Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés




Mon laptop S/s Windows Vista est fortement ralenti et ne réagit plus normalement.


Certaines applications ne se lance plus (pas même en administrateur) c'est le cas pour Malwarebytes


et au lancement de certaines applications le centre de sécurité me demande l'autorisation pour lancer celles-ci ! exemple pour Google Chrome, Firefox


Enfin les pages de recherche ne sont pas affichés et je tombe sur des pages diverses de publicité


Merci par avance pour votre aide




Lancez cet outil de diagnostic:

Téléchargez ZhpDiag de Coolman

Décompresser le fichier ZHPDiag.fix sur le bureau

puis double-cliquer sur le fichier ZHPDiag.exe pour installer l'outil

Sur le bureau ,il y aura 3 icôneszhp0710.png


Sous XP, double clic sur ZhpDiag

Sous Vista/7, faire un clic droit et Exécuter en tant qu'administrateur


Clic sur la Loupe pour lancer le scan

En cas de blocage sur O80, cliquez sur le tournevis pour le décocher

Postez en le rapport ZhpDiag.txt qui apparait sur le bureau

Comment poster les rapports

Vous copiez/collez tout ou partie des rapports dans un ou plusieurs messages.

Autre solution:

Aller sur le site :Ci-Jointicne2cjoint.png

Appuyez sur Parcourir et chercher les rapports sur le disque,

Ensuite appuyez sur Créer le lien CJoint,

>> dans la page suivante --> ,,

une adresse http//.. sera créée

Copier /coller cette adresse dans votre prochain message.





Voici le rapport :


Rapport de ZHPDiag v1.28.1346 par Nicolas Coolman, Update du 29/08/2011

Run by Matt at 08/09/2011 23:22:14

Web site : ZHPDiag Outil de diagnostic



---\\ Web Browser

MSIE: Internet Explorer v7.0.6000.17037

MFIE: Mozilla Firefox 6.0.1 v6.0.1 (Defaut)


---\\ Windows Product Information

Windows Vista Home Premium Edition, 32-bit (Build 6000)

Windows Server License Manager Script : OK

~ Vista, OEM_SLP channel

System Locked Preinstallation (OEM_SLP) : OK

Windows ID Activation : OK

~ Windows Partial Key : G6MF9

Windows License : OK

Windows Automatic Updates : OK


---\\ System Information

~ Processor: x86 Family 6 Model 15 Stepping 6, GenuineIntel

~ Operating System: 32 Bits

Boot mode: Normal (Normal boot)

Total RAM: 2045 MB (68% free)

System Restore: Activé (Enable)

System drive C: has 29 GB (20%) free of 140 GB


---\\ Logged in mode

~ Computer Name: PC-DE-MATT

~ User Name: Matt

~ All Users Names: Matt, Administrateur,

~ Unselected Option: O45,O61,O62,O65,O66,O82

Logged in as Administrator


---\\ Environnement Variables

~ System Unit : C:\

~ %AppData% : C:\Users\Matt\AppData\Roaming\

~ %Desktop% : C:\Users\Matt\Desktop\

~ %Favorites% : C:\Users\Matt\Favorites\

~ %LocalAppData% : C:\Users\Matt\AppData\Local\

~ %StartMenu% : C:\Users\Matt\AppData\Roaming\Microsoft\Windows\Start Menu\

~ %Windir% : C:\Windows\

~ %System% : C:\Windows\system32\


---\\ DOS/Devices

C:\ Hard drive, Flash drive, Thumb drive (Free 29 Go of 140 Go)

D:\ Floppy drive, Flash card reader, USB Key (Free 51 Go of 60 Go)

E:\ CD-ROM drive (Not Inserted)

F:\ CD-ROM drive (Not Inserted)

G:\ Floppy drive, Flash card reader, USB Key (Free 0 Go of 1 Go)




---\\ Security Center & Tools Informations

[HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoStartMenuSubFolder: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoResolveSearch: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoClose: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableRegistryTools: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoDispScrSavPage: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK

[HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : OK

~ Scan Security Center in 00mn 00s




---\\ Recherche particulière de fichiers génériques

[MD5.37440D09DEAE0B672A04DCCF7ABF06BE] - (.Microsoft Corporation - Explorateur Windows.) (.10/12/2008 - 07:20:29.) -- C:\Windows\Explorer.exe [2923520]

[MD5.4B555106290BD117334E9A08761C035A] - (....) (.02/01/2007 - 10:45:37.) -- C:\Windows\system32\rundll32.exe [44544]

[MD5.D4385B03E8CCCEE6F0EE249F827C1F3E] - (.Microsoft Corporation - Application de démarrage de Windows.) (.02/01/2007 - 10:45:57.) -- C:\Windows\system32\Wininit.exe [95744]

[MD5.0F340B61FA7221DDF8B8375BC0217B71] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.03/04/2010 - 17:54:49.) -- C:\Windows\system32\wininet.dll [832512]

[MD5.9F75392B9128A91ABAFB044EA350BAAD] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.02/01/2007 - 10:45:57.) -- C:\Windows\system32\Winlogon.exe [308224]

[MD5.B35CFCEF838382AB6490B321C87EDF17] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.13/02/2008 - 23:05:24.) -- C:\Windows\system32\drivers\atapi.sys [21560]

[MD5.37430AA7A66D7A63407ADC2C0D05E9F6] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.11/03/2008 - 23:50:41.) -- C:\Windows\system32\drivers\ntfs.sys [1060920]

[MD5.FF524497A864EDF9C040E31DB29D6449] - (....) (.02/01/2007 - 16:41:45.) -- C:\Windows\system32\fr-FR\user32.dll.mui [20480]

~ Scan Generic Processes in 00mn 00s




---\\ Etat des fichiers cachés (Caché/Total)

~ Mes images (My Pictures) : 34/7393

~ Mes musiques (My Musics) : 235/932

~ Mes Videos (My Videos) : 1/6

~ Mes Favoris (My Favorites) : 46/456

~ Mes Documents (My Documents) : 20/313

~ Mon Bureau (My Desktop) : 42/2569

~ Menu demarrer (Programs) : 7/24

~ Scan Hidden Files in 00mn 10s




---\\ Processus lancés

[MD5.AFA1F8CC076AB0462512A78473D86D53] - (.BitTorrent, Inc. - DNA.) -- C:\Users\Matt\Program Files\DNA\btdna.exe [323392] [PID.2220]

[MD5.6FB6057066E2AC3434AFD6152C471840] - (.Sony Corporation - VAIO Update.) -- C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe [546936] [PID.2352]

[MD5.83E9CD075F8D80D19609AB0FF6EAF5D6] - (.Sony Corporation - Wireless Switch Setting Utility.) -- C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe [465016] [PID.2368]

[MD5.A3281C695E7280D402A635442D85F88F] - (.TOSHIBA CORPORATION. - TosBtMng.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2134016] [PID.2376]

[MD5.9041C38ED44C81016CE03162E9F134CD] - (.TOSHIBA CORPORATION. - TosA2dp.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe [274432] [PID.2644]

[MD5.2C92B17E820094F37037B6CE114BEB69] - (.TOSHIBA CORPORATION. - Pas de description.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe [69632] [PID.2796]

[MD5.8C35DB52F07A78E8DF230D76F141FD29] - (.TOSHIBA CORPORATION. - TosBtHSP.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe [270336] [PID.3040]

[MD5.93FA8AD0F0B1466C80D38DE3361B0EA2] - (.TOSHIBA CORPORATION. - TosAVRC.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe [270336] [PID.3748]

[MD5.7914370AAC5CDE8DCAE1C674A6C90229] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [669696] [PID.3264]

[MD5.05CB3DA78A4BBD9B799A5957F9D101CC] - (.Microsoft Corporation - Console IME.) -- C:\Windows\system32\conime.exe [68608] [PID.2152]

[MD5.A1DCD30534835CB67733AD00175125A6] - (.Microsoft Corporation - Service de gestion des licences Microsoft.) -- C:\Windows\system32\SLsvc.exe [2605568] [PID.]

[MD5.00E36BEEA22C92D1030C6D8F80BC0F6A] - (.Microsoft Corporation - SQL Server Windows NT.) -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29262680] [PID.]

[MD5.D2F4F32B59440011174B4F8137AF4E0C] - (.Microsoft Corporation - SQL Server VSS Writer.) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [87904] [PID.]

[MD5.28DC5D626E036A75A572556F0A6EB1F6] - (.Conexant Systems, Inc. - Modem Audio Service.) -- C:\Windows\system32\DRIVERS\xaudio.exe [386560] [PID.]

~ Scan Processes Running in 00mn 01s




---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)



M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml

M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\avg_igeared.xml

M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml

M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml

M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml

M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml

M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml

M3 - MFPP: Plugins - [Matt] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml

M2 - MFEP: prefs.js [Matt - tox6nznd.default\{20a82645-c095-46ed-80e3-08825760534b}] [MicrosoftCG] Microsoft .NET Framework Assistant v1.1 (.Microsoft.)

P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files\Mozilla Firefox\Plugins\np-mswmp.dll

P2 - FPN:Firefox Plugin Navigator . (.BitTorrent, Inc. - BitTorrent Plugin 1.) -- C:\Program Files\Mozilla Firefox\Plugins\npbittorrent.dll

P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeployJava1.dll

P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin.dll

P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin2.dll

P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin3.dll

P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin4.dll

P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin5.dll

P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin6.dll

P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin7.dll

P2 - FPN: [HKLM] [] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32.dll

P2 - FPN: [HKLM] [] - (.Adobe Systems, Inc. - Adobe Shockwave for Director Netscape plug-in, version 11.5.) -- C:\Windows\system32\Adobe\Director\np32dsw.dll

P2 - FPN: [HKLM] [,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

P2 - FPN: [HKLM] [] - (.BitTorrent, Inc. - Delivery Network Acceleration by BitTorrent.) -- C:\Program Files\DNA\plugins\npbtdna.dll

P2 - FPN: [HKLM] [ Browser Plugin,version=1.0.0] - (...) -- C:\Program Files\DivX\DivX Web Player\npdivx32.dll (.not file.)

P2 - FPN: [HKLM] [ Content Upload Plugin,version=1.0.0] - (.DivX,Inc. - DivX® Content Upload Plugin.) -- C:\Program Files\DivX\DivX Content Uploader\npUpload.dll

P2 - FPN: [HKLM] [] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

P2 - FPN: [HKLM] [,version=3.0.0] - (.Google, Inc. - Picasa plugin.) -- C:\Program Files\Google\Picasa3\npPicasa3.dll

P2 - FPN: [HKLM] [,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

P2 - FPN: [HKLM] [ Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\\npGoogleUpdate3.dll

P2 - FPN: [HKLM] [ Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\\npGoogleUpdate3.dll

P2 - FPN: [HKCU] [] - (.BitTorrent, Inc. - Delivery Network Acceleration by BitTorrent.) -- C:\Users\Matt\Program Files\DNA\plugins\npbtdna.dll

P2 - FPN: [HKCU] [,version=1.0.3] - (.Pas de propriétaire - Provides additional functionality on Facebook. See <a href="http://www.) -- C:\Users\Matt\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll

P2 - FPN: [HKCU] [] - (.Google - Version -- C:\Users\Matt\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll

P2 - FPN: [HKCU] [] - (.Pas de propriétaire - Google Talk Plugin Video Accelerator version: -- C:\Users\Matt\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll

P2 - FPN: [HKCU] [ Update;version=3] - (.Google Inc. - Google Update.) -- C:\Users\Matt\AppData\Local\Google\Update\\npGoogleUpdate3.dll

P2 - FPN: [HKCU] [ Update;version=9] - (.Google Inc. - Google Update.) -- C:\Users\Matt\AppData\Local\Google\Update\\npGoogleUpdate3.dll

~ Scan Firefox Browser in 00mn 00s




---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Bing, Actualité et Sport

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Bing, Actualité et Sport

R0 - HKUS\S-1-5-21-2335098037-1364520116-3212336512-1003\Software\Microsoft\Internet Explorer\Main,Start Page = MSN : Hotmail, Messenger, Bing, Actualité et Sport

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Microsoft Corporation

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Microsoft Corporation

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = Bing

R1 - HKUS\S-1-5-21-2335098037-1364520116-3212336512-1003\Software\Microsoft\Internet Explorer\Main,Search Page = Microsoft Corporation

R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (7.00.6000.16386 (vista_rtm.061101-2205)) -- C:\Windows\system32\ieframe.dll

R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} . (...) (No version) -- (.not file.)

R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2

~ Scan IE Browser in 00mn 00s




---\\ Internet Explorer, Proxy Management (R5)

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

~ Scan Proxy management in 00mn 00s




---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)

F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,

F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

~ Scan Keys in 00mn 00s




---\\ Redirection du fichier Hosts (O1)

~ Scan Hosts File in 00mn 00s




---\\ Browser Helper Objects de navigateur (O2)

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Mediafour XPlay Explorer notifications - {4907C0AD-874D-44D9-B13E-7B0A4D8B9D3E} . (.Mediafour Corporation - Pas de description.) -- C:\Program Files\Mediafour\XPlay 3\XPBHO.DLL

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} . (.Safer Networking Limited - SBSD IE Protection.) -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} Clé orpheline

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} . (.Your Company Name - BAE.dll.) -- C:\PROGRA~1\GOOGLE~1\BAE.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll

~ Scan BHO in 00mn 00s




---\\ Applications démarrées par registre & par dossier (O4)

O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe

O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe

O4 - HKCU\..\Run: [bitTorrent DNA] . (.BitTorrent, Inc. - DNA.) -- C:\Users\Matt\Program Files\DNA\btdna.exe

O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] . (.Microsoft Corporation - Chargeur CTF.) -- C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] . (.Microsoft Corporation - Chargeur CTF.) -- C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-21-2335098037-1364520116-3212336512-1003\..\Run: [bitTorrent DNA] . (.BitTorrent, Inc. - DNA.) -- C:\Users\Matt\Program Files\DNA\btdna.exe

~ Scan Application in 00mn 00s




---\\ Autres liens utilisateurs (O4)

O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe

O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Mail\WinMail.exe

O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe

O4 - Global Startup: C:\Users\Matt\Desktop\Ad-Aware.lnk . (...) -- C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe (.not file.)

O4 - Global Startup: C:\Users\Matt\Desktop\ColorPic.lnk . (...) -- C:\Program Files\ColorPic 4.1\ColorPic.exe

O4 - Global Startup: C:\Users\Matt\Desktop\Grand Dictionnaire Hachette Oxford.lnk . (.Oxford University Press.) -- C:\Program Files\GDHO\gdho.exe

O4 - Global Startup: C:\Users\Matt\Desktop\Incoming - Raccourci.lnk . (...) -- C:\Program Files\eMule\Incoming

O4 - Global Startup: C:\Users\Matt\Desktop\PhotoFiltre.lnk . (.Antonio Da Cruz.) -- C:\Program Files\PhotoFiltre\photofiltre.exe

O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Démarrer Microsoft Office Outlook.lnk . (.Microsoft Corporation.) -- C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE

O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe

O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe

O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk . (...) -- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe

O4 - Global Startup: C:\Users\Matt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe

~ Scan Global Startup in 00mn 00s




---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)

O8 - Extra context menu item: Add to Google Photos Screensa&ver . (.Google Inc. - Google Photos Screensaver.) -- C:\Windows\system32\GPhotos.scr

O8 - Extra context menu item: Ajouter un site de support RSS à VAIO Information FLOW . (...) -- C:\Program Files\Sony\VAIO Information FLOW\aiesc.html

O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.exe

~ Scan IE Menu Contextuel in 00mn 00s




---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\PROGRA~1\MICROS~3\OFFICE11\REFBARH.ICO

O9 - Extra button: Recherche - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} -- C:\Program Files\Bodog Poker\BPGame.exe (.not file.)

