02-20 - 01:14:10 - [327267569] ----D- C:\Program Files\Java

O43 - CFD: 2008-06-30 - 21:56:44 - [122240459] ----D- C:\Program Files\Kodak

O43 - CFD: 2008-09-02 - 21:43:58 - [79802142] ----D- C:\Program Files\Labtec

O43 - CFD: 2010-12-10 - 03:13:24 - [749576] ----D- C:\Program Files\LimeWire

O43 - CFD: 2008-09-02 - 21:44:14 - [19357386] ----D- C:\Program Files\Logitech

O43 - CFD: 2010-12-29 - 08:50:54 - [4942956] ----D- C:\Program Files\Malwarebytes' Anti-Malware

O43 - CFD: 2010-10-22 - 05:00:42 - [526291] ----D- C:\Program Files\Microsoft

O43 - CFD: 2006-11-02 - 08:37:36 - [93446071] ----D- C:\Program Files\Microsoft Games

O43 - CFD: 2008-08-21 - 13:08:42 - [366533155] ----D- C:\Program Files\Microsoft Office

O43 - CFD: 2011-03-19 - 04:09:58 - [39396803] ----D- C:\Program Files\Microsoft Silverlight

O43 - CFD: 2008-11-20 - 16:43:06 - [1829877] ----D- C:\Program Files\Microsoft SQL Server Compact Edition

O43 - CFD: 2010-12-15 - 04:13:06 - [144641984] ----D- C:\Program Files\Microsoft Works

O43 - CFD: 2010-06-25 - 07:07:36 - [8167779] ----D- C:\Program Files\Microsoft.NET

O43 - CFD: 2010-08-13 - 02:02:02 - [99342446] ----D- C:\Program Files\Movie Maker

O43 - CFD: 2008-05-05 - 15:42:56 - [3921216] ----D- C:\Program Files\MP3 Player Utilities

O43 - CFD: 2006-11-02 - 08:37:36 - [25757] ----D- C:\Program Files\MSBuild

O43 - CFD: 2008-08-18 - 23:09:26 - [27815471] ----D- C:\Program Files\MSECache

O43 - CFD: 2008-05-05 - 15:28:36 - [0] ----D- C:\Program Files\MSXML 4.0

O43 - CFD: 2008-02-19 - 01:09:04 - [155434389] ----D- C:\Program Files\muvee Technologies

O43 - CFD: 2009-10-10 - 22:04:24 - [116363] R---D- C:\Program Files\Online Services

O43 - CFD: 2008-08-18 - 23:59:20 - [0] ----D- C:\Program Files\ 2.4

O43 - CFD: 2008-09-09 - 22:29:20 - [9326446] ----D- C:\Program Files\Paint.NET

O43 - CFD: 2010-10-12 - 10:45:46 - [76337719] ----D- C:\Program Files\QuickTime

O43 - CFD: 2009-10-29 - 18:53:32 - [3684999] ----D- C:\Program Files\Radialpoint

O43 - CFD: 2008-08-18 - 23:04:38 - [62844252] ----D- C:\Program Files\Realtek

O43 - CFD: 2006-11-02 - 08:37:36 - [38694657] ----D- C:\Program Files\Reference Assemblies

O43 - CFD: 2008-07-01 - 17:29:42 - [11093081] ----D- C:\Program Files\Siber Systems

O43 - CFD: 2010-03-12 - 22:33:16 - [254582] ----D- C:\Program Files\UnifiedToolbar

O43 - CFD: 2006-11-02 - 09:01:56 - [0] --H-D- C:\Program Files\Uninstall Information

O43 - CFD: 2009-10-29 - 18:52:22 - [8110441] ----D- C:\Program Files\Videotron

O43 - CFD: 2010-03-09 - 02:40:36 - [12435208] ----D- C:\Program Files\Webshots

O43 - CFD: 2009-09-19 - 01:36:18 - [1016832] ----D- C:\Program Files\Windows Calendar

O43 - CFD: 2009-09-19 - 01:36:14 - [2737152] ----D- C:\Program Files\Windows Collaboration

O43 - CFD: 2009-09-19 - 01:36:00 - [4490624] ----D- C:\Program Files\Windows Defender

O43 - CFD: 2009-09-19 - 01:36:14 - [7084664] ----D- C:\Program Files\Windows Journal

O43 - CFD: 2010-10-22 - 04:58:06 - [146671059] ----D- C:\Program Files\Windows Live

O43 - CFD: 2010-03-12 - 21:33:34 - [1303] ----D- C:\Program Files\Windows Live Toolbar

O43 - CFD: 2011-02-09 - 07:45:40 - [9116344] ----D- C:\Program Files\Windows Mail

O43 - CFD: 2010-10-14 - 03:33:04 - [4498121] ----D- C:\Program Files\Windows Media Player

O43 - CFD: 2008-05-03 - 23:12:08 - [7957544] ----D- C:\Program Files\Windows NT

O43 - CFD: 2009-09-19 - 01:36:10 - [13528738] ----D- C:\Program Files\Windows Photo Gallery

O43 - CFD: 2009-11-18 - 04:20:38 - [134144] ----D- C:\Program Files\Windows Portable Devices

O43 - CFD: 2009-09-19 - 01:36:16 - [7866954] ----D- C:\Program Files\Windows Sidebar

O43 - CFD: 2008-12-07 - 22:22:58 - [0] ----D- C:\Program Files\Yahoo!

O43 - CFD: 2011-03-20 - 15:54:32 - [3482710] ----D- C:\Program Files\ZHPDiag

O43 - CFD: 2009-08-27 - 01:41:54 - [10887811] ----D- C:\Program Files\Common Files\Adobe

O43 - CFD: 2010-10-12 - 10:39:26 - [75145842] ----D- C:\Program Files\Common Files\Apple

O43 - CFD: 2008-12-14 - 22:27:36 - [55974] ----D- C:\Program Files\Common Files\ArcSoft

O43 - CFD: 2008-08-21 - 13:08:38 - [92976] ----D- C:\Program Files\Common Files\DESIGNER

O43 - CFD: 2008-05-22 - 17:28:44 - [457237] ----D- C:\Program Files\Common Files\Hewlett-Packard

O43 - CFD: 2008-02-19 - 00:58:46 - [5160872] ----D- C:\Program Files\Common Files\HP

O43 - CFD: 2008-02-19 - 01:23:28 - [14028235] ----D- C:\Program Files\Common Files\InstallShield

O43 - CFD: 2011-02-20 - 01:16:34 - [47515189] ----D- C:\Program Files\Common Files\Java

O43 - CFD: 2008-12-14 - 22:08:20 - [3266818] ----D- C:\Program Files\Common Files\Kodak

O43 - CFD: 2008-05-05 - 15:14:10 - [12725285] ----D- C:\Program Files\Common Files\Labtec

O43 - CFD: 2009-08-04 - 15:50:14 - [32098444] ---AD- C:\Program Files\Common Files\LightScribe

O43 - CFD: 2008-09-02 - 21:44:46 - [58138692] ----D- C:\Program Files\Common Files\LogiShrd

O43 - CFD: 2009-01-04 - 18:57:44 - [1337318] ----D- C:\Program Files\Common Files\Logitech

O43 - CFD: 2008-02-19 - 01:08:14 - [56415] ---AD- C:\Program Files\Common Files\LS Getting Started

O43 - CFD: 2010-10-22 - 04:55:08 - [436768674] ----D- C:\Program Files\Common Files\microsoft shared

O43 - CFD: 2008-12-14 - 22:07:54 - [651776] ----D- C:\Program Files\Common Files\MSSoap

O43 - CFD: 2008-02-19 - 01:09:04 - [49399251] ----D- C:\Program Files\Common Files\muvee Technologies

O43 - CFD: 2009-04-25 - 21:05:40 - [1963995] ----D- C:\Program Files\Common Files\PC Tools

O43 - CFD: 2006-11-02 - 07:18:34 - [2702] ----D- C:\Program Files\Common Files\Services

O43 - CFD: 2006-11-02 - 07:18:34 - [41101735] ----D- C:\Program Files\Common Files\SpeechEngines

O43 - CFD: 2008-05-26 - 00:35:42 - [1811224] ----D- C:\Program Files\Common Files\Symantec Shared

O43 - CFD: 2009-09-19 - 01:36:10 - [42750094] ----D- C:\Program Files\Common Files\System

O43 - CFD: 2010-05-09 - 02:25:26 - [218474680] ----D- C:\Program Files\Common Files\Windows Live

O43 - CFD: 2008-05-04 - 00:03:44 - [42434246] -SH-D- C:\Program Files\Common Files\WindowsLiveInstaller

O43 - CFD: 2009-08-27 - 01:41:48 - [764] ----D- C:\ProgramData\Adobe

O43 - CFD: 2010-02-10 - 11:49:44 - [4477285] ----D- C:\ProgramData\agi

O43 - CFD: 2010-03-12 - 20:50:06 - [35035550] ----D- C:\ProgramData\Alwil Software

O43 - CFD: 2008-05-05 - 02:15:14 - [31628800] ----D- C:\ProgramData\Apple

O43 - CFD: 2010-10-12 - 10:45:14 - [26921472] ----D- C:\ProgramData\Apple Computer

O43 - CFD: 2006-11-02 - 09:02:04 - [0] -SH-D- C:\ProgramData\Application Data

O43 - CFD: 2008-12-14 - 22:15:28 - [1273] ----D- C:\ProgramData\ArcSoft

O43 - CFD: 2008-05-03 - 23:12:08 - [0] -SH-D- C:\ProgramData\Bureau

O43 - CFD: 2008-06-12 - 01:06:30 - [7396] ----D- C:\ProgramData\CyberLink

O43 - CFD: 2006-11-02 - 09:02:04 - [0] -SH-D- C:\ProgramData\Desktop

O43 - CFD: 2006-11-02 - 09:02:04 - [0] -SH-D- C:\ProgramData\Documents

O43 - CFD: 2008-05-03 - 23:12:08 - [0] -SH-D- C:\ProgramData\Favoris

O43 - CFD: 2006-11-02 - 09:02:04 - [0] -SH-D- C:\ProgramData\Favorites

O43 - CFD: 2011-02-16 - 18:53:12 - [523440] ----D- C:\ProgramData\Google

O43 - CFD: 2009-10-10 - 22:03:22 - [1146652] ----D- C:\ProgramData\Hewlett-Packard

O43 - CFD: 2008-09-09 - 22:13:24 - [1844516] ----D- C:\ProgramData\HP

O43 - CFD: 2010-07-24 - 02:51:32 - [8979] ----D- C:\ProgramData\HP Product Assistant

