Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés




J'ai récemment acheté un nouvel ordinateur avec Windows 7. Mais de temps en temps il rame beaucoup (effets visuels lents, son haché, ...)

Ca n'arrive pas tout le temps, donc j'ai l'impression qu'il s'agit d'un malware.


J'ai fait une analyse ZHPDiag dont voici le résultat :


Rapport de ZHPDiag v1.28.291 par Nicolas Coolman, Update du 17/12/2011

Run by Pierrotin at 23/12/2011 19:11:06

Web site : ZHPDiag Outil de diagnostic

State : Nouvelle version disponible



---\\ Web Browser

MSIE: Internet Explorer v9.0.8112.16421

MFIE: Mozilla Firefox 8.0.1 v8.0.1

GCIE: Google Chrome v16.0.912.63 (Defaut)


---\\ Windows Product Information

~ Langage: Français

Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)

Windows Server License Manager Script : OK

~ Windows® 7, OEM_SLP channel

System Locked Preinstallation (OEM_SLP) : OK

Windows ID Activation : OK

~ Windows Partial Key : 32W74

Windows License : OK

~ Windows Remaining Initializations Number : 2

Software Protection Service (Protection logicielle) : OK

Windows Automatic Updates : OK

Windows Activation Technologies : OK


---\\ System Information

~ Processor: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel

~ Operating System: 64 Bits

Boot mode: Normal (Normal boot)

Total RAM: 8139 MB (74% free)

System Restore: Activé (Enable)

System drive C: has 496 GB (73%) free of 678 GB


---\\ Logged in mode

~ Computer Name: PIERROTIN-PC

~ User Name: Pierrotin

~ All Users Names: UpdatusUser, Pierrotin, HomeGroupUser$, Administrateur,

~ Unselected Option: O45,O61,O62,O65,O66,O82,O89

Logged in as Administrator


---\\ Environnement Variables

~ System Unit : C:\

~ %AppData% : C:\Users\Pierrotin\AppData\Roaming\

~ %Desktop% : C:\Users\Pierrotin\Desktop\

~ %Favorites% : C:\Users\Pierrotin\Favorites\

~ %LocalAppData% : C:\Users\Pierrotin\AppData\Local\

~ %StartMenu% : C:\Users\Pierrotin\AppData\Roaming\Microsoft\Windows\Start Menu\

~ %Windir% : C:\Windows\

~ %System% : C:\Windows\system32\


---\\ DOS/Devices

C:\ Hard drive, Flash drive, Thumb drive (Free 496 Go of 678 Go)

D:\ CD-ROM drive (Not Inserted)

E:\ Hard drive, Flash drive, Thumb drive (Free 534 Go of 1397 Go)

F:\ CD-ROM drive (Not Inserted)




---\\ Security Center & Tools Informations

[HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyComputer: OK

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK

[HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

~ Scan Security Center in 00mn 00s




---\\ Recherche particulière de fichiers génériques

[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.14/10/2011 - 16:59:29.) -- C:\Windows\Explorer.exe [2871808]

[MD5.DD81D91FF3B0763C392422865C9AC12E] - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) (.14/07/2009 - 02:39:31.) -- C:\Windows\system32\rundll32.exe [45568]

[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\system32\Wininit.exe [129024]

[MD5.69151E566295E5A977FE71FFAFD3B3F8] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.15/12/2011 - 02:44:47.) -- C:\Windows\system32\wininet.dll [1390080]

[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.21/11/2010 - 04:24:29.) -- C:\Windows\system32\Winlogon.exe [390656]

[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.21/11/2010 - 04:24:16.) -- C:\Windows\system32\sppcomapi.dll [232448]

[MD5.0D57D091E06BB1E58E72E5D08479FDDF] - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows multi-utilisateurs.) (.21/11/2010 - 07:18:22.) -- C:\Windows\system32\fr-FR\user32.dll.mui [20480]

[MD5.D5B031C308A409A0A576BFF4CF083D30] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.14/10/2011 - 16:59:30.) -- C:\Windows\system32\drivers\AFD.sys [499200]

[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\drivers\atapi.sys [24128]

[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\drivers\Cdfs.sys [92160]

[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\drivers\Cdrom.sys [147456]

[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.21/11/2010 - 04:24:32.) -- C:\Windows\system32\drivers\DfsC.sys [102400]

[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\drivers\HDAudBus.sys [122368]

[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\drivers\i8042prt.sys [105472]

[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\drivers\IpNat.sys [116224]

[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.14/10/2011 - 16:59:23.) -- C:\Windows\system32\drivers\MRxSmb.sys [158208]

[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.21/11/2010 - 04:23:51.) -- C:\Windows\system32\drivers\netBT.sys [261632]

[MD5.A2F74975097F52A00745F9637451FDD8] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.14/10/2011 - 16:59:26.) -- C:\Windows\system32\drivers\ntfs.sys [1659776]

[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\drivers\Parport.sys [97280]

[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21/11/2010 - 04:24:33.) -- C:\Windows\system32\drivers\Rasl2tp.sys [129536]

[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\drivers\smb.sys [93184]

[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.21/11/2010 - 04:24:32.) -- C:\Windows\system32\drivers\tdx.sys [119296]

[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\drivers\volsnap.sys [295808]

~ Scan Generic Processes in 00mn 00s




---\\ Etat des fichiers cachés (Caché/Total)

~ Mes images (My Pictures) : 1/1579

~ Mes musiques (My Musics) : 3/359

~ Mes Videos (My Videos) : 1/5

~ Mes Favoris (My Favorites) : 3/14

~ Mes Documents (My Documents) : 2/26750

~ Mon Bureau (My Desktop) : 2/4

~ Menu demarrer (Programs) : 7/29

~ Scan Hidden Files in 00mn 18s




---\\ Processus lancés

[MD5.4872674151CB01FCD6CFF50556BC9A21] - (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [703088] [PID.4068]

[MD5.1136B11FB4B6A598051BD9648A798F7C] - (.Pas de propriétaire - Stage Remote Manager.) -- C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe [2022976] [PID.3308]

[MD5.7A15CB514C3D743F0DA6AD3470F364F6] - (.RME - Fireface Settings.) -- C:\Windows\System32\firefaceusb.exe [88064] [PID.3504]

[MD5.EB67F46854326F760D6031DEC675AF10] - (.RME - TotalMix FX.) -- C:\Windows\System32\TotalMixFX.exe [3362816] [PID.3424]

[MD5.C265BFF559718F341D16C8355B4EDAED] - (.Pas de propriétaire - Stage Remote Service.) -- C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe [474176] [PID.3760]

[MD5.CEA0461AAE4B8B6216F164501B1B5A10] - (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [4910912] [PID.3792]

[MD5.1326F5E02DD85318BB56AACC1BD854C6] - ( - Controls the LoopBe1 internal MIDI port..) -- C:\Program Files (x86)\\LoopBe1\loopBeMon.exe [273024] [PID.4104]

[MD5.2BCA6F878A80C0D9CD14CA27B9CCD6FF] - (.Pas de propriétaire - Alienware On-Screen Display.) -- C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe [1545584] [PID.4268]

[MD5.4A73AB8412D3AA6CFAD24051FF9DBFA7] - (.Intel Corporation - IAStorIcon.) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160] [PID.4292]

[MD5.2EF0B3C51971F51ED700C01CFBC5B82A] - (.Creative Technology Ltd - Webcam Central.) -- C:\Program Files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe [503942] [PID.4356]

[MD5.4164A47F3A2DA7EA44572904C3DF44A4] - (.Pas de propriétaire - Roxio Burn Launcher.) -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544] [PID.4540]

[MD5.AD7E89D547F133D178EA7B4C3CB1B134] - (.Pas de propriétaire - desktop weather widget.) -- C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe [885760] [PID.4640]

[MD5.444EB38A256BE60F2013488C49D2AB3F] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [421736] [PID.4664]

[MD5.784627E486E9671615B45435EE676FA8] - (.SoftThinks - Dell - AlienRespawn Update Launcher.) -- C:\Program Files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe [315712] [PID.4244]

[MD5.E9DAAABF8CBD6B8F645CCA1BF58FE7C8] - (.SoftThinks - Dell - AlienRespawn.) -- C:\Program Files (x86)\AlienRespawn\TOASTER.EXE [3970880] [PID.4276]

[MD5.CD4F7B90CB09831BCDEDE0A206CCDB35] - (.Pas de propriétaire - ST Service Scheduling.) -- C:\Program Files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE [2751808] [PID.4168]

[MD5.DEB8C454A6D488F7FADB37DAA8DB083C] - (.Alienware Corporation - Alienware AlienFX Controller.) -- C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe [69584] [PID.5832]

[MD5.DFB18903DF3C4397991D96F50793C057] - (.Alienware - Hook32 Manager.) -- C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe [14792] [PID.1628]

[MD5.78D76239DF5A161C702FDECC7D6E4863] - (.Google Inc. - Google Chrome.) -- C:\Users\Pierrotin\AppData\Local\Google\Chrome\Application\chrome.exe [1047096] [PID.1940]

[MD5.C098B157C30C65E01E5D217C23705635] - (.Pas de propriétaire - AlienFusionController.) -- C:\Program Files\Alienware\Command Center\AlienFusionController.exe [16832] [PID.7424]

[MD5.6E3245DF783E58375B3465F03274743E] - (.Sun Microsystems, Inc. - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696] [PID.7336]

[MD5.A80C173AC5C75706BB74AE4D78F2A53D] - (.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe [164864] [PID.1712]

[MD5.7A62069635E0376A030E624A48EF80DC] - (.Nero AG - SyncUP.) -- C:\Program Files (x86)\Nero\SyncUP\SyncUP.exe [3110184] [PID.4448]

[MD5.B7C5410D1A88DADE14BFD135AA5B80DF] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [712192] [PID.4376]

[MD5.3DEBBECF665DCDDE3A95D9B902010817] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [55144] [PID.]

[MD5.74EC60E20516AAA573BE74F31175270F] - (.SoftThinks SAS - SoftThinks Agent Service.) -- C:\Program Files (x86)\AlienRespawn\sftservice.EXE [1692480] [PID.]

[MD5.79969ACAEEBEDA7DC3673656AB9918FD] - (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [378472] [PID.]

[MD5.8FFF9083252C16FE3960173722605E9E] - (.Intel Corporation - IAStorDataSvc.) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [13336] [PID.]

[MD5.9D1CCE440552500DED3A62F9D779CDB4] - (.Nero AG - NeroUpdate.) -- C:\Program Files (x86)\Nero\Update\NASvc.exe [503080] [PID.]

[MD5.4B7636C52A359AB0783B350A5FBDBB49] - (.NVIDIA Corporation - NVIDIA Settings Update Manager.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2009704] [PID.]

~ Scan Processes Running in 00mn 00s




---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)

C:\Users\Pierrotin\AppData\Local\Google\Chrome\User Data\Default\Preferences

G1 - GCS: Preference [user Data\Default] None

G0 - GCSP: Preference [user Data\Default][HomePage] Google

G2 - GCE: Preference [user Data\Default] [ddhjhhphjkenhkjllbmfjcgbbmedhbij] SoundCloud Sounds in Google Mail v.0.2.2 (Activé)

~ Scan Google Browser in 00mn 00s




---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)

P2 - FPN: [HKLM] [] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_27 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

P2 - FPN: [HKLM] [,version=10] - (...) -- C:\Program Files\mcafee\msc\npMcSnFFPl64.dll

P2 - FPN: [HKCU] [ Update;version=3] - (.Google Inc. - Google Update.) -- C:\Users\Pierrotin\AppData\Local\Google\Update\\npGoogleUpdate3.dll

P2 - FPN: [HKCU] [ Update;version=9] - (.Google Inc. - Google Update.) -- C:\Users\Pierrotin\AppData\Local\Google\Update\\npGoogleUpdate3.dll

~ Scan Firefox Browser in 00mn 00s




---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)

R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Dell - Ordinateurs de Bureau, PC Portables, Netbooks | Dell France

R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Search

R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = Search

R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Search

R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = Dell - Ordinateurs de Bureau, PC Portables, Netbooks | Dell France

R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons

R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk

R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons

R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk

R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)) -- C:\Windows\System32\ieframe.dll

R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1

R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1

~ Scan IE Browser in 00mn 00s




---\\ Internet Explorer, Proxy Management (R5)

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

~ Scan Proxy management in 00mn 00s




---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)

F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,

F2 - REG:system.ini: VMApplet=C:\Windows\system32\SystemPropertiesPerformance.exe

~ Scan Keys in 00mn 00s




---\\ Redirection du fichier Hosts (O1)

~ Le fichier hosts est sain (The hosts file is clean).

~ Scan Hosts File in 00mn 00s




---\\ Browser Helper Objects de navigateur (O2)

O2 - BHO: scriptproxy [64Bits] - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} . (.McAfee, Inc. - VSCore Script Scanner.) -- C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20111221220923.dll

O2 - BHO: Windows Live ID Sign-in Helper [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: AcroIEHelperStub [64Bits] - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: scriptproxy [64Bits] - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} . (.McAfee, Inc. - VSCore Script Scanner.) -- C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20111221220923.dll

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID [64Bits] - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\

O2 - BHO: Java Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

~ Scan BHO in 00mn 00s




---\\ Applications démarrées par registre & par dossier (O4)

O4 - HKLM\..\Run: [synTPEnh] . (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [NVHotkey] . (.NVIDIA Corporation - NVIDIA Hotkey Service, Version 267.21.) -- C:\Windows\system32\nvHotkey.dll

O4 - HKLM\..\Run: [igfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe

O4 - HKLM\..\Run: [RtHDVBg] . (.Realtek Semiconductor - HD Audio Background Process.) -- C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

O4 - HKLM\..\Run: [FreeFallProtection] . (.Pas de propriétaire - FF_Protection MFC Application.) -- C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe

O4 - HKLM\..\Run: [intelWireless] . (.Intel® Corporation - Intel® PROSet/Wireless Framework.) -- C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe

O4 - HKLM\..\Run: [Command Center Controllers] . (.Microsoft - RequiredApplicationsLauncher.) -- C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe

O4 - HKLM\..\Run: [stage Remote] . (.Pas de propriétaire - Stage Remote Manager.) -- C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe

O4 - HKLM\..\Run: [DellStage] . (.Pas de propriétaire - Dell Stage.) -- C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe

O4 - HKLM\..\Run: [FirefaceUsbTray1] . (.RME - Fireface Settings.) -- C:\Windows\System32\firefaceusb.exe

O4 - HKLM\..\Run: [FirefaceMixTray2] . (.RME - TotalMix FX.) -- C:\Windows\system32\TotalMixFX.exe

O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Pierrotin\AppData\Local\Google\Update\GoogleUpdate.exe

O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe

O4 - HKLM\..\Wow6432Node\Run: [AlienwareOn-ScreenDisplay] . (.Pas de propriétaire - Alienware On-Screen Display.) -- C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe

O4 - HKLM\..\Wow6432Node\Run: [iAStorIcon] . (.Intel Corporation - IAStorIcon.) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

O4 - HKLM\..\Wow6432Node\Run: [integrated Webcam Live! Central] . (.Creative Technology Ltd - Webcam Central.) -- C:\Program Files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe

O4 - HKLM\..\Wow6432Node\Run: [Dell Registration] . (.Dell, Inc. - System Registration.) -- C:\Program Files (x86)\System Registration\prodreg.exe

O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe

O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe

O4 - HKLM\..\Wow6432Node\Run: [RoxWatchTray] . (.Sonic Solutions - RoxMMTrayApp Module.) -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe

O4 - HKLM\..\Wow6432Node\Run: [Desktop Disc Tool] . (.Pas de propriétaire - Roxio Burn Launcher.) -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe

O4 - HKLM\..\Wow6432Node\Run: [mcui_exe] . (.McAfee, Inc. - McAfee Security Center.) -- C:\Program Files\\agent\mcagent.exe

O4 - HKLM\..\Wow6432Node\Run: [NeroLauncher] . (...) -- C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe

O4 - HKLM\..\Wow6432Node\Run: [AccuWeatherWidget] . (.Pas de propriétaire - desktop weather widget.) -- C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe

O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe

O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe

O4 - HKUS\S-1-5-20\..\Run: [sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe

O4 - HKUS\S-1-5-21-1848326168-4228689542-2198875216-1001-1848326168-4228689542-2198875216-1000\..\Run: [sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe

O4 - HKUS\S-1-5-21-1848326168-4228689542-2198875216-1001-1848326168-4228689542-2198875216-1000\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe

~ Scan Application in 00mn 00s




---\\ Autres liens utilisateurs (O4)

O4 - Global Startup: C:\Users\Pierrotin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

O4 - Global Startup: C:\Users\Pierrotin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

O4 - Global Startup: C:\Users\Pierrotin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk . (.Spotify Ltd.) -- C:\Users\Pierrotin\AppData\Roaming\Spotify\spotify.exe

O4 - Global Startup: C:\Users\Pierrotin\Desktop\Google Chrome.lnk . (.Google Inc..) -- C:\Users\Pierrotin\AppData\Local\Google\Chrome\Application\chrome.exe

O4 - Global Startup: C:\Users\Pierrotin\Desktop\Spotify.lnk . (.Spotify Ltd.) -- C:\Users\Pierrotin\AppData\Roaming\Spotify\spotify.exe

O4 - Global Startup: C:\Users\Pierrotin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

O4 - Global Startup: C:\Users\Pierrotin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk . (.Mozilla Messaging.) -- C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe

~ Scan Global Startup in 00mn 00s




---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)

O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no

~ Scan IE Control Panel in 00mn 00s




---\\ Winsock hijacker (Layered Service Provider) (O10)

O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\System32\nlaapi.dll

O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d’affectation de noms de messagerie.) -- C:\Windows\System32\NapiNSP.dll

O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\System32\pnrpnsp.dll

O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d’espace de noms PNRP.) -- C:\Windows\System32\pnrpnsp.dll

O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\System32\mswsock.dll

O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\System32\winrnr.dll

O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\System32\wshbth.dll

O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.dll

O10 - WLSP:\000000000009\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.dll

O10 - WLSP:\000000000010\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files (x86)\Bonjour\mdnsNSP.dll

~ Scan Winsock in 00mn 00s




---\\ Modification Domaine/Adresses DNS (O17)

O17 - HKLM\System\CCS\Services\Tcpip\..\{578B383F-31B9-468C-A0C3-ADA6BF097006}: DhcpNameServer =

O17 - HKLM\System\CCS\Services\Tcpip\..\{B5C9E144-C7AA-430B-91B2-FE6893EA7B2D}: DhcpNameServer =

O17 - HKLM\System\CCS\Services\Tcpip\..\{B5C9E144-C7AA-430B-91B2-FE6893EA7B2D}: DhcpDomain = dellris2tpdl.dellris1.ris

O17 - HKLM\System\CS1\Services\Tcpip\..\{578B383F-31B9-468C-A0C3-ADA6BF097006}: DhcpNameServer =

O17 - HKLM\System\CS1\Services\Tcpip\..\{B5C9E144-C7AA-430B-91B2-FE6893EA7B2D}: DhcpNameServer =

O17 - HKLM\System\CS1\Services\Tcpip\..\{B5C9E144-C7AA-430B-91B2-FE6893EA7B2D}: DhcpDomain = dellris2tpdl.dellris1.ris

O17 - HKLM\System\CS2\Services\Tcpip\..\{578B383F-31B9-468C-A0C3-ADA6BF097006}: DhcpNameServer =

O17 - HKLM\System\CS2\Services\Tcpip\..\{B5C9E144-C7AA-430B-91B2-FE6893EA7B2D}: DhcpNameServer =

O17 - HKLM\System\CS2\Services\Tcpip\..\{B5C9E144-C7AA-430B-91B2-FE6893EA7B2D}: DhcpDomain = dellris2tpdl.dellris1.ris

~ Scan Domain in 00mn 00s




---\\ Protocole additionnel (O18)

O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\System32\mshtml.dll

O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll

O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll

O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll

O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll

O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll

O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll

O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll

O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\System32\mshtml.dll

O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll

O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\System32\mshtml.dll

O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll

O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll

O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll

O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\System32\mshtml.dll

O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\MSVidCtl.dll

O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft ®.) -- C:\Windows\System32\mshtml.dll

O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll

O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll

O18 - Filter: application/x-mfe-ipt [64Bits] - {3EF5086B-5478-4598-A054-786C45D75692} . (.McAfee, Inc. - McAfee MSC IE plugin DLL.) -- C:\Program Files\mcafee\msc\McSnIePl64.dll

O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll

~ Scan Protocole Additionnel in 00mn 00s




---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)

O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\system32\igfxdev.dll

~ Scan Winlogon in 00mn 00s




---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)

O20 - AppInit_DLLs: . (.NVIDIA Corporation - NVIDIA Compatible NVIDIA shim initializatio.) - C:\Windows\system32\nvinitx.dll

~ Scan AppInit DLL in 00mn 00s




---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

~ Scan SSODL in 00mn 00s




---\\ Liste des services NT non Microsoft et non désactivés (O23)

O23 - Service: Andrea RT Filters Service (AERTFilters) . (.Andrea Electronics Corporation - Andrea filters APO access service (64-bit).) - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe

O23 - Service: Alienware Fusion Service (AlienFusionService) . (.Alienware - AlienFusionService.) - C:\Program Files\Alienware\Command Center\AlienFusionService.exe

O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) . (.Intel® Corporation - Intel® PROSet/Wireless Event Log Service.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe

O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation - IAStorDataSvc.) - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

O23 - Service: McAfee Personal Firewall Service (McMPFSvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

O23 - Service: McAfee Services (mcmscsvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

O23 - Service: McAfee VirusScan Announcer (McNaiAnn) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

O23 - Service: McAfee Network Agent (McNASvc) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

O23 - Service: McAfee Proxy Service (McProxy) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

O23 - Service: McAfee McShield (McShield) . (.McAfee, Inc. - McAfee On-Access Scanner service.) - C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe

O23 - Service: McAfee Firewall Core Service (mfefire) . (.McAfee, Inc. - McAfee Core Firewall Service.) - C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe

O23 - Service: McAfee Validation Trust Protection Service (mfevtp) . (.McAfee, Inc. - McAfee Process Validation Service.) - C:\Windows\system32\mfevtps.exe

O23 - Service: McAfee Anti-Spam Service (MSK80Service) . (.McAfee, Inc. - McAfee Service Host.) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

O23 - Service: C:\Program Files (x86)\Nero\Update\NASvc.exe (NAUpdate) . (.Nero AG - NeroUpdate.) - C:\Program Files (x86)\Nero\Update\NASvc.exe

O23 - Service: NVIDIA Driver Helper Service (NVSvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 267.2.) - C:\Windows\system32\nvvsvc.exe

O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) . (.NVIDIA Corporation - NVIDIA Settings Update Manager.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) . (.Intel® Corporation - Intel® PROSet/Wireless Registry Service.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) . (.Sonic Solutions - RoxWatch12 Module.) - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe

O23 - Service: SoftThinks Agent Service (SftService) . (.SoftThinks SAS - SoftThinks Agent Service.) - C:\Program Files (x86)\AlienRespawn\SftService.exe

O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) . (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

~ Scan Services in 00mn 00s




---\\ Enumération Active Desktop & MHTML Editor (O24)

O24 - Default MHTML Editor: Last - .(...) - (.not file.)

~ Scan Desktop Component in 00mn 00s




---\\ BootExecute (O34)

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

~ Scan Keys in 00mn 00s




---\\ Session Manager Key (AppCertDlls,KnownDLLs) (O36)

O36 - KnownDLLs: (clbcatq) . (.Microsoft Corporation - COM+ Configuration Catalog.) -- C:\Windows\system32\clbcatq.dll

O36 - KnownDLLs: (ole32) . (.Microsoft Corporation - Microsoft OLE pour Windows.) -- C:\Windows\system32\ole32.dll

O36 - KnownDLLs: (advapi32) . (.Microsoft Corporation - API avancées Windows 32.) -- C:\Windows\system32\advapi32.dll

O36 - KnownDLLs: (COMDLG32) . (.Microsoft Corporation - DLL commune de boîtes de dialogues.) -- C:\Windows\system32\COMDLG32.dll

O36 - KnownDLLs: (gdi32) . (.Microsoft Corporation - GDI Client DLL.) -- C:\Windows\system32\gdi32.dll

O36 - KnownDLLs: (IERTUTIL) . (.Microsoft Corporation - Run time utility for Internet Explorer.) -- C:\Windows\system32\IERTUTIL.dll

O36 - KnownDLLs: (IMAGEHLP) . (.Microsoft Corporation - Windows NT Image Helper.) -- C:\Windows\system32\IMAGEHLP.dll

O36 - KnownDLLs: (IMM32) . (.Microsoft Corporation - Multi-User Windows IMM32 API Client DLL.) -- C:\Windows\system32\IMM32.dll

O36 - KnownDLLs: (kernel32) . (.Microsoft Corporation - DLL du client API BASE Windows NT.) -- C:\Windows\system32\kernel32.dll

O36 - KnownDLLs: (LPK) . (.Microsoft Corporation - Language Pack.) -- C:\Windows\system32\LPK.dll

O36 - KnownDLLs: (MSCTF) . (.Microsoft Corporation - DLL de MSCTF Server.) -- C:\Windows\system32\MSCTF.dll

O36 - KnownDLLs: (MSVCRT) . (.Microsoft Corporation - Windows NT CRT DLL.) -- C:\Windows\system32\MSVCRT.dll

O36 - KnownDLLs: (NORMALIZ) . (.Microsoft Corporation - Unicode Normalization DLL.) -- C:\Windows\system32\NORMALIZ.dll

O36 - KnownDLLs: (NSI) . (.Microsoft Corporation - NSI User-mode interface DLL.) -- C:\Windows\system32\NSI.dll

O36 - KnownDLLs: (OLEAUT32) . (.Microsoft Corporation - Pas de description.) -- C:\Windows\system32\OLEAUT32.dll

O36 - KnownDLLs: (PSAPI) . (.Microsoft Corporation - Process Status Helper.) -- C:\Windows\system32\PSAPI.dll

O36 - KnownDLLs: (rpcrt4) . (.Microsoft Corporation - Runtime d’appel de procédure distante.) -- C:\Windows\system32\rpcrt4.dll

O36 - KnownDLLs: (sechost) . (.Microsoft Corporation - Host for SCM/SDDL/LSA Lookup APIs.) -- C:\Windows\system32\sechost.dll

O36 - KnownDLLs: (Setupapi) . (.Microsoft Corporation - Installation de L’API Windows.) -- C:\Windows\system32\Setupapi.dll

O36 - KnownDLLs: (SHELL32) . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\system32\SHELL32.dll

O36 - KnownDLLs: (SHLWAPI) . (.Microsoft Corporation - Bibliothèque d’utilitaires légers du Shell.) -- C:\Windows\system32\SHLWAPI.dll

O36 - KnownDLLs: (URLMON) . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\URLMON.dll

O36 - KnownDLLs: (user32) . (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\Windows\system32\user32.dll

O36 - KnownDLLs: (USP10) . (.Microsoft Corporation - Uniscribe Unicode script processor.) -- C:\Windows\system32\USP10.dll

O36 - KnownDLLs: (WININET) . (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\system32\WININET.dll

O36 - KnownDLLs: (WLDAP32) . (.Microsoft Corporation - DLL API LDAP Win32.) -- C:\Windows\system32\WLDAP32.dll

O36 - KnownDLLs: (WS2_32) . (.Microsoft Corporation - Windows Socket 2.0 32-Bit DLL.) -- C:\Windows\system32\WS2_32.dll

O36 - KnownDLLs: (DifxApi) . (.Microsoft Corporation - Driver Install Frameworks for API library m.) -- C:\Windows\system32\difxapi.dll

~ Scan Keys in 00mn 00s




---\\ Tâches planifiées en automatique (O39)

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1848326168-4228689542-2198875216-1001Core.job

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1848326168-4228689542-2198875216-1001UA.job

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job

O39 - APT:Automatic Planified Task - C:\Windows\Tasks\SystemToolsDailyTest.job

[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskUserS-1-5-21-1848326168-4228689542-2198875216-1001Core] (.Google Inc..) -- C:\Users\Pierrotin\AppData\Local\Google\Update\GoogleUpdate.exe

[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskUserS-1-5-21-1848326168-4228689542-2198875216-1001UA] (.Google Inc..) -- C:\Users\Pierrotin\AppData\Local\Google\Update\GoogleUpdate.exe

[MD5.AA91DB1BB44440165262CE7046F82F47] [APT] [PCDEventLauncher] (.PC-Doctor, Inc..) -- C:\Program Files\AlienAutopsy\sessionchecker.exe

[MD5.D7EBDA052E28500F65B7600DDCD3BE3E] [APT] [PCDoctorBackgroundMonitorTask] (.PC-Doctor, Inc..) -- C:\Program Files\AlienAutopsy\uaclauncher.exe

[MD5.D7EBDA052E28500F65B7600DDCD3BE3E] [APT] [PCDoctorBackgroundMonitorTask-Delay] (.PC-Doctor, Inc..) -- C:\Program Files\AlienAutopsy\uaclauncher.exe

[MD5.D7EBDA052E28500F65B7600DDCD3BE3E] [APT] [systemToolsDailyTest] (.PC-Doctor, Inc..) -- C:\Program Files\AlienAutopsy\uaclauncher.exe

[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe

~ Scan Scheduled Task in 00mn 03s




---\\ Composants installés (ActiveSetup Installed Components) (O40)

O40 - ASIC: Internet Explorer [64Bits] - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe

O40 - ASIC: Browser Customizations [64Bits] - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - Personnalisation d’IEAK.) -- C:\Windows\System32\iedkcs32.dll

O40 - ASIC: Java (Sun) [64Bits] - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\Program Files\Java\jre6\bin\regutils.dll

O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll

O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Windows Media Player.) -- C:\Windows\system32\wmp.dll

O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe

O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll

~ Scan Active Setup in 00mn 00s




---\\ Pilotes lancés au démarrage (O41)

O41 - Driver: C:\Windows\system32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys

O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\system32\DRIVERS\blbdrive.sys

O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\DRIVERS\cdrom.sys

O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\system32\Drivers\dfsc.sys

O41 - Driver: C:\Windows\system32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\system32\drivers\discache.sys

O41 - Driver: (dtsoftbus01) . (.DT Soft Ltd - DAEMON Tools Virtual Bus Driver.) - C:\Windows\system32\DRIVERS\dtsoftbus01.sys

O41 - Driver: (mfenlfk) . (.McAfee, Inc. - McAfee NDIS Light Filter Driver.) - C:\Windows\system32\DRIVERS\mfenlfk.sys

O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\DRIVERS\mssmbios.sys

O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\system32\DRIVERS\netbios.sys

O41 - Driver: C:\Windows\system32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\system32\DRIVERS\netbt.sys

O41 - Driver: C:\Windows\system32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\system32\drivers\nsiproxy.sys

O41 - Driver: C:\Windows\system32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\system32\DRIVERS\pacer.sys

O41 - Driver: C:\Windows\system32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\system32\DRIVERS\rdbss.sys

O41 - Driver: C:\Windows\system32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\DRIVERS\RDPCDD.sys

O41 - Driver: C:\Windows\system32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\system32\drivers\rdpencdd.sys

O41 - Driver: C:\Windows\system32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\system32\drivers\rdprefmp.sys

O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys

O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\system32\DRIVERS\termdd.sys

O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys

O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\system32\DRIVERS\vwififlt.sys

O41 - Driver: C:\Windows\system32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\system32\DRIVERS\wanarp.sys

O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\system32\DRIVERS\wfplwf.sys

~ Scan Drivers in 00mn 00s




---\\ Logiciels installés (O42)

O42 - Logiciel: AccelerometerP11 - (.STMicroelectronics.) [HKLM] -- {87434D51-51DB-4109-B68F-A829ECDCF380}

O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX

O42 - Logiciel: Adobe Reader X MUI - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-FFFF-7B44-AA0000000001}

O42 - Logiciel: Advanced Audio FX Engine - (.Creative Technology Ltd.) [HKLM] -- Advanced Audio FX Engine