~ Scan IE Extra Buttons in 00mn 00s




---\\ Winsock hijacker (Layered Service Provider) (O10)

O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll

O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll

O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll

O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll

O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll

O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll

O10 - WLSP:\000000000007\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll

~ Scan Winsock in 00mn 00s




---\\ Objets ActiveX (Downloaded Program Files)(O16)

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -

O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () -

~ Scan Objets ActiveX in 00mn 00s




---\\ Protocole additionnel (O18)

O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\system32\mshtml.dll

O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll

O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll

O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll

O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll

O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll

O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll

O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll

O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll

O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\system32\mshtml.dll

O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler.) -- C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll

O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\system32\mshtml.dll

O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\system32\inetcomm.dll

O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll

O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll

O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler.) -- C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Handler: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} . (.Microsoft Corporation - Microsoft Office XP Web Components.) -- C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL

O18 - Handler: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} . (.Microsoft Corporation - Microsoft Office Web Components 2003.) -- C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL

O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\system32\mshtml.dll

O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll

O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\system32\mshtml.dll

O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll

O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll

O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll

O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll

O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll

O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

~ Scan Protocole Additionnel in 00mn 00s




---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)

O20 - Winlogon Notify: VESWinlogon . (.Sony Corporation - VAIO Event Service (Winlogon Notification M.) -- C:\Windows\system32\VESWinlogon.dll

~ Scan Winlogon in 00mn 00s




---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Contrôleur de site Web.) -- C:\Windows\system32\webcheck.dll

~ Scan SSODL in 00mn 00s




---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)

O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\system32\browseui.dll

~ Scan STS/SSO in 00mn 00s




---\\ Liste des services NT non Microsoft et non désactivés (O23)

O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) . (...) - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe (.not file.)

O23 - Service: Apple Mobile Device (Apple Mobile Device) . (...) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (.not file.)

O23 - Service: Service Bonjour (Bonjour Service) . (...) - C:\Program Files\Bonjour\mDNSResponder.exe (.not file.)

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) . (...) - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (.not file.)

O23 - Service: Service Google Update (gupdate) (gupdate) . (...) - C:\Program Files\Google\Update\GoogleUpdate.exe (.not file.)

O23 - Service: M4iPodWPDService (M4iPodWPDService) . (...) - C:\Program Files\Common Files\Mediafour\iPod\M4iPodWPDService.exe (.not file.)

O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) . (...) - C:\Windows\system32\sfrem01.exe (.not file.)

O23 - Service: SigmaTel Audio Service (STacSV) . (...) - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe (.not file.)

O23 - Service: TOSHIBA Bluetooth Service (TOSHIBA Bluetooth Service) . (...) - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (.not file.)

O23 - Service: VAIO Event Service (VAIO Event Service) . (...) - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe

O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) . (...) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (.not file.)

O23 - Service: VAIO Entertainment File Import Service (VzFw) . (...) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (.not file.)

O23 - Service: XAudioService (XAudioService) . (.Conexant Systems, Inc. - Modem Audio Service.) - C:\Windows\system32\DRIVERS\xaudio.exe

~ Scan Services in 00mn 00s




---\\ Enumération Active Desktop & MHTML Editor (O24)

O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Office Word.) - C:\Program Files\Microsoft Office\OFFICE11\WINWORD.exe

~ Scan Desktop Component in 00mn 00s




---\\ Tâches planifiées en automatique (O39)

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2335098037-1364520116-3212336512-1003Core.job

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2335098037-1364520116-3212336512-1003UA.job

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\User_Feed_Synchronization-{749F7267-3809-4F65-A674-B375A4B1B6E4}.job

~ Scan Scheduled Task in 00mn 00s




---\\ Pilotes lancés au démarrage (O41)

O41 - Driver: (CbFs) . (.EldoS Corporation - Callback File System Driver.) - C:\Windows\system32\drivers\cbfs.sys

O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\DRIVERS\cdrom.sys

O41 - Driver: (DfsC) . (.Microsoft Corporation - DFS Client MUP Surrogate Driver.) - C:\Windows\system32\Drivers\dfsc.sys

O41 - Driver: (DMICall) . (.Sony Corporation - Windows 2000 DMI Call Kernel Driver.) - C:\Windows\system32\DRIVERS\DMICall.sys

O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\system32\DRIVERS\i8042prt.sys

O41 - Driver: (kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\system32\DRIVERS\kbdclass.sys

O41 - Driver: (mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\system32\DRIVERS\mouclass.sys

O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\system32\DRIVERS\netbios.sys

O41 - Driver: (netbt) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\system32\DRIVERS\netbt.sys

O41 - Driver: (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\system32\drivers\nsiproxy.sys

O41 - Driver: C:\Windows\system32\drivers\pacer.sys (PSched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\system32\DRIVERS\pacer.sys

O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\system32\DRIVERS\rasacd.sys

O41 - Driver: (rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\system32\DRIVERS\rdbss.sys

O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\DRIVERS\RDPCDD.sys

O41 - Driver: (RDPENCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\drivers\rdpencdd.sys

O41 - Driver: C:\Windows\system32\tcpipcfg.dll (Smb) . (.Microsoft Corporation - SMB Transport driver.) - C:\Windows\system32\DRIVERS\smb.sys

O41 - Driver: C:\Windows\system32\tcpipcfg.dll (Tcpip) . (.Microsoft Corporation - TCP/IP Driver.) - C:\Windows\system32\drivers\tcpip.sys

O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys

O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\system32\DRIVERS\termdd.sys

O41 - Driver: (Tosrfcom) . (.TOSHIBA Corporation - Bluetooth RFCOMM Driver.) - C:\Windows\system32\Drivers\tosrfcom.sys

O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys

O41 - Driver: (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\system32\DRIVERS\wanarp.sys

~ Scan Drivers in 00mn 00s




---\\ Logiciels installés (O42)

O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin

O42 - Logiciel: Adobe Photoshop Elements 5.0 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Photoshop Elements 5

O42 - Logiciel: Adobe Shockwave Player 11.5 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Shockwave Player

O42 - Logiciel: Alps Pointing-device for VAIO - (.Pas de propriétaire.) [HKLM] -- {9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}

O42 - Logiciel: Archiveur WinRAR - (.Pas de propriétaire.) [HKLM] -- WinRAR archiver

O42 - Logiciel: AviSynth 2.5 - (.Pas de propriétaire.) [HKLM] -- AviSynth

O42 - Logiciel: Azureus Vuze - (.Vuze, Inc..) [HKLM] -- Azureus Vuze

O42 - Logiciel: BS Contact VRML/X3D - (.Bitmanagement Software GmbH.) [HKLM] -- {2928EFE3-4841-4571-AD29-9900AB10943E}

O42 - Logiciel: BitTorrent - (.BitTorrent, Inc.) [HKCU] -- BitTorrent

O42 - Logiciel: Browser Address Error Redirector - (.Pas de propriétaire.) [HKLM] -- {3EE33958-7381-4E7B-A4F3-6E43098E9E9C}

O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner

O42 - Logiciel: Click to DVD 2.0.05 Menu Data - (.Sony Corporation.) [HKLM] -- {9E407618-D9CD-4F39-9490-9ED45294073D}

O42 - Logiciel: Click to DVD 2.6.00 - (.Sony Corporation.) [HKLM] -- {E809063C-51A3-4269-8984-D1EB742F2151}

O42 - Logiciel: ColorPic - (.Iconico.) [HKLM] -- ColorPic

O42 - Logiciel: CopyTrans Suite Remove Only - (.Pas de propriétaire.) [HKLM] -- CopyTrans Suite

O42 - Logiciel: DNA - (.BitTorrent Inc..) [HKCU] -- BitTorrent DNA

O42 - Logiciel: DVgate Plus - (.Sony Corporation.) [HKLM] -- {685BCC47-B8EC-45EC-BBCE-77DF2451502C}

O42 - Logiciel: DivX Content Uploader - (.DivX, Inc..) [HKLM] -- {D050D7362D214723AD585B541FFB6C11}

O42 - Logiciel: DivX Web Player - (.DivX,Inc..) [HKLM] -- {B7050CBDB2504B34BC2A9CA0A692CC29}

O42 - Logiciel: EPSON Stylus SX400 Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM] -- EPSON Stylus SX400 Series

O42 - Logiciel: Facebook Plug-In - (.Facebook, Inc..) [HKCU] -- Facebook Plug-In

O42 - Logiciel: FastStone Capture 5.2 (French) - (.FastStone Soft.) [HKLM] -- FastStone Capture

O42 - Logiciel: GDR 4053 for SQL Server Database Services 2005 ENU (KB970892) - (.Microsoft Corporation.) [HKLM] -- KB970892_SQL9

O42 - Logiciel: Grand Dictionnaire Hachette-Oxford - (.Pas de propriétaire.) [HKLM] -- Grand Dictionnaire Hachette-Oxford

O42 - Logiciel: HDAUDIO SoftV92 Data Fax Modem with SmartCP - (.Pas de propriétaire.) [HKLM] -- CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200

O42 - Logiciel: HotKey Utility - (.Pas de propriétaire.) [HKLM] -- {B36C3DFD-BAB0-4513-BD27-FA4906A738FD}

O42 - Logiciel: HotKey Utility - (.Pas de propriétaire.) [HKLM] -- {BB311F54-39D6-4A03-8E18-053D1B2833D7}

O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595

O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484

O42 - Logiciel: Intel® PRO Network Connections Drivers - (.Pas de propriétaire.) [HKLM] -- PROSet

O42 - Logiciel: LAN Setting Utility - (.Sony Corporation.) [HKLM] -- {5958CAC6-373E-402F-84FE-0A699AA920B9}

O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1

O42 - Logiciel: Microsoft SQL Server 2005 - (.Microsoft Corporation.) [HKLM] -- Microsoft SQL Server 2005

O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 Language Pack SP1 - fra

O42 - Logiciel: Mozilla Firefox 6.0.1 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 6.0.1 (x86 fr)

O42 - Logiciel: Octoshape add-in for Adobe Flash Player - (.Pas de propriétaire.) [HKCU] -- Octoshape add-in for Adobe Flash Player

O42 - Logiciel: OpenMG Secure Module 4.6.01 - (.Sony Corporation.) [HKLM] -- InstallShield_{3D79DB6E-73DA-46C9-B8FA-DAE52108246F}

O42 - Logiciel: Outil VAIO Media Registration 6.0 - (.Sony Corporation.) [HKLM] -- {AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}

O42 - Logiciel: PDFCreator - (.Frank Heindörfer, Philip Chinery.) [HKLM] -- {0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}

O42 - Logiciel: PhotoFiltre - (.Pas de propriétaire.) [HKCU] -- PhotoFiltre

O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM] -- Picasa 3

O42 - Logiciel: Plugins SonicStage Mastering Studio - (.Sony Corporation.) [HKLM] -- {9C1C8A04-F8CA-4472-A92D-4288CE32DE86}

O42 - Logiciel: PokerStars - ( [HKLM] -- PokerStars

O42 - Logiciel: SanDisk_Button_Manager.exe - (.DMAILER.) [HKCU] -- {7994634D-6165-49f7-A296-F60D4F87E1EC}SanDisk_Button_Manager.exe

O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- KB931906

O42 - Logiciel: Setting Utility Series - (.Sony Corporation.) [HKLM] -- {59452470-A902-477F-9338-9B88101681BD}

O42 - Logiciel: SigmaTel Audio - (.SigmaTel.) [HKLM] -- {A462213D-EED4-42C2-9A60-7BDD4D4B0B17}

O42 - Logiciel: SonicStage 4.2 - (.Sony Corporation.) [HKLM] -- {A0EB195B-5876-48E6-879D-33D4B2102610}

O42 - Logiciel: SonicStage Mastering Studio - (.Sony Corporation.) [HKLM] -- {6332AFF1-9D9A-429C-AA03-F82749FA4F49}

O42 - Logiciel: SonicStage Mastering Studio Audio Filter - (.Sony Corporation.) [HKLM] -- {DF7DB916-90E5-40F2-9010-B8125EB5FD6F}

O42 - Logiciel: SonicStage Mastering Studio Audio Filter Custom Preset - (.Sony Corporation.) [HKLM] -- {EC37A846-53AC-4DA7-98FA-76A4E74AA900}

O42 - Logiciel: Sony Utilities DLL - (.Sony Corporation.) [HKLM] -- {EF3D45BB-2260-4008-88EA-492E7744A9DF}

O42 - Logiciel: Sony Video Shared Library - (.Sony Corporation.) [HKLM] -- {01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}

O42 - Logiciel: SoulSeek Client 156c - (.Pas de propriétaire.) [HKLM] -- Soulseek

O42 - Logiciel: SpaceMonger 2.1.1 - (.Sixty-Five.) [HKLM] -- SpaceMonger

O42 - Logiciel: Spybot - Search & Destroy - (.Safer Networking Limited.) [HKLM] -- {B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1

O42 - Logiciel: Spybot - Search & Destroy 1.3 - (.Safer Networking Limited.) [HKLM] -- Spybot - Search & Destroy_is1

O42 - Logiciel: System Requirements Lab - (.Pas de propriétaire.) [HKLM] -- SystemRequirementsLab

O42 - Logiciel: Time Adjuster STANDARD 3.1 - ( [HKCU] -- TimeAdjuster

O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707

O42 - Logiciel: VAIO Aqua Breeze Wallpaper - (.Sony Corporation.) [HKLM] -- {97BCD719-6ECB-458F-97D6-F38D2E07375E}

O42 - Logiciel: VAIO Camera Capture Utility - (.Sony Corporation.) [HKLM] -- {6D2576EC-A0E9-418A-A09A-409933A3B6F4}

O42 - Logiciel: VAIO Camera Utility - (.Sony Corporation.) [HKLM] -- {1417F599-1DBD-4499-9375-B2813E9F890C}

O42 - Logiciel: VAIO Control Center - (.Sony Corporation.) [HKLM] -- {FC37C108-821D-4EDE-8F40-D5B497586805}

O42 - Logiciel: VAIO Cozy Orange Wallpaper - (.Sony Corporation.) [HKLM] -- {2A2FF7F5-6F0E-4A5D-A881-39365E718BD6}

O42 - Logiciel: VAIO Data Restore Tool - (.Pas de propriétaire.) [HKLM] -- {57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}

O42 - Logiciel: VAIO Entertainment Platform - (.Sony Corporation.) [HKLM] -- {6B1F20F2-6321-4669-A58C-33DF8E7517FF}

O42 - Logiciel: VAIO Event Service - (.Sony Corporation.) [HKLM] -- {F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}

O42 - Logiciel: VAIO Hardware Diagnostics - (.Pas de propriétaire.) [HKLM] -- {A947C2B3-7445-42C4-9063-EE704CACCB22}

O42 - Logiciel: VAIO Information FLOW - (.Sony Corporation.) [HKLM] -- {24960AC2-C413-4A86-B1C1-E4CCADCA44D3}

O42 - Logiciel: VAIO Media 6.0 - (.Sony Corporation.) [HKLM] -- {560F6B2E-F0DF-44E5-8190-A4A161F0E205}

O42 - Logiciel: VAIO Media AC3 Decoder 1.0 - (.Pas de propriétaire.) [HKLM] -- {2063C2E8-3812-4BBD-9998-6610F80C1DD4}

O42 - Logiciel: VAIO Media Content Collection 6.0 - (.Sony Corporation.) [HKLM] -- {500162A0-4DD5-460A-BAFD-895AAE48C532}

O42 - Logiciel: VAIO Media Integrated Server 6.0 - (.Sony Corporation.) [HKLM] -- {785EB1D4-ECEC-4195-99B4-73C47E187721}

O42 - Logiciel: VAIO Media Redistribution 6.0 - (.Sony Corporation.) [HKLM] -- {5855C127-1F20-404D-B7FB-1FD84D7EAB5E}

O42 - Logiciel: VAIO Photo 2007 - (.Sony Corporation.) [HKLM] -- {5E343EF6-D27C-4CFC-9FAE-9AAFB541BCEE}

O42 - Logiciel: VAIO Power Management - (.Sony Corporation.) [HKLM] -- {9E319E96-ED8E-4B01-9775-C521A1869A25}

O42 - Logiciel: VAIO Tender Green Wallpaper - (.Sony Corporation.) [HKLM] -- {934A3213-1CB6-4264-84A2-EE080C017BCA}

O42 - Logiciel: VAIO Update 3 - (.Sony Corporation.) [HKLM] -- {48820099-ED7D-424B-890C-9A82EF00656D}

O42 - Logiciel: Videora iPod touch Converter 3.07 - (.Red Kawa Inc..) [HKLM] -- Videora iPod touch Converter

O42 - Logiciel: Visual C++ 2008 x86 Runtime - v9.0.30729.01 - (.Microsoft Corporation.) [HKLM] -- {F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01

O42 - Logiciel: WinDVD for VAIO - (.InterVideo Inc..) [HKLM] -- InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}

O42 - Logiciel: Wireless Switch Setting Utility - (.Sony Corporation.) [HKLM] -- {2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}

O42 - Logiciel: dBpoweramp Music Converter - (.Illustrate.) [HKLM] -- dBpoweramp Music Converter


---\\ HKCU & HKLM Software Keys




[HKCU\Software\Alcohol Soft]









[HKCU\Software\Apple Computer, Inc.]