O43 - CFD: 2008-05-22 - 17:53:18 - [265] ----D- C:\ProgramData\HPSSUPPLY

O43 - CFD: 2008-06-30 - 21:58:10 - [207213439] ----D- C:\ProgramData\Kodak

O43 - CFD: 2008-06-12 - 01:07:32 - [390] ----D- C:\ProgramData\LightScribe

O43 - CFD: 2008-09-04 - 07:53:20 - [7065347] ----D- C:\ProgramData\Logishrd

O43 - CFD: 2008-09-02 - 21:44:16 - [5870948] ----D- C:\ProgramData\Logitech

O43 - CFD: 2010-08-12 - 23:43:22 - [14162272] ----D- C:\ProgramData\Malwarebytes

O43 - CFD: 2011-02-16 - 18:49:48 - [1062] ----D- C:\ProgramData\McAfee

O43 - CFD: 2008-05-03 - 23:12:08 - [0] -SH-D- C:\ProgramData\Menu Démarrer

O43 - CFD: 2008-09-06 - 23:03:56 - [185795921] ----D- C:\ProgramData\MGS

O43 - CFD: 2010-10-22 - 04:55:52 - [333132437] -S--D- C:\ProgramData\Microsoft

O43 - CFD: 2010-12-15 - 04:07:12 - [57040] ----D- C:\ProgramData\Microsoft Help

O43 - CFD: 2008-05-03 - 23:12:08 - [0] -SH-D- C:\ProgramData\Modèles

O43 - CFD: 2008-02-19 - 01:09:00 - [0] ----D- C:\ProgramData\muvee Technologies

O43 - CFD: 2009-04-25 - 20:19:40 - [0] ----D- C:\ProgramData\PC Tools

O43 - CFD: 2010-10-26 - 16:16:40 - [797804] ----D- C:\ProgramData\Radialpoint

O43 - CFD: 2008-07-01 - 17:30:46 - [96] ----D- C:\ProgramData\RoboForm

O43 - CFD: 2010-12-07 - 04:54:54 - [0] ----D- C:\ProgramData\Softdisk LLC

O43 - CFD: 2006-11-02 - 09:02:04 - [0] -SH-D- C:\ProgramData\Start Menu

O43 - CFD: 2010-03-31 - 23:27:54 - [294] ----D- C:\ProgramData\Sun

O43 - CFD: 2011-03-10 - 02:54:46 - [0] ---AD- C:\ProgramData\TEMP

O43 - CFD: 2006-11-02 - 09:02:06 - [0] -SH-D- C:\ProgramData\Templates

O43 - CFD: 2009-10-29 - 18:52:22 - [3080] ----D- C:\ProgramData\Videotron

O43 - CFD: 2009-10-29 - 18:52:32 - [0] ----D- C:\ProgramData\Vidéotron

O43 - CFD: 2008-05-22 - 17:43:06 - [236] ----D- C:\ProgramData\WEBREG

O43 - CFD: 2009-06-09 - 14:05:06 - [0] ----D- C:\ProgramData\WindowsSearch

O43 - CFD: 2008-12-07 - 22:25:02 - [0] ----D- C:\ProgramData\Winferno

O43 - CFD: 2008-11-20 - 16:40:40 - [582292] ----D- C:\ProgramData\WLInstaller

O43 - CFD: 2008-05-09 - 02:35:28 - [2309772] ----D- C:\Users\mimi\AppData\Roaming\Adobe

O43 - CFD: 2008-12-22 - 03:50:24 - [23] ----D- C:\Users\mimi\AppData\Roaming\agi

O43 - CFD: 2008-05-05 - 02:19:10 - [151308] ----D- C:\Users\mimi\AppData\Roaming\Apple Computer

O43 - CFD: 2008-12-14 - 22:21:04 - [288022] ----D- C:\Users\mimi\AppData\Roaming\ArcSoft

O43 - CFD: 2010-07-22 - 16:46:44 - [0] ----D- C:\Users\mimi\AppData\Roaming\CBS Interactive

O43 - CFD: 2008-06-15 - 00:23:42 - [8768884] ----D- C:\Users\mimi\AppData\Roaming\CyberLink

O43 - CFD: 2010-12-09 - 10:00:30 - [7928291] ----D- C:\Users\mimi\AppData\Roaming\EoRezo

O43 - CFD: 2009-07-16 - 00:10:34 - [34637] ----D- C:\Users\mimi\AppData\Roaming\Google

O43 - CFD: 2009-10-10 - 22:03:22 - [24705] ----D- C:\Users\mimi\AppData\Roaming\Hewlett-Packard

O43 - CFD: 2008-05-28 - 03:39:48 - [229016] ----D- C:\Users\mimi\AppData\Roaming\HP

O43 - CFD: 2009-10-17 - 17:17:34 - [37120] ----D- C:\Users\mimi\AppData\Roaming\HpUpdate

O43 - CFD: 2008-05-03 - 23:22:26 - [0] ----D- C:\Users\mimi\AppData\Roaming\Identities

O43 - CFD: 2008-06-07 - 20:17:44 - [1210814] ----D- C:\Users\mimi\AppData\Roaming\LANCITE

O43 - CFD: 2008-09-02 - 21:46:56 - [272] ----D- C:\Users\mimi\AppData\Roaming\Leadertech

O43 - CFD: 2010-12-10 - 03:13:24 - [16114637] ----D- C:\Users\mimi\AppData\Roaming\LimeWire

O43 - CFD: 2008-05-03 - 23:21:14 - [13864] ----D- C:\Users\mimi\AppData\Roaming\Macromedia

O43 - CFD: 2010-08-12 - 23:43:48 - [15229993] ----D- C:\Users\mimi\AppData\Roaming\Malwarebytes

O43 - CFD: 2006-11-02 - 08:37:36 - [0] ----D- C:\Users\mimi\AppData\Roaming\Media Center Programs

O43 - CFD: 2010-03-06 - 02:13:04 - [21534009] -S--D- C:\Users\mimi\AppData\Roaming\Microsoft

O43 - CFD: 2010-06-02 - 01:01:22 - [0] ----D- C:\Users\mimi\AppData\Roaming\Mozilla

O43 - CFD: 2008-08-18 - 23:17:36 - [15090575] ----D- C:\Users\mimi\AppData\Roaming\OpenOffice.org2

O43 - CFD: 2009-04-25 - 20:19:40 - [0] ----D- C:\Users\mimi\AppData\Roaming\PC Tools

O43 - CFD: 2008-06-30 - 21:58:34 - [0] ----D- C:\Users\mimi\AppData\Roaming\Skinux

O43 - CFD: 2008-05-03 - 23:23:08 - [0] ----D- C:\Users\mimi\AppData\Roaming\Symantec

O43 - CFD: 2009-10-29 - 18:52:42 - [4527983] ----D- C:\Users\mimi\AppData\Roaming\Videotron

O43 - CFD: 2009-10-29 - 18:52:44 - [0] ----D- C:\Users\mimi\AppData\Roaming\Vidéotron

O43 - CFD: 2008-12-22 - 03:50:24 - [22621218] ----D- C:\Users\mimi\AppData\Roaming\Webshots

O43 - CFD: 2008-08-18 - 23:04:28 - [0] ----D- C:\Users\mimi\AppData\Roaming\WinBatch

O43 - CFD: 2010-10-25 - 08:41:52 - [295] ----D- C:\Users\mimi\AppData\Roaming\Windows Live Writer

O43 - CFD: 2008-05-04 - 00:42:26 - [0] ----D- C:\Users\mimi\AppData\Roaming\Yahoo!




---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)

O44 - LFC:[MD5.CF721E064F489AB8C52CFC2D8A3B5C17] - 2008-01-02 - 03:27:00 ---A- . (...) -- C:\Windows\System32\iglhxo32.vp [2096]

O44 - LFC:[MD5.46537E443C84983A1E2D7A7744C275D1] - 2008-03-25 - 16:46:42 ---A- . (...) -- C:\Windows\System32\iglhxs32.vp [32896]

O44 - LFC:[MD5.B2EDF82825D979928AE07CBE9C7A2160] - 2009-07-16 - 12:30:03 ---A- . (...) -- C:\Windows\System32\WsmTxt.xsl [2426]

O44 - LFC:[MD5.3C436603213561E2E7DD3D4459DBB7D4] - 2009-07-16 - 12:30:03 ---A- . (...) -- C:\Windows\System32\wsmanconfig_schema.xml [4675]

O44 - LFC:[MD5.F6D48AE1F578493D2E19DD644B153976] - 2009-08-01 - 01:27:37 ---A- . (...) -- C:\Windows\System32\winrm.vbs [201184]

O44 - LFC:[MD5.79361C48047BB7276778E775FFC8AD6B] - 2011-02-20 - 00:14:09 ---A- . (...) -- C:\Windows\System32\jupdate-1.6.0_24-b07.log [3199]

O44 - LFC:[MD5.68288DA42BC798992A42CD59061B199D] - 2011-02-20 - 00:14:58 ---A- . (.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\Windows\System32\java.exe [145184]

O44 - LFC:[MD5.5BF8BA1B854D7DFCE1F47E58852B3D8F] - 2011-02-20 - 00:14:59 ---A- . (.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\Windows\System32\javaw.exe [145184]

O44 - LFC:[MD5.58DC5CBDC930AF070B177843810F2C85] - 2011-02-20 - 00:14:59 ---A- . (.Sun Microsystems, Inc. - Java Web Start Launcher.) -- C:\Windows\System32\javaws.exe [157472]

O44 - LFC:[MD5.1C2E6BB4FE8621B1B863855B02BC33EB] - 2011-02-23 - 09:54:55 ---A- . (.AVAST Software - avast! File System Access Blocking Driver.) -- C:\Windows\System32\drivers\aswFsBlk.sys [19544]

O44 - LFC:[MD5.B0F137F664F10829CD2380B0E20E7C29] - 2011-02-23 - 09:55:03 ---A- . (.AVAST Software - avast! File System Minifilter for Windows 2.) -- C:\Windows\System32\drivers\aswMonFlt.sys [53592]

O44 - LFC:[MD5.B6A9373619D851BE80FB5F1B5EED0D4E] - 2011-02-23 - 09:55:10 ---A- . (.AVAST Software - avast! TDI RDR Driver.) -- C:\Windows\System32\drivers\aswRdr.sys [25432]

O44 - LFC:[MD5.C7F1CEA32766184911293F4E1EE653F5] - 2011-02-23 - 09:55:49 ---A- . (.AVAST Software - avast! TDI Filter Driver.) -- C:\Windows\System32\drivers\aswTdi.sys [49240]

O44 - LFC:[MD5.4B1A54BA2BC5873A774DF6B70AB8B0B3] - 2011-02-23 - 09:56:45 ---A- . (.AVAST Software - avast! self protection module.) -- C:\Windows\System32\drivers\aswSP.sys [301528]

O44 - LFC:[MD5.9BE41C1AE8BC481EB662D85C98D979C2] - 2011-02-23 - 09:56:55 ---A- . (.AVAST Software - avast! Virtualization Driver.) -- C:\Windows\System32\drivers\aswSnx.sys [371544]

O44 - LFC:[MD5.C6E1D434F1F3A5226B0DDFDF84B12677] - 2011-02-23 - 10:04:17 ---A- . (.AVAST Software - avast! start-up scanner.) -- C:\Windows\System32\aswBoot.exe [190016]