O42 - Logiciel: AlienAutopsy - (.Dell Inc..) [HKLM] -- AlienAutopsy

O42 - Logiciel: AlienAutopsy - (.PC-Doctor, Inc..) [HKLM] -- {0090A87C-3E0E-43D4-AA71-A71B06563A4A}

O42 - Logiciel: AlienRespawn - (.Alienware.) [HKLM] -- {0ED7EE95-6A97-47AA-AD73-152C08A15B04}

O42 - Logiciel: AlienRespawn - Support Software - (.Pas de propriétaire.) [HKLM] -- {A9668246-FB70-4103-A1E3-66C9BC2EFB49}

O42 - Logiciel: Alienware M14x Manual - (.Alienware Corp..) [HKLM] -- InstallShield_{B90A9452-2233-4B2A-8277-5DC4FEC239CB}

O42 - Logiciel: Alienware M14x Manual - (.Alienware Corp..) [HKLM] -- {B90A9452-2233-4B2A-8277-5DC4FEC239CB}

O42 - Logiciel: Alienware On-Screen Display - (.Pas de propriétaire.) [HKLM] -- InstallShield_{0D69462F-99CC-4F8D-942E-666E21CE59F8}

O42 - Logiciel: Alienware Product Registration - (.Dell Inc..) [HKLM] -- {2A0F2CC5-3065-492C-8380-B03AA7106B1A}

O42 - Logiciel: Ambisone VST 2.02 - (.Pas de propriétaire.) [HKLM] -- Dynasone_VST_2.02

O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {343666E2-A059-48AC-AD67-230BF74E2DB2}

O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {75104836-CAC7-444E-A39E-3F54151942F5}

O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}

O42 - Logiciel: Audio Damage Mayhem VST v1.0 - (.Pas de propriétaire.) [HKLM] -- Audio Damage Mayhem VST v1.0

O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}

O42 - Logiciel: Chainer v1.0 - (.Pas de propriétaire.) [HKLM] -- Chainer 1.0

O42 - Logiciel: Command Center - (.Alienware Corp..) [HKLM] -- InstallShield_{A3A06A93-1106-4110-AE11-F9EC3A33322F}

O42 - Logiciel: Command Center - (.Alienware Corp..) [HKLM] -- {A3A06A93-1106-4110-AE11-F9EC3A33322F}

O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}

O42 - Logiciel: DAEMON Tools Lite - (.DT Soft Ltd.) [HKLM] -- DAEMON Tools Lite

O42 - Logiciel: Dell MusicStage - (.Fingertapps.) [HKLM] -- {0EE30424-E151-4CC5-8421-9886D0FDDB67}

O42 - Logiciel: Dell PhotoStage - (.ArcSoft.) [HKLM] -- {E4335E82-17B3-460F-9E70-39D9BC269DB3}

O42 - Logiciel: Dell Stage - (.Fingertapps.) [HKLM] -- {7D356F08-270A-4BA4-9B54-CF0C53463E8C}

O42 - Logiciel: Dell Stage Remote - (.ArcSoft.) [HKLM] -- {AF4D3C63-009B-4A17-B02E-D395065DD3F0}

O42 - Logiciel: Dell VideoStage - (.CyberLink Corp..) [HKLM] -- InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}

O42 - Logiciel: Dell VideoStage - (.CyberLink Corp..) [HKLM] -- {DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}

O42 - Logiciel: DirectX 9 Runtime - (.Sonic Solutions.) [HKLM] -- {AF9E97C1-7431-426D-A8D5-ABE40995C0B1}

O42 - Logiciel: EMSC - (.Compal Electronics, Inc..) [HKLM] -- {FEF06E73-A519-4510-8CF3-B66041B91D8A}

O42 - Logiciel: FabFilter One v3.0 - (.Pas de propriétaire.) [HKLM] -- FabFilter One v3.0

O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM] -- {488F0347-C4A7-4374-91A7-30818BEDA710}

O42 - Logiciel: Google Chrome - (.Google Inc..) [HKCU] -- Google Chrome

O42 - Logiciel: High-Definition Video Playback - (.Nero AG.) [HKLM] -- {237CCB62-8454-43E3-B158-3ACD0134852E}

O42 - Logiciel: IK Multimedia Amplitube DX/VST/RTAS v2.0 - (.Pas de propriétaire.) [HKLM] -- IK Multimedia Amplitube DX/VST/RTAS v2.0

O42 - Logiciel: IK Multimedia Authorization Manager version 1.0.5 - (.IK Multimedia.) [HKLM] -- {85BC0DCB-69E5-4279-AA25-F108EF896588}_is1

O42 - Logiciel: IK Multimedia Sampletank XL v2.0.2.R1 - (.Pas de propriétaire.) [HKLM] -- IK Multimedia Sampletank XL v2.0.2.R1

O42 - Logiciel: Integrated Webcam Live! Central - (.Creative Technology Ltd.) [HKLM] -- Integrated Webcam Live! Central

O42 - Logiciel: Intel PROSet Wireless - (.Pas de propriétaire.) [HKLM] -- ProInst

O42 - Logiciel: Intel® Control Center - (.Intel Corporation.) [HKLM] -- {F8A9085D-4C7A-41a9-8A77-C8998A96C421}

O42 - Logiciel: Intel® Processor Graphics - (.Intel Corporation.) [HKLM] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}

O42 - Logiciel: Intel® Rapid Storage Technology - (.Intel Corporation.) [HKLM] -- {3E29EE6C-963A-4aae-86C1-DC237C4A49FC}

O42 - Logiciel: Intel® Wireless Display - (.Intel Corporation.) [HKLM] -- {F84906ED-BB54-4889-B131-FED9C9056FC8}

O42 - Logiciel: Java 6 Update 27 (64-bit) - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F86416027FF}

O42 - Logiciel: Java 6 Update 29 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216027FF}

O42 - Logiciel: LinPlug & Dash Organ - (.Pas de propriétaire.) [HKLM] -- LinPlug & Dash Organ

O42 - Logiciel: Live 8.2.6 - (.Pas de propriétaire.) [HKLM] -- Live 8.2.6

O42 - Logiciel: Logiciel Intel® PROSet/Wireless WiFi - (.Intel Corporation.) [HKLM] -- {290D4DB2-F1B4-4B8E-918D-D71EF29A001B}

O42 - Logiciel: LoopBe1 - Internal MIDI Port - (.Pas de propriétaire.) [HKLM] -- LoopBe1

O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}

O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}

O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}

O42 - Logiciel: Magix Samplitude Professional v7.20 - (.Pas de propriétaire.) [HKLM] -- Magix Samplitude Professional v7.20

O42 - Logiciel: McAfee SecurityCenter - (.McAfee, Inc..) [HKLM] -- MSC

O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile

O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}

O42 - Logiciel: Microsoft .NET Framework 4 Extended - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Extended

O42 - Logiciel: Microsoft .NET Framework 4 Extended - (.Microsoft Corporation.) [HKLM] -- {8E34682C-8118-31F1-BC4C-98CD9675E1C2}

O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}

O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {710f4c1c-cc18-4c49-8cbf-51240c89a1a2}

O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 - (.Microsoft Corporation.) [HKLM] -- {8220EEFE-38CD-377E-8595-13398D740ACE}

O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 - (.Microsoft Corporation.) [HKLM] -- {5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}

O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 - (.Microsoft Corporation.) [HKLM] -- {820B6609-4C97-3A2B-B644-573B06A0F0CC}

O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM] -- {9A25302D-30C0-39D9-BD6F-21E6EC160475}

O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}

O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 - (.Microsoft Corporation.) [HKLM] -- {9BE518E6-ECC6-35A9-88E4-87755C07200F}

O42 - Logiciel: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 - (.Microsoft Corporation.) [HKLM] -- {196BB40D-1578-3D01-B289-BEFC77A11A1E}

O42 - Logiciel: Mozilla Firefox 8.0.1 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 8.0.1 (x86 fr)

O42 - Logiciel: Mozilla Thunderbird (8.0) - (.Mozilla.) [HKLM] -- Mozilla Thunderbird (8.0)

O42 - Logiciel: NVIDIA Logiciel système PhysX 9.10.0514 - (.NVIDIA Corporation.) [HKLM] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX

O42 - Logiciel: NVIDIA PhysX - (.NVIDIA Corporation.) [HKLM] -- {B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}

O42 - Logiciel: NVIDIA Pilote 3D Vision 267.21 - (.NVIDIA Corporation.) [HKLM] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision

O42 - Logiciel: NVIDIA Pilote graphique 267.21 - (.NVIDIA Corporation.) [HKLM] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver

O42 - Logiciel: NVIDIA Stereoscopic 3D Driver - (.NVIDIA Corporation.) [HKLM] -- NVIDIAStereo

O42 - Logiciel: Nero 10 Movie ThemePack Basic - (.Nero AG.) [HKLM] -- {F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}

O42 - Logiciel: Nero Control Center 10 - (.Nero AG.) [HKLM] -- {6DFB899F-17A2-48F0-A533-ED8D6866CF38}

O42 - Logiciel: Nero ControlCenter 10 Help (CHM) - (.Nero AG.) [HKLM] -- {523B2B1B-D8DB-4B41-90FF-C4D799E2758A}

O42 - Logiciel: Nero Core Components 10 - (.Nero AG.) [HKLM] -- {2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}

O42 - Logiciel: Nero Update - (.Nero AG.) [HKLM] -- {65BB0407-4CC8-4DC7-952E-3EEFDF05602A}

O42 - Logiciel: Notepad++ - (.Pas de propriétaire.) [HKLM] -- Notepad++

O42 - Logiciel: Ohmforce Predatohm VST2 v1.0 PRO - (.Pas de propriétaire.) [HKLM] -- Ohmforce Predatohm VST2 v1.0 PRO

O42 - Logiciel: PSP VintageWarmer v1.5d - (.Pas de propriétaire.) [HKLM] -- PSP VintageWarmer v1.5d

O42 - Logiciel: PhotoShowExpress - (.Sonic Solutions.) [HKLM] -- {3250260C-7A95-4632-893B-89657EB5545B}

O42 - Logiciel: PlugSound - Vol 02 - Fretted Instruments - (.Pas de propriétaire.) [HKLM] -- Fretted Instruments

O42 - Logiciel: RBVirtualFolder64Inst - (.Roxio, Inc..) [HKLM] -- {9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}

O42 - Logiciel: RME Fireface USB - (.RME Intelligent Audio Solutions.) [HKLM] -- FIREFACE_USB

O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}

O42 - Logiciel: Rob Papen and LinPlug Albino v1.0 - (.Pas de propriétaire.) [HKLM] -- Rob Papen and LinPlug Albino v1.0

O42 - Logiciel: Roxio Activation Module - (.Roxio.) [HKLM] -- {A121EEDE-C68F-461D-91AA-D48BA226AF1C}

O42 - Logiciel: Roxio BackOnTrack - (.Roxio.) [HKLM] -- {5A06423A-210C-49FB-950E-CB0EB8C5CEC7}

O42 - Logiciel: Roxio Burn - (.Roxio.) [HKLM] -- {7746BFAA-2B5D-4FFD-A0E8-4558F4668105}

O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}

O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {EF56258E-0326-48C5-A86C-3BAC26FC15DF}

O42 - Logiciel: Roxio Creator Starter - (.Roxio.) [HKLM] -- {F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}

O42 - Logiciel: Roxio Express Labeler 3 - (.Roxio.) [HKLM] -- {6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}

O42 - Logiciel: Roxio File Backup - (.Roxio.) [HKLM] -- {60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}

O42 - Logiciel: SampleTank FREE - (.IK Multimedia.) [HKLM] -- {6559654F-2F38-491F-8411-211517C3E635}

O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2478663

O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2518870

O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2539636

O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2572078

O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Extended (KB2416472) - (.Microsoft Corporation.) [HKLM] -- {8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2416472

O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Extended (KB2487367) - (.Microsoft Corporation.) [HKLM] -- {8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2487367

O42 - Logiciel: Skype 5.5 - (.Skype Technologies S.A..) [HKLM] -- {AA59DDE4-B672-4621-A016-4C248204957A}

O42 - Logiciel: Sonic CinePlayer Decoder Pack - (.Sonic Solutions.) [HKLM] -- {9A00EC4E-27E1-42C4-98DD-662F32AC8870}

O42 - Logiciel: SpinAudio RoomVerb M2 v2.1.153 - (.Pas de propriétaire.) [HKLM] -- SpinAudio RoomVerb M2 v2.1.153

O42 - Logiciel: Spotify - (.Pas de propriétaire.) [HKCU] -- Spotify

O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM] -- SynTPDeinstKey

O42 - Logiciel: SyncUP - (.Nero AG.) [HKLM] -- {40F06490-8C14-43AA-99D3-EEEFDBAC3CFC}

O42 - Logiciel: SyncUP - (.Nero AG.) [HKLM] -- {D92C9CCE-E5F0-4125-977A-0590F3225B74}

O42 - Logiciel: Ultrafunk Sonitus:fx R3 plug-in uninstaller - (.Pas de propriétaire.) [HKLM] -- Sonitus-fx-R3

O42 - Logiciel: Update for Microsoft .NET Framework 4 Client Profile (KB2468871) - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2468871

O42 - Logiciel: Update for Microsoft .NET Framework 4 Client Profile (KB2473228) - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2473228

O42 - Logiciel: Update for Microsoft .NET Framework 4 Client Profile (KB2533523) - (.Microsoft Corporation.) [HKLM] -- {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2533523

O42 - Logiciel: Update for Microsoft .NET Framework 4 Extended (KB2468871) - (.Microsoft Corporation.) [HKLM] -- {8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2468871

O42 - Logiciel: Update for Microsoft .NET Framework 4 Extended (KB2533523) - (.Microsoft Corporation.) [HKLM] -- {8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2533523

O42 - Logiciel: VLC media player 1.1.11 - (.VideoLAN.) [HKLM] -- VLC media player

O42 - Logiciel: WinRAR 4.00 (32 bits) - (.win.rar GmbH.) [HKLM] -- WinRAR archiver

O42 - Logiciel: Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite

O42 - Logiciel: Windows Live - (.Microsoft Corporation.) [HKLM] -- {34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}

O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {D45240D3-B6B3-4FF9-B243-54ECE3E10066}

O42 - Logiciel: Windows Live ID Sign-in Assistant - (.Microsoft Corporation.) [HKLM] -- {1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}

O42 - Logiciel: Windows Live Installer - (.Microsoft Corporation.) [HKLM] -- {0B0F231F-CE6A-483D-AA23-77B364F75917}

O42 - Logiciel: Windows Live Language Selector - (.Microsoft Corporation.) [HKLM] -- {180C8888-50F1-426B-A9DC-AB83A1989C65}

O42 - Logiciel: Windows Live Movie Maker - (.Microsoft Corporation.) [HKLM] -- {6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}

O42 - Logiciel: Windows Live Movie Maker - (.Microsoft Corporation.) [HKLM] -- {92EA4134-10D1-418A-91E1-5A0453131A38}

O42 - Logiciel: Windows Live PIMT Platform - (.Microsoft Corporation.) [HKLM] -- {83C292B7-38A5-440B-A731-07070E81A64F}

O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM] -- {A9BDCA6B-3653-467B-AC83-94367DA3BFE3}

O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM] -- {C893D8C0-1BA0-4517-B11C-E89B65E72F70}

O42 - Logiciel: Windows Live Photo Gallery - (.Microsoft Corporation.) [HKLM] -- {3336F667-9049-4D46-98B6-4C743EEBC5B1}

O42 - Logiciel: Windows Live SOXE - (.Microsoft Corporation.) [HKLM] -- {682B3E4F-696A-42DE-A41C-4C07EA1678B4}

O42 - Logiciel: Windows Live SOXE Definitions - (.Microsoft Corporation.) [HKLM] -- {200FEC62-3C34-4D60-9CE8-EC372E01C08F}

O42 - Logiciel: Windows Live UX Platform - (.Microsoft Corporation.) [HKLM] -- {CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}

O42 - Logiciel: Windows Live UX Platform Language Pack - (.Microsoft Corporation.) [HKLM] -- {05E379CC-F626-4E7D-8354-463865B303BF}

O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {D66F0C3C-24F2-4463-9E2F-4381E5C40A26}

O42 - Logiciel: rgc:audio Triangle II - (.Pas de propriétaire.) [HKLM] -- rgc:audio Triangle II Monophonic Synthesizer_is1


---\\ HKCU & HKLM Software Keys





[HKCU\Software\Apple Computer, Inc.]