[HKCU\Software\Apple Inc.]






[HKCU\Software\Bitmanagement Software]

[HKCU\Software\Bodog Poker]




[HKCU\Software\DT Soft]



[HKCU\Software\Full Tilt Poker]






[HKCU\Software\Gost Publishing]

[HKCU\Software\IM Providers]









[HKCU\Software\Local AppWizard-Generated Applications]


[HKCU\Software\Malwarebytes' Anti-Malware]




[HKCU\Software\NVIDIA Corporation]

[HKCU\Software\NVIDIA nvCpl Container]






[HKCU\Software\PepiMK Software]




[HKCU\Software\Safer Networking Limited]



[HKCU\Software\Sony Corporation]







[HKCU\Software\VB and VBA Program Settings]



[HKCU\Software\WinRAR SFX]








[HKLM\Software\ACE Compression Software]

[HKLM\Software\AGEIA Technologies]




[HKLM\Software\Alcohol Soft]



[HKLM\Software\Apple Computer, Inc.]

[HKLM\Software\Apple Inc.]



[HKLM\Software\Bitmanagement Software]

[HKLM\Software\Bodog Poker]






[HKLM\Software\Conexant Systems Inc ]




[HKLM\Software\Full Tilt Poker]

[HKLM\Software\GEAR Software]

[HKLM\Software\Global IP Solutions]













[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]

[HKLM\Software\Malwarebytes' Anti-Malware]





[HKLM\Software\NVIDIA Corporation]









[HKLM\Software\Safer Networking Limited]





[HKLM\Software\Sony Corporation]











~ Scan Softwares in 00mn 00s




---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)

O43 - CFD: 30/08/2011 - 22:53:48 - [101607514] ----D- C:\Program Files\Ad-Remover

O43 - CFD: 03/03/2008 - 20:36:20 - [2010920809] ----D- C:\Program Files\Adobe

O43 - CFD: 05/08/2007 - 16:53:14 - [3177] ----D- C:\Program Files\ALA

O43 - CFD: 25/05/2007 - 14:55:38 - [13] ----D- C:\Program Files\Alice

O43 - CFD: 10/10/2010 - 00:44:42 - [2738105] ----D- C:\Program Files\Apoint

O43 - CFD: 01/09/2011 - 01:20:22 - [2428606] ----D- C:\Program Files\Apple Software Update

O43 - CFD: 10/03/2009 - 00:33:52 - [0] ----D- C:\Program Files\AVG

O43 - CFD: 22/12/2007 - 00:11:18 - [2655233] ----D- C:\Program Files\AviSynth 2.5

O43 - CFD: 05/08/2008 - 22:31:20 - [32847214] ----D- C:\Program Files\Azureus

O43 - CFD: 23/04/2008 - 21:02:36 - [8409490] R---D- C:\Program Files\Bitmanagement Software

O43 - CFD: 20/01/2009 - 01:10:18 - [1041232] ----D- C:\Program Files\BitTorrent

O43 - CFD: 05/09/2011 - 22:27:08 - [223449] ----D- C:\Program Files\Bonjour

O43 - CFD: 22/08/2011 - 21:56:56 - [4068448] ----D- C:\Program Files\CCleaner

O43 - CFD: 02/04/2011 - 13:45:38 - [432522] ----D- C:\Program Files\ColorPic 4.1

O43 - CFD: 05/09/2011 - 22:21:26 - [794519606] ----D- C:\Program Files\Common Files

O43 - CFD: 04/12/2006 - 12:01:12 - [1033640] ----D- C:\Program Files\CONEXANT

O43 - CFD: 03/08/2007 - 21:43:34 - [1634536] ----D- C:\Program Files\DAEMON Tools

O43 - CFD: 27/10/2007 - 00:24:04 - [6144939] ----D- C:\Program Files\DivX

O43 - CFD: 28/08/2011 - 21:18:24 - [408704] ----D- C:\Program Files\DNA

O43 - CFD: 28/08/2011 - 15:38:10 - [9120287551] ----D- C:\Program Files\eMule

O43 - CFD: 14/08/2011 - 00:09:04 - [16894659] ----D- C:\Program Files\Enigma Software Group

O43 - CFD: 26/02/2007 - 22:53:02 - [1368984] ----D- C:\Program Files\FastStone Capture

O43 - CFD: 04/12/2006 - 12:06:04 - [0] -SH-D- C:\Program Files\Fichiers communs

O43 - CFD: 25/01/2009 - 01:45:50 - [145] ----D- C:\Program Files\Full Tilt Poker

O43 - CFD: 30/03/2008 - 18:54:16 - [107476875] ----D- C:\Program Files\GDHO

O43 - CFD: 20/08/2011 - 15:54:48 - [158019604] ----D- C:\Program Files\Google

O43 - CFD: 05/12/2006 - 10:44:42 - [98346] ----D- C:\Program Files\Google BAE

O43 - CFD: 30/12/2009 - 20:58:56 - [1273978] ----D- C:\Program Files\HotKey_2.4.00.07090

O43 - CFD: 29/08/2009 - 03:15:54 - [9893135] ----D- C:\Program Files\Illustrate

O43 - CFD: 30/12/2009 - 21:39:46 - [84458491] --H-D- C:\Program Files\InstallShield Installation Information

O43 - CFD: 04/12/2006 - 12:20:44 - [41895] ----D- C:\Program Files\Intel

O43 - CFD: 04/04/2010 - 20:16:22 - [2776365] ----D- C:\Program Files\Internet Explorer

O43 - CFD: 21/12/2006 - 16:04:40 - [144706607] ----D- C:\Program Files\InterVideo

O43 - CFD: 01/09/2011 - 01:39:40 - [1047787] ----D- C:\Program Files\iPod

O43 - CFD: 01/09/2011 - 01:41:34 - [124246827] ----D- C:\Program Files\iTunes

O43 - CFD: 29/05/2010 - 12:22:22 - [170275531] ----D- C:\Program Files\Java

O43 - CFD: 05/09/2011 - 22:06:38 - [449584] ----D- C:\Program Files\Malwarebytes' Anti-Malware

O43 - CFD: 25/01/2009 - 02:27:28 - [10563334] ----D- C:\Program Files\Mediafour

O43 - CFD: 09/03/2008 - 12:40:26 - [800662] ----D- C:\Program Files\Microsoft CAPICOM

O43 - CFD: 14/04/2007 - 14:20:58 - [92804023] ----D- C:\Program Files\Microsoft Games

O43 - CFD: 14/08/2011 - 00:04:28 - [314904501] ----D- C:\Program Files\Microsoft Office

O43 - CFD: 15/10/2009 - 03:04:08 - [252565008] ----D- C:\Program Files\Microsoft SQL Server

O43 - CFD: 24/07/2011 - 23:15:30 - [6583142] ----D- C:\Program Files\Microsoft Windows 7 Upgrade Advisor

O43 - CFD: 07/01/2008 - 14:27:46 - [324960225] ----D- C:\Program Files\Microsoft Works

O43 - CFD: 05/02/2007 - 16:56:00 - [1856386] ----D- C:\Program Files\Microsoft.NET

O43 - CFD: 13/03/2010 - 04:22:04 - [99153006] ----D- C:\Program Files\Movie Maker

O43 - CFD: 05/09/2011 - 18:39:54 - [37617962] ----D- C:\Program Files\Mozilla Firefox

O43 - CFD: 02/11/2006 - 14:37:36 - [25757] ----D- C:\Program Files\MSBuild

O43 - CFD: 02/01/2010 - 13:40:08 - [29794014] ----D- C:\Program Files\MSECache

O43 - CFD: 02/11/2006 - 14:37:36 - [3272760] ----D- C:\Program Files\MSN

O43 - CFD: 02/02/2007 - 21:12:02 - [0] ----D- C:\Program Files\MSXML 4.0

O43 - CFD: 21/07/2007 - 19:05:56 - [43189] ----D- C:\Program Files\nutri

O43 - CFD: 03/04/2011 - 17:38:56 - [2028] ----D- C:\Program Files\office Convert Pdf to Jpg Jpeg Tiff Free

O43 - CFD: 19/02/2011 - 18:58:02 - [103880292] ----D- C:\Program Files\PC Tools Security

O43 - CFD: 29/08/2009 - 00:23:36 - [21625423] ----D- C:\Program Files\PDFCreator

O43 - CFD: 16/07/2010 - 02:54:34 - [16419068] ----D- C:\Program Files\Photo Story 3 for Windows

O43 - CFD: 03/04/2011 - 03:27:18 - [3699431] ----D- C:\Program Files\PhotoFiltre

O43 - CFD: 05/11/2010 - 22:21:58 - [73920286] ----D- C:\Program Files\PokerStars

O43 - CFD: 01/09/2011 - 01:24:52 - [75697179] ----D- C:\Program Files\QuickTime

O43 - CFD: 22/12/2007 - 00:36:54 - [14669943] ----D- C:\Program Files\Red Kawa

O43 - CFD: 02/11/2006 - 14:37:36 - [38637313] ----D- C:\Program Files\Reference Assemblies

O43 - CFD: 05/12/2006 - 10:59:10 - [295644083] ----D- C:\Program Files\Roxio

O43 - CFD: 17/05/2009 - 18:03:48 - [3125920] ----D- C:\Program Files\SDHelper (Spybot - Search & Destroy)

O43 - CFD: 04/12/2006 - 12:25:04 - [7656563] ----D- C:\Program Files\SigmaTel

O43 - CFD: 31/07/2011 - 18:29:02 - [17357532] R---D- C:\Program Files\Skype

O43 - CFD: 30/12/2009 - 21:00:24 - [502724736] ----D- C:\Program Files\Sony

O43 - CFD: 08/06/2011 - 22:32:06 - [3218853] ----D- C:\Program Files\Soulseek

O43 - CFD: 27/08/2011 - 21:46:18 - [4273752] ----D- C:\Program Files\SpaceMonger

O43 - CFD: 14/08/2011 - 10:35:00 - [64231932] ----D- C:\Program Files\Spybot - Search & Destroy

O43 - CFD: 13/10/2007 - 13:03:10 - [767494] ----D- C:\Program Files\SystemRequirementsLab

O43 - CFD: 17/05/2009 - 18:03:48 - [4520960] ----D- C:\Program Files\TeaTimer (Spybot - Search & Destroy)

O43 - CFD: 25/09/2007 - 00:45:54 - [0] ----D- C:\Program Files\THQ

O43 - CFD: 12/06/2007 - 00:20:10 - [2045407] ----D- C:\Program Files\TimeAdjuster

O43 - CFD: 21/12/2006 - 16:05:32 - [47144382] ----D- C:\Program Files\Toshiba

O43 - CFD: 11/01/2008 - 22:25:42 - [0] ----D- C:\Program Files\Ubisoft

O43 - CFD: 02/11/2006 - 15:01:56 - [0] --H-D- C:\Program Files\Uninstall Information

O43 - CFD: 06/02/2007 - 11:18:36 - [74973069] ----D- C:\Program Files\VideoLAN

O43 - CFD: 26/10/2007 - 13:48:50 - [0] ----D- C:\Program Files\Webteh

O43 - CFD: 30/08/2007 - 03:10:50 - [1016832] ----D- C:\Program Files\Windows Calendar

O43 - CFD: 02/11/2006 - 14:42:34 - [2761216] ----D- C:\Program Files\Windows Collaboration

O43 - CFD: 13/04/2007 - 03:02:38 - [4486592] ----D- C:\Program Files\Windows Defender

O43 - CFD: 02/11/2006 - 14:42:34 - [7078008] ----D- C:\Program Files\Windows Journal

O43 - CFD: 12/04/2008 - 17:50:02 - [32695964] ----D- C:\Program Files\Windows Live

O43 - CFD: 17/04/2010 - 04:22:00 - [9071240] ----D- C:\Program Files\Windows Mail

O43 - CFD: 30/10/2009 - 23:00:50 - [4496487] ----D- C:\Program Files\Windows Media Player

O43 - CFD: 04/12/2006 - 12:06:04 - [7940176] ----D- C:\Program Files\Windows NT

O43 - CFD: 02/11/2006 - 14:42:34 - [13463714] ----D- C:\Program Files\Windows Photo Gallery

O43 - CFD: 10/01/2008 - 04:03:10 - [6503190] ----D- C:\Program Files\Windows Sidebar

O43 - CFD: 05/02/2008 - 00:19:18 - [6036676] ----D- C:\Program Files\WindSolutions

O43 - CFD: 04/02/2007 - 13:15:00 - [3718034] ----D- C:\Program Files\WinRAR

O43 - CFD: 08/09/2011 - 23:22:46 - [4016808] ----D- C:\Program Files\ZHPDiag

O43 - CFD: 03/03/2008 - 20:36:20 - [87326373] ----D- C:\Program Files\Common Files\Adobe

O43 - CFD: 01/09/2011 - 01:39:32 - [93153076] ----D- C:\Program Files\Common Files\Apple

O43 - CFD: 05/02/2007 - 16:59:16 - [86016] ----D- C:\Program Files\Common Files\DESIGNER

O43 - CFD: 21/12/2006 - 16:10:48 - [16253778] ----D- C:\Program Files\Common Files\InstallShield

O43 - CFD: 29/05/2010 - 12:47:10 - [32860126] ----D- C:\Program Files\Common Files\Java

O43 - CFD: 25/01/2009 - 02:27:28 - [5627234] ----D- C:\Program Files\Common Files\Mediafour

O43 - CFD: 15/07/2010 - 22:37:40 - [338718107] ----D- C:\Program Files\Common Files\microsoft shared