O44 - LFC:[MD5.0439C6170F7F6355BB5275C9CAA6050F] - 2011-02-23 - 10:04:21 ---A- . (.AVAST Software - avast! Screen Saver stub.) -- C:\Windows\avastSS.scr [40648]

O44 - LFC:[MD5.01C47C2ECED034EF6F8C1552A97CFF00] - 2011-03-05 - 10:43:20 ---A- . (...) -- C:\Windows\System32\config.nt [2577]

O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 2011-03-08 - 23:00:52 ---A- . (...) -- C:\Windows\setuperr.log [0]

O44 - LFC:[MD5.DA386332E63281DB7D2923DC963D6F2E] - 2011-03-08 - 23:01:45 ---A- . (...) -- C:\Windows\setupact.log [695]

O44 - LFC:[MD5.C15460AB6B60AF53303D9DE7881A7033] - 2011-03-15 - 20:30:21 ---A- . (...) -- C:\Windows\PFRO.log [518]

O44 - LFC:[MD5.06582762FCF85981F188D74E1E162361] - 2011-03-20 - 02:55:52 ---A- . (...) -- C:\Windows\MEMORY.DMP [179501972]

O44 - LFC:[MD5.4E9425D784EC099FDBB8B1839D4E35EE] - 2011-03-20 - 02:56:42 ---A- . (...) -- C:\Windows\ntbtlog.txt [41218]

O44 - LFC:[MD5.62F534791AE488A475A3E508D92AF4CC] - 2011-03-20 - 03:29:27 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd32.sys [2307072]

O44 - LFC:[MD5.CADB1C9B8CE4F23EC49BD3B713DBE027] - 2011-03-20 - 03:29:28 ---A- . (.Intel Corporation - LDDM User Mode Driver for Intel® Graphics.) -- C:\Windows\System32\igdumd32.dll [3301376]

O44 - LFC:[MD5.BC74A74B020374D280FB8DB82FCB8D55] - 2011-03-20 - 03:29:30 ---A- . (.Intel Corporation - hccutils Module.) -- C:\Windows\System32\hccutils.dll [106496]

O44 - LFC:[MD5.829ABAD7E87B155C25B69C41A872CF5D] - 2011-03-20 - 03:29:30 ---A- . (.Intel Corporation - igfxsrvc Module.) -- C:\Windows\System32\igfxsrvc.dll [48640]

O44 - LFC:[MD5.1CF370D5C495F52DB8B83346BDF3AE7C] - 2011-03-20 - 03:29:31 ---A- . (.Intel Corporation - igfxsrvc Module.) -- C:\Windows\System32\igfxsrvc.exe [256536]

O44 - LFC:[MD5.FBDD6B407BEF4524D71363E8D820C24B] - 2011-03-20 - 03:29:32 ---A- . (.Intel Corporation - igfxpph Module.) -- C:\Windows\System32\igfxpph.dll [204800]

O44 - LFC:[MD5.5B69A33D1F6AB3BB734B9BEF4099160B] - 2011-03-20 - 03:29:33 ---A- . (.Intel Corporation - igfxcfg Module.) -- C:\Windows\System32\igfxcfg.exe [539160]

O44 - LFC:[MD5.BADB93F5B0EED724DC833C3A5A330CF8] - 2011-03-20 - 03:29:33 ---A- . (.Intel Corporation - igfxcpl Module.) -- C:\Windows\System32\igfxcpl.cpl [122880]

O44 - LFC:[MD5.AC88A8E42CDD202F83C39AAC5CBFB105] - 2011-03-20 - 03:29:33 ---A- . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll [204800]

O44 - LFC:[MD5.409E5B10053382C9D339BAEAA6584999] - 2011-03-20 - 03:29:34 ---A- . (.Intel Corporation - hkcmd Module.) -- C:\Windows\System32\hkcmd.exe [166424]

O44 - LFC:[MD5.767B74C5242D0F33E610F31A2363D7F6] - 2011-03-20 - 03:29:34 ---A- . (.Intel Corporation - igfxTray Module.) -- C:\Windows\System32\igfxtray.exe [141848]

O44 - LFC:[MD5.495F21584FC2875F8C824755CE52BBF1] - 2011-03-20 - 03:29:34 ---A- . (.Intel Corporation - igfxdo Module.) -- C:\Windows\System32\igfxdo.dll [135168]

O44 - LFC:[MD5.93A472E1FB39AF5A7E8315CDBDDC1806] - 2011-03-20 - 03:29:35 ---A- . (.Intel Corporation - igfxress Module.) -- C:\Windows\System32\igfxress.dll [3293184]

O44 - LFC:[MD5.B76195C8E8845FF2A8FA658709345DE2] - 2011-03-20 - 03:29:40 ---A- . (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe [133656]

O44 - LFC:[MD5.B94049ED36059FB37B0D077C855F159E] - 2011-03-20 - 03:29:41 ---A- . (.Intel Corporation - igfxTMM Module.) -- C:\Windows\System32\igfxTMM.dll [241664]

O44 - LFC:[MD5.7570C98D7BCFB09DF159A9CFDD9592AD] - 2011-03-20 - 03:29:42 ---A- . (.Intel Corporation - igfxext Module.) -- C:\Windows\System32\igfxext.exe [170520]

O44 - LFC:[MD5.98467169F5C85138FDE29A85C268C8F5] - 2011-03-20 - 03:29:43 ---A- . (.Intel Corporation - Oemdspif Module.) -- C:\Windows\System32\oemdspif.dll [69632]

O44 - LFC:[MD5.150B8CE4F300CAF1C7F10B2130AFBFF0] - 2011-03-20 - 03:29:43 ---A- . (.Intel Corporation - igfxext Module.) -- C:\Windows\System32\igfxexps.dll [24576]

O44 - LFC:[MD5.0CC1F17E8B2D6210708B6E4920EF0642] - 2011-03-20 - 03:29:44 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrara.lrc [159744]

O44 - LFC:[MD5.0315D4956246ACE396BAB40B4700D3E2] - 2011-03-20 - 03:29:45 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrchs.lrc [114688]

O44 - LFC:[MD5.25A8F57918888648B003671AA857588C] - 2011-03-20 - 03:29:45 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrcht.lrc [110592]

O44 - LFC:[MD5.AA16F911229FB8B9B7CF9453539412E6] - 2011-03-20 - 03:29:45 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrdan.lrc [176128]

O44 - LFC:[MD5.3406324B4105280FF5F6B9032675F5BD] - 2011-03-20 - 03:29:46 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrdeu.lrc [192512]

O44 - LFC:[MD5.1534E172D3FA9A5F562255AD58EF62CC] - 2011-03-20 - 03:29:46 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrenu.lrc [172032]

O44 - LFC:[MD5.8CF43AE2EC1D8279DDB75541E66EEDC4] - 2011-03-20 - 03:29:46 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxresp.lrc [188416]

O44 - LFC:[MD5.4FE2C378DB00345411AB83233C2AE2AC] - 2011-03-20 - 03:29:46 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrfin.lrc [176128]

O44 - LFC:[MD5.B697441F26A8C3EE4554A4DBA784DA88] - 2011-03-20 - 03:29:46 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrfra.lrc [184320]

O44 - LFC:[MD5.3EF352FAABCD99320554172EB37A96A0] - 2011-03-20 - 03:29:46 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrheb.lrc [155648]

O44 - LFC:[MD5.2D7B69E7552DB322BBE152AD430D4784] - 2011-03-20 - 03:29:47 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrita.lrc [188416]

O44 - LFC:[MD5.28458D1049FA058768DB736A79DCF63B] - 2011-03-20 - 03:29:47 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrjpn.lrc [131072]

O44 - LFC:[MD5.DB123F3E491AE46A2B6826AC73CA366F] - 2011-03-20 - 03:29:47 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrkor.lrc [126976]

O44 - LFC:[MD5.ED406EEDB3A5936CD2EBCEA7FBC8151B] - 2011-03-20 - 03:29:47 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrnld.lrc [188416]

O44 - LFC:[MD5.EDA9F4D2D6D5502FAE7CEFFED8D65430] - 2011-03-20 - 03:29:47 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrnor.lrc [176128]

O44 - LFC:[MD5.CBDC8C55BED17C0618229D87CFDF4CE7] - 2011-03-20 - 03:29:47 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrplk.lrc [180224]

O44 - LFC:[MD5.0A0A59E2D0E603177D3A5EB344B85F7E] - 2011-03-20 - 03:29:47 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrptb.lrc [180224]

O44 - LFC:[MD5.64FB5E977620AC7D9426C775A5DA47A0] - 2011-03-20 - 03:29:48 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrptg.lrc [180224]

O44 - LFC:[MD5.DA4CCD2608C0E8DDF2CED77292B80FBA] - 2011-03-20 - 03:29:48 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrrus.lrc [180224]

O44 - LFC:[MD5.3C551293D5D7A88F2300D8B3D0C65727] - 2011-03-20 - 03:29:48 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrsky.lrc [176128]

O44 - LFC:[MD5.DB982EBA97C5F24DF8C809B602EAB677] - 2011-03-20 - 03:29:48 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrslv.lrc [172032]

O44 - LFC:[MD5.0F1154C31228E044805C03649B960A52] - 2011-03-20 - 03:29:48 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrsve.lrc [176128]

O44 - LFC:[MD5.B921A78EF1B3E4907D4A35467A11F429] - 2011-03-20 - 03:29:48 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrtha.lrc [163840]

O44 - LFC:[MD5.7ADECA447E7E253DF346BC1E31DF0365] - 2011-03-20 - 03:29:49 ---A- . (.Intel Corporation - OpenGL® Driver for Intel® Graphics Acce.) -- C:\Windows\System32\ig4icd32.dll [2420736]

O44 - LFC:[MD5.EBEDD4406281CF885EA488569C4A1600] - 2011-03-20 - 03:29:49 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrcsy.lrc [176128]

O44 - LFC:[MD5.A25646C6751A557C9EE6DDC0C157A603] - 2011-03-20 - 03:29:49 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrell.lrc [192512]

O44 - LFC:[MD5.2B09B3C05933CBC0B710DC4381A2B26B] - 2011-03-20 - 03:29:49 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrhun.lrc [184320]

O44 - LFC:[MD5.EE996847D89FB31F284B47A82A00DCF7] - 2011-03-20 - 03:29:49 ---A- . (.Intel Corporation - igfxres Module.) -- C:\Windows\System32\igfxrtrk.lrc [172032]

O44 - LFC:[MD5.383FD7C95B7C0CAEF338DF6A78E3FD23] - 2011-03-20 - 03:29:50 ---A- . (.Intel Corporation - OpenGL® Device Driver for Intel® Graphi.) -- C:\Windows\System32\ig4dev32.dll [2174976]

O44 - LFC:[MD5.9477D99EDC98D62063FBA80E7B6D7A7E] - 2011-03-20 - 07:56:03 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1497962]