[HKCU\Software\Apple Inc.]




[HKCU\Software\Creative Tech]

[HKCU\Software\DT Soft]




[HKCU\Software\IK Multimedia]









[HKCU\Software\NVIDIA Corporation]












[HKCU\Software\WinRAR SFX]




[HKCU\Software\rgc:audio software]

[HKLM\Software\AGEIA Technologies]


[HKLM\Software\ATI Technologies]




[HKLM\Software\Apple Computer, Inc.]

[HKLM\Software\Apple Inc.]






[HKLM\Software\Creative Tech]


[HKLM\Software\DT Soft]



[HKLM\Software\Dell Computer Corporation]




[HKLM\Software\GEAR Software]

[HKLM\Software\IK Multimedia]















[HKLM\Software\NVIDIA Corporation]






[HKLM\Software\Propellerhead Software]

[HKLM\Software\Realtek Semiconductor Corp.]




[HKLM\Software\SRS Labs]










[HKLM\Software\Waves Audio]



[HKLM\Software\Wise Solutions]








[HKLM\Software\rgc:audio software]

~ Scan Softwares in 00mn 00s




---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)

O43 - CFD: 17/12/2011 - 14:05:08 - [125,316] ----D- C:\Program Files\AlienAutopsy

O43 - CFD: 14/10/2011 - 15:44:02 - [245,880] ----D- C:\Program Files\Alienware

O43 - CFD: 14/12/2011 - 18:43:48 - [0,586] ----D- C:\Program Files\Bonjour

O43 - CFD: 14/12/2011 - 18:43:56 - [139,874] ----D- C:\Program Files\Common Files

O43 - CFD: 14/10/2011 - 16:05:22 - [0,012] ----D- C:\Program Files\dell stage

O43 - CFD: 21/11/2010 - 07:29:50 - [86,076] ----D- C:\Program Files\DVD Maker

O43 - CFD: 28/11/2011 - 18:30:40 - [0] -SH-D- C:\Program Files\Fichiers communs

O43 - CFD: 14/10/2011 - 15:32:40 - [118,054] ----D- C:\Program Files\Intel

O43 - CFD: 15/12/2011 - 09:00:36 - [5,915] ----D- C:\Program Files\Internet Explorer

O43 - CFD: 14/12/2011 - 18:44:38 - [1,999] ----D- C:\Program Files\iPod

O43 - CFD: 14/12/2011 - 18:45:00 - [4,365] ----D- C:\Program Files\iTunes

O43 - CFD: 14/10/2011 - 15:24:40 - [98,012] ----D- C:\Program Files\Java

O43 - CFD: 14/10/2011 - 15:57:50 - [282,575] ----D- C:\Program Files\mcafee

O43 - CFD: 14/10/2011 - 15:57:26 - [2,532] ----D- C:\Program Files\

O43 - CFD: 21/11/2010 - 07:29:46 - [142,324] ----D- C:\Program Files\Microsoft Games

O43 - CFD: 14/07/2009 - 06:32:40 - [0,025] ----D- C:\Program Files\MSBuild

O43 - CFD: 14/10/2011 - 15:11:56 - [275,979] ----D- C:\Program Files\NVIDIA Corporation

O43 - CFD: 14/10/2011 - 15:25:08 - [37,766] ----D- C:\Program Files\Realtek

O43 - CFD: 14/07/2009 - 06:32:40 - [35,109] ----D- C:\Program Files\Reference Assemblies

O43 - CFD: 14/10/2011 - 15:56:08 - [0,948] ----D- C:\Program Files\Roxio

O43 - CFD: 14/10/2011 - 17:01:36 - [1,597] ----D- C:\Program Files\STMicroelectronics

O43 - CFD: 14/10/2011 - 17:00:54 - [32,869] ----D- C:\Program Files\Synaptics

O43 - CFD: 14/07/2009 - 06:09:28 - [0] --H-D- C:\Program Files\Uninstall Information

O43 - CFD: 21/11/2010 - 07:19:02 - [3,853] ----D- C:\Program Files\Windows Defender

O43 - CFD: 21/11/2010 - 07:29:48 - [8,797] ----D- C:\Program Files\Windows Journal

O43 - CFD: 21/11/2010 - 07:19:02 - [6,359] ----D- C:\Program Files\Windows Mail

O43 - CFD: 21/11/2010 - 07:19:02 - [7,331] ----D- C:\Program Files\Windows Media Player

O43 - CFD: 28/11/2011 - 18:30:40 - [12,043] ----D- C:\Program Files\Windows NT

O43 - CFD: 21/11/2010 - 07:19:02 - [5,261] ----D- C:\Program Files\Windows Photo Viewer

O43 - CFD: 21/11/2010 - 04:31:36 - [0,233] ----D- C:\Program Files\Windows Portable Devices

O43 - CFD: 21/11/2010 - 07:19:02 - [6,718] ----D- C:\Program Files\Windows Sidebar

O43 - CFD: 14/12/2011 - 18:43:56 - [6,277] ----D- C:\Program Files\Common Files\Apple

O43 - CFD: 14/10/2011 - 15:32:40 - [29,163] ----D- C:\Program Files\Common Files\Intel

O43 - CFD: 14/10/2011 - 15:57:26 - [35,012] ----D- C:\Program Files\Common Files\mcafee

O43 - CFD: 08/12/2011 - 23:38:00 - [57,209] ----D- C:\Program Files\Common Files\Microsoft Shared

O43 - CFD: 14/07/2009 - 04:20:10 - [0,003] ----D- C:\Program Files\Common Files\Services

O43 - CFD: 14/07/2009 - 04:20:10 - [0,581] ----D- C:\Program Files\Common Files\SpeechEngines

O43 - CFD: 30/11/2011 - 16:54:44 - [11,629] ----D- C:\Program Files\Common Files\System

O43 - CFD: 28/11/2011 - 19:09:48 - [0] ----D- C:\ProgramData\Ableton

O43 - CFD: 14/10/2011 - 15:52:18 - [0,000] ----D- C:\ProgramData\Adobe

O43 - CFD: 14/12/2011 - 18:44:04 - [34,707] ----D- C:\ProgramData\Apple

O43 - CFD: 14/12/2011 - 18:44:38 - [42,923] ----D- C:\ProgramData\Apple Computer

O43 - CFD: 14/07/2009 - 06:08:58 - [0] -SH-D- C:\ProgramData\Application Data

O43 - CFD: 28/11/2011 - 18:30:40 - [0] -SH-D- C:\ProgramData\Bureau

O43 - CFD: 08/12/2011 - 21:20:22 - [0] ----D- C:\ProgramData\Creative

O43 - CFD: 29/11/2011 - 00:09:44 - [0,001] ----D- C:\ProgramData\DAEMON Tools Lite

O43 - CFD: 28/11/2011 - 18:38:22 - [45,486] ----D- C:\ProgramData\dell

O43 - CFD: 14/07/2009 - 06:08:58 - [0] -SH-D- C:\ProgramData\Desktop

O43 - CFD: 14/07/2009 - 06:08:58 - [0] -SH-D- C:\ProgramData\Documents

O43 - CFD: 28/11/2011 - 18:30:40 - [0] -SH-D- C:\ProgramData\Favoris

O43 - CFD: 14/07/2009 - 06:08:58 - [0] -SH-D- C:\ProgramData\Favorites

O43 - CFD: 29/11/2011 - 14:41:40 - [0,000] ----D- C:\ProgramData\IK Multimedia

O43 - CFD: 14/10/2011 - 15:47:34 - [0,011] ----D- C:\ProgramData\install_clap

O43 - CFD: 14/10/2011 - 16:20:34 - [0,012] ----D- C:\ProgramData\Intel

O43 - CFD: 14/10/2011 - 15:54:54 - [3,389] ----D- C:\ProgramData\Macrovision

O43 - CFD: 28/11/2011 - 19:55:10 - [12,526] ----D- C:\ProgramData\McAfee

O43 - CFD: 28/11/2011 - 18:30:40 - [0] -SH-D- C:\ProgramData\Menu Démarrer

O43 - CFD: 08/12/2011 - 12:45:38 - [116,894] ----D- C:\ProgramData\Microsoft

O43 - CFD: 28/11/2011 - 18:30:40 - [0] -SH-D- C:\ProgramData\Modèles

O43 - CFD: 14/10/2011 - 16:04:12 - [2,409] ----D- C:\ProgramData\Nero

O43 - CFD: 23/12/2011 - 18:53:52 - [6,048] ----D- C:\ProgramData\NVIDIA

O43 - CFD: 14/10/2011 - 08:06:32 - [0,764] ----D- C:\ProgramData\NVIDIA Corporation

O43 - CFD: 29/11/2011 - 16:04:18 - [20,528] ----D- C:\ProgramData\PCDr

O43 - CFD: 14/10/2011 - 15:56:10 - [17,271] ----D- C:\ProgramData\PhotoShow Shared Assets

O43 - CFD: 14/10/2011 - 15:33:12 - [0] ----D- C:\ProgramData\Roaming

O43 - CFD: 14/10/2011 - 16:20:50 - [20,832] ----D- C:\ProgramData\Roxio

O43 - CFD: 08/12/2011 - 19:43:26 - [17,984] ----D- C:\ProgramData\Skype

O43 - CFD: 04/12/2011 - 14:55:58 - [0,154] ----D- C:\ProgramData\Sonic

O43 - CFD: 14/07/2009 - 06:08:58 - [0] -SH-D- C:\ProgramData\Start Menu

O43 - CFD: 14/10/2011 - 15:24:22 - [0,000] ----D- C:\ProgramData\Sun

O43 - CFD: 14/10/2011 - 15:47:58 - [0,342] ----D- C:\ProgramData\Temp

O43 - CFD: 14/07/2009 - 06:08:58 - [0] -SH-D- C:\ProgramData\Templates

O43 - CFD: 14/10/2011 - 15:56:50 - [5,825] ----D- C:\ProgramData\Uninstall

O43 - CFD: 14/10/2011 - 15:28:00 - [2,282] ----D- C:\ProgramData\Vista32

O43 - CFD: 14/10/2011 - 15:28:00 - [3,071] ----D- C:\ProgramData\Vista64

O43 - CFD: 14/10/2011 - 15:30:42 - [0,323] ----D- C:\ProgramData\Win732

O43 - CFD: 14/10/2011 - 15:30:42 - [0,521] ----D- C:\ProgramData\Win764

O43 - CFD: 14/10/2011 - 15:28:00 - [2,043] ----D- C:\ProgramData\XP32

O43 - CFD: 14/12/2011 - 18:45:02 - [0,854] ----D- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}

O43 - CFD: 28/11/2011 - 19:09:48 - [154,982] ----D- C:\Users\Pierrotin\AppData\Roaming\Ableton

O43 - CFD: 28/11/2011 - 18:39:20 - [0] ----D- C:\Users\Pierrotin\AppData\Roaming\Adobe

O43 - CFD: 14/12/2011 - 18:59:16 - [0,194] ----D- C:\Users\Pierrotin\AppData\Roaming\Apple Computer

O43 - CFD: 28/11/2011 - 18:35:42 - [0,001] ----D- C:\Users\Pierrotin\AppData\Roaming\Creative

O43 - CFD: 29/11/2011 - 00:11:28 - [0,003] ----D- C:\Users\Pierrotin\AppData\Roaming\DAEMON Tools Lite

O43 - CFD: 28/11/2011 - 18:35:52 - [0,427] ----D- C:\Users\Pierrotin\AppData\Roaming\Dell

O43 - CFD: 28/11/2011 - 18:35:46 - [0] ----D- C:\Users\Pierrotin\AppData\Roaming\Dell Touch Zone

O43 - CFD: 29/11/2011 - 13:12:46 - [4,001] ----D- C:\Users\Pierrotin\AppData\Roaming\FabFilter

O43 - CFD: 28/11/2011 - 18:35:52 - [0,011] ----D- C:\Users\Pierrotin\AppData\Roaming\Fingertapps

O43 - CFD: 28/11/2011 - 18:35:20 - [0] ----D- C:\Users\Pierrotin\AppData\Roaming\Identities

O43 - CFD: 29/11/2011 - 14:47:30 - [0,000] ----D- C:\Users\Pierrotin\AppData\Roaming\IK Multimedia

O43 - CFD: 29/11/2011 - 14:41:40 - [0] ----D- C:\Users\Pierrotin\AppData\Roaming\InstallShield

O43 - CFD: 28/11/2011 - 18:30:50 - [0,001] ----D- C:\Users\Pierrotin\AppData\Roaming\Intel

O43 - CFD: 28/11/2011 - 18:35:40 - [0] ----D- C:\Users\Pierrotin\AppData\Roaming\Intel Corporation

O43 - CFD: 28/11/2011 - 18:35:40 - [0,000] ----D- C:\Users\Pierrotin\AppData\Roaming\Leadertech

O43 - CFD: 28/11/2011 - 18:42:32 - [0,007] ----D- C:\Users\Pierrotin\AppData\Roaming\Macromedia

O43 - CFD: 28/11/2011 - 19:38:14 - [0,000] ----D- C:\Users\Pierrotin\AppData\Roaming\Macrovision

O43 - CFD: 21/11/2010 - 07:29:26 - [0] ----D- C:\Users\Pierrotin\AppData\Roaming\Media Center Programs

O43 - CFD: 10/12/2011 - 14:13:12 - [2,718] -S--D- C:\Users\Pierrotin\AppData\Roaming\Microsoft

O43 - CFD: 14/12/2011 - 23:00:52 - [12,026] ----D- C:\Users\Pierrotin\AppData\Roaming\Mozilla

O43 - CFD: 28/11/2011 - 18:51:46 - [0,000] ----D- C:\Users\Pierrotin\AppData\Roaming\Nero

O43 - CFD: 28/11/2011 - 20:10:56 - [0,357] ----D- C:\Users\Pierrotin\AppData\Roaming\Notepad++

O43 - CFD: 29/11/2011 - 16:02:44 - [112,363] ----D- C:\Users\Pierrotin\AppData\Roaming\PCDr

O43 - CFD: 28/11/2011 - 18:35:44 - [0,032] ----D- C:\Users\Pierrotin\AppData\Roaming\Roxio

O43 - CFD: 28/11/2011 - 19:38:38 - [0] ----D- C:\Users\Pierrotin\AppData\Roaming\Roxio Burn

O43 - CFD: 08/12/2011 - 23:37:12 - [1,485] ----D- C:\Users\Pierrotin\AppData\Roaming\Skype

O43 - CFD: 11/12/2011 - 15:01:56 - [7,767] ----D- C:\Users\Pierrotin\AppData\Roaming\Spotify

O43 - CFD: 14/12/2011 - 20:46:18 - [121,778] ----D- C:\Users\Pierrotin\AppData\Roaming\Thunderbird

O43 - CFD: 05/12/2011 - 23:15:20 - [0,075] ----D- C:\Users\Pierrotin\AppData\Roaming\vlc

O43 - CFD: 28/11/2011 - 19:05:12 - [0,000] ----D- C:\Users\Pierrotin\AppData\Roaming\WinRAR

O43 - CFD: 29/11/2011 - 00:38:12 - [0,017] ----D- C:\Users\Pierrotin\AppData\Roaming\Xlutop

O43 - CFD: 14/12/2011 - 18:44:10 - [0] ----D- C:\Users\Pierrotin\AppData\Local\Apple

O43 - CFD: 14/12/2011 - 18:45:14 - [18,723] ----D- C:\Users\Pierrotin\AppData\Local\Apple Computer

O43 - CFD: 28/11/2011 - 18:30:50 - [0] -SH-D- C:\Users\Pierrotin\AppData\Local\Application Data

O43 - CFD: 28/11/2011 - 18:40:48 - [1,226] ----D- C:\Users\Pierrotin\AppData\Local\Apps

O43 - CFD: 28/11/2011 - 18:36:36 - [21,743] ----D- C:\Users\Pierrotin\AppData\Local\Dell