O43 - CFD: 02/11/2006 - 13:18:34 - [2702] ----D- C:\Program Files\Common Files\Services

O43 - CFD: 21/12/2006 - 16:21:58 - [70991261] ----D- C:\Program Files\Common Files\Sony Shared

O43 - CFD: 02/11/2006 - 13:18:34 - [41100711] ----D- C:\Program Files\Common Files\SpeechEngines

O43 - CFD: 16/08/2009 - 21:35:52 - [5381514] ----D- C:\Program Files\Common Files\Symantec Shared

O43 - CFD: 14/06/2007 - 09:14:16 - [22732900] ----D- C:\Program Files\Common Files\System

O43 - CFD: 19/12/2009 - 19:41:26 - [0] ----D- C:\Program Files\Common Files\Windows Live

O43 - CFD: 07/03/2008 - 11:06:12 - [55124592] -SH-D- C:\Program Files\Common Files\WindowsLiveInstaller

O43 - CFD: 14/08/2011 - 00:08:38 - [25161216] ----D- C:\Program Files\Common Files\Wise Installation Wizard

O43 - CFD: 03/03/2008 - 20:36:44 - [376291648] ----D- C:\ProgramData\Adobe

O43 - CFD: 11/08/2011 - 04:01:12 - [208] ----D- C:\ProgramData\aN01603MdKiF01603

O43 - CFD: 06/02/2010 - 16:34:44 - [145475780] ----D- C:\ProgramData\Apple

O43 - CFD: 01/09/2011 - 01:23:58 - [66283534] ----D- C:\ProgramData\Apple Computer

O43 - CFD: 02/11/2006 - 15:02:04 - [0] -SH-D- C:\ProgramData\Application Data

O43 - CFD: 04/08/2008 - 01:26:26 - [20] ----D- C:\ProgramData\Azureus

O43 - CFD: 04/12/2006 - 12:06:04 - [0] -SH-D- C:\ProgramData\Bureau

O43 - CFD: 05/02/2008 - 00:19:34 - [3489219] ----D- C:\ProgramData\CopyTransControlCenter

O43 - CFD: 02/11/2006 - 15:02:04 - [0] -SH-D- C:\ProgramData\Desktop

O43 - CFD: 02/11/2006 - 15:02:04 - [0] -SH-D- C:\ProgramData\Documents

O43 - CFD: 28/08/2011 - 15:38:10 - [0] ----D- C:\ProgramData\eMule

O43 - CFD: 28/08/2011 - 19:03:42 - [566344] ----D- C:\ProgramData\EPSON

O43 - CFD: 04/12/2006 - 12:06:04 - [0] -SH-D- C:\ProgramData\Favoris

O43 - CFD: 02/11/2006 - 15:02:04 - [0] -SH-D- C:\ProgramData\Favorites

O43 - CFD: 12/12/2007 - 00:56:56 - [19772] ----D- C:\ProgramData\FLEXnet

O43 - CFD: 22/06/2007 - 21:16:00 - [4096] ----D- C:\ProgramData\Grisoft

O43 - CFD: 28/08/2011 - 22:34:20 - [359] ----D- C:\ProgramData\Lavasoft

O43 - CFD: 01/08/2011 - 00:53:42 - [9468189] ----D- C:\ProgramData\Malwarebytes

O43 - CFD: 25/01/2009 - 02:27:26 - [10593042] ----D- C:\ProgramData\Mediafour

O43 - CFD: 04/12/2006 - 12:06:04 - [0] -SH-D- C:\ProgramData\Menu Démarrer

O43 - CFD: 19/12/2009 - 19:41:22 - [304901871] -S--D- C:\ProgramData\Microsoft

O43 - CFD: 04/12/2006 - 12:06:04 - [0] -SH-D- C:\ProgramData\Modèles

O43 - CFD: 17/04/2010 - 12:59:06 - [155] ----D- C:\ProgramData\Norton

O43 - CFD: 17/04/2010 - 12:10:38 - [181474] ----D- C:\ProgramData\NortonInstaller

O43 - CFD: 18/12/2006 - 15:14:00 - [8480] ----D- C:\ProgramData\NVIDIA

O43 - CFD: 22/08/2011 - 21:53:50 - [208] ----D- C:\ProgramData\oG01300OoIlL01300

O43 - CFD: 31/07/2011 - 18:29:00 - [18861207] ----D- C:\ProgramData\Skype

O43 - CFD: 04/12/2006 - 12:09:44 - [18009573] ----D- C:\ProgramData\Sony

O43 - CFD: 02/02/2007 - 22:31:18 - [616133926] ----D- C:\ProgramData\Sony Corporation

O43 - CFD: 05/09/2011 - 17:35:38 - [208239] ----D- C:\ProgramData\Spybot - Search & Destroy

O43 - CFD: 02/11/2006 - 15:02:04 - [0] -SH-D- C:\ProgramData\Start Menu

O43 - CFD: 29/05/2010 - 12:47:10 - [119] ----D- C:\ProgramData\Sun

O43 - CFD: 17/04/2010 - 12:10:40 - [25524389] ----D- C:\ProgramData\Symantec

O43 - CFD: 19/02/2011 - 01:44:38 - [0] ---AD- C:\ProgramData\TEMP

O43 - CFD: 02/11/2006 - 15:02:06 - [0] -SH-D- C:\ProgramData\Templates

O43 - CFD: 21/12/2006 - 16:17:42 - [0] ----D- C:\ProgramData\VAIO Media Platform

O43 - CFD: 12/04/2008 - 17:47:24 - [395900] ----D- C:\ProgramData\WLInstaller

O43 - CFD: 01/03/2011 - 23:31:24 - [542643] ----D- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

O43 - CFD: 06/02/2010 - 16:18:04 - [3350] ----D- C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}

O43 - CFD: 29/08/2009 - 03:16:06 - [0] ----D- C:\Users\Matt\AppData\Roaming\AccurateRip

O43 - CFD: 25/09/2007 - 00:52:24 - [66776] ----D- C:\Users\Matt\AppData\Roaming\Ace

O43 - CFD: 05/09/2011 - 22:26:02 - [12671993] ----D- C:\Users\Matt\AppData\Roaming\Adobe

O43 - CFD: 19/08/2011 - 02:27:18 - [899] ----D- C:\Users\Matt\AppData\Roaming\Afycb

O43 - CFD: 06/02/2010 - 16:33:54 - [1021678534] ----D- C:\Users\Matt\AppData\Roaming\Apple Computer

O43 - CFD: 03/10/2009 - 15:41:36 - [1582863] ----D- C:\Users\Matt\AppData\Roaming\Azureus

O43 - CFD: 06/08/2011 - 23:25:36 - [6241142] ----D- C:\Users\Matt\AppData\Roaming\BitTorrent

O43 - CFD: 26/10/2007 - 13:48:50 - [512000] ----D- C:\Users\Matt\AppData\Roaming\BSplayer

O43 - CFD: 26/10/2007 - 13:43:56 - [6292] ----D- C:\Users\Matt\AppData\Roaming\BSplayer Pro

O43 - CFD: 09/08/2011 - 00:34:24 - [0] ----D- C:\Users\Matt\AppData\Roaming\c42f7236

O43 - CFD: 05/02/2008 - 00:51:22 - [26878] ----D- C:\Users\Matt\AppData\Roaming\CopyTrans

O43 - CFD: 05/02/2008 - 00:19:28 - [30740] ----D- C:\Users\Matt\AppData\Roaming\CopyTransControlCenter

O43 - CFD: 16/08/2009 - 21:23:16 - [17652] ----D- C:\Users\Matt\AppData\Roaming\CopyTransDoctor

O43 - CFD: 16/08/2009 - 19:03:18 - [0] ----D- C:\Users\Matt\AppData\Roaming\DAEMON Tools Lite

O43 - CFD: 08/09/2011 - 23:19:14 - [17827] ----D- C:\Users\Matt\AppData\Roaming\DNA

O43 - CFD: 16/07/2011 - 21:08:32 - [951] ----D- C:\Users\Matt\AppData\Roaming\dvdcss

O43 - CFD: 26/06/2010 - 02:14:14 - [5719763] ----D- C:\Users\Matt\AppData\Roaming\Facebook

O43 - CFD: 26/02/2007 - 22:53:06 - [3377] ----D- C:\Users\Matt\AppData\Roaming\FastStone

O43 - CFD: 02/12/2007 - 16:48:32 - [0] ----D- C:\Users\Matt\AppData\Roaming\GibbHill Properties Ltd

O43 - CFD: 12/02/2007 - 21:49:48 - [34314] ----D- C:\Users\Matt\AppData\Roaming\Google

O43 - CFD: 19/08/2011 - 01:47:14 - [0] ----D- C:\Users\Matt\AppData\Roaming\Icytvo

O43 - CFD: 04/12/2006 - 12:08:46 - [0] ----D- C:\Users\Matt\AppData\Roaming\Identities

O43 - CFD: 02/02/2007 - 23:02:28 - [0] ----D- C:\Users\Matt\AppData\Roaming\InterVideo

O43 - CFD: 02/09/2008 - 00:07:10 - [0] ----D- C:\Users\Matt\AppData\Roaming\Lavasoft

O43 - CFD: 02/02/2007 - 21:02:00 - [4150742] ----D- C:\Users\Matt\AppData\Roaming\Macromedia

O43 - CFD: 01/08/2011 - 00:53:50 - [8615786] ----D- C:\Users\Matt\AppData\Roaming\Malwarebytes

O43 - CFD: 02/11/2006 - 14:37:36 - [0] ----D- C:\Users\Matt\AppData\Roaming\Media Center Programs

O43 - CFD: 15/08/2011 - 18:37:42 - [7386648] -S--D- C:\Users\Matt\AppData\Roaming\Microsoft

O43 - CFD: 22/08/2011 - 21:10:26 - [30661135] ----D- C:\Users\Matt\AppData\Roaming\Mozilla

O43 - CFD: 18/12/2007 - 01:04:52 - [0] ----D- C:\Users\Matt\AppData\Roaming\Opera

O43 - CFD: 11/04/2011 - 22:16:04 - [269] ----D- C:\Users\Matt\AppData\Roaming\PhotoFiltre

O43 - CFD: 20/08/2011 - 11:30:20 - [41160891] ----D- C:\Users\Matt\AppData\Roaming\SanDisk

O43 - CFD: 22/02/2007 - 23:12:26 - [8096] R-H-D- C:\Users\Matt\AppData\Roaming\SecuROM

O43 - CFD: 12/06/2011 - 18:11:42 - [0] ----D- C:\Users\Matt\AppData\Roaming\SharePod

O43 - CFD: 06/08/2011 - 23:25:36 - [2404652] ----D- C:\Users\Matt\AppData\Roaming\Skype

O43 - CFD: 02/06/2007 - 13:34:08 - [2294499] ----D- C:\Users\Matt\AppData\Roaming\Sony Corporation

O43 - CFD: 27/08/2011 - 21:46:18 - [39713] ----D- C:\Users\Matt\AppData\Roaming\SpaceMonger

O43 - CFD: 07/01/2008 - 14:23:22 - [0] ----D- C:\Users\Matt\AppData\Roaming\Template

O43 - CFD: 24/06/2007 - 17:37:06 - [0] ----D- C:\Users\Matt\AppData\Roaming\Toshiba

O43 - CFD: 09/02/2007 - 19:26:46 - [4] ----D- C:\Users\Matt\AppData\Roaming\Uniblue

O43 - CFD: 05/09/2011 - 00:05:54 - [645631] ----D- C:\Users\Matt\AppData\Roaming\vlc

O43 - CFD: 23/08/2009 - 16:25:48 - [1458171] ----D- C:\Users\Matt\AppData\Local\Adobe

O43 - CFD: 21/12/2007 - 02:40:08 - [69980968] ----D- C:\Users\Matt\AppData\Local\Apple

O43 - CFD: 19/12/2010 - 03:11:38 - [54068088] ----D- C:\Users\Matt\AppData\Local\Apple Computer

O43 - CFD: 02/02/2007 - 20:33:26 - [0] -SH-D- C:\Users\Matt\AppData\Local\Application Data

O43 - CFD: 17/10/2007 - 00:15:08 - [0] ----D- C:\Users\Matt\AppData\Local\Apps

O43 - CFD: 21/01/2008 - 23:40:50 - [0] ----D- C:\Users\Matt\AppData\Local\Asobo Studio

O43 - CFD: 23/04/2008 - 21:03:04 - [10506238] ----D- C:\Users\Matt\AppData\Local\Bitmanagement Software

O43 - CFD: 20/01/2009 - 01:10:04 - [0] ----D- C:\Users\Matt\AppData\Local\DNA

O43 - CFD: 24/08/2009 - 20:54:16 - [596883796] ----D- C:\Users\Matt\AppData\Local\Google

O43 - CFD: 02/02/2007 - 20:33:26 - [0] -SH-D- C:\Users\Matt\AppData\Local\Historique

O43 - CFD: 28/12/2007 - 19:40:38 - [160149571] ----D- C:\Users\Matt\AppData\Local\Microsoft

O43 - CFD: 24/07/2011 - 23:17:58 - [13238] ----D- C:\Users\Matt\AppData\Local\Microsoft Corporation

O43 - CFD: 03/03/2007 - 20:34:16 - [1456623] ----D- C:\Users\Matt\AppData\Local\Microsoft Games

O43 - CFD: 08/12/2007 - 19:48:10 - [65293955] ----D- C:\Users\Matt\AppData\Local\Mozilla

O43 - CFD: 06/11/2010 - 11:13:40 - [2149448] ----D- C:\Users\Matt\AppData\Local\PokerStars

O43 - CFD: 09/10/2010 - 17:51:22 - [0] ----D- C:\Users\Matt\AppData\Local\Sunbelt Software

O43 - CFD: 08/09/2011 - 23:20:20 - [33384] ----D- C:\Users\Matt\AppData\Local\temp

O43 - CFD: 02/02/2007 - 20:33:26 - [0] -SH-D- C:\Users\Matt\AppData\Local\Temporary Internet Files

O43 - CFD: 21/12/2006 - 16:32:44 - [34693] ----D- C:\Users\Matt\AppData\Local\Toshiba

O43 - CFD: 02/02/2007 - 21:53:26 - [6713606] ----D- C:\Users\Matt\AppData\Local\VirtualStore

~ Scan Program Folder in 00mn 13s




---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)

O44 - LFC:[MD5.D4F8042CD2B651D15B63D74F840D378E] - 08/09/2011 - 21:21:08 ---A- . (...) -- C:\Windows\WindowsUpdate.log [24815]

O44 - LFC:[MD5.271117592DD1E98CC58E490125CA8AF9] - 08/09/2011 - 21:18:42 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]

O44 - LFC:[MD5.3A65872381030E52A1D4A7388F5D5ADC] - 05/09/2011 - 21:46:55 ---A- . (...) -- C:\ComboFix.txt [16111]

O44 - LFC:[MD5.3CF3D4A45CC2AF973DBC30EC8D33252B] - 05/09/2011 - 21:33:06 ---A- . (...) -- C:\Windows\system.ini [215]

O44 - LFC:[MD5.96C0CA43392D7147D1BC1D8C6CA45D68] - 05/09/2011 - 21:31:37 ---A- . (...) -- C:\Windows\PFRO.log [3670]

O44 - LFC:[MD5.753BC16326FEE4A421ACB636CCD602F4] - 05/09/2011 - 17:43:52 ---A- . (.NirSoft - NirCmd.) -- C:\Windows\NIRCMD.exe [60416]