O44 - LFC:[MD5.9552F2020B5953E76BA7FF2D3671964D] - 2011-03-20 - 07:56:03 ---A- . (...) -- C:\Windows\System32\perfc009.dat [104284]

O44 - LFC:[MD5.DE410084E12A770A32FBCB618DD0DE18] - 2011-03-20 - 07:56:03 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [126798]

O44 - LFC:[MD5.C0466014288F888B50F57C401C0B8D35] - 2011-03-20 - 07:56:03 ---A- . (...) -- C:\Windows\System32\perfh009.dat [596210]

O44 - LFC:[MD5.B0F1B7305913E5AF2865C40533FD3CB2] - 2011-03-20 - 07:56:03 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [679552]

O44 - LFC:[MD5.4C9C5F3CE02000102B954F767BFA7E41] - 2011-03-20 - 14:11:23 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]

O44 - LFC:[MD5.28EF12005489197600ECFD7FFCEF1200] - 2011-03-20 - 14:18:20 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1334160]




---\\ MountPoints2 Shell Key (O51)

O51 - MPSK:{c40f894f-2e25-11df-8da7-001d9265f71c}\AutoRun\command. (.Microsoft Corporation - Démarrer le programme Assistant Réseau sans fil.) -- C:\Windows\System32\setupSNK.exe




---\\ Trojan Driver Search Data (HKLM) (O52)

O52 - TDSD: \Drivers32\"VIDC.I420"="lvcodec2.dll" . (.Logitech Inc. - Video Codec.) -- C:\Windows\System32\lvcodec2.dll

O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm

O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll

O52 - TDSD: \Drivers32\"msacm.l3codecp"="l3codecp.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Audio Layer-3 Codec for MSACM.) -- C:\Windows\System32\l3codecp.acm

O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\Windows\System32\ir50_32.dll

O52 - TDSD: \Drivers32\"vidc.iv41"="" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\Windows\System32\

O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (.Intel® Corporation - Pas de description.) -- C:\Windows\System32\ir32_32.dll

O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (.Intel® Corporation - Pas de description.) -- C:\Windows\System32\ir32_32.dll

O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm

O52 - TDSD: \drivers.desc\"ir32_32.dll"="Indeo® video R3.2 by Intel" . (.Pas de propriétaire - Pas de description.) -- (.not file.)

O52 - TDSD: \drivers.desc\""="Indeo® video interactive R4.3 by Intel" . (.Pas de propriétaire - Pas de description.) -- (.not file.)

O52 - TDSD: \drivers.desc\"ir50_32.dll"="Indeo® Video 5,10" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\Windows\System32\ir50_32.dll

O52 - TDSD: \drivers.desc\"iyvu9_32.dll"="Indeo® video Raw YVU9 by Intel" . (.Pas de propriétaire - Pas de description.) -- C:\Windows\System32\iyvu9_32.dll

O52 - TDSD: \drivers.desc\"C:\Windows\system32\"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\Windows\system32\




---\\ ShareTools MSconfig StartupReg (O53)

O53 - SMSR:HKLM\...\startupreg\Adobe Reader Speed Launcher [Key] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

O53 - SMSR:HKLM\...\startupreg\iTunesHelper [Key] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\iTunes\iTunesHelper.exe

O53 - SMSR:HKLM\...\startupreg\KiweeHook [Key] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Kiwee Toolbar\3.2\kwtbaim.exe

O53 - SMSR:HKLM\...\startupreg\LogitechCommunicationsManager [Key] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe

O53 - SMSR:HKLM\...\startupreg\LogitechQuickCamRibbon [Key] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Labtec\WebCam10\WebCam10.exe

O53 - SMSR:HKLM\...\startupreg\QuickTime Task [Key] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe




---\\ Microsoft Control Security Providers (O54)

O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TS Single Sign On Security Package.) -- C:\Windows\system32\credssp.dll

O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TS Single Sign On Security Package.) -- C:\Windows\system32\credssp.dll




---\\ Microsoft Windows Policies System (O55)

O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=2

O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1

O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1

O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0

O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0

O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=

O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=

O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0

O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1

O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1

O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0

O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0




---\\ Microsoft Windows Policies Explorer (O56)

O56 - MWPE:[HKLM\...\policies\Explorer] - "BindDirectlyToPropertySetStorage"=0




---\\ Liste des Drivers Système (O58)

O58 - SDL:[MD5.F8A6018193BE629B8EA4C5D7B2452B70] - 2004-09-16 - 12:26:40 ---A- . (...) -- C:\Windows\system32\drivers\ADFUUD.SYS [12634]

O58 - SDL:[MD5.04F0FCAC69C7C71A3AC4EB97FAFC8303] - 2008-01-20 - 21:23:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\system32\drivers\adp94xx.sys [422968]

O58 - SDL:[MD5.60505E0041F7751BDBB80F88BF45C2CE] - 2008-01-20 - 21:23:25 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\system32\drivers\adpahci.sys [300600]

O58 - SDL:[MD5.8A42779B02AEC986EAB64ECFC98F8BD7] - 2008-01-20 - 21:23:26 ---A- . (.Adaptec, Inc. - Adaptec LH Ultra160 Driver (x86).) -- C:\Windows\system32\drivers\adpu160m.sys [101432]

O58 - SDL:[MD5.241C9E37F8CE45EF51C3DE27515CA4E5] - 2008-01-20 - 21:23:27 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\system32\drivers\adpu320.sys [149560]

O58 - SDL:[MD5.9EAEF5FC9B8E351AFA7E78A6FAE91F91] - 2008-01-20 - 21:23:00 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\system32\drivers\aliide.sys [17464]

O58 - SDL:[MD5.5D2888182FB46632511ACEE92FDAD522] - 2008-01-20 - 21:23:23 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\system32\drivers\arc.sys [79416]

O58 - SDL:[MD5.5E2A321BD7C8B3624E41FDEC3E244945] - 2008-01-20 - 21:23:24 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\system32\drivers\arcsas.sys [79928]

O58 - SDL:[MD5.1C2E6BB4FE8621B1B863855B02BC33EB] - 2011-02-23 - 09:54:55 ---A- . (.AVAST Software - avast! File System Access Blocking Driver.) -- C:\Windows\system32\drivers\aswFsBlk.sys [19544]

O58 - SDL:[MD5.B0F137F664F10829CD2380B0E20E7C29] - 2011-02-23 - 09:55:03 ---A- . (.AVAST Software - avast! File System Minifilter for Windows 2003/Vista.) -- C:\Windows\system32\drivers\aswMonFlt.sys [53592]

O58 - SDL:[MD5.B6A9373619D851BE80FB5F1B5EED0D4E] - 2011-02-23 - 09:55:10 ---A- . (.AVAST Software - avast! TDI RDR Driver.) -- C:\Windows\system32\drivers\aswRdr.sys [25432]

O58 - SDL:[MD5.9BE41C1AE8BC481EB662D85C98D979C2] - 2011-02-23 - 09:56:55 ---A- . (.AVAST Software - avast! Virtualization Driver.) -- C:\Windows\system32\drivers\aswSnx.sys [371544]

O58 - SDL:[MD5.4B1A54BA2BC5873A774DF6B70AB8B0B3] - 2011-02-23 - 09:56:45 ---A- . (.AVAST Software - avast! self protection module.) -- C:\Windows\system32\drivers\aswSP.sys [301528]

O58 - SDL:[MD5.C7F1CEA32766184911293F4E1EE653F5] - 2011-02-23 - 09:55:49 ---A- . (.AVAST Software - avast! TDI Filter Driver.) -- C:\Windows\system32\drivers\aswTdi.sys [49240]

O58 - SDL:[MD5.BC12F2404BB6F2B6B2FF3C4C246CB752] - 2009-12-11 - 16:20:49 ---A- . (.AVG Technologies CZ, s.r.o. - AVG AVI Loader Driver.) -- C:\Windows\system32\drivers\avgldx86.sys [335240]

O58 - SDL:[MD5.5903D729D4F0C5BCA74123C96A1B29E0] - 2009-12-11 - 16:20:49 ---A- . (.AVG Technologies CZ, s.r.o. - AVG Resident Shield Minifilter Driver.) -- C:\Windows\system32\drivers\avgmfx86.sys [27784]

O58 - SDL:[MD5.92D8E1E8502E649B60E70074EB29C380] - 2009-12-11 - 16:20:45 ---A- . (.AVG Technologies CZ, s.r.o. - AVG Network connection watcher.) -- C:\Windows\system32\drivers\avgtdix.sys [108552]

O58 - SDL:[MD5.9F9ACC7F7CCDE8A15C282D3F88B43309] - 2006-11-02 - 03:24:45 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\system32\drivers\BrFiltLo.sys [13568]

O58 - SDL:[MD5.56801AD62213A41F6497F96DEE83755A] - 2006-11-02 - 03:24:46 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\system32\drivers\BrFiltUp.sys [5248]

O58 - SDL:[MD5.B304E75CFF293029EDDF094246747113] - 2006-11-02 - 03:25:24 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\system32\drivers\BrSerId.sys [71808]

O58 - SDL:[MD5.203F0B1E73ADADBBB7B7B1FABD901F6B] - 2006-11-02 - 03:24:44 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\system32\drivers\BrSerWdm.sys [62336]

O58 - SDL:[MD5.BD456606156BA17E60A04E18016AE54B] - 2006-11-02 - 03:24:44 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\system32\drivers\BrUsbMdm.sys [12160]

O58 - SDL:[MD5.AF72ED54503F717A43268B3CC5FAEC2E] - 2006-11-02 - 03:24:47 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\system32\drivers\BrUsbSer.sys [11904]

O58 - SDL:[MD5.0CA25E686A4928484E9FDABD168AB629] - 2008-01-20 - 21:23:00 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\cmdide.sys [19000]

O58 - SDL:[MD5.AE1FDF7BF7BB6C6A70F67699D880592A] - 2006-11-02 - 04:50:11 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\system32\drivers\djsvs.sys [71272]

O58 - SDL:[MD5.5425F74AC0C1DBD96A1E04F17D63F94C] - 2008-01-20 - 21:23:24 ---A- . (.Intel Corporation - Pilote désérialisé NDIS 6 de la carte Intel® PRO/1000.) -- C:\Windows\system32\drivers\E1G60I32.sys [118784]

O58 - SDL:[MD5.23B62471681A124889978F6295B3F4C6] - 2008-01-20 - 21:23:22 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\system32\drivers\elxstor.sys [342584]

O58 - SDL:[MD5.B283F1BC1FF852BD232449A4B3E3CE63] - 2006-05-18 - 09:48:50 ---A- . (.FTDI Ltd. - FTDIBUS USB Driver.) -- C:\Windows\system32\drivers\ftdibus.sys [47249]

O58 - SDL:[MD5.678A73F56DDF84A08C31123C386E9967] - 2006-05-18 - 09:49:02 ---A- . (.FTDI Ltd. - FTDIBUS Serial Device Driver.) -- C:\Windows\system32\drivers\ftser2k.sys [61067]