O43 - CFD: 28/11/2011 - 18:41:12 - [0] ----D- C:\Users\Pierrotin\AppData\Local\Deployment

O43 - CFD: 28/11/2011 - 18:41:34 - [691,449] ----D- C:\Users\Pierrotin\AppData\Local\Google

O43 - CFD: 28/11/2011 - 18:30:50 - [0] -SH-D- C:\Users\Pierrotin\AppData\Local\Historique

O43 - CFD: 22/12/2011 - 09:56:36 - [191,900] ----D- C:\Users\Pierrotin\AppData\Local\Microsoft

O43 - CFD: 14/12/2011 - 23:00:52 - [7,289] ----D- C:\Users\Pierrotin\AppData\Local\Mozilla

O43 - CFD: 23/12/2011 - 19:09:22 - [33,219] ----D- C:\Users\Pierrotin\AppData\Local\Nero

O43 - CFD: 28/11/2011 - 20:17:38 - [0,007] ----D- C:\Users\Pierrotin\AppData\Local\Nero_AG

O43 - CFD: 01/12/2011 - 19:31:50 - [0,021] ----D- C:\Users\Pierrotin\AppData\Local\SoftThinks

O43 - CFD: 11/12/2011 - 14:59:18 - [9,746] ----D- C:\Users\Pierrotin\AppData\Local\Spotify

O43 - CFD: 23/12/2011 - 19:11:14 - [383,993] ----D- C:\Users\Pierrotin\AppData\Local\Temp

O43 - CFD: 28/11/2011 - 18:30:50 - [0] -SH-D- C:\Users\Pierrotin\AppData\Local\Temporary Internet Files

O43 - CFD: 14/12/2011 - 20:46:18 - [5,790] ----D- C:\Users\Pierrotin\AppData\Local\Thunderbird

O43 - CFD: 28/11/2011 - 20:17:44 - [0,075] ----D- C:\Users\Pierrotin\AppData\Local\TotalMixFX

O43 - CFD: 29/11/2011 - 14:51:16 - [664,729] ----D- C:\Users\Pierrotin\AppData\Local\VirtualStore

O43 - CFD: 22/12/2011 - 09:57:32 - [0,016] ----D- C:\Users\Pierrotin\AppData\Local\Windows Live

O43 - CFD: 22/12/2011 - 09:57:30 - [0] ----D- C:\Users\Pierrotin\AppData\Local\{33A608C0-3539-45BF-A8D1-3ED34EB1CC18}

O43 - CFD: 22/12/2011 - 09:57:02 - [0] ----D- C:\Users\Pierrotin\AppData\Local\{643426E6-9041-452A-AA44-9361A1C3BB49}

O43 - CFD: 22/12/2011 - 10:22:10 - [0] ----D- C:\Users\Pierrotin\AppData\Local\{65B4EFE9-3555-4229-A9F9-9D04A9F2EF9F}

O43 - CFD: 28/11/2011 - 19:07:00 - [1884,767] ----D- C:\Program Files (x86)\Ableton

O43 - CFD: 14/10/2011 - 15:52:14 - [448,534] ----D- C:\Program Files (x86)\Adobe

O43 - CFD: 23/12/2011 - 18:54:10 - [330,525] ----D- C:\Program Files (x86)\AlienRespawn

O43 - CFD: 14/10/2011 - 15:27:14 - [2,423] ----D- C:\Program Files (x86)\Alienware On-Screen Display

O43 - CFD: 14/12/2011 - 18:44:08 - [2,316] ----D- C:\Program Files (x86)\Apple Software Update

O43 - CFD: 14/12/2011 - 18:43:48 - [0,602] ----D- C:\Program Files (x86)\Bonjour

O43 - CFD: 29/11/2011 - 00:38:12 - [0,806] ----D- C:\Program Files (x86)\Chainer

O43 - CFD: 14/10/2011 - 15:32:40 - [6,385] ----D- C:\Program Files (x86)\Cisco

O43 - CFD: 14/12/2011 - 18:43:40 - [601,565] ----D- C:\Program Files (x86)\Common Files

O43 - CFD: 14/10/2011 - 15:49:44 - [1,904] ----D- C:\Program Files (x86)\Creative

O43 - CFD: 14/10/2011 - 15:49:16 - [0,109] ----D- C:\Program Files (x86)\Creative Live! Cam

O43 - CFD: 14/10/2011 - 15:48:06 - [0,064] ----D- C:\Program Files (x86)\Cyberlink

O43 - CFD: 29/11/2011 - 00:10:16 - [24,459] ----D- C:\Program Files (x86)\DAEMON Tools Lite

O43 - CFD: 14/10/2011 - 16:04:20 - [319,942] ----D- C:\Program Files (x86)\Dell

O43 - CFD: 28/11/2011 - 18:38:22 - [167,833] ----D- C:\Program Files (x86)\Dell Stage

O43 - CFD: 28/11/2011 - 18:38:22 - [0,000] ----D- C:\Program Files (x86)\Dell Touch Software Suite

O43 - CFD: 29/11/2011 - 00:42:10 - [2,399] ----D- C:\Program Files (x86)\FabFilter

O43 - CFD: 29/11/2011 - 14:42:26 - [74,256] ----D- C:\Program Files (x86)\IK Multimedia

O43 - CFD: 29/11/2011 - 14:42:24 - [54,346] --H-D- C:\Program Files (x86)\InstallShield Installation Information

O43 - CFD: 14/10/2011 - 15:49:20 - [94,688] ----D- C:\Program Files (x86)\Integrated Webcam

O43 - CFD: 14/10/2011 - 15:30:10 - [25,385] ----D- C:\Program Files (x86)\Intel

O43 - CFD: 14/10/2011 - 15:45:16 - [52,083] ----D- C:\Program Files (x86)\Intel Corporation

O43 - CFD: 15/12/2011 - 09:00:36 - [4,915] ----D- C:\Program Files (x86)\Internet Explorer

O43 - CFD: 14/12/2011 - 18:45:00 - [140,752] ----D- C:\Program Files (x86)\iTunes

O43 - CFD: 28/11/2011 - 18:40:06 - [86,625] ----D- C:\Program Files (x86)\Java

O43 - CFD: 05/12/2011 - 22:44:20 - [110,502] ----D- C:\Program Files (x86)\Magix

O43 - CFD: 22/12/2011 - 09:40:38 - [1,199] ----D- C:\Program Files (x86)\McAfee

O43 - CFD: 14/10/2011 - 15:57:26 - [0,409] ----D- C:\Program Files (x86)\

O43 - CFD: 08/12/2011 - 12:46:08 - [1,745] ----D- C:\Program Files (x86)\Microsoft SQL Server Compact Edition

O43 - CFD: 12/02/2011 - 11:51:28 - [0,023] ----D- C:\Program Files (x86)\Microsoft.NET

O43 - CFD: 21/12/2011 - 22:09:24 - [36,422] ----D- C:\Program Files (x86)\Mozilla Firefox

O43 - CFD: 14/12/2011 - 20:46:06 - [38,259] ----D- C:\Program Files (x86)\Mozilla Thunderbird

O43 - CFD: 14/07/2009 - 06:32:40 - [0,025] ----D- C:\Program Files (x86)\MSBuild

O43 - CFD: 29/11/2011 - 20:06:18 - [0] ----D- C:\Program Files (x86)\MSXML 4.0

O43 - CFD: 29/11/2011 - 13:02:38 - [0,747] ----D- C:\Program Files (x86)\

O43 - CFD: 14/10/2011 - 16:04:12 - [219,968] ----D- C:\Program Files (x86)\Nero

O43 - CFD: 28/11/2011 - 20:10:50 - [10,911] ----D- C:\Program Files (x86)\Notepad++

O43 - CFD: 14/10/2011 - 15:12:30 - [106,253] ----D- C:\Program Files (x86)\NVIDIA Corporation

O43 - CFD: 29/11/2011 - 13:11:26 - [1,413] ----D- C:\Program Files (x86)\PSP VintageWarmer

O43 - CFD: 14/10/2011 - 15:24:48 - [3,205] ----D- C:\Program Files (x86)\Realtek

O43 - CFD: 14/07/2009 - 06:32:40 - [37,345] ----D- C:\Program Files (x86)\Reference Assemblies

O43 - CFD: 14/10/2011 - 15:56:20 - [452,887] ----D- C:\Program Files (x86)\Roxio

O43 - CFD: 29/11/2011 - 15:17:56 - [-313,631] ----D- C:\Program Files (x86)\SampleTank 2

O43 - CFD: 08/12/2011 - 19:43:26 - [16,555] R---D- C:\Program Files (x86)\Skype

O43 - CFD: 29/11/2011 - 13:18:32 - [2,061] ----D- C:\Program Files (x86)\Sonitus-fx-R3

O43 - CFD: 29/11/2011 - 13:10:26 - [9,327] ----D- C:\Program Files (x86)\SpinAudio

O43 - CFD: 14/10/2011 - 15:25:38 - [1,398] ----D- C:\Program Files (x86)\STMicroelectronics

O43 - CFD: 14/10/2011 - 15:51:40 - [4,010] ----D- C:\Program Files (x86)\System Registration

O43 - CFD: 14/10/2011 - 15:25:16 - [0] --H-D- C:\Program Files (x86)\Temp

O43 - CFD: 14/07/2009 - 05:57:08 - [0] --H-D- C:\Program Files (x86)\Uninstall Information

O43 - CFD: 05/12/2011 - 22:53:40 - [80,793] ----D- C:\Program Files (x86)\VideoLAN

O43 - CFD: 29/11/2011 - 18:25:40 - [724,411] ----D- C:\Program Files (x86)\vstplugins

O43 - CFD: 21/11/2010 - 07:19:02 - [0,500] ----D- C:\Program Files (x86)\Windows Defender

O43 - CFD: 08/12/2011 - 12:45:54 - [79,255] ----D- C:\Program Files (x86)\Windows Live

O43 - CFD: 21/11/2010 - 07:19:02 - [5,895] ----D- C:\Program Files (x86)\Windows Mail

O43 - CFD: 21/11/2010 - 07:19:02 - [4,791] ----D- C:\Program Files (x86)\Windows Media Player

O43 - CFD: 14/07/2009 - 06:32:40 - [11,632] ----D- C:\Program Files (x86)\Windows NT

O43 - CFD: 21/11/2010 - 07:19:02 - [4,213] ----D- C:\Program Files (x86)\Windows Photo Viewer

O43 - CFD: 21/11/2010 - 04:31:40 - [0,181] ----D- C:\Program Files (x86)\Windows Portable Devices

O43 - CFD: 21/11/2010 - 07:19:02 - [5,717] ----D- C:\Program Files (x86)\Windows Sidebar

O43 - CFD: 28/11/2011 - 19:02:44 - [3,868] ----D- C:\Program Files (x86)\WinRAR

O43 - CFD: 23/12/2011 - 19:11:32 - [7,698] ----D- C:\Program Files (x86)\ZHPDiag

O43 - CFD: 14/10/2011 - 15:52:22 - [17,968] ----D- C:\Program Files (x86)\Common Files\Adobe

O43 - CFD: 14/12/2011 - 18:44:38 - [98,968] ----D- C:\Program Files (x86)\Common Files\Apple

O43 - CFD: 14/10/2011 - 15:26:56 - [6,795] ----D- C:\Program Files (x86)\Common Files\InstallShield

O43 - CFD: 14/10/2011 - 08:07:30 - [13,585] ----D- C:\Program Files (x86)\Common Files\Intel

O43 - CFD: 14/10/2011 - 15:45:18 - [67,410] ----D- C:\Program Files (x86)\Common Files\Intel Corporation

O43 - CFD: 14/10/2011 - 15:24:04 - [1,201] ----D- C:\Program Files (x86)\Common Files\Java

O43 - CFD: 14/10/2011 - 15:57:50 - [4,013] ----D- C:\Program Files (x86)\Common Files\mcafee

O43 - CFD: 08/12/2011 - 12:45:00 - [20,982] ----D- C:\Program Files (x86)\Common Files\microsoft shared

O43 - CFD: 14/10/2011 - 16:03:16 - [46,407] ----D- C:\Program Files (x86)\Common Files\Nero

O43 - CFD: 14/10/2011 - 15:56:30 - [4,328] ----D- C:\Program Files (x86)\Common Files\PX Storage Engine

O43 - CFD: 14/10/2011 - 15:56:50 - [260,341] ----D- C:\Program Files (x86)\Common Files\Roxio Shared

O43 - CFD: 14/07/2009 - 04:20:10 - [0,003] ----D- C:\Program Files (x86)\Common Files\Services

O43 - CFD: 14/10/2011 - 15:56:18 - [3,591] ----D- C:\Program Files (x86)\Common Files\Sonic Shared

O43 - CFD: 14/07/2009 - 04:20:10 - [39,200] ----D- C:\Program Files (x86)\Common Files\SpeechEngines

O43 - CFD: 14/10/2011 - 15:56:16 - [0,699] ----D- C:\Program Files (x86)\Common Files\SureThing Shared

O43 - CFD: 30/11/2011 - 16:54:44 - [9,771] ----D- C:\Program Files (x86)\Common Files\System

O43 - CFD: 08/12/2011 - 12:43:18 - [0] ----D- C:\Program Files (x86)\Common Files\Windows Live

O43 - CFD: 29/11/2011 - 00:06:58 - [6,304] ----D- C:\Program Files (x86)\Common Files\Wise Installation Wizard

~ Scan Program Folder in 00mn 24s




---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)

O44 - LFC:[MD5.25ABEE9425E1953CB4063A57D64E1EFD] - 23/12/2011 - 18:58:04 ---A- . (...) -- C:\Windows\SysNative\PerfStringBackup.INI [1661710]

O44 - LFC:[MD5.96F59AF7C47B7797F8353500DCAA496B] - 23/12/2011 - 18:58:04 ---A- . (...) -- C:\Windows\SysNative\perfc009.dat [121080]

O44 - LFC:[MD5.9AE1F41EC4D4CC6BBB8DF7851617DF77] - 23/12/2011 - 18:58:04 ---A- . (...) -- C:\Windows\SysNative\perfc00C.dat [148792]

O44 - LFC:[MD5.71DBB1011CC2BC8017CE0153C4149B6D] - 23/12/2011 - 18:58:04 ---A- . (...) -- C:\Windows\SysNative\perfh009.dat [652148]

O44 - LFC:[MD5.67A6DAEB17252C10150DC09F8C493369] - 23/12/2011 - 18:58:04 ---A- . (...) -- C:\Windows\SysNative\perfh00C.dat [745306]

O44 - LFC:[MD5.25ABEE9425E1953CB4063A57D64E1EFD] - 23/12/2011 - 18:58:04 ---A- . (...) -- C:\Windows\system32\PerfStringBackup.INI [1661710]

O44 - LFC:[MD5.96F59AF7C47B7797F8353500DCAA496B] - 23/12/2011 - 18:58:04 RSHAD . (...) -- C:\Windows\system32\perfc009.dat [121080]

O44 - LFC:[MD5.9AE1F41EC4D4CC6BBB8DF7851617DF77] - 23/12/2011 - 18:58:04 RSHAD . (...) -- C:\Windows\system32\perfc00C.dat [148792]

O44 - LFC:[MD5.71DBB1011CC2BC8017CE0153C4149B6D] - 23/12/2011 - 18:58:04 RSHAD . (...) -- C:\Windows\system32\perfh009.dat [652148]

O44 - LFC:[MD5.67A6DAEB17252C10150DC09F8C493369] - 23/12/2011 - 18:58:04 RSHAD . (...) -- C:\Windows\system32\perfh00C.dat [745306]

O44 - LFC:[MD5.B0FB146AAAF3D551466072B96F41C2BF] - 23/12/2011 - 18:57:31 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1473330]

O44 - LFC:[MD5.6B9653C92B70EA0EE3703878BB5065DD] - 23/12/2011 - 18:53:49 ---A- . (...) -- C:\Windows\setupact.log [46420]

O44 - LFC:[MD5.BC8B8B163BF08ECD0DB51ED8789FDC26] - 23/12/2011 - 18:53:49 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]