O44 - LFC:[MD5.A46842C9B0C567A5A9584E83A163560C] - 05/09/2011 - 17:43:52 ---A- . (.SteelWerX - Freeware implementation of REG.EXE.) -- C:\Windows\SWREG.exe [518144]

O44 - LFC:[MD5.0297C72529807322B152F517FDB0A9FC] - 05/09/2011 - 17:43:52 ---A- . (.SteelWerX - Freeware implementation of SC.EXE.) -- C:\Windows\SWSC.exe [406528]

O44 - LFC:[MD5.B1A9CF0B6F80611D31987C247EC630B4] - 05/09/2011 - 17:43:52 ---A- . (.SteelWerX - Freeware implementation of XCACLS.) -- C:\Windows\SWXCACLS.exe [212480]

O44 - LFC:[MD5.8182FF89C65E4D38B2DE4BB0FB18564E] - 01/09/2011 - 00:41:36 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\system32\drivers\GEARAspiWDM.sys [26600]

O44 - LFC:[MD5.005EE82BABF1D2D32188A75BEDF500A4] - 01/09/2011 - 00:41:36 ---A- . (.GEAR Software Inc. - GEARAspi (x86).) -- C:\Windows\system32\GEARAspi.dll [107368]

O44 - LFC:[MD5.9860E0446EB0490A4C44F647F1B33EC3] - 28/08/2011 - 21:28:10 ---A- . (...) -- C:\aaw7boot.log [25183]

O44 - LFC:[MD5.84E2BAF41430A967C0F8EC7E0CD27D94] - 28/08/2011 - 20:20:07 ---A- . (...) -- C:\Ad-Report-SCAN[2].txt [4072]

O44 - LFC:[MD5.B279EEB09E6F7CA578DCBE04093A96C7] - 28/08/2011 - 10:31:45 ---A- . (...) -- C:\Ad-Report-CLEAN[1].txt [5104]

O44 - LFC:[MD5.307B42DC13AEE90B240B3CBB4D33F9D5] - 28/08/2011 - 09:40:29 ---A- . (...) -- C:\Ad-Report-SCAN[1].txt [4837]

O44 - LFC:[MD5.E9344F2ACC7D69841432AC95E2D98FD1] - 27/08/2011 - 20:46:21 ---A- . (...) -- C:\Windows\system32\wnsm2i.rdb [4]

O44 - LFC:[MD5.F51C8102BF019AD2C59B9AD397617794] - 27/08/2011 - 20:43:41 ---A- . (...) -- C:\Windows\system32\PerfStringBackup.INI [1697198]

O44 - LFC:[MD5.576526BFE96B5C4CED719438B94A6119] - 27/08/2011 - 20:43:41 ---A- . (...) -- C:\Windows\system32\perfc009.dat [127716]

O44 - LFC:[MD5.2FC98A840A429B6266F5D9A38A85E766] - 27/08/2011 - 20:43:41 ---A- . (...) -- C:\Windows\system32\perfc00C.dat [147298]

O44 - LFC:[MD5.E4F24B46A4738C64980A614339A4D2CE] - 27/08/2011 - 20:43:41 ---A- . (...) -- C:\Windows\system32\perfh009.dat [665312]

O44 - LFC:[MD5.6DCEED90430B49825ECE04FE054E83C5] - 27/08/2011 - 20:43:41 ---A- . (...) -- C:\Windows\system32\perfh00C.dat [764018]

O44 - LFC:[MD5.CB17A47D090938A02DACB066D6D5A124] - 27/08/2011 - 18:19:23 ---A- . (...) -- C:\Windows\system32\rp_rules.dat [44]

O44 - LFC:[MD5.8A3D5B46FF8C9CED46304F1EBB5F9AFE] - 27/08/2011 - 18:19:23 ---A- . (...) -- C:\Windows\system32\rp_stats.dat [64]

O44 - LFC:[MD5.73CF233421AFCFF617879C27B8790AD0] - 19/08/2011 - 00:34:46 ---A- . (...) -- C:\scandisk.lnk [479]

O44 - LFC:[MD5.E42BC24ED4DBD4C23A59231A3CAA57C9] - 11/08/2011 - 02:06:33 ---A- . (...) -- C:\Windows\system32\MRT.INI [127]

O44 - LFC:[MD5.77CFB196DBEE4AB8E5A175326E907CFB] - 11/08/2011 - 02:02:09 ---A- . (...) -- C:\Windows\win.ini [388]

O44 - LFC:[MD5.F042EE4C8D66248D9B86DCF52ABAE416] - 26/06/2011 - 07:45:56 ---A- . (...) -- C:\Windows\PEV.exe [256000]

O44 - LFC:[MD5.0277C027A26428DB64EF4F64F52BB4FD] - 07/11/2010 - 18:20:24 ---A- . (...) -- C:\Windows\MBR.exe [208896]

O44 - LFC:[MD5.9E05A9C264C8A908A8E79450FCBFF047] - 31/08/2000 - 01:00:00 ---A- . (...) -- C:\Windows\grep.exe [80412]

O44 - LFC:[MD5.2B657A67AEBB84AEA5632C53E61E23BF] - 31/08/2000 - 01:00:00 ---A- . (...) -- C:\Windows\sed.exe [98816]

O44 - LFC:[MD5.5E832F4FAF5F481F2EAF3B3A48F603B8] - 31/08/2000 - 01:00:00 ---A- . (...) -- C:\Windows\zip.exe [68096]

~ Scan Files in 00mn 01s




---\\ Export de clé d'application autorisée (O47)

O47 - AAKE:Key Export SP - "C:\Program Files\BitTorrent\bittorrent.exe" [Enabled] .(.BitTorrent, Inc. - BitTorrent.) -- C:\Program Files\BitTorrent\bittorrent.exe

~ Scan Keys in 00mn 00s




---\\ Contrôle du Safe Boot (CSB) (O49)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\system32\Drivers\sermouse.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\system32\Drivers\vga.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\system32\Drivers\vgasave.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\system32\Drivers\volmgr.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Volume Manager Extension Driver.) -- C:\Windows\system32\Drivers\volmgrx.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\system32\Drivers\ipnat.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\system32\Drivers\nsiproxy.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Miniport.) -- C:\Windows\system32\Drivers\rdpencdd.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\system32\Drivers\sermouse.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\system32\Drivers\vga.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\system32\Drivers\vgasave.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\system32\Drivers\volmgr.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Volume Manager Extension Driver.) -- C:\Windows\system32\Drivers\volmgrx.sys

~ Scan CSB in 00mn 00s




---\\ Trojan Driver Search Data (HKLM) (O52)

O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm

O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\system32\iccvid.dll

O52 - TDSD: \Drivers32\"VIDC.dvsd"="C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll" . (...) -- (.not file.)

O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm

~ Scan Keys in 00mn 00s




---\\ ShareTools MSconfig StartupReg (O53)

O53 - SMSR:HKLM\...\startupreg\Google Update [Key] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Matt\AppData\Local\Google\Update\GoogleUpdate.exe

O53 - SMSR:HKLM\...\startupreg\iTunesHelper [Key] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe

O53 - SMSR:HKLM\...\startupreg\QuickTime Task [Key] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe

O53 - SMSR:HKLM\...\startupreg\SanDisk_Button_Manager.exe [Key] . (.Gemalto N.V. - SanDiskBackup.) -- C:\Users\Matt\AppData\Roaming\SanDisk\SanDisk_Button_Manager.exe

~ Scan SMSR Keys in 00mn 00s




---\\ Microsoft Control Security Providers (O54)

O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TS Single Sign On Security Package.) -- C:\Windows\system32\credssp.dll

O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TS Single Sign On Security Package.) -- C:\Windows\system32\credssp.dll

~ Scan Keys in 00mn 00s




---\\ Microsoft Windows Policies System (O55)

O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=2

O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1

O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1

O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0

O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0

O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=

O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=

O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0

O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1

O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1

O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0

O55 - MWPS:[HKLM\...\Policies\System] - "DisableRegistryTools"=0

~ Scan Keys in 00mn 00s




---\\ Microsoft Windows Policies Explorer (O56)

O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145

O56 - MWPE:[HKCU\...\policies\Explorer] - "NoLogOff"=0

O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDrives"=0

O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDrives"=0

~ Scan Keys in 00mn 00s




---\\ Liste des Drivers Système (O58)

O58 - SDL:[MD5.2EDC5BBAC6C651ECE337BDE8ED97C9FB] - 02/01/2007 - 10:51:38 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\system32\drivers\adp94xx.sys [420968]

O58 - SDL:[MD5.B84088CA3CDCA97DA44A984C6CE1CCAD] - 02/01/2007 - 10:51:32 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\system32\drivers\adpahci.sys [297576]

O58 - SDL:[MD5.7880C67BCCC27C86FD05AA2AFB5EA469] - 02/01/2007 - 10:50:35 ---A- . (.Adaptec, Inc. - Adaptec LH Ultra160 Driver (x86).) -- C:\Windows\system32\drivers\adpu160m.sys [98408]

O58 - SDL:[MD5.9AE713F8E30EFC2ABCCD84904333DF4D] - 02/01/2007 - 10:51:00 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\system32\drivers\adpu320.sys [147048]

O58 - SDL:[MD5.90395B64600EBB4552E26E178C94B2E4] - 02/01/2007 - 10:49:20 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\system32\drivers\aliide.sys [14952]

O58 - SDL:[MD5.7C2F57BCE81FA74933F0E1C84A97C9DB] - 02/01/2007 - 01:35:58 ---A- . (.Alps Electric Co., Ltd. - Alps Touch Pad Driver.) -- C:\Windows\system32\drivers\Apfiltr.sys [140800]

O58 - SDL:[MD5.5F673180268BB1FDB69C99B6619FE379] - 02/01/2007 - 10:50:09 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\system32\drivers\arc.sys [67688]

O58 - SDL:[MD5.957F7540B5E7F602E44648C7DE5A1C05] - 02/01/2007 - 10:50:10 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\system32\drivers\arcsas.sys [67688]

O58 - SDL:[MD5.9F9ACC7F7CCDE8A15C282D3F88B43309] - 02/01/2007 - 09:24:45 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\system32\drivers\BrFiltLo.sys [13568]

O58 - SDL:[MD5.56801AD62213A41F6497F96DEE83755A] - 02/01/2007 - 09:24:46 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\system32\drivers\BrFiltUp.sys [5248]

O58 - SDL:[MD5.B304E75CFF293029EDDF094246747113] - 02/01/2007 - 09:25:24 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\system32\drivers\BrSerId.sys [71808]

O58 - SDL:[MD5.203F0B1E73ADADBBB7B7B1FABD901F6B] - 02/01/2007 - 09:24:44 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\system32\drivers\BrSerWdm.sys [62336]

O58 - SDL:[MD5.BD456606156BA17E60A04E18016AE54B] - 02/01/2007 - 09:24:44 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\system32\drivers\BrUsbMdm.sys [12160]

O58 - SDL:[MD5.AF72ED54503F717A43268B3CC5FAEC2E] - 02/01/2007 - 09:24:47 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\system32\drivers\BrUsbSer.sys [11904]

O58 - SDL:[MD5.68DFC4BCFA33C91CBCFC86C058267398] - 25/01/2009 - 20:20:16 ---A- . (.EldoS Corporation - Callback File System Driver.) -- C:\Windows\system32\drivers\cbfs.sys [136744]

O58 - SDL:[MD5.45201046C776FFDAF3FC8A0029C581C8] - 02/01/2007 - 10:49:28 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\cmdide.sys [16488]

O58 - SDL:[MD5.AE1FDF7BF7BB6C6A70F67699D880592A] - 02/01/2007 - 10:50:11 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\system32\drivers\djsvs.sys [71272]

O58 - SDL:[MD5.F206E28ED74C491FD5D7C0A1119CE37F] - 02/01/2007 - 11:56:30 ---A- . (.Sony Corporation - Windows 2000 DMI Call Kernel Driver.) -- C:\Windows\system32\drivers\DMICall.sys [10216]

O58 - SDL:[MD5.5C940A174DFB2C42B9F6BA6EDC2BAA0B] - 02/01/2007 - 06:15:24 ---A- . (.Intel Corporation - Intel® PRO/100 Adapter NDIS 5.1 driver.) -- C:\Windows\system32\drivers\e100b325.sys [165760]

O58 - SDL:[MD5.7505290504C8E2D172FA378CC0497BCC] - 02/01/2007 - 08:30:55 ---A- . (.Intel Corporation - Pilote désérialisé NDIS 6 de la carte Intel® PRO/1000.) -- C:\Windows\system32\drivers\e1e6032.sys [200704]

O58 - SDL:[MD5.F88FB26547FD2CE6D0A5AF2985892C48] - 02/01/2007 - 08:30:54 ---A- . (.Intel Corporation - Pilote désérialisé NDIS 6 de la carte Intel® PRO/1000.) -- C:\Windows\system32\drivers\E1G60I32.sys [117760]

O58 - SDL:[MD5.E8F3F21A71720C84BCF423B80028359F] - 02/01/2007 - 10:51:34 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\system32\drivers\elxstor.sys [316520]

O58 - SDL:[MD5.8182FF89C65E4D38B2DE4BB0FB18564E] - 01/09/2011 - 12:17:00 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\system32\drivers\GEARAspiWDM.sys [26600]

O58 - SDL:[MD5.DF353B401001246853763C4B7AAA6F50] - 02/01/2007 - 10:50:10 ---A- . (.Hewlett-Packard Company - Smart Array Storport Driver.) -- C:\Windows\system32\drivers\HpCISSs.sys [37480]

O58 - SDL:[MD5.31F949D452201F2F0AF0C88D7DB512CD] - 02/01/2007 - 03:08:14 ---A- . (.Conexant Systems, Inc. - HSF_HWAZL WDM driver.) -- C:\Windows\system32\drivers\HSXHWAZL.sys [206848]

O58 - SDL:[MD5.6D2350BB6E77E800FC4BE4E5B7A2E89A] - 02/01/2007 - 03:08:04 ---A- . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- C:\Windows\system32\drivers\HSX_CNXT.sys [659968]

O58 - SDL:[MD5.53229DCF431D76434816CD29251168A0] - 02/01/2007 - 03:09:26 ---A- . (.Conexant Systems, Inc. - HSF_DP driver.) -- C:\Windows\system32\drivers\HSX_DPV.sys [986624]

O58 - SDL:[MD5.C957BF4B5D80B46C5017BF0101E6C906] - 02/01/2007 - 10:51:25 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver (base).) -- C:\Windows\system32\drivers\iaStorV.sys [232040]

O58 - SDL:[MD5.2D077BF86E843F901D8DB709C95B49A5] - 02/01/2007 - 10:50:17 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\system32\drivers\iirsp.sys [41576]

O58 - SDL:[MD5.BCED60D16156E428F8DF8CF27B0DF150] - 02/01/2007 - 10:50:07 ---A- . (.Integrated Technology Express, Inc. - ITE IT8211 ATA/ATAPI SCSI miniport.) -- C:\Windows\system32\drivers\iteatapi.sys [35944]

O58 - SDL:[MD5.06FA654504A498C30ADCA8BEC4E87E7E] - 02/01/2007 - 10:50:09 ---A- . (.Integrated Technology Express, Inc. - ITE IT8212 ATA RAID SCSI miniport.) -- C:\Windows\system32\drivers\iteraid.sys [35944]

O58 - SDL:[MD5.FE8300320281D658A7854D5CFC02A63F] - 11/02/2005 - 11:19:20 ---A- . (.MCCI - Sony Ericsson 750 Driver.) -- C:\Windows\system32\drivers\k750bus.sys [55216]