O58 - SDL:[MD5.16EE7B23A009E00D835CDB79574A91A6] - 2008-01-20 - 21:23:26 ---A- . (.Hewlett-Packard Company - Smart Array Storport Driver.) -- C:\Windows\system32\drivers\HpCISSs.sys [40504]

O58 - SDL:[MD5.FE440536BD98AF772130DC3A6FE1915F] - 2008-05-08 - 04:05:18 ---A- . (.Conexant Systems, Inc. - HSF_HWB2 WDM driver.) -- C:\Windows\system32\drivers\HSXHWBS2.sys [266752]

O58 - SDL:[MD5.72CC6A8CA7891031D6380DB5025C773C] - 2008-05-08 - 04:04:16 ---A- . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- C:\Windows\system32\drivers\HSX_CNXT.sys [661504]

O58 - SDL:[MD5.88749FBF8BEB18C90E7D6626C8C1910B] - 2008-05-08 - 04:03:18 ---A- . (.Conexant Systems, Inc. - HSF_DP driver.) -- C:\Windows\system32\drivers\HSX_DP.sys [980992]

O58 - SDL:[MD5.54155EA1B0DF185878E0FC9EC3AC3A14] - 2008-01-20 - 21:23:23 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver (base).) -- C:\Windows\system32\drivers\iaStorV.sys [235064]

O58 - SDL:[MD5.62F534791AE488A475A3E508D92AF4CC] - 2008-03-25 - 15:44:24 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\system32\drivers\igdkmd32.sys [2307072]

O58 - SDL:[MD5.2D077BF86E843F901D8DB709C95B49A5] - 2006-11-02 - 04:50:17 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\system32\drivers\iirsp.sys [41576]

O58 - SDL:[MD5.BCED60D16156E428F8DF8CF27B0DF150] - 2006-11-02 - 04:50:07 ---A- . (.Integrated Technology Express, Inc. - ITE IT8211 ATA/ATAPI SCSI miniport.) -- C:\Windows\system32\drivers\iteatapi.sys [35944]

O58 - SDL:[MD5.06FA654504A498C30ADCA8BEC4E87E7E] - 2006-11-02 - 04:50:09 ---A- . (.Integrated Technology Express, Inc. - ITE IT8212 ATA RAID SCSI miniport.) -- C:\Windows\system32\drivers\iteraid.sys [35944]

O58 - SDL:[MD5.C7E15E82879BF3235B559563D4185365] - 2008-01-20 - 21:23:23 ---A- . (.LSI Logic - LSI Logic Fusion-MPT FC Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_fc.sys [96312]

O58 - SDL:[MD5.EE01EBAE8C9BF0FA072E0FF68718920A] - 2008-01-20 - 21:23:25 ---A- . (.LSI Logic - LSI Logic Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas.sys [89656]

O58 - SDL:[MD5.912A04696E9CA30146A62AFA1463DD5C] - 2008-01-20 - 21:23:23 ---A- . (.LSI Logic - LSI Logic Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_scsi.sys [96312]

O58 - SDL:[MD5.D395B2DC1705454AA36A34099E066DF0] - 2007-03-06 - 16:49:20 ---A- . (.Labtec Inc. - Labtec Video Driver.) -- C:\Windows\system32\drivers\LV561AV.SYS [491168]

O58 - SDL:[MD5.A6919138F29AE45E90E99FA94737E04C] - 2008-07-26 - 07:25:02 ---A- . (...) -- C:\Windows\system32\drivers\LVPr2Mon.sys [25624]

O58 - SDL:[MD5.23F8EF78BB9553E465A476F3CEE5CA18] - 2008-07-26 - 10:26:20 ---A- . (.Logitech Inc. - USB Statistic Driver.) -- C:\Windows\system32\drivers\LVUSBSta.sys [41752]

O58 - SDL:[MD5.836E0E09CA9869BE7EB39EF2CF3602C7] - 2010-12-20 - 18:08:40 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\system32\drivers\mbam.sys [20952]

O58 - SDL:[MD5.D68E165C3123ABA3B1282EDDB4213BD8] - 2010-12-20 - 18:09:00 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\system32\drivers\mbamswissarmy.sys [38224]

O58 - SDL:[MD5.0CEA2D0D3FA284B85ED5B68365114F76] - 2006-06-19 - 09:26:58 ---A- . (.Conexant - Diagnostic Interface x86 Driver.) -- C:\Windows\system32\drivers\mdmxsdk.sys [12672]

O58 - SDL:[MD5.0001CE609D66632FA17B84705F658879] - 2008-01-20 - 21:23:27 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows Vista/Longhorn for x.) -- C:\Windows\system32\drivers\megasas.sys [31288]

O58 - SDL:[MD5.C252F32CD9A49DBFC25ECF26EBD51A99] - 2008-01-20 - 21:23:27 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\system32\drivers\MegaSR.sys [386616]

O58 - SDL:[MD5.4FBBB70D30FD20EC51F80061703B001E] - 2006-11-02 - 04:49:59 ---A- . (.LSI Logic Corporation - MegaRAID RAID Controller Driver for Windows Vista/Longhorn for.) -- C:\Windows\system32\drivers\Mraid35x.sys [33384]

O58 - SDL:[MD5.2E7FB731D4790A1BC6270ACCEFACB36E] - 2006-11-02 - 04:50:19 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\system32\drivers\nfrd960.sys [45160]

O58 - SDL:[MD5.E875C093AEC0C978A90F30C9E0DFBB72] - 2006-11-02 - 02:36:50 ---A- . (.N-trig Innovative Technologies - Pilote intégré de digitalisateur de tablette N-trig.) -- C:\Windows\system32\drivers\ntrigdigi.sys [20608]

O58 - SDL:[MD5.2EDF9E7751554B42CBB60116DE727101] - 2008-01-20 - 21:23:21 ---A- . (.NVIDIA Corporation - NVIDIA® nForce RAID Driver.) -- C:\Windows\system32\drivers\nvraid.sys [102968]

O58 - SDL:[MD5.ABED0C09758D1D97DB0042DBB2688177] - 2008-01-20 - 21:23:21 ---A- . (.NVIDIA Corporation - NVIDIA® nForce Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor.sys [45112]

O58 - SDL:[MD5.3379E7A840DE135FB7A829E03BC9CC25] - 2008-12-18 - 11:16:56 ---A- . (.PC Tools - PC Tools App Monitor Driver.) -- C:\Windows\system32\drivers\PCTAppEvent.sys [73840]

O58 - SDL:[MD5.AA9CFA67850893FBB168B9C4E4C86952] - 2009-04-03 - 10:18:26 ---A- . (.PC Tools - PC Tools KDS Core Driver.) -- C:\Windows\system32\drivers\PCTCore.sys [130936]

O58 - SDL:[MD5.5AA75B88E57AEDF7FDB1F6B5196AD8A6] - 2008-12-10 - 10:36:04 ---A- . (.PC Tools - PC Tools SG Plugin Driver.) -- C:\Windows\system32\drivers\pctplsg.sys [64392]

O58 - SDL:[MD5.0A6DB55AFB7820C99AA1F3A1D270F4F6] - 2008-01-20 - 21:23:24 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\system32\drivers\ql2300.sys [1122360]

O58 - SDL:[MD5.81A7E5C076E59995D54BC1ED3A16E60B] - 2006-11-02 - 04:50:35 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\system32\drivers\ql40xx.sys [106088]

O58 - SDL:[MD5.5D26CCB06E1F3B5C26E863DF3F4F2611] - 2008-07-03 - 16:03:48 ---A- . (.Realtek Semiconductor Corp. - Realtek® High Definition Audio Function Driver.) -- C:\Windows\system32\drivers\RTKVHDA.sys [2152088]

O58 - SDL:[MD5.C347A3CDE57077056E7E73D3498F7D7D] - 2007-10-03 - 11:18:12 ---A- . (.Realtek Corporation - Realtek 8101E/8168/8169 NDIS6 32-bit Driver.) -- C:\Windows\system32\drivers\Rtlh86.sys [99840]

O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 2006-11-02 - 01:37:21 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\system32\drivers\secdrv.sys [20480]

O58 - SDL:[MD5.A99C6C8B0BAA970D8AA59DDC50B57F94] - 2008-01-20 - 21:23:26 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\system32\drivers\sisraid4.sys [74808]

O58 - SDL:[MD5.192AA3AC01DF071B541094F251DEED10] - 2006-11-02 - 04:50:05 ---A- . (.LSI Logic - LSI Logic 8XX SCSI Miniport Driver.) -- C:\Windows\system32\drivers\symc8xx.sys [35944]

O58 - SDL:[MD5.8C8EB8C76736EBAF3B13B633B2E64125] - 2006-11-02 - 04:49:56 ---A- . (.LSI Logic - LSI Logic Hi-Perf SCSI Miniport Driver.) -- C:\Windows\system32\drivers\sym_hi.sys [31848]

O58 - SDL:[MD5.8072AF52B5FD103BBBA387A1E49F62CB] - 2006-11-02 - 04:50:03 ---A- . (.LSI Logic - LSI Logic Ultra160 SCSI Miniport Driver.) -- C:\Windows\system32\drivers\sym_u3.sys [34920]

O58 - SDL:[MD5.9224BB254F591DE4CA8D572A5F0D635C] - 2008-01-20 - 21:23:20 ---A- . (.ULi Electronics Inc. - ULi SATA Controller Driver.) -- C:\Windows\system32\drivers\uliahci.sys [238648]

O58 - SDL:[MD5.8514D0E5CD0534467C5FC61BE94A569F] - 2006-11-02 - 04:50:35 ---A- . (.Promise Technology, Inc. - Promise Ultra/Sata Series Driver for Win2003.) -- C:\Windows\system32\drivers\ulsata.sys [98408]

O58 - SDL:[MD5.38C3C6E62B157A6BC46594FADA45C62B] - 2008-01-20 - 21:23:23 ---A- . (.Promise Technology, Inc. - Promise SATAII150 Series Windows Drivers.) -- C:\Windows\system32\drivers\ulsata2.sys [115816]

O58 - SDL:[MD5.AADF5587A4063F52C2C3FED7887426FC] - 2008-01-20 - 21:23:00 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\viaide.sys [20024]

O58 - SDL:[MD5.587253E09325E6BF226B299774B728A9] - 2008-01-20 - 21:23:23 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\system32\drivers\vsmraid.sys [130616]

O58 - SDL:[MD5.DAB33CFA9DD24251AAA389FF36B64D4B] - 2007-10-18 - 06:36:54 ---A- . (.Conexant Systems, Inc. - Modem Audio Device Driver.) -- C:\Windows\system32\drivers\XAudio.sys [8704]

O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 2006-11-02 - 02:09:42 ---A- . (...) -- C:\Windows\system32\ANSI.SYS [9029]

O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 2006-11-02 - 02:09:45 ---A- . (...) -- C:\Windows\system32\country.sys [27097]

O58 - SDL:[MD5.E6BC0F98FECEF245A0010D350C1A0B9B] - 2006-11-02 - 02:09:41 ---A- . (...) -- C:\Windows\system32\HIMEM.SYS [4768]