O44 - LFC:[MD5.E1C9BDCB6C5B7C7BB09EFB32BDFEA9B6] - 22/12/2011 - 09:40:16 ---A- . (...) -- C:\Windows\PFRO.log [39560]

O44 - LFC:[MD5.22FD52626EC13522E0AA572D1B4B6994] - 19/12/2011 - 19:59:57 ---A- . (...) -- C:\Windows\sam7_E.INI [446]

O44 - LFC:[MD5.6574E58698BFB20DA3132B41D969D78F] - 19/12/2011 - 19:59:57 ---A- . (...) -- C:\Windows\win.ini [508]

O44 - LFC:[MD5.9AC9A7E49C23535AFA6F3FC5ED5537C7] - 17/12/2011 - 13:55:13 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]

O44 - LFC:[MD5.433C196FFEEA807FF74D772BBA296449] - 15/12/2011 - 11:18:16 ---A- . (...) -- C:\Windows\Active Setup Log.txt [1439]

O44 - LFC:[MD5.A669D2BDBB44AE6496C06A9416FA63F2] - 15/12/2011 - 11:17:54 ---A- . (...) -- C:\Windows\Active Setup Log.BAK [1439]

O44 - LFC:[MD5.23639E447ED667222E2E742DA6B2515F] - 15/12/2011 - 09:01:39 ---A- . (...) -- C:\Windows\SysNative\FNTCACHE.DAT [319144]

O44 - LFC:[MD5.23639E447ED667222E2E742DA6B2515F] - 15/12/2011 - 09:01:39 RSHAD . (...) -- C:\Windows\system32\FNTCACHE.DAT [319144]

O44 - LFC:[MD5.AC0612BEB517CACF463E1F5EE76E52FD] - 14/12/2011 - 18:45:01 ---A- . (.GEAR Software Inc. - GEARAspi (x64).) -- C:\Windows\SysNative\GEARAspi64.dll [126312]

O44 - LFC:[MD5.E403AACF8C7BB11375122D2464560311] - 14/12/2011 - 18:45:01 RSHAD . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\system32\drivers\GEARAspiWDM.sys [34152]

O44 - LFC:[MD5.AC0612BEB517CACF463E1F5EE76E52FD] - 14/12/2011 - 18:45:01 RSHAD . (.GEAR Software Inc. - GEARAspi (x64).) -- C:\Windows\system32\GEARAspi64.dll [126312]

O44 - LFC:[MD5.70B9F82509F36A70136414D331223C7E] - 08/12/2011 - 12:44:39 ---A- . (...) -- C:\Windows\DirectX.log [199158]

O44 - LFC:[MD5.01255BE3D9C11714B5CB828BF396AD66] - 05/12/2011 - 22:44:44 ---A- . (...) -- C:\Windows\magix.ini [97]

O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 05/12/2011 - 21:28:23 RSHAD . (...) -- C:\Windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf [0]

O44 - LFC:[MD5.4F1040788C5BF3555A09019819355EE0] - 29/11/2011 - 20:07:05 ---A- . (...) -- C:\Windows\msxml4-KB973688-enu.LOG [293538]

O44 - LFC:[MD5.598D9E0B0626545FA7D4AE20CAF29EDA] - 29/11/2011 - 20:06:28 ---A- . (...) -- C:\Windows\msxml4-KB954430-enu.LOG [292368]

O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 29/11/2011 - 18:15:22 RSHAD . (...) -- C:\Windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf [0]

O44 - LFC:[MD5.FA5892378230DBA340A41A3A1FC0B044] - 29/11/2011 - 15:57:28 ---A- . (...) -- C:\Windows\reViSiT.ini [9703]

O44 - LFC:[MD5.3762C4C97611F4324A44706AEF2D734B] - 29/11/2011 - 14:56:15 ---A- . (...) -- C:\Windows\msocreg32.dat [16]

O44 - LFC:[MD5.65577EF62A45AA9A29639BEC2649FB72] - 29/11/2011 - 00:34:01 ---A- . (.Indigo Rose Corporation - SUF60Runtime.) -- C:\Windows\iun6002.exe [720896]

O44 - LFC:[MD5.47154934E68C58BA025A1166711F1982] - 29/11/2011 - 00:16:39 ---A- . (.InstallShield Software Corporation - InstallShield® unInstaller.) -- C:\Windows\IsUninst.exe [314368]

O44 - LFC:[MD5.D3D64CF7B2BCEAA34A270F45A3FFFB36] - 29/11/2011 - 00:10:14 RSHAD . (.DT Soft Ltd - DAEMON Tools Virtual Bus Driver.) -- C:\Windows\system32\drivers\dtsoftbus01.sys [270912]

O44 - LFC:[MD5.7A15CB514C3D743F0DA6AD3470F364F6] - 28/11/2011 - 19:46:11 ---A- . (.RME - Fireface Settings.) -- C:\Windows\SysNative\firefaceusb.exe [88064]

O44 - LFC:[MD5.7A15CB514C3D743F0DA6AD3470F364F6] - 28/11/2011 - 19:46:11 ---A- . (.RME - Fireface Settings.) -- C:\Windows\system32\firefaceusb.exe [88064]

O44 - LFC:[MD5.B4E01816ED6BD5CE05E97A01B3E75540] - 28/11/2011 - 19:46:11 ---A- . (.RME - Fireface USB Asio Treiber.) -- C:\Windows\SysNative\fireface_usb_asio_64.dll [29184]

O44 - LFC:[MD5.EB67F46854326F760D6031DEC675AF10] - 28/11/2011 - 19:46:11 ---A- . (.RME - TotalMix FX.) -- C:\Windows\SysNative\TotalMixFX.exe [3362816]

O44 - LFC:[MD5.B4E01816ED6BD5CE05E97A01B3E75540] - 28/11/2011 - 19:46:11 RSHAD . (.RME - Fireface USB Asio Treiber.) -- C:\Windows\system32\fireface_usb_asio_64.dll [29184]

O44 - LFC:[MD5.E8760C189C199707AD689C7FF8609153] - 28/11/2011 - 19:46:11 RSHAD . (.RME - Fireface USB Audio Driver (WDM).) -- C:\Windows\system32\drivers\fireface_usb_64.sys [100096]

O44 - LFC:[MD5.EB67F46854326F760D6031DEC675AF10] - 28/11/2011 - 19:46:11 RSHAD . (.RME - TotalMix FX.) -- C:\Windows\system32\TotalMixFX.exe [3362816]

O44 - LFC:[MD5.7AB8E6671B32ABB9E89140E30BF535DE] - 28/11/2011 - 19:46:10 ---A- . (.RME - Fireface USB Asio Treiber.) -- C:\Windows\SysNative\fireface_usb_asio.dll [27136]

O44 - LFC:[MD5.7AB8E6671B32ABB9E89140E30BF535DE] - 28/11/2011 - 19:46:10 ---A- . (.RME - Fireface USB Asio Treiber.) -- C:\Windows\system32\fireface_usb_asio.dll [27136]

O44 - LFC:[MD5.82088BF2B224FF6413BE1A11079D2ED7] - 28/11/2011 - 19:46:10 RSHAD . (.RME - Fireface USB Audio Driver (WDM).) -- C:\Windows\system32\drivers\fireface_usb.sys [81152]

O44 - LFC:[MD5.1FB3BA6C0F403EE0684B636FCCC8E97F] - 28/11/2011 - 18:37:28 ---A- . (...) -- C:\Windows\RPSETUP.EXE.LOG [34714362]

O44 - LFC:[MD5.04D98743206D094FFB2D43EA89A4E36B] - 28/11/2011 - 18:29:08 ---A- . (...) -- C:\Windows\SysNative\license.rtf [206462]

O44 - LFC:[MD5.04D98743206D094FFB2D43EA89A4E36B] - 28/11/2011 - 18:29:08 ---A- . (...) -- C:\Windows\system32\license.rtf [206462]

O44 - LFC:[MD5.41FDFAC6F767B6CA7EEA4B2D3B32B841] - 15/04/2011 - 17:01:28 ---A- . (...) -- C:\Windows\SysNative\fireface_usb.inf [221621]

O44 - LFC:[MD5.41FDFAC6F767B6CA7EEA4B2D3B32B841] - 15/04/2011 - 17:01:28 RSHAD . (...) -- C:\Windows\system32\fireface_usb.inf [221621]

O44 - LFC:[MD5.FA0AF57E428365FBBE643C7989D5C0B5] - 08/02/2011 - 12:26:42 ---A- . (...) -- C:\Windows\SysNative\TotalMixFX.chm [22648]

O44 - LFC:[MD5.FA0AF57E428365FBBE643C7989D5C0B5] - 08/02/2011 - 12:26:42 ---A- . (...) -- C:\Windows\system32\TotalMixFX.chm [22648]

O44 - LFC:[MD5.F9EE207CC85F207F0433C402DC1FEBCC] - 12/11/2002 - 17:29:58 ---A- . (...) -- C:\Windows\mgxoschk.ini [730]

~ Scan Files in 00mn 48s




---\\ Déni du service (Local Security Authority) (O48)

O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll

O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\TSpkg.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\LIVESSP.dll

~ Scan Keys in 00mn 00s




---\\ Contrôle du Safe Boot (CSB) (O49)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\system32\Drivers\sermouse.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\system32\Drivers\vga.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\system32\Drivers\vgasave.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\system32\Drivers\volmgr.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\system32\Drivers\volmgrx.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\system32\Drivers\ipnat.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\mfefirek.sys . (.McAfee, Inc. - McAfee Core Firewall Engine Driver.) -- C:\Windows\system32\Drivers\mfefirek.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\mfehidk.sys . (.McAfee, Inc. - McAfee Link Driver.) -- C:\Windows\system32\Drivers\mfehidk.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\system32\Drivers\nsiproxy.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\system32\Drivers\rdpencdd.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\system32\Drivers\sermouse.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\system32\Drivers\vga.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\system32\Drivers\vgasave.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\system32\Drivers\volmgr.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\system32\Drivers\volmgrx.sys

~ Scan CSB in 00mn 00s




---\\ MountPoints2 Shell Key (O51) (None)


---\\ Trojan Driver Search Data (HKLM) (O52)

O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm

O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm

~ Scan Keys in 00mn 00s




---\\ ShareTools MSconfig StartupReg (O53) (None)


---\\ Microsoft Control Security Providers (O54)

O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\system32\credssp.dll

O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\system32\credssp.dll

~ Scan Keys in 00mn 00s




---\\ Microsoft Windows Policies System (O55)

O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5

O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3

O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0

O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1

O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1

O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0

O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0

O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=

O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=

O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0

O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1

O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1

O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0

~ Scan Keys in 00mn 00s




---\\ Microsoft Windows Policies Explorer (O56)

O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1

O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1

O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0

~ Scan Keys in 00mn 00s




---\\ Liste des Drivers Système (O58)

O58 - SDL:[MD5.E0065CBF1A25C015C218457D2CD522B9] - 14/10/2011 - 15:42:12 ---A- . (.ST Microelectronics - Accelerometer Port I/O.) -- C:\Windows\system32\drivers\Accelern.sys [27760]

O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 10/06/2009 - 02:52:21 RSHAD . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\system32\drivers\adp94xx.sys [491088]

O58 - SDL:[MD5.597F78224EE9224EA1A13D6350CED962] - 13/07/2009 - 02:52:21 RSHAD . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\system32\drivers\adpahci.sys [339536]

O58 - SDL:[MD5.E109549C90F62FB570B9540C4B148E54] - 13/07/2009 - 02:52:21 RSHAD . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\system32\drivers\adpu320.sys [182864]

O58 - SDL:[MD5.5812713A477A3AD7363C7438CA2EE038] - 14/07/2009 - 02:52:21 RSHAD . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\system32\drivers\aliide.sys [15440]

O58 - SDL:[MD5.D4121AE6D0C0E7E13AA221AA57EF2D49] - 14/10/2011 - 16:59:26 RSHAD . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\system32\drivers\amdsata.sys [107904]

O58 - SDL:[MD5.F67F933E79241ED32FF46A4F29B5120B] - 10/06/2009 - 02:52:20 RSHAD . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows -.) -- C:\Windows\system32\drivers\amdsbs.sys [194128]

O58 - SDL:[MD5.540DAF1CEA6094886D72126FD7C33048] - 14/10/2011 - 16:59:26 RSHAD . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\system32\drivers\amdxata.sys [27008]

O58 - SDL:[MD5.C484F8CEB1717C540242531DB7845C4E] - 13/07/2009 - 02:52:21 RSHAD . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\system32\drivers\arc.sys [87632]

O58 - SDL:[MD5.019AF6924AEFE7839F61C830227FE79C] - 13/07/2009 - 02:52:21 RSHAD . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\system32\drivers\arcsas.sys [97856]

O58 - SDL:[MD5.B5ACE6968304A3900EEB1EBFD9622DF2] - 10/06/2009 - 21:34:23 RSHAD . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver..) -- C:\Windows\system32\drivers\b57nd60a.sys [270848]

O58 - SDL:[MD5.F09EEE9EDC320B5E1501F749FDE686C8] - 14/07/2009 - 21:41:06 RSHAD . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\system32\drivers\BrFiltLo.sys [18432]

O58 - SDL:[MD5.B114D3098E9BDB8BEA8B053685831BE6] - 14/07/2009 - 21:41:06 RSHAD . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\system32\drivers\BrFiltUp.sys [8704]

O58 - SDL:[MD5.43BEA8D483BF1870F018E2D02E06A5BD] - 14/07/2009 - 02:19:07 RSHAD . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\system32\drivers\BrSerId.sys [286720]

O58 - SDL:[MD5.A6ECA2151B08A09CACECA35C07F05B42] - 14/07/2009 - 21:41:10 RSHAD . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\system32\drivers\BrSerWdm.sys [47104]

O58 - SDL:[MD5.B79968002C277E869CF38BD22CD61524] - 14/07/2009 - 21:41:10 RSHAD . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\system32\drivers\BrUsbMdm.sys [14976]

O58 - SDL:[MD5.A87528880231C54E75EA7A44943B38BF] - 14/07/2009 - 21:41:10 RSHAD . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\system32\drivers\BrUsbSer.sys [14720]

O58 - SDL:[MD5.7A2CE8C1BF4DAA1F2766E21E9CA11078] - 14/10/2011 - 14:17:46 RSHAD . (.Broadcom Corporation. - Broadcom Bluetooth USB AMP Filter for Windows Vista.) -- C:\Windows\system32\drivers\btwampfl.sys [344616]

O58 - SDL:[MD5.D895DC213EDBDA5FCC53AAD1F1E0E63B] - 14/10/2011 - 14:17:46 RSHAD . (.Broadcom Corporation. - Broadcom Bluetooth AVDT Service.) -- C:\Windows\system32\drivers\btwavdt.sys [135720]

O58 - SDL:[MD5.6D7AA2BDE0135599C5F230D69DB3B420] - 14/10/2011 - 14:17:46 RSHAD . (.Broadcom Corporation. - Bluetooth Remote Control HID Minidriver.) -- C:\Windows\system32\drivers\btwrchid.sys [21544]

O58 - SDL:[MD5.3E5B191307609F7514148C6832BB0842] - 10/06/2009 - 21:34:28 RSHAD . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\system32\drivers\bxvbda.sys [468480]

O58 - SDL:[MD5.ED0263B2EB24F0F4E3898036FA1D28A1] - 15/10/2011 - 13:16:16 RSHAD . (.McAfee, Inc. - McAfee Personal Firewall IDS Plugin.) -- C:\Windows\system32\drivers\cfwids.sys [65264]

O58 - SDL:[MD5.E19D3F095812725D88F9001985B94EDD] - 14/07/2009 - 02:52:31 RSHAD . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\cmdide.sys [17488]

O58 - SDL:[MD5.4CE9F703D1DD69FB656D1953E9C88103] - 14/10/2011 - 16:49:00 RSHAD . (.Creative Technology Ltd. - Advanced Audio FX Driver (64-bit).) -- C:\Windows\system32\drivers\CtAudDrv.sys [224768]

O58 - SDL:[MD5.BC3D4F90978CD7C8EABD1BAF3BF7873A] - 14/10/2011 - 17:20:46 RSHAD . (.Creative Technology Ltd. - Video Class Upper Filter Driver (64-bit).) -- C:\Windows\system32\drivers\CtClsFlt.sys [176096]