O58 - SDL:[MD5.A03516D5C5FB064835DFF8FD1C251E5D] - 11/02/2005 - 11:19:14 ---A- . (.MCCI - Windows 2000/XP support functions.) -- C:\Windows\system32\drivers\k750wh.sys [5744]

O58 - SDL:[MD5.A03516D5C5FB064835DFF8FD1C251E5D] - 11/02/2005 - 11:19:14 ---A- . (.MCCI - Windows 2000/XP support functions.) -- C:\Windows\system32\drivers\k750whnt.sys [5744]

O58 - SDL:[MD5.A2262FB9F28935E862B4DB46438C80D2] - 02/01/2007 - 10:50:04 ---A- . (.LSI Logic - LSI Logic Fusion-MPT FC Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_fc.sys [65640]

O58 - SDL:[MD5.30D73327D390F72A62F32C103DAF1D6D] - 02/01/2007 - 10:50:05 ---A- . (.LSI Logic - LSI Logic Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas.sys [65640]

O58 - SDL:[MD5.E1E36FEFD45849A95F1AB81DE0159FE3] - 02/01/2007 - 10:50:10 ---A- . (.LSI Logic - LSI Logic Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_scsi.sys [65640]

O58 - SDL:[MD5.A3442F017D533025F5EFB26DFB5A4CD0] - 25/01/2009 - 07:53:16 ---A- . (.Mediafour Corporation - MacDrive file system driver.) -- C:\Windows\system32\drivers\MDFSYSNT.SYS [293632]

O58 - SDL:[MD5.0CEA2D0D3FA284B85ED5B68365114F76] - 02/01/2007 - 06:26:58 ---A- . (.Conexant - Diagnostic Interface x86 Driver.) -- C:\Windows\system32\drivers\mdmxsdk.sys [12672]

O58 - SDL:[MD5.D153B14FC6598EAE8422A2037553ADCE] - 02/01/2007 - 10:49:53 ---A- . (.LSI Logic Corporation - MEGASAS RAID Controller Driver for Windows Vista/Longhorn for x.) -- C:\Windows\system32\drivers\megasas.sys [28776]

O58 - SDL:[MD5.4FBBB70D30FD20EC51F80061703B001E] - 02/01/2007 - 10:49:59 ---A- . (.LSI Logic Corporation - MegaRAID RAID Controller Driver for Windows Vista/Longhorn for.) -- C:\Windows\system32\drivers\Mraid35x.sys [33384]

O58 - SDL:[MD5.ACC6170D80C69E50145B370023B64ED3] - 02/01/2007 - 01:42:28 ---A- . (.Intel® Corporation - Intel® Wireless LAN Driver.) -- C:\Windows\system32\drivers\NETw3v32.sys [1786880]

O58 - SDL:[MD5.2E7FB731D4790A1BC6270ACCEFACB36E] - 02/01/2007 - 10:50:19 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\system32\drivers\nfrd960.sys [45160]

O58 - SDL:[MD5.E875C093AEC0C978A90F30C9E0DFBB72] - 02/01/2007 - 08:36:50 ---A- . (.N-trig Innovative Technologies - Pilote intégré de digitalisateur de tablette N-trig.) -- C:\Windows\system32\drivers\ntrigdigi.sys [20608]

O58 - SDL:[MD5.B4B983D2B0BD436298EA2F8CE63E20CF] - 02/01/2007 - 08:58:00 ---A- . (.NVIDIA Corporation - NVIDIA Compatible Windows 2000 Miniport Driver, Version 97.32.) -- C:\Windows\system32\drivers\nvlddmkm.sys [4451392]

O58 - SDL:[MD5.E69E946F80C1C31C53003BFBF50CBB7C] - 02/01/2007 - 10:50:24 ---A- . (.NVIDIA Corporation - NVIDIA® nForce RAID Driver.) -- C:\Windows\system32\drivers\nvraid.sys [88680]

O58 - SDL:[MD5.9E0BA19A28C498A6D323D065DB76DFFC] - 02/01/2007 - 10:50:13 ---A- . (.NVIDIA Corporation - NVIDIA® nForce Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor.sys [40040]

O58 - SDL:[MD5.49452BFCEC22F36A7A9B9C2181BC3042] - 25/01/2009 - 20:19:06 ---A- . (.Sonic Solutions - Px Engine Device Driver for Windows 2000/XP.) -- C:\Windows\system32\drivers\pxhelp20.sys [43872]

O58 - SDL:[MD5.CCDAC889326317792480C0A67156A1EC] - 02/01/2007 - 10:51:45 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\system32\drivers\ql2300.sys [900712]

O58 - SDL:[MD5.81A7E5C076E59995D54BC1ED3A16E60B] - 02/01/2007 - 10:50:35 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\system32\drivers\ql40xx.sys [106088]

O58 - SDL:[MD5.F2B3E0E54817BECDEDBC095B25DAA248] - 02/01/2007 - 14:08:36 ---A- . (.Ricoh - Description string for UvcFilter driver.) -- C:\Windows\system32\drivers\R5U870FLx86.sys [72704]

O58 - SDL:[MD5.5F598E844E7A465932507314444BD97A] - 02/01/2007 - 14:08:32 ---A- . (.Ricoh - Description string for UvcUpperFilter driver.) -- C:\Windows\system32\drivers\R5U870FUx86.sys [43904]

O58 - SDL:[MD5.0505DA5D357F18A5D42FC5DEDE6BC9A0] - 30/07/2011 - 20:32:51 ---A- . (.Sunbelt Software - Anti-Rootkit Engine.) -- C:\Windows\system32\drivers\SBREDrv.sys [101720]

O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 02/01/2007 - 07:37:21 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\system32\drivers\secdrv.sys [20480]

O58 - SDL:[MD5.AAD95FE3E005489C7156FA111F744EAF] - 05/07/2006 - 13:39:29 ---A- . (.Protection Technology (StarForce) - FrontLine Environment Driver.) -- C:\Windows\system32\drivers\sfdrv01.sys [59256]

O58 - SDL:[MD5.4D0CE0FADCA29E7DA68CE597AC9010BD] - 05/07/2006 - 13:46:06 ---A- . (.Protection Technology (StarForce) - FrontLine Environment Driver.) -- C:\Windows\system32\drivers\sfdrv01a.sys [63352]

O58 - SDL:[MD5.DAAD4C099EBF5094D32C373AC1AC0F3C] - 14/06/2006 - 15:56:56 ---A- . (.Protection Technology (StarForce) - FrontLine Helper Driver.) -- C:\Windows\system32\drivers\sfhlp02.sys [13680]

O58 - SDL:[MD5.107B772690050D3B19CBC637AD8FD96E] - 12/01/2007 - 19:09:53 ---A- . (.Protection Technology (StarForce) - FrontLine File System Driver.) -- C:\Windows\system32\drivers\sfvfs02.sys [82296]

O58 - SDL:[MD5.4CDAF939DF995B0EEFD91E069BFDA30D] - 02/01/2007 - 05:30:34 ---A- . (.Silicon Image, Inc. - Serial ATA miniport driver.) -- C:\Windows\system32\drivers\SI3132.sys [74672]

O58 - SDL:[MD5.85F5613EBFE1C51A72D03BDAA1F7B912] - 02/01/2007 - 05:31:14 ---A- . (.Silicon Image, Inc. - Filter driver for Silicon Image SATALink controllers..) -- C:\Windows\system32\drivers\SiRemFil.sys [12464]

O58 - SDL:[MD5.CEDD6F4E7D84E9F98B34B3FE988373AA] - 02/01/2007 - 10:50:10 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\system32\drivers\sisraid2.sys [38504]

O58 - SDL:[MD5.DF843C528C4F69D12CE41CE462E973A7] - 02/01/2007 - 10:50:16 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\system32\drivers\sisraid4.sys [71784]

O58 - SDL:[MD5.E2BC0802646A08A443EE17A43DCBB68A] - 02/01/2007 - 05:31:46 ---A- . (.Silicon Image, Inc. - Windows Accelerator Driver.) -- C:\Windows\system32\drivers\SiWinAcc.sys [17328]

O58 - SDL:[MD5.2F30C6EC1904CDB6F32CA69622726EB4] - 02/01/2007 - 10:44:52 ---A- . (.Sony Corporation - Sony Image Filter Driver.) -- C:\Windows\system32\drivers\SonyImgF.sys [30976]

O58 - SDL:[MD5.DB31D8989B3450569C29780E7FA98C48] - 02/01/2007 - 12:34:22 ---A- . (.Sony Corporation - Sony Firmware Extension Parser driver.) -- C:\Windows\system32\drivers\SonyNC.sys [27520]

O58 - SDL:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 09/02/2007 - 00:00:00 ---A- . (...) -- C:\Windows\system32\drivers\sptd.sys [721904]

O58 - SDL:[MD5.09460DFF222BD1D2CB051C99EE4204E6] - 02/01/2007 - 06:18:44 ---A- . (.SigmaTel, Inc. - NDRC.) -- C:\Windows\system32\drivers\stwrt.sys [645120]

O58 - SDL:[MD5.192AA3AC01DF071B541094F251DEED10] - 02/01/2007 - 10:50:05 ---A- . (.LSI Logic - LSI Logic 8XX SCSI Miniport Driver.) -- C:\Windows\system32\drivers\symc8xx.sys [35944]

O58 - SDL:[MD5.8C8EB8C76736EBAF3B13B633B2E64125] - 02/01/2007 - 10:49:56 ---A- . (.LSI Logic - LSI Logic Hi-Perf SCSI Miniport Driver.) -- C:\Windows\system32\drivers\sym_hi.sys [31848]

O58 - SDL:[MD5.8072AF52B5FD103BBBA387A1E49F62CB] - 02/01/2007 - 10:50:03 ---A- . (.LSI Logic - LSI Logic Ultra160 SCSI Miniport Driver.) -- C:\Windows\system32\drivers\sym_u3.sys [34920]

O58 - SDL:[MD5.7C7445B4C2BD46C56ABB3499DA52B75C] - 02/01/2007 - 14:56:03 ---A- . (.Texas Instruments - ti21sony.sys.) -- C:\Windows\system32\drivers\ti21sony.sys [227328]

O58 - SDL:[MD5.E362D54FD394999C4178936396664E57] - 02/01/2007 - 18:58:56 ---A- . (.TOSHIBA Corporation. - Toshiba Bluetooth HID mini port driver.) -- C:\Windows\system32\drivers\Toshidpt.sys [3712]

O58 - SDL:[MD5.8D624D3BD1F2D78BD1C01A2D4E954B4E] - 02/01/2007 - 19:33:22 ---A- . (.TOSHIBA Corporation - TOSHIBA Bluetooth Port Emulation Driver.) -- C:\Windows\system32\drivers\tosporte.sys [41600]

O58 - SDL:[MD5.B758FDA2E4389DC41688E4B8CEE832A0] - 02/01/2007 - 13:57:36 ---A- . (.TOSHIBA CORPORATION - Bluetooth RF Bus Driver.) -- C:\Windows\system32\drivers\tosrfbd.sys [113792]

O58 - SDL:[MD5.90C8525BC578AAFFE87C2D0ED4379E9E] - 02/01/2007 - 17:55:16 ---A- . (.TOSHIBA Corporation - Bluetooth RFBNEP Driver.) -- C:\Windows\system32\drivers\tosrfbnp.sys [36480]

O58 - SDL:[MD5.5BA1CA3B3CDDB1DDC67DF473F05D1EC2] - 02/01/2007 - 16:45:08 ---A- . (.TOSHIBA Corporation - Bluetooth RFCOMM Driver.) -- C:\Windows\system32\drivers\tosrfcom.sys [64896]

O58 - SDL:[MD5.28099A4E52148319AFA685D93A2244D0] - 02/01/2007 - 16:07:46 ---A- . (.TOSHIBA Corporation. - Bluetooth HID Driver from TOSHIBA.) -- C:\Windows\system32\drivers\TosRfhid.sys [73600]

O58 - SDL:[MD5.C52FD27B9ADF3A1F22CB90E6BCF9B0CB] - 02/01/2007 - 13:42:42 ---A- . (.TOSHIBA Corporation. - Bluetooth BNEP Driver.) -- C:\Windows\system32\drivers\tosrfnds.sys [18612]

O58 - SDL:[MD5.1FF09B64D1E0C82EE81026718D8D47C2] - 02/01/2007 - 16:09:22 ---A- . (.TOSHIBA Corporation - Bluetooth Audio Driver (WDM).) -- C:\Windows\system32\drivers\TosRfSnd.sys [53504]

O58 - SDL:[MD5.20CC46C5D3326122E1A0A8C9DAD00E0D] - 02/01/2007 - 00:29:10 ---A- . (.TOSHIBA CORPORATION - Bluetooth USB Miniport Driver.) -- C:\Windows\system32\drivers\tosrfusb.sys [40960]

O58 - SDL:[MD5.3CD4EA35A6221B85DCC25DAA46313F8D] - 02/01/2007 - 10:51:25 ---A- . (.ULi Electronics Inc. - ULi SATA Controller Driver.) -- C:\Windows\system32\drivers\uliahci.sys [235112]

O58 - SDL:[MD5.8514D0E5CD0534467C5FC61BE94A569F] - 02/01/2007 - 10:50:35 ---A- . (.Promise Technology, Inc. - Promise Ultra/Sata Series Driver for Win2003.) -- C:\Windows\system32\drivers\ulsata.sys [98408]

O58 - SDL:[MD5.38C3C6E62B157A6BC46594FADA45C62B] - 02/01/2007 - 10:50:45 ---A- . (.Promise Technology, Inc. - Promise SATAII150 Series Windows Drivers.) -- C:\Windows\system32\drivers\ulsata2.sys [115816]

O58 - SDL:[MD5.83CAFCB53201BBAC04D822F32438E244] - 01/09/2011 - 07:06:08 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\system32\drivers\usbaapl.sys [42496]

O58 - SDL:[MD5.FD2E3175FCADA350C7AB4521DCA187EC] - 02/01/2007 - 10:49:30 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\viaide.sys [17512]

O58 - SDL:[MD5.D984439746D42B30FC65A4C3546C6829] - 02/01/2007 - 10:50:41 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR X86-32.) -- C:\Windows\system32\drivers\vsmraid.sys [112232]

O58 - SDL:[MD5.5A7FF9A18FF6D7E0527FE3ABF9204EF8] - 02/01/2007 - 09:39:10 ---A- . (.Conexant Systems, Inc. - Modem Audio Device Driver.) -- C:\Windows\system32\drivers\XAudio.sys [8192]

O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 02/01/2007 - 08:09:42 ---A- . (...) -- C:\Windows\system32\ANSI.SYS [9029]

O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 02/01/2007 - 08:09:45 ---A- . (...) -- C:\Windows\system32\country.sys [27097]

O58 - SDL:[MD5.E6BC0F98FECEF245A0010D350C1A0B9B] - 02/01/2007 - 08:09:41 ---A- . (...) -- C:\Windows\system32\HIMEM.SYS [4768]

O58 - SDL:[MD5.492090267B9608C62B956CD29BE3AFB7] - 02/01/2007 - 08:09:44 ---A- . (...) -- C:\Windows\system32\KEY01.SYS [42809]

O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 02/01/2007 - 08:09:44 ---A- . (...) -- C:\Windows\system32\KEYBOARD.SYS [42537]

O58 - SDL:[MD5.FFFF296A08DBF2AC0126C62E3778AC0D] - 02/01/2007 - 08:09:29 ---A- . (...) -- C:\Windows\system32\NTDOS.SYS [27866]