O58 - SDL:[MD5.492090267B9608C62B956CD29BE3AFB7] - 2006-11-02 - 02:09:44 ---A- . (...) -- C:\Windows\system32\KEY01.SYS [42809]

O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 2006-11-02 - 02:09:44 ---A- . (...) -- C:\Windows\system32\KEYBOARD.SYS [42537]

O58 - SDL:[MD5.FFFF296A08DBF2AC0126C62E3778AC0D] - 2006-11-02 - 02:09:29 ---A- . (...) -- C:\Windows\system32\NTDOS.SYS [27866]

O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 2006-11-02 - 02:09:35 ---A- . (...) -- C:\Windows\system32\NTDOS404.SYS [29146]

O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 2006-11-02 - 02:09:38 ---A- . (...) -- C:\Windows\system32\NTDOS411.SYS [29370]

O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 2006-11-02 - 02:09:40 ---A- . (...) -- C:\Windows\system32\NTDOS412.SYS [29274]

O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 2006-11-02 - 02:09:31 ---A- . (...) -- C:\Windows\system32\NTDOS804.SYS [29146]

O58 - SDL:[MD5.2E4112FB7D1B76E11ADFD7487B5D0E95] - 2006-11-02 - 02:09:20 ---A- . (...) -- C:\Windows\system32\NTIO.SYS [33952]

O58 - SDL:[MD5.A98EBD4C2DF983665BF2D1AF49949974] - 2006-11-02 - 02:09:23 ---A- . (...) -- C:\Windows\system32\NTIO404.SYS [34672]

O58 - SDL:[MD5.3F7E6406EDEF197C5CAAB2240EEF6F48] - 2006-11-02 - 02:09:24 ---A- . (...) -- C:\Windows\system32\NTIO411.SYS [35776]

O58 - SDL:[MD5.3E64D681B776CC57BDC38A46D881F85B] - 2006-11-02 - 02:09:26 ---A- . (...) -- C:\Windows\system32\NTIO412.SYS [35536]

O58 - SDL:[MD5.D86B6435729231C171432B4E77801BDB] - 2006-11-02 - 02:09:22 ---A- . (...) -- C:\Windows\system32\NTIO804.SYS [34672]




---\\ Liste des outils de nettoyage (O63)

O63 - Logiciel: ZHPDiag 1.27 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1




---\\ Liste des services Legacy (O64)

O64 - Services: CurCS - C:\Windows\system32\drivers\afd.sys - Ancilliary Function Driver for Winsock (AFD) .(.Microsoft Corporation - Ancillary Function Driver for WinSock.) - LEGACY_AFD

O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWFSBLK.sys - (.not file.) - aswFsBlk (aswFsBlk) .(...) - LEGACY_ASWFSBLK

O64 - Services: CurCS - C:\Windows\system32\drivers\aswMonFlt.sys - aswMonFlt (aswMonFlt) .(.AVAST Software - avast! File System Minifilter for Windows 2.) - LEGACY_ASWMONFLT

O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWRDR.sys - (.not file.) - aswRdr (aswRdr) .(...) - LEGACY_ASWRDR

O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWSNX.sys - (.not file.) - aswSnx (aswSnx) .(...) - LEGACY_ASWSNX

O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWSP.sys - (.not file.) - aswSP (aswSP) .(...) - LEGACY_ASWSP

O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWTDI.sys - (.not file.) - avast! Network Shield Support (aswTdi) .(...) - LEGACY_ASWTDI

O64 - Services: CurCS - C:\Windows\system32\Drivers\avgldx86.sys - AVG AVI Loader Driver x86 (AvgLdx86) .(.AVG Technologies CZ, s.r.o. - AVG AVI Loader Driver.) - LEGACY_AVGLDX86

O64 - Services: CurCS - C:\Windows\system32\Drivers\avgmfx86.sys - AVG On-access Scanner Minifilter Driver x86 (AvgMfx86) .(.AVG Technologies CZ, s.r.o. - AVG Resident Shield Minifilter Driver.) - LEGACY_AVGMFX86

O64 - Services: CurCS - C:\Windows\system32\Drivers\avgtdix.sys - AVG8 Network Redirector (AvgTdiX) .(.AVG Technologies CZ, s.r.o. - AVG Network connection watcher.) - LEGACY_AVGTDIX

O64 - Services: CurCS - C:\Windows\system32\Drivers\BEEP.sys - (.not file.) - Beep (Beep) .(...) - LEGACY_BEEP

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\bowser.sys - Bowser (bowser) .(.Microsoft Corporation - NT Lan Manager Datagram Receiver Driver.) - LEGACY_BOWSER

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\cdfs.sys - CD/DVD File System Reader (cdfs) .(.Microsoft Corporation - CD-ROM File System Driver.) - LEGACY_CDFS

O64 - Services: CurCS - C:\Windows\System32\CLFS.sys - Common Log (CLFS) (CLFS) .(.Microsoft Corporation - Common Log File System Driver.) - LEGACY_CLFS

O64 - Services: CurCS - (.not file.) - CO_Mon (CO_Mon) .(...) - LEGACY_CO_MON

O64 - Services: CurCS - C:\Windows\System32\drivers\crcdisk.sys - Crcdisk Filter Driver (crcdisk) .(.Microsoft Corporation - Disk Block Verification Filter Driver.) - LEGACY_CRCDISK

O64 - Services: CurCS - C:\Windows\system32\drivers\dfsc.sys (DfsC) .(.Microsoft Corporation - DFS Namespace Client Driver.) - LEGACY_DFSC

O64 - Services: CurCS - C:\Windows\system32\drivers\dxgkrnl.sys - LDDM Graphics Subsystem (DXGKrnl) .(.Microsoft Corporation - DirectX Graphics Kernel.) - LEGACY_DXGKRNL

O64 - Services: CurCS - C:\Windows\system32\Drivers\FASTFAT.sys - (.not file.) - FAT12/16/32 File System Driver (fastfat) .(...) - LEGACY_FASTFAT

O64 - Services: CurCS - C:\Windows\System32\drivers\fileinfo.sys - File Information FS MiniFilter (FileInfo) .(.Microsoft Corporation - FileInfo Filter Driver.) - LEGACY_FILEINFO

O64 - Services: CurCS - C:\Windows\System32\drivers\fltmgr.sys - FltMgr (FltMgr) .(.Microsoft Corporation - Gestionnaire de filtres de système de fichi.) - LEGACY_FLTMGR

O64 - Services: CurCS - C:\Windows\system32\Drivers\FS_REC.sys - Fs_Rec (Fs_Rec) .(...) - LEGACY_FS_REC

O64 - Services: CurCS - C:\Windows\System32\drivers\HTTP.sys - HTTP (HTTP) .(.Microsoft Corporation - HTTP Pile du protocole.) - LEGACY_HTTP

O64 - Services: CurCS - (.not file.) - Symantec Intrusion Prevention Driver (IDSvix86) .(...) - LEGACY_IDSVIX86

O64 - Services: CurCS - C:\Windows\System32\Drivers\ksecdd.sys - KSecDD (KSecDD) .(.Microsoft Corporation - Kernel Security Support Provider Interface.) - LEGACY_KSECDD

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\Lbd.sys (.not file.) - Lbd (Lbd) .(...) - LEGACY_LBD

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\lltdio.sys - Link-Layer Topology Discovery Mapper I/O Driver (lltdio) .(.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) - LEGACY_LLTDIO

O64 - Services: CurCS - C:\Windows\system32\drivers\luafv.sys - UAC File Virtualization (luafv) .(.Microsoft Corporation - Pilote de filtre de virtualisation de fichi.) - LEGACY_LUAFV

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\LVPr2Mon.sys - Logitech LVPr2Mon Driver (LVPr2Mon) .(...) - LEGACY_LVPR2MON

O64 - Services: CurCS - C:\Users\mimi\AppData\Local\Temp\mbr.sys (.not file.) - mbr (mbr) .(...) - LEGACY_MBR

O64 - Services: CurCS - (.not file.) - mchInjDrv (mchInjDrv) .(...) - LEGACY_MCHINJDRV

O64 - Services: CurCS - C:\Windows\System32\drivers\mountmgr.sys - Mount Point Manager (MountMgr) .(.Microsoft Corporation - Mount Point Manager.) - LEGACY_MOUNTMGR

O64 - Services: CurCS - C:\Windows\system32\FirewallAPI.dll (mpsdrv) .(.Microsoft Corporation - API du Pare-feu Windows.) - LEGACY_MPSDRV

O64 - Services: CurCS - C:\Windows\system32\drivers\mrxdav.sys - WebDav Client Redirector Driver (MRxDAV) .(.Microsoft Corporation - Windows NT WebDav Minirdr.) - LEGACY_MRXDAV

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\mrxsmb.sys - SMB MiniRedirector Wrapper and Engine (mrxsmb) .(.Microsoft Corporation - Windows NT SMB Minirdr.) - LEGACY_MRXSMB

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\mrxsmb10.sys - SMB 1.x MiniRedirector (mrxsmb10) .(.Microsoft Corporation - Longhorn SMB Downlevel SubRdr.) - LEGACY_MRXSMB10

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\mrxsmb20.sys - SMB 2.0 MiniRedirector (mrxsmb20) .(.Microsoft Corporation - Longhorn SMB 2.0 Redirector.) - LEGACY_MRXSMB20

O64 - Services: CurCS - C:\Windows\system32\Drivers\MSFS.sys - Msfs (Msfs) .(...) - LEGACY_MSFS

O64 - Services: CurCS - C:\Windows\System32\drivers\msisadrv.sys - ISA/EISA Class Driver (msisadrv) .(.Microsoft Corporation - ISA Driver.) - LEGACY_MSISADRV

O64 - Services: CurCS - C:\Windows\System32\Drivers\mup.sys - Mup (Mup) .(.Microsoft Corporation - Multiple UNC Provider driver.) - LEGACY_MUP

O64 - Services: CurCS - C:\Windows\System32\drivers\ndis.sys - NDIS System Driver (NDIS) .(.Microsoft Corporation - NDIS 6.0 wrapper driver.) - LEGACY_NDIS

O64 - Services: CurCS - C:\Windows\system32\Drivers\NDPROXY.sys - NDProxy (NDProxy) .(...) - LEGACY_NDPROXY

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\netbios.sys - NetBIOS Interface (NetBIOS) .(.Microsoft Corporation - NetBIOS interface driver.) - LEGACY_NETBIOS

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\netbt.sys - NETBT (netbt) .(.Microsoft Corporation - MBT Transport driver.) - LEGACY_NETBT

O64 - Services: CurCS - C:\Windows\system32\Drivers\NPFS.sys - Npfs (Npfs) .(...) - LEGACY_NPFS

O64 - Services: CurCS - C:\Windows\System32\drivers\nsiproxy.sys - NSI proxy service (nsiproxy) .(.Microsoft Corporation - NSI Proxy.) - LEGACY_NSIPROXY