O58 - SDL:[MD5.D3D64CF7B2BCEAA34A270F45A3FFFB36] - 29/11/2011 - 00:10:14 RSHAD . (.DT Soft Ltd - DAEMON Tools Virtual Bus Driver.) -- C:\Windows\system32\drivers\dtsoftbus01.sys [270912]

O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 10/06/2009 - 02:47:48 RSHAD . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\system32\drivers\elxstor.sys [530496]

O58 - SDL:[MD5.E47D9D7E6E53892FC97282482F4AE307] - 14/10/2011 - 21:43:42 ---A- . (.Windows ® Win 7 DDK provider - Embedded System Control.) -- C:\Windows\system32\drivers\EMSC.sys [16752]

O58 - SDL:[MD5.DC5D737F51BE844D8C82C695EB17372F] - 10/06/2009 - 21:34:33 RSHAD . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\system32\drivers\evbda.sys [3286016]

O58 - SDL:[MD5.82088BF2B224FF6413BE1A11079D2ED7] - 28/11/2011 - 17:01:22 RSHAD . (.RME - Fireface USB Audio Driver (WDM).) -- C:\Windows\system32\drivers\fireface_usb.sys [81152]

O58 - SDL:[MD5.E8760C189C199707AD689C7FF8609153] - 28/11/2011 - 17:01:48 RSHAD . (.RME - Fireface USB Audio Driver (WDM).) -- C:\Windows\system32\drivers\fireface_usb_64.sys [100096]

O58 - SDL:[MD5.E403AACF8C7BB11375122D2464560311] - 14/12/2011 - 13:17:08 RSHAD . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\system32\drivers\GEARAspiWDM.sys [34152]

O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 13/07/2009 - 21:31:59 RSHAD . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\system32\drivers\hcw85cir.sys [31232]

O58 - SDL:[MD5.A6518DCC42F7A6E999BB3BEA8FD87567] - 14/10/2011 - 00:48:26 RSHAD . (.Intel Corporation - Intel® Management Engine Interface.) -- C:\Windows\system32\drivers\HECIx64.sys [56344]

O58 - SDL:[MD5.39D2ABCD392F3D8A6DCE7B60AE7B8EFC] - 21/11/2010 - 04:23:47 RSHAD . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\system32\drivers\HpSAMD.sys [78720]

O58 - SDL:[MD5.D7921D5A870B11CC1ADAB198A519D50A] - 14/10/2011 - 05:45:48 RSHAD . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\Windows\system32\drivers\iaStor.sys [438808]

O58 - SDL:[MD5.AAAF44DB3BD0B9D1FB6969B23ECC8366] - 14/10/2011 - 16:59:26 RSHAD . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\system32\drivers\iaStorV.sys [410496]

O58 - SDL:[MD5.795C99DC4F574C97C03D0BB39CF099EE] - 14/10/2011 - 03:31:52 RSHAD . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\system32\drivers\igdkmd64.sys [12262336]

O58 - SDL:[MD5.5C18831C61933628F5BB0EA2675B9D21] - 13/07/2009 - 02:48:04 RSHAD . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\system32\drivers\iirsp.sys [44112]

O58 - SDL:[MD5.DD587A55390ED2295BCE6D36AD567DA9] - 14/10/2011 - 03:39:38 RSHAD . (.Intel Corporation - Intel® Turbo Boost Technology Driver.) -- C:\Windows\system32\drivers\Impcd.sys [158976]

O58 - SDL:[MD5.FC727061C0F47C8059E88E05D5C8E381] - 14/10/2011 - 03:39:26 RSHAD . (.Intel® Corporation - Intel® Display Audio Driver.) -- C:\Windows\system32\drivers\IntcDAud.sys [317440]

O58 - SDL:[MD5.EBED8B3FF4A823C1A6EEBEED7B29353F] - 14/10/2011 - 20:10:44 RSHAD . (.Atheros Communications, Inc. - Atheros L1c PCI-E Gigabit Ethernet Controller.) -- C:\Windows\system32\drivers\L1C62x64.sys [76912]

O58 - SDL:[MD5.37EFB026E1A8A79FBE7044A241281B3E] - 29/11/2011 - 17:42:56 RSHAD . ( - LoopBe1 Internal MIDI Device.) -- C:\Windows\system32\drivers\loopbe1.sys [13824]

O58 - SDL:[MD5.1A93E54EB0ECE102495A51266DCDB6A6] - 13/07/2009 - 02:48:04 RSHAD . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_fc.sys [114752]

O58 - SDL:[MD5.1047184A9FDC8BDBFF857175875EE810] - 13/07/2009 - 02:48:04 RSHAD . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas.sys [106560]

O58 - SDL:[MD5.30F5C0DE1EE8B5BC9306C1F0E4A75F93] - 13/07/2009 - 02:48:04 RSHAD . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas2.sys [65600]

O58 - SDL:[MD5.0504EACAFF0D3C8AED161C4B0D369D4A] - 13/07/2009 - 02:48:04 RSHAD . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_scsi.sys [115776]

O58 - SDL:[MD5.A55805F747C6EDB6A9080D7C633BD0F4] - 10/06/2009 - 02:48:04 RSHAD . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for.) -- C:\Windows\system32\drivers\megasas.sys [35392]

O58 - SDL:[MD5.BAF74CE0072480C3B6B7C13B2A94D6B3] - 13/07/2009 - 02:48:04 RSHAD . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\system32\drivers\MegaSR.sys [284736]

O58 - SDL:[MD5.EF3ACFB7E3F82D5F7CDE9EF5F0A4E2E2] - 15/10/2011 - 13:16:16 RSHAD . (.McAfee, Inc. - Access Protection Filter Driver.) -- C:\Windows\system32\drivers\mfeapfk.sys [160280]

O58 - SDL:[MD5.E7A60BDB4365B561D896019B82FB7DD0] - 15/10/2011 - 13:16:16 RSHAD . (.McAfee, Inc. - Anti-Virus File System Filter Driver.) -- C:\Windows\system32\drivers\mfeavfk.sys [229528]

O58 - SDL:[MD5.8C679B2374803C85439B6AF6FD91D039] - 29/11/2011 - 13:16:16 RSHAD . (.McAfee, Inc. - McAfee Driver Cleaning Driver.) -- C:\Windows\system32\drivers\mfeclnk.sys [10248]

O58 - SDL:[MD5.670DFFE55E2F9AB99D9169C428BCECE9] - 15/10/2011 - 13:16:16 RSHAD . (.McAfee, Inc. - McAfee Core Firewall Engine Driver.) -- C:\Windows\system32\drivers\mfefirek.sys [481768]

O58 - SDL:[MD5.1892616B7F9291FD77C3FA0A5811FE9F] - 15/10/2011 - 13:16:16 RSHAD . (.McAfee, Inc. - McAfee Link Driver.) -- C:\Windows\system32\drivers\mfehidk.sys [647080]

O58 - SDL:[MD5.1721261C77F6E7A9E0CB51B7D9F31B60] - 29/11/2011 - 13:16:16 RSHAD . (.McAfee, Inc. - McAfee NDIS Light Filter Driver.) -- C:\Windows\system32\drivers\mfenlfk.sys [75808]

O58 - SDL:[MD5.65776BD8029E409935B90DE30BF99526] - 15/10/2011 - 13:16:16 RSHAD . (.McAfee, Inc. - McAfee Code Analysis Driver.) -- C:\Windows\system32\drivers\mferkdet.sys [100912]

O58 - SDL:[MD5.4F17D8B85B903D96EF7033BB6EF50516] - 15/10/2011 - 13:16:16 RSHAD . (.McAfee, Inc. - Anti-Virus Mini-Firewall Driver.) -- C:\Windows\system32\drivers\mfewfpk.sys [284648]

O58 - SDL:[MD5.5D262402B0634C998F8CBCEAD7DD8676] - 14/10/2011 - 15:43:48 RSHAD . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\system32\drivers\NETwNs64.sys [8505856]

O58 - SDL:[MD5.77889813BE4D166CDAB78DDBA990DA92] - 13/07/2009 - 02:48:26 RSHAD . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\system32\drivers\nfrd960.sys [51264]

O58 - SDL:[MD5.0EBC9D13CD96C15B1B18D8678A609E4B] - 14/10/2011 - 01:18:22 RSHAD . (.Renesas Electronics Corporation - USB 3.0 Hub Driver.) -- C:\Windows\system32\drivers\nusb3hub.sys [82432]

O58 - SDL:[MD5.7BDEC000D56D485021D9C1E63C2F81CA] - 14/10/2011 - 01:18:22 RSHAD . (.Renesas Electronics Corporation - USB 3.0 Host Controller Driver.) -- C:\Windows\system32\drivers\nusb3xhc.sys [181760]

O58 - SDL:[MD5.857FB74754EBFF94EE3AD40788740916] - 14/10/2011 - 18:04:24 RSHAD . (.NVIDIA Corporation - NVIDIA HDMI Audio Driver.) -- C:\Windows\system32\drivers\nvhda64v.sys [155752]

O58 - SDL:[MD5.D5DEA2C1865CAB9EE6AA29CF9E79A2CE] - 14/10/2011 - 18:04:20 RSHAD . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 267.21.) -- C:\Windows\system32\drivers\nvlddmkm.sys [13056488]

O58 - SDL:[MD5.5EF70F7714C664BCF50EDFC141DEA9B8] - 14/10/2011 - 18:04:22 RSHAD . (.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version 267.21.) -- C:\Windows\system32\drivers\nvpciflt.sys [25960]

O58 - SDL:[MD5.0A92CB65770442ED0DC44834632F66AD] - 14/10/2011 - 16:59:26 RSHAD . (.NVIDIA Corporation - NVIDIA® nForce RAID Driver.) -- C:\Windows\system32\drivers\nvraid.sys [148352]

O58 - SDL:[MD5.DAB0E87525C10052BF65F06152F37E4A] - 14/10/2011 - 16:59:26 RSHAD . (.NVIDIA Corporation - NVIDIA® nForce Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor.sys [166272]

O58 - SDL:[MD5.A53A15A11EBFD21077463EE2C7AFEEF0] - 10/06/2009 - 02:45:46 RSHAD . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\system32\drivers\ql2300.sys [1524816]

O58 - SDL:[MD5.4F6D12B51DE1AAEFF7DC58C4D75423C8] - 13/07/2009 - 02:45:45 RSHAD . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\system32\drivers\ql40xx.sys [128592]

O58 - SDL:[MD5.976BEA339C5305CA7711436EF96D1D0E] - 14/10/2011 - 16:15:46 RSHAD . (.Realtek Semiconductor Corp. - Realtek® High Definition Audio Function Driver.) -- C:\Windows\system32\drivers\RTKVHD64.sys [2713960]

O58 - SDL:[MD5.9D21618E7A3B2C75CF1A2ECBBE723730] - 14/10/2011 - 01:35:08 RSHAD . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vista/Win7.) -- C:\Windows\system32\drivers\RtsPStor.sys [337512]

O58 - SDL:[MD5.3EA8A16169C26AFBEB544E0E48421186] - 14/07/2009 - 21:37:19 RSHAD . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\system32\drivers\secdrv.sys [23040]

O58 - SDL:[MD5.843CAF1E5FDE1FFD5FF768F23A51E2E1] - 10/06/2009 - 02:45:45 RSHAD . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\system32\drivers\sisraid2.sys [43584]

O58 - SDL:[MD5.6A6C106D42E9FFFF8B9FCB4F754F6DA4] - 13/07/2009 - 02:45:46 RSHAD . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\system32\drivers\sisraid4.sys [80464]

O58 - SDL:[MD5.92E7F6666633D2DD91D527503DAA7BE0] - 14/10/2011 - 10:05:12 RSHAD . (.ST Microelectronics - Disk Class Filter Driver for Accelerometer.) -- C:\Windows\system32\drivers\stdcfltn.sys [21616]

O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 13/07/2009 - 02:45:55 RSHAD . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\system32\drivers\stexstor.sys [24656]

O58 - SDL:[MD5.D8205430CFD64FDB7D691D3BB74FD18F] - 14/10/2011 - 17:18:06 RSHAD . (.Synaptics Incorporated - Synaptics Touchpad Driver.) -- C:\Windows\system32\drivers\SynTP.sys [1395760]

O58 - SDL:[MD5.E5689D93FFE4E5D66C0178761240DD54] - 14/07/2009 - 02:45:55 RSHAD . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\viaide.sys [17488]

O58 - SDL:[MD5.5E2016EA6EBACA03C04FEAC5F330D997] - 10/06/2009 - 02:45:55 RSHAD . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\system32\drivers\vsmraid.sys [161872]

O58 - SDL:[MD5.94DC2BF6CBAAA95E369C3756D3115A76] - 14/10/2011 - 11:02:22 RSHAD . (.Intel Corporation - Intel Wireless Display Solution.) -- C:\Windows\system32\drivers\WDKMD.sys [42392]

O58 - SDL:[MD5.CF460F454A0473E6C7AD846B94D8382A] - 14/10/2011 - 21:43:42 ---A- . (.Windows ® Win 7 DDK provider - Embedded System Control.) -- C:\Windows\SysWOW64\drivers\EMSC.sys [13680]

~ Scan Drivers in 00mn 03s




---\\ Liste des outils de nettoyage (O63)

O63 - Logiciel: ZHPDiag 1.28 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1

~ Scan ADS in 00mn 00s




---\\ Liste des services Legacy (O64)

O64 - Services: CurCS - 14/10/2011 - C:\Windows\system32\drivers\afd.sys (AFD) .(.Microsoft Corporation - Ancillary Function Driver for WinSock.) - LEGACY_AFD

O64 - Services: CurCS - 15/10/2011 - C:\Windows\system32\drivers\cfwids.sys (cfwids) .(.McAfee, Inc. - McAfee Personal Firewall IDS Plugin.) - LEGACY_CFWIDS

O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\clfs.sys (CLFS) .(.Microsoft Corporation - Common Log File System Driver.) - LEGACY_CLFS

O64 - Services: CurCS - 21/11/2010 - C:\Windows\system32\Drivers\cng.sys (CNG) .(.Microsoft Corporation - Kernel Cryptography, Next Generation.) - LEGACY_CNG

O64 - Services: CurCS - 21/11/2010 - C:\Windows\system32\drivers\dxgkrnl.sys (DXGKrnl) .(.Microsoft Corporation - DirectX Graphics Kernel.) - LEGACY_DXGKRNL

O64 - Services: CurCS - 21/11/2010 - C:\Windows\system32\drivers\fvevol.sys (fvevol) .(.Microsoft Corporation - BitLocker Drive Encryption Driver.) - LEGACY_FVEVOL

O64 - Services: CurCS - 21/11/2010 - C:\Windows\system32\drivers\hwpolicy.sys (hwpolicy) .(.Microsoft Corporation - Hardware Policy Driver.) - LEGACY_HWPOLICY

O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\DRIVERS\lltdio.sys (lltdio) .(.Microsoft Corporation - Link-Layer Topology Mapper I/O Driver.) - LEGACY_LLTDIO

O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\luafv.sys (luafv) .(.Microsoft Corporation - Pilote de filtre de virtualisation de fichi.) - LEGACY_LUAFV

O64 - Services: CurCS - 15/10/2011 - C:\Windows\system32\drivers\mfeapfk.sys (mfeapfk) .(.McAfee, Inc. - Access Protection Filter Driver.) - LEGACY_MFEAPFK

O64 - Services: CurCS - 15/10/2011 - C:\Windows\system32\drivers\mfeavfk.sys (mfeavfk) .(.McAfee, Inc. - Anti-Virus File System Filter Driver.) - LEGACY_MFEAVFK

O64 - Services: CurCS - ??\??\???? - McAfee Inc. (mfeavfk01) .(. - .) - LEGACY_MFEAVFK01

O64 - Services: CurCS - 15/10/2011 - C:\Windows\system32\drivers\mfefirek.sys (mfefirek) .(.McAfee, Inc. - McAfee Core Firewall Engine Driver.) - LEGACY_MFEFIREK

O64 - Services: CurCS - 15/10/2011 - C:\Windows\system32\drivers\mfehidk.sys (mfehidk) .(.McAfee, Inc. - McAfee Link Driver.) - LEGACY_MFEHIDK