O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 02/01/2007 - 08:09:35 ---A- . (...) -- C:\Windows\system32\NTDOS404.SYS [29146]

O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 02/01/2007 - 08:09:38 ---A- . (...) -- C:\Windows\system32\NTDOS411.SYS [29370]

O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 02/01/2007 - 08:09:40 ---A- . (...) -- C:\Windows\system32\NTDOS412.SYS [29274]

O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 02/01/2007 - 08:09:31 ---A- . (...) -- C:\Windows\system32\NTDOS804.SYS [29146]

O58 - SDL:[MD5.2E4112FB7D1B76E11ADFD7487B5D0E95] - 02/01/2007 - 08:09:20 ---A- . (...) -- C:\Windows\system32\NTIO.SYS [33952]

O58 - SDL:[MD5.A98EBD4C2DF983665BF2D1AF49949974] - 02/01/2007 - 08:09:23 ---A- . (...) -- C:\Windows\system32\NTIO404.SYS [34672]

O58 - SDL:[MD5.3F7E6406EDEF197C5CAAB2240EEF6F48] - 02/01/2007 - 08:09:24 ---A- . (...) -- C:\Windows\system32\NTIO411.SYS [35776]

O58 - SDL:[MD5.3E64D681B776CC57BDC38A46D881F85B] - 02/01/2007 - 08:09:26 ---A- . (...) -- C:\Windows\system32\NTIO412.SYS [35536]

O58 - SDL:[MD5.D86B6435729231C171432B4E77801BDB] - 02/01/2007 - 08:09:22 ---A- . (...) -- C:\Windows\system32\NTIO804.SYS [34672]

~ Scan Drivers in 00mn 05s




---\\ Liste des outils de nettoyage (O63)

O63 - Logiciel: ZHPDiag 1.28 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1

~ Scan ADS in 00mn 00s




---\\ Liste des services Legacy (O64)

O64 - Services: CurCS - ??/??/???? - C:\ComboFix\catchme.sys (.not file.) - catchme (catchme) .(...) - LEGACY_CATCHME

O64 - Services: CurCS - 22/08/2008 - C:\Windows\system32\drivers\cbfs.sys - CbFs(CbFs) .(.EldoS Corporation - Callback File System Driver.) - LEGACY_CBFS

O64 - Services: CurCS - 18/10/2006 - C:\Windows\system32\DRIVERS\DMICall.sys - Sony DMI Call service(DMICall) .(.Sony Corporation - Windows 2000 DMI Call Kernel Driver.) - LEGACY_DMICALL

O64 - Services: CurCS - ??/??/???? - C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys (.not file.) - esgiguard (esgiguard) .(...) - LEGACY_ESGIGUARD

O64 - Services: CurCS - 05/07/2006 - C:\Windows\system32\drivers\sfdrv01.sys - StarForce Protection Environment Driver (version 1.x)(sfdrv01) .(.Protection Technology (StarForce) - FrontLine Environment Driver.) - LEGACY_SFDRV01

O64 - Services: CurCS - 05/07/2006 - C:\Windows\system32\drivers\sfdrv01a.sys - StarForce Protection Environment Driver (version 1.x.a)(sfdrv01a) .(.Protection Technology (StarForce) - FrontLine Environment Driver.) - LEGACY_SFDRV01A

O64 - Services: CurCS - 14/06/2006 - C:\Windows\system32\drivers\sfhlp02.sys - StarForce Protection Helper Driver (version 2.x)(sfhlp02) .(.Protection Technology (StarForce) - FrontLine Helper Driver.) - LEGACY_SFHLP02

O64 - Services: CurCS - 12/01/2007 - C:\Windows\system32\drivers\sfvfs02.sys - StarForce Protection VFS Driver (version 2.x)(sfvfs02) .(.Protection Technology (StarForce) - FrontLine File System Driver.) - LEGACY_SFVFS02

O64 - Services: CurCS - 01/11/2006 - C:\Windows\system32\drivers\siwinacc.sys - SATALink driver accelerator(SiFilter) .(.Silicon Image, Inc. - Windows Accelerator Driver.) - LEGACY_SIFILTER

O64 - Services: CurCS - ??/??/???? - C:\Windows\system32\Drivers\sptd.sys - sptd (sptd) .(...) - LEGACY_SPTD

O64 - Services: CurCS - 04/08/2006 - C:\Windows\system32\DRIVERS\xaudio.sys - XAudio(XAudio) .(.Conexant Systems, Inc. - Modem Audio Device Driver.) - LEGACY_XAUDIO

~ Scan Services in 00mn 01s




---\\ File Associations Shell Spawning (O67)

O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (. - .) -- "%1" %*

O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\system32\shell32.dll

O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- "%1" %*

O67 - Shell Spawning: <.com> <ComFile>[HKLM\..\open\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- "%1" %*

O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe

O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe

O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe

O67 - Shell Spawning: <.exe> <exefile>[HKCU\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe

O67 - Shell Spawning: <.exe> <exefile>[HKU\..\open\Command] (...) -- C:\Windows\system32\config\systemprofile\AppData\Local\nfj.exe

O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\system32\shell32.dll

O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- "%1" %*

O67 - Shell Spawning: <.com> <ComFile>[HKCR\..\open\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- "%1" %*

O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe

O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe

O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe

~ Scan Keys in 00mn 00s




---\\ Start Menu Internet (O68)

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe

~ Scan Keys in 00mn 00s




---\\ Search Browser Infection (O69)

O69 - SBI: SearchScopes [HKCU] ${searchCLSID} [DefaultScope] - (@ieframe.dll,-12512) - Bing

O69 - SBI: SearchScopes [HKCU] {6C247B9D-04A8-4F04-B308-D0582265D29D} - (Google) - Google

O69 - SBI: SearchScopes [HKCU] {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (AVG Secure Search) - iGeared – A Community Toolbar for Smart Webmasters

~ Scan Keys in 00mn 00s




---\\ Internet Feature Controls (O81)

O81 - IFC: Internet Feature Controls [HKUS\.DEFAULT] [FEATURE_BROWSER_EMULATION] -- svchost.exe

O81 - IFC: Internet Feature Controls [HKUS\S-1-5-18] [FEATURE_BROWSER_EMULATION] -- svchost.exe

~ Scan Keys in 00mn 00s




---\\ Recherche particuliere à la racine de certains dossiers (O84)

[MD5.B55E9CC49FF03496C478273A0950D7FB] [sPRF][01/09/2008] (...) -- C:\Program Files\Lavasoft_Adaware_multi.exe [19153264]

[MD5.8919AF797D9DCF0F224CFE4ED88548C6] [sPRF][21/12/2007] (...) -- C:\Program Files\videoraipodtouchconverter_Installer.exe [7151099]

[MD5.0E6B9B7B6EF8ED324535A632AD8C1E04] [sPRF][29/10/2007] (...) -- C:\Program Files\vlc-0.8.6c-win32.exe [9679815]

~ Scan Files in 00mn 01s




---\\ Recherche d'infection Rogue (O86)


~ Scan Files in 00mn 00s




---\\ Firewall Active Exception List (FirewallRules) (O87)

O87 - FAEL: "{84E48B24-F2F7-4219-9A1E-21894EB4909E}" | In - Public - P6 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\Program Files\DNA\btdna.exe

O87 - FAEL: "{67EAD51B-3505-4E4B-A1C8-318A94B477FD}" | In - Public - P17 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\Program Files\DNA\btdna.exe

O87 - FAEL: "{514CAD07-E706-4688-A641-DD815AEA53EB}" | In - Public - P6 - TRUE | .(.BitTorrent, Inc. - BitTorrent.) -- C:\Program Files\BitTorrent\bittorrent.exe

O87 - FAEL: "{9FFF6818-9ADA-49B3-B4BB-7C9FB2B970B0}" | In - Public - P17 - TRUE | .(.BitTorrent, Inc. - BitTorrent.) -- C:\Program Files\BitTorrent\bittorrent.exe

O87 - FAEL: "{CC3AE0CD-0C29-44E4-8DBD-4D360EC85660}" |In - Public - P6 - TRUE | .(...) -- C:\Program Files\Bonjour\mDNSResponder.exe (.not file.)

O87 - FAEL: "{F3468DBA-CD99-462D-A617-976D47327236}" |In - Public - P17 - TRUE | .(...) -- C:\Program Files\Bonjour\mDNSResponder.exe (.not file.)

O87 - FAEL: "{EFA4DA92-F782-495E-BDCF-D452D1612402}" | In - Public - P6 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files\iTunes\iTunes.exe

O87 - FAEL: "{5F30FC77-BE86-4FA9-8260-CE0B14232970}" | In - Public - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files\iTunes\iTunes.exe

O87 - FAEL: "{A101A122-3CD5-40D6-B028-38132B1B093B}" | In - Public - P6 - FALSE | .(...) -- C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe

O87 - FAEL: "{17FE5BEB-EA17-48E2-B9D8-DF9C61B87E5F}" | In - Public - P17 - FALSE | .(...) -- C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe

O87 - FAEL: "TCP Query User{1295C9CD-2821-4DA8-91A1-6352F383A415}C:\program files\emule\emule.exe" |In - Public - P6 - TRUE | .(...) -- C:\program files\emule\emule.exe (.not file.)

O87 - FAEL: "UDP Query User{B62C87C6-DD3F-4A8D-83FD-EEFBE4B627A5}C:\program files\emule\emule.exe" |In - Public - P17 - TRUE | .(...) -- C:\program files\emule\emule.exe (.not file.)

O87 - FAEL: "TCP Query User{9DFCC76F-7DDD-4F45-AE59-89D5D2584227}C:\program files\sopcast\sopcast.exe" |In - Public - P6 - TRUE | .(...) -- C:\program files\sopcast\sopcast.exe (.not file.)

O87 - FAEL: "UDP Query User{FB0C63F7-8E8B-4282-B938-3C4B541A2488}C:\program files\sopcast\sopcast.exe" |In - Public - P17 - TRUE | .(...) -- C:\program files\sopcast\sopcast.exe (.not file.)

O87 - FAEL: "TCP Query User{FA45268A-7DCF-485A-8FED-7174D3C30962}C:\program files\sopcast\adv\sopadver.exe" |In - Public - P6 - TRUE | .(...) -- C:\program files\sopcast\adv\sopadver.exe (.not file.)

O87 - FAEL: "UDP Query User{C28F2345-5B78-4998-98F0-229FF3447D06}C:\program files\sopcast\adv\sopadver.exe" |In - Public - P17 - TRUE | .(...) -- C:\program files\sopcast\adv\sopadver.exe (.not file.)

O87 - FAEL: "TCP Query User{1A0B2D8B-EEEF-40F3-8C10-88E1C7F1C1EC}C:\program files\soulseek\slsk.exe" | In - Public - P6 - TRUE | .(.Pas de propriétaire - SoulSeek.) -- C:\program files\soulseek\slsk.exe

O87 - FAEL: "UDP Query User{46EF7D67-68E5-4502-91AD-D973CCA13BFE}C:\program files\soulseek\slsk.exe" | In - Public - P17 - TRUE | .(.Pas de propriétaire - SoulSeek.) -- C:\program files\soulseek\slsk.exe

O87 - FAEL: "TCP Query User{2FE62528-EE52-4010-99F5-BD2145E1E466}C:\program files\mozilla firefox\firefox.exe" | In - Public - P6 - TRUE | .(.Mozilla Corporation - Firefox.) -- C:\program files\mozilla firefox\firefox.exe

O87 - FAEL: "UDP Query User{29CFA443-5D64-4E28-B199-F380A1F6982F}C:\program files\mozilla firefox\firefox.exe" | In - Public - P17 - TRUE | .(.Mozilla Corporation - Firefox.) -- C:\program files\mozilla firefox\firefox.exe

O87 - FAEL: "{20112519-126F-48FE-8285-A5C4C9590CCE}" | In - Public - P6 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.dll

O87 - FAEL: "{139E471F-CB70-464F-A315-92B750D7A511}" | In - Public - P17 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.dll

O87 - FAEL: "{310DFBE7-07E5-41A5-AB0B-460549B0C0AF}" | In - Public - P6 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe

O87 - FAEL: "{7D0AFA5D-032E-4F9E-87A8-1C4E8602D4D5}" | In - Public - P17 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe

O87 - FAEL: "TCP Query User{45DBB206-C737-4F21-A6CA-AD25F50DD2F5}C:\users\matt\program files\dna\btdna.exe" | In - Public - P6 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\users\matt\program files\dna\btdna.exe

O87 - FAEL: "UDP Query User{F22AC7E9-9160-4E7E-8EFF-F96B31BBF848}C:\users\matt\program files\dna\btdna.exe" | In - Public - P17 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\users\matt\program files\dna\btdna.exe

O87 - FAEL: "TCP Query User{B347802D-B532-4988-A110-E5D2CA5F78D1}C:\users\matt\program files\dna\btdna.exe" | In - Private - P6 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\users\matt\program files\dna\btdna.exe

O87 - FAEL: "UDP Query User{BFD14251-6312-417D-830A-4E4B1B0F5AF1}C:\users\matt\program files\dna\btdna.exe" | In - Private - P17 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\users\matt\program files\dna\btdna.exe

O87 - FAEL: "{165B9827-4AF7-4870-AF09-B08075B8C6D7}" | In - Private - P6 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.dll

O87 - FAEL: "{4670BEC3-5130-4800-9210-CDD4916CCDF5}" | In - Private - P17 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.dll

O87 - FAEL: "{3EB155BB-3734-4CAA-BC49-075353B5F326}" | In - Private - P6 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe

O87 - FAEL: "{854D566D-EAA0-495B-9258-6E55D45541C3}" | In - Private - P17 - TRUE | .(.Google - Google Talk Plugin.) -- C:\Users\Matt\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe

O87 - FAEL: "TCP Query User{0666A263-B69E-461A-B48C-E22C7BEC5F23}C:\program files\dna\btdna.exe" | In - Private - P6 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\program files\dna\btdna.exe

O87 - FAEL: "UDP Query User{B6DCA486-4509-4C9F-A965-8EFBFD2958FA}C:\program files\dna\btdna.exe" | In - Private - P17 - TRUE | .(.BitTorrent, Inc. - DNA.) -- C:\program files\dna\btdna.exe

O87 - FAEL: "TCP Query User{058D2BD5-7A9D-4A68-804E-36BB5A3962B9}C:\program files\soulseek\slsk.exe" | In - Private - P6 - TRUE | .(.Pas de propriétaire - SoulSeek.) -- C:\program files\soulseek\slsk.exe

O87 - FAEL: "UDP Query User{20B98830-1474-4EC8-9602-D51824836C69}C:\program files\soulseek\slsk.exe" | In - Private - P17 - TRUE | .(.Pas de propriétaire - SoulSeek.) -- C:\program files\soulseek\slsk.exe

O87 - FAEL: "TCP Query User{159143BA-0A47-4DB7-A52D-CBEA6D2DAAA6}C:\program files\emule\emule.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files\emule\emule.exe (.not file.)

O87 - FAEL: "UDP Query User{53DE6241-9E85-46D7-A580-9FF26763A73A}C:\program files\emule\emule.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files\emule\emule.exe (.not file.)