O64 - Services: CurCS - C:\Windows\system32\Drivers\NTFS.sys - Ntfs (Ntfs) .(...) - LEGACY_NTFS

O64 - Services: CurCS - C:\Windows\system32\Drivers\NULL.sys - Null (Null) .(...) - LEGACY_NULL

O64 - Services: CurCS - C:\PROGRA~1\PC-DOC~1\PCD5SRVC.pkms (.not file.) - PCD5SRVC{BD6912E3-AC9D80E8-05040000} - PCDR Kernel Mode Service Helper Driver (PCD5SRVC{BD6912E3-AC9D80E8-05040000}) .(...) - LEGACY_PCD5SRVC{BD6912E3-AC9D80E8-05040000}

O64 - Services: CurCS - C:\Windows\System32\drivers\PCTCore.sys - PCTools KDS (PCTCore) .(.PC Tools - PC Tools KDS Core Driver.) - LEGACY_PCTCORE

O64 - Services: CurCS - C:\Windows\System32\drivers\peauth.sys - PEAUTH (PEAUTH) .(.Microsoft Corporation - Protected Environment Authentication and Au.) - LEGACY_PEAUTH

O64 - Services: CurCS - C:\Windows\system32\drivers\pacer.sys (PSched) .(.Microsoft Corporation - Planificateur de paquets QoS.) - LEGACY_PSCHED

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\rasacd.sys - Remote Access Auto Connection Driver (RasAcd) .(.Microsoft Corporation - RAS Automatic Connection Driver.) - LEGACY_RASACD

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\rdbss.sys - Redirected Buffering Sub Sysytem (rdbss) .(.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - LEGACY_RDBSS

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\RDPCDD.sys - RDPCDD (RDPCDD) .(.Microsoft Corporation - RDP Miniport.) - LEGACY_RDPCDD

O64 - Services: CurCS - C:\Windows\System32\drivers\rdpencdd.sys - RDP Encoder Mirror Driver (RDPENCDD) .(.Microsoft Corporation - RDP Miniport.) - LEGACY_RDPENCDD

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\rspndr.sys - Link-Layer Topology Discovery Responder (rspndr) .(.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) - LEGACY_RSPNDR

O64 - Services: CurCS - C:\Windows\system32\Drivers\SECDRV.sys - (.not file.) - Security Driver (secdrv) .(...) - LEGACY_SECDRV

O64 - Services: CurCS - C:\Windows\system32\tcpipcfg.dll (Smb) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_SMB

O64 - Services: CurCS - C:\Windows\system32\Drivers\SPLDR.sys - (.not file.) - Security Processor Loader Driver (spldr) .(...) - LEGACY_SPLDR

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\srv.sys - srv (srv) .(.Microsoft Corporation - Server driver.) - LEGACY_SRV

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\srv2.sys - srv2 (srv2) .(.Microsoft Corporation - Smb 2.0 Server driver.) - LEGACY_SRV2

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\srvnet.sys - srvnet (srvnet) .(.Microsoft Corporation - Server Network driver.) - LEGACY_SRVNET

O64 - Services: CurCS - (.not file.) - SYMDNS (SYMDNS) .(...) - LEGACY_SYMDNS

O64 - Services: CurCS - (.not file.) - SymEvent (SymEvent) .(...) - LEGACY_SYMEVENT

O64 - Services: CurCS - (.not file.) - SYMFW (SYMFW) .(...) - LEGACY_SYMFW

O64 - Services: CurCS - (.not file.) - SYMNDISV (SYMNDISV) .(...) - LEGACY_SYMNDISV

O64 - Services: CurCS - (.not file.) - SYMREDRV (SYMREDRV) .(...) - LEGACY_SYMREDRV

O64 - Services: CurCS - (.not file.) - SYMTDI (SYMTDI) .(...) - LEGACY_SYMTDI

O64 - Services: CurCS - C:\Windows\system32\tcpipcfg.dll (Tcpip) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_TCPIP

O64 - Services: CurCS - C:\Windows\System32\drivers\tcpipreg.sys - TCP/IP Registry Compatibility (tcpipreg) .(.Microsoft Corporation - TCP/IP Registry Compatibility Driver.) - LEGACY_TCPIPREG

O64 - Services: CurCS - C:\Windows\system32\tcpipcfg.dll (tdx) .(.Microsoft Corporation - Objets de configuration du réseau.) - LEGACY_TDX

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\udfs.sys - udfs (udfs) .(.Microsoft Corporation - UDF File System Driver.) - LEGACY_UDFS

O64 - Services: CurCS - C:\Windows\system32\drivers\vga.sys - VgaSave (VgaSave) .(.Microsoft Corporation - VGA/Super VGA Video Driver.) - LEGACY_VGASAVE

O64 - Services: CurCS - C:\Windows\System32\drivers\volmgrx.sys - Dynamic Volume Manager (volmgrx) .(.Microsoft Corporation - Volume Manager Extension Driver.) - LEGACY_VOLMGRX

O64 - Services: CurCS - C:\Windows\System32\drivers\volsnap.sys - Volumes de stockage (volsnap) .(.Microsoft Corporation - Pilote de cliché instantané du volume.) - LEGACY_VOLSNAP

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\wanarp.sys - Remote Access IPv6 ARP Driver (Wanarpv6) .(.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - LEGACY_WANARPV6

O64 - Services: CurCS - C:\Windows\System32\drivers\Wdf01000.sys - Kernel Mode Driver Frameworks service (Wdf01000) .(.Microsoft Corporation - WDF dynamique.) - LEGACY_WDF01000

O64 - Services: CurCS - C:\Windows\System32\DRIVERS\xaudio.sys - XAudio (XAudio) .(.Conexant Systems, Inc. - Modem Audio Device Driver.) - LEGACY_XAUDIO




---\\ File Associations Shell Spawning (O67)

O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] "%1" %* (.not file.)

O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe

O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] "%1" %* (.not file.)

O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] "%1" %* (.not file.)

O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] "%1" %* (.not file.)

O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe

O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe

O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe

O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] "%1" %* (.not file.)

O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe

O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] "%1" %* (.not file.)

O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] "%1" %* (.not file.)

O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] "%1" %* (.not file.)

O67 - Shell Spawning: <.html> <htmlfile>[HKCR\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe

O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe

O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe




---\\ Start Menu Internet (O68)

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe




---\\ Search Browser Infection (O69)

O69 - SBI: SearchScopes [HKCU] {06D5DBFB-0673-4A06-A7F5-C7B1B334E75D} - (Yahoo! Search) - Yahoo! Recherche

O69 - SBI: SearchScopes [HKCU] {0BC6E3FA-78EF-4886-842C-5A1258C4455A} [DefaultScope] - (Search the Web) - Bing

O69 - SBI: SearchScopes [HKCU] {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} - (Ask Search) -

O69 - SBI: SearchScopes [HKCU] {5D228923-218C-4703-B63A-B00AB761059A} - ( - Web Search

O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) - Google

O69 - SBI: SearchScopes [HKUS\.DEFAULT] {0BC6E3FA-78EF-4886-842C-5A1258C4455A} [DefaultScope] - (Search the Web) - Bing

O69 - SBI: SearchScopes [HKUS\S-1-5-18] {0BC6E3FA-78EF-4886-842C-5A1258C4455A} [DefaultScope] - (Search the Web) - Bing




---\\ Firewall Active Exception List (FirewallRules) (O87)

O87 - FAEL: "CoreNet-GP-LSASS-Out-TCP" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Processus de l’autorité de sécurité locale.) -- C:\Windows\system32\lsass.exe

O87 - FAEL: "FPS-SpoolSvc-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe

O87 - FAEL: "FPS-SpoolSvc-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe

O87 - FAEL: "NetPres-Out-TCP" | Out - Public - P6 - FALSE | .(.Microsoft Corporation - Connect to a Network Projector.) -- C:\Windows\system32\netproj.exe

O87 - FAEL: "NetPres-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Connect to a Network Projector.) -- C:\Windows\system32\netproj.exe

O87 - FAEL: "NetPres-WSD-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Connect to a Network Projector.) -- C:\Windows\system32\netproj.exe

O87 - FAEL: "NetPres-WSD-In-UDP" | In - Domain - P17 - FALSE | .(.Microsoft Corporation - Connect to a Network Projector.) -- C:\Windows\system32\netproj.exe

O87 - FAEL: "NetPres-Out-TCP-NoScope" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Connect to a Network Projector.) -- C:\Windows\system32\netproj.exe

O87 - FAEL: "NetPres-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Connect to a Network Projector.) -- C:\Windows\system32\netproj.exe

O87 - FAEL: "RemoteSvcAdmin-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\Windows\system32\services.exe

O87 - FAEL: "RemoteSvcAdmin-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\Windows\system32\services.exe

O87 - FAEL: "WinCollab-Out-UDP" | Out - Domain - P17 - FALSE | .(.Microsoft Corporation - Windows Meeting Space.) -- C:\Program Files\Windows Collaboration\WinCollab.exe

O87 - FAEL: "WinCollab-In-UDP" | In - Domain - P17 - TRUE | .(.Microsoft Corporation - Windows Meeting Space.) -- C:\Program Files\Windows Collaboration\WinCollab.exe

O87 - FAEL: "WinCollab-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Windows Meeting Space.) -- C:\Program Files\Windows Collaboration\WinCollab.exe

O87 - FAEL: "WinCollab-In-TCP" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Windows Meeting Space.) -- C:\Program Files\Windows Collaboration\WinCollab.exe

O87 - FAEL: "WinCollab-DFSR-Out-TCP" | Out - Domain - P6 - FALSE | .(.Microsoft Corporation - Réplication DFS.) -- C:\Windows\system32\dfsr.exe

O87 - FAEL: "WinCollab-DFSR-In-TCP" | In - Domain - P6 - TRUE | .(.Microsoft Corporation - Réplication DFS.) -- C:\Windows\system32\dfsr.exe

O87 - FAEL: "{C02764DB-508F-45F2-B682-C695A17EABA5}" | In - None - P6 - TRUE | .(.CyberLink Corp. - PowerDirector.) -- c:\Program Files\Cyberlink\PowerDirector\PDR.exe

O87 - FAEL: "{94610ADD-A3F2-4AB2-9056-F9D569DB7824}" | In - None - P6 - TRUE | .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe

O87 - FAEL: "{1CF29E06-2485-47EF-883D-4AE24E8B2C4E}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Windows Live\Messenger\livecall.exe (.not file.)

O87 - FAEL: "{64D728AE-EBEB-4597-BB74-32DA4407AEDE}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe

O87 - FAEL: "{5DE70C22-4A94-40D5-8324-9A05F132A8D8}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe

O87 - FAEL: "{5C44A879-CC73-45D7-9C5D-3BABCBC2D911}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files\AVG\AVG8\avgupd.exe (.not file.)

O87 - FAEL: "{D0E8FA24-F650-4494-AF92-A0A2B95AABC2}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files\AVG\AVG8\avgemc.exe (.not file.)