O64 - Services: CurCS - 15/10/2011 - C:\Windows\system32\DRIVERS\mfenlfk.sys (mfenlfk) .(.McAfee, Inc. - McAfee NDIS Light Filter Driver.) - LEGACY_MFENLFK

O64 - Services: CurCS - 15/10/2011 - C:\Windows\system32\drivers\mferkdet.sys (mferkdet) .(.McAfee, Inc. - McAfee Code Analysis Driver.) - LEGACY_MFERKDET

O64 - Services: CurCS - 15/10/2011 - C:\Windows\system32\drivers\mfewfpk.sys (mfewfpk) .(.McAfee, Inc. - Anti-Virus Mini-Firewall Driver.) - LEGACY_MFEWFPK

O64 - Services: CurCS - 21/11/2010 - C:\Windows\system32\drivers\msahci.sys (msahci) .(.Microsoft Corporation - MS AHCI 1.0 Standard Driver.) - LEGACY_MSAHCI

O64 - Services: CurCS - 14/10/2011 - C:\Windows\system32\drivers\ndis.sys (NDIS) .(.Microsoft Corporation - Pilote NDIS 6.20.) - LEGACY_NDIS

O64 - Services: CurCS - 21/11/2010 - C:\Windows\system32\drivers\netbt.sys (NetBT) .(.Microsoft Corporation - MBT Transport driver.) - LEGACY_NETBT

O64 - Services: CurCS - 11/03/2011 - C:\Windows\system32\DRIVERS\nvpciflt.sys (nvpciflt) .(.NVIDIA Corporation - NVIDIA Windows Kernel Mode Driver, Version.) - LEGACY_NVPCIFLT

O64 - Services: CurCS - 21/11/2010 - C:\Windows\System32\drivers\pacer.sys (Psched) .(.Microsoft Corporation - Planificateur de paquets QoS.) - LEGACY_PSCHED

O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\DRIVERS\rspndr.sys (rspndr) .(.Microsoft Corporation - Link-Layer Topology Responder Driver for ND.) - LEGACY_RSPNDR

O64 - Services: CurCS - ??\??\???? - C:\Windows\system32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV

O64 - Services: CurCS - 14/10/2011 - C:\Windows\system32\DRIVERS\srvnet.sys (srvnet) .(.Microsoft Corporation - Server Network driver.) - LEGACY_SRVNET

O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\drivers\vga.sys (VgaSave) .(.Microsoft Corporation - VGA/Super VGA Video Driver.) - LEGACY_VGASAVE

O64 - Services: CurCS - 21/11/2010 - C:\Windows\system32\drivers\volsnap.sys (volsnap) .(.Microsoft Corporation - Pilote de cliché instantané du volume.) - LEGACY_VOLSNAP

O64 - Services: CurCS - 14/07/2009 - C:\Windows\system32\rascfg.dll (Wanarpv6) .(.Microsoft Corporation - Objets de configuration RAS.) - LEGACY_WANARPV6

~ Scan Services in 00mn 00s




---\\ File Associations Shell Spawning (O67)

O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (. - .) -- "%1" %*

O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\system32\control.exe

O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (.Microsoft Corporation - Windows Control Panel.) -- "%1" %*

O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (.Microsoft Corporation - Windows Control Panel.) -- "%1" %*

O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe

O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe

O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\Pierrotin\AppData\Local\Google\Chrome\Application\chrome.exe

O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\system32\control.exe

O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] (.Microsoft Corporation - Windows Control Panel.) -- "%1" %*

O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] (.Microsoft Corporation - Windows Control Panel.) -- "%1" %*

O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.html> <ChromeHTML>[HKCR\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\Pierrotin\AppData\Local\Google\Chrome\Application\chrome.exe

O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe

O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe

~ Scan Keys in 00mn 00s




---\\ Start Menu Internet (O68)

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\Pierrotin\AppData\Local\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\Pierrotin\AppData\Local\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Users\Pierrotin\AppData\Local\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Users\Pierrotin\AppData\Local\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe

~ Scan Keys in 00mn 00s




---\\ Recherche des services démarrés par Svchost (O83)

O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\system32\aelupsvc.dll [72192]

O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\system32\certprop.dll [80384]

O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\system32\certprop.dll [80384]

O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\system32\srvsvc.dll [236032]

O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\system32\gpsvc.dll [777728]

O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\system32\ikeext.dll [853504]

O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\system32\Audiosrv.dll [679424]

O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\system32\rasauto.dll [99328]

O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\system32\rasmans.dll [344064]

O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\system32\mprdim.dll [97792]

O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\system32\sens.dll [64512]

O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\system32\ipnathlp.dll [359424]

O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows.) -- C:\Windows\system32\tapisrv.dll [316928]

O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\system32\termsrv.dll [680960]

O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\system32\wuaueng.dll [2420736]

O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\system32\qmgr.dll [849920]

O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\system32\shsvcs.dll [370688]

O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\system32\iphlpsvc.dll [569344]

O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720]

O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\system32\appinfo.dll [70656]

O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\system32\iscsiexe.dll [156672]

O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\system32\mmcss.dll [67584]

O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [242688]

O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\system32\sessenv.dll [121856]

O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\system32\browser.dll [136192]

O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\system32\eapsvc.dll [111104]

O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\system32\schedsvc.dll [1110016]

O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\system32\kmsvc.dll [90624]

O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\system32\wercplsupport.dll [84480]

O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [209920]

O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\system32\themeservice.dll [44544]

O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\system32\bdesvc.dll [100864]

~ Scan Services in 00mn 00s




---\\ Recherche particuliere à la racine de certains dossiers (O84)

[MD5.D6145F574E9DC2CAFC314A09A7660CB5] [sPRF][05/02/2003] (...) -- C:\Users\Pierrotin\AppData\Local\Temp\arctic-loop.exe [245248]

[MD5.0E2281AEC56203CA6A9E1848F7DBDF5A] [sPRF][19/10/2011] (.Sun Microsystems, Inc. - Java Platform SE binary.) -- C:\Users\Pierrotin\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe [909088]

[MD5.E77CA5C844D7C95B2B841B7B0218C016] [sPRF][29/11/2011] (...) -- C:\Users\Pierrotin\AppData\Local\Temp\minimp3.exe [45056]

[MD5.858AD3C66AE342BFC52001707123F8C9] [sPRF][20/12/1999] (...) -- C:\Users\Pierrotin\AppData\Local\Temp\mpegc.dll [56832]

[MD5.887173F53072CD2D238014F4199B35CF] [sPRF][10/07/2011] (...) -- C:\Users\Pierrotin\AppData\Local\Temp\xmlUpdater.exe [118784]

~ Scan Files in 00mn 03s




---\\ Firewall Active Exception List (FirewallRules) (O87)

O87 - FAEL: "NetPres-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)

O87 - FAEL: "NetPres-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)

O87 - FAEL: "NetPres-WSD-In-UDP" |In - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)

O87 - FAEL: "NetPres-WSD-Out-UDP" |Out - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)

O87 - FAEL: "NetPres-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)

O87 - FAEL: "NetPres-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)

O87 - FAEL: "{041FB682-D325-47F8-AC0B-726A94F16016}" | In - Public - P6 - FALSE | .(.NVIDIA Corporation - NVIDIA Settings Update Manager.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

O87 - FAEL: "{A3A9661E-10D5-436F-9CA4-6E5F791B4D09}" | In - Public - P17 - FALSE | .(.NVIDIA Corporation - NVIDIA Settings Update Manager.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

O87 - FAEL: "{55C5AB04-7F09-4B1B-A806-C9A2587ACD11}" | In - None - P17 - TRUE | .(.Pas de propriétaire - Wireless PAN DHCP and DNS Server.) -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe

O87 - FAEL: "{9464935C-0B92-44E6-BCF6-5BD85622B248}" | In - None - P17 - TRUE | .(.Intel Corporation - WiDiApp.) -- C:\Program Files (x86)\Intel Corporation\Intel Wireless Display\WiDiApp.exe

O87 - FAEL: "{33180C7A-2933-4AB1-B8B9-C88CDBCDC586}" | In - None - P17 - TRUE | .(.CyberLink Corp. - VideoStage.) -- C:\Program Files (x86)\Dell\VideoStage\VideoStage.exe

O87 - FAEL: "{9D46A377-587F-4483-8C65-BF0D998D4B03}" | In - Public - P6 - TRUE | .(.McAfee, Inc. - McAfee Service Host.) -- C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

O87 - FAEL: "{7A8BF117-CF8B-49F9-AF3E-BAD13A8AC64C}" | In - Public - P17 - TRUE | .(.McAfee, Inc. - McAfee Service Host.) -- C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

O87 - FAEL: "{C68504FD-162C-4DE8-AB5E-B58B59D84BB0}" | In - None - P6 - TRUE | .(.Pas de propriétaire - Stage Remote Service.) -- C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe

O87 - FAEL: "{371DCE24-2B6A-46E6-A5B7-D1E3103A8118}" | In - None - P6 - TRUE | .(.Pas de propriétaire - Stage Remote Manager.) -- C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe

O87 - FAEL: "{CC01CC71-4728-43E8-90A2-63C27649A41E}" | In - None - P6 - TRUE | .(.ArcSoft, Inc. - Stage Remote Controller.) -- C:\Program Files (x86)\Dell\Stage Remote\Controller.exe

O87 - FAEL: "{DAD13286-3699-478E-8732-2C8FCDD44D43}" | In - None - P6 - TRUE | .(...) -- C:\Program Files (x86)\Dell\Stage Remote\InstallerHelp.exe

O87 - FAEL: "{EA7E7397-3DBC-409A-82CB-BE6B325ABDD8}" | In - None - P6 - TRUE | .(.Pas de propriétaire - Stage Remote Player.) -- C:\Program Files (x86)\Dell\Stage Remote\DMR.exe

O87 - FAEL: "{15699FB6-9AD6-4934-B305-FF76C13DAE4D}" | In - None - P17 - TRUE | .(.Pas de propriétaire - Stage Remote Service.) -- C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe

O87 - FAEL: "{49B67732-9705-4D84-BF8F-541440DE565A}" | In - None - P17 - TRUE | .(.Pas de propriétaire - Stage Remote Manager.) -- C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe

O87 - FAEL: "{B058470F-58A8-44CA-8811-92775D5BDF3C}" | In - None - P17 - TRUE | .(.ArcSoft, Inc. - Stage Remote Controller.) -- C:\Program Files (x86)\Dell\Stage Remote\Controller.exe

O87 - FAEL: "{7E98726F-60F9-450B-BFA7-BC693E0C46DA}" | In - None - P17 - TRUE | .(.Pas de propriétaire - Stage Remote Player.) -- C:\Program Files (x86)\Dell\Stage Remote\DMR.exe

O87 - FAEL: "{850CCA93-134D-419B-A09F-B1EEE394037C}" | In - None - P17 - TRUE | .(...) -- C:\Program Files (x86)\Dell\Stage Remote\InstallerHelp.exe

O87 - FAEL: "{56675491-B98D-4A05-A6E0-803FE702C6CC}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\dell stage\dell stage\accuweather\accuweather.exe (.not file.)

O87 - FAEL: "{6F11ED8B-D8E6-45E0-A724-C092F6D51B8D}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\dell stage\musicstage\musicstageengine.exe (.not file.)

O87 - FAEL: "{5C05C928-F004-4692-B6FF-CD6001FB6498}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\dell stage\dell stage\stage_primary.exe (.not file.)

O87 - FAEL: "{C10CEB3B-2EA0-4E62-B4D4-36235E285A87}" | In - None - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe

O87 - FAEL: "{D63EFD2C-B0F9-4084-97F6-1D9FED2E0964}" | In - None - P17 - TRUE | .(.Apple Inc. - WebKit2WebProcess.exe.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe

O87 - FAEL: "{3908D565-C8E1-4D4B-9B53-D16DF82AA15C}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe

O87 - FAEL: "{6D2580E3-819F-48B4-95BC-020B6696C468}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe

O87 - FAEL: "{1330E862-86A0-4261-BED0-E64B0C4CED88}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe

O87 - FAEL: "{4DABA880-2121-4653-941D-690B067A1B50}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe

O87 - FAEL: "{E6D813DF-56A9-403F-9A4F-5C3B6B230AB9}" | In - None - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files (x86)\iTunes\iTunes.exe

~ Scan Firewall in 00mn 01s




---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)

SR - | Auto 14/10/2011 98208 | (AERTFilters) . (.Andrea Electronics Corporation.) - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe

SR - | Auto 14/10/2011 15296 | (AlienFusionService) . (.Alienware.) - C:\Program Files\Alienware\Command Center\AlienFusionService.exe

SR - | Auto 14/12/2011 55144 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

SR - | Auto 14/12/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe

SR - | Auto 14/10/2011 1515792 | (EvtEng) . (.Intel® Corporation.) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe

SR - | Auto 14/10/2011 13336 | (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

SS - | Demand 14/10/2011 73728 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

SR - | Demand 14/12/2011 934760 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe

SS - | Demand 08/03/2011 224704 | (McAWFwk) . (.McAfee, Inc..) - C:\Program Files\mcafee\msc\McAWFwk.exe

SS - | Auto 14/10/2011 249936 | (McMPFSvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

SR - | Auto 14/10/2011 249936 | (mcmscsvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

SR - | Auto 14/10/2011 249936 | (McNaiAnn) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

SR - | Auto 14/10/2011 249936 | (McNASvc) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

SS - | Demand 14/10/2011 501768 | (McODS) . (.McAfee, Inc..) - C:\Program Files\mcafee\virusscan\mcods.exe

SS - | Disabled 14/10/2011 249936 | (McOobeSv) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

SR - | Auto 14/10/2011 249936 | (McProxy) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

SS - | Auto 29/11/2011 199272 | (McShield) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe

SS - | Auto 29/11/2011 208536 | (mfefire) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe

SS - | Auto 29/11/2011 161168 | (mfevtp) . (.McAfee, Inc..) - C:\Windows\system32\mfevtps.exe

SR - | Auto 14/10/2011 249936 | (MSK80Service) . (.McAfee, Inc..) - C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe

SS - | Demand 340240 | (MyWiFiDHCPDNS) . (...) - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe

SR - | Auto 14/10/2011 503080 | C:\Program Files (x86)\Nero\Update\NASvc.exe (NAUpdate) . (.Nero AG.) - C:\Program Files (x86)\Nero\Update\NASvc.exe

SR - | Auto 14/10/2011 993896 | (NVSvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe

SR - | Auto 14/10/2011 2009704 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

SR - | Auto 14/10/2011 836880 | (RegSrvc) . (.Intel® Corporation.) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

SS - | Demand 14/10/2011 1116656 | (RoxMediaDB12OEM) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe

SS - | Auto 14/10/2011 219632 | (RoxWatch12) . (.Sonic Solutions.) - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe

SR - | Auto 29/11/2011 1692480 | (SftService) . (.SoftThinks SAS.) - C:\Program Files (x86)\AlienRespawn\SftService.exe

SR - | Auto 14/10/2011 378472 | (Stereo Service) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

SS - | Demand 14/10/2011 74392 | (stllssvr) . (.MicroVision Development, Inc..) - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe

SR - | Auto 14/07/2009 27136 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Scan Services in 00mn 07s




---\\ Recherche Master Boot Record Infection (MBR)(O80)

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, GMER - Rootkit Detector and Remover

Run by Pierrotin at 23/12/2011 19:13:12


device: opened successfully

user: error reading MBR


Disk trace:

error: Read Descripteur non valide

kernel: error reading MBR

~ Scan MBR in 00mn 02s




---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)

Written by ad13, http://ad13.geekstog

Run by Pierrotin at 23/12/2011 19:13:14


********* Dump file Name *********


~ Scan MBR in 00mn 04s




---\\ Liste des émulateurs de CD/DVD (Hook du MBR)

O42 - Logiciel: DAEMON Tools Lite - (.DT Soft Ltd.) [HKLM] -- DAEMON Tools Lite

~ Scan Emulateurs in 00mn 04s




End of the scan (1422 lines in 02mn 07s)(0)



Pouvez-vous m'aider?



Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
  • Créer...