O87 - FAEL: "TCP Query User{1F8AFBC9-5455-4695-B5A8-BB5147D3BB93}C:\program files\bittorrent\bittorrent.exe" | In - Private - P6 - TRUE | .(.BitTorrent, Inc. - BitTorrent.) -- C:\program files\bittorrent\bittorrent.exe

O87 - FAEL: "UDP Query User{ECB6AF88-1E49-4AA6-B977-C7A6C682DE06}C:\program files\bittorrent\bittorrent.exe" | In - Private - P17 - TRUE | .(.BitTorrent, Inc. - BitTorrent.) -- C:\program files\bittorrent\bittorrent.exe

O87 - FAEL: "TCP Query User{59D48740-417C-4236-8490-EBC832FEDBF0}C:\program files\mozilla firefox\firefox.exe" | In - Private - P6 - TRUE | .(.Mozilla Corporation - Firefox.) -- C:\program files\mozilla firefox\firefox.exe

O87 - FAEL: "UDP Query User{89CC35D7-FD81-4EBF-9E8D-C6C491CF58B5}C:\program files\mozilla firefox\firefox.exe" | In - Private - P17 - TRUE | .(.Mozilla Corporation - Firefox.) -- C:\program files\mozilla firefox\firefox.exe

O87 - FAEL: "{6B858B40-31C8-4FF4-8782-902075EA170F}" | In - Public - P6 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe

O87 - FAEL: "{3B6A6340-3E17-40EC-AA46-8DCB8901C469}" | In - Public - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe

O87 - FAEL: "{F9030FCE-3E72-42C0-BEB5-C3F16F4AC2C9}" | In - Private - P6 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe

O87 - FAEL: "{56D08488-2F00-4C14-A4A3-2C3A12FCBC3D}" | In - Private - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe

O87 - FAEL: "TCP Query User{DF698C2F-33FB-4F49-B412-E8D5B5F93887}C:\users\matt\appdata\roaming\macromedia\flash player\\bin\octoshape\octoshape.exe" | In - Private - P6 - TRUE | .(.Octoshape ApS.) -- C:\users\matt\appdata\roaming\macrom

O87 - FAEL: "UDP Query User{06F540C6-95C4-445E-8FCE-A304FF03B389}C:\users\matt\appdata\roaming\macromedia\flash player\\bin\octoshape\octoshape.exe" | In - Private - P17 - TRUE | .(.Octoshape ApS.) -- C:\users\matt\appdata\roaming\macro

O87 - FAEL: "TCP Query User{0A826A8D-0F78-4E65-BF8D-401FBD5CC111}C:\program files\google\google earth\plugin\geplugin.exe" | In - Private - P6 - TRUE | .(.Google - Google Earth.) -- C:\program files\google\google earth\plugin\geplugin.exe

O87 - FAEL: "UDP Query User{820FF97A-1BFA-46B9-8604-638A996F993D}C:\program files\google\google earth\plugin\geplugin.exe" | In - Private - P17 - TRUE | .(.Google - Google Earth.) -- C:\program files\google\google earth\plugin\geplugin.exe

O87 - FAEL: "{49A864EB-99ED-43E4-8CF5-FCA569A46F9F}" |In - Private - P6 - TRUE | .(...) -- C:\Users\Matt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DH8190VO\241fdfd[1].exe (.not file.)

O87 - FAEL: "{6BD9A413-5288-4E06-AB58-B305F2F1CF12}" |In - Private - P17 - TRUE | .(...) -- C:\Users\Matt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DH8190VO\241fdfd[1].exe (.not file.)

O87 - FAEL: "{F3F6C444-9E28-40FD-8A0C-FE97219A6097}" |In - Private - P6 - TRUE | .(...) -- C:\Windows\AppPatch\qslkpf.exe (.not file.)

O87 - FAEL: "{CA85E7CE-2E48-49C6-B7B0-10A903856D92}" |In - Private - P17 - TRUE | .(...) -- C:\Windows\AppPatch\qslkpf.exe (.not file.)

O87 - FAEL: "{716EEB25-F222-4069-8D60-DA484AB29787}" |In - Public - P6 - TRUE | .(...) -- C:\Windows\AppPatch\qslkpf.exe (.not file.)

O87 - FAEL: "{1895CCA3-D660-4F5B-B629-3FA4A53E06BF}" |In - Public - P17 - TRUE | .(...) -- C:\Windows\AppPatch\qslkpf.exe (.not file.)

O87 - FAEL: "TCP Query User{6C0F3AB7-932A-43EF-93AD-D709DDB32706}C:\program files\mozilla firefox\plugin-container.exe" | In - Private - P6 - TRUE | .(.Mozilla Corporation.) -- C:\program files\mozilla firefox\plugin-container.exe

O87 - FAEL: "UDP Query User{6F123AA8-6CA6-4781-853F-74FBFBDBD851}C:\program files\mozilla firefox\plugin-container.exe" | In - Private - P17 - TRUE | .(.Mozilla Corporation.) -- C:\program files\mozilla firefox\plugin-container.exe

O87 - FAEL: "TCP Query User{9BE1ABBF-E830-4A50-9BD9-3FFC3B44FED7}C:\users\matt\appdata\local\google\update\googleupdate.exe" | In - Private - P6 - TRUE | .(.Google Inc..) -- C:\users\matt\appdata\local\google\update\googleupdate.exe

O87 - FAEL: "UDP Query User{70F2EC4C-9A5B-4F8A-B95E-209BF3CA43EB}C:\users\matt\appdata\local\google\update\googleupdate.exe" | In - Private - P17 - TRUE | .(.Google Inc..) -- C:\users\matt\appdata\local\google\update\googleupdate.exe

O87 - FAEL: "TCP Query User{72799B76-90C0-47AD-950D-7F52815DA057}C:\program files\spybot - search & destroy\sdupdate.exe" | In - Private - P6 - TRUE | .(.Safer Networking Limited.) -- C:\program files\spybot - search & destroy\sdupdate.exe

O87 - FAEL: "UDP Query User{96F3CEC5-A8D6-497E-9E9E-906842165304}C:\program files\spybot - search & destroy\sdupdate.exe" | In - Private - P17 - TRUE | .(.Safer Networking Limited.) -- C:\program files\spybot - search & destroy\sdupdate.exe

O87 - FAEL: "TCP Query User{A5C1965C-090D-4D9B-A60F-83F56A7742B3}C:\program files\sony\vaio update 3\vaioupdt.exe" | In - Private - P6 - TRUE | .(.Sony Corporation - VAIO Update.) -- C:\program files\sony\vaio update 3\vaioupdt.exe

O87 - FAEL: "UDP Query User{B984729F-FE08-413B-9CBF-C6498CDBB2F7}C:\program files\sony\vaio update 3\vaioupdt.exe" | In - Private - P17 - TRUE | .(.Sony Corporation - VAIO Update.) -- C:\program files\sony\vaio update 3\vaioupdt.exe

O87 - FAEL: "TCP Query User{330D969F-54CA-48AD-A749-41B59A792C07}C:\program files\malwarebytes' anti-malware\mbam.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files\malwarebytes' anti-malware\mbam.exe (.not file.)

O87 - FAEL: "UDP Query User{6B48977D-A8E3-43B1-89C4-40DCF3F8C8A2}C:\program files\malwarebytes' anti-malware\mbam.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files\malwarebytes' anti-malware\mbam.exe (.not file.)

O87 - FAEL: "TCP Query User{7818D38B-B451-44E7-9241-7A9282940BDF}C:\program files\avira\antivir desktop\avnotify.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files\avira\antivir desktop\avnotify.exe (.not file.)

O87 - FAEL: "UDP Query User{B582C45C-B127-4A78-9D87-CA2A9CFFF94E}C:\program files\avira\antivir desktop\avnotify.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files\avira\antivir desktop\avnotify.exe (.not file.)

O87 - FAEL: "TCP Query User{C9166196-12E0-49C4-B3C4-4E0A73AA0A76}C:\program files\red kawa\video converter 3\rkvideoconverter.exe" | In - Private - P6 - TRUE | .(.Red Kawa Inc..) -- C:\program files\red kawa\video converter 3\rkvideoconverter.exe

O87 - FAEL: "UDP Query User{80203B07-6174-4040-9D69-AA58FDAAF24C}C:\program files\red kawa\video converter 3\rkvideoconverter.exe" | In - Private - P17 - TRUE | .(.Red Kawa Inc..) -- C:\program files\red kawa\video converter 3\rkvideoconverter.exe

O87 - FAEL: "{B1C1B2DF-A2BD-420B-910F-766DE2AEB792}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files\Bonjour\mDNSResponder.exe (.not file.)

O87 - FAEL: "{7D203B48-2729-489B-B847-6C761D31BE56}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files\Bonjour\mDNSResponder.exe (.not file.)

O87 - FAEL: "TCP Query User{4F59AD46-5B7E-426B-A35A-4D3F4ABD3866}C:\program files\itunes\itunes.exe" | In - Private - P6 - TRUE | .(.Apple Inc. - iTunes.) -- C:\program files\itunes\itunes.exe

O87 - FAEL: "UDP Query User{52A49439-18A0-4D03-952A-2A3D8767282A}C:\program files\itunes\itunes.exe" | In - Private - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\program files\itunes\itunes.exe

O87 - FAEL: "TCP Query User{37CAE5D6-E2AC-4171-AB65-54264D843542}C:\program files\common files\apple\mobile device support\" | In - Private - P6 - TRUE | .(.Apple Inc..) -- C:\program files\common files\apple\mobile devic

O87 - FAEL: "UDP Query User{76E7A423-C596-4840-898D-A3BA869385BA}C:\program files\common files\apple\mobile device support\" | In - Private - P17 - TRUE | .(.Apple Inc..) -- C:\program files\common files\apple\mobile devi

O87 - FAEL: "TCP Query User{7D911D1C-B0C6-4F94-AC8B-E9CEFCE38EF1}C:\program files\avira\antivir desktop\apnstub.exe" |In - Private - P6 - TRUE | .(...) -- C:\program files\avira\antivir desktop\apnstub.exe (.not file.)

O87 - FAEL: "UDP Query User{91CC2ADD-A219-4C70-9230-371780577E79}C:\program files\avira\antivir desktop\apnstub.exe" |In - Private - P17 - TRUE | .(...) -- C:\program files\avira\antivir desktop\apnstub.exe (.not file.)

O87 - FAEL: "TCP Query User{C7E85CA7-9CF9-4E21-861C-683A01B1C8DD}C:\program files\videolan\vlc\vlc.exe" | In - Private - P6 - TRUE | .(...) -- C:\program files\videolan\vlc\vlc.exe

O87 - FAEL: "UDP Query User{7297F383-256E-401C-BA1E-6D80FA80F0D0}C:\program files\videolan\vlc\vlc.exe" | In - Private - P17 - TRUE | .(...) -- C:\program files\videolan\vlc\vlc.exe

O87 - FAEL: "TCP Query User{0F7D565D-CD43-4A65-8072-6110237D50E7}C:\combofix\combofix-download.3xe" |In - Private - P6 - TRUE | .(...) -- C:\combofix\combofix-download.3xe (.not file.)

O87 - FAEL: "UDP Query User{38EC8024-667E-4349-85A9-F33C8AB787EB}C:\combofix\combofix-download.3xe" |In - Private - P17 - TRUE | .(...) -- C:\combofix\combofix-download.3xe (.not file.)

~ Scan Firewall in 00mn 01s




---\\ Scan Additionnel (O88)

Database Version : 8617 - (29/08/2011)

Clés trouvées (Keys found) : 0

Valeurs trouvées (Values found) : 0

Dossiers trouvés (Folders found) : 1

Fichiers trouvés (Files found) : 0


C:\Program Files\Enigma Software Group\SpyHunter =>Crapware.SpyHunter

~ Scan Additionnel in 00mn 10s




---\\ Recherche détournement de DNS routeur (O89)

Serveur : UnKnown


~ Scan DNS in 00mn 00s




---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)

SS - | Auto 0 | (AdobeActiveFileMonitor5.0) . (...) - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe

SS - | Auto 0 | (Apple Mobile Device) . (...) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

SS - | Auto 0 | (Bonjour Service) . (...) - C:\Program Files\Bonjour\mDNSResponder.exe

SS - | Auto 0 | (CLTNetCnService) . (...) - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

SS - | Auto 0 | (gupdate) . (...) - C:\Program Files\Google\Update\GoogleUpdate.exe

SS - | Demand 0 | (gupdatem) . (...) - C:\Program Files\Google\Update\GoogleUpdate.exe

SS - | Demand 06/09/2007 136120 | (gusvc) . (.Google.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

SS - | Demand 02/02/2007 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

SS - | Demand 0 | (iPod Service) . (...) - C:\Program Files\iPod\bin\iPodService.exe

SS - | Auto 0 | (M4iPodWPDService) . (...) - C:\Program Files\Common Files\Mediafour\iPod\M4iPodWPDService.exe

SS - | Demand 02/01/2007 57344 | (MSCSPTISRV) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AvLib\MSCSPTISRV.exe

SS - | Demand 02/01/2007 57344 | (PACSPTISVR) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AvLib\PACSPTISVR.exe

SS - | Auto 0 | (sfrem01) . (...) - C:\Windows\system32\sfrem01.exe

SS - | Demand 02/01/2007 69632 | (SPTISRV) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AvLib\SPTISRV.exe

SS - | Demand 02/01/2007 69632 | (SSScsiSV) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\AvLib\SSScsiSV.exe

SS - | Auto 0 | (STacSV) . (...) - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe

SS - | Auto 0 | (TOSHIBA Bluetooth Service) . (...) - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

SS - | Demand 02/01/2007 73728 | (VAIO Entertainment TV Device Arbitration Service) . (.Sony Corporation.) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe

SS - | Auto 182392 | (VAIO Event Service) . (...) - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe

SS - | Demand 02/01/2007 2523136 | (VAIOMediaPlatform-IntegratedServer-AppServer) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe

SS - | Demand 02/01/2007 1089536 | (VAIOMediaPlatform-IntegratedServer-UPnP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

SS - | Demand 02/01/2007 741376 | (VAIOMediaPlatform-UCLS-AppServer) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe

SS - | Demand 02/01/2007 1089536 | (VAIOMediaPlatform-UCLS-UPnP) . (.Sony Corporation.) - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

SS - | Demand 0 | (Vcsw) . (...) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

SS - | Auto 0 | (VzCdbSvc) . (...) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

SS - | Auto 0 | (VzFw) . (...) - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

SS - | Auto 02/01/2007 22016 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\system32\svchost.exe

SR - | Auto 05/09/2011 386560 | (XAudioService) . (.Conexant Systems, Inc..) - C:\Windows\system32\DRIVERS\xaudio.exe

~ Scan Services in 00mn 01s




---\\ Recherche Master Boot Record Infection (MBR)(O80)

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, GMER - Rootkit Detector and Remover

Run by Matt at 08/09/2011 23:23:29


device: opened successfully

user: MBR read successfully


Disk trace:

called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x85DE64D0]<<

1 ntkrnlpa!IofCallDriver[0x82427F3B] -> \Device\Harddisk0\DR0[0x859625E0]

3 nt[0x824B07E2] -> ntkrnlpa!IofCallDriver[0x82427F3B] -> [0x85306858]

5 acpi[0x8044332A] -> ntkrnlpa!IofCallDriver[0x82427F3B] -> [0x852E9BB0]

\Driver\atapi[0x8530F5C8] -> IRP_MJ_CREATE -> 0x85DE64D0

error: Read Un périphérique attaché au système ne fonctionne pas correctement.

kernel: MBR read successfully

detected disk devices:

detected hooks:

\Driver\atapi -> 0x8521d1f8

user & kernel MBR OK

Warning: possible MBR rootkit infection !

~ Scan MBR in 00mn 03s




---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)

Written by ad13, http://ad13.geekstog

Run by Matt at 08/09/2011 23:23:31


********* Dump file Name *********


~ Scan MBR in 00mn 05s




End of the scan (1331 lines in 01mn 16s)(0)

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
  • Créer...