O87 - FAEL: "{FFE72D97-A3C5-44D0-AFD6-9F6EBBF2AD26}" | In - Private - P6 - TRUE | .(.Lime Wire, LLC - LimeWire.) -- C:\Program Files\LimeWire\LimeWire.exe

O87 - FAEL: "{F99EE220-E4A5-464F-A1D6-7FF594102800}" | In - Private - P17 - TRUE | .(.Lime Wire, LLC - LimeWire.) -- C:\Program Files\LimeWire\LimeWire.exe

O87 - FAEL: "{3ED3E828-3A0D-4E3A-BC94-A4F22DA44B3A}" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe

O87 - FAEL: "TCP Query User{C91AC6E3-57EF-4C7F-9B46-8F8D69D1F923}C:\program files\internet explorer\iexplore.exe" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Internet Explorer.) -- C:\program files\internet explorer\iexplore.exe

O87 - FAEL: "UDP Query User{D0C8486B-D9E9-4079-AC30-7AA3127256EE}C:\program files\internet explorer\iexplore.exe" | In - Private - P17 - TRUE | .(.Microsoft Corporation - Internet Explorer.) -- C:\program files\internet explorer\iexplore.exe

O87 - FAEL: "TCP Query User{4FE8AD4F-8450-4673-AE58-D609EB452026}C:\program files\kodak\kodak easyshare software\bin\easyshare.exe" | In - Private - P6 - TRUE | .(.Eastman Kodak Company.) -- C:\program files\kodak\kodak easyshare software\bin\easyshare.e

O87 - FAEL: "UDP Query User{CF3CB13D-404E-4782-8A31-BAC5BD9BFEBE}C:\program files\kodak\kodak easyshare software\bin\easyshare.exe" | In - Private - P17 - TRUE | .(.Eastman Kodak Company.) -- C:\program files\kodak\kodak easyshare software\bin\easyshare.

O87 - FAEL: "{260EE80B-CE4E-4D97-A8D0-AAFB6A48AE5B}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files\AVG\AVG8\avgnsx.exe (.not file.)

O87 - FAEL: "{E1258F9E-3EEF-4BF3-8956-73B198EADE1E}" | In - Private - P6 - TRUE | .(.Radialpoint Inc. - Pas de description.) -- C:\Program Files\Videotron\Videotron Service Agent\ServicepointService.exe

O87 - FAEL: "{F9D2C759-C807-4C1F-8268-1D8AC076B777}" | In - Private - P17 - TRUE | .(.Radialpoint Inc. - Pas de description.) -- C:\Program Files\Videotron\Videotron Service Agent\ServicepointService.exe

O87 - FAEL: "TCP Query User{69595D1F-289D-48D0-98AE-DAC79988F70B}C:\program files\limewire\limewire.exe" | In - Public - P6 - TRUE | .(.Lime Wire, LLC - LimeWire.) -- C:\program files\limewire\limewire.exe

O87 - FAEL: "UDP Query User{7DE2F1AD-8290-40BB-BA10-3C996DD0AE31}C:\program files\limewire\limewire.exe" | In - Public - P17 - TRUE | .(.Lime Wire, LLC - LimeWire.) -- C:\program files\limewire\limewire.exe

O87 - FAEL: "{8BEE8F4F-358B-432F-AE52-BDD878AAACA1}" | In - None - P17 - TRUE | .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe

O87 - FAEL: "{690BA04F-8129-42DA-86F7-5A463E42564D}" | In - Public - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe

O87 - FAEL: "{7FD13AC5-A9A3-44FC-8E05-D693CBE80620}" | In - Public - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe




---\\ Scan additionnel (O88)

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}] =>Adware.AskSBar

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}] =>Adware.AskSBar

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}] =>Adware.AskSBar

[HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{D4027C7F-154A-4066-A1AD-4243D8127440} =>Adware.AskSBar

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}] =>Adware.AskSBar

[HKLM\Software\Classes\AppID\EoRezoBHO.DLL] =>PUP.Eorezo

[HKLM\Software\Classes\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}] =>PUP.Eorezo

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]:Eoweather =>PUP.Eorezo

[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdate_is1] =>PUP.Eorezo

[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}] =>Toolbar.Kiwee

C:\Program Files\ =>Adware.AskBar

C:\Users\mimi\AppData\Roaming\\EoRezo =>PUP.Eorezo

C:\ProgramData\AGI =>Toolbar.Kiwee




---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)

SR - | Auto 2010-01-26 20480 | (AGCoreService) . (.AG Interactive.) - C:\Program Files\AGI\core\\AGCoreService.exe

SS - | Auto 2010-01-26 0 | (AGWinService) . (...) - C:\Program Files\AGI\common\win32\PythonService.exe

SR - | Auto 2008-02-18 110592 | (Apple Mobile Device) . (.Apple, Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

SR - | Auto 2011-02-23 42184 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

SS - | Auto 2011-02-23 0 | (avg8emc) . (...) - C:\PROGRA~1\AVG\AVG8\avgemc.exe

SS - | Auto 2011-02-23 0 | (avg8wd) . (...) - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

SR - | Auto 2008-12-12 238888 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe

SS - | Auto 2010-02-10 135664 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe

SR - | Auto 2007-09-19 65536 | (HP Health Check Service) . (.Hewlett-Packard.) - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe

SR - | Auto 2009-03-17 73728 | (LightScribeService) . (.Hewlett-Packard Company.) - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

SR - | Auto 2008-07-26 186904 | (LVCOMSer) . (.Logitech Inc..) - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

SR - | Auto 2008-07-26 150040 | (LVPrcSrv) . (.Logitech Inc..) - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

SS - | Demand 2008-07-26 0 | (PCD5SRVC{BD6912E3-AC9D80E8-05040000}) . (...) - C:\PROGRA~1\PC-DOC~1\PCD5SRVC.pkms

SR - | Auto 2009-10-09 578800 | (ServicepointService) . (.Radialpoint Inc..) - C:\Program Files\Videotron\Videotron Service Agent\ServicepointService.exe

SR - | Auto 2008-01-20 21504 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\system32\svchost.exe

SR - | Auto 2007-10-18 386560 | (XAudioService) . (.Conexant Systems, Inc..) - C:\Windows\system32\DRIVERS\xaudio.exe




---\\ Recherche Master Boot Record Infection (MBR)(O80)

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.1 by Gmer, GMER - Rootkit Detector and Remover

Run by mimi at 2011-03-20 15:56:00


device: opened successfully

user: MBR read successfully


Disk trace:

called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys

1 ntkrnlpa!IofCallDriver[0x8288A912] -> \Device\Harddisk0\DR0[0x85B87AC8]

3 CLASSPNP[0x837A98B3] -> ntkrnlpa!IofCallDriver[0x8288A912] -> [0x852C6918]

5 acpi[0x8069C6BC] -> ntkrnlpa!IofCallDriver[0x8288A912] -> \Device\Ide\IdeDeviceP0T0L0-0[0x852BFA38]

kernel: MBR read successfully

user & kernel MBR OK




---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)

Written by ad13, http://ad13.geekstog

Run by mimi at 2011-03-20 15:56:02

Use the desktop link 'MBRCheck' to have full report

Dump file Name : C:\PhysicalDisk0_MBR.bin




End of the scan (1298 lines in 01mn 43s)(0)



Merci encore :)

  • Modérateurs
Posté(e) (modifié)



Ton PC est infecté : il y a 16 malwares... étonnant que MBAM n'ait rien trouvé :


R3 - URLSearchHook: agihelper.AGUtils - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) (4.0.31106.0 (Main.031106-0000)) -- mscoree.dll => Infection BT (AGI Toolbar)

O42 - Logiciel: SoftwareUpdate 1.5 - (.EoRezo.) [HKLM] -- SoftwareUpdate_is1 => Infection PUP (PUP.Eorezo)

[HKCU\Software\AppDataLow\Software\Smart-Shopper] => Infection BT

O43 - CFD: 2010-12-10 - 03:14:46 - [1618] ----D- C:\Program Files\ => Infection BT (Adware.AskBarDis)

O43 - CFD: 2010-03-12 - 22:33:16 - [254582] ----D- C:\Program Files\UnifiedToolbar => Infection BT

O43 - CFD: 2010-12-09 - 10:00:30 - [7928291] ----D- C:\Users\mimi\AppData\Roaming\EoRezo => Infection PUP (PUP.Eorezo)

O53 - SMSR:HKLM\...\startupreg\KiweeHook [Key] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Kiwee Toolbar\3.2\kwtbaim.exe => Infection BT (KiweeToolbar)

O69 - SBI: SearchScopes [HKCU] {0BC6E3FA-78EF-4886-842C-5A1258C4455A} [DefaultScope] - (Search the Web) - Bing => Infection BT (AGI Toolbar)

O69 - SBI: SearchScopes [HKUS\.DEFAULT] {0BC6E3FA-78EF-4886-842C-5A1258C4455A} [DefaultScope] - (Search the Web) - Bing => Infection BT (AGI Toolbar)

O69 - SBI: SearchScopes [HKUS\S-1-5-18] {0BC6E3FA-78EF-4886-842C-5A1258C4455A} [DefaultScope] - (Search the Web) - Bing => Infection BT (AGI Toolbar)

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}] =>Adware.AskSBar => Infection BT (AskSBar.Adw)

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}] =>Adware.AskSBar => Infection BT (AskSBar.Adw)

[HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{D4027C7F-154A-4066-A1AD-4243D8127440} =>Adware.AskSBar => Infection BT (AskSBar.Adw)

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}] =>Adware.AskSBar => Infection BT (AskSBar.Adw)

[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}] =>Toolbar.Kiwee => Infection BT (AGI Toolbar)

C:\ProgramData\AGI =>Toolbar.Kiwee


Malware (16)

A faire stp :


  • Je te conseille d'ouvrir un nouveau sujet dans la section "Analyse et éradication des malwares", afin de procéder à une bonne désinfection :
  • De manière à ce que le helper qui te prendra en charge soit informé des manips déjà effectuées, merci de copier/coller en début de ton nouveau sujet le lien avec le présent sujet (tu le trouveras en cliquant sur le n° du présent Post)

Bonne continuation,


Modifié par Tonton57



Je te remercie beaucoup et je vais suivre ton conseil et démarrer un nouveau sujet. J'en reviens pas que mon PC soit infecté autant.


Je viens de voir que j'ai 71 éléments infectés en quarantaine, peut-être que ceux que l'on voient sont ceux la???


J'aimerais savoir si je dois conserver les icônes sur mon bureau de:





ZHPDiag: bloc note


Merci :)

Salut Tournedos, ;)


De manière à ne pas interférer ds le processus de désinfection en cours (il est impératif de ne pas traiter 1 même sujet par 2 helpers en même temps, au risque d'occasionner de graves dommages au système), je préfère que tu poses la question à l'ami pear ( ;) ) qui t'a pris en charge.


Je reste bien entendu à ta disposition pour toute question, mais après la finalisation de la désinfection.


Sur ce, bonne soirée et à bientôt ! ;)


Modifié par Tonton